Privacy policy ============== This policy explains how Gepek d.o.o. processes personal data when you use Gepek — the website thegepek.com and the mobile app for Android and iOS. It describes only the processing the service actually carries out. The Croatian version is authoritative. ## Controller and contact The controller is Gepek d.o.o., M. Krleže 15, 44320 Kutina, Croatia. For any question about personal data and to exercise your rights, write to [info@thegepek.com](mailto:info@thegepek.com) or by post to the address above. We have not appointed a data protection officer because our processing does not require one; the company's management answers your requests. ## Which data we process - **Account data:** name, e-mail address, profile picture and Google account identifier, which we receive from Google when you sign in; interface language; registration date. - **Phone:** your phone number, only if you add it to your profile yourself. - **Trips:** origin, destination and waypoints (name and coordinates), route, departure time, number of seats and package slots, indicative prices. - **Requests:** pickup and drop-off point, number of seats, package size and description, package photos and the notes you write. - **Messages:** the content of messages you exchange with the other party of a request, and when they were sent and read. - **Reviews:** the rating and comment you write or receive, and your overall rating. - **Location:** the driver's last position while sharing a trip live; a one-off reading of your location when you choose "my location". - **Notifications and devices:** in-app notifications; the push destination (an Expo push token on your phone or a browser subscription on the web), device type and device language. - **Restrictions and moderation:** if we restrict your account or hide your content — the kind of restriction, the reason and statement of reasons, its duration, when the decision was taken and the staff member who took it; the marking of hidden content with its reason. - **Audit log:** which staff member viewed or changed your data, when and why. - **Technical data:** IP address and request counters for abuse protection, time of last activity, server error logs. We do not ask for special categories of data (e.g. about health or religion). Please do not enter such data, or data about other people, in free text — messages, notes, descriptions and reviews. ## Purposes, legal bases and retention We process most data because it is needed for the service you asked for by accepting the [Terms of use](/legal/terms) — the legal basis is performance of a contract (Art. 6(1)(b) GDPR). Where we rely on legitimate interest (Art. 6(1)(f)), this is stated. When you delete your account, we remove your name, phone, picture and e-mail. Records of trips, requests, messages and reviews remain without those data, labelled "Deleted user", because they are part of other users' history (see [Account deletion](/legal/account-deletion)). Where it says "while you have an account" below, no separate shorter period has been set yet. ### User account and sign-in Purpose: creating and running your account, signing in with Google and presenting you to other users (name, picture, rating, member since). Basis: contract. Retention: while you have an account; name, e-mail and picture are refreshed from Google at every sign-in. ### Publishing and searching trips Purpose: publishing your trip, calculating its route and showing it to users whose origin and destination lie along the route. We calculate routes on our own server. We do not store search queries with your account; we record only anonymous statistics (see below). Trips of drivers whose account is suspended or banned are not shown in search. Basis: contract. Retention: while you have an account, then as described above. ### Seat and package requests Purpose: sending a request to the driver, the driver's decision and tracking its status. We re-encode package photos and strip their metadata (including GPS). Basis: contract. Retention: while you have an account, then as described above. ### Phone contact Purpose: arranging the pickup. If you added a phone number, only the other party of a request in progress (pending or accepted) sees it, and only on the trip detail — never in lists or search. Once the request is rejected, cancelled or completed, the number is no longer shown. Basis: contract. We do not store the number separately. ### Messages Purpose: arrangements between the driver and the requester about one request. Only the two participants of a conversation see its messages. A push notification about a new message does not contain its text. Basis: contract. Retention: while you have an account, then as described above. ### Reviews and ratings Purpose: trust between users. You can leave a review only after a real request on a trip; signed-in users see it on the reviewed person's profile. Basis: contract. Retention: while you have an account; after account deletion reviews remain under the label "Deleted user". ### Notifications and push notifications Purpose: informing you about events that concern you (requests, decisions, cancellations, messages, reviews). We