Skip to main content

Privacy Policy

Last updated: September 15, 2026

These principles explain what personal data the GL-TAXI platform processes when you use our public website, mobile app or admin console, why we process it, who we share it with, and what rights you have. This document is an engineering-prepared draft based on the product's actually implemented functionality.

Controller and contact

The GL-TAXI platform is operated by:

Legal name
Hashlab s. r. o.
Registered address
Juraja Sklenára 100/29, 052 01 Spišské Tomášovce
Company registration number
52575420
VAT ID
SK2121069203
Commercial register entry
Mestský súd Košice, oddiel Sro, vložka č. 46939/V
Privacy contact
informacie@lovepix.sk
Contents

1. Categories of data subjects

These principles apply to: riders and customers who book rides, reservations or goods deliveries; drivers; taxi-company (tenant) administrators and their companies; visitors of the public website; and contact persons who reach us through the "for taxi companies" partner-enquiry form.

2. Account and authentication data

Your account holds your email, phone number, first and last name, role (customer, driver, administrator) and preferred language. Sign-in is handled by Supabase Auth and your account is linked to it. We also record when your password was set and your age confirmation at registration. A driver's own name, phone and email live only on this one account record and are never duplicated elsewhere.

3. Rides and reservations

When you request a ride or make a reservation, we store the pickup and drop-off location (coordinates and address), the requested or scheduled time, the fare, distance, duration and status, linked to your account and the driver's. The fare quote shown before you confirm additionally stores the raw coordinates and addresses you entered.

4. Goods delivery

When you place a delivery order, we store the delivery address and coordinates. For goods flagged as age-restricted, the delivering driver confirms the recipient's age at the point of delivery — beyond this confirmation record, we do not collect any identity document.

5. Precise location (GPS)

The mobile app requests location only in the foreground, never in the background. We use it to: (1) prefill your pickup point, only if you tap "use my location" yourself; (2) while a driver is on an active trip, stream their live position to that trip's customer so you can see them approaching; (3) while a driver is online and available (not on a trip), report their approximate position roughly every 2 minutes so dispatch can find the nearest available driver. Driver location pings are stored for 90 days and then automatically deleted.

6. Messages (chat)

During a trip, the customer and driver can message each other in the app. We store the message text, sender and time sent so both sides have the trip's message history. No read-receipt is recorded.

7. Ratings

After a ride or delivery, a rating score and an optional comment may be recorded for a driver.

8. Payments

Payments are processed by Stripe. We never receive or store your full card number or CVC — those stay with Stripe. What we do store: a Stripe customer reference, a Stripe payment/refund reference, and display-safe card metadata such as the card brand and last 4 digits — the same applies to a card you save for future use. To be explicit: full payment-card data is not stored by GL-TAXI.

9. Uploads

Today the only file-upload feature in the product is product-image uploads used by taxi-company administrators managing their catalog in the admin console. There is no rider- or driver-submitted photo or document upload feature. Uploaded images are stored in Supabase Storage.

10. Push notifications

The mobile app registers a per-device push token (Expo) so we can send trip/order notifications (e.g. driver assigned, driver arriving). The token is linked to your account and tenant and is kept until you sign out or disable notifications, at which point it is unregistered.

11. Error reporting and technical telemetry

We use Sentry to catch application errors and performance issues across the web app, admin console and mobile app. It is configured to not collect cookies, request/response headers, request bodies, URL query parameters or GraphQL variables, and phone numbers, coordinates, one-time codes, tokens and similar secrets are stripped from every event before it is sent. We do not use session replay/screen recording.

12. Partner enquiries

If you contact us through the "for taxi companies" form, we store your company name, contact person, email, phone, city/region, fleet size and your message, together with the time you gave consent and the version of this notice you agreed to. This data is kept for up to 365 days from submission and then automatically deleted by a daily job, unless we need to keep it longer for a legitimate business reason (e.g. an ongoing partnership discussion) or a legal obligation.

13. Maps and address lookup (Google)

To calculate routes, look up addresses and render maps, our server calls Google's Places, Geocoding and Routes APIs, sending the coordinates/addresses involved in your request. The mobile app itself holds no direct Google API key and never calls Google directly — on Android it uses a separate key only for rendering map tiles; on iOS, map tiles come from Apple Maps instead.

