Government Data Request Policy
How ZIP.GY handles requests from public authorities for user data.
ZIP.GY holds personal information that our customers, drivers and partner businesses trust us with — names, phone numbers, addresses, trip and order history. From time to time a police force, regulator, court or other public authority may ask us to disclose some of it. This policy sets out the process we follow every time that happens. It applies to all data we hold, including data received through third-party platforms such as Meta's WhatsApp Business Platform.
1. Every request is reviewed for legality
No user data is disclosed to a public authority until the request has been reviewed to confirm it has a proper legal basis. That review checks that the request is in writing, comes from an identifiable and competent authority, cites the law or instrument it is made under, and covers data we actually hold.
Responsibility for this review sits with the ZIP.GY director / data controller. Operational staff and dispatch team members are not permitted to release user data to an authority on their own initiative and must escalate any such request immediately.
2. We will challenge requests we believe are unlawful
We do not treat a request as valid simply because it comes from an authority. Where a request appears to lack legal basis, to be overly broad, to be improperly served, or to conflict with the privacy rights of our users, we will push back — by seeking clarification or narrowing, by formally objecting, by requiring a court order where one is legally necessary, and by obtaining legal advice and contesting the request before the appropriate body where that is warranted.
We will not voluntarily hand over user data in the absence of a lawful obligation to do so.
3. We disclose the minimum information necessary
Where we are lawfully required to disclose data, we release only the specific records and specific fields the request actually compels, limited to the individuals and the time period named. We do not provide whole-account exports, bulk data sets, or unrelated records as a convenience.
Anything outside the scope of the request — other users, other trips, payment credentials, or data we hold for a different purpose — is withheld.
4. Every request and response is documented
We keep an internal record of each request from a public authority. That record includes the date received and the requesting authority, the legal instrument relied upon, the data requested, the legal reasoning applied and the decision reached, who at ZIP.GY made and approved the decision, any external legal advisor involved, exactly what data was disclosed or the grounds for refusal, and the date of our response.
These records are retained so that our handling of any request can be reviewed and accounted for after the fact.
5. Notifying affected users
Where we are legally permitted to do so, we will inform an affected user that their data has been requested, so that they have the opportunity to seek their own legal advice. We will not notify a user where a valid legal instrument prohibits us from doing so.
Serving a request on ZIP.GY
Public authorities should direct requests, in writing and citing the legal basis relied upon, to ZIP.GY's registered business address. Requests received informally — by phone call, in person, or through a driver, rider or partner business — will not be actioned and will be referred back for formal service.