Skip to content
Expert Guide Series

What Legal Requirements Must My Delivery App Meet for Commercial Use?

Running a delivery app in the UK is genuinely exciting. The market is real, the demand is there, and the technology to build something polished has never been more accessible. But between the idea and the launch sits a surprisingly dense layer of legal obligations that many founders underestimate until something goes wrong. Understanding what the law requires from a delivery app before it goes live is not just good practice, it is what keeps the business standing once real users arrive and real money moves.

The requirements span several different areas of law, and no single regulator owns the whole picture. Data protection, food safety, payment rules, employment obligations, accessibility standards and consumer rights each come from a different direction. Some apply the moment you collect a user's email address. Others kick in only when you start processing payments or hiring couriers. Getting clear on which rules apply at which stage, and why they exist, makes the compliance task feel less like an obstacle and more like a foundation worth building on.

Delivery apps face legal obligations across multiple areas, and understanding them early protects the whole business.

What follows is a practical guide to the main legal requirements a delivery app must meet for commercial use in the UK, written to help founders, product teams and operators understand what they are dealing with before a problem forces the conversation.

Data Protection and GDPR Compliance

A delivery app collects personal data the moment a user creates an account. Names, addresses, payment details, location data, order history and device identifiers all count as personal data under UK GDPR, which means the rules apply immediately and comprehensively. There is no minimum size threshold. A startup with 50 users carries the same core obligations as a platform with 5 million.

The first obligation is lawful basis. The app must have a valid legal reason to collect and process each category of data it holds. For most delivery apps, this means either contractual necessity (processing an address to fulfil a delivery) or consent (sending marketing emails). Relying on consent requires that it was freely given, specific, informed and easily withdrawn. A pre-ticked box does not count.

Privacy Notice and Data Minimisation

Every app must have a clear, readable privacy notice that explains what data is collected, why, how long it is kept, and who it is shared with. Writing this in plain language matters. A notice buried in legalese that users cannot understand fails the transparency requirement even if it technically covers all the right ground.

Data minimisation is a core principle of UK GDPR. The app should only collect what it genuinely needs. Asking for a date of birth when the product does not require age verification, or storing precise GPS coordinates indefinitely when only a delivery postcode is needed, creates unnecessary legal exposure. Collecting less data also means less to protect and less to account for if something goes wrong.

Register with the Information Commissioner's Office (ICO) before launch. Most businesses that process personal data are legally required to pay the data protection fee, and failure to do so is an offence regardless of whether any data breach has occurred.

Food Safety and Hygiene Regulations

If the delivery app facilitates the sale or transport of food, food safety law enters the picture. The exact obligations depend on the app's role. A platform that simply connects restaurants with customers sits in a different position from one that employs its own food handlers or operates a dark kitchen. But even a pure marketplace carries responsibilities it should not ignore.

Under the Food Safety Act 1990 and associated regulations, food businesses operating in the UK must be registered with their local authority at least 28 days before they begin trading. If the app operator handles food directly, this applies. If the app partners with restaurants and food vendors, those businesses must each hold their own registration, and the platform should take reasonable steps to verify that they do. Partnering with an unregistered food business and processing orders on their behalf creates reputational and potentially legal exposure.

Food Hygiene Ratings

The Food Hygiene Rating Scheme runs across England, Wales and Northern Ireland. In Wales, displaying ratings is a legal requirement for food businesses. In England, display is voluntary for the business but many delivery platforms have chosen to surface ratings anyway, partly because users expect to see them and partly because the transparency supports trust. Platforms operating in Wales must ensure their restaurant partners' ratings are visible to users.

Delivery drivers who handle food, even in sealed packaging, can fall under food hygiene rules depending on the nature of what they carry. Training requirements, temperature control obligations for chilled or hot food, and vehicle hygiene standards all become relevant once food is physically in transit under the app's control.

Ask every food business partner for their Food Hygiene Rating and local authority registration number before activating them on the platform. Build this into your onboarding checklist rather than treating it as an afterthought.

Design built to grow your product

We give your app the strategic and design foundations it needs to launch well and keep growing. Research, UX/UI design and technical specs ready for your development team.