14. Recipients and sub-processors

Data is processed on our behalf by: Supabase (authentication, database hosting, file storage), Stripe (payment processing), Google (maps, address lookup, routing), Expo (push notification delivery) and Sentry (error monitoring). For phone-based sign-in, Supabase Auth uses Twilio solely to deliver a one-time SMS login code — our own backend never calls Twilio directly. Taxi-company (tenant) administrators only see their own tenant's data in the console, never another tenant's.

15. International data transfers

Some of the sub-processors above (Stripe, Google, Sentry) may process data on infrastructure located outside the EU/EEA depending on their own regional configuration. Where that happens, the transfer is safeguarded by the European Commission's Standard Contractual Clauses or another legally recognized transfer mechanism under that sub-processor's own data processing agreement.

16. Retention periods

Several retention periods are enforced in code today. Driver location pings are kept for 90 days, and partner enquiries for up to 365 days (see above), before automatic deletion. Ride, reservation, and goods-delivery records keep their financial details for accounting purposes, but their precise pickup/drop-off location and address are automatically cleared after 2 years. Chat messages are automatically deleted after 180 days. Ordinary in-app notifications are deleted after 90 days; notifications created as part of an administrator broadcast are retained with the associated broadcast audit record for up to 365 days. Account records have no automatic, time-based deletion, but you can delete your own account at any time (see "How to delete your account" below), which erases it immediately rather than waiting out a retention period. Rating records (scores and comments you or a driver left) currently have no deletion mechanism at all, automatic or on request, and are not affected by deleting your account.

17. Purposes and legal bases for processing

We process account, ride, reservation, delivery, payment and chat data to perform the contract you enter into by requesting a ride, reservation or delivery (Art. 6(1)(b) GDPR). Device/error telemetry and driver-location/dispatch data are processed on the basis of our legitimate interest in operating a reliable, secure service (Art. 6(1)(f)). Where you submit the partner-enquiry form, we process your data based on the consent you give by checking the consent box (Art. 6(1)(a)), which you may withdraw at any time by contacting us, without affecting the lawfulness of processing carried out before the withdrawal.

18. Automated decision-making

When you request a ride or delivery, our dispatch system automatically assigns the request to an available nearby driver based on their reported position — this is an operational routing/logistics function, not an automated evaluation of your personal characteristics, and it does not produce legal or similarly significant effects on you within the meaning of Art. 22 GDPR. We do not otherwise use profiling or automated decision-making about you.

19. Minors and age-restricted goods

Account registration requires confirming you meet the applicable age requirement at sign-up. Separately, for goods orders flagged as age-restricted, the delivering driver confirms the recipient's age at the point of delivery, independent of the account-level confirmation above. The service is not directed at children.

20. Your rights

In connection with the processing of your personal data, you have the right to access, rectification, erasure, restriction of processing, objection to processing, data portability, and — where consent is the legal basis — to withdraw it at any time, without affecting the lawfulness of processing before the withdrawal. You can exercise your rights at the contact address above.

21. How to delete your account

You can delete your own account directly in the mobile app: Profile → Account → Delete Account, then confirm. This is refused, with a clear reason, while you have a ride, reservation or delivery in progress, or — for a driver — while you're on an active trip; finish or cancel it first. Once it goes through, your profile, saved payment methods and notification settings are removed straight away and you're signed out. Past rides and deliveries stay in our records for accounting purposes, but they no longer show your name, email, phone number, or exact pickup/drop-off or delivery location once your account is deleted. Deleting your account does not remove ratings you've given or received, or chat messages you sent — those follow the retention described above. If you'd rather not use the in-app flow, or the app doesn't cover something you need erased, contact us at the address above and we'll handle it directly.

22. Complaint to a supervisory authority

If you believe the processing of your personal data breaches applicable rules, you have the right to lodge a complaint with the Slovak Data Protection Authority (Úrad na ochranu osobných údajov Slovenskej republiky), Galvaniho Business Centrum II, Galvaniho 7/B, 821 04 Bratislava, Slovakia, https://dataprotection.gov.sk, tel.: +421 2 3231 3214, email: statny.dozor@pdp.gov.sk.

23. Platform and taxi-company relationship

GL-TAXI is a multi-tenant platform: each taxi company (tenant) operates within its own isolated data scope, and its administrators only see their own tenant's rides, drivers and orders — never another tenant's. The precise legal characterization of GL-TAXI and each taxi-company tenant (joint controllers, independent controllers, or controller/processor for tenant-scoped data) has not yet been determined.

24. Changes to this policy

We may update these principles from time to time. Changes are posted on this page with a new date/version; material changes may require renewed consent where processing is based on consent (e.g. the partner-enquiry form's consent checkbox).