Privacy Policy
1. Personal Data We Collect
1.1 Account Data (all users)
- Full name and email address (from Apple or Google OAuth; Apple may provide a relay email)
- Phone number (verified via SMS OTP through Twilio Verify)
- Profile photo (optional for Riders; required for Drivers as part of PCO documentation)
- Username and date of birth
- Password (hashed; only if you choose email/password login in addition to OAuth)
1.2 Driver-Specific Data
- Driving Licence, Insurance Documents, PCO Certificate, PCO Photo ID (uploaded images)
- Vehicle details: make, model, year, colour, registration plate, vehicle category
- Stripe Connect account details (managed by Stripe; we receive only a payout reference)
1.3 Trip & Bidding Data
- Pickup and drop-off addresses and any intermediate stops
- Scheduled pickup date and time
- Vehicle category preference
- Bid amounts placed by Drivers
- Trip status events and timestamps (e.g., driver arrived, trip started, completed)
1.4 Payment Data
- Payment method type (card, Apple Pay) — we do not store full card numbers
- Transaction IDs, amounts charged, refunds, and payout records
- All card data is tokenised and processed by Stripe in accordance with PCI DSS
1.5 Location Data
- Real-time GPS location of Drivers during active Trips (broadcast via WebSocket)
- Pickup and drop-off coordinates derived from addresses via Google Maps APIs
- Background location permission on iOS is requested explicitly when a Driver starts a Trip
1.6 Device & Usage Data
- Device identifiers (Firebase Cloud Messaging token for push notifications)
- App crash reports and non-fatal error logs (Firebase Crashlytics)
- Basic usage analytics: first open, session start, registration, trip created, bid placed (Firebase Analytics)
1.7 Communications Data
- In-app notifications and push notification delivery status
- Support correspondence (email to Ridersupport@frugalbookingservice.com)
2. How We Collect Your Data
We collect data directly from you when you register and use the App; from Apple or Google when you authenticate via OAuth; from Twilio Verify when your phone number is confirmed; from Stripe when payment is processed; and automatically from your device via Firebase, Google Maps, and WebSocket connections.
3. How We Use Your Data
We process your personal data for the following purposes and legal bases:
- Account creation and authentication — Performance of a contract
- Matching Riders with Drivers and processing Trips — Performance of a contract
- Payment processing and payouts via Stripe — Performance of a contract
- Driver document verification — Legal obligation (PHV licensing requirements)
- Real-time trip tracking and notifications — Performance of a contract
- Platform safety, fraud prevention, and dispute resolution — Legitimate interests
- Crash reporting and basic analytics — Legitimate interests (improving app stability)
- Compliance with UK GDPR right-to-erasure requests — Legal obligation
4. Third-Party Processors
We share your data with trusted third-party processors under appropriate data processing agreements:
- Stripe — Payment processing and driver payouts (PCI DSS compliant). Stripe Privacy Policy: stripe.com/privacy
- Google (Maps SDK, Directions API, Places Autocomplete, Firebase FCM, Crashlytics, Analytics) — Maps, routing, push notifications, crash reporting. Google Privacy Policy: policies.google.com/privacy
- Twilio Verify — SMS OTP delivery for phone verification. Twilio Privacy Policy: twilio.com/legal/privacy
- Stfalcon Studio — Development partner with access to anonymised or staging data only under a Data Processing Agreement
- Hetzner (Kubernetes hosting in Finland/Germany) — Infrastructure hosting in the EU/EEA under UK Adequacy Decision
5. International Data Transfers
Your data is stored on servers hosted in the EU (Finland and Germany) operated by Hetzner. Data transfers from the UK to the EU are covered by the UK’s Adequacy Regulations for the EU. Where other transfers occur (e.g., to Google or Stripe servers in the US), we rely on Standard Contractual Clauses or the UK International Data Transfer Agreements (IDTAs) as appropriate.
6. Cookies & Tracking
The App does not use browser cookies. Firebase Analytics and Crashlytics use device-level identifiers to provide analytics and crash reporting. You can opt out of Firebase Analytics by contacting us, though this may affect App functionality.
7. Children’s Privacy
The App is not intended for users under 18. We do not knowingly collect personal data from children. If you believe a child has registered, contact us at privacy@frugal.app and we will promptly delete the account.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via in-app or push notification at least 14 days before changes take effect. The updated policy will always be accessible within the App and on our website.
9. Contact
Data Protection enquiries: privacy@frugal.app · Frugal Booking Service Ltd · Ridersupport@frugalbookingservice.com