Store Stash Driver — Privacy Policy
Last updated: 12 August 2026
This policy is published at /legal/driver-privacy on the Store Stash web app (public, unauthenticated route in apps/web). Both stores require a working, publicly reachable privacy-policy link on the listing and in App/Play Console — use that hosted URL.
Who we are
Store Stash provides a workforce platform for licensed moving, storage, and transportation companies. The Store Stash Driver app is used by drivers and crew of a company that subscribes to Store Stash. Your employing/affiliated company is the controller of your driver and job data; Store Stash operates the platform and processes data on that company's behalf.
Information we collect
We collect only what the app needs to do its job:
- Account & identity — your name (legal and preferred), email address, phone number, profile photo, driver status, and company affiliation.
- Driver compliance documents — photos of your driver's license (a government-issued ID), your vehicle registration, and your insurance certificate, uploaded during onboarding. These are sensitive documents. They are used only to verify your identity and driver eligibility so your moving company can review and approve you to work, and access to them is restricted to you, your company, and platform administrators.
- Precise location — collected only while you are signed in, on duty, and on an active trip, and only while the app is in use (foreground). It is used to share live ETA and trip progress with your dispatching company. The app does not collect location in the background and does not track you when you are off duty or the app is closed.
- Photos you capture — pickup, delivery, and exception photos taken to advance a shipment, plus an optional profile photo you choose from your library.
- Vehicle information — truck type, capacity, and optionally plate and VIN, used for job matching and verification.
- Messages — messages you exchange with your dispatch office inside the app.
- Device & notifications — a push notification token (via Expo) so we can deliver job and message alerts.
- Limited diagnostics — basic technical logs needed to keep the service running and secure.
We do not collect contacts, browsing history, or advertising identifiers, and we do not use the microphone.
How we use information
To authenticate you; assign and manage jobs; share live ETA with your dispatch office; attach proof-of-service photos; enable driver↔office messaging; send operational notifications; verify your identity, vehicles, and driver eligibility (including review of your compliance documents by your company); and secure and support the service. We do not use your data for advertising.
Legal bases
Where a legal basis for processing is required, we rely on: performance of a contract — processing your account, documents, jobs, photos, messages, and trip data is necessary to provide the driver platform you and your company use; legitimate interests — operating, securing, and supporting the service (e.g. diagnostics, audit logs, fraud prevention); and consent — foreground location sharing, which you accept in the driver terms and can withdraw at any time by going off duty or disabling the location permission in your device settings.
How information is shared
- Your dispatching/affiliated company — the company you drive for can see your driver profile, compliance documents, job activity, live trip location while on an active trip, photos, and messages.
- Service providers (sub-processors) acting on our instructions: cloud hosting and file storage (Amazon Web Services), database hosting (Neon — Postgres), authentication (Clerk), push-notification delivery (Expo), maps and ETA (Google Maps Platform), and transactional email (SendGrid/Twilio). These providers are US companies; file storage is hosted in the AWS
eu-north-1(Stockholm) region and other data in US regions, and may be transferred between them to operate the service. Payment processors (Stripe/Square) handle the company's subscription billing only and never receive driver data; our AI lead-generation tooling (OpenAI) never receives driver data. - Legal — where required by law or to protect rights and safety.
We do not sell your personal information, and we do not share it with third parties for their own advertising or cross-app tracking.
Data retention
We keep your information while your account is active and as needed to provide the service and meet legal, tax, and record-keeping obligations. When you delete your account (or a deletion request is completed on your behalf), your account is deactivated immediately and your personal data and uploaded documents are deleted or anonymized under our internal deletion procedure, except for minimal records we are required to retain (e.g. audit and financial records), which are kept only as long as the law requires.
Your choices and account deletion
You can delete your account from inside the app: open Profile → Delete account and confirm. This immediately deactivates your account and sign-in, notifies your company, and queues your personal data and documents for removal under our retention policy. If you no longer have the app installed, you can request deletion at the public web page /legal/delete-account on the Store Stash web app, or by emailing support@storestashapp.com. Deletion cannot be completed while you are mid-trip — finish or hand off an active trip first. You can turn off location and photo permissions at any time in your device settings (some features will stop working without them).
Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a portable copy of your personal information. You can exercise deletion directly in the app (above); for any other request, contact support@storestashapp.com and we will respond within the time required by applicable law. Because your employing company is the controller of your driver and job data, we may route or coordinate your request with that company. We do not discriminate against you for exercising these rights.
Security
Data is encrypted in transit (HTTPS/TLS) and encrypted at rest by our hosting providers (Neon for the database, AWS S3 for files). Certain high-sensitivity fields (such as storage-unit access codes and integration credentials) are additionally encrypted at the application level with AES-256-GCM. Tenant data is isolated per company using database row-level security, and access is restricted to authorized personnel and processors. If a security breach affects your personal information, we will notify affected companies and users, and regulators where applicable, as required by law.
Children
This is a workforce application intended for adult employees and contractors. It is not directed to children and we do not knowingly collect data from children.
Changes
We may update this policy; material changes will be reflected by the effective date above and, where appropriate, in-app or by email.
Contact
Questions or requests: support@storestashapp.com.