1. What is this notice about?
This notice explains which personal data we process when you use the TaxiBuddy mobile app as a driver or as an administrator of a taxi company — why we process it, who we share it with, how long we keep it and which rights you have.
This notice does not apply to:
- The use of the public website taxibuddy.be — see the Website Privacy Notice.
- Cookies and analytics on the website — see the Cookie Notice.
- Passengers of the taxi company — they receive their information through their taxi company.
2. Who are we — and who is your controller?
Important difference from the website notice: for the vast majority of the data we process through the app, your taxi company is the controller and we are the processor. We process your data on behalf of your taxi company, under a data processing agreement (DPA).
| Item | Value |
|---|---|
| Processor | Cools IT Solutions BV — trading under the name TaxiBuddy |
| Address | Dorp 4E bus 021, 2820 Bonheiden, Belgium |
| KBO + VAT | BE 0803.017.171 |
| Managing director + privacy contact | Jarno Cools |
| Contact (all questions) | privacy@taxibuddy.be |
| Controller | Your taxi company — name visible in the app under *Profile → Company* |
We have not appointed a formal Data Protection Officer (DPO) — our scale does not legally require it.
When is TaxiBuddy itself the controller? For a few matters that have nothing to do with your taxi company: app performance monitoring, platform security, account management at Auth0 for sign-in. For this limited set, we are the controller.
3. Which data do we process in the app?
a. Account and profile data. At first sign-in and in your profile:
- First and last name
- E-mail address (= your sign-in)
- Phone number
- Language preference (NL/EN/FR)
- Role in the taxi company (Administrator or Driver)
- Technical identity-provider identifier after signing in
- For drivers: driving licence / taxi pass number
b. Location data (Drivers only). When you start a shift or start/end a ride, the app captures your location once through the standard operating-system API. We take point captures only, at the exact moment of that action — there is no continuous background tracking. Between actions (ride in progress, shift in progress) the app collects no location data. When you close the app or lock the phone, all location processing stops.
Per point capture we store: latitude and longitude (lat/long, accurate to about 10 metres), the moment of capture, and the type of action involved (start of a shift, start of a ride, end of a ride). For the start and end location of a ride we also request a geocoded address through Google Maps Platform (see section 5).
c. Ride and booking data (entered by Admins, viewable by Drivers): passenger's name + phone number + (optional) e-mail/address, number of travellers, planned start time, departure and destination addresses, price agreement, payment method, cancellation reason + who cancelled, free notes. This data is entered by an Admin (dispatcher / fleet manager), not by the passenger. The duty to inform the passenger rests with the taxi company — we provide a template for that.
d. Working-time / shift data. Per shift: driver ID, vehicle ID, start location (lat/long, see b), start and end times, odometer reading (start + end), status (in progress / paused / ended), breaks with timestamps.
e. Vehicle and licence data (viewable by Admins): licence plate, VIN, taxi licence number, make + model, assignment to a driver account.
f. Audit / activity logs. For evidence and dispute management we record who performed which status change (e.g. onboarding, deactivation, company status). Per log line: actor account ID + role, status change (from → to), optional comment, timestamp.
g. Technical data. The app automatically collects: device and OS version (for compatibility debugging), app version, crash logs and performance traces (see section 5 — Microsoft Application Insights). No advertising identifiers. We use no IDFA (iOS) or Android Advertising ID.
4. Why do we use your data?
| Purpose | Which data | Who is the controller? | Legal basis |
|---|---|---|---|
| Signing you in and assigning your role | Account data | TaxiBuddy + your taxi company | Performance of the contract — Art. 6(1)(b) |
| Planning, executing and settling rides | Location + ride + shift + vehicle | Your taxi company | Performance of the contract |
| Statutory ride registration with Chiron (Flemish government) | Driving licence number + licence plate + GPS + timestamps + price | Your taxi company (TaxiBuddy = transmitter) | Legal obligation — Art. 6(1)(c) |
| Working-time registration (payroll administration) | Shifts + breaks | Your taxi company | Social / employment law |
| Invoicing the subscription to your taxi company | Company data + IBAN + amounts | TaxiBuddy | Legal obligation (VAT, accounting) |
| Keeping the app stable and secure | Crash logs + performance data | TaxiBuddy | Legitimate interest — Art. 6(1)(f) |
| Detecting and investigating security incidents | Audit logs + technical data | TaxiBuddy + your taxi company | Legitimate interest + legal obligation |
We do not use your data for:
