Limos4 App Privacy Policy
Last updated: 25 September 2026
Applies to: the Limos4 mobile app for iOS and Android (com.limos4.client), version 1.1 and later.
This policy explains what the Limos4 mobile app collects, why, who we share it with, and what control you have. It covers the app only. Our website at www.limos4.com is covered by the Limos4 Privacy Notice. Where the two differ in respect of the app, this policy governs.
1. Who we are
Limos4 GmbH ("Limos4", "we", "us") is the controller of the personal data described here.
Industriestrasse 12
8305 Dietlikon, Zürich
Switzerland
Phone: +41 43 505 24 24
Email: [email protected]
Data Protection Officer
Limos4 GmbH — Data Protection Officer
Dušana Radića 27
37000 Kruševac
Serbia
Email: [email protected]
Phone: +41 78 605 49 88
The Limos4 app is a business-to-business tool. Accounts are created for us by arrangement with your employer or the organisation that holds a Limos4 corporate account — there is no self-service sign-up in the app. Where your organisation determines why and how your data is processed, it acts as controller and we act as its processor; where we decide those things ourselves, we are the controller.
2. Summary
| Do we track you or serve ads? | No. The app contains no advertising, no analytics SDK, no attribution SDK, and no cross-app or cross-site tracking. On iOS the app declares NSPrivacyTracking: false and no tracking domains. |
| Do we collect your device location? | No. The app never requests GPS or network location. Location permissions are blocked in the Android build and no location permission is declared on iOS. Addresses are only ever the ones you type or pick. |
| Do we access your phone's contacts, camera, photos or microphone? | No. |
| Do we record your screen? | Only around an error, and masked on your device first: all text, images and card fields are blocked out before a recording is sent to our error-monitoring provider. See section 3.3. |
| Do we see your card number? | No. Card details go directly from your device to Stripe. Limos4 never receives your full card number or security code. |
| Do we sell your data? | No. We do not sell or share personal data for advertising. |
| The only permission the app asks for | Notifications — and only after an in-app explanation, never on first launch. |
3. What the app collects
3.1 Information you give us
Account and sign-in. Your username, email address, and password when you sign in; your display name, company name, preferred language, and your role or position within your organisation's account. If you use "Remember me", your sign-in identifier (never your password) is kept on your device so it can be pre-filled next time.
Requesting access. If you use the request-access form: your name, work email, mobile number, and your company's name, type, industry, size, website, street, city, postal code, and country, plus any message you write. This is emailed to our team, who set the account up manually.
Bookings. For each reservation: pickup, drop-off and any intermediate stop addresses; date and time; service type (transfer or by-the-hour) and duration; the vehicle class and price you select; passenger and luggage counts; child-seat requirements; and, where relevant, flight details (airline code and flight number; for private aviation the tail number, FBO, and handling agent's contact number), ship name, train station, train number and wagon number, event name, and your purchase-order or cost-centre reference. Any note you write is sent as a reservation comment.
Ride preferences. Cabin temperature, conversation, music, chilled water, chauffeur language, route preference, privacy mode, and service animal. These are stored on your device and appended to the comment on the reservations you make, so that dispatch and your chauffeur can act on them.
Saved places. A label and category, the formatted address, its Google Place identifier and coordinates, any notes you add, and any colleague or passenger you tag. If you share a saved place, the address, coordinates and notes become visible to the colleague you share it with on your organisation's account.
Payments. When you add a card, the card number, expiry and security code are captured by Stripe's own secure input and sent directly from your device to Stripe — they never pass through Limos4's systems. What we receive and store is the Stripe payment-method identifier, the card brand, last four digits and expiry, the cardholder name, and the billing name, email, phone and address you enter. Apple Pay works the same way, with your name and postal address supplied by Wallet.
Change and cancellation requests. Changing or cancelling a ride sends a free-text request to our team by email; we process whatever you write in it.
3.2 Information about other people
The app is built for booking on behalf of others, so it necessarily handles data about people who are not you:
- Passengers and colleagues on your organisation's account. The app displays the names, email addresses and phone numbers already held on your corporate account so you can select who a ride is for or share a saved place with them. The app sends only internal identifiers back to us — it never uploads a third party's name, email or phone.
