Data and privacy
Privacy Notice
Last updated July 14, 2026
Scope
This notice describes how the Helm software platform processes information for transportation operators, their authorized team members, drivers, passengers, affiliate partners, and visitors to Helm product pages. Transportation companies using Helm remain responsible for their own customer-facing privacy notices and lawful instructions.
Information processed
- Account and business information, including names, contact details, roles, subscription status, and workspace settings.
- Trip information, including pickup and drop-off locations, schedule, flight details, passenger and booking-contact details, vehicle selection, notes, pricing, driver assignment, and trip status.
- Driver information, including profile, availability, vehicle eligibility, dispatch activity, and location only after explicit location consent.
- Affiliate-network information, including service areas, fleet capabilities, rate agreements, acceptance history, performance events, settlement status, and disputes.
- Technical and security information, including IP address, device and browser information, authentication events, audit history, error telemetry, and integration delivery status.
How information is used
Helm uses information to provide quoting, booking, dispatch, passenger communication, affiliate-network, billing, support, fraud-prevention, security, reliability, and product-improvement functions. Helm does not sell personal information.
Helm Select sharing
When a visitor submits a Helm Select request, Helm compares the itinerary with availability published by verified operators. Matched operators may receive generalized pickup and destination areas, schedule, requested vehicle class, and passenger count so they can decide whether to propose an option. Customer identity, contact details, private notes, flight number, and street-level addresses remain hidden from matched operators. The selected operator receives the complete itinerary after selection so it can confirm availability; customer contact details are released to that operator after successful payment.
Payments
Payment details are collected and processed by a payment provider for the selected transportation operator. Helm receives transaction identifiers, amounts, status, refunds, disputes, connected-account status, and limited billing details needed to operate the marketplace and support the transaction. Helm does not store complete card numbers or card security codes.
Service providers and integrations
Information may be processed by infrastructure, database, mapping, payment, email, messaging, calendar, analytics, and error-monitoring providers when required to deliver configured features. Each operator controls which optional integrations it enables.
Retention and deletion
Records are retained for the period needed to provide the service, meet contractual and legal obligations, resolve disputes, prevent abuse, and maintain audit integrity. Unconverted Helm Select requests that have no payment record are scheduled for deletion after 90 days, and isolated automated test requests without financial activity after 7 days. Booking, payment, refund, dispute, settlement, and audit records may be retained longer where required for accounting, fraud prevention, legal claims, or regulatory obligations. Location pings use a short operational retention period. Expired authentication artifacts are scheduled for deletion. Workspace administrators and requesters may request export or deletion through Helm Support, subject to legal retention requirements.
Security
Helm uses tenant-scoped access controls, signed sessions and action links, encrypted transport, hashed credentials and reset codes, rate limiting, audit records, and restricted administrative operations. No system can guarantee absolute security; suspected incidents should be reported immediately through Helm Support.
Your choices
Depending on applicable law and the operator relationship, individuals may request access, correction, deletion, restriction, or portability. Passenger requests should normally begin with the transportation operator that collected the trip information.