1. Who we are
The controller of your personal data is Kwiker, a company registered in the Republic of Kosovo (“Kwiker”, “we”, “us”).
For any privacy question or request, email info@kwiker.app, or message us on WhatsApp.
2. Scope
This policy applies to the Kwiker mobile application and the kwiker.app website. Kwiker is a carpooling platform: drivers (“providers”) publish routes they are already driving and offer empty seats; passengers book a seat and pay the driver in cash. Kwiker does not transport passengers itself and does not hold or process your payment.
This policy does not cover third-party services you may reach from Kwiker (for example, your phone's maps or messaging apps), which operate under their own privacy policies.
3. Data we collect
We collect only what the service needs to work safely.
| Category | What it includes | Source |
|---|---|---|
| Account & profile | Name, email, phone number, password (stored hashed, never in plain text), profile photo, gender, city, country, language, member-since date | You |
| Identity verification | Verification status and result, document type, verification reference, rejection reason (providers only) | Our verification partner |
| Trips & bookings | Routes, departure times, seats, price, trip status, seat requests, cash-settlement records | You |
| Vehicle (providers) | Make and model, plate, colour, seats, vehicle photo | You |
| Messages & reputation | In-app chat messages between you and the other party, ratings, reviews, reports you file | You |
| Blocking & hidden conversations | The accounts you have blocked and when; which conversations you have removed from your chat list and when | You |
| Location | Trip origin and destination; live location only while a trip is active or you actively share it (see §6) | Your device |
| Safety | Emergency contacts you save, trip/location share links you create | You |
| Device & technical | Push-notification token, platform (iOS/Android), app version, last-active timestamp, diagnostic logs | Your device |
| Referrals | Invite codes you create or use | You |
We do not collect payment-card data, because Kwiker trips are paid in cash directly to the driver.
4. Why we use it & legal basis
We process personal data under the Law on Protection of Personal Data (Law No. 06/L-082) and, where applicable, the GDPR.
| Purpose | Legal basis |
|---|---|
| Create and operate your account; match passengers and drivers; run the booking and trip lifecycle | Performance of a contract |
| Verify provider identity before they can offer rides | Performance of a contract; legitimate interest in community safety; |
| Safety features: SOS, live trip sharing, emergency contacts | Performance of a contract; your consent for location access; vital interests in an emergency |
| Prevent fraud, abuse, and harmful behaviour; handle reports; moderate the community | Legitimate interest in a safe platform |
| Push notifications about your trips and requests | Performance of a contract |
| Product analytics to improve the service | Legitimate interest; consent where required |
| Comply with legal obligations and respond to lawful requests | Legal obligation |
5. Identity verification (providers)
Before a driver can offer rides, they complete an identity check through our verification partner, Didit. The check involves scanning an identity document (ID card, passport, or driver's licence) together with a face-liveness step to confirm the document belongs to the person presenting it.
The liveness step may involve processing biometric data, which is a special category of personal data requiring a specific legal basis and safeguards.
Kwiker receives and stores the outcome of the check (verified / pending / rejected, the document type, a reference, and any rejection reason). Handling and retention of the underlying document images and biometric templates are governed by the verification partner's own policy and our agreement with them.
Passengers are not required to complete identity verification.
6. Location data
Location is used narrowly and never tracked in the background for advertising:
- Trip routes. The origin and destination you enter when posting or searching a trip.
- Live trip location. While a trip is in progress, a driver's live location can be shown to the passengers on that trip, and to anyone the trip has been shared with via a share link.
- Share my location. If you choose to share your current location, we generate a link you send to people you trust, through your own messaging app.
- SOS. If you trigger SOS, the app places a call to the local emergency number (112 in Kosovo) and can share your trip link with your saved emergency contacts.
Share links expire automatically. You can withdraw location permission at any time in your device settings; some safety features will stop working if you do.
6a. Emergency contacts
If you save an emergency contact, you give us that person's name and phone number. They are not a Kwiker user by default and have not agreed to anything — so please only add someone who would expect to hear from you in an emergency.
We use those details for one purpose: when you trigger SOS. If the contact happens to be a Kwiker user, they receive a notification naming you and carrying your live trip link. If they are not, nothing is sent automatically — your phone opens its own share sheet so you send the link yourself. We never message your contacts for any other reason, and we do not read your device address book.
Emergency contacts are deleted with your account. Either you or the contact may ask us to remove them at any time.
7. Messages & reports
In-app chat lets you coordinate a trip with the other party. Messages are stored so that both participants can see the conversation history.
Kwiker staff do not read private conversations as a matter of course. A conversation may be reviewed by authorised staff only when it is reported (by you or the other party), or where required to investigate a safety incident, fraud, or a legal request. Such access is restricted to trained staff and is logged.
Blocking
If you block someone we store which account you blocked and when. The other person is not told. We may also create a moderation report — always when you ask us to, and also when the block affects a trip that has already been booked, because a booking that has to stand needs a record of why.
One thing is worth stating plainly: a message sent to you by someone you have blocked is stored, but never shown to you. The sender sees an ordinary sent message. We do that so that blocking somebody does not quietly tell them they have been blocked, which is what makes the feature safe to use against a person who is harassing you.
Deleting a conversation
Deleting a conversation removes it from your chat list. It does not delete the messages, and it does not remove the conversation for the other person — their copy is unchanged and they are not told. If they message you again, the conversation comes back with its history.
We keep the record of when you hid a conversation. The other half of a conversation is the other person's data and, in a dispute, their evidence — so one participant cannot erase it. To stop someone contacting you, block them. To erase your messages altogether, delete your account.
