Privacy Policy for Passengers
This policy is information provided under Art. 13 and 14 GDPR. It is not a consent and does not require your acceptance.
1. Controller and Data Protection Requests
Controller within the meaning of the General Data Protection Regulation (GDPR):
Emaride EU S.à r.l. société à responsabilité limitée under Luxembourg law represented by its sole manager Tobias Felten Luxembourg Trade register (RCS): registration pending VAT (TVA): registration pending Email: info@emaride.lu
Data protection requests: privacy@emaride.lu
A data protection officer has not been appointed at present. Assessing whether an appointment is required under Art. 37 GDPR, and the appointment itself, are open items before go-live. Until then, privacy@emaride.lu is the responsible point of contact.
2. Scope
This policy applies to the processing of personal data of passengers ("Customers") in connection with the Emaride app and website (together the "Platform") — for private passengers and for passengers booking through a business customer account.
Separate notices apply to other roles:
- Drivers:
datenschutz-fahrer(privacy notice for drivers) - Contact persons of fleet partners and business customers:
datenschutz-partner
3. Categories of Data Processed
We only process data necessary for rides, payment and support — and, subject to your consent, the data for advertising measurement on our public marketing pages named in Section 9:
| Category | Examples |
|---|---|
| Master / account data | name, email, phone number, password (hashed), language setting |
| Profile and address data | saved addresses (max. 3), preferred settings |
| Location data | pickup and destination, GPS position during an active ride |
| Ride data | bookings, route, timestamps, status, OTP/QR verification, no-show events |
| Payment data | payment method (token, max. 3), transaction and invoice data, tips |
| Ratings | ratings given by you and given about you |
| Support / communication data | tickets, chat logs with (possibly AI-assisted) support |
| Device and usage data | device and app version, push token, log and error data |
Full payment card data is not stored by us but processed exclusively by the payment provider (see Section 5).
4. Purposes and Legal Bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Provision of the Platform, arranging and handling rides | Art. 6(1)(b) (contract) |
| Location processing to carry out the ride (pickup, routing, safety) | Art. 6(1)(b) (contract) |
| OTP/QR verification at the start of the ride | Art. 6(1)(b) (contract) |
| Payment processing, invoicing | Art. 6(1)(b) and (c) (legal obligation) |
| Retention of invoice/tax records | Art. 6(1)(c) (legal obligation) |
| Fraud prevention, abuse/penalty checks, safety | Art. 6(1)(f) (legitimate interest) |
| Support and communication | Art. 6(1)(b) and (f) |
| Push and in-app notifications about your rides and payments | Art. 6(1)(b) (contract) |
| Ratings (trust and quality in the marketplace) | Art. 6(1)(f) |
| Logging of security- and billing-relevant events | Art. 6(1)(f) |
| Reach and advertising measurement on the public marketing pages (Section 9) | Art. 6(1)(a) (consent) |
Notifications are strictly transactional — ride status, vehicle arrival, payment and support events. We do not send advertising or marketing messages. The legal basis is therefore Art. 6(1)(b) (performance of the contract) and not Art. 6(1)(a); there is no marketing dispatch for which consent would have to be obtained. You can additionally turn push messages off at any time in your device settings.
For product improvement and internal reporting we use anonymised data with no link to an identifiable person — for example ride counts per area and time slot. Such reporting takes place exclusively within our own system, without any external analytics or tracking service, without recognising individuals and without profiling. As soon as data could be linked to a person, it would no longer be anonymous reporting and the processing would fall under one of the purposes listed above.
5. Recipients and Processors
Subcontractors and drivers are separate controllers
Fleet partners (subcontractors) and drivers are not processors of Emaride. They pursue their own purposes — the transport contract in their own name, dispatching, payroll, their own tax obligations — and are therefore separate controllers within the meaning of Art. 4(7) GDPR. The transfer of your ride data to them is consequently a controller-to-controller transfer on the basis of Art. 6(1)(b) and (f) GDPR and not processing on our behalf under Art. 28 GDPR. For their own processing — retention, access, erasure — the respective partner is responsible towards you; on request we will name the partner responsible for your ride.
