Privacy Policy
This Privacy Policy explains how HALLT Ltd (“HALLT”, “we”, “us”) collects, uses, stores, and shares personal data when you use www.hallt.co.uk and the HALLT mobile applications (passenger, driver, and related admin tools).
HALLT is an electronic hail platform for licensed Hackney carriage (black cab / ply-for-hire) services. We are not a private hire operator and do not process passenger journey fares as a booking office.
App users also accept our full Terms of Service in the app (including a data-protection section). If wording conflicts for contract purposes, the in-app Terms version you accepted applies; this page is the public privacy notice for the website and stores (Google Play / App Store).
1. Who we are (data controller)
Data controller (under UK GDPR): HALLT Ltd
Company number: 17349811
Registered office: Suite A, 82 James Carter Road, Mildenhall, IP28 7DE
Email: info@hallt.co.uk
Website: https://www.hallt.co.uk
“Data controller” is a UK data-protection term. It means HALLT Ltd is the organisation legally responsible for personal data processed in the HALLT apps and on this website (deciding why and how that information is used). It does not mean a private hire booking office, radio despatcher, or phone-based taxi controller.
For privacy questions or to exercise your rights, email info@hallt.co.uk. You may also complain to the UK Information Commissioner’s Office (ICO): ico.org.uk.
2. This website
The marketing site is a simple static site. You do not need an account to browse it. If you email us, we use your email address and message content to reply and manage enquiries.
Hosting may generate standard technical logs (for example IP address, browser type, pages requested, timestamps) for security, abuse prevention, and reliability. We do not currently run marketing analytics cookies on this site. If we add analytics or similar tools later, we will update this Policy.
3. What data we process in the apps
Depending on whether you are a passenger or a driver, we may process:
- Identity and contact: name, email, phone number; for drivers, legal first and last name where collected (for verification and compliance — display name shown to passengers may differ).
- Passenger mobile number: used for one-time passcode (OTP) sign-in and account security. Passenger telephone numbers are not shared with drivers, are not shown on hails, and are not used for marketing calls or texts. Changing number while signed in is done in-app with a code to the new number; if you can no longer use your registered mobile and cannot sign in, HALLT is not obliged to rebind a new number to that account. After account deletion, a phone-registry binding may be retained so the same mobile cannot simply create a fresh HALLT account (see retention / account closure below).
- Account and security: authentication identifiers, session IDs (single-device session where used), optional biometric app lock (device unlock only — we do not receive your fingerprint/Face ID template from the OS). Driver email sign-up may keep legal/display names on the device only until email is verified; incomplete driver sign-ups that never complete email verification may be removed automatically after about 24 hours (Auth account cleanup).
- Profile: photo and display details you provide. Passenger photos may be held as pending review until HALLT admin approves them for drivers to see on hails; rejected photos may stay visible to you and admin but not to drivers.
-
Optional customer trust verification (passengers, including dual-mode
drivers hailing as passengers):
- Linking Google (Android) or Apple (iOS) to your HALLT login — we store link flags so drivers can see a social-verified badge. This is not required to hail.
- Optional government photo ID image and a short live selfie, pending and approved copies, submission timestamps, admin approve/reject outcomes and reasons, and assistive on-device likeness scores/notes for HALLT admin review. Used only to operate the optional “ID checked” trust path for drivers on HALLT — not for advertising.
- Optional profile-face match: comparing your approved passenger profile photo to an approved ID (scores, flags, admin soft confirmation) so drivers can see a stronger face-matched trust badge. Separate from Driver Live Verification (DLV).
- Trust tier / badge stamps placed on hail records, and a count of completed real hails (“successful hails with HALLT”) shown to drivers where the product displays it.
- Location: live or recent GPS when using map, hail, For Hire, trip, taxi rank / presence, or (for drivers) background location while For Hire or on a trip so matching, district rules, ranks, and trip integrity work. If you use trip share, live taxi coordinates for that trip may also be published to a temporary follow link you create (see section 6A).
