This Privacy Policy defines the rules for processing the personal data of users of the PL Taxi web platform and mobile application.
This document has been prepared in accordance with:
Using the Platform means that you have read this Privacy Policy. The protection of users' personal data is one of the fundamental elements of the Platform Operator's activity.
The controller of personal data is:
The Controller is responsible for the lawful processing of personal data and for applying appropriate organizational and technical measures to ensure data security.
For the purposes of this Policy:
This Policy applies to all persons using the Platform, in particular:
The Controller may process the following data:
For a Passenger, the Controller processes the first name, phone number, and e-mail address. With respect to Carriers, drivers, and contractors, the Controller may additionally process:
The Controller may process the GPS data of the mobile device while the application is in use for the purpose of:
Location is processed only to the extent necessary to provide the services.
The Controller may collect:
The Controller may process information including:
The Controller does not store full payment card data. Payment processing is carried out by external payment operators in accordance with applicable security standards.
For cashless payments, the funds for the ride are received into the account of the Controller (PL Group Sp. z o.o.), which acts as an intermediary in the settlements between the Passenger and the Carrier, and then transfers them to the Carrier after deducting the service commission.
The Controller processes personal data only to the extent necessary to carry out the activity of the PL Taxi Platform and in accordance with the GDPR. Personal data may be processed for the following purposes:
Data processing is necessary to create and manage a user account, fulfil ride orders, provide ride-related information, contact the user, and ensure the proper functioning of the Platform.
Legal basis: Article 6(1)(b) GDPR.
The Controller processes data in order to perform agreements concluded with passengers, carriers, drivers, and contractors.
Legal basis: Article 6(1)(b) GDPR.
Data is processed for the purpose of accepting payments, confirming transactions, settling with carriers, maintaining accounting records, and processing refunds.
Legal basis: Article 6(1)(b) and (c) GDPR.
The Controller processes data in order to fulfil obligations arising from the law, in particular concerning accounting, tax law, prevention of abuse, and cooperation with state authorities.
Legal basis: Article 6(1)(c) GDPR.
The Controller processes data in order to handle complaints, resolve disputes, contact the user, and document the course of the complaint procedure.
Legal basis: Article 6(1)(b) and (f) GDPR.
The Controller processes data in order to prevent fraud, detect abuse, protect users and carriers, protect IT systems, and ensure payment security.
Legal basis: Article 6(1)(f) GDPR.
The Controller may process data in order to pursue receivables, defend against claims, and conduct court and administrative proceedings.
Legal basis: Article 6(1)(f) GDPR.
The Controller may contact the user regarding the fulfilment of rides, safety, changes to the Terms and the Privacy Policy, technical issues, and responses to user requests.
Legal basis: Article 6(1)(b) GDPR.
If the user gives separate consent, the Controller may send information about new services, promotions, discounts, loyalty programmes, and commercial information.
Legal basis: Article 6(1)(a) GDPR. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.
The Controller may transfer personal data only to entities to which it is necessary for the provision of services or which results from applicable law. Recipients of the data may include, in particular:
The Controller transfers data only to the extent necessary to achieve the specific processing purpose.
As a rule, personal data is processed within the territory of the European Economic Area (EEA). If the Controller uses the services of technology providers established outside the EEA, personal data may be transferred to third countries only in accordance with the applicable provisions of the GDPR.
In particular, the transfer of data may take place only where:
The Controller exercises due diligence to ensure that each data recipient provides an adequate level of personal data protection.
The Controller stores personal data only for the period necessary to achieve the purposes for which it was collected, unless applicable law requires a longer retention period. Data may be stored for the following periods:
After the retention period expires, the data is deleted or anonymized, unless further storage is required by applicable law.
Every person whose data is processed by the Controller is entitled to the rights arising from the GDPR. The data subject has the right to:
The Controller responds to data subjects' requests without undue delay, no later than within one month of receiving the request, unless the law provides for the possibility of extending this period.
The Controller may use partially automated processes for the purpose of:
The Controller does not make decisions producing legal effects concerning the user based solely on automated data processing, unless permitted by applicable law.
The Platform uses cookies and similar technologies to ensure the proper functioning of the website and mobile application. Cookies are small text files stored on the user's device while using the Platform.
The Controller uses the following types of cookies:
Detailed rules for the use of cookies are set out in the separate Cookie Policy. The user may change cookie settings at any time using the settings of their web browser or mobile device. Restricting the use of cookies may affect the proper functioning of certain Platform services.
The Controller applies appropriate organizational and technical measures to ensure the security of personal data. In particular, the Controller applies:
Access to personal data is held only by persons authorized by the Controller or by entities processing data under appropriate agreements. The Controller takes action to reduce the risk of loss, destruction, disclosure, or unauthorized use of personal data.
The Platform services are not intended for persons under 18 years of age, unless applicable law provides otherwise. The Controller does not knowingly collect the personal data of children.
If the Controller becomes aware of the processing of a child's data without the required legal basis, it will promptly take action to delete such data.
The Controller reserves the right to amend this Privacy Policy in the event of:
The current version of the Privacy Policy is published on the Platform's website. In the event of significant changes, users may be informed via e-mail, the mobile application, or the Platform's website.
For matters concerning the protection of personal data, please contact the Controller:
The Controller handles requests concerning the protection of personal data without undue delay, in accordance with applicable law.
This Privacy Policy is an integral part of the legal documentation of the PL Taxi Platform.
In matters not regulated by this Policy, the provisions of the GDPR and applicable laws of the Republic of Poland apply.
If any provision of this Policy is found to be invalid, the remaining provisions retain full force and effect. This Privacy Policy applies to all users of the PL Taxi Platform.