Limos4 Chauffeur App Privacy Policy
Last updated: 7 August 2026
Applies to: the Limos4 Chauffeur mobile app for iOS and Android (com.limos4.chauffeur), version 1.0 and later.
This notice explains what the Limos4 Chauffeur app collects, why, who we share it with, and what control you have. It is a work tool for professional chauffeurs: it does not advertise to you, does not profile you, and does not sell anything about you. It covers the app only. Our website at www.limos4.com is covered by the Limos4 Privacy Notice. Where the two differ in respect of the app, this notice governs.
1. In short
| Who is responsible | Limos4 GmbH, Dietlikon, Switzerland |
| The most intrusive thing we collect | Your precise location, including while the app is in the background — but only during an active ride. |
| When tracking stops | The moment you mark the ride Dropped off, No show or Garage in — and at the latest 4 hours after it started. |
| When we never track you | Between rides, before or after your shift, on your days off, while off duty, and on the drive from home to your first pickup. |
| How long we keep the location trail | 90 days, then it is deleted. |
| Do we sell your data? | No. Never. |
| Do we use it for advertising? | No. The app contains no advertising, no analytics SDK, and no attribution SDK. |
| Do we use it to rank, score or discipline you? | No. Your location is never used to assess your performance, rank you, allocate work preferentially, or support disciplinary action. |
| Do we make automated decisions about you? | No. Ride assignment is done by human dispatchers. |
| Deleting your account | In the app under Profile → Sign out → Delete account, or at app.chauffeur.limos4.com/account-deletion |
| Questions | [email protected] |
You have a right to object to our use of your location. Section 11 sets this out separately, because it matters more than the rest of the rights list.
2. Who is responsible for your data
2.1 The controller
Limos4 GmbH ("Limos4", "we", "us") is the controller of the personal data described here.
Industriestrasse 12
8305 Dietlikon, Zürich
Switzerland
Phone: +41 43 505 24 24
Email: [email protected]
Reach us by email, by phone or by post — whichever you prefer.
2.2 Data Protection Officer
Aleksandra Tasić — Data Protection Officer
Dušana Radića 27
37000 Kruševac
Serbia
Email: [email protected]
Phone: +41 78 605 49 88
You can contact her directly and in confidence about anything in this notice.
2.3 If you drive for a partner company
If a partner company employs or contracts you rather than Limos4 directly, two organisations hold data about you and each is responsible for its own part. We are separate controllers, not joint ones.
| Organisation | Responsible for |
|---|---|
| Limos4 GmbH | Your app account and sign-in; the rides dispatched to you through the Limos4 system; the statuses, times and locations you send while driving them; and the documents, receipts, arrival proofs and incident reports you submit through the app. |
| Your partner company | Your employment or contractor relationship — your contract, your pay, your working time, your personnel file, and the driver record they hold. |
We send your partner company the rides assigned to you, their statuses and times, and your location trail for those rides, so they can settle the work with us. Our contract with them forbids using that location data to evaluate, rank or discipline you. It is operational data, not a management tool, and the same rule binds them that binds us (section 4.3).
To have your employment record erased, ask your partner company; we cannot do it for them. To have your Limos4 app account deleted, come to us (section 13).
3. Where your data comes from
- From you — when you sign in, upload a document, log an expense, file an incident report, or set your availability.
- Generated by the app — your location while a ride is active, the timestamps on each ride status, crash reports.
- From your device — the push token, an app-install identifier, your app version and language.
- From Apple, Google or Microsoft — if you use one of those sign-in buttons, they confirm your identity to us (section 4.2).
- From your partner company or from Limos4 dispatch — the driver record that lets us match your login to the rides you are assigned. Where your name, phone number or employer reached us this way rather than from you, the categories concerned are your identity and contact details and your driver or employment reference.
4. What we collect, why, and on what legal basis
Article references are to the GDPR. Where you are in Switzerland the revised Federal Act on Data Protection (nFADP) applies; we process on the same grounds.
Where we rely on legitimate interests (Art. 6(1)(f)), we have weighed our interest against your rights and recorded the result. You can ask us for that assessment at any time — write to [email protected].
4.1 Account and identity
| What | Why | Legal basis |
|---|---|---|
| Name, email address, username | Create and run your account; identify you to dispatch | Performance of a contract — Art. 6(1)(b) |
| Password, stored only as a salted hash | Authenticate you | Performance of a contract |
| Driver number, partner company, employer, role, language | Route the right rides to you; show the app in your language | Performance of a contract |
| Which sign-in methods you have linked | Let you manage them | Performance of a contract |
We never store your password on your device. If you tick "Remember me", only your email address is saved locally.