send push notifications only if you switch them on yourself; you can switch them off in your profile or in your device or browser settings. Push content is minimal: the kind of event, the other party's name and place names — never a message text, phone number or e-mail. Basis: contract. Retention: in-app notifications while you have an account; the push destination until you sign out, switch push off, delete your account or the relay tells us it is no longer valid. ### Location Purpose: (a) a driver can share their position with riders and senders whose request was accepted while the trip is under way; (b) you can pick your current location as a starting point. We read the location only while the app is open and only with your permission; there is no background tracking and no movement history — we keep only the driver's last position on that trip. For (b) we do not store the coordinates with your account. Basis: contract, on your explicit action. ### Staff access: support, moderation and security Purpose: Gepek's authorised staff help users, handle reports and disputes, moderate content and protect the security of the service. Only staff members with an assigned role — support (SUPPORT) or administrator (ADMIN) — have access; we check the role on every request. Staff can view account data, trips, requests, reviews, the list of your devices for push notifications, your notifications (their type and content) and the messages of conversations, including a search of message text. In lists and search results e-mail and phone are masked; the full contact is shown only in the view of an individual user. Staff never see push tokens or browser subscriptions. Staff access data only when a specific case requires it, and every such access is recorded (see Audit log). Staff can correct your account data (a change of e-mail address always requires a stated reason) and change or cancel a trip or request — we notify those affected of a cancellation and of a change to the departure time or a price — and an administrator can delete your account at your request, with the same effect as deleting it in the app. When and why we do this is described in the [Terms of use](/legal/terms). Basis: legitimate interest (Art. 6(1)(f)) — helping users, resolving disputes fairly, protecting users from fraud and abuse and enforcing the Terms of use. You can object to this processing (see Your rights). Retention: staff create no separate copies of your data; the retention periods given for each kind of data apply. ### Audit log Purpose: accountability for staff access to data. Every sensitive view by staff — opening a conversation, searching messages, viewing a user — and every change is recorded in the audit log before the staff member sees the data; if the entry cannot be saved, the data are not shown. An entry contains which staff member acted and in which role, the action, the data it concerned, the old and new values of changed fields, the stated reason and the time. Entries cannot be altered or deleted before the retention period ends. Basis: legitimate interest (Art. 6(1)(f)) — accountability and security of processing (Art. 5(2) and Art. 32 GDPR). Retention: 12 months (365 days), after which entries are deleted automatically every day. ### Account restrictions and content moderation Purpose: enforcing the [Terms of use](/legal/terms) — temporary suspension or permanent ban of an account and hiding messages and reviews that break the rules. When we restrict an account we store the kind of restriction, the reason category, the staff member's statement of reasons, the end of a suspension and when and by which staff member the decision was taken. While your account is restricted you cannot sign in or use the service, and your trips are not shown in search; on a permanent ban your active trips and requests are cancelled and the other party receives a cancellation notice. The staff member's statement of reasons is shown to you verbatim, and you can send an appeal to [info@thegepek.com](mailto:info@thegepek.com). A hidden message or review is not deleted but kept so that the decision can be reviewed and reversed. Instead of a hidden message both participants of the conversation see the label "Removed by moderation"; a hidden review is no longer shown on the profile and does not count towards the overall rating. With hidden content we store the reason, the time and the staff member. You receive the statement of reasons for the decision in the app, and a push notification if you switched them on. Basis: contract (enforcing the Terms of use) and legitimate interest (Art. 6(1)(f)) — user safety and protection against abuse. Retention: a ban until it is lifted or the account is deleted; the data of an expired suspension are removed by a weekly automatic clean-up; hidden content as long as the content itself (see above); the history of decisions in the audit log for 12 months. ### Anonymous search statistics Purpose: aggregate statistics on demand — for example, on which routes users look for a ride but find no trip — to improve the service. For each search we record only: whether a seat