- Hail and trip records: pickup, destination, times, status, cancellations (including cancel reasons such as intentional delay / non-progress towards pickup), passenger/luggage/pet/accessibility notes, estimates, match metadata, meet confirmation, short pickup meet / verification codes where used for pickup integrity, destination-change answers, and related operational records.
- Live location trails during trips for safety, integrity, and review (typically customer trail samples while a trip is open).
- Driver approach samples: after a hail is accepted, the app may buffer short GPS samples of the driver’s path towards pickup. Those samples are ephemeral and are discarded when the passenger is on board or the hail ends normally. They are kept with the hail / conduct report only if the passenger cancels citing intentional delay or similar non-progress, so HALLT can review (including assistive auto-scores that inform administrators and do not alone decide guilt). Confirmed outcomes may adjust cancel-after-accept scores and driver conduct flags.
- Device and technical data: device type, app version, push tokens, diagnostics, and (for drivers) a random per-install device identifier used only for Driver Live Verification / trusted-device binding — not an advertising ID.
- In-app trip messages after a hail is accepted (text, timestamps, role — not phone numbers exchanged as a feature).
- Support threads with HALLT administrators (two-way with you, or moderated three-way between admin, driver, and passenger). Includes message text, timestamps, who can see each message, moderation status (for example pending until admin releases a reply to the other party), status notices, and related push/in-app alerts while a thread is open.
- Trip-share records when a passenger creates a safety follow link: share token, trip status, vehicle/plate identifiers shown on the link (not the driver’s display name or profile photo), pickup/drop-off labels, live taxi position updates while sharing is active, expiry/revoke flags. The passenger’s phone number is not put on the share link.
- Favourites and history you choose to store in the app.
- Reliability / safety signals: e.g. cancel-after-accept patterns (including provisional scores pending admin review of a delay report), blocks between users, identity or conduct reports (including intentional-delay / non-progress reports), and related admin confirm/reject outcomes.
- Accessibility and party notes you choose to provide for a hail (for example wheelchair-accessible vehicle request, assistance dog, passenger count). These are used for matching, capacity, and legal equality duties — not as a medical record or health-profiling product.
Drivers — additional data
- Licensing and vehicle documents and images (badge, licences, insurance, plates, vehicle details, capacity, accessibility flags, licensing authority), including where a face crop from a badge photo is used as a profile image.
- On-device text recognition (OCR) results used to check documents / plates against stored fields.
- Council / public register checks: where available, automated or assisted lookups against published hackney / taxi licensing registers (and related outcomes, timestamps, and messages) to support verification and ongoing compliance before or while For Hire.
- Driver Live Verification (DLV): live face capture and comparison against an enrolled face for the licensed driver account (including face-derived embeddings/templates, pass/fail outcomes, attempt history, and trusted-device binding). This is separate from optional phone biometrics (Face ID / fingerprint) used only to unlock the device — HALLT does not receive your OS fingerprint or Face ID template. Where the product design allows, we prefer storing compact embeddings and decision outcomes rather than long-term raw selfie files on our servers; short-lived capture data may be processed on the device and via our backend to complete a check. DLV is security / identity data only: it is not used to sell advertising profiles or for marketing targeting.
- Rank presence, vehicle permits, and related keys.
- District driver board: operational notices posted by drivers within a licensing district (message text, district, timestamps, author identifiers) and optional notification preferences (for example sound). HALLT administrators may monitor board content for safety and abuse prevention.
- Driver Assist (optional, off by default): preference flags; when a driver activates Driver Assist, activation location (map pin), active/cancel status, limited identity and vehicle card fields shared to nearby drivers and HALLT admin (for example name, plate, vehicle colour, profile photo where available), approximate distance metadata, related push notification records, and a short operational audit. Telephone numbers are not shared through Driver Assist. See section 6B.
- Platform fee / balance records and settlement of amounts owed to HALLT (not passenger journey fares).