8. Who we share data with
We do not sell your personal data. We share it only with service providers who process it on our behalf, under contract, and only for the purposes below.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Hosting, database, authentication, file storage, realtime | Substantially all app data |
| Didit | Provider identity verification | Identity document, face liveness, verification result |
| Expo / push services (APNs, FCM) | Delivering push notifications | Push token, notification content |
| Google Maps & Places | Displaying maps, and suggesting addresses as you type | Coordinates and the place text you search for |
| Hostinger (email delivery) | Transactional email — address verification, password reset, and the copy of your data we send when you ask for an export or delete your account | Your email address, the message, and the export file where one is attached |
| Sentry (crash reporting) | Diagnosing crashes and errors in the app | Error details, device model, operating-system and app version, and your account identifier — never your name, email address or IP address. Processed in the European Union. |
Route calculation runs on our own server (router.kwiker.app).
The start and end of a trip are not sent to a third-party routing service.
We may also disclose data to authorities where legally required, and to the other party of a trip to the extent necessary for that trip (for example, your first name, photo, and rating).
An up-to-date sub-processor list is available on request.
9. International transfers
Some providers listed above may process data outside Kosovo, including in the European Economic Area or other countries. Where data is transferred, we rely on appropriate safeguards such as standard contractual clauses or an adequacy decision.
10. How long we keep data
We keep personal data only as long as necessary for the purposes above, or as required by law.
| Data | Retention |
|---|---|
| Account & profile | While your account is active; deleted on account deletion (see Delete your account) |
| Trip & booking records | Six years from the date of the trip — dispute, safety and legal purposes — with your name removed on account deletion |
| Chat messages | Deleted with your account, unless the conversation has been reported — see reports below |
| Identity verification (result, and the document images held by our verification partner) | Five years after your account is deleted, then erased — see below |
| Emergency contacts you saved | Deleted with your account |
| Crash and error reports | Kept for a short diagnostic period (currently 30 days) and then deleted automatically |
| Live location | Transient — pruned shortly after the trip ends |
| Trip/location share links | Expire automatically after the trip |
| Reports, safety incidents, moderation records | Five years after the report is closed — this outlives account deletion, because a report about someone must not disappear when they delete the account it was filed against |
| Re-registration block: a one-way fingerprint of your phone, email and ID document | 90 days from the day you ask to be deleted, so that an account cannot be deleted and re-opened straight away — and indefinitely where the account was removed for a safety reason. It is an irreversible hash — it cannot be turned back into your details, it is never shared, and it is read only when somebody tries to sign up |
| Ratings & reviews you left for others | Retained in anonymised form to preserve the integrity of others' reputation |
| Cash settlement records | Retained for the other party's earnings history, tax and dispute purposes, with your name removed on account deletion |
| Security & audit log | Retained as our record of account and safety actions; the entry no longer identifies you after account deletion |
| Identifiers of deleted or banned accounts | Kept indefinitely as irreversible one-way values only — see below |
Identity-verification data after you delete your account
Deleting your account removes your profile, but the identity check completed by a driver is kept for five years afterwards and then erased. This is deliberate and narrow: it is the only record that can establish who actually drove a given trip, and it is what allows us to answer a court order, a police investigation or a serious safety complaint about a ride that already happened.
Our lawful basis is Article 17(3) GDPR — retention necessary for the establishment, exercise or defence of legal claims, and for compliance with legal obligations. Five years reflects the period in which such a claim can realistically be brought. It is a fixed limit, not an open-ended one, and the data is deleted when it expires.
During that period the data is not used for any other purpose. It is not used to market to you, it does not restore your account, and it is accessible only to authorised staff responding to a specific legal or safety request. We disclose it to the authorities only where we are legally required to — on a valid legal request, never proactively.
Identifiers of deleted or banned accounts
When an account is deleted or permanently banned, we retain irreversible identifiers of that account to prevent re-registration. This is what stops somebody who was removed for harassment, fraud or a safety incident from simply signing up again the next day with the same phone number or identity document.
We do not keep your phone number, email address or identity document. We keep a one-way cryptographic value derived from them, combined with a secret key. It cannot be reversed to reveal the original, and it cannot be read to identify you — it can only be compared against the same value if the same details are presented again at sign-up or identity verification.
Our lawful basis is legitimate interest (Article 6(1)(f) GDPR): protecting our users from people who have already been removed from the platform. You may object under Article 21 — contact us on WhatsApp.
11. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, row-level access controls in our database, restricted and logged staff access to personal data, hashed passwords, and least-privilege credentials for internal tools.
No system is perfectly secure. If a personal-data breach is likely to result in a risk to your rights, we will notify the supervisory authority and, where required, you.
12. Your rights
Subject to the applicable law, you have the right to:
- access the personal data we hold about you, and receive a copy;
- correct inaccurate or incomplete data;
- delete your data (“right to be forgotten”), subject to legal retention;
- restrict or object to processing based on legitimate interest;
- data portability, where processing is based on contract or consent;
- withdraw consent at any time, without affecting prior lawful processing;
- lodge a complaint with the supervisory authority (see §16).
To exercise any right: use Delete your account for deletion, or contact WhatsApp. We will respond within the period required by law. We may need to verify your identity before acting on a request.
13. Minimum age
Kwiker is not intended for children. Passengers must be at least 16 years old, and providers must be at least 18 years old and hold a valid driving licence. If we learn that we have collected data from someone below the minimum age, we will delete it.
15. Changes to this policy
We may update this policy as the product evolves. We will publish the updated version here and change the “last updated” date. Where a change is material, we will notify you in the app or by email before it takes effect.
16. Complaints & contact
If you have a concern, contact us first — we would like the chance to put it right. Email info@kwiker.app, or message us on WhatsApp. We reply within 30 days.
You also have the right to lodge a complaint with the Information and Privacy Agency of the Republic of Kosovo (ivp-rks.org), or with the supervisory authority in your country of residence.