We share data with these recipients to the extent necessary — with Meta exclusively after your consent:
Subcontractors and drivers — to carry out the booked ride. The assigned Driver receives: first name, phone number (for the call/SMS contact), pickup and destination address including coordinates, verification status, the average and number of your ratings as a passenger, the number of your completed rides and an indicator of the payment type (card payment). Not transmitted: email address, surname, card details, saved addresses, rating texts and data from other rides.
Rating average, ride count and phone number are loaded before the ride is accepted; a Driver who declines has therefore seen them. We consider this to require review and have recorded it as an open point in our record of processing activities.
Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland — reach and advertising measurement on the public marketing pages, exclusively after your consent (Section 9). Meta is a joint controller with us under Art. 26 GDPR and not our processor; the transfer therefore does not appear in the table below.
Authorities — where legally required.
Processors (Art. 28 GDPR)
In addition, we engage the following processors, which act exclusively on our instructions:
| Service | Purpose | Location | Basis |
|---|---|---|---|
| Supabase | Hosting, database, auth, storage | EU (Frankfurt) | DPA |
| Stripe | Payment processing (Merchant of Record) | US/IE | DPA + SCC |
| Google Maps Platform | Maps, geocoding, routing | US | DPA + SCC |
| Mapbox | Map rendering (web) | US | DPA + SCC |
| Resend | Transactional email, ride OTP | US | DPA + SCC |
| Twilio (via Supabase Auth) | SMS delivery for phone-login OTP (not the ride verification, which is delivered by email via Resend) | US | DPA + SCC |
| OpenAI | Regulatory digest, AI ticket triage; the transmitted content is not stored with the processor | US | DPA + SCC |
| Expo | Push notifications | US | DPA + SCC |
| Vercel | Web dashboard and landing page hosting | US | DPA + SCC |
| Apple | Single sign-on (optional) | US | DPA + SCC |
| Single sign-on (optional) | US | DPA + SCC |
Emaride itself does not hold or control any Fare funds; cashless card payments are processed exclusively through Stripe as a licensed payment provider and merchant of record.
The "Basis" column describes the contractual requirement for each processor engaged, not the status currently achieved: for processing within the EU, a data processing agreement (DPA) under Art. 28 GDPR is envisaged, and for transfers to third countries, EU Standard Contractual Clauses (SCC) under Chapter V GDPR are additionally envisaged. Concluding these agreements with the respective providers is a prerequisite for the Platform going live.
On our public marketing pages we use the Meta pixel after you have given your consent (see Section 9). For this reach and advertising measurement we are a joint controller together with Meta Platforms Ireland Ltd., Merrion Road, Dublin 4, Ireland (Art. 26 GDPR). Meta additionally processes the data collected in the process for its own purposes and may build profiles for advertising purposes from it; we have no influence over that. No such measurement takes place in the logged-in area of the Platform or in the app, and no profiles for advertising purposes are built there.
6. International Transfers
Insofar as data is transferred to countries outside the EEA (see the "Location" column in Section 5 as well as the onward transfer to Meta in the USA described in Section 9), this only takes place on the basis of appropriate safeguards under Chapter V GDPR, in particular the EU Standard Contractual Clauses or an adequacy decision of the EU Commission. Our own data storage takes place in the EU (Frankfurt).
7. Retention Periods
| Data | Period |
|---|---|
| Account and profile data | for the duration of the usage relationship; anonymisation upon your request |
| GPS coordinates of a ride (origin, destination) | 24 months, then irreversibly removed |
| Pickup and destination address of a ride | 10 years (description of the invoiced service, see below) |
| Invoice and transaction data | 10 years (commercial and tax law retention) |
| Support tickets and chat content | 24 months after the matter is closed, then the content is removed |
| OTP code for ride verification | deleted immediately after verification (at the latest after 1 day) |
| Notifications (push/in-app) | 90 days |
| Log data | 24 months |
| Last vehicle position of a driver | deleted 30 days after the last update |
| Export file for the access request (Section 11) | 8 days; the download link is valid for 7 days |
Ride data is treated in two stages. After 24 months we irreversibly remove the metre-accurate GPS coordinates of a ride — that is the intrusive part and it serves no tax purpose. The pickup and destination address, by contrast, is retained for 10 years: our invoice records contain no address, which makes the ride address the only description of the invoiced service. Overwriting it would gut a record we are required to keep.