- Ride details. A ride's detail screen may show the lead passenger's and other passengers' names, emails and phone numbers, who booked the ride, and — once assigned — your chauffeur's name, phone number and vehicle registration. For some organisations' events it also shows details the organisation attaches to the ride, such as the film or programme, the guest's category and the guest manager responsible. Tapping a phone number or email address hands it to your phone's own dialler, email app or share sheet.
If you enter or select another person's details, you are responsible for having a proper basis to share them with us, and for telling that person that their data is processed as described here.
3.3 Information collected automatically
Diagnostics and crash reports. We use Sentry to find and fix crashes and errors. A report may contain your device model, operating system version, app version and build, available memory and storage, battery and screen state, language and time zone, an app installation identifier, the error and its stack trace, and a short trail of recent app activity. We attach only internal identifiers — your user, organisation and role IDs, and codes for your account type and position — never your name, email address or password. A sample of performance traces (currently about one in five sessions' transactions) is also collected.
Before any diagnostic report leaves your device, we strip personal data out of the technical request records it contains: addresses you typed or selected, coordinates, route geometry, ride search terms and access keys are removed automatically, leaving only the endpoint and the error. Our diagnostics therefore tell us what failed, not where you were going.
Screen recordings around errors. The app keeps a short, rolling recording of its own screens on your device. It is sent to Sentry only if an error occurs — up to one minute before the error and the rest of that session — and sessions without an error are never uploaded. Before any frame leaves your device, all text, images and graphics on it, card fields included, are blocked out, so a recording shows the layout of each screen and where you tapped, not what it said. It also lists the network requests the app made, with personal data removed from their addresses as described above; what the requests contained is never included.
Push notifications. If you enable them, we register a notification token issued by the Expo push service, together with your platform (iOS or Android), your chosen app language, and the app version. We do not send a device name, advertising identifier, or location.
App updates. Each time the app starts it asks Expo's update service whether a newer version of the app's code is available. That request tells Expo your platform, the app's runtime version and release channel, a random identifier for this installation, and your IP address. It is not linked to your account.
Version check. When the app starts, and at most every few hours after that, it asks our server which app versions are still supported, so it can tell you when you need to update. The request carries only your platform (iOS or Android).
Server logs. Our API records standard technical information for security and troubleshooting, including IP address, timestamps and the endpoint called.
3.4 What the app does not collect
- Device location. The app has no location permission and no location code. Every coordinate in the app comes from an address you typed or selected, not from your device's GPS.
- Your phone's address book. "Contacts" in the app means people on your organisation's Limos4 account, held on our servers — not your device's contacts.
- Camera, photos, microphone, or files. These permissions are blocked in the Android build and unused on iOS.
- Advertising or tracking identifiers. There is no IDFA/AAID use, no analytics, and no ad or attribution SDK in the app.
- Special-category data. We do not ask for health, biometric, racial, religious, political or sexual-orientation data. Accessibility-related details you choose to provide (child seats requested when booking, or travelling with a service animal) are used solely to fulfil the ride.
4. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6 / Swiss FADP) |
|---|---|---|
| Creating and securing your account, signing you in, refreshing your session | Account and sign-in data | Performance of a contract |
| Quoting, booking, dispatching and completing rides; passing your requirements to the chauffeur | Booking, addresses, passengers, preferences, comments | Performance of a contract |
| Showing your recent rides, notifications and saved places while you are offline | A saved copy on your device | Performance of a contract |
| Setting up and managing your payment methods; billing your organisation | Payment-method identifiers, card metadata, billing details | Performance of a contract; legal obligation (accounting) |
| Sending you ride-status notifications | Push token, platform, language, app version | Consent (you enable notifications and can withdraw at any time) |
| Onboarding a new corporate account | Request-access form data | Steps prior to entering a contract |
| Keeping the app secure, preventing fraud and abuse | Server logs, authentication records | Legitimate interests |
| Diagnosing crashes and errors so the app works | Diagnostic and device data; masked screen recordings around errors | Legitimate interests |
| Meeting accounting, tax and legal retention duties | Booking and invoice records | Legal obligation |
| Answering your support requests | Whatever you send us | Performance of a contract; legitimate interests |
We do not use app data for marketing or advertising. The app sends only ride-related notifications, and we do not build advertising profiles from your app activity.
