Personal data protection

Privacy Policy

This policy covers the passenger app, passenger PWA and public CroCab web forms. Driver-account processing is covered by a separate CroCab Driver policy.

This policy explains what information CroCab processes, why it is needed and what rights you have.

Controller

Information we process

Purposes

Legal bases

We process information required to respond to a request, make arrangements and organise a ride in order to take steps at your request and perform a contract. Security records, abuse prevention and necessary technical diagnostics are processed on the basis of our legitimate interest in protecting users and the platform. Records required by tax, accounting or other law are processed to comply with a legal obligation. Where consent is required, it may be withdrawn without affecting earlier lawful processing.

Reservations and automated dispatch

Drivers eligible under the platform rules may see the limited information needed to assess a reservation, and the first valid acceptance assigns it to that driver. The initial search lasts for up to ten minutes. If no driver accepts, the request receives a no-driver-available outcome; the passenger or authorised dispatcher may start no more than two additional searches. If a driver does not confirm departure by the calculated deadline, the system may return the reservation to nearest-available-driver dispatch. A driver's explicit decline sends the offer onward and the third decline of the same ride automatically sets that driver offline. Returning an already assigned ride to dispatch is recorded separately and does not count as a decline. This operational automation supports delivery of the requested ride and is not used to profile passengers. Contact CroCab dispatch if you need assistance or human review.

Public website, security and cookies

The CroCab public website currently uses no analytics or marketing cookies. Cloudflare Turnstile protects the request form and processes technical signals about the network, device, browser and interaction to detect automated abuse. Depending on Cloudflare's security configuration, it may set a strictly necessary security cookie. CroCab does not use this information for advertising. If optional cookies are introduced, appropriate controls and consent will be provided before they are enabled.

The pilot-partner survey and permanent partner application are separate flows. The survey stores the work-city names entered for aggregate analysis, but does not request an address or precise location and does not attach a name, contact detail, account, IP address, user-agent or browser fingerprint to an answer. A random retry key is stored separately only to avoid a duplicate database row after a network retry. Until submission, the draft stays in browser-local storage and is removed after a successful submission. The separate application stores only the details the provider submits so CroCab can make the requested contact; it remains available after the survey ends, contains no anonymous-answer identifier and is not linked to the survey.

Passenger PWA and necessary local storage

The passenger PWA at app.crocab.com uses the same CroCab account, Supabase data contract and permissions as the Android passenger app. It sets no analytics or marketing cookies. It uses only necessary browser-local storage for the secure sign-in session, installation identity, language and preferences, plus a service-worker cache for the application's static files. Ride information, locations and Supabase API responses are not stored in that cache. Signing out removes the authentication session; remaining local storage and cache can be removed through browser settings. Because only technically necessary mechanisms are used, no optional-cookie consent is shown. If optional analytics or marketing are introduced, they will remain disabled until consent is given.

The PWA requests location only after the passenger's action or to show an active ride while the page is visible. Web notifications require separate browser permission and use Firebase Cloud Messaging only after the passenger enables them. On iPhone, installation, location and notification availability depend on browser support and the iOS version.

App diagnostics

The passenger Android app uses Google Firebase Crashlytics to identify and fix crashes, ANRs and other technical failures. The CroCab PWA currently does not send Crashlytics reports. CroCab does not add names, email addresses, phone numbers, ride addresses or precise location to diagnostic reports. Under Google's retention policy, crash traces and associated identifiers are kept for 90 days before removal from live and backup systems begins.

Partners and service providers

Information required to perform a ride is shared only in a limited view with drivers eligible to accept a reservation, the assigned driver and the transport partner. After an incident, continuation may be offered only to another active and eligible driver and partner already registered in CroCab, including an eligible owner who drives personally and has no employed drivers. CroCab does not send an outside driver. A fresh live Customer location is available only to the currently assigned Driver through a protected request and is not shown to other drivers. The single billing partner receives the information needed to issue one receipt, while each operating partner sees only its own leg and the information required for the internal settlement. Location and automatic visual navigation rerouting alone do not change the accepted price; route and price may change only through a passenger's explicitly accepted active-ride revision. Persistent ride-comfort preferences are disclosed to the driver only after the ride has been assigned. Supabase, Google Firebase, Cloudflare, Geoapify and OpenStreetMap infrastructure provide technical services only to the extent required to operate, secure and maintain CroCab. Where a provider processes data outside the EEA, appropriate contractual and other safeguards apply.

Retention

Information is retained only while needed to provide the service, process a request, evidence an accepted price, resolve disputes, maintain security or meet legal obligations. Route and price revisions are retained with the ride record as evidence of the offered and accepted amendment. Incident, ride-leg, passenger-decision, payment-collection, debt, receipt and internal-settlement records are retained with the ride for the applicable accounting, tax, transport, dispute and security periods. A live Customer location is deleted when the ride ends, is cancelled or is no longer assigned. The Driver cannot retrieve a point older than 30 seconds, and an additional hourly safeguard removes records older than one hour. Other retention periods depend on the record and its purpose. An unsuccessful or unconfirmed web request is removed when no longer needed for communication, security or evidence of how it was handled. Records that must remain after account deletion are pseudonymised for the applicable retention period.

Anonymous pilot-survey answers are retained for no more than 12 months and are then deleted automatically. The technical network-address digest used to protect the separate interest form against automated abuse is removed from that application after 24 hours. A contact application is kept only while needed to communicate, assess the request and record its outcome, or for less time where deletion is possible and requested.

Your rights

Where applicable, you may request access, correction, deletion, restriction, portability or object to processing. Contact us at the address above or through the app. You may also lodge a complaint with the Croatian Personal Data Protection Agency.

Changes

Material changes receive a new version and effective date. Where required, the app will ask users to accept the updated document.

Unpaid receipt incidents

After a receipt is issued, the driver may report its amount as unpaid. We process its receipt and ride link, report, collection state, messages to Admin and resolution audit. Registered passengers receive a notification and may send Admin an objection or evidence of payment. A report is not an automatic decision on a dispute. Access is limited to the related passenger, authorised driver, relevant partners and Admin. Passenger, driver and partner messages to Admin use separate conversations. Processing supports service performance, complaints, collection and legal claims. We assess the need and period for retaining each dispute record under the retention rules on this page, and remove or pseudonymise unnecessary information.

Dated campaign benefits

The supplemental discount rules explain eligibility, calculation, long-route priority, account-level usage and associated data processing. They apply when a campaign benefit is displayed and used. Read discount rules (2026-09-05-discounts-v1).