- Marketing by TaxiBuddy or third parties
- Profiling with legal effects
- Sale to third parties
- Automated decisions affecting your employment relationship
5. Who do we share your data with?
We pass your data on to carefully selected service providers that help us run the platform. We have a data processing agreement with each of them.
| Service provider | Purpose | Location | Safeguard |
|---|---|---|---|
| Auth0 (Okta) | Sign-in, password management, role checks | EU tenant (Frankfurt) | No transfer outside the EEA |
| Microsoft Azure | Hosting, database, monitoring | EU (West Europe — Amsterdam) | No transfer outside the EEA |
| Resend | Sending app-related e-mails (invitation, ride tickets, payment instructions) | EU (on AWS EU) | EU-only processing |
| OnFact (Infinwebs BV) | Invoicing the taxi company subscription | Belgium (AWS Dublin) | No transfer outside the EEA |
| Google Maps Platform | Geocoding of addresses + route information | United States | EU-US Data Privacy Framework + SCCs |
| Microsoft Application Insights | Performance monitoring and crash reporting | EU (Azure) | Under the Microsoft DPA |
| Capawesome Cloud (Genz IT Solutions GmbH, DE) | Over-the-air app updates (bundle delivery) | Germany — Hetzner/Scaleway/Cloudflare CDN | DPA, EU-US DPF + SCCs for the Cloudflare transfer |
In addition, we transmit ride data to Chiron — the Flemish government system for ride registration of taxi services. Chiron is not a sub-processor: it is a separate controller (public authority) with its own legal regime.
For the complete list of external parties TaxiBuddy uses: see our Sub-processor list.
We do not share your data with:
- Taxi companies other than your own
- Marketing or advertising networks
- Third parties for commercial purposes
6. App permissions — what does the app request on your device?
| Permission | When is it requested? | What do we do with it? | Works without it? |
|---|---|---|---|
| Location *(Drivers only)* | At the first shift start or ride start | Recording point captures at the exact moment | No — without location you cannot start a shift or ride |
| File access | When saving/opening ride tickets or invoices (PDF) | Temporary storage in your downloads folder | Limited — you will not be able to open PDFs locally |
| Network connection | Continuously — required for communication with our servers | Data synchronisation | No |
We request no access to:
- Camera (we do not support photo uploads)
- Microphone
- Contacts
- Calendar
- SMS
- Advertising identifiers (IDFA/AAID)
You can withdraw the location permission at any time through your operating system (iOS: *Settings → TaxiBuddy → Location*; Android: *Settings → Apps → TaxiBuddy → Permissions*). This will prevent starting shifts and rides — contact your taxi company in that case.
7. What does the app store on your device itself?
The app stores a limited set of data locally to enable offline use and fast sign-in:
- Identity-provider session token in secure device storage (not in plain text) — to keep you signed in between sessions
- Language preference and UI settings in the app's standard preferences storage
- Temporary copies of opened ride tickets in the downloads folder
The app uses no tracking cookies and no analytics cookies. Cookies belong to the website, not to the mobile app.
When you sign out or delete the app, all local data is erased (except any PDFs you saved yourself in your downloads folder).
