Privacy Policy
1. Overview & Scope
This privacy policy informs you about how we process personal data when you use the piccab rider app to book taxi rides. piccab arranges taxi rides for you in the Ingolstadt area: you book a ride through the app, we forward your request to an affiliated taxi company whose driver carries out the ride. Payment is made exclusively directly in the taxi (cash or card with the driver) – piccab itself does not process any payment data.
Scope: This privacy policy applies to the piccab rider app as well as to our website at piccab.de. If you merely visit our website, we only process technically necessary server log data (including your IP address) for the secure and stable provision of the site on the basis of our legitimate interest (Art. 6(1)(f) GDPR); we only set analytics or marketing cookies on the website with your consent. Data processing in relation to the drivers or taxi companies is governed by separate contractual arrangements and is not the subject of this policy.
Website analytics (Google Analytics 4): On our website piccab.de we use – only after your consent via the cookie banner – Google Analytics 4 to analyse website usage statistically. The provider is Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, where applicable involving Google LLC, USA. We use the measurement ID G-121G9JS1RP; the IP address is truncated (anonymize_ip). Cookies (in particular _ga and _ga_*) with a lifetime of up to 24 months are set. Processing only takes place after you have selected "Accept" in the cookie banner; without consent, no analytics script is loaded and no analytics cookie is set. The legal basis is your consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG), which you can withdraw at any time with effect for the future via "Cookie settings" in the website footer. This may involve a transfer to the USA (see section 16); Google is certified under the EU-US Data Privacy Framework. Retention of the analytics data is governed by the retention period configured in Google Analytics and by Google's privacy terms. This website analytics concerns the website only; no analytics takes place in the piccab app (see section 12).
Conversion measurement (Google Ads): On our website piccab.de we use – likewise only after your consent via the cookie banner – Google Ads conversion tracking to measure whether visitors who reached us via a Google ad actually visit our website. The provider is Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, where applicable involving Google LLC, USA. Cookies (in particular _gcl_aw and _gcl_au) with a lifetime of typically 90 days are set. We only receive aggregated statistics from Google (e.g. the total number of conversions) and no information that would allow us to identify you personally. Remarketing or personalised advertising based on your website visit does not take place (the corresponding consent signal "ad_personalization" remains disabled). Processing only takes place after you have selected "Accept" in the cookie banner; without consent, no tracking script is loaded and no marketing cookie is set. The legal basis is your consent (Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG), which you can withdraw at any time with effect for the future via "Cookie settings" in the website footer. This may involve a transfer to the USA (see section 16); Google is certified under the EU-US Data Privacy Framework. This, too, concerns the website only; no advertising tracking takes place in the piccab app.
2. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Eduard Doronin (sole proprietorship, brand "doSoftware")
Stömmerstr. 3a
85055 Ingolstadt
Germany
Email: [email protected]
VAT ID: DE462121951
Data protection officer: We have not appointed a data protection officer, as in our assessment the legal requirements for doing so are currently not met (one-person business). For all questions regarding data protection and the exercise of your rights, please contact the controller named above directly at [email protected].
3. What data we process
Depending on how you use piccab, we process the following categories of personal data:
- Account and profile data: first name, last name, mobile number (mandatory, unique), email address (mandatory at registration), country or country code, and your gender.
- Location data: your GPS location while you use the app, pickup and destination coordinates, route, and the places/favourites you save (coordinates + name, without phone number).
- Ride data: bookings, ride history, scheduled rides ("appointments"), the calculated fare, cancellations, and saved route polylines (the route taken, from which a movement profile of your rides can be derived).
- Communication data: chat messages between you and the driver, content from the referral program.
- Ratings: your star rating and an optional free-text comment about the ride.
- Referral data: your personal referral code and the assignment of referring/referred users.
- Push token: the device token for push notifications.
- Device and technical data: IP address, approximate location from the IP address (geo-IP), device name/platform/type, app type, app version, session token, FCM token, and timestamps.
- Diagnostic and crash data: error, crash, and performance telemetry from the app.
4. Purposes and legal bases at a glance
We process your data for the purposes set out below. We specify the applicable legal basis in more detail in the following sections; in overview:
- Art. 6(1)(b) GDPR (contract): setting up and managing your account, arranging and carrying out the ride, calculating the fare, exchanging data with the driver or taxi company, chat, scheduled rides, location determination for booking.