or package transport is sought, origin and destination rounded to cells of a 0.1° grid (roughly 8–11 km), the name of the town or village of origin and destination (never a street or house number), the travel date, the number of trips found and the time rounded to the hour. We never record your account, IP address, token or exact coordinates, so an entry cannot be linked to you. We use the statistics only in aggregate and take no decisions about individuals based on them. Basis: legitimate interest (Art. 6(1)(f)) — developing and improving the service. Retention: 12 months, after which entries are deleted automatically. ### Usage analytics (Google Analytics) Purpose: understanding how Gepek is used so we can improve it — which pages and screens are opened, how many searches find a ride, how many requests are sent and trips published. We use Google Analytics 4 on the website and Google Analytics for Firebase in the Android app, **only if you consent** in the cookie banner on the website or in the prompt when you first open the app. Until you consent, Google's code is not loaded at all on the website, and collection is switched off in the app. What is sent: the path of the page or screen without query or identifiers (e.g. `/trips/:id`), the kind of event and a few predefined values (e.g. whether a seat or a package is searched for, whether a search found a ride, sign-in via Google or development login), together with a random identifier of the browser or app installation and technical data Google collects (device and browser type, language, approximate country- or region-level location derived from the IP address, which Google does not store). We never send names, e-mail addresses, phone numbers, messages, descriptions, place names or coordinates, and we do not link analytics to your account. Google signals, ad personalisation and advertising identifiers are switched off. The processor is Google Ireland Limited (Ireland) under Google's data processing terms; Google LLC may process data in the USA, under the EU-U.S. Data Privacy Framework (see Transfers outside the EU and EEA). Basis: consent (Art. 6(1)(a) GDPR) and, for storing and reading identifiers on your device, consent under the electronic communications rules. You can withdraw consent at any time, as easily as you gave it: on the website through the "Cookie settings" link in the page footer, in the app by switching off Analytics in your profile (Privacy section). Withdrawal stops collection at once; on the website we delete the `_ga` cookies, in the app the identifier and the data on the device are deleted. Withdrawal does not affect the lawfulness of processing before it. Retention: aggregate reports remain, while event- and identifier-level data in Google Analytics is deleted after 14 months; the `_ga` cookies expire after at most 13 months. ### Service security Purpose: protection against overload, mass collection of data and abuse. We process IP addresses and request counters and temporarily block addresses that exceed a threshold. Basis: legitimate interest (network and information security). Retention: counters and blocks from a few seconds up to one hour at most. ## Who receives your data - **Other users:** signed-in users see your name, picture, rating and member-since date, and the trips you publish. Phone, messages and request details are seen only by the other party of that request, as described above. Instead of a message hidden by moderation, the participants of the conversation see only the label "Removed by moderation", and a hidden review is not shown; if your account is banned, the other party of the cancelled trips and requests receives a cancellation notice. - **Gepek's authorised staff:** staff members with the support or administrator role, to the extent described in the section "Staff access"; every sensitive view is recorded in the audit log. - **Google** (Google Ireland Limited and Google LLC): signing in with a Google account. For its sign-in service Google is an independent controller. Profile pictures load directly from Google's servers, so Google sees the IP address of the device displaying them. - **Google Analytics** (Google Ireland Limited, as processor): usage statistics, only with your consent (see Usage analytics). - **Push notifications in the mobile app:** Expo (650 Industries, Inc., USA) forwards notifications to Firebase Cloud Messaging (Google) for Android or to the Apple Push Notification service (Apple Inc.) for iOS. These relays see the destination and content of the notification. - **Push notifications on the web:** the notification is delivered by the push service your browser selects — Google (Chrome), Mozilla (Firefox), Microsoft (Edge) or Apple (Safari). The content is end-to-end encrypted; the service sees only the destination, size and time of the message. - **Photon** (komoot GmbH, Germany): when you type a place or choose "my location", our server sends Photon the query text or coordinates to get place names — without your name, account or IP address. - **The server hosting provider** as a processor that handles data only on our instructions. - **Public authorities**, only