Back to home

Privacy Notice — TaxiBuddy app

Version 0.2Last updated: June 2026

This notice explains which personal data we process when you use the TaxiBuddy mobile app (iOS + Android) as a driver or as an administrator of a taxi company. For the public website taxibuddy.be, a separate Website Privacy Notice applies.

1. What is this notice about?

This notice explains which personal data we process when you use the TaxiBuddy mobile app as a driver or as an administrator of a taxi company — why we process it, who we share it with, how long we keep it and which rights you have.

This notice does not apply to:

  • The use of the public website taxibuddy.be — see the Website Privacy Notice.
  • Cookies and analytics on the website — see the Cookie Notice.
  • Passengers of the taxi company — they receive their information through their taxi company.

2. Who are we — and who is your controller?

Important difference from the website notice: for the vast majority of the data we process through the app, your taxi company is the controller and we are the processor. We process your data on behalf of your taxi company, under a data processing agreement (DPA).

ItemValue
ProcessorCools IT Solutions BV — trading under the name TaxiBuddy
AddressDorp 4E bus 021, 2820 Bonheiden, Belgium
KBO + VATBE 0803.017.171
Managing director + privacy contactJarno Cools
Contact (all questions)privacy@taxibuddy.be
ControllerYour taxi company — name visible in the app under *Profile → Company*

We have not appointed a formal Data Protection Officer (DPO) — our scale does not legally require it.

When is TaxiBuddy itself the controller? For a few matters that have nothing to do with your taxi company: app performance monitoring, platform security, account management at Auth0 for sign-in. For this limited set, we are the controller.

3. Which data do we process in the app?

a. Account and profile data. At first sign-in and in your profile:

  • First and last name
  • E-mail address (= your sign-in)
  • Phone number
  • Language preference (NL/EN/FR)
  • Role in the taxi company (Administrator or Driver)
  • Technical identity-provider identifier after signing in
  • For drivers: driving licence / taxi pass number

b. Location data (Drivers only). When you start a shift or start/end a ride, the app captures your location once through the standard operating-system API. We take point captures only, at the exact moment of that action — there is no continuous background tracking. Between actions (ride in progress, shift in progress) the app collects no location data. When you close the app or lock the phone, all location processing stops.

Per point capture we store: latitude and longitude (lat/long, accurate to about 10 metres), the moment of capture, and the type of action involved (start of a shift, start of a ride, end of a ride). For the start and end location of a ride we also request a geocoded address through Google Maps Platform (see section 5).

c. Ride and booking data (entered by Admins, viewable by Drivers): passenger's name + phone number + (optional) e-mail/address, number of travellers, planned start time, departure and destination addresses, price agreement, payment method, cancellation reason + who cancelled, free notes. This data is entered by an Admin (dispatcher / fleet manager), not by the passenger. The duty to inform the passenger rests with the taxi company — we provide a template for that.

d. Working-time / shift data. Per shift: driver ID, vehicle ID, start location (lat/long, see b), start and end times, odometer reading (start + end), status (in progress / paused / ended), breaks with timestamps.

e. Vehicle and licence data (viewable by Admins): licence plate, VIN, taxi licence number, make + model, assignment to a driver account.

f. Audit / activity logs. For evidence and dispute management we record who performed which status change (e.g. onboarding, deactivation, company status). Per log line: actor account ID + role, status change (from → to), optional comment, timestamp.

g. Technical data. The app automatically collects: device and OS version (for compatibility debugging), app version, crash logs and performance traces (see section 5 — Microsoft Application Insights). No advertising identifiers. We use no IDFA (iOS) or Android Advertising ID.