- Drivers Loyalty Reward Scheme (DLRS) where operated: weekly metrics used to set a temporary platform fee percentage (for example For Hire / on-trip availability time with valid liveness signals; exclusive hail offer presentation and outcomes such as opened, accepted, rejected, timed out, completed, or cancelled; fee percentage and tier applied to completed jobs). Not used for passenger journey fares or customer promos.
HALLT may also operate test or simulation modes (for example simulated hails or internal store-testing configurations). Those create operational/test records and are not real passenger journeys or a substitute for lawful licensing.
4. Why we process data (purposes)
- Provide and secure the Application and accounts
- Facilitate and match electronic hails; show necessary info to the other party
- Driver verification, DLV, licensing support, council-register checks, and compliance
- Rank / district operations and For Hire availability
- District driver operational messaging and related notifications
- Pickup integrity (including meet confirmation and short meet / verification codes where used)
- Fraud, abuse, identity, and safety prevention
- Customer support and operational communications (including push notifications, admin inbox messages, and support threads — including moderated three-way conversations)
- Trip safety share: providing a temporary follow view to people the passenger chooses to invite
- Optional passenger trust verification and showing limited trust badges / completed-hail signals to drivers on offers and trips
- Optional Driver Assist: alerting a limited set of nearby HALLT drivers (and logging for HALLT admin) when a driver requests peer help
- Driver platform fee accounting and payment settlement
- Where operated, Drivers Loyalty Reward Scheme (DLRS): calculating weekly fee tiers and showing drivers their progress
- Legal compliance, tax, disputes, and enforcement of our Terms
- Improve reliability and product quality (including limited test/simulation tooling)
5. Lawful bases (UK GDPR)
We rely on one or more of:
- Contract — to provide the service you signed up for (account, hail, driver tools).
- Legitimate interests — security, fraud/abuse prevention, product integrity, limited service improvement (balanced against your rights).
- Legal obligation — where law requires retention or disclosure.
- Consent — where required for certain device permissions or optional features (you can withdraw permissions in device settings; core features may then stop working). Optional Driver Assist is enabled and activated by the driver; they can turn the preference off and cancel an active alert in the app.
Driver Live Verification (face-derived biometrics). Face images and face-derived embeddings used to verify who is using a licensed driver account are treated as high-sensitivity / biometric-related data under UK practice. We use them only for identity and security of driver accounts (not advertising).
- Art. 6 (personal data): typically performance of our contract with the driver and/or legitimate interests in platform integrity, fraud prevention, and passenger safety (balanced against driver rights).
- Art. 9 (special category / biometric for identification): where this applies, we rely on the driver’s explicit consent given by completing enrolment / live checks and accepting the in-app Terms (and this Policy), and/or such other Art. 9 condition as may lawfully apply after legal review. Completing DLV is a condition of using For Hire and receiving live hails; a driver who refuses, fails, or later withdraws DLV consent may keep an account for non-hire history where the product allows, but For Hire / live hail access can remain blocked until verification is restored.
- Access to DLV templates and outcomes is restricted (backend systems and limited HALLT administrators for support, safety, and abuse review). Drivers cannot self-write “verified” status outside the official enrolment / recheck flow.
Optional passenger ID / face likeness. Where photo-ID live selfies or profile-to-ID face scores are treated as special-category / biometric-related data under UK practice, we use them only for the optional passenger trust badges described above (not advertising). You choose whether to submit them. Declining does not block ordinary hailing. We rely on your consent when you submit those checks, and/or such other lawful basis as may apply. You can ask us to clear pending ID uploads via in-app support or info@hallt.co.uk; badge downgrade may follow.
Automated integrity decisions. Some availability and safety decisions are applied automatically or semi-automatically (for example DLV fail or lockout, document expiry turning For Hire off, reliability cool-downs after ignored offers, unpaid platform balance holds, or district licensing gates). Where the product provides a path, you may contact HALLT or use in-app support / admin review. These measures protect passengers, other drivers, and licensing integrity.