- Art. 6(1)(f) GDPR (legitimate interest): security and fraud prevention (including the referral hash), recovery of account access and security-related notifications by email, crash and error diagnostics, the rating system, as well as stability and improvement of the service.
- Art. 6(1)(a) GDPR (consent): marketing communication; push notifications and diagnostic functions, insofar as consent is required for this under Section 25 TDDDG.
- Art. 6(1)(c) GDPR (legal obligation): compliance with tax and commercial retention obligations and responding to legitimate requests from authorities.
5. Account & sign-in via SMS code
Using piccab requires signing in. Sign-in is carried out exclusively via your phone number and a one-time code (OTP) sent by SMS. We do not use passwords, email sign-in, or social login. To complete your profile we collect first name, last name, your email address, and your gender. Providing a valid email address is required at registration; it serves as your account's contact address, in particular for recovering access to your account and for security-related notifications. The email address is not used as a sign-in method (sign-in is exclusively via the SMS code). We only use your address for advertising emails if you have given separate consent (see section 14); the obligation to provide an email address is not linked to any consent to advertising. Providing your gender is required so that the driver can reliably recognise you at the pickup point – in particular in the case of gender-neutral first names.
Email confirmation: After registration (or after changing your email address) we send you a confirmation email containing a confirmation link. Your email address only counts as confirmed once you click this link. The confirmation link is valid for 24 hours and can be used only once; the associated confirmation value is retained only briefly for technical purposes. If you have also consented to advertising emails, confirmation takes place via the confirmation link of the newsletter sign-up instead (double opt-in, see section 14); that click then also confirms your email address for your account. Legal basis for the confirmation: Art. 6(1)(b) GDPR and our legitimate interest in preventing the misuse of third-party email addresses (Art. 6(1)(f) GDPR).
For sending the SMS with the confirmation code, we use the service provider Vonage. Your mobile number is transmitted to it so that the SMS can be delivered (for the third-country aspect, see section 16).
Purpose: identification and secure sign-in, protection against unauthorised access.
Legal basis: performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR), including the collection of the email address as account data; for sending the code via external providers and for using the email address for account recovery and security-related notifications, also our legitimate interest (Art. 6(1)(f) GDPR).
Retention period: for the duration of your account; after deletion in accordance with section 20. The one-time code itself is kept only briefly for verification.
6. Location data
piccab uses your location to make booking easier for you: during a booking, we continuously update your GPS position, and your pickup point is tied to your current GPS position. We also process the coordinates of the pickup and destination as well as the calculated route. When you save places/favourites, we store their coordinates and a name (without a phone number).
No background location tracking: piccab accesses your location exclusively in the foreground, i.e. only while the app is actively open and visible – including during an active ride. piccab does not create a persistent location profile. (This does not affect the receipt of push notifications, see section 12.)
Disabling/consequences: You can revoke the location permission at any time in your operating system settings (iOS/Android). Without location access, the location-based functions (automatic pickup point, map position) work only to a limited extent; you can then enter addresses manually. Without location sharing, the driver only sees your selected pickup point.
Purpose: determining the pickup location, map display, route and fare calculation, arranging and carrying out the ride, including enabling the driver to find you at the pickup point.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR), as location access is necessary for the booking service you have requested; the technical access to your device's location function is strictly necessary for this (Section 25(2) TDDDG). The release via your operating system's prompt is merely the technical authorisation step.
Retention period: pickup/destination coordinates and routes are stored as part of the ride record (see section 18); saved places until you delete them or until account deletion.
7. Map services (Google)
For maps, address search, and route calculation, we use Google services. Data may be transmitted to Google in this context:
- Google Maps SDK: for displaying the map in the app.
- Google Routes API (server-side): we transmit pickup and destination coordinates to Google in order to calculate distance and route.
- Google Places API: when you search for an address, your entered search terms (for autocomplete) and coordinates (for address resolution / reverse geocoding) are transmitted to Google.
The provider is Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland, where applicable with the involvement of Google LLC, USA. Within the Google Maps Platform, Google processes data partly for its own purposes and is, to that extent, an independent controller under data protection law; further details can be found in Google's privacy notices. A transfer to the USA may take place in this context (see section 16).
