LuxDispatch
Privacy Policy
Effective May 8, 2026
Overview
LuxDispatch is dispatch-management software for licensed chauffeured ground transport operators. Each operator runs a separate tenant. Operator data is isolated via database row-level security plus token-scoped, server-side access controls, and is never shared with another operator or any third party except the subprocessors listed below.
What we collect
Operator accounts: Name, email address, phone number, organization name, role within the organization. Used for authentication, team management, and transactional communications.
Client records: Names, phone numbers, email addresses, addresses, and booking preferences as entered by the operator. LuxDispatch does not independently collect client data. All client records are created and owned by the operator.
Booking data: Pickup/dropoff locations, times, vehicle types, driver assignments, special instructions, pricing, and invoice records. This is the operator’s business data.
Usage data: Error logs, page views, and performance metrics collected via Sentry for debugging and reliability. No personally identifiable information is sent to Sentry beyond what appears in error stack traces. Sentry Session Replay is enabled to help reproduce errors — roughly 10% of sessions plus 100% of sessions that hit an error — with all text and form inputs masked, and replay disabled entirely on passenger/affiliate token pages.
Payment data: LuxDispatch does not process or store payment card numbers — no card is charged through the app today. A client’s billing method is a note for the operator’s own off-platform billing; any card handling happens outside LuxDispatch.
Subprocessors
LuxDispatch uses the following third-party services to operate the platform:
- SupabaseDatabase hosting, authentication, file storage · US (AWS us-east-1)
- TwilioSMS dispatch notifications to drivers · US
- ResendTransactional email (confirmations, invoices, team invites) · US
- SentryError monitoring and performance tracking · US
- Anthropic (Claude)AI booking parsing (text-only, no PII stored by Anthropic) · US
- VercelApplication hosting and deployment · US (AWS)
Data retention
Operator data is retained for the duration of the subscription. The organization owner can delete the tenant at any time from Settings by typing the organization code to confirm — an authenticated, owner-only action. We do not accept deletion requests by email, because we cannot verify the requester without the signed-in session. Deletion is a soft delete with a 30-day recovery window, after which the data is permanently removed.
Specific windows: soft-deleted rows are retained for 30 days; authentication logs for 90 days; audit-trail rows for 2 years. Point-in-time database backups are retained for 7 days, after which deleted rows can no longer be restored.
GDPR rights
If you are located in the European Economic Area, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Export your data in a machine-readable format
- Object to or restrict processing of your data
To exercise any of these rights, contact hello@luxdispatch.app. We will respond within 30 days.
Passengers and clients whose records appear in an operator’s system should contact that operator directly. LuxDispatch has no direct relationship with passengers and cannot modify or delete their records without the operator’s consent.
AI data handling
LuxDispatch uses AI (Anthropic Claude) to parse incoming booking text into structured fields. The AI receives the raw booking message text, which may contain passenger or booker names and contact details, in order to parse the booking. We do not send full client/CRM databases to the AI provider, and per Anthropic’s commercial API terms it does not train on or retain this content. AI suggestions are never auto-applied — the dispatcher reviews and confirms every parsed booking.
Security
All data is encrypted in transit (TLS 1.3) and at rest (AES-256 via Supabase/AWS). Authentication is handled via Supabase Auth with optional multi-factor authentication. Tenant data is isolated through database row-level security plus token-scoped, server-side access controls. Every data mutation is audit-logged with timestamp, actor, and before/after values.
Changes to this policy
Material changes are communicated by email to the operator primary contact at least 30 days before they take effect. A dated change log is maintained in the product repository.
Contact
For privacy inquiries, data requests, or concerns: hello@luxdispatch.app