6. Who sees what
- Passengers may see limited driver/vehicle info needed to identify the correct taxi (e.g. display name, photo, plate, vehicle description).
- Drivers may see limited passenger info needed for the hail (e.g. name, approved profile photo, pickup, destination, party notes). Drivers may also see optional trust badges (for example account linked, ID checked, profile-face matched) and a successful-hails count where shown — not your phone number, not your ID document image, and not raw selfie files. Passenger phone numbers are not shared with drivers.
- HALLT administrators may review documents, trips, reports, support threads, and related records for onboarding, safety, fees, and support. In moderated three-way support, a party’s message may be visible only to admin until admin approves or edits a release for the other party.
- Trip-share invitees (anyone who opens a follow link the passenger created) may see the limited trip and vehicle information described in section 6A — without needing a HALLT account.
- Nearby drivers receiving Driver Assist may see the limited driver card and location information described in section 6B when another driver activates Driver Assist. HALLT administrators may also see Driver Assist activations for safety and abuse review.
6A. Trip share (safety follow links)
The HALLT app may let a passenger share an active trip by creating a temporary web link (for example on hallt.co.uk). The passenger chooses who to send the link to (for example via the device share sheet). The link is a capability: anyone who receives it can open the follow page until the trip ends, the passenger stops sharing, the link expires (typically within a few hours), or the account is closed. After stop, expiry, or closure the follow page no longer serves live trip data (a short end screen may still appear). Sharing can start once a driver is on the hail — the passenger may not yet be in the taxi.
Invitees may typically see:
- Trip status (for example taxi on the way, arrived, on trip, completed/cancelled)
- Vehicle description (for example colour / type) where available
- Vehicle registration and hackney plate identifiers (to verify the correct taxi)
- Pickup and drop-off labels and map pins (the stated journey places — not a live track of the passenger)
- Live or recent taxi map position (driver GPS) while the share is active — not the passenger’s live GPS pin
Invitees do not receive the passenger’s phone number through the share link, and do not see the driver’s display name or profile photo. The follow page is not a full passenger account. Passengers should only share with people they trust. Misuse of trip share (for example harassment or unlawful tracking) is prohibited under our Terms.
Lawful basis: for creating and maintaining a trip share we rely primarily on the passenger’s consent (they choose to create and send the link), together with our legitimate interests in offering a safety feature, with safeguards (temporary links, limited taxi fields, no passenger phone on the link, public read stopped when sharing ends). Taxi location, vehicle identifiers, and stated pickup / drop-off labels and pins appear on a share because they are necessary for the safety feature the passenger initiated for that hail.
6B. Driver Assist (driver-to-driver safety alert)
The HALLT app may offer an optional Driver Assist control for licensed drivers. Driver Assist is off by default. A driver must enable it in Preferences and then deliberately activate an alert (hold-to-send with confirmation) while on shift (For Hire, Unavailable mid-shift, or on an active HALLT trip). Driver Assist is not shown in local passenger UI when a driver is only using the hail-as-customer convenience mode.
When activated, HALLT may notify a limited number of other HALLT drivers (typically up to about fifteen) whose recent location presence is within approximately two miles of the activator’s pin. Selection is by distance and recent presence, not only the same licensing district — so near a district border, drivers from a neighbouring district may receive the alert if they are close enough and online.
Recipients may typically see:
- Driver display or legal name
- Vehicle registration / plate and vehicle colour where available
- Profile photo where available
- Map pin at the Driver Assist activation location
- Approximate distance from the recipient
Recipients do not receive the activator’s telephone number through Driver Assist. Driver Assist publishes a pin at activation time; it is not a continuous live tracking feed of the activator after the alert. The activator may cancel when safe. HALLT may also log an internal admin alert for operational and safety review.
