Privacy Policy — b-tarikak
Last updated: 23 August 2026
Controller: Mohamad Kaddour, Margarethenstraße 22, 65239 Hochheim am Main, Germany
Contact: support@b-tarikak.de
b-tarikak ("the app") connects travelers with people who want to send small
items with them. This policy explains what personal data we process and why.
1. Data we collect
| Data | When | Why (purpose) | Legal basis (GDPR Art. 6) |
|---|---|---|---|
| Email address | Registration | Account identity, login, one-time codes | Contract (6(1)(b)) |
| Full name | Registration | Shown to trip/agreement partners | Contract |
| Password (hashed, bcrypt) | Registration | Authentication | Contract |
| Phone number (optional) | Profile, at any time | Contact detail you choose to record. Not verified, and never shown to other users — visible only to you and to our administrators | Consent (6(1)(a)) |
| Profile photo (optional) | Profile | Trust between users | Consent (6(1)(a)) |
| Receiving address — street, house number, postal code, city, country | Publishing a trip / profile | Pickup logistics. The house number is never shown publicly; the rest may be shown to matched users | Contract |
| Approximate coordinates (geocoded from the address) | Publishing a trip | "Near me" distance in search | Legitimate interest (6(1)(f)) |
| Live GPS location (optional, one-off) | When you tap "use my location" | Center the search near you; not stored | Consent |
| Photograph of your passport data page | Account verification, if you choose to request it | Confirming the name and date of birth you gave us, for the "verified" badge | Consent (6(1)(a)) |
| Name, date of birth and nationality read from the passport | During that check | Compared with what you typed, so a reviewer can see whether they agree | Consent |
| A one-way fingerprint of the passport number (HMAC with a secret key) | On approval | Detecting one passport being used to verify several accounts. The passport number itself is never stored, and the fingerprint cannot be turned back into it | Legitimate interest (6(1)(f)) |
| Feedback message, app version, device type | When you send feedback from the "About Us" screen | Improving the app and replying to you | Legitimate interest (6(1)(f)) |
| IP address attached to feedback | When you send feedback | Investigating abuse of the feedback form only. Erased after 90 days | Legitimate interest |
| Trips, agreements, item details, chat messages, ratings, reports | Using the app | Providing the service | Contract |
| Device push token | If push is enabled | Notifications | Consent |
| Technical logs (IP, request metadata) | Every request | Security, abuse prevention, debugging | Legitimate interest |
| Error records — failing address, error text, and the account id involved (no IP) | When a server error occurs | Diagnosing faults. Deleted after 30 days | Legitimate interest (6(1)(f)) |
| Aggregate daily counters — how often an ad was shown or tapped, which routes were searched | Using the app | Statistics and advertiser reporting. No user identifier, no IP, and no way to link a count back to a person | Legitimate interest (6(1)(f)) |
| Campaign code from the link you arrived through, plus your account id and the word "registration" | Only once, if you reached the website through one of our campaign links and then created an account | Knowing which campaign brought people who actually signed up. Sent to our own server at go.b-tarikak.de | Legitimate interest (6(1)(f)) |
We do not process payment data in the app (any payment is arranged
off-app between users, or off-app for advertising).
2. Third parties (processors / recipients)
- Hosting / database: netcup GmbH, Karlsruhe, Germany. The server and the
database are located in Germany; no user data is stored outside the EU by us.
- OpenStreetMap Nominatim — address ↔ coordinates and city suggestions.
Only the place text you type / your address is sent; identified with our
contact email per their usage policy.
- No Telegram. Identity documents were once sent through a Telegram bot.
That route is removed: passport photographs now go only to our own server in
Germany, over an encrypted connection, and no document is sent to Telegram or
any other messaging service.
go.b-tarikak.de— our own campaign-measurement server, on the same
infrastructure in Germany. It receives the single registration event
described in the table above. It is ours, not a third party's, and no
advertising network receives it.
- Resend (email delivery, EU region) — receives your email address in order
to deliver registration and password-reset codes.
- Google Play — distribution. We do not enable any third-party analytics
or advertising SDK in the app.
We do not sell personal data.
3. Retention & deletion
- You can request deletion in-app / by contacting us. Accounts are
soft-deleted and then anonymized (name, email and phone scrubbed) while
transaction records needed for disputes/legal obligations are retained for
the legally required period.
- Passport photographs are stored encrypted on our server and are
deleted the moment a reviewer decides — approved or rejected, the image
and the details read from it are erased together. Anything never reviewed is
deleted automatically after 90 days. Sending one is entirely voluntary:
verification is optional and the app works fully without it.
- A person always makes the decision. Software reads the passport's
machine-readable strip first and offers an opinion, but it can neither verify
nor refuse an account on its own — so there is no solely automated decision
about you in the sense of Art. 22 GDPR.
- The passport-number fingerprint on an approved account is kept for as
long as the account exists, and is deleted with it. It is a keyed one-way
value: it cannot be turned back into your passport number.
- IP addresses stored with feedback are erased automatically after 90 days.
The feedback text itself is kept, as it carries no network identifier once
the IP is gone.
- Server logs are rotated automatically and kept only as long as security and
debugging require.
- Error records (the failing address, the error text, and the account id
involved — no IP) are deleted automatically after 30 days.
- One-time codes expire within minutes.
We do not collect your location when you send feedback.
4. Your rights (GDPR)
Access, rectification, erasure, restriction, portability, objection, and the
right to lodge a complaint with a supervisory authority
(for our seat: Der Hessische Beauftragte für Datenschutz und
Informationsfreiheit, Postfach 3163, 65021 Wiesbaden). Contact:
support@b-tarikak.de.
5. Security
Passwords are hashed (bcrypt). Sessions use short-lived access tokens with
rotating refresh tokens. Traffic is encrypted in transit (HTTPS). Access to
production data is restricted.
Passport photographs are additionally encrypted where they are stored, with a
key held outside the database, and every time an administrator opens one it is
recorded — who looked, at whose document, and when.
6. Children
The app is not directed at children under 16, and accounts may only be created
by adults (see the Terms of Service).
7. Changes
We may update this policy; material changes will be announced in-app.