Who we are
This Privacy Policy explains how Green Bee Logistics Limited ("CUBRINX", "we", "us", "our") collects, uses, shares and protects personal data when you use our website at cubrinx.com (the "Website") and our payments and receivables services for wholesale distribution (the "Services").
- Legal entity: Green Bee Logistics Limited
- Registered in: England and Wales
- Company number: [COMPANY NUMBER — INSERT]
- Registered office: 167–169 Great Portland Street, 5th Floor, London W1W 5PF, United Kingdom
- Trading name: CUBRINX
Scope of this policy
This policy applies to personal data we process about:
- Visitors to our Website;
- Representatives of distributors who enquire about, apply for, or use the Services ("Customers");
- Operators and their representatives who apply to or participate in the CUBRINX Operator Network;
- People who contact us, subscribe to updates, or apply for a role with us.
The personal data we collect
We may collect and process the following categories of personal data, depending on how you interact with us:
- Identity and contact information — such as your name, job title, company name, work email address, telephone number, and postal address;
- Account and commercial information — such as details about your organisation, your role, pilot or operator application information, and records relating to your use of the Services;
- Transaction and payment information — such as invoice details, payment history, and limited payment card information (for example, the last four digits) received from our payment processor;
- Technical and usage data — such as IP address, browser type, device information, pages visited, and cookie identifiers;
- Communications — such as correspondence with us, support requests, and your marketing preferences.
How we collect personal data
We collect personal data: (a) directly from you, when you fill in a form, request a pilot, apply to the Operator Network, contact us, or use the Services; (b) automatically, through cookies and similar technologies when you use the Website; and (c) from third parties, such as Stripe (payment confirmations) and our analytics provider.
How and why we use your personal data
We use personal data for the following purposes:
- to respond to enquiries, pilot requests, and operator network applications;
- to provide, administer, and improve the Services;
- to process payments and manage receivables;
- to communicate with you about the Services, including operational and service-related messages;
- to send marketing communications where permitted (see section 7);
- to maintain the security and integrity of our Website and Services;
- to comply with legal, regulatory, tax, and accounting obligations.
Our legal bases for processing
Under the UK GDPR, we rely on the following legal bases:
- Performance of a contract — to provide the Services you or your organisation have requested, and to take steps prior to entering a contract (e.g. handling a pilot enquiry or operator application).
- Legitimate interests — to operate, secure, improve and promote our Services, to respond to enquiries, and to manage our business, provided your interests and rights do not override these. Our legitimate interests include running and growing a sustainable business and keeping our Services safe.
- Consent — for non-essential cookies and certain marketing communications. You can withdraw consent at any time (see sections 7 and 13).
- Legal obligation — to comply with our legal, accounting, tax and regulatory duties.
Marketing
We may send you updates about CUBRINX where you have asked to receive them or where we are permitted to do so under applicable law (including the "soft opt-in" for existing business contacts under PECR). Every marketing message includes an unsubscribe link, and you can opt out at any time by contacting privacy@cubrinx.com. Opting out of marketing will not affect service-related communications we need to send you.
Payment processing and Stripe
We use Stripe (Stripe Payments Europe, Limited and its affiliates) to process payments through the Services. When a payment is made:
- Card and bank account details are entered into, and processed by, Stripe directly. CUBRINX does not receive or store full card numbers or bank credentials.
- Stripe is certified as a PCI DSS Level 1 service provider, the highest level of certification available in the payments industry.
- We receive from Stripe only the information we need to operate the Services — for example payment confirmations, transaction references, payment status, and the last four digits of a card.
International transfers
We aim to keep personal data within the UK and EEA. Some of our service providers (including Stripe and certain infrastructure providers) may process data outside the UK/EEA. Where they do, we ensure an appropriate safeguard is in place, such as:
- the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses; and/or
- the EU Standard Contractual Clauses (SCCs); and/or
- transfers to countries with a UK/EU adequacy decision.
How we protect personal data
We use appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, and EU-region hosting. More detail is set out in our Security Statement at cubrinx.com/security. No method of transmission or storage is completely secure, but we work to protect your data.
How long we keep personal data
We keep personal data only for as long as necessary for the purposes set out in this policy, including to satisfy legal, accounting, tax or reporting requirements.
- Enquiry and application data — kept for the duration of our discussions and for a reasonable period afterwards [CONFIRM PERIOD WITH SOLICITOR].
- Customer account and transaction data — kept for the life of the relationship and for the period afterwards required by law (UK company and tax records are generally kept for 6 years) [CONFIRM].
- Marketing data — kept until you opt out.
- Website/technical data — kept for a short period consistent with our analytics and security needs.
Your rights
Under the UK GDPR (and EU GDPR where it applies to you), you have the right to:
- be informed about how we use your personal data;
- access the personal data we hold about you;
- request rectification of inaccurate or incomplete data;
- request erasure of your data ("right to be forgotten") in certain circumstances;
- restrict or object to our processing in certain circumstances;
- data portability, where applicable;
- withdraw consent at any time, where processing is based on consent.
Complaints and supervisory authorities
If you have a concern, please contact us first at privacy@cubrinx.com and we will do our best to resolve it. You also have the right to complain to a supervisory authority:
- United Kingdom — the Information Commissioner's Office (ICO), www.ico.org.uk.
- Spain — the Agencia Española de Protección de Datos (AEPD), www.aepd.es.
- Elsewhere in the EEA — your local data protection authority.
Third-party links
The Website may contain links to third-party sites. We are not responsible for their privacy practices, and we encourage you to read their privacy policies.
Changes to this policy
We may update this policy from time to time. We will post the updated version on this page and update the "Last updated" date. Where changes are significant, we will take reasonable steps to notify you.
Contact us
Questions about this policy or your personal data:
Questions about this document?
Write to privacy@cubrinx.com