We do not carry out automatic deletion of your account for inactivity — we expressly do not promise it here. Your account is deleted or anonymised when you request it (in the app or via privacy@emaride.lu). Invoice data subject to statutory retention is kept in the legally required form.
8. Location Data in Detail
During an active ride we process location data to ensure pickup, routing and safety. Background location data is only collected to the extent you permit it in your device settings. You can disable location sharing at any time via your device; certain functions may then be limited.
9. Cookies and Similar Technologies
On the website we set strictly necessary cookies and — only after your consent — cookies for advertising measurement.
Strictly necessary:
| Cookie | Purpose | Storage period |
|---|---|---|
emaride_lang |
stores the display language you selected | 1 year |
emaride_consent |
stores your decision about advertising measurement | 180 days |
Supabase auth session (sb-…-auth-token) |
keeps you signed in after login and protects the session | session, or until the sign-in token expires or is revoked |
emaride_remember |
stores your "remember me" choice and thereby the lifetime of the sign-in | session if "no", otherwise up to 400 days |
No consent is required for these cookies. The exemption in § 25(2) TDDDG applies
(strictly necessary in order to provide a telemedia service expressly requested by you);
the corresponding exemption under Luxembourg law applies in the same way. The
emaride_consent cookie is also necessary when you decline — it is the only way for us to
honour your refusal.
Only after your consent — the Meta pixel:
| Cookie | Purpose | Storage period |
|---|---|---|
_fbp (Meta) |
recognises your browser again in order to measure how our ads perform | 90 days |
_fbc (Meta) |
stores the identifier of the ad you arrived through | 90 days |
The Meta pixel runs exclusively on our public marketing pages — the home page and the page about our WhatsApp channel. We do not use it in the logged-in area of the Platform or in the app.
The legal basis is your consent under § 25(1) TDDDG and Art. 6(1)(a) GDPR. As long as you have not consented, no script from Meta is loaded and no data is transferred to Meta — not even if you leave the dialog unanswered. If you consent, your IP address, the page requested, the referring page and the identifiers named above are transferred to Meta Platforms Ireland Ltd.; Meta may forward this data to the USA (adequacy decision EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses).
We store your decision exclusively in the emaride_consent cookie on your device. We keep
no server-side consent record: on these pages you are not known to us, and a record would
be what first created an identifier about you.
You can withdraw your consent at any time with effect for the future. At the bottom of the marketing pages you will permanently find the "Cookie settings" button; one click reopens the dialog. Withdrawing is just as easy as consenting and has no disadvantages for you.
In the app we use functional storage on the device — for the login, the language setting and recently used settings. These are likewise necessary to operate the app.
10. Automated Decisions (Art. 22 GDPR)
Two processes on the Platform are prepared automatically:
- the penalty check for cancellations and no-show events, and
- the automatic suspension ("auto-lock") when mandatory documents expire or the highest penalty level is reached.
Measures with a significant effect on you — in particular the restriction or suspension of your account — are not taken solely by automated means. You are entitled to:
- human intervention and review by a person at Emaride,
- the right to express your point of view, and
- the right to contest the decision.
The measure is communicated to you with a statement of reasons in a reviewable manner; an objection can be raised via privacy@emaride.lu or through support in the app and is reviewed by a person.
No profiling for advertising purposes is carried out by us. If you have consented to the Meta pixel (Section 9), Meta may build its own advertising profiles from the data collected in the process; we have no influence over that processing.
