Who is responsible?
East London Man With A Van is responsible for the information collected through this website. Contact us at hello@eastlondonmanwithavan.com or 07807 933846 for questions about your data.
What we collect and why
When you request a move, we collect your name, contact details, collection and delivery addresses, preferred timing, inventory and access notes. We use these to prepare an estimate, check availability, contact you and perform the agreed service. This processing is necessary to take steps at your request before a contract and to fulfil a confirmed booking.
The job diary also holds the estimate, booking status, assigned crew, internal operational notes and payment status. We don’t collect card details or process online payments. Please avoid including sensitive information or identification documents in your booking notes.
Who can access the information?
Authorised business administrators can access the job diary. Drivers and crew receive the details necessary for their assigned work. Our website and database providers process information on our behalf: Vercel hosts the website and Supabase stores the booking database. Resend sends booking alerts to the business administrators; these contain a booking reference and a link to the private job diary.
UK postcode lookups use Postcodes.io. Route calculations send coordinates derived from those postcodes to the configured road-routing provider. These services do not receive your name, contact details or full street address from our route calculation. We use them to estimate mileage.
If you use “Find postcode”, the address search text is sent to Photon (Komoot), which uses OpenStreetMap data. Only enter the building, street and town; names, phone numbers and booking notes are not needed. You can enter a postcode manually instead.
If you choose WhatsApp or email, your message is handled by that provider under its own privacy terms. These are optional contact methods. Some providers may process data outside the UK; applicable contractual safeguards and provider arrangements should govern those transfers.
Security and essential cookies
Administrator access uses an essential, secure, HTTP-only sign-in cookie that expires after 30 days. The public website does not set advertising cookies or include marketing analytics. We process limited technical request information to protect the forms from abuse; rate-limit identifiers are hashed and expire within the relevant short protection window. Hosting providers may retain security logs under their policies.
Cloudflare Turnstile protects booking submissions and administrator sign-in against bots. Cloudflare processes technical information, including IP address and browser signals, for this security check. We do not send your booking details or password to Turnstile. See Cloudflare’s privacy policy.
How long information is needed
We retain booking information while it is needed to manage your request, deliver the service, resolve questions and meet applicable accounting or legal obligations. Unnecessary enquiry and operational details should be removed when they are no longer needed. Contact us to request deletion or ask about the retention of your particular booking.
Your choices and rights
You can ask to access or correct your information, and request erasure, restriction or portability where those rights apply. You may also object to processing based on legitimate interests. We may need to verify your identity before responding. If a legal obligation requires us to keep a record, we’ll explain that.
Raise privacy concerns with us first so we can help. You can also complain to the UK Information Commissioner’s Office at ico.org.uk.
Notice updated: 20 September 2026.