Chapara

Privacy Policy

Last updated: 25 July 2026

This Privacy Policy explains how Chapara collects, uses and protects personal data when you use our in-vehicle advertising platform. It covers people who hold a Chapara account, and also members of the public who scan one of our QR codes.

Who we are

Chapara Ltd is the data controller for the personal data described in this policy, for the purposes of the UK GDPR and the Data Protection Act 2018. We operate from Bristol, United Kingdom.

  • Controller: Chapara Ltd
  • Registered in England & Wales, company no.: 17361660
  • Registered office: 15 Milsom Street, Easton, Bristol, BS5 0SS
  • Contact: [email protected]

We have not appointed a Data Protection Officer, as we are not required to. Privacy questions go to the address above.

Whose data we handle

  • Drivers — vehicle owners who display adverts through the Chapara network.
  • Advertisers — the business contacts who book and manage campaigns.
  • Administrators — Chapara staff who operate the platform.
  • People who scan a QR code — passengers and members of the public. You do not need an account, and we do not identify you. See QR code scanning below.
  • People who contact us — anyone who uses our contact form or support messaging, with or without an account.

What we collect

Account data (everyone with a login)

  • Name and email address.
  • Your password, stored only as a salted scrypt hash — we never hold the password itself and cannot recover it.
  • Your role, account status, and whether your email address has been verified.
  • Session records. The cookie in your browser holds a random token; our servers store only a hash of it.
  • If you sign in with Google: your Google account identifier, email address and name, as supplied by Google. We only accept Google accounts with a verified email address. We do not receive your Google password and do not access anything else in your Google account.

Driver data

  • Contact details and your service area.
  • Vehicle details — make, model, colour and registration plate.
  • A photo of your vehicle's number plate, which you upload so we can confirm the vehicle exists and matches your registration. This is the only document we ask you for. We do not collect or store your driving licence, private hire licence, insurance certificate or any identity document.
  • Weekly verification submissions — the photos you upload showing the advert in place, a screenshot from your driving platform, and the number of trips you recorded that week.
  • Records of payments we have made to you.
  • Where an advert is assigned to your vehicle, the assignment record linking the two, and which equipment is installed.

Your trip count is used only for our own internal reporting. It is never shown to advertisers, and it is never used to calculate what you are paid.

Advertiser data

  • Business name and the contact details of the person managing the account.
  • Campaign details and your design brief — business description, headline, slogan, website, phone number, offer codes and any notes you give us.
  • Logos, reference artwork and other brand assets you upload.
  • The advert designs our team produces for you, and which option you approve.
  • Payment records, invoices and campaign reports.

QR code scanning

When someone scans a Chapara QR code in a vehicle, we record the scan before sending them on to the advertiser's website. We record:

  • A one-way hash of the IP address, salted with a secret only we hold. The IP address itself is never written down, and the hash cannot be turned back into it. We use it only to tell a repeat scan from a new one within a 24-hour window.
  • The browser's user-agent string, and the device type, operating system and browser we read from it.
  • The page that referred the scan, if any.
  • An approximate city and country, supplied by our network provider Cloudflare from the connection. This is city-level at best and is often unavailable.
  • The time of the scan and which campaign code was scanned.

We do notset any cookie on your device when you scan, do not track you across other websites, do not build a profile of you, and cannot identify you. Once you reach the advertiser's website, that website's own privacy policy applies to what happens next — we have no control over it.

Advertisers are shown counts only. They never see an individual scan, a hash, a location or a device.

Contact and support

If you use our contact form or open a support ticket, we hold your name, email address and whatever you write to us, together with our replies. Guests who contact us without an account are held only by the name and email they give.

Device notifications

If you turn on notifications for a device, your browser gives us a subscription address for that device, which we store against your account. Notifications we send carry no content — the device is simply woken up and then fetches the message from us over your signed-in session, so nothing about you passes through the notification services run by Apple, Google or Mozilla. You can turn this off per device at any time from your account settings.

Operational records

  • Audit logs of administrative actions — who changed what, and when.
  • Email delivery records — which emails were sent to which address, and whether they were delivered.
  • Server and security logs, used to run the service and detect abuse. Authentication tokens and access codes are stripped out before anything is written to a log.
  • Error reports when something breaks, so we can fix it. These are filtered to remove personal data before they leave our servers.

Payment data

We hold payment records, amounts and status. Card payments are taken by Stripe on their own systems — card numbers never reach Chapara and we do not store them.

