Heatherstone Logistics

Legal

Privacy policy

We collect the data we need to deliver shipments and run an account, and not much else. This policy describes what we hold, why, and how to ask for a copy or have it deleted.

Last updated · 2026-02-08

  1. 01What we collect

    For booking and delivery: your name, business name, email, phone, collection and drop-off addresses, parcel description, and any handling notes you provide. For recipients: name, address, and phone or email if you supply them so we can send a tracking link.

    For account customers: invoicing details, named contacts on your side, and the named driver(s) assigned to your account.

  2. 02Why we collect it

    To carry out the contract of carriage you booked with us, to keep you informed about the shipment, to invoice you, and to maintain the audit trail required by HMRC, MHRA (where cold-chain), and our insurers.

  3. 03Who sees it

    Your data is seen by the driver assigned to the shipment, the dispatcher in the originating depot, and your named account manager (if you have one). Recipient details are shared only with the driver carrying out the delivery and used to send the live tracking link.

    We do not sell or trade personal data with anyone, ever. We do not use behavioural advertising trackers or third-party analytics that share data outside Heatherstone.

  4. 04Cookies

    The marketing site uses one first-party cookie to remember your acceptance of this notice. The customer dashboard uses first-party cookies to keep you signed in. We do not use third-party advertising cookies or session-replay tools.

  5. 05How long we keep it

    Active account: held for the lifetime of the account. Closed account: held for six years for tax and audit purposes, then deleted. Cold-chain audit data: held for ten years per MHRA guidance.

    Marketing-only contact data (someone who asked for a quote but didn't book): deleted automatically after twelve months of no further contact.

  6. 06Your rights

    You can ask us at any time for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it (subject to the retention obligations above). Email privacy@heatherstone.example and we will respond within thirty days.

  7. 07Where data is stored

    All operational data is hosted in the UK on UK-region servers. Backups are encrypted at rest and stored in a second UK region. No customer or recipient personal data leaves the UK.

  8. 08Complaints

    If you believe we have mishandled your data, contact us first at privacy@heatherstone.example. You also have the right to complain to the Information Commissioner's Office (ico.org.uk).

Questions about this policy? Get in touch with our compliance team.