Last updated: 19 August 2026
Website and Kairo platform privacy policy. For the Kairo Operator and Kairo Driver mobile-app policy, see /privacy.
KAIRO is operated by Kairo Engine Ltd, a company registered in England and Wales (company number 17127596), with its registered office at 61 Lyne View, Hyde, SK14 4ND. We provide a software-as-a-service platform for chauffeur and executive car operators to manage dispatch, fleet, invoicing, and client communications.
Data Controller: Kairo Engine Ltd (company number 17127596), 61 Lyne View, Hyde, SK14 4ND, United Kingdom
Contact: support@kairoengine.com
Name, email address, phone number, company name, company address, VAT number, and payment information (processed by Stripe, we never store card numbers).
Passenger names, phone numbers, email addresses, pickup and drop-off addresses, flight numbers, special instructions, and booking history.
GPS coordinates from drivers during active jobs, used for live tracking and ETA calculation. Location data is collected only while a driver is on an active job and is not tracked outside working hours.
Invoice amounts, payment statuses, expense records, and revenue figures. Card payment details are handled entirely by Stripe and never touch our servers.
Emails forwarded to the KAIRO AI inbox for booking extraction, and messages sent through the platform.
Pages visited, features used, session duration, browser type, and device information, collected to improve the platform experience.
KAIRO uses the Anthropic Claude API to power intelligent features:
Data sent to Anthropic's API is processed in real time and is not stored by Anthropic beyond the API call. Anthropic does not use your data to train their models. Full details are in Anthropic's privacy policy (opens in a new tab).
We share data with the following service providers, solely to operate the platform:
| Service | Purpose |
|---|---|
| Supabase | Database hosting and authentication (EU/US servers) |
| Vercel | Web application hosting |
| Anthropic (Claude) | AI-powered email parsing and business insights |
| Google Maps Platform | Geocoding, distance calculation, and address autocomplete |
| AviationStack | Flight tracking and status information |
| Resend | Transactional email delivery (when operator SMTP not configured) |
| Stripe | Subscription billing and payment processing |
| Xero | Accounting integration (only when connected by operator) |
| Expo | Mobile push notifications for the driver app |
We do not sell your data to any third party. We do not share your business data, client lists, or operational information with other KAIRO operators.
We retain operational data while your account is active. After account deletion, operational records are normally deleted or de-identified within 30 days. We retain invoices and the booking amounts they derive from for up to six years where UK financial law requires it, and may retain driver compliance records where a legal obligation applies. Personal identifiers are removed where they are no longer required. See the account-deletion notice for the applicable routes and exceptions.
You have the following rights regarding your personal data:
To exercise any of these rights, email support@kairoengine.com or use the account deletion option in Settings, under Account & data.
You can delete your account at any time from Settings → Account & data. Deleting removes your sign-in straight away, and nobody can use it again afterwards.
The workspace records behind that login, including bookings, clients, invoices, drivers, vehicles and configuration, then follow the retention schedule in our data processing agreement. We delete operational records within 30 days of the subscription ending, and we keep invoices and other financial records for six years because HMRC requires it. Export anything you want to keep before you delete, because we cannot undo it afterwards.
We serve every request over TLS 1.2 or later, and Supabase Postgres and object storage encrypt what they hold with AES-256. Postgres row-level security policies separate one operator’s data from another’s at the database layer rather than in the screens above it. We restrict access to production systems.
We do not hold SOC 2 or ISO 27001 certification, and we do not offer multi-factor authentication yet. Our security page lists each control we run today alongside the ones we do not, so you can check rather than take our word for it.
KAIRO is a business-to-business service. It is not directed at individuals under the age of 18. We do not knowingly collect personal data from children.
Some of our service providers process data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses and adequacy decisions, in compliance with UK GDPR requirements.
Kairo Engine Ltd is a UK company and this policy is written under UK GDPR. If you use Kairo from the United States, as an operator, driver or client, the rights in section 7 above apply to you in the same way: access, correction, deletion, portability and objection, on request to support@kairoengine.com.
Kairo has not registered under the California Consumer Privacy Act or any other US state privacy law. The thresholds those laws set (currently around $26.6 million in annual revenue, or personal data on 100,000 California consumers or households, under the CCPA) are well above the scale Kairo operates at today. As stated in section 5 above, Kairo does not sell personal data to any third party.
We may update this privacy policy from time to time. Material changes will be communicated via email at least 30 days before taking effect. The “last updated” date at the top of this page will always reflect the most recent version. Continued use of KAIRO after changes take effect constitutes acceptance.
For any privacy-related enquiries or to exercise your rights, contact us at: support@kairoengine.com
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk (opens in a new tab).
This privacy policy is governed by the laws of England and Wales and the UK General Data Protection Regulation (UK GDPR).