1. Data Controller
The data controller responsible for processing personal data under the EU General Data Protection Regulation (GDPR) is:
Yaa Solutions GmbH (Blitzride is a brand of Yaa Solutions GmbH)
Oberndorfer Hütte 1
35606 Solms
Germany
Email: contact@yaa-group.com
Authorized representatives: managing directors Asif Mahmood, Muhammad Yousaf, Artium Lond. Commercial register: HRB 134423, Amtsgericht Frankfurt am Main (local court).
2. Data Protection Officer
No Data Protection Officer has been appointed, as there is no legal requirement to do so. For all privacy inquiries, contact contact@yaa-group.com.
3. Overview — What We Process
3.1 When you create an account (both apps)
- Name
- Email address
- Phone number (for SMS OTP verification)
- Profile picture (optional)
- Language preference
3.2 When using the customer app (Blitzride)
- Location data (precise and coarse, only while the app is in use, to find nearby drivers and set pickup points)
- Booking history (pickup and drop-off, timestamp, fare, rating)
- Push notification token
- Device data for diagnostics (app version, OS version, device model)
3.3 When using the driver app (Blitzride Driver)
- Location data including in the background, only while a ride is active or while the driver is online, for transmission to dispatch and display to the customer
- Ride history and earnings
- Microphone recordings (push-to-talk communication with dispatch; recordings are not persistently stored)
- Camera and photo library access (for ride documentation and profile picture)
- Push notification token
3.4 When visiting the website blitzride.de
- Server log data (IP address, timestamp, requested page, browser identifier) — technically required for delivery and security, deleted after 14 days at the latest (Art. 6 (1) (f) GDPR).
- No tracking, analytics or advertising cookies. The website sets no cookies that require consent — which is why there is no cookie banner.
- Fonts are served locally from our own server; visiting the site makes no connection to Google servers (e.g. Google Fonts).
4. Purposes and Legal Bases
| Purpose | Data | Legal basis |
|---|---|---|
| Account creation and management | Name, email, phone | Art. 6 (1) (b) GDPR (contract performance) |
| Ride matching and execution | Location, booking data | Art. 6 (1) (b) GDPR |
| Ride-related push notifications | Push token | Art. 6 (1) (b) GDPR |
| Background location (driver app, only during active shift) | Location | Art. 6 (1) (b) GDPR |
| Error diagnostics and app improvement | Device data, crash logs | Art. 6 (1) (f) GDPR (legitimate interest) |
| Compliance with tax and legal obligations | Booking / billing data | Art. 6 (1) (c) GDPR |
5. No Sharing with Third Parties
We do not sell your data and we do not share it with third parties for advertising, marketing or analytics purposes. There is no ad-network tracking and no transfer to address dealers or data brokers.
Your data stays in Germany: we operate the entire platform (database, backend, web applications) on our own servers in German data centres (Hetzner Online GmbH, server locations Falkenstein and Nuremberg). No US cloud provider is used to store your data.
Personal data is accessible only to the following recipients — and only to the extent strictly necessary to provide our service:
- Licensed local fleet operators in your region — only the details required to carry out a ride (name, pickup and drop-off, phone number for queries). Data processing agreement under Art. 28 GDPR in place.
- Hetzner Online GmbH (Gunzenhausen, Germany) — server infrastructure, hosting exclusively in German data centres. DPA under Art. 28 GDPR in place.
- Google Firebase Cloud Messaging (Google Ireland Limited) — solely for the technical delivery of push notifications; only the device token is transmitted, never ride or profile data.
- Google Maps Platform (Google Ireland Limited) — map display and address search in the apps.
- Stripe Payments Europe, Ltd. (Dublin, Ireland) — card payments only: payment processing. Your card details are processed directly by Stripe and are never stored on our servers.
- fiskaly GmbH (Vienna, Austria) — legally mandated technical security system (TSE) for receipts under the German KassenSichV (§ 146a AO); processes transaction/receipt data only.
- Tax advisors and authorities, where legally required.
All of the above service providers are contractually bound as processors under Art. 28 GDPR and may process your data only on our instructions and only for the stated purpose. No sharing beyond this takes place.
6. International Transfers
Your data is stored and processed on servers in Germany. Only the technical delivery of push notifications (Google Firebase) may involve a transfer to servers outside the EU/EEA; such transfers are based on the EU Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and the EU-US Data Privacy Framework, where applicable.
7. Retention
- Account data: until the account is deleted by the user; afterwards in accordance with statutory retention periods (e.g. § 147 AO, 10 years for billing-relevant records).
- Trip location data: 90 days after trip completion; afterwards only in aggregated, non-personal form.
- Error logs: 30 days.
- Push tokens: until the app is uninstalled or notifications are revoked.
8. Your Rights
You have the right at any time to:
- Access your processed data (Art. 15 GDPR)
- Correct inaccurate data (Art. 16 GDPR)
- Erasure ("right to be forgotten") (Art. 17 GDPR)
- Restrict processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
- Withdraw a given consent with effect for the future
Please direct requests to contact@yaa-group.com.
You also have the right to lodge a complaint with a supervisory authority. The competent authority for us is:
The Hessian Commissioner for Data Protection and Freedom of Information
Postfach 31 63, 65021 Wiesbaden, Germany
Phone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de
Web: datenschutz.hessen.de
9. Account Deletion
You can delete your account at any time within the app under Profile → Delete account, or request deletion in writing at contact@yaa-group.com. We confirm deletion within 30 days, subject to statutory retention obligations.
10. App Permissions in Detail
The apps request the following permissions. You can revoke any permission at any time in Android Settings; individual features will then be unavailable.
| Permission | App | Purpose |
|---|---|---|
| Location (precise / coarse) | Both | Find nearby drivers / broadcast position |
| Background location | Driver | Live location during active ride |
| Foreground service | Driver | Location streaming when app is minimized |
| Microphone | Driver | Push-to-talk with dispatch |
| Camera | Both | Profile picture and ride documentation |
| Photo library | Both | Upload profile picture |
| Notifications | Both | Ride requests, status updates |
| Vibration / wake lock | Both | Notification signal, keep screen on during navigation |
11. Changes to This Policy
We may update this policy if processing changes or legal requirements demand it. We will notify you in-app of material changes.
12. Contact
Questions about this policy: contact@yaa-group.com.