5. Who we share it with
We share personal data only with the following categories of recipient, each under a written contract that limits them to processing on our instructions.
| Recipient | What they receive | Why |
|---|---|---|
| Your organisation | Your bookings, and the account and billing records associated with them | Your corporate account holder administers the account and is invoiced for rides |
| Chauffeurs and transport partners fulfilling your ride | Pickup, stops and drop-off, timing, passenger name and contact details, ride preferences and comments | To perform the ride you booked |
| Stripe Inc. / Stripe Payments Europe Ltd. | Card details entered on your device, and the billing name, email, phone and address you provide | Payment-method storage and processing — stripe.com/privacy |
| Google (Google Maps Platform) | The address text you type into the search field, the places you select, and the pickup, stop and drop-off addresses and route geometry of rides you view, together with your device's IP address | Address autocomplete, route calculation and the map images shown in the app — policies.google.com/privacy |
| Functional Software, Inc. (Sentry) | Diagnostic, crash and device data and masked screen recordings around errors, with internal user identifiers only | Crash reporting and error monitoring — sentry.io/privacy |
| Expo (Expo Push Service and EAS Update), and Apple (APNs) or Google (FCM) | Your push token and the text of each notification; for updates, your platform, app version, a random installation identifier and IP address | Delivering notifications and app updates — expo.dev/privacy |
| Our IT, hosting and email providers | As needed to run the service | Infrastructure and communications |
We may also disclose personal data where we are legally required to, to establish or defend legal claims, or in connection with a merger, acquisition or sale of assets — in which case we will require the recipient to honour this policy.
Requests to Google Maps are made directly by your device. As a result, Google receives your IP address and the address text involved. If the app is built without a Google Maps key, no such requests are made and the app falls back to an offline illustration of the route.
6. International transfers
Our servers are located in Germany. Personal data is also processed by our group and support teams in Serbia, and by the providers listed above, some of which process data in the United States and other countries.
For transfers out of the EEA, the UK or Switzerland to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum and the Swiss adaptations where relevant), together with supplementary technical and organisational measures. Copies of our data processing agreements incorporating those clauses, and details of the safeguards applied to a specific transfer, are available on request from [email protected].
7. How long we keep it
| Data | Retention |
|---|---|
| Account and profile data | For as long as your account is active. On deletion it is removed or irreversibly anonymised — see section 9. |
| Saved places, ride preferences, payment-method references, notification history and settings | Until you delete them, or until your account is deleted, whichever is first |
| Booking and invoice records | Retained as business records of the corporate client for up to 10 years to meet accounting and tax retention obligations under EU law. After account deletion these records are no longer linked to you personally. |
| The saved copy on your device (recent rides and their routes, notifications, saved places) | Up to 7 days after it was last refreshed, and deleted when you sign out or delete your account |
| Push notification tokens | Until you disable notifications, sign out, or delete your account |
| Diagnostic and crash data | Up to 90 days for crash and error reports and screen recordings, and up to 30 days for performance samples, after which our diagnostics provider deletes them automatically. |
| Server and authentication logs | Up to 90 days |
When we no longer have a lawful basis to keep data, we delete or anonymise it. Where deletion is not immediately possible — for example in backup archives — we isolate the data from further processing until deletion is possible.
8. Your rights
Wherever you are, you can contact us to exercise the rights available to you. If you are in the EEA, the UK or Switzerland, these include the right to:
- access the personal data we hold about you and obtain a copy;
- rectify data that is inaccurate or incomplete;
- erase your data ("right to be forgotten");
- restrict processing in certain circumstances;
- object to processing based on our legitimate interests;
- data portability — receive data you gave us in a structured, machine-readable format;
- withdraw consent at any time where we rely on it (for example, notifications), without affecting processing already carried out;
- not be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not carry out such decision-making in the app.
To exercise any of these, email [email protected] or our DPO at [email protected]. We will respond within one month, and will tell you if we need longer or need to verify your identity first. Exercising your rights is free unless a request is manifestly unfounded or excessive.