4.2 Signing in with Apple, Google or Microsoft
| Provider | What we receive |
|---|---|
| Apple | A stable Apple identifier, and — on your first sign-in only — your name and email address. If you choose Hide My Email we receive an Apple private-relay address; Apple forwards our mail to you and can see that we contacted you. A relay address is still your personal data, not an anonymous one. You can switch forwarding off at any time, which would cut our only email channel to you. |
| A stable Google identifier, your email address and your name. If you use a Google Workspace account, the token also tells us your organisation's domain — that is, who employs you. | |
| Microsoft | A stable Microsoft identifier, your email address and your name. If you use a work or school account, the token also tells us which organisation's tenant you belong to. We discard the access and refresh tokens Microsoft issues — we cannot read your mail, files or calendar, and never ask to. |
Legal basis: performance of a contract — you chose this sign-in method. Apple, Google and Microsoft act as independent controllers for the sign-in itself, under their own policies: Apple, Google, Microsoft.
4.3 Location — in full
This is the most intrusive thing the app does, so we set it out completely.
When we collect it. Only while a ride is active — from the moment you set it to Garage out, En route, On location, Passenger on board or On stop. Collection stops by itself when you mark the ride Dropped off, No show, Garage in or Completed; or when 4 hours have passed since tracking began for that ride; or when you sign out.
We do not collect your location between rides, before or after your shift, on your days off, while you are off duty, or on the unpaid drive from home to your first pickup. There is no "always" location permission in this app: on iOS we ask only for While Using the App, and on Android we do not request the background-location permission at all. Collection continues while the app is in the background during an active ride only, and while it does you can see it — Android shows a permanent notification in your status bar saying a ride is in progress, and iOS shows the blue location indicator at the top of the screen. If neither is showing, we are not collecting your location.
| What we collect | Latitude, longitude, accuracy radius, timestamp, speed |
| Precision | Street-level ("balanced" accuracy) — not the highest-precision navigation mode |
| How often | About once a minute while a ride is active |
| Plus | One position fix at each ride-status change, stored with that status |
| Plus | Optionally, the position where you confirmed arrival, if you submit an arrival photo |
Why. So dispatch can locate the vehicle and answer the customer's "where is my driver?"; so the customer sees an accurate ETA for the ride they booked; and so each ride status carries a verifiable time and place, which is what we and our insurers rely on when a ride is disputed.
Our legal basis, and why it is not consent. We rely on legitimate interests (Art. 6(1)(f)). The interest is specific: operating a chauffeur dispatch service in which the ETA given to a customer is accurate and the record of a completed ride is verifiable. It is our interest and our customers'.
We do not rely on your consent, and nothing in the app should be read as asking for it. In a working relationship consent is not freely given, so it would not be a valid basis — and if you could withdraw it and thereby stop being dispatched, the withdrawal would carry a detriment, which proves the consent was never free to begin with. We also do not rely on necessity for the contract: driving for wages is a contract that can be performed without a continuous location trail, and saying otherwise would overstate what the contract requires. Because the basis is legitimate interests, you have the right to object — see section 11.
The permission prompt your phone shows you is a device-level control, and the disclosure screen the app shows beforehand exists because Google Play requires it. Neither is your GDPR consent, and neither changes the basis above.
If you decline or withdraw the device permission. If you are a Limos4 driver, the app will not open an active ride without precise location; it explains why and offers to take you to your settings, and the rest of the app keeps working. This is deliberate: dispatch cannot run a ride it cannot locate, and the ride record would have no verifiable position. If you opened a single ride from a link (section 14), you are not blocked — you can drive the ride with location off, and dispatch and the customer simply will not see your ETA.
We are working on a pause control inside the app, so you can stop location collection for a period without changing your phone's settings. When it ships we will describe it here. We will never ask you why you paused.
Who sees it. Limos4 dispatchers see your live position while a ride is active. Limos4 operations staff can also look up the trail for a past ride as part of their work — for example when reconciling a ride, answering a customer query, or handling a claim. The customer of the ride you are driving sees the vehicle's position and an ETA; they are not shown your name, your phone number or your identity alongside it. Your partner company, if one employs you, receives the trail for their own rides under the contractual restriction described in section 2.3. Nobody else. It is never sold and never used for advertising.