HALLT does not guarantee that any driver will see, open, or respond. Driver Assist is not an emergency service and does not contact the emergency services on anyone’s behalf. In an emergency, call 999 (UK) immediately.
Lawful basis: we rely on the driver’s consent (enable Driver Assist and activate an alert) and/or our legitimate interests in offering a peer safety tool for drivers, with safeguards (opt-in, confirmation, limited fields, distance/cap fan-out, cancel, short retention, misuse may be restricted under our Terms).
7. Sharing and processors
We do not sell your personal data.
We use service providers who process data on our instructions, including:
- Google Firebase / Google Cloud (authentication, database, storage, cloud functions, hosting, crash/diagnostics where enabled) — typically europe-west2 and related Google infrastructure.
- Google Maps / location services for maps and geolocation features.
- Firebase Cloud Messaging / Apple Push Notification service for push notifications.
- Stripe — for driver platform fee settlement (card Checkout). Passenger journey fares are paid to the driver (cash/card machine etc.), not through HALLT as a private hire fare.
- On-device machine learning libraries (for example Google ML Kit for OCR / face detection bridges, and on-device face-embedding models used for DLV) so verification can run on your phone where designed. Face and document images for those checks are processed for HALLT’s verification purposes as described in this Policy. Google’s ML Kit terms also allow ML Kit to contact Google for things like bug fixes, model updates, and hardware compatibility, and to send performance and utilisation metrics about the ML Kit APIs in the app (not a substitute for HALLT’s privacy notice for your account data). See Google’s ML Kit terms and privacy materials for that metrics processing.
We may also share data with licensing authorities or law enforcement where required or permitted by law, and with professional advisers under confidentiality.
Data may be processed outside the UK by infrastructure providers subject to appropriate safeguards where required (for example standard contractual clauses or equivalent).
8. Location, camera, and other permissions
Location is central to hail, matching, driver district rules, ranks, and trip integrity. Drivers who go For Hire or take trips may need location (including background) so the service works when the app is not in the foreground. If you turn off necessary permissions, those features may be unavailable.
Camera and photos are used for profile images (including passenger photo review), driver licensing documents, plate/badge checks, and Driver Live Verification captures. Notifications deliver hail offers, trip updates, support-thread alerts, Driver Assist peer alerts, and operational alerts. Optional device biometrics only unlock the phone or app lock — they are not HALLT’s DLV face templates. Where the app uses on-device text-to-speech for accessibility or prompts, that synthesis is local to the device unless a feature later says otherwise.
On-screen driver details: while a passenger is shown identifying driver / vehicle details for an active hail, the app may use platform protections to discourage screenshots or screen recording (for example secure-window flags on Android, and on iOS detecting capture and briefly covering the screen). These measures help protect identity details from casual harvesting; they are not a guarantee against every capture method, and HALLT does not store the passenger’s screenshot images.
9. Retention
We keep data for as long as needed to provide the service and for legal, accounting, licensing-support, safety, and dispute purposes, then delete or anonymise where practicable. Indicative periods (ops may refine these; legal holds can extend retention):
- Active account profile / login: while the account is open, then removed or anonymised on closure subject to the carve-outs below.
- Unverified driver email sign-up: Firebase Auth users created for driver registration who never verify their email may be deleted automatically after about 24 hours; any temporary on-device signup details are discarded with that path.
- DLV embeddings / templates and outcomes: while the driver account is active for verification and For Hire integrity, then deleted or anonymised after account closure or ban within a limited operational window (unless needed for an active fraud / safety investigation).
- Optional customer ID / selfie / face-match fields: while a check is pending; after admin approve, the full government photo-ID page (passport or driving licence image) is kept for about 30 days for dispute and abuse checks, then deleted. The live ID-selfie used to approve the ID is kept while ID-checked / face-matched trust badges remain active (and is the face reference for the optional HALLT / top-tier face match against your passenger profile photo); it is deleted on badge revoke paths where designed and on account closure. Face-match scores and decision flags follow badge lifetime, then delete or anonymise where practicable with account closure rules.
