Legal
Privacy Policy
Last updated: 25 August 2026
1. Who we are
Lasta ("we", "us", "our") operates a same-day parcel delivery platform connecting customers with independent couriers in Ireland. Our registered office is in Dublin, Ireland. We are the data controller for all personal data collected through our website and mobile applications.
For any privacy-related questions, contact us at: [email protected]
2. What data we collect
Customer app users
- Name, email address, and phone number (account registration)
- Pickup and delivery addresses
- Payment information (processed securely by Stripe; we do not store card details)
- Order history and delivery preferences
- Device identifiers and push notification tokens
- App usage data and crash reports
Courier applicants and couriers
- Name, date of birth, email address, phone number, home address, and profile photo
- A government-issued identity document (passport, national ID card or residence permit): the image itself, and the details read from it
- A selfie taken during the application
- Biometric data: the facial geometry derived from your selfie and from the photo on your identity document, used to confirm they are the same person and that you have not already registered under another account
- Nationality and right-to-work status, including a work permit or visa document where one applies
- PPS number, for tax purposes
- Bank account details (IBAN) for earnings payouts
- The result of screening your name against international sanctions and politically-exposed-person lists
- Precise GPS location: while you are online and available for deliveries, including when the app is in the background
- Trip history and delivery performance data
- Device identifiers and push notification tokens
3. Why we collect it (legal basis)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Processing and fulfilling delivery orders | Contract performance |
| Real-time tracking of your delivery | Contract performance |
| Processing payments via Stripe | Contract performance |
| Courier background location while online and available | Contract performance / Legitimate interests |
| Verifying a courier's identity using facial geometry (special category data) | Explicit consent (Art. 9(2)(a)), given in the app before any photo is taken. You can refuse, but we cannot approve an application without it. |
| Confirming right to work, and screening against sanctions lists | Legal obligation / Legitimate interests |
| Sending order status and push notifications | Contract performance / Consent |
| Fraud prevention and platform safety | Legitimate interests |
| Improving our services and analytics | Legitimate interests |
| Complying with legal obligations | Legal obligation |
4. Location data
Couriers: We collect precise GPS location the whole time you are online and available for deliveries, including when the app is in the background. This is what lets us offer you the orders nearest to you, and lets the customer follow a delivery you are carrying. Collection stops when you go offline. You may revoke location permission at any time in your device settings, but you will not be able to go online without it.
Customers: We use your device location only when you grant permission, to auto-fill pickup addresses. We do not track customer location in the background.
5. Sharing your data
We share your data only where necessary:
- Stripe: payment processing and courier payouts. Subject to Stripe's own privacy policy.
- Supabase: cloud database and file storage (servers in the EU).
- Amazon Web Services: identity verification. Your identity document and selfie are processed by AWS to read the document and to compare the two faces.
- OpenSanctions: the sanctions and politically-exposed-person data we screen courier names against.
- Resend: sending our emails.
- Cloudflare: protecting our forms from automated abuse.
- Expo / Firebase: push notification delivery.
- Couriers and customers: limited profile information is shared between the matched courier and customer to complete a delivery (first name, transport type, live location).
- Legal authorities: where required by Irish or EU law.
We do not sell your personal data to third parties.
6. Data retention
We keep your data for as long as your account is open and you are using Lasta. Some records we have to keep for longer regardless, because the law requires it: financial records, for example, are retained for seven years under Irish tax law.
You can ask us to delete your data at any time, and we will tell you what we are able to delete and what we are obliged to keep. Deletion is handled by a person rather than automatically, so email us at [email protected] and we will confirm when it is done.
7. Your rights (GDPR)
Under the General Data Protection Regulation, you have the right to:
- Access: request a copy of the data we hold about you
- Rectification: correct inaccurate data
- Erasure: request deletion of your data ("right to be forgotten")
- Restriction: ask us to limit how we use your data
- Portability: receive your data in a machine-readable format
- Objection: object to processing based on legitimate interests
- Withdraw consent: at any time, where processing is based on consent
To exercise any of these rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Data Protection Commission (Ireland's supervisory authority).
8. Security
We use industry-standard measures to protect your data, including encrypted connections (TLS), secure cloud infrastructure, and access controls. Payment data is processed by Stripe and is never stored on our servers.
9. Cookies
Our website uses cookies. See our Cookie Policy for details.
10. Children
Our services are not directed at children under 18. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us data, contact us and we will delete it promptly.
11. Changes to this policy
We may update this policy periodically. Material changes will be notified via the app or email. The date at the top of this page reflects the latest revision.