What it is not used for. Your location is used for dispatch, ETA, safety, and investigating a specific reported incident or claim. It is not used to assess your performance, rank you, allocate work preferentially, or support disciplinary action. That applies to Limos4, and by contract to any partner company that receives it. We do not derive driving-behaviour scores from it — no speed monitoring, no harsh-braking analytics, no driver league tables. If that ever changes we will tell you before it does, and you would be able to object first.
| Location data | Kept for |
|---|---|
| The continuous trail during a ride | 90 days, then deleted |
| The single position fix stored with each ride status | Kept with the ride record — see section 9 |
On your device, unsent location samples are discarded once they are more than 15 minutes old.
4.4 Addresses and map look-ups
When you open navigation, or when the app works out the distance to a pickup, the customer's address is passed to your device's map and geocoding services — Apple Maps, Google Maps or Waze, depending on your choice in the app, and the operating system's own geocoder. That is the customer's data rather than yours, but it leaves the device to a third party, so we disclose it. We receive nothing back about you.
4.5 Ride and job data
| What | Why | Legal basis |
|---|---|---|
| The rides assigned to you, with times and addresses | To do the job | Performance of a contract |
| Every status you set, with its timestamp and position | Operational record; proof of service; settlement with partners; insurance evidence | Performance of a contract; legitimate interests; legal obligation |
| Vehicle and licence plate for the ride | Operational record | Performance of a contract |
| Your end-of-ride settlement — vehicle condition, tags, closing remarks | To close the ride and flag issues to fleet and operations | Performance of a contract; legitimate interests |
Setting certain statuses causes the system to send an automatic SMS or email to the customer.
4.6 Expenses and receipts
Amount, currency, category (parking, toll, waiting, cleaning, fuel, other), payment method, your note, and the time you logged it. Why: to reimburse you and reconcile the ride. Legal basis: performance of a contract, and legal obligation — Swiss law requires us to keep business records for ten years (Code of Obligations, Art. 958f).
A receipt photo stays on your phone and is not uploaded to us. It remains there until you delete the receipt or delete your account.
4.7 Compliance documents
Your driving licence, chauffeur or professional permit, ID or passport, and other documents, as a PDF or photo, with an expiry date. These are identity documents. They can show your date of birth, a document or national number, your photograph and your address.
Why: to verify you are licensed to drive and to warn you before a document expires. Operating a chauffeur service with an unlicensed driver is unlawful and uninsurable. Legal basis: legal obligation — our licensing and transport-operator obligations in the markets we operate in — and performance of a contract. Who sees them: Limos4 operations staff who check them, and licensing authorities, regulators or our insurers where they are entitled to ask.
Please upload no more than we ask for. If a document shows something we do not need, you may cover it before photographing, unless it is needed to check the document's validity.
4.8 Arrival-confirmation photos
Where a ride requires proof of arrival: 1–5 camera photos, optionally a short note and the position where you took them. Why: to evidence that the vehicle was at the pickup point at the stated time, which is what settles a no-show dispute. Legal basis: legitimate interests and performance of a contract.
These are photos of a place. Please do not photograph the passenger, and avoid capturing bystanders, other vehicles' plates, or the inside of a private residence.
4.9 Incident reports
Category (damage, accident, dispute, medical, breakdown, other), a free-text description, the ride, the time, and up to 5 photos. Why: to respond, to notify our insurers, and to meet our reporting duties. Legal basis: legitimate interests and legal obligation.
Health information. An incident report — especially under medical or accident — can describe an injury or health condition, yours or someone else's. Where it does, we process that information to establish, exercise or defend legal claims, including insurance and liability claims (Art. 9(2)(f)), and where it concerns you as a worker, to meet our obligations in the field of employment and social security law (Art. 9(2)(b)).
Include only what is needed to describe the incident. Do not record another person's medical details and do not photograph an injured person.
4.10 Availability and off-duty status
The days and time windows you mark yourself available, and whether you are off duty and until when. Why: so dispatch does not offer you rides you cannot take. Legal basis: performance of a contract.
4.11 Device and push notifications
| What | Why |
|---|---|
| Push token, issued by Apple or Google and relayed via Expo's push service | Send you ride and dispatch notifications |
| An app-install identifier — Identifier for Vendor on iOS, Android ID on Android | Know which device to notify; sign you out of a specific device |
| Platform, app version, build, language | Notify you in your language; support you when something breaks |
Legal basis: performance of a contract — dispatch notifications are how the job works. Neither identifier is an advertising ID. The app requests no advertising identifier and contains no advertising, analytics or attribution software. It does not track you across other apps or websites.
