Fin Delivery
How we handle courier personal data — and what we do not collect.
Suomi · English · Customer app notice
This notice explains what we collect about you as a courier, why, and for how long we keep it. Location data has its own section because it is the most sensitive part — read section 4 at minimum.
In short
We collect your location only while you are on shift and have granted permission. Outside a shift we do not collect your location at all — not less often, not less precisely, but not at all. When you end a shift, collection stops in the same action, not at the next measurement interval.
Fin Delivery Oy
Business ID 3584658-3
Nöykkiönlaaksontie 42, 02330 Espoo, Finland
Privacy matters: info@fin-delivery.com
We have not appointed a Data Protection Officer. If we appoint one, we will update this section.
This notice applies to the courier app and to working as a courier. If you order food as a customer, the customer app privacy notice applies instead — they are separate records and we do not combine them.
It does not cover what merchants or the payment provider do with data as controllers in their own right.
| Category | Examples | Why |
|---|---|---|
| Basic details | Name, phone number, email, vehicle type | Creating your account, contacting you, dispatching work |
| Shift data | Shift start and end, accepted and declined offers, delivery status | Running operations, calculating pay, resolving disputes |
| Location data | Device location during a shift | See section 4 — handled separately |
| Payout data | Completed deliveries, distance travelled, payment transactions | Paying you and meeting statutory accounting obligations |
| Device data | Device model, OS version, app version, push token | Diagnosing faults, delivering notifications |
| Support contacts | Support messages and their content | Providing support and monitoring its quality |
We do not collect special categories of personal data (health, beliefs, trade union membership or similar) and we do not ask for them.
Your location is processed only when both conditions are true at the same time:
When you end a shift, location collection stops immediately as part of that same action. It does not quietly continue in the background, at a reduced rate, or at coarser precision.
While you are on shift, the app collects location also when the app is not on screen or the phone is locked. This is necessary because you are riding or driving and are not looking at your phone, yet the customer still needs to see the delivery progressing.
We ask for this permission separately and show you an explanation beforehand that you must accept. You may decline — you can still use the app, but you cannot go on shift.
You can withdraw location permission at any time in your device settings.
The legal basis for this limit
The EU Platform Work Directive (EU) 2024/2831, Article 7 prohibits a platform from processing data on a person's private conversations and behaviour while they are not performing or offering to perform platform work. The prohibition is absolute — a courier's consent does not make it lawful. The deadline for national transposition is 2 December 2026. We have built the system to this standard now rather than fixing it as the deadline approaches.
Individual location points are kept for 90 days and then deleted. After that, only an aggregated distance remains on the payout record, not the route as points.
This period is longer than on the customer side because a dispute over pay or a suspicion of fraud typically surfaces after the delivery, not during it.
| Processing | Legal basis (GDPR) |
|---|---|
| Maintaining your account, dispatching work, paying you | 6(1)(b) — performance of a contract |
| Processing location during a shift | 6(1)(b) — necessary to provide the service |
| Accounting and tax records | 6(1)(c) — legal obligation |
| Fraud prevention and platform safety | 6(1)(f) — legitimate interest |
| Optional messages and marketing | 6(1)(a) — consent, which you may withdraw |
The device location permission is a different thing from the legal basis above: the permission is the technical precondition for the operating system to let the app read location, and you can withdraw it at any time.
We do not sell your personal data. We do not share it with advertising networks.
Your location and shift data are held inside the EU, in Amazon Web Services' Stockholm region (eu-north-1). No transfer outside the EU takes place for this data.
The push token and technical data needed to deliver a notification are processed by Expo and, depending on your device, Apple or Google. Where this involves a transfer outside the European Economic Area, the transfer relies on a European Commission adequacy decision or the Commission's Standard Contractual Clauses.
Stripe, through which your fees are paid, is a US company. For it, any transfer relies either on a European Commission adequacy decision (EU–US Data Privacy Framework) or on the Commission's Standard Contractual Clauses.
| Data | Retention |
|---|---|
| Location points | 90 days, then deleted |
| Aggregated distance on the payout record | Per accounting retention |
| Shift and delivery history | For the duration of the courier relationship and afterwards for the period accounting law requires |
| Accounting records and vouchers | Under the Finnish Accounting Act (1336/1997): vouchers 6 years, accounting books and financial statements 10 years |
| Support messages | 2 years |
| Basic details and account | For the duration of the courier relationship, see section 10 |
We cannot delete data that accounting law requires us to keep before that period expires. Such records are pseudonymised when your account is deleted.
Offers are dispatched by systematic rules that take into account, among other things, distance to the pickup point, vehicle type, and whether you are already on a delivery.
The Platform Work Directive (EU) 2024/2831 gives you the right to know on what grounds automated systems affect your work, and the right to human review of significant decisions. If and when we introduce automated decisions that affect your pay, the volume of work offered to you, or your access to your account, we will explain the grounds and provide a route to human review.
We do not profile you on the basis of your private life.
You can request deletion of your account and associated personal data by email to info@fin-delivery.com. New accounts are not created in the courier app; Fin Delivery or its contracting partner provides login credentials after approved onboarding.
Once requested, the account is locked immediately and you can no longer accept work. Personal data — profile, contact details, location history, push tokens — is deleted after 30 days. You can cancel the request within that period.
After deletion, what remains is only the vouchers and payment transactions that accounting law requires, with identifying details replaced by a pseudonym.
We cannot process a deletion request while you have a delivery in progress or an unresolved payment dispute. We will tell you clearly if that is the case.
We respond to requests within one month. If a request is unusually broad, we will tell you about the extension.
Connections between the app and our servers are encrypted. Access to location data is limited to people who need it for their work, and access is logged. We do not store passwords in plain text.
If a data breach occurs that is likely to result in a high risk to your rights, we will notify you and the supervisory authority within the time the law requires.
If we change this notice materially — in particular what happens to location data — we will tell you in the app before the change takes effect. Previous versions are available on request.
Fin Delivery Oy · Business ID 3584658-3
Nöykkiönlaaksontie 42, 02330 Espoo, Finland
info@fin-delivery.com