Purpose: map display, address search/resolution, and distance and route calculation as the basis for arranging the ride.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR); otherwise our legitimate interest in a functional map display (Art. 6(1)(f) GDPR).
Retention period: processing at Google is governed by Google's privacy terms. In our system, the associated coordinates are stored as part of the ride record (see section 18).
8. Carrying out the ride & data exchange with the driver / taxi company
In order to carry out your ride, we transmit certain data to the assigned driver or the executing taxi company. Specifically, we pass on: your first name, your gender (so the driver knows who to look out for), your pickup and destination, and, where applicable, chat messages you send in the context of the ride.
What you see about the vehicle: In the current version, the app shows you no driver name and no driver photo. Instead, you see the name of the executing taxi company, the vehicle model, the service category, the licence plate, a vehicle photo, as well as the live position and the estimated time of arrival (ETA) of the vehicle. The background is that on the provider side a piccab account is assigned to a taxi company and not to an individual person.
Direct call (no masked call)
Via the "Call" button, the app in the current version opens your device's phone dialer and calls the driver's real phone number directly. The call runs over your mobile network, not over piccab; piccab does not use number masking for this call and does not record it. This means: during the call, the driver can see your real number (via caller ID), and you see the driver's real number. Should masked telephony be introduced in a future version, we will update this policy accordingly.
Purpose: carrying out the booked ride, coordinating pickup and process.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Retention period: the transmitted ride data is stored as part of the ride record (see section 18). The direct call itself is not stored or logged by piccab.
9. In-app chat
You can exchange text messages with the driver via an in-app chat, e.g. to coordinate the pickup point. These messages are stored and are associated with the respective ride record.
Purpose: communication for carrying out the ride, traceability in case of queries.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR); there is also a legitimate interest in storage for traceability (Art. 6(1)(f) GDPR).
Retention period: tied to the associated ride record; deleted or anonymised together with it after the applicable retention period expires (see section 18).
10. Ratings
After a ride, you can rate it (stars and optional free text). The rating is stored and serves quality assurance and improvement of the service.
Purpose: quality assurance, improvement of service and ride arrangement.
Legal basis: legitimate interest in a functioning rating and quality system (Art. 6(1)(f) GDPR).
Retention period: deleted or anonymised together with the associated ride record, at the latest 90 days after account deletion, unless a statutory retention obligation applies.
11. Referral program
As part of our referral program, you receive a personal referral code. Participation is voluntary and is based on your active use of the code. If you invite other people, we assign referring and referred users to each other in order to allocate the bonus correctly.
Fraud prevention after account deletion: When you delete your account, instead of your phone number we store a SHA-256 hash value calculated from it (a pseudonym). This hash is used exclusively to check whether an already deleted number is being used again for the referral bonus, and is not used for any other purpose. In this way we prevent repeated abuse of the referral bonus (e.g. by repeatedly creating new accounts).
Purpose: operating the referral program; preventing abuse of the referral bonus.
Legal basis: performance of a contract for participation in the program (Art. 6(1)(b) GDPR); for the fraud-prevention hash, our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR).
Retention period: referral data for the duration of the account; the SHA-256 hash is retained even after account deletion for as long as a risk of abuse exists, but no longer than 24 months.
12. Push notifications
To inform you about the status of your ride (e.g. "Driver on the way", "Vehicle has arrived"), we send push notifications via Firebase Cloud Messaging (FCM) from Google. For this, a push token is generated on your device, which we store and transmit to Google (Firebase). These notifications can also be received while the app is running in the background or is closed. In the app, from Firebase we use exclusively the messaging service (Cloud Messaging) – no Firebase Analytics and no Crashlytics. (For the consent-based website analytics with Google Analytics 4, see section 1.)
Purpose: sending ride-related and service-relevant notifications.
Legal basis: performance of a contract for ride-related messages (Art. 6(1)(b) GDPR); the storing/reading of the push token on your device is based on your consent via the system/app permission (Art. 6(1)(a) GDPR in conjunction with Section 25 TDDDG).
Retention period: the push token is stored for as long as your account exists or the device is registered; upon account deletion it is removed (see section 20). You can disable push notifications at any time in your device settings.