Ride notifications can appear on your lock screen, including the ride reference. Change this in your phone's notification settings; mute individual categories in the app. Signing out unregisters the device.
4.12 Crash and error reports
When the app crashes or errors, a diagnostic report goes to Sentry, hosted in the European Union (Germany). It contains the error and code path, your device model, operating system version, app version and locale, and a technical breadcrumb trail.
It is configured not to attach personal identifiers: sending of default personal data is off, no user identity is attached, your IP address is not stored, and authentication tokens, passwords, email addresses, phone numbers and passenger names are stripped before the report leaves your device.
Legal basis: legitimate interests — our interest in an app that works. Diagnostics are the only way we find a crash that happens on one device model. We cannot guarantee no personal data ever reaches a report — an error from our own server could quote back part of a record — so we minimise, we strip against a denylist, and we keep reports for 90 days.
4.13 What stays only on your device
- Session tokens, in the device's hardware-backed secure store (iOS Keychain / Android Keystore)
- A cached copy of your profile, so the app opens without a round trip
- Your remembered email address, if you asked for it
- Receipt photos
- A queue of anything submitted while offline — incident reports and photos, receipts, settlements, arrival proofs — held until it uploads
- Your appearance, language and preferred-navigation settings
On iOS the Keychain can survive deleting the app, so reinstalling may leave you signed in. Sign out first if you are handing the phone to someone else.
5. Passenger data you see in the app
The app shows you the personal data of customers and passengers so you can do the ride: name, phone number, email address, pickup and drop-off addresses, flight details, and booking notes. That data is theirs and Limos4 is its controller. When you use it, you handle it on our behalf:
- Use it only to carry out the ride.
- Do not save passenger contacts to your personal phonebook and do not keep a copy afterwards.
- Do not photograph passengers or share ride details with anyone.
- Do not contact a passenger after the ride except about a lost item, and route that through dispatch.
Calling or texting from the app dials the passenger's real number through your phone's own dialler, so it lands in your device's call and message history. Delete it when the ride is over.
6. Who we share your data with
We do not sell your data and we do not share it for anyone else's marketing. Every organisation listed below that processes data on our behalf is bound by a written contract requiring it to act only on our instructions and to protect your data to the same standard as this notice.
| Recipient | What they receive |
|---|---|
| Limos4 dispatch and operations | Everything you submit through the app |
| The customer of a ride you are driving | The vehicle's position and an ETA while that ride is active — not your name, phone number or identity |
| The partner company you drive for, if Limos4 does not employ you directly | The rides assigned to you with their statuses and times, and your location trail for those rides, for settlement — under the contractual restriction in section 2.3 |
| Booking partners and corporate clients | Ride status updates for the rides they booked |
Our service providers, each acting on our instructions:
| Provider | Role | Where the data goes |
|---|---|---|
| Hetzner Online GmbH | Hosts the Limos4 servers and databases | Germany |
| Cloudflare, Inc. | Sits in front of our servers as a security and content-delivery layer, so it handles app traffic in transit, including your device's IP address | Global edge network; company in the United States |
| Functional Software, Inc. (Sentry) | Crash and error reporting — sentry.io/privacy | Germany (EU region). Account and support data may be handled in the United States |
| 650 Industries, Inc. (Expo) | Relays push notifications to Apple and Google — it receives the push token and the notification text — expo.dev/privacy | United States |
| Google LLC / Google Ireland Ltd (Firebase Cloud Messaging) | Delivers notifications to Android devices — policies.google.com/privacy | Global — no EU-only region for push |
| Apple Inc. (Apple Push Notification service) | Delivers notifications to iOS devices — apple.com/legal/privacy | Global — no EU-only region for push |
| Limos4 operations and support staff in Serbia | Operations, support and data-protection functions | Serbia |
Notifications carry no ride detail. A push message says only that a ride has been assigned, plus a numeric ride reference the app uses to open the right screen. No passenger name, address, phone number or flight detail is ever placed in a notification, so none of it passes through the push relay. The ride details themselves are fetched separately, over an authenticated connection to our own servers in Germany.
Apple, Google and Microsoft act as independent controllers, not as our service providers, for the sign-in itself (section 4.2).
We may also disclose personal data to our insurers and their loss adjusters where an incident, damage or liability claim requires it; to auditors and lawyers under confidentiality; to authorities where we are legally obliged to, or to establish, exercise or defend legal claims; and in connection with a merger, acquisition or sale of assets — in which case we will require the recipient to honour this notice, and you would be told before your data moves.