4. Why do we use your data?

PurposeWhich dataWho is the controller?Legal basis
Signing you in and assigning your roleAccount dataTaxiBuddy + your taxi companyPerformance of the contract — Art. 6(1)(b)
Planning, executing and settling ridesLocation + ride + shift + vehicleYour taxi companyPerformance of the contract
Statutory ride registration with Chiron (Flemish government)Driving licence number + licence plate + GPS + timestamps + priceYour taxi company (TaxiBuddy = transmitter)Legal obligation — Art. 6(1)(c)
Working-time registration (payroll administration)Shifts + breaksYour taxi companySocial / employment law
Invoicing the subscription to your taxi companyCompany data + IBAN + amountsTaxiBuddyLegal obligation (VAT, accounting)
Keeping the app stable and secureCrash logs + performance dataTaxiBuddyLegitimate interest — Art. 6(1)(f)
Detecting and investigating security incidentsAudit logs + technical dataTaxiBuddy + your taxi companyLegitimate interest + legal obligation

We do not use your data for:

  • Marketing by TaxiBuddy or third parties
  • Profiling with legal effects
  • Sale to third parties
  • Automated decisions affecting your employment relationship

5. Who do we share your data with?

We pass your data on to carefully selected service providers that help us run the platform. We have a data processing agreement with each of them.

Service providerPurposeLocationSafeguard
Auth0 (Okta)Sign-in, password management, role checksEU tenant (Frankfurt)No transfer outside the EEA
Microsoft AzureHosting, database, monitoringEU (West Europe — Amsterdam)No transfer outside the EEA
ResendSending app-related e-mails (invitation, ride tickets, payment instructions)EU (on AWS EU)EU-only processing
OnFact (Infinwebs BV)Invoicing the taxi company subscriptionBelgium (AWS Dublin)No transfer outside the EEA
Google Maps PlatformGeocoding of addresses + route informationUnited StatesEU-US Data Privacy Framework + SCCs
Microsoft Application InsightsPerformance monitoring and crash reportingEU (Azure)Under the Microsoft DPA
Capawesome Cloud (Genz IT Solutions GmbH, DE)Over-the-air app updates (bundle delivery)Germany — Hetzner/Scaleway/Cloudflare CDNDPA, EU-US DPF + SCCs for the Cloudflare transfer

In addition, we transmit ride data to Chiron — the Flemish government system for ride registration of taxi services. Chiron is not a sub-processor: it is a separate controller (public authority) with its own legal regime.

For the complete list of external parties TaxiBuddy uses: see our Sub-processor list.

We do not share your data with:

  • Taxi companies other than your own
  • Marketing or advertising networks
  • Third parties for commercial purposes

6. App permissions — what does the app request on your device?

PermissionWhen is it requested?What do we do with it?Works without it?
Location *(Drivers only)*At the first shift start or ride startRecording point captures at the exact momentNo — without location you cannot start a shift or ride
File accessWhen saving/opening ride tickets or invoices (PDF)Temporary storage in your downloads folderLimited — you will not be able to open PDFs locally
Network connectionContinuously — required for communication with our serversData synchronisationNo

We request no access to:

  • Camera (we do not support photo uploads)
  • Microphone
  • Contacts
  • Calendar
  • SMS
  • Advertising identifiers (IDFA/AAID)

You can withdraw the location permission at any time through your operating system (iOS: *Settings → TaxiBuddy → Location*; Android: *Settings → Apps → TaxiBuddy → Permissions*). This will prevent starting shifts and rides — contact your taxi company in that case.

7. What does the app store on your device itself?

The app stores a limited set of data locally to enable offline use and fast sign-in:

  • Identity-provider session token in secure device storage (not in plain text) — to keep you signed in between sessions
  • Language preference and UI settings in the app's standard preferences storage
  • Temporary copies of opened ride tickets in the downloads folder

The app uses no tracking cookies and no analytics cookies. Cookies belong to the website, not to the mobile app.

When you sign out or delete the app, all local data is erased (except any PDFs you saved yourself in your downloads folder).

8. How long do we keep your data?

Below is a simplified table. The full internal retention policy can be consulted on reasonable request via privacy@taxibuddy.be.