13. Diagnostics & stability (Sentry)
To detect and fix errors and crashes and to monitor the app's performance, we use Sentry (Functional Software, Inc.). In this context, technical diagnostic data is processed, such as error and crash reports, affected app functions, device data, and timestamps.
Purpose: stability, error correction, and improvement of app quality.
Legal basis: legitimate interest in a stable, secure, and error-free app (Art. 6(1)(f) GDPR); insofar as information is stored or read on your device in this context, we additionally rely on your consent (Art. 6(1)(a) GDPR in conjunction with Section 25 TDDDG).
Hosting: Sentry processes the diagnostic data for us in the EU region (data centre in Frankfurt am Main, Germany); these data are not transferred to the USA.
Retention period: diagnostic data is deleted after 90 days.
14. Marketing consent & newsletter
In your profile (and once after registration) you will find a toggle for "Marketing emails". Advertising by email takes place only if you have given separate, express consent. The obligation to provide your email address at registration (see section 5) is not linked to any consent to advertising.
We use the service Brevo (Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany; parent company Brevo SAS, France) to send our newsletter. A data processing agreement under Art. 28 GDPR is in place with Brevo; primary hosting takes place in the EU. Sign-up uses a double opt-in procedure: after giving consent you receive a confirmation email and are only added to the mailing list once you click the confirmation link. Clicking the confirmation link documents your consent (the time is logged) and at the same time confirms your email address for your piccab account (see section 5). Brevo reports status events about your subscription back to us (e.g. confirmation, unsubscribe, delivery failures). Brevo may transfer personal data to sub-processors in the USA (safeguarded by the EU-US Data Privacy Framework) and in India (safeguarded by EU standard contractual clauses).
Purpose: management of your marketing consent; advertising communication by email (e.g. vouchers, ride credit, news).
Legal basis: your consent (Art. 6(1)(a) GDPR); the logging of your consent serves to fulfil our accountability obligations (Art. 5(2), Art. 7(1) GDPR).
Withdrawal: You can withdraw your consent at any time with effect for the future – via the toggle in your profile or the unsubscribe link in every email. Upon withdrawal your address is removed from the mailing list.
Retention period: until withdrawal or until account deletion.
15. Recipients & processors
To provide the service, we use carefully selected service providers or pass data on to the following recipients. Hosting, SMS dispatch, and diagnostics are carried out as processing on our behalf under Art. 28 GDPR and according to our instructions; for the Google Maps Platform services, Google is partly an independent controller (see section 7):
- Brevo (Brevo GmbH, Köpenicker Str. 126, 10179 Berlin, Germany; parent company Brevo SAS, France) – sending system emails, in particular the email for confirming your email address (see section 5), and – with consent – the newsletter (see section 14). The data transmitted comprises your email address, first name, and the content of the respective email; Brevo reports delivery and status events back to us. Primary hosting in the EU; possible sub-processors in the USA (EU-US Data Privacy Framework) and India (EU standard contractual clauses). System emails are sent independently of any consent to advertising (Art. 6(1)(b) and (f) GDPR).
- Vonage (Vonage Holdings Corp., USA) – sending the SMS with the sign-in code.
- Google / Firebase (Google Ireland Ltd., Ireland; Google LLC, USA) – push notifications (FCM), Google Maps, Routes, and Places, as well as – only on the website and only with consent – Google Analytics 4 and Google Ads conversion tracking (see section 1).
- Sentry (Functional Software, Inc.) – crash and diagnostic data; processing in the EU region (Frankfurt am Main, Germany).
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany – hosting of backend/API in a German data centre (data processing agreement under Art. 28 GDPR).
- Cloudflare (Cloudflare Germany GmbH or Cloudflare, Inc., USA) – upstream CDN, routing and security service (reverse proxy/DNS) in front of our servers; in doing so it processes connection data including your IP address for secure, fast and resilient delivery and protection against attacks (DPA pursuant to Art. 28 GDPR).
- Apple App Store or Google Play – delivery and updating of the app via the respective stores.
- Driver or executing taxi company – recipient of the data required to carry out the ride (see section 8).
In addition, we may transmit data to competent authorities or courts insofar as we are legally obliged to do so (Art. 6(1)(c) GDPR).
