Personal data protection
Privacy Policy
This policy covers the passenger app, passenger PWA and public CroCab web forms. Driver-account processing is covered by a separate CroCab Driver policy.
This policy explains what information CroCab processes, why it is needed and what rights you have.
This English text is provided for convenience. The Croatian version is authoritative.
Controller
Information we process
- account details such as name, contact information and data required for secure sign-in
- ride, reservation and web-request details such as pickup, destination, up to three selected intermediate stops, the internally selected recommended route and geometry, distance, duration, price and discount, requested time, category, services, notes, acceptance status and driver departure deadline
- active-ride revisions: previous and proposed stops, route and price, the passenger's decision and the driver's acknowledgement of an accepted amendment
- incident and continuation details: incident type, time and location, the driver's and passenger's choices, frozen distance and duration, individual CroCab driver/vehicle/partner legs, replacement search and safety holds
- payment and fiscal details needed for one passenger receipt, including the calculated partial or full amount, cash or card choice, collection result, any outstanding debt, the single billing partner, operating partners, internal partner settlement and the single CroCab commission
- persistent ride-comfort preferences: a cooler or warmer cabin, a quiet ride without conversation and music switched off; passengers may change or clear these preferences in the app
- passenger location after the passenger's action and with Android-device or browser permission; while the app is visible, a GPS pickup may be refreshed before arrival, and during an active ride the passenger's current location is refreshed to show movement consistently to the passenger and only the assigned driver, without passenger background tracking
- technical and security information including the notification device or browser, sign-in records, installation identifier, necessary local session and preference storage, abuse prevention and system protection data
- stability diagnostics including crash and ANR reports, stack traces, app version, device and operating-system details, and random installation and session identifiers
- ratings, comments, enquiries and complaints
- future pilot-partner survey answers, including entered work-city names but no address, precise location, name, contact detail, CroCab account, IP address, user-agent or browser fingerprint
- contact and business details a transport provider voluntarily submits through the separate permanent partner application
Purposes
- creating and maintaining accounts
- receiving web requests and organising, confirming, assigning and tracking rides or reservations
- ride communication, support and complaints
- security, abuse prevention and legal compliance
- accounting, tax and transport obligations where applicable
Legal bases
We process information required to respond to a request, make arrangements and organise a ride in order to take steps at your request and perform a contract. Security records, abuse prevention and necessary technical diagnostics are processed on the basis of our legitimate interest in protecting users and the platform. Records required by tax, accounting or other law are processed to comply with a legal obligation. Where consent is required, it may be withdrawn without affecting earlier lawful processing.
Reservations and automated dispatch
Drivers eligible under the platform rules may see the limited information needed to assess a reservation, and the first valid acceptance assigns it to that driver. The initial search lasts for up to ten minutes. If no driver accepts, the request receives a no-driver-available outcome; the passenger or authorised dispatcher may start no more than two additional searches. If a driver does not confirm departure by the calculated deadline, the system may return the reservation to nearest-available-driver dispatch. A driver's explicit decline sends the offer onward and the third decline of the same ride automatically sets that driver offline. Returning an already assigned ride to dispatch is recorded separately and does not count as a decline. This operational automation supports delivery of the requested ride and is not used to profile passengers. Contact CroCab dispatch if you need assistance or human review.
Public website, security and cookies
The CroCab public website currently uses no analytics or marketing cookies. Cloudflare Turnstile protects the request form and processes technical signals about the network, device, browser and interaction to detect automated abuse. Depending on Cloudflare's security configuration, it may set a strictly necessary security cookie. CroCab does not use this information for advertising. If optional cookies are introduced, appropriate controls and consent will be provided before they are enabled.
The pilot-partner survey and permanent partner application are separate flows. The survey stores the work-city names entered for aggregate analysis, but does not request an address or precise location and does not attach a name, contact detail, account, IP address, user-agent or browser fingerprint to an answer. A random retry key is stored separately only to avoid a duplicate database row after a network retry. Until submission, the draft stays in browser-local storage and is removed after a successful submission. The separate application stores only the details the provider submits so CroCab can make the requested contact; it remains available after the survey ends, contains no anonymous-answer identifier and is not linked to the survey.
