Glasi Platform User Privacy Policy
This policy explains what personal data Glasi collects about you as a platform user, why, who we share it with, and your rights. Please read it alongside the Platform User Terms of Use.
Who controls your data
Glasi Ltd ("Glasi", "we", "us") is the controller of the data described here. We are registered in England and Wales (company number 17147716), registered office 63 Winchester Street, Botley, Southampton, England, SO30 2EB. Contact us at hello@glasi.co.uk.
Numbermill Ltd (company number 08884038) ("Numbermill") is your employer for the work you do through Glasi. Numbermill is a separate controller for your employment and payroll data. This policy covers Glasi's handling of your data. Numbermill's own handling is covered by Numbermill's privacy policy.
What we collect
Identity and contact. Your name, phone number, email, home address, postcode, the area you are in, and who referred you. Your date of birth and age group. Your Instagram handle, if you give it for the follow badge.
Right to work and statutory identifiers. Your National Insurance number, your right-to-work share code, the date your right to work was verified, the location of the evidence of that check, the expiry date of your right to work where relevant, and your declaration that you have the right to work in the UK. We treat this as some of the most sensitive data we hold.
Screening and eligibility. Your answers about hospitality experience, transport, work clothing, being physically able to do the work, speaking English, agreeing to the work standard, and your availability.
Notes we make about you. Vetting notes, reliability notes and score, general admin notes, and your status with us (for example whether you are active, onboarded, or paused).
Engagement and pay band. Your tier, your hourly rate, and your points.
Things you write or upload. Your bio and your profile photo. Your profile photo is stored at a web address that is hard to guess but is not password protected, so anyone with the exact link could view the image.
Consent and acknowledgements. Records that you accepted these terms and acknowledged the Key Information Document, including when and the name you typed.
Account and device. Sign-in details (your password is held by our authentication provider, never by us in readable form), your notification permission state, your device push token and device identifier, and timestamps for events like being invited, setting a password, and completing the tutorial.
Location. Covered separately below, because it is the most sensitive thing we process.
Location, in detail
Location is the most sensitive data we handle, so we are specific about it.
We only capture your location while you are in a session. Capture begins at the moment you tap to join a session, never before. We do not take your location when you install the app, when you sign in, or at any time you are not in a session.
What happens during a session. When you join, the app takes one location fix and then follows your location as you stand by, as you travel to a venue once dispatched, and while you work. The app samples your location based on how far you have moved rather than on a fixed timer, roughly every 25 to 75 metres depending on whether you are travelling or already at the venue, with an occasional check if you stay in one place for a while. When you clock out, the app takes one final fix and then stops.
Movement sensing. While you are on your way to a venue the app also reads your phone's motion and activity signal, for example whether you are still, walking, or in a vehicle, so it can tell when you have actually arrived. This is recorded alongside your location while you travel and is used only to detect arrival.
Why we need it, and why "Always". We use your location to:
- work out which venues are within walking distance of you, so you only hear requests you could reach (the walking-distance estimate for hearing requests is worked out from your address, and refined from your live position when you join);
- set how long you have to respond to a request, based on your travel time;
- show the venue a live estimate of when you will arrive, as a number of minutes only;
- detect automatically when you have arrived;
- notice if you have been dispatched but have not set off, so the venue is not left waiting; and
- record that you were at the venue while you worked, and when you left, which protects you and the venue if there is ever a dispute about an assignment.
Several of these happen while the app is in the background, for example while you are walking to a venue with your phone in your pocket. That is why being dispatched requires background ("Always") location. You can be dispatched only if "Always" is enabled. Enabling it also awards engagement points; you are free to enable it or not, but without it you will not be selected for assignments.
What you see while it is on. While the app is using your location it shows a notification and an in-app banner making clear it is active and that it only happens during a session.
Who sees your location. The venue never sees your coordinates. It sees only an estimated number of minutes until you arrive. Your live position is sent to Google's distance service to calculate walking time and estimates (see processors below). Glasi can see platform user positions on its internal operations view while a session is live.
How long we keep it. We keep raw location data (your coordinates) for up to six months, then delete it. We keep the derived facts that have lasting value, such as the time you arrived and your estimated travel minutes, with your assignment record.
AI support chat
The in-app support chat is answered by an AI assistant. When you send a message, your message and the recent conversation are sent to Anthropic, our AI provider, which runs the model (Claude, model claude-sonnet-4-6) that writes the reply. Along with your messages we send a small amount of context so the assistant can help you: your first name, your tier, and, once you have been dispatched, the venue name and address and your estimated arrival time.
