Legal document — 02

Privacy Policy

We know how important your personal data is to us. This document transparently explains what data we collect, how we use it, and how we protect it.

Last updated · 01.01.2026 GDPR compliant · Yes Data controller · Burncode LLC

01Data we collect

To ensure the full functionality of our Service, we collect data belonging to the following categories:

Personal identification

  • First name, last name, phone number, email address.
  • Profile photo, front and back of the identity document (for drivers).
  • Date of birth, gender (optional).

Vehicle information (drivers only)

  • Technical passport details, state registration number.
  • Photograph of the driving license.
  • Photographs of the vehicle.

Technical information

  • Device type, operating system, application version.
  • IP address, Firebase push token.
  • Location (only where active permission is granted, for the duration of the trip).
  • In-app activity log (crash reports, usage statistics).

Payment information

Card numbers are not stored on our servers. Payments are processed directly by EPoint and App Store / Google Play. We only receive information about the transaction identifier and its status.

02Use of data

  • To establish a connection between drivers and passengers.
  • To process payments and manage subscriptions.
  • For security, to prevent fraud, and to detect fake accounts.
  • To analyze application performance and add new features.
  • To communicate with you — notifications, updates, support replies.
  • To fulfill obligations arising from legislation.

03Who we share data with

We do not sell your personal data to third parties. However, the necessary minimum of data is transferred in the following cases:

  • EPoint — for the processing of card payments.
  • Google Firebase — push notifications, analytics, and crash reporting.
  • AWS S3 — for the storage of images and documents.
  • Twilio / BulkSMS — for SMS verification codes.
  • Authorized state bodies — only on the basis of a court decision or a lawful request.

04Retention period

Data is retained for as long as your account is active. When you delete your account, other data is deleted or anonymized, subject to a mandatory archiving period of 5 years arising from financial and tax legislation.

05Security

Data is transmitted over encrypted channels (TLS 1.3) and stored on servers in encrypted form. Passwords are hashed with bcrypt. Under role-based access control, only authorized personnel may view the data.

No system is perfect. If we detect that data has been accessed without authorization, we will contact you within 72 hours.

06User rights

You may exercise the following rights at any time:

  • Right of access — to all data we hold about you.
  • Right to rectification — to correct inaccurate data.
  • Right to erasure — the "right to be forgotten".
  • Right to data portability — to obtain your data in a machine-readable format.
  • Right to object — to processing.

To exercise these rights, you may use the contact section or the "Manage My Data" menu within the application.

07Children's privacy

Our Service is not intended for persons under the age of 18. If we discover that data belonging to a child has been collected, we delete it immediately.

08International transfers

Our data centers are located primarily in Europe (Frankfurt). Firebase and AWS services may use international data centers; in such cases, the GDPR Adequacy Decision and Standard Contractual Clauses apply.

09Contact

For any questions relating to privacy, write to [email protected] or use the contact page.


Your data is yours — we are merely its custodian. Contact →