- Hail / trip, fee ledger, identity/conduct reports, and journey evidence: longer retention where needed for disputes, tax/accounting, safety patterns, and licensing-support evidence.
- Live location trails during a trip: for trip integrity and dispute review for that journey — not kept as a permanent public tracking feed.
- Driver approach samples: discarded when the trip starts or the hail ends without a qualifying delay cancel; if retained with an intentional-delay report, kept with hail / conduct / dispute records for admin review (same integrity window as other journey evidence — not a permanent public tracking feed).
- Trip-share records: while the share is active (trip ongoing or short TTL), then deactivated on complete/cancel/revoke/expiry or account closure; residual records only as needed for security, abuse prevention, and short operational audit — not indefinite public tracking.
- Driver licensing document images (badge, vehicle licence, insurance): while the driver account is active for verification and compliance, and may be retained after standard account closure for licensing-support and disputes. Separate hard-purge tools (pre-launch / test) may delete those files. Profile photos and passenger ID / selfie uploads are removed on standard closure (selfie also on ID-badge revoke).
- Driver Assist records: while the alert is active; after cancel or resolution, residual records only as needed for short operational/admin audit, security, and abuse prevention — not continuous public tracking of the driver.
- Phone registry: after a Customer account deletion, a binding for the mobile number previously used may be retained so the same number cannot simply create a fresh HALLT account (reopen / unlock is controlled by HALLT and may be refused after ban or abuse). Driver email logins are not reopened with a mobile number.
- Support thread messages: for as long as needed to resolve the matter and for safety/dispute follow-up, aligned with general support and trip retention.
- Stripe payment metadata (drivers): as required for accounting and as retained by Stripe under their terms.
Account closure (in-app “Delete account”): we close your login and remove or anonymise the live profile (name, photos, contact fields), passenger ID / selfie uploads, DLV face templates, push tokens, and live For Hire / GPS / trip-share / session state. Driver licensing document images (badge, licence, insurance) are not wiped on standard deletion — they may be kept for licensing-support and disputes. We may also retain trip, fee, report, and related operational records linked to your internal user id (with the profile anonymised) for legal, tax, fraud, and safety reasons. If you used a Customer mobile login, we may retain a phone-registry binding for that number so it cannot simply open a new account. Driver email logins are not reopened with a mobile number. Outstanding driver platform balances must usually be cleared before self-serve deletion.
Separate hard purge tools may be used by HALLT for pre-launch / test cleanup; those are not the default consumer deletion path.
10. Your rights
Under UK data protection law you may have rights to:
- Access your personal data
- Rectification of inaccurate data
- Erasure (subject to lawful exceptions, including retention needs above)
- Restriction of processing
- Data portability (where applicable)
- Object to certain processing based on legitimate interests
- Withdraw consent where processing is consent-based
Contact info@hallt.co.uk. We may need to verify your identity before acting on a request.
11. Children
HALLT accounts are for users aged 18+ (or older if your jurisdiction requires). We do not knowingly offer accounts to children. At terms acceptance we ask you to self-confirm that you are 18 or over (a soft declaration stored with your acceptance). This is not an identity-document age check.
12. Security
We use technical and organisational measures appropriate to the risk (access controls, encrypted transport, least-privilege admin tools, verification for drivers). No system is perfectly secure; please protect your device and login.
13. International users
HALLT is designed for use in the United Kingdom under UK taxi / Hackney rules in supported licensing areas. If you access the service from elsewhere, UK law and this Policy still describe how we handle data for the service we operate.
14. Changes
We may update this Policy as the product evolves. The “Last updated” date will change. Material changes to the in-app Terms may require re-acceptance in the Application.
15. Contact
HALLT Ltd
Company number: 17349811
Registered office: Suite A, 82 James Carter Road, Mildenhall, IP28 7DE
Email: info@hallt.co.uk
Web: https://www.hallt.co.uk