We do not send Anthropic your surname, your contact details, your home address, your National Insurance number, your right-to-work information, your date of birth, your pay, or any clock-in or clock-out codes. Anthropic processes your messages only to generate a reply and does not use them to train its models. A member of the Glasi team can also read and reply to support conversations.
Why we are allowed to process your data
We rely on the following bases under UK data protection law:
- Performing our arrangement with you, and steps before it. Running sessions, dispatching you, recording assignments, and supporting pay all need your data. Most location processing falls here, because the service cannot work without knowing where you are relative to a venue.
- Legal obligation. Holding right-to-work records, and keeping records of the work-finding services we provide, are legal requirements.
- Our legitimate interests. Vetting and reliability notes, fraud and quality checks, and running our support chat rely on our interest in operating a safe, working platform, balanced against your rights.
Your National Insurance number, right-to-work data, and date of birth are sensitive, but they are not special category data under the law, so we do not need a special condition to hold them. We still protect them as some of the most sensitive data we hold.
Who we share your data with
We use the following processors and partners.
- Supabase hosts our database, sign-in, file storage, and server functions. Your data sits here, in the EU (Ireland, region eu-west-1).
- Anthropic provides the AI that answers the in-app support chat. See "AI support chat" above for exactly what we send and what we never send.
- Google Firebase Cloud Messaging delivers push notifications. It receives your device token and the notification content. On Apple devices, Apple's push service completes the delivery.
- Google Distance Matrix calculates walking distances and arrival estimates. It receives your postcode or address, or your live position once you are dispatched, together with the venue address.
- Resend sends onboarding emails. It receives your email and first name.
- Numbermill is your employer and runs your pay. For payroll it receives your National Insurance number, your name, your Glasi reference, and your assignment hours and pay.
We use Google Firebase Crashlytics to diagnose and fix app crashes; it collects crash reports and diagnostic data (such as device type, operating system, and the app's state at the time of a crash), not your name or contact details. We do not use any payment processor. We do not hold your bank details. Your bank details sit with Numbermill, who pays you.
What a venue sees about you. Before you are dispatched, a venue sees nothing about you. Once you are dispatched, it sees your name, your estimated arrival in minutes, and the clock-in code. After the assignment, it sees your name, your Glasi reference, the assignment reference, and its own rating of you. A venue never sees your phone, address, National Insurance number, right-to-work data, date of birth, photo, points, or tier.
Transfers outside the UK
Supabase, which holds your data, is in the EU (Ireland), and transfers from the UK to the EEA are permitted under the UK's adequacy rules, so your core data stays in an adequate jurisdiction. Some of our other processors are based outside the UK and the EEA, including in the United States (for example push notifications, the distance service, the support chat, and onboarding email). For those transfers we rely on safeguards approved under UK data protection law, such as the UK-US Data Bridge (the UK Extension to the EU-US Data Privacy Framework) where the recipient is certified, or the UK International Data Transfer Agreement.
How long we keep your data
- Location coordinates: up to six months, then deleted (see the location section).
- Records of the work-finding services we provided you: at least one year after we last provide services to you, as the law requires, and in practice for as long as needed for tax, pay, and dispute purposes.
- Assignment and pay records: kept for up to six years to meet tax, pay, and limitation-period requirements.
- Right-to-work evidence: held by Numbermill as your employer, and we keep our record for the same period Numbermill applies.
If you stop working with us and never worked an assignment, we remove your identifying details after a set period. If you worked assignments, we keep the records above and remove your identifying details once they are no longer needed.
Your rights
Under UK data protection law you can ask us to:
- give you a copy of your data;
- correct data that is wrong;
- delete your data;
- restrict or object to how we use it; and
- provide it in a portable form.
Some data we must keep even if you ask us to delete it, for example right-to-work and pay records the law requires us to retain. We will explain if that applies.
To exercise any of these, contact hello@glasi.co.uk. You can also complain to the Information Commissioner's Office at ico.org.uk, though we would like the chance to put things right first.
Decisions made automatically
When a venue sends a request, the app passes it on to eligible platform users nearby and asks who is available. From the platform users who respond that they are available, one is dispatched: either a Glasi operator selects and dispatches a platform user, or, when automatic dispatch is switched on, a dispatch engine selects one automatically. The choice is guided by a number of factors including how close you are and how you have engaged with the app. This affects whether you are selected for a particular assignment. It does not by itself decide your pay or your status with us, and you can contact us about any decision. Even when automatic dispatch is on, a person at Glasi can review or change a selection.
Changes to this policy
We can update this policy. If a change is material, we will ask you to read it the next time you sign in.
Contact
Glasi Ltd, 63 Winchester Street, Botley, Southampton, England, SO30 2EB. Email hello@glasi.co.uk.