Who is actually delivering food into your building? The courier-identity risk nobody costed in
The Home Office is now sharing asylum-hotel locations with Deliveroo, Just Eat and Uber Eats to crack down on account-sharing and illegal working among gig couriers. For residential buildings, hotels and offices, the question is bigger: even if only a third of your residents order delivery, the whole community comes into contact with whoever is buzzing the door. Here's what the data shows and why a lobby handoff layer is the safer default.

In July 2025 the Home Office <a href="https://www.bbc.co.uk/news/articles/cy4yjpv87v0o" className="text-primary underline underline-offset-2" target="_blank" rel="noopener">began sharing the locations of asylum hotels with Deliveroo, Just Eat and Uber Eats</a> so the platforms can flag accounts spending suspicious time at those addresses. The trigger was account-sharing: verified gig couriers renting their logins to people without the right to work in the UK. Thousands of accounts have already been removed.
That headline matters far beyond immigration policy. It exposes a quieter operational truth every building owner already half-knows: the person actually walking through your front door with a Deliveroo bag is not always the person whose ID Deliveroo verified. And that has consequences for every resident, guest and employee in the building — not just the ones who ordered.
The 'I don't even use Deliveroo' problem
Most building owners assume delivery risk is proportional to delivery adoption. A 30% adoption rate means 30% of the risk, surely. It doesn't work like that.
If a third of your residents order food delivery, but every order means a courier buzzing the main door, riding the lift, standing in the corridor — then 100% of residents share the exposure. The person who never opens a delivery app still encounters the courier in the lobby, on the lift, outside their neighbour's door. The 'I don't use it' household has not opted out of anything.
This is the bit that doesn't show up in any tender or service-charge breakdown: a single resident's order quietly creates a community-wide access event.
What 'verified courier' actually means in 2026
Deliveroo, Uber Eats and Just Eat all run right-to-work checks and photo verification on new riders. They have all tightened those checks in the last twelve months. None of that controls who is physically wearing the backpack on any given night.
Substituted riders, family members, friends-of-friends and rented accounts are common enough that the platforms themselves are the ones lobbying government for shared address data. Read that the right way round: the firms with the most to lose from over-stating verification quality are publicly admitting it isn't tight enough.
For a building owner that means the practical question — 'who is the person standing at the intercom right now?' — has a less confident answer than the app interface suggests.
Why the building, not the platform, carries the residual risk
Platform liability ends at the order confirmation. From the moment the courier is buzzed in, the risk profile transfers to the building. Examples building managers already deal with:
- Tailgating into the lobby behind a courier and roaming corridors
- Couriers riding lifts to floors that aren't theirs after a drop
- Fire-door propping while couriers run multi-stop drops in the same block
- Lost or substituted bags handled by reception without any audit trail
- Verbal disputes between residents and couriers in shared corridors
- Aggressive doorstep interactions, particularly for lone female residents at night
None of those are theoretical. They are the same incidents that drove the original <a href="/blog/why-luxury-blocks-banning-couriers" className="text-primary underline underline-offset-2">'no couriers above the lobby' policies</a> in central London prime residential, long before this year's account-sharing story.
The risk grows with the building, not the order
A 12-unit block sees roughly 50–80 courier visits per week. A 300-unit BTR scheme sees 1,500–2,000. A typical multi-tenant office tower in Zone 1 sees 200–400 lunchtime drops in a single peak hour. Each one is an access event that needs someone, somewhere in the operation, to make a snap judgement on identity and intent.
The cost-of-getting-it-wrong is not symmetric. A locker mis-allocation is a 90-second concierge fix. A stranger walking a corridor late at night is a complaint, a review, a press story, or worse.
The lobby handoff: the same safer-default that worked for parcels
The parcel industry settled this question a decade ago. Amazon lockers, InPost, parcel rooms, hub-and-spoke pickup — all designed so couriers don't enter the building. They drop, the resident collects. The courier's identity stops mattering past the lobby door because the courier never goes past the lobby door.
Food delivery just took longer to get there because of temperature. A Foodie Locker closes that gap: a temperature-controlled compartment in the lobby that accepts hot, ambient and chilled drops, notifies the resident or guest, and releases on a one-time PIN or QR. The courier transaction lives entirely in the lobby. The community above the lobby never sees them. See <a href="/blog/office-food-delivery-london-secure-handoff" className="text-primary underline underline-offset-2">the secure handoff problem</a> for the office equivalent.
What changes when the handoff moves to the lobby
Six specific changes show up in the operational data within weeks:
- Courier dwell time inside the building drops from 4–7 minutes to under 60 seconds
- Lift utilisation for courier trips drops to zero
- Door-propping incidents drop sharply (couriers no longer need to walk through fire doors)
- Concierge time on delivery triage drops 60–80%, freeing them for actual security and resident work
- Audit trail per order — courier ID at drop, resident PIN at collect — becomes searchable for the first time
- Resident complaints about strangers in corridors largely disappear
Crucially, none of that requires residents to change behaviour, opt in, or use a new app. They keep ordering from the same platforms. The building just changes where the handoff happens.
Why this matters for the Building Safety Act and for insurance
Post-Grenfell, the Building Safety Act has pushed accountable persons to demonstrate active control over who is in higher-risk residential buildings. Uncontrolled courier flow through fire doors and shared corridors is exactly the kind of weakness the Act's golden-thread documentation expects you to be able to evidence and improve. A lobby handoff layer is one of the cleanest, lowest-friction interventions a building can make to tighten that picture without restricting residents' lifestyles.
Insurance is moving the same way. Several UK building insurers are now asking specific questions about courier access control at renewal. 'Couriers do not access the building above lobby level' is a defensible, evidenced answer.
What good looks like
A safer-default building delivery setup has four components:
- Lobby-located temperature-controlled smart food locker sized to peak (the Foodie Locker product line)
- Courier flow that ends at the locker — courier ID logged, compartment assigned, audit trail kept
- Resident/guest collection on PIN or QR, with auto-reminders and dwell monitoring
- Concierge dashboard showing live drops, exceptions and any flagged courier behaviour
That setup is already standard in BTR, PBSA and increasingly in office and hotel lobbies across London. It is becoming the baseline rather than the premium.
Want to map the courier-access risk in a specific building? <a href="/contact" className="text-primary underline underline-offset-2">Book a demo</a>.