Why we use it, and our lawful basis

  • To run the service you signed up for — accounts, campaigns, vehicle assignments, verification, reporting and payments. Basis: contract.
  • To measure campaign engagement through QR scans, so advertisers can see whether a campaign worked. Basis: legitimate interests— ours and the advertiser's in measuring the campaign. We have weighed this against the privacy of people who scan, which is why the IP address is hashed rather than kept, no cookie is set, and no profile is built.
  • To keep the platform secure and prevent abuse — rate limiting, audit logging, error monitoring. Basis: legitimate interests.
  • To answer your messages and provide support. Basis: contract, or legitimate interests if you do not have an account.
  • To keep records the law requires us to keep, such as financial records. Basis: legal obligation.
  • To send device notifications. Basis: consent, given through your browser's permission prompt and withdrawable at any time.

You can turn individual email notifications on or off in your account settings. Some emails — confirming your email address, resetting your password, or telling you about a decision on your account — are part of the service and cannot be switched off while your account is open.

Keeping drivers and advertisers apart

This is a rule the platform enforces in code, not just in policy:

  • Advertisers never receive drivers' personal data or documents. A request from an advertiser for anything belonging to a driver is refused outright.
  • Advertiser reports are built from summaries our administrators prepare and publish. Raw driver records and verification submissions are never passed through into an advertiser's view.
  • A driver is told the name of a campaign assigned to their vehicle, and nothing about the advertiser's commercial terms.

Who we share it with

We do not sell personal data and we do not share it for anyone else's marketing. We use the following providers to run the service, each under a contract that limits them to acting on our instructions:

  • Hetzner — server hosting and database (Germany, EU).
  • Cloudflare — domain, network protection and private file storage (UK/EU, with a global network).
  • Stripe — card payment processing (Ireland and USA).
  • Resend — sending our emails (USA).
  • Sentry — error monitoring (USA).
  • Google — only if you choose to sign in with Google (USA).
  • Apple, Google and Mozilla push services — only if you turn on device notifications, and only to wake your device; they carry no content.

We will also disclose data where the law requires it, or to establish or defend a legal claim.

Sending data outside the UK

Our servers and file storage are in the UK and the European Economic Area. Some of the providers listed above are based in the United States. Where personal data is transferred there, we rely on the UK's adequacy regulations for the EU–US Data Privacy Framework where the provider is certified under it, and otherwise on the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, together with the provider's own technical safeguards.

How long we keep it

  • Account data — while your account is open, then 12 months after it closes.
  • Financial records — payments, invoices and the records behind them: 6 years, as UK tax and company law requires.
  • Driver plate photos and verification submissions — for as long as you participate, then 12 months.
  • Campaign briefs, artwork and reports — for the campaign, then 24 months.
  • QR scan records — 24 months, after which only the totals remain.
  • Audit logs — 6 years, since they evidence the financial and operational record.
  • Support tickets and contact messages — 3 years from the last message.
  • Sessions and email delivery records — short-lived; sessions expire automatically.

We may keep something longer where we need it for an ongoing legal claim, or where the law requires it.

Your rights

Under UK GDPR you have the right to:

  • ask what personal data we hold about you, and get a copy;
  • have inaccurate data corrected;
  • ask us to delete your data;
  • ask us to restrict how we use it;
  • object to processing based on legitimate interests, including our QR scan measurement;
  • receive data you gave us in a portable format;
  • withdraw consent at any time, where we relied on consent.

If you have an account, you can request a copy of your data or ask us to delete your account directly from your account settings, and we will respond within one month. Otherwise, or if you scanned a QR code and want to object, use the contact page. Note that because QR scan records contain no identifier for you, we may not be able to locate a specific scan — but you are welcome to raise it with us.

If you are unhappy with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office (ico.org.uk, 0303 123 1113).

Automated decision-making

We do not make decisions about you by automated means alone, and we do not profile you. Driver applications, document reviews, weekly verification and campaign approvals are all decided by a person, and where we reject something we tell you why.

Children

Chapara is for businesses and licensed drivers. It is not intended for anyone under 18, and we do not knowingly collect data about children.

How we protect it

  • Everything travels over an encrypted connection.
  • Passwords are salted and hashed; session tokens are stored only as hashes.
  • Uploaded files are stored privately and are never publicly reachable. They are served only through short-lived links generated after we have checked who you are and whether you are allowed to see that file.
  • Every protected action is authorised on our servers and scoped to what you own — not just to your role.
  • Administrative actions are recorded in an audit log.
  • Sensitive routes are rate limited; tokens are stripped from logs.

No system is perfectly secure, but we take these measures seriously. If a breach affects your rights, we will notify you and the ICO as the law requires.

Changes to this policy

We may update this policy. The date at the top shows when it last changed, and we will tell account holders about significant changes before they take effect.

Contact

For privacy questions or to exercise your rights, email [email protected] or use our contact page. See also our Cookie Policy and Terms.