8. How long do we keep your data?
Below is a simplified table. The full internal retention policy can be consulted on reasonable request via privacy@taxibuddy.be.
| Type of data | Retention period |
|---|---|
| Driver account (after leaving service) | 5 years — social law / NSSO |
| Admin account (after cancellation) | 3 years — Belgian limitation law |
| Ride data with GPS (full) | 7 years — Accounting Act |
| Ride data without PII (anonymised) | year 7 → year 10 |
| Working-time / shift data | 5 years — NSSO |
| Customer/passenger contact details | 7 years after the last ride — Accounting Act |
| Invoices (TaxiBuddy → your taxi company) | 10 years — VAT Act |
| Audit logs of status changes | 10 years — limitation period |
| Performance and crash logs (Application Insights) | 90 days |
For your account we apply a soft delete with a 30-day "undo window": when an account is deleted it remains recoverable for 30 days (in case of a mistaken action), after which it is automatically hard-deleted. PII that may not legally be deleted (e.g. through ride records for accounting) is anonymised, not kept under your name.
9. How do we secure your data?
We take appropriate technical and organisational measures:
- Encryption in transit: all communication between the app and our servers over HTTPS (TLS 1.2 or higher)
- Encryption at rest: databases at Microsoft Azure use transparent data encryption (TDE)
- Token-based authentication: every signed-in request is verified
- Multi-tenant data isolation: a user of company A technically cannot see data of company B
- Back-office access restriction: only our authorised staff have access, for support
- Logging without PII: monitoring logs filter out e-mail addresses, IBANs, VAT numbers and phone numbers before storage
- Soft delete with an "undo window": protects against accidental deletes by support
- Backups: Azure SQL Point-in-Time Restore (35 days for production)
No system is completely watertight. If a data breach involving your data were ever to occur, we will report it to the Belgian Data Protection Authority within 72 hours and — if there is a high risk to you — also directly to you or to your taxi company (so they can inform you).
10. Which rights do you have?
Under the GDPR you have the following rights over your personal data:
| Right | What it means |
|---|---|
| Right of access (Art. 15) | You can request which data we hold about you |
| Right to rectification (Art. 16) | You can have inaccurate data corrected |
| Right to erasure (Art. 17, "right to be forgotten") | You can ask us to delete your data, except where a statutory retention duty blocks this (e.g. rides in accounting) |
| Right to restriction (Art. 18) | You can ask us to temporarily stop further processing of your data |
| Right to data portability (Art. 20) | You can receive a copy of your data in a machine-readable format |
| Right to object (Art. 21) | You can object to processing based on legitimate interest |
| Right to lodge a complaint | You can lodge a complaint with the Belgian Data Protection Authority (see section 12) |
11. How do you exercise your rights?
First route — through your taxi company (controller): for the vast majority of the data in the app, your taxi company is the responsible party. Contact your Admin or the manager of your taxi company. They can adjust, or arrange to adjust, much of the data directly in the app.
Second route — directly through TaxiBuddy: if your request concerns the TaxiBuddy platform processing (sign-in, security, monitoring), or if your taxi company does not respond, you can contact us directly:
- E-mail: privacy@taxibuddy.be
- State: which right you want to exercise, which data it concerns, and how we can verify your identity (e.g. replying from the e-mail address you use in the app)
We handle your request within one month of receipt. For complex requests we may extend this period by a maximum of two months — we will inform you of this within the first month. There is no charge, except for manifestly unfounded or excessive requests.
12. Lodging a complaint with the supervisory authority
You have the right to lodge a complaint with the Belgian Data Protection Authority:
- Data Protection Authority (GBA/APD)
- Drukpersstraat 35, 1000 Brussels
- Tel: +32 2 274 48 00
- contact@apd-gba.be
- dataprotectionauthority.be
We recommend contacting your taxi company or us first (privacy@taxibuddy.be) so we can address any concerns directly, but you are of course not obliged to do so.
13. Applicable law and competent court
This privacy notice and all processing we describe in it are governed by Belgian law, supplemented by the directly applicable European General Data Protection Regulation (GDPR).
For disputes that cannot be resolved by mutual agreement or through the Data Protection Authority, the courts of the judicial district of Antwerp, Mechelen division have exclusive jurisdiction.
14. Changes to this notice
When we change this privacy notice, we update the version number and the date at the top of this page. For significant changes (such as new processing purposes, new sub-processors or new permissions) we show the updated notice again in the app, asking you to take note of it.