Privacy Policy - Merton Man And Van

This Privacy Policy explains how Merton Man And Van collects, uses, stores, shares, and protects personal data. It applies to all Merton Man And Van customers in the area, including individuals, households, businesses, and organisations that use our removals, delivery, transport, and related services. We are committed to handling personal information in a lawful, fair, transparent, and secure manner in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

Merton Man And Van is a service provider operating in the local area and supplying van-based moving and transport services. For the purpose of data protection law, we act as the data controller for the personal data we collect and process about our customers, prospective customers, suppliers, and website or communication users where applicable.

This policy sets out how we treat personal data whenever it is collected through booking enquiries, service arrangements, payment processing, customer support, correspondence, and operational delivery of our services.

2. Information We Collect

We only collect personal data that is necessary for providing our services, managing customer relationships, meeting legal obligations, and improving our operations. The categories of data we may collect include:

  • Identity information such as your name or business name
  • Contact information such as address, phone number, and email address
  • Booking and service details including moving date, property information, access notes, item descriptions, and service preferences
  • Payment and transaction information such as billing details, payment status, and invoices
  • Communication records including emails, messages, call notes, complaints, and feedback
  • Operational information such as delivery instructions, risk notes, parking restrictions, and collection or drop-off details
  • Technical information if you interact with our digital systems, which may include device data, IP address, and basic usage information

We may also process limited additional information where it is necessary for the safe and effective delivery of our services, for example, details relating to access requirements or special handling instructions.

Information we do not intentionally collect

We do not intentionally seek to collect sensitive personal data unless it is strictly necessary and you choose to provide it or it is required for a specific service. If such data is provided, we will only process it where there is a valid legal basis and appropriate safeguards in place.

3. How We Use Personal Data

We use personal data for the following purposes:

  • To provide quotes, confirm bookings, and deliver services
  • To communicate with customers about schedules, service changes, and operational matters
  • To issue invoices, process payments, and manage accounts
  • To maintain business records and service history
  • To respond to queries, complaints, and claims
  • To improve service quality, planning, and customer experience
  • To meet legal, regulatory, tax, and insurance requirements
  • To protect our rights, property, staff, and customers

We always aim to use data only for clear and legitimate purposes. We do not use personal data in a way that is incompatible with the original reason it was collected.

4. Lawful Basis for Processing

Under UK GDPR, we must have a lawful basis to process personal data. Depending on the circumstances, we may rely on one or more of the following legal bases:

  • Contract – where processing is necessary to take steps at your request before entering into a contract or to perform a contract with you
  • Legal obligation – where we must process data to comply with laws such as tax, accounting, or record-keeping requirements
  • Legitimate interests – where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms
  • Consent – where we ask for your permission for specific processing activities, and you may withdraw consent at any time

Where we rely on legitimate interests, these may include running our business efficiently, protecting against fraud, maintaining service quality, and managing customer relationships. Where consent is the basis, we will make that clear at the point of collection.

5. Sharing and Processors

We may share personal data with carefully selected third parties that help us operate our business. These parties act as processors or independent controllers depending on the service they provide. We only share the minimum information necessary and require appropriate confidentiality and security measures.

Examples of processors and recipients may include:

  • Payment providers for taking and reconciling payments
  • Accounting and bookkeeping services for financial administration and tax compliance
  • IT and cloud storage providers for data hosting, system support, and secure backups
  • Communication and scheduling tools used to manage customer bookings and service updates
  • Insurance providers where information is needed to handle claims or assess risk
  • Professional advisers such as legal or financial advisers when necessary
  • Regulators, authorities, or law enforcement where disclosure is required by law

We do not sell personal data. If data is transferred outside the UK, we will ensure that suitable safeguards are in place, such as an adequacy decision or approved contractual protections.

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, insurance, and reporting requirements. The retention period will depend on the type of data and the reason for processing.

In general:

  • Booking and service records may be kept for the duration of the customer relationship and a reasonable period afterwards
  • Financial and tax records are usually retained for the legally required period
  • Complaint and claims records may be held for as long as needed to resolve the matter and protect legal interests
  • General correspondence may be retained for operational continuity and audit purposes

When personal data is no longer required, we will securely delete, anonymise, or destroy it.

7. Data Security

We use appropriate technical and organisational measures to safeguard personal data against unauthorised access, loss, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and regular review of business systems and practices.

Although we take reasonable steps to protect personal information, no system can be guaranteed completely secure. If a data breach occurs that is likely to pose a risk to your rights and freedoms, we will take the appropriate action required by law.

8. Your Rights

As a data subject, you have certain rights under data protection law. These may include:

  • Right of access – to request a copy of the personal data we hold about you
  • Right to rectification – to ask us to correct inaccurate or incomplete information
  • Right to erasure – to request deletion of your data in certain circumstances
  • Right to restriction – to ask us to limit how we use your data in certain situations
  • Right to object – to object to processing based on legitimate interests or direct marketing
  • Right to data portability – to request transfer of certain data in a structured format where applicable
  • Right to withdraw consent – where we rely on consent, you may withdraw it at any time

Exercising one of these rights will not usually affect the lawfulness of processing carried out before your request. Some rights may be subject to legal limitations or exceptions.

How to exercise your rights

You may contact us using the usual business communication channels to make a request. We may need to verify your identity before responding. We aim to respond within the timeframe required by law.

9. Marketing and Communication Preferences

Where we send service-related communications, these are normally necessary for the performance of our services or for legitimate operational reasons. If we ever send optional promotional communications, we will ensure that the correct legal basis is in place and that you can opt out where appropriate.

We do not use personal data for unrelated marketing without proper notice and, where required, consent.

10. Children’s Data

Our services are not directed at children, and we do not knowingly collect personal data from children except where it is incidental to providing services requested by an adult customer or lawful representative. If we become aware that we have collected children’s data inappropriately, we will take steps to delete it or handle it lawfully.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data processing practices. Any updated version will take effect when published or otherwise communicated. We encourage customers to review this policy periodically so they remain informed about how their information is used.

12. Summary of Our Commitment

We are committed to keeping your personal data safe, using it only when lawful and necessary, and ensuring that it is retained for no longer than required. We treat privacy as an essential part of our service and aim to maintain clear, responsible, and respectful handling of all personal information entrusted to us.

By using Merton Man And Van services in the area, you acknowledge that your personal data may be processed in accordance with this Privacy Policy.

Merton Man And Van

GDPR-compliant privacy policy for Merton Man And Van covering data collection, lawful basis, retention, processors, and user rights for all local customers.

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.