Type of dataRetention period
Driver account (after leaving service)5 years — social law / NSSO
Admin account (after cancellation)3 years — Belgian limitation law
Ride data with GPS (full)7 years — Accounting Act
Ride data without PII (anonymised)year 7 → year 10
Working-time / shift data5 years — NSSO
Customer/passenger contact details7 years after the last ride — Accounting Act
Invoices (TaxiBuddy → your taxi company)10 years — VAT Act
Audit logs of status changes10 years — limitation period
Performance and crash logs (Application Insights)90 days

For your account we apply a soft delete with a 30-day "undo window": when an account is deleted it remains recoverable for 30 days (in case of a mistaken action), after which it is automatically hard-deleted. PII that may not legally be deleted (e.g. through ride records for accounting) is anonymised, not kept under your name.

9. How do we secure your data?

We take appropriate technical and organisational measures:

  • Encryption in transit: all communication between the app and our servers over HTTPS (TLS 1.2 or higher)
  • Encryption at rest: databases at Microsoft Azure use transparent data encryption (TDE)
  • Token-based authentication: every signed-in request is verified
  • Multi-tenant data isolation: a user of company A technically cannot see data of company B
  • Back-office access restriction: only our authorised staff have access, for support
  • Logging without PII: monitoring logs filter out e-mail addresses, IBANs, VAT numbers and phone numbers before storage
  • Soft delete with an "undo window": protects against accidental deletes by support
  • Backups: Azure SQL Point-in-Time Restore (35 days for production)

No system is completely watertight. If a data breach involving your data were ever to occur, we will report it to the Belgian Data Protection Authority within 72 hours and — if there is a high risk to you — also directly to you or to your taxi company (so they can inform you).

10. Which rights do you have?

Under the GDPR you have the following rights over your personal data:

RightWhat it means
Right of access (Art. 15)You can request which data we hold about you
Right to rectification (Art. 16)You can have inaccurate data corrected
Right to erasure (Art. 17, "right to be forgotten")You can ask us to delete your data, except where a statutory retention duty blocks this (e.g. rides in accounting)
Right to restriction (Art. 18)You can ask us to temporarily stop further processing of your data
Right to data portability (Art. 20)You can receive a copy of your data in a machine-readable format
Right to object (Art. 21)You can object to processing based on legitimate interest
Right to lodge a complaintYou can lodge a complaint with the Belgian Data Protection Authority (see section 12)

11. How do you exercise your rights?

First route — through your taxi company (controller): for the vast majority of the data in the app, your taxi company is the responsible party. Contact your Admin or the manager of your taxi company. They can adjust, or arrange to adjust, much of the data directly in the app.

Second route — directly through TaxiBuddy: if your request concerns the TaxiBuddy platform processing (sign-in, security, monitoring), or if your taxi company does not respond, you can contact us directly:

  • E-mail: privacy@taxibuddy.be
  • State: which right you want to exercise, which data it concerns, and how we can verify your identity (e.g. replying from the e-mail address you use in the app)

We handle your request within one month of receipt. For complex requests we may extend this period by a maximum of two months — we will inform you of this within the first month. There is no charge, except for manifestly unfounded or excessive requests.

12. Lodging a complaint with the supervisory authority

You have the right to lodge a complaint with the Belgian Data Protection Authority:

  • Data Protection Authority (GBA/APD)
  • Drukpersstraat 35, 1000 Brussels
  • Tel: +32 2 274 48 00
  • contact@apd-gba.be
  • dataprotectionauthority.be

We recommend contacting your taxi company or us first (privacy@taxibuddy.be) so we can address any concerns directly, but you are of course not obliged to do so.

13. Applicable law and competent court

This privacy notice and all processing we describe in it are governed by Belgian law, supplemented by the directly applicable European General Data Protection Regulation (GDPR).

For disputes that cannot be resolved by mutual agreement or through the Data Protection Authority, the courts of the judicial district of Antwerp, Mechelen division have exclusive jurisdiction.

14. Changes to this notice

When we change this privacy notice, we update the version number and the date at the top of this page. For significant changes (such as new processing purposes, new sub-processors or new permissions) we show the updated notice again in the app, asking you to take note of it.