7. Which countries your data goes to
Limos4 GmbH is in Switzerland. Swiss law requires us to name every country your data is disclosed to, including countries with equivalent protection — so this list includes Germany.
| Country | Who is there | Why it is allowed |
|---|---|---|
| Germany | Hetzner (our servers); Sentry's EU region | Recognised as providing adequate protection. No additional safeguard needed. |
| Switzerland | Limos4 GmbH | Recognised as adequate by the European Commission. |
| Serbia | Limos4 operations, support and data-protection staff | Not covered by an adequacy decision. These transfers are made under the European Commission's Standard Contractual Clauses (Decision 2021/914), with the adaptations required by the Swiss authority. |
| United States | Cloudflare; Expo (push relay); Sentry account and support data; Apple, Google and Microsoft for sign-in and push | Standard Contractual Clauses, or the EU–US Data Privacy Framework where the recipient is certified under it. |
| Elsewhere | Apple and Google operate push infrastructure globally and offer no EU-only region | Standard Contractual Clauses or Data Privacy Framework, as applicable. |
Copies of our data processing agreements incorporating those clauses, and details of the safeguards applied to a specific transfer, are available on request from [email protected].
8. Do you have to provide it?
| Account details (4.1) | Required by our agreement with you. Without them there is no account. |
| Compliance documents (4.7) | Required by law. Without them we cannot lawfully dispatch you. |
| Location during a ride (4.3) | Not a legal requirement, and not something you consent to — but if you switch the device permission off, a Limos4 driver cannot open an active ride. |
| Ride statuses (4.5) | Required by our agreement — they are the record of the work. |
| Everything else — receipt photos, notes, incident detail beyond the facts | Your choice. |
Required fields are marked as such in the app.
9. How long we keep it
| Data | Retention |
|---|---|
| Account, profile, linked sign-ins | While your account is active; deleted or anonymised when you delete it — see section 13 |
| Session tokens on your device | Until they expire or you sign out |
| Continuous location trail during a ride | 90 days |
| Position fix stored with each ride status | With the ride record — 10 years |
| Completed ride records, with statuses and times | 10 years — Swiss Code of Obligations Art. 958f, plus tax and insurance obligations |
| Expense receipts and settlements | 10 years — same basis |
| Arrival-confirmation photos | 10 years — they are proof of service for the ride |
| Incident reports and their photos | 10 years — insurance and liability claims |
| Compliance documents | While valid, then 10 years after expiry, so we can evidence you were licensed for the rides you drove |
| Availability and off-duty records | 12 months |
| Push token and device registration | Until you sign out or unregister the device |
| Crash and error reports | 90 days |
| Data queued on your device | Until it uploads; unsent location samples are discarded after 15 minutes |
When we no longer need something and no retention obligation applies, we delete it, or anonymise it so it can no longer be linked to you. Where deletion is not immediately possible — for example in backup archives — we isolate the data from further processing until deletion is possible.
10. How we protect it
Everything travels over encrypted HTTPS. Session tokens live in your device's hardware-backed secure store, not ordinary app storage. Passwords are stored only as salted hashes. Access inside Limos4 is limited to staff who need it for their role. Crash reports are stripped of identifiers before they leave your device.
No system is perfectly secure. If a breach is likely to result in a high risk to your rights, we will tell you, and we will notify the competent authority as required.
11. Your right to object
You have the right to object, at any time, to our collection and use of your location, and to anything else in this notice that we base on our legitimate interests.
This right exists because we chose legitimate interests as our basis (section 4.3) rather than asking for your consent. It is a real right, not a formality.
To object, email [email protected] and say what you are objecting to. You do not have to give a reason, though telling us about your particular situation helps us weigh it.
When you object we must stop, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or that we need the data to establish, exercise or defend legal claims. We will tell you which it is, in writing, and explain why.
Objecting is not the same as switching off the device permission. The permission is a technical control; an objection is a legal request that we must answer.
We set this out separately, and before the other rights, because the law requires it to be brought explicitly to your attention rather than buried in a list.