Because the app is a corporate service, some requests — particularly about ride records billed to your employer — may need to be directed to your organisation as controller. We will tell you if that is the case.
Complaints. You may lodge a complaint with your local supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC). In the EEA it is your member state's data protection authority; in the UK, the Information Commissioner's Office.
If you are a resident of California or another US state with a comprehensive privacy law, you have rights to know, access, correct, delete and obtain a copy of your personal data, to opt out of sale, sharing and targeted advertising, and not to be discriminated against for exercising them. We do not sell or share personal data, and do not use it for targeted advertising. To exercise these rights, email [email protected].
9. Deleting your account
You can delete your Limos4 account yourself, at any time, in two ways:
- In the app: Account → Delete account. You will be asked to re-enter your password and confirm.
- On the web, without the app installed: https://app.portal.limos4.com/account-deletion
What deletion removes. Your sign-in access is revoked immediately and you are signed out on every device. Your profile details are irreversibly anonymised; your saved places (and any shares of them), your saved payment-method references, your notification history and settings, your feedback, and all access and push tokens are deleted. On your device, the app clears your stored session, remembered sign-in identifier, ride preferences, notification settings and its saved copy of your rides, notifications and saved places; only your theme and language choices remain, and neither identifies you.
What we keep. Records of completed bookings and invoices are kept for up to 10 years to meet accounting and tax retention obligations under EU law, but they are no longer linked to you personally.
Limits you should know about. Free text written by other users on your organisation's account — for example a note on a saved place — may still mention you, and is outside the reach of automated deletion. Our payment provider's own customer record is removed separately by our operations team. If you need a complete erasure beyond the automated process, contact [email protected] and we will carry it out manually.
10. Data stored on your device
The app keeps two kinds of data on your device.
In the operating system's secure storage (iOS Keychain / Android Keystore-backed encrypted storage):
- your session and refresh tokens and their expiry times;
- your profile record (identifiers, email, username, company, role or position, language);
- your sign-in identifier, if you chose "Remember me" — never your password;
- your ride preferences, notification settings and current notification token;
- your appearance and language choices;
- the access token of a session you signed out of, kept only until our server confirms that session has ended.
In the app's private cache folder: a saved copy of your recent rides and their routes, your notifications and your saved places, so the app can show them when you are offline. It is kept for at most 7 days after it was last refreshed, is excluded from device backups, can be cleared by the operating system at any time, and is deleted when you sign out.
Signing out clears your session, your profile and the saved copy; deleting your account clears everything except your appearance and language choices, and any sign-out still waiting to reach our server. Uninstalling the app removes the cache folder and, on Android, everything else. On iOS the operating system can keep an app's Keychain entries after the app is deleted, so when the app is installed again it looks for entries left by an earlier installation, erases them, and ends that installation's session on our server.
11. Security
We protect your data with encryption in transit (HTTPS/TLS) for all network traffic, short-lived access tokens with automatic refresh, secure operating-system storage for credentials on the device, and access controls on our systems. Card data is handled by Stripe, a PCI-DSS Level 1 service provider, and never reaches our systems. Our logging is deliberately designed to exclude address text, coordinates and payment tokens. Screen recordings are masked on your device before upload, so the text, images and card fields on your screen never leave it.
No system can be guaranteed completely secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as required by law.
12. Children
The Limos4 app is a business service intended for use by adults acting for an organisation. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact [email protected] and we will delete it.
Where an adult books a ride for a minor passenger — for example by requesting a child seat — we process only what is needed to carry out that ride safely.
13. Changes to this policy
We may update this policy as the app changes or the law requires. The "Last updated" date at the top always reflects the current version. If we make a material change — for example, collecting a new category of data or adding a new recipient — we will tell you in the app or by email before it takes effect. Please review this policy from time to time.
14. Contact us
| Privacy questions | [email protected] |
| Data Protection Officer | [email protected] · +41 78 605 49 88 |
| Rights requests (US state laws) | [email protected] |
| General support | [email protected] |
| Post | Limos4 GmbH, Industriestrasse 12, 8305 Dietlikon, Zürich, Switzerland · +41 43 505 24 24 |