where the law requires it. We serve maps, route calculation and fonts from our own servers. We use no advertising services; analytics (Google Analytics) only with your consent. ## Transfers outside the EU and EEA Expo, Google LLC (including Google Analytics), Apple, Microsoft and Mozilla may process data in the USA. We base such transfers on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework for certified recipients, or on the European Commission's standard contractual clauses (Art. 45 and 46 GDPR). All other data stay in the EU. ## Cookies and local storage We use no cookies for advertising. Google Analytics cookies are set only if you consent in the cookie banner; without consent they are not set. We remember your choice in browser storage, and you can change it through the "Cookie settings" link. The `gepek-lang` cookie is set only when you pick a language on the public pages yourself: it remembers that choice for a year, so your next visit is not redirected to your browser's language. The website keeps in browser storage (localStorage) only what the service you request needs: your sign-in (token and a copy of your profile), your display theme and a flag if you switched push notifications off; for web push the browser registers a service worker. The mobile app keeps your sign-in in the device's secure storage. Signing out removes the sign-in from the device. ### List of cookies and local storage | Name | Type | Purpose | Duration | |---|---|---|---| | `_ga` | cookie (Google Analytics) | tells browsers apart for statistics — only with consent | up to 13 months | | `_ga_` | cookie (Google Analytics) | session state for statistics — only with consent | up to 13 months | | `gepek-lang` | cookie (necessary) | the language you picked on the public pages | 1 year | | `gepek.consent` | localStorage (necessary) | your cookie and analytics choice, with its date and text version | until you change it or delete your account | | sign-in session | localStorage (necessary) | sign-in and a copy of your profile | until sign-out (the token is valid for 7 days) | | `gepek.push.disabled` | localStorage (necessary) | a flag that you switched push notifications off | until you change it | | `gepek-color-mode` | localStorage (necessary) | display theme | until you change it | | app installation identifier | Firebase Analytics (Android) | tells installations apart for statistics — only with consent | until consent is withdrawn or the app is removed | ## How we protect data - All traffic is encrypted (HTTPS/TLS, HSTS); the database and internal services are not reachable from the internet. - Strict website security rules (Content Security Policy) make injecting malicious code harder. - Every request checks that the user is entitled to the data (driver, requester, conversation participant). - Phone and e-mail never appear in lists or search results; staff see them masked in lists. - Staff access is limited by roles and recorded in an audit log that cannot be altered. - Request rate limits protect against mass collection of data. ## Automated decision-making We make no decisions based solely on automated processing that have legal or similarly significant effects on you. Search only filters and orders trips (see [How we order results](/legal/ranking)); you and the driver make the decision. A temporary IP block after exceeding a threshold lasts one hour at most. A suspension or ban of an account and the hiding of content are always decided by a staff member after review, with a statement of reasons. The anonymous search statistics serve only aggregate analysis and are not used for decisions about individuals. ## Your rights You have the right of access to your data, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interest, including staff access to your data. The right of access also covers the data on a restriction of your account and on the moderation of your content. You can withdraw your consent to analytics at any time (Art. 7(3)), as described under Usage analytics. You can change your name and phone in your profile yourself and delete your account in the app (see [Account deletion](/legal/account-deletion)). Send your request to [info@thegepek.com](mailto:info@thegepek.com) or by post to Gepek d.o.o., M. Krleže 15, 44320 Kutina, Croatia. We will reply without undue delay and at the latest within one month of receiving the request; in complex cases this can be extended by two further months, and we will tell you so. To protect your data we may ask you to confirm your identity — usually by replying from your account's e-mail address. ## Complaint to the supervisory authority If you believe the processing of your data breaks the rules, you can lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, [azop@azop.hr](mailto:azop@azop.hr), [azop.hr](https://azop.hr). We would appreciate the chance to try to solve the problem first. ## Changes to this policy We update this policy when the processing it describes changes. We will inform you in the app about material changes before they take effect. The current version is always published on this page. --- https://thegepek.com/en/legal/privacy