Spindl Delivery
Privacy Policy
Effective date: 5 August 2026
This policy describes how Spindl (Spindl OÜ, Estonia — "we", "us") processes personal data of couriers who use the Spindl Delivery app ("the App").
Data we collect
- Account data — name, email address, phone number, vehicle type, and a hashed password, provided by you at registration.
- Verification (KYC) data — when you apply to be verified as a courier: your business name, business registry code, payout bank account number (IBAN), and a photo of your government-issued identity document. We use these solely to verify that you can work and invoice as a courier and to know where to send your delivery earnings.
- Location data — two separate things.
Your coverage spot: the place you pin on the map to say where you want to work. To centre that map, the App reads your device location once, with your permission, when you use the locate-me control.
Your position while you are working: while you are online with the App open, and continuously from the moment you accept a delivery until you mark it delivered (including while your screen is off, with a Spindl notification visible the whole time), the App sends your position to us. We use it only to work out how far you actually are from a restaurant, so that the price and delivery time you offer, and the arrival time shown to the customer, reflect where you are rather than where you pinned your coverage spot. It never runs while you are offline. We keep only your most recent position: each new one replaces the last, and it is erased when you go offline or delete your account.
This is required to send offers. Your coverage spot is something you choose, so pricing from it would let couriers move a pin to charge more for the same journey. Measuring from your real position is what keeps the price the same for everyone doing the same work — so if we have no current position for you, you can still receive requests but cannot offer on them until we do. You can withdraw at any time by turning off location for the App or deleting your account; you will simply not be able to send offers.
Matching with delivery requests uses only your chosen coverage spot.
- Delivery activity — offers you make, deliveries you complete, delivery fees earned, and your online session history.
- Device data — a push notification token, if you enable notifications.
How we use it
- To dispatch delivery requests to couriers within their chosen coverage area.
- To show your first name, vehicle type, price, and estimated delivery time to customers choosing a courier.
- To share your name and phone number with the customer and the restaurant for an accepted delivery, so they can contact you about that delivery.
- To display your earnings and activity history to you.
- To measure how far you are from a restaurant, so your offer price and delivery time are based on where you are, and to keep the customer's arrival estimate current during a delivery. Your coordinates are not passed on to the restaurant or the customer — only a distance and a number of minutes derived from them.
We do not sell personal data and we do not use it for advertising.
Legal basis
Processing is based on the performance of our agreement with you (providing the courier marketplace) under GDPR Article 6(1)(b), and on our legitimate interest in keeping the service safe and reliable under Article 6(1)(f).
Your position while working is processed under Article 6(1)(b): the price and delivery time you commit to are the substance of that agreement, and they cannot be calculated fairly from a location you set yourself. We do not ask for your consent to it, because consent obtained as a condition of working would not be freely given — we tell you plainly instead that it is part of how the service works, and you remain free not to use the service.
Sharing and processors
Delivery-related data is shared with the restaurant's point-of-sale system and the ordering customer, limited to what they need to receive their delivery.
The following providers process data on our behalf, under data-processing agreements:
- Amazon Web Services (EU, eu-north-1) — server hosting and storage, including your verification data and ID document photo.
- Resend (email delivery) — when you submit verification, your submission (including the ID document photo and IBAN) is emailed to our operations inbox for review.
- Expo and Google Firebase Cloud Messaging — delivery of push notifications to your device, if you enable them.
- Vercel — hosting of the App's web version.
Retention and deletion
Account data is kept while your account is active. You can delete your account at any time in the App under Account → Delete account, or request deletion via our account deletion page. Deletion removes your personal data (name, email, phone, verification data including the ID document photo and IBAN, your coverage spot, your last known position, sessions, push token) immediately; completed delivery records are retained in anonymized form for bookkeeping. The emailed copy of your verification submission is deleted from our operations inbox as part of processing your account deletion.
Your rights
Under the GDPR you may request access, correction, export, or erasure of your data, and you may lodge a complaint with the Estonian Data Protection Inspectorate (AKI). Contact us at support@spindl.app.
Changes
We will post any changes to this policy on this page and update the effective date above.