See how we work Get started

No commitment

Licensing and Business Registration Requirements

Operating a delivery app as a commercial business in the UK requires the operator to be properly registered. For most founders, this means incorporating as a limited company at Companies House, or registering as a sole trader with HMRC. The structure chosen affects tax obligations, personal liability and how contracts with partners, drivers and users are structured, so it is worth getting legal advice before deciding.

Beyond basic business registration, the app may need specific licences depending on what it sells. Alcohol delivery is subject to the Licensing Act 2003. To sell or arrange the sale of alcohol, the business needs a premises licence for each site from which alcohol is dispatched, and a designated premises supervisor who holds a personal licence. Apps that facilitate alcohol sales from third-party retailers need to understand clearly who holds the licence and whether their platform activities require them to hold one too.

Licensing rules for alcohol, tobacco and age-restricted goods apply to delivery platforms from the first transaction.

Age verification is a related issue. If the app sells age-restricted products such as alcohol, tobacco or certain medicines, a legally compliant age verification process must be in place before checkout, not just at the door on delivery. Relying entirely on a driver to check ID at the point of handover is not sufficient on its own, and the platform needs a documented process that satisfies the law.

Sector-Specific Registrations

Some categories of goods require additional regulatory registration. Pharmacy deliveries, medical device logistics and certain chemical products each come with their own frameworks. If the app intends to expand into any of these areas, specialist legal advice is essential before launch rather than after the first order arrives.

Payment Processing and Financial Regulations

Taking money from users through an app is a regulated activity. The way that activity is structured determines which rules apply and how directly they fall on the app operator. Most delivery apps use a third-party payment processor, such as Stripe or Adyen, which carries its own Payment Card Industry Data Security Standard (PCI DSS) compliance. But passing payment handling to a processor does not transfer all responsibility. The app operator still needs to understand what data flows through its systems and ensure it does not store card data it has no right to hold.

If the app sits between the customer and the merchant, collecting money and then disbursing it to restaurant partners or vendors, it starts to look more like a payment service. The Financial Conduct Authority (FCA) regulates payment services in the UK under the Payment Services Regulations 2017. Platforms that transmit or process funds on behalf of others, rather than simply acting as a technical conduit for a processor, should take specific legal advice on whether they need to register with the FCA or apply for an e-money licence.

Platform Fees and Transparency

Whatever the platform charges in fees must be clearly disclosed to both the consumer and the merchant partner before any transaction is completed. Hidden charges, fees that only appear at the final checkout screen, or commissions buried in terms that restaurant partners never read, all create legal risk under consumer and contract law. Clarity protects everyone and reduces dispute rates, which matters practically as well as legally.

Where the app operates in specific territories with local fee caps, these must be factored into the commercial model. New York City, for example, caps the delivery fee that third-party apps can charge restaurants at no more than 15% of the purchase price of each online order, according to the New York City Department of Consumer and Worker Protection. Operators planning to scale into international markets need to audit local regulations before entering each new geography.

Consumer Rights and Refund Obligations

When a user places an order through a delivery app, they enter into a contract. The Consumer Rights Act 2015 governs that contract and sets out rights that cannot be waived through terms and conditions, however carefully drafted. If a product arrives damaged, significantly late, or fails to match its description, the consumer has rights regardless of what the app's terms say.

Refund obligations depend partly on the type of goods ordered. Food, as a perishable item, sits in a different category from a consumer product, but that does not remove the right to a remedy if the order was wrong or the food was unfit to eat. The platform needs a clear, accessible refund and complaints process that users can actually find and use. Burying dispute resolution in a long terms of service document, or making users email a generic inbox with no response time commitment, does not meet the standard the law expects.

Distance Selling Rules

Delivery apps operate as distance selling businesses, which means the Consumer Contracts Regulations 2013 apply. Users have a right to clear pre-contract information, including the total price, the delivery arrangements, and the identity of the seller. For marketplace apps where third-party restaurants or vendors are the actual seller, the platform must make it clear who the consumer is contracting with. Presenting the app as the seller when the legal seller is actually a restaurant partner creates misrepresentation risk.

Write your refund policy in plain, direct language and link to it from every order confirmation. A policy that users can read and understand in 60 seconds reduces disputes and builds trust far more effectively than a legally comprehensive document no one reads.