12. Your other rights
| Right | What it means, and how to use it | Limits |
|---|---|---|
| Access | Ask us for a copy of the personal data we hold about you and how we use it. We can also tell you the actual identity of everyone we disclosed it to. | We may need to verify who you are first. |
| Rectification | Correct anything inaccurate. You can change most profile details in the app yourself; for the rest, email us. | — |
| Erasure | Have your data deleted. The fastest route is the account-deletion flow in section 13. | Does not reach data we are legally required to keep, or that we need for legal claims. |
| Restriction | Have us pause processing while a dispute about accuracy or our legitimate interests is resolved. | — |
| Portability | Receive the data you gave us, in a structured, machine-readable format. | Covers only data processed on the basis of consent or contract. Your location trail is based on legitimate interests, so it falls outside this right — but you can still get it under the right of access. |
| No automated decisions | We do not make decisions about you by automated means alone — see section 16. | — |
Two working channels, either is fine: [email protected], or post to the Data Protection Officer at the address in section 2.2. We answer within one month and will tell you if we need longer and why. Exercising your rights is free unless a request is manifestly unfounded or excessive.
Complaints. Tell us first — we would rather fix it. You can also go to a regulator or a court. If you are in the EEA, you may complain to a supervisory authority, and you get to choose: the authority where you habitually live, or where you work, or where the thing you are complaining about happened. If you are in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC) can investigate and order measures, but it does not decide individual complaints — your own remedy is a civil action in the Swiss courts, where you can seek an injunction, damages, or a declaration. If you are in the UK, the Information Commissioner's Office.
13. Deleting your account
You can delete your Limos4 chauffeur account yourself, at any time, in two ways:
- In the app: Profile → Sign out → Delete account (email-and-password accounts).
- On the web, without the app installed: https://app.chauffeur.limos4.com/account-deletion — use this if you sign in with Apple, Google or Microsoft, since you have no Limos4 password for us to check.
| What is deleted | Your sign-in and access; your linked Apple, Google and Microsoft sign-ins; your uploaded document records; your availability and notification settings; and your registered devices. You are signed out everywhere and your user record is anonymised. |
| What we keep, and why | Completed ride records, expense receipts, settlements, arrival proofs and incident reports — for 10 years, to meet accounting, tax and insurance obligations. They are restricted to that purpose and removed from day-to-day operational use. The ride record keeps the driver name and phone number as they stood at the time of the ride, because it is the record of who drove it. It is no longer linked to your login, but it is not anonymous. |
| What is not ours to delete | Your driver record at your partner company is deactivated, not deleted — it is their employment record. To have it erased, contact them, or write to [email protected] and we will pass the request on. |
Your location trail is deleted on its own 90-day cycle regardless of whether you delete your account. You do not have to delete your whole account to reduce what we hold: clear your availability, go off duty, or switch off notification categories at any time.
14. If you opened a ride from a link
Some chauffeurs — usually drivers at partner companies — open a single ride by tapping a link sent by SMS or WhatsApp, with no account. If that is you:
- We process the same ride data described above, for that one ride, including your location while it is active, on the same legal basis (section 4.3) and with the same right to object (section 11).
- Where your data came from: your name, phone number and driver reference reached us from your partner company or from the dispatcher who assigned the ride — not from you.
- We create no password and do not ask for your email address.
- The link expires — 24 hours after drop-off, or 72 hours after the scheduled pickup.
- The link gives you access to that ride only. Our servers refuse any request from a link session for a different ride, or for driver lists, documents or account settings.
- You are never shown prices.
- Your partner company remains responsible for your employment record (section 2.3).
- You have no account to delete, so the app cannot offer you a deletion button. To exercise any right — access, objection, erasure — email [email protected] and tell us which ride the link was for, or write to the Data Protection Officer at the address in section 2.2. We will verify your identity through the partner company that assigned the ride.
15. Children
The app is a professional tool for licensed chauffeurs and may not be used by anyone under 18. We do not knowingly collect data from children. If you believe a minor has used the app, contact [email protected] and we will delete the account.
16. Automated decisions
We do not make decisions producing legal or similarly significant effects about you by automated means alone. Ride assignment, document approval and any action following an incident report are decided by people.
17. Changes to this notice
We update this notice when the app changes, and the "Last updated" date at the top always reflects the current version.
If a change materially affects you — a new category of data, a new purpose, a new recipient, a new country, or a change to how you exercise your rights — we will tell you in the app, in a message about that change, before it takes effect. Where the change is fundamental we will tell you far enough in advance that you can object first. We will not ask you to check this page periodically. Keeping you informed is our job, not yours.
18. Contact us
| Privacy questions and rights requests | [email protected] |
| Data Protection Officer | Aleksandra Tasić · [email protected] · +41 78 605 49 88 |
| General support | [email protected] |
| Post | Limos4 GmbH, Industriestrasse 12, 8305 Dietlikon, Zürich, Switzerland · +41 43 505 24 24 |