Privacy Policy

Privacy Policy of inOneCar.com

Last updated: April 2025

This Privacy Policy outlines the rules for processing personal data by the Data Controller when using only the inOneCar Mobile Application, in accordance with applicable law, including the GDPR and the Digital Services Act (DSA). It does not cover third-party websites and services that may be accessed through links available within the application.

1. Data Controller

The Data Controller is inOneCar.com sp. z o.o., with its registered office at ul. Wrocławska 42, 56-400 Oleśnica, Poland, entered into the Register of Entrepreneurs of the National Court Register maintained by the District Court for Wrocław-Fabryczna in Wrocław, 9th Commercial Division, under KRS number: 0000451895, NIP: 9112006834, REGON: 022075110 (hereinafter: the Controller or inOneCar.com). The Controller and its subcontractors and affiliates process Users' personal data and information that may constitute the Users' trade secrets. For matters related to personal data, please contact: kontakt@inonecar.com.

2. Scope of Collected Data

We collect and process the following data:

  • name, surname, email address, phone number (for registration and user identification),
  • device identifier (Device ID),
  • profile data (e.g., name, surname, profile visibility, contact details such as email and phone, car information),
  • location data (details below).

Data may be obtained directly from the user or automatically via the mobile device, local data storage mechanisms (e.g., app cache), or user interaction with the application.

3. Location Data

The inOneCar app may process user location data to:

  • show available rides nearby,
  • define routes and pick-up points,
  • match users for shared rides,
  • enable real-time tracking of the driver's location by the passenger, with the driver's consent to share location.

Location data is collected when the application is actively used and, with the user's consent, also in the background. The user can withdraw consent at any time in device settings. This data is not shared with third parties.

4. Purpose of Data Processing

Personal data is processed to:

  • provide and personalize services,
  • enable contact between users,
  • handle complaints and inquiries,
  • communicate information about services,
  • fulfill legal obligations,
  • ensure platform security and stability.

5. Legal Basis for Processing

Data is processed in accordance with GDPR and DSA based on:

  • user consent (e.g., location, marketing, communication),
  • a contract indirectly concluded between the employer (a company using inOneCar.com services) and the Controller, granting employees access to the application,
  • a data processing agreement between the client company (employer) and the Controller, under which user data is processed for service provision,
  • legal obligations (e.g., billing, documentation),
  • legitimate interests of the Controller (e.g., functionality development, compliance, security).

Where the user accesses the application as an employee of a client company, the employer may also fulfill the information obligation, per the data processing agreement with the Controller. The Controller recommends that the client company inform its employees about data processing principles in connection with the application.

6. Local Mechanisms and Analytics Tools

The inOneCar application may use local equivalents of cookies (e.g., session tokens, app cache) solely to:

  • adapt the app's operation to user preferences,
  • ensure the app's security and stability.

We do not use third-party cookies or activity tracking tools within the app. The application uses Google services (e.g., Firebase/Analytics) in compliance with applicable law and based on anonymized data. No user-identifiable data is stored or shared.

7. Data Retention

Data is stored as long as necessary to achieve the purposes for which it was collected – including service provision under a client contract – unless legal regulations require a longer retention period (e.g., for accounting or tax purposes).

After withdrawal of consent, account deactivation, or the end of cooperation with the client company, data is deleted or anonymized unless further processing is necessary to fulfill legal obligations, resolve complaints, or protect the Controller's claims.

8. User Rights

The user has the right to:

  • access their personal data,
  • request its rectification, completion, deletion, or restriction of processing,
  • object to processing,
  • data portability,
  • object to profiling or automated decision-making.

Requests may be submitted by sending an email from the account-associated address to: kontakt@inonecar.com. The Controller will make every effort to respond within 30 days unless otherwise required by law. In the case of a deletion request, data may be retained only to the extent required by law.

Users may also edit their data directly in the inOneCar mobile app in the "Profile" section – including name, surname, email address, phone number, other contact details, and password. Profile visibility is set automatically and cannot be edited by the user.

9. Data Security

To ensure the security of personal data, the Controller applies appropriate technical and organizational measures, including:

  • encryption of data transmission using SSL protocol,
  • password-protected user accounts (minimum 8 characters), which users should keep confidential and not share,
  • sharing the user's phone number only after confirming a ride reservation,
  • restricting access to phone numbers within the employer's corporate network and only after ride confirmation,
  • managing visibility of rides in accordance with user-assigned visibility settings,
  • implementing access control, system monitoring, and physical safeguards against unauthorized access,
  • ensuring only authorized personnel have access to data necessary to provide services,
  • regularly assessing risks and the effectiveness of security measures, in accordance with Article 32 GDPR.

The mobile application is developed in line with best practices for mobile app security, including system updates and permission controls. If using third-party IT services (e.g., cloud, analytics), the Controller selects only providers that meet GDPR-compliant data security standards.

10. Data Sharing

Data is not shared with third parties, except where required by law or governed by contracts with trusted service providers, such as hosting, technical tools, analytics, or IT infrastructure (e.g., Google Firebase, Google Cloud Platform), who process data exclusively on behalf of the Controller and under data processing agreements.

Authorized representatives of client companies (employers of users) may also have access to data, in accordance with cooperation terms agreed between the Controller and the company.

11. International Users

This policy complies with GDPR and the Digital Services Act (DSA). When transferring data outside the European Economic Area (EEA), we apply protection measures in accordance with Article 46 GDPR, including standard contractual clauses approved by the European Commission or adequacy decisions. Data is processed on servers located in the EEA or in countries providing equivalent data protection levels.

12. Contact

For matters related to data processing, please contact:

  • Email: kontakt@inonecar.com
  • Address: inOneCar.com sp. z o.o., ul. Wrocławska 42, 56-400 Oleśnica, Poland

13. Changes to the Privacy Policy

This policy may be updated if legal regulations, supervisory authority recommendations, or the operation of the application changes. Updates will be published at www.inonecar.com/help/privacypolicy and take effect upon publication.

14. Final Information

This Privacy Policy applies exclusively to the use of the inOneCar Mobile Application. All disputes concerning its application shall be resolved in accordance with Polish law. The competent court shall be the one having jurisdiction over the Controller's registered office, unless mandatory provisions of law state otherwise.

Effective Date: April 2, 2025