Allergen Information and Labelling Laws

Allergen information is one of the most serious legal obligations a food delivery platform carries, and also one of the most frequently handled poorly. Natasha's Law, which came into force in England, Wales and Northern Ireland in October 2021, requires full ingredient and allergen labelling on food that is prepacked for direct sale. The 14 major allergens regulated under UK food law must be clearly identified in any food listing where they are present.

For a delivery app, this creates a direct responsibility to ensure that menu listings accurately reflect the allergen information provided by restaurant and food partners. Displaying inaccurate or incomplete allergen data, even if the inaccuracy originated with the partner business, can result in serious harm to a user with an allergy, and the platform's role in presenting that information will be scrutinised if something goes wrong.

Responsibility for Accuracy

The platform cannot simply republish whatever information a restaurant partner provides and consider its obligation discharged. A reasonable approach involves requiring partners to confirm their allergen data is accurate, building allergen fields into the menu management system so information cannot be left blank, and including a clear statement on every product listing advising users to contact the restaurant directly if they have a severe allergy or specific dietary need.

Users with severe allergies deserve clear, prominent information, not fine print. Placing allergen details one click away from the menu, or making them available only in a terms document, does not reflect how people actually behave when ordering food quickly on a mobile app.

Accessibility Standards

A delivery app that is not accessible excludes a substantial part of the population. Visual impairments, motor difficulties, cognitive differences and hearing conditions all affect how people interact with digital products, and designing without these users in mind produces an app that fails them. In the UK, the Equality Act 2010 requires businesses to make reasonable adjustments so that disabled people can access their services, and a delivery app is a service.

The technical benchmark most widely used for accessibility is the Web Content Accessibility Guidelines (WCAG). WCAG 2.1 Level AA is the standard referenced by UK public sector accessibility regulations, and it represents a sensible target for any commercial app aiming to serve a broad audience. The guidelines cover contrast ratios, text sizing, keyboard navigability, screen reader compatibility and much more. According to a WebAIM study, around 98.1% of home pages had detectable WCAG 2 failures, which suggests the gap between current practice and the required standard is wide across the industry.

Practical Accessibility Requirements

Contrast ratio matters more than most teams realise. Research from Build Grow Scale found that contrast ratio at the 4.5:1 minimum impacts conversions 3.2 times more than specific colour choice, which means accessibility and commercial performance point in the same direction. Clear button labels, logical heading structures, and descriptive alternative text for images are baseline requirements, not optional extras.

Testing with assistive technology, including screen readers on both iOS and Android, should be part of the quality assurance process before launch, not a task deferred to a future sprint.

Liability, Insurance, and Terms of Service

A delivery app operates at the centre of several relationships simultaneously: between the consumer and the food vendor, between the vendor and the courier, and between the app and all three. When something goes wrong, which relationship carries the legal liability depends entirely on how those relationships are structured in the platform's contracts and terms of service.

Terms of service must be clear, fair and brought to the user's attention before they accept them. Under the Consumer Rights Act 2015, any term that is found to be unfair is not binding on the consumer, even if they clicked to accept it. Terms that attempt to exclude all liability for a poor delivery experience, or that shift responsibility entirely to the restaurant partner in a way that leaves the consumer with no meaningful remedy, are likely to fail this test.

Insurance Considerations

Professional indemnity insurance, public liability insurance and product liability insurance are each worth reviewing for a delivery app. If the platform employs its own couriers or delivery vehicles, employer's liability insurance is a legal requirement. If couriers use their own vehicles, the platform should check that those vehicles are insured for business use, as standard personal motor insurance policies typically exclude delivery activities.

Food spoilage, late delivery leading to a cancelled event, or an allergic reaction caused by incorrect menu information are all scenarios where liability questions arise quickly. Knowing in advance which insurance policies respond to which claims, and what the platform's contractual exposure is in each case, is considerably better than finding out when the first claim arrives.

Employment Law and Gig Economy Obligations

How a delivery app classifies the people who work for it carries significant legal weight. UK employment law recognises three categories: employee, worker and self-employed contractor. The distinction matters because employees and workers have rights that contractors do not, including the national minimum wage, holiday pay, and protection from unfair dismissal.