16. Transfer to third countries
Some of the service providers used process data (also) outside the European Economic Area (EEA), in particular in the USA: Google/Firebase, Cloudflare, and Vonage. With a transfer to the USA or other third countries, there is generally no level of data protection equivalent to EU law.
We base such transfers on appropriate safeguards pursuant to Art. 46 GDPR, in particular the EU Standard Contractual Clauses (SCCs). Insofar as the respective recipient is certified under the EU-US Data Privacy Framework (this applies in particular to Google), the transfer is additionally based on this.
17. Storing and reading information on the device (Section 25 TDDDG)
For the operation of the app, we store and read information on or from your device, such as the FCM push token, the session token, location information, and data of the diagnostic functions used (Sentry). Accesses that are strictly necessary to provide the service you have expressly requested (e.g. session token for sign-in, location access for booking) are based on Section 25(2) TDDDG. Accesses that are not strictly necessary (e.g. push notifications, diagnostic functions) are carried out only on the basis of your consent under Section 25(1) TDDDG, which we obtain via the system or app permissions. You can revoke permissions granted at any time in your device settings.
18. Retention period
In principle, we store personal data only for as long as is necessary for the respective purposes. Afterwards it is deleted or anonymised, at the latest 90 days after account deletion, unless a statutory retention obligation applies.
Statutory retention: ride, receipt, and accounting data are subject to tax and commercial retention obligations (in particular Section 147 AO, Section 257 HGB, and the GoBD). We retain this data in accordance with the statutory retention periods (receipts generally 8 years, other records generally 10 years) and only delete it after these periods expire. During this time, processing is limited to fulfilling the retention obligation.
19. Automated decision-making
To arrange your ride, we use an automated assignment (matching) that allocates your booking to a suitable available vehicle or taxi company. No profiling takes place, and there is no dynamic or surge pricing – the regulated taxi tariff applies. As part of fraud prevention, when you sign in again we automatically check whether a previously deleted number is involved; this only determines eligibility for the referral bonus and has no other legal effect on you.
A solely automated decision within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you does not take place. Independently of this, if you have problems with the arrangement you can contact us at any time; we will then review your request through a natural person.
20. Account deletion
You can remove your account at any time directly in the app via the "Delete account" function (Apple- and GDPR-compliant). Upon deletion, your personal profile and usage data is deleted or rendered unrecognisable, in particular: name, email, gender, country/area code, profile picture, push token, sessions, saved places, referral code, marketing consent, notes, and any technically created payment placeholders (where present). Your mobile number is not set "to NULL", but is replaced by a placeholder that cannot be linked to a person, so that there is no longer any reference to a person.
What is retained: ride and accounting records are retained due to statutory retention obligations (see section 18). In addition, as described in section 11, we retain the pseudonymous SHA-256 hash of your phone number to protect against abuse of the referral bonus.
21. Your rights as a data subject
You have the following rights under the GDPR:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR), in particular to processing based on Art. 6(1)(f) GDPR
- Right to withdraw consent given, with effect for the future (Art. 7(3) GDPR)
To exercise your rights, an informal message to [email protected] is sufficient.
22. Right to lodge a complaint with the supervisory authority
Without prejudice to other legal remedies, you have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for us is:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
23. Obligation to provide data
Providing certain data is necessary for using piccab. In particular, we need your mobile number, your first and last name, your email address, and your gender (so the driver can recognise you at the pickup point) in order to set up your account and arrange rides, and – during booking – your location or pickup and destination. Without this data we cannot provide the service, or can provide it only to a limited extent. Optional details (e.g. saved places, marketing consent) are voluntary; not providing them has no disadvantages other than the loss of the respective convenience function.
24. Data security
We take appropriate technical and organisational measures to protect your data against loss, misuse, and unauthorised access (Art. 32 GDPR). Data transmission between the app and the servers is encrypted via TLS. Our measures are continuously adapted to the state of the art.
25. Minimum age
piccab is aimed at adults. Use is only permitted from the age of 18. An age check during onboarding is carried out exclusively via your self-declaration; there is no technical age verification. By using the service, you confirm that you are at least 18 years old.
26. Changes to this privacy policy
We adapt this privacy policy when the legal situation, our processing activities, or the services used change. The current version available in the app applies in each case.
Status: 2 July 2026, 22:19 · Version: 5