Passenger PWA and necessary local storage
The passenger PWA at app.crocab.com uses the same CroCab account, Supabase data contract and permissions as the Android passenger app. It sets no analytics or marketing cookies. It uses only necessary browser-local storage for the secure sign-in session, installation identity, language and preferences, plus a service-worker cache for the application's static files. Ride information, locations and Supabase API responses are not stored in that cache. Signing out removes the authentication session; remaining local storage and cache can be removed through browser settings. Because only technically necessary mechanisms are used, no optional-cookie consent is shown. If optional analytics or marketing are introduced, they will remain disabled until consent is given.
The PWA requests location only after the passenger's action or to show an active ride while the page is visible. Web notifications require separate browser permission and use Firebase Cloud Messaging only after the passenger enables them. On iPhone, installation, location and notification availability depend on browser support and the iOS version.
App diagnostics
The passenger Android app uses Google Firebase Crashlytics to identify and fix crashes, ANRs and other technical failures. The CroCab PWA currently does not send Crashlytics reports. CroCab does not add names, email addresses, phone numbers, ride addresses or precise location to diagnostic reports. Under Google's retention policy, crash traces and associated identifiers are kept for 90 days before removal from live and backup systems begins.
Partners and service providers
Information required to perform a ride is shared only in a limited view with drivers eligible to accept a reservation, the assigned driver and the transport partner. After an incident, continuation may be offered only to another active and eligible driver and partner already registered in CroCab, including an eligible owner who drives personally and has no employed drivers. CroCab does not send an outside driver. A fresh live Customer location is available only to the currently assigned Driver through a protected request and is not shown to other drivers. The single billing partner receives the information needed to issue one receipt, while each operating partner sees only its own leg and the information required for the internal settlement. Location and automatic visual navigation rerouting alone do not change the accepted price; route and price may change only through a passenger's explicitly accepted active-ride revision. Persistent ride-comfort preferences are disclosed to the driver only after the ride has been assigned. Supabase, Google Firebase, Cloudflare, Geoapify and OpenStreetMap infrastructure provide technical services only to the extent required to operate, secure and maintain CroCab. Where a provider processes data outside the EEA, appropriate contractual and other safeguards apply.
Retention
Information is retained only while needed to provide the service, process a request, evidence an accepted price, resolve disputes, maintain security or meet legal obligations. Route and price revisions are retained with the ride record as evidence of the offered and accepted amendment. Incident, ride-leg, passenger-decision, payment-collection, debt, receipt and internal-settlement records are retained with the ride for the applicable accounting, tax, transport, dispute and security periods. A live Customer location is deleted when the ride ends, is cancelled or is no longer assigned. The Driver cannot retrieve a point older than 30 seconds, and an additional hourly safeguard removes records older than one hour. Other retention periods depend on the record and its purpose. An unsuccessful or unconfirmed web request is removed when no longer needed for communication, security or evidence of how it was handled. Records that must remain after account deletion are pseudonymised for the applicable retention period.
Anonymous pilot-survey answers are retained for no more than 12 months and are then deleted automatically. The technical network-address digest used to protect the separate interest form against automated abuse is removed from that application after 24 hours. A contact application is kept only while needed to communicate, assess the request and record its outcome, or for less time where deletion is possible and requested.
Your rights
Where applicable, you may request access, correction, deletion, restriction, portability or object to processing. Contact us at the address above or through the app. You may also lodge a complaint with the Croatian Personal Data Protection Agency.
Changes
Material changes receive a new version and effective date. Where required, the app will ask users to accept the updated document.
Unpaid receipt incidents
After a receipt is issued, the driver may report its amount as unpaid. We process its receipt and ride link, report, collection state, messages to Admin and resolution audit. Registered passengers receive a notification and may send Admin an objection or evidence of payment. A report is not an automatic decision on a dispute. Access is limited to the related passenger, authorised driver, relevant partners and Admin. Passenger, driver and partner messages to Admin use separate conversations. Processing supports service performance, complaints, collection and legal claims. We assess the need and period for retaining each dispute record under the retention rules on this page, and remove or pseudonymise unnecessary information.
Dated campaign benefits
The supplemental discount rules explain eligibility, calculation, long-route priority, account-level usage and associated data processing. They apply when a campaign benefit is displayed and used. Read discount rules (2026-09-05-discounts-v1).