11. Your Rights
Under the GDPR you have the right to:
- access (Art. 15),
- rectification (Art. 16),
- erasure / anonymisation (Art. 17),
- restriction of processing (Art. 18),
- data portability (Art. 20),
- object to processing based on legitimate interests (Art. 21),
- withdraw consent given (Art. 7(3)), insofar as processing is based on consent.
For the access request under Art. 15 we provide a data export in the app and in your account: you trigger it yourself and receive a file containing your account data, rides, payments and support matters. The export file is deleted after 8 days and the download link is valid for 7 days. You can also trigger the anonymisation of your account directly in the app. For everything else, contact privacy@emaride.lu.
Joint controllership with Meta. For the advertising measurement on the public marketing pages (Sections 5 and 9) we are a joint controller together with Meta Platforms Ireland Ltd. You may therefore assert your rights both against us and directly against Meta (Art. 26(3) GDPR); the information on Meta's own processing can be found in Meta's privacy policy. We will make the essence of the arrangement under Art. 26(2) GDPR available to you on request at privacy@emaride.lu; concluding it is — as with the provider agreements in Section 5 — a prerequisite for going live.
12. Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority in Luxembourg is the
Commission nationale pour la protection des données (CNPD) 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg <https://cnpd.public.lu>
As the controller is established in Luxembourg, the CNPD is the lead supervisory authority under the one-stop-shop (Art. 56 GDPR). Data subjects resident in Germany may additionally lodge a complaint with their local data protection authority (Landesdatenschutzbehörde) at any time (Art. 77 GDPR).
13. Data Security
We use appropriate technical and organisational measures (including encryption in transit, access controls by role and country, hashed passwords) to protect your data (Art. 32 GDPR).
14. Changes to This Privacy Policy
We may adjust this policy to reflect changes in the law or in functionality. The current version is available in the app and on the website; it carries a version number and an effective date.
15. Deviations from the V2.1 Legal Package
This version follows the V2.1 Legal Package. Where it deviates, it does so because the policy may only promise what the product actually does:
| V2.1 Part | Our section | Deviation and reason |
|---|---|---|
| Part A — Privacy Notice Passengers | Sections 1–14 | Adopted. Extended by Section 2 (explicit passenger scope with references to the notices for drivers and partners), because those roles have separate documents. |
| Part C / Part K — role of the fleet partners | Section 5 (intro) | Fleet partners and drivers are expressly treated as separate controllers, the transfer as controller-to-controller under Art. 6(1)(b)/(f) — not as processing under Art. 28. |
| Part D — cookies and consent | Section 9 | The Meta pixel runs on the public marketing pages — exclusively after prior consent given through a dialog with equivalent buttons. No advertising measurement takes place in the logged-in area or in the app. |
| Part D — consent logs (12 months) | Section 7 | Deliberate deviation. Consent is stored only in the emaride_consent cookie on the data subject's device, not recorded server-side: on the pages concerned there is no identification, and a record would be what first created an identifier. |
| Part E.2 — ride and location data (24 months) | Section 7 | Implemented in two stages: GPS coordinates 24 months, pickup/destination address 10 years. Our invoice records contain no address, so the ride address is the only description of the service on a record we keep. |
| Part E.2 — active account + 12 months / inactive account 24 m. | Section 7 | Not promised. Automatic deletion for inactivity is not implemented; deletion and anonymisation happen exclusively upon request. |
| Part E.2 — support data | Section 7 | 24 months after closure (version 1.2 said "up to 3 years"). 24 months matches the implemented period. |
| Part E.2 — marketing consent (until withdrawal + 36 months) | Sections 4 and 7 | Not applicable: there is no marketing dispatch and therefore no marketing consent to retain. All notifications are transactional, legal basis Art. 6(1)(b) — not (a) as in version 1.2. The consent for advertising measurement (Section 9) is separate; it is stored exclusively in the cookie on the device. |
| Part E.2 — litigation hold | Section 7 | Not listed: a procedure suspending retention periods for pending disputes does not exist in the product. It is therefore not claimed here. |