The Supreme Court's 2021 ruling in Uber v Aslam established that Uber drivers qualified as workers rather than independent contractors, despite Uber's contractual framing of them as self-employed. The test applied by courts looks at the reality of the working relationship, including how much control the platform exercises over how and when work is done, rather than simply what the contract says. Delivery app operators should take this seriously: calling couriers independent contractors in a contract does not settle the question if the operational reality points elsewhere.

Minimum Pay and Worker Rights

Where couriers are classified as workers, they are entitled to the National Living Wage for every hour worked. In jurisdictions with specific delivery worker protections, the rates are higher. New York City sets a minimum pay rate of $22.13 per hour (not including tips) for time spent making deliveries, according to the New York City Department of Consumer and Worker Protection, and the rate increases annually.

  • Ensure couriers classified as workers receive the National Living Wage for all working time, including waiting time between orders where the platform controls their availability.
  • Provide written terms of engagement to all couriers before they begin work, covering pay, how work is allocated and how the relationship can end.
  • Review the operational model regularly as classification law continues to develop through tribunal and court decisions.
  • Keep records of hours worked and payments made, as these form the basis of any minimum wage compliance audit.

Getting the classification right from the start, rather than waiting for a tribunal claim, protects the business and the people working for it.

Conclusion

The legal requirements for a delivery app are wide-ranging, but they share a common thread. Each one exists because real people, whether users placing orders, couriers making deliveries, or restaurant partners listing their menus, are affected by the decisions built into the platform. Data protection rules exist because personal information misused causes real harm. Allergen labelling requirements exist because incomplete information can kill. Worker classification rules exist because people deserve fair pay and basic protections.

Treating these requirements as a checklist to clear before launch is one approach, but it tends to produce minimal compliance rather than genuine confidence. The more useful frame is to understand what each rule is protecting and build the product around that. An app designed with honesty about data use, clarity about allergens, genuine accessibility, and fair treatment of couriers will pass most legal tests because it was designed well, not because the legal team reviewed every clause.

Compliance also evolves. Employment law continues to develop through case law. GDPR enforcement is active and growing. Accessibility expectations are rising. Building a habit of regular legal review into the product and commercial calendar, rather than treating it as a one-time pre-launch task, is what keeps a delivery app on the right side of the rules as both the business and the regulatory environment change.

If you are building a delivery app and want to think through how design and compliance work together to create a product people genuinely trust, let's talk about your delivery app.

Frequently Asked Questions

Do data protection rules apply to my delivery app even if I only have a small number of users?

Yes, UK GDPR applies from the moment you collect any personal data, regardless of how many users you have. A startup with 50 users carries the same core obligations as a large platform, so compliance cannot be deferred until the business scales.

What counts as personal data for a delivery app?

Personal data includes names, delivery addresses, payment details, location data, order history and device identifiers. If a piece of information can be used to identify a person, directly or indirectly, it falls under UK GDPR and must be handled accordingly.

Do I need to register with the ICO before launching my delivery app?

Yes, most businesses that process personal data are legally required to register with the Information Commissioner's Office and pay the data protection fee. Failing to do so is an offence in its own right, even if no data breach has taken place.

What lawful basis should a delivery app rely on when processing user data?

Most delivery apps will rely on either contractual necessity, for example processing an address to complete a delivery, or consent, for example sending marketing emails. Consent must be freely given, specific, informed and easy to withdraw, so pre-ticked boxes are not acceptable.

Does my delivery app need to comply with food safety regulations?

If your app facilitates the sale or transport of food, food safety law is relevant to your business. The exact obligations depend on your role in the process, so it is important to establish early on whether your app is acting as a marketplace, a food business, or something in between.

What should a privacy notice include for a delivery app?

A privacy notice must explain what data is collected, why it is collected, how long it is kept, and who it is shared with. It should be written in plain, readable language, as a notice that users cannot understand fails the transparency requirement even if it covers all the required points.

Is it a problem if my delivery app collects more data than it strictly needs?

Yes, data minimisation is a core principle of UK GDPR, meaning you should only collect what is genuinely necessary. Collecting excessive data creates unnecessary legal exposure and gives you more information to protect and account for if something goes wrong.

At what point do legal obligations start to apply when building a delivery app?

Different obligations kick in at different stages. Some apply the moment you collect a user's email address, while others begin when you start processing payments or taking on couriers. Mapping out which rules apply at which stage early on makes compliance far more manageable.