Last updated: June 24, 2026 · Effective: May 13, 2026
TaxiRadar ("we", "us", "the app") is a notification service that alerts taxi drivers when ride-hailing fare-multiplier (surge) levels rise in selected service areas. This Privacy Policy explains what data we collect, why, who we share it with, and the rights you have over it.
By installing or using TaxiRadar you agree to the practices described below. If you do not agree, do not install the app or uninstall it.
1. Data we collect
1.1 Account identifiers
Anonymous Firebase Authentication ID. On first launch the app receives a random anonymous identifier from Firebase Authentication. It links your preferences and subscription state to this install. It is not derived from any personal information.
Google account email and display name (optional). If you choose to sign in with Google, we receive your Google email address and display name so your subscription and trial state can survive a reinstall or device change. Without sign-in, only the anonymous identifier above is used.
Firebase Cloud Messaging (FCM) token. A device-specific identifier issued by Google so we can send you push notifications. Rotated automatically by the operating system.
Device identifiers and device metadata. An Android device identifier and basic device metadata (model, OS version, app version) are read locally and attached to crash reports and, for internal administrator accounts only, to diagnostic event records.
1.2 Preferences and app settings
Selected service areas (e.g. Zagreb city, Zagreb Airport)
Surge-level threshold at which you wish to be notified (per area)
Notification on/off toggle
Background watcher on/off toggle
Interface language (English / Croatian)
These settings are stored locally on your device and mirrored to our Firebase Realtime Database so that re-installs and device changes restore your preferences.
1.3 Subscription and purchase data
Active entitlements and their expiration timestamps (e.g. "Zagreb monthly/yearly", "Airport monthly/yearly", "combined monthly/yearly")
Subscription product identifiers and period type (trial, monthly, yearly)
Trial eligibility and trial-grant timestamps
Card numbers, billing addresses, and other payment instruments are processed exclusively by Google Play Billing. We never receive or store payment-card data.
1.4 Diagnostics and crash data
Crash reports. Uncaught exceptions, stack traces, and short context strings are collected by Firebase Crashlytics so we can fix bugs.
Basic usage analytics. Firebase Analytics records app-open events and aggregated session data. We do not log screen-level user activity or content viewed.
Administrator diagnostics. For a small number of internal administrator accounts only, the app records detailed notification-delivery events (token refreshes, message receipts, taps, dismissals) so we can verify that the alerting pipeline works. These events are not recorded for normal users.
1.5 Data we do not collect
GPS or any device location signal
Contacts, calendar, SMS, call history
Photos, microphone, camera
Passwords (Google handles authentication tokens; we never see your Google password)
Web browsing history
Biometric or health data
Service-area selection is a city-level preference you set in the app. It is not derived from any location sensor on your device.
2. How we use your data
Deliver push notifications when a surge level crosses the threshold you have configured.
Persist your subscription so you do not have to pay again after re-installing or switching devices (only when you sign in with Google).
Validate purchases and trial eligibility through Google Play Billing and our subscription processor.
Diagnose crashes and operational issues.
Operate the 24/7 monitoring service that produces the surge data the app reports on.
We do not use your data for advertising, profiling, or any form of marketing.
3. Third parties we share data with
We use the following service providers ("processors") to operate the app. All transfers are over HTTPS/TLS.
We do not sell your data. We do not share your data with advertisers. We do not use it to build advertising profiles.
4. Relationship to Bolt and other ride-hailing platforms
TaxiRadar is independent of, and not affiliated with, Bolt Operations OÜ, Uber, or any other ride-hailing operator. We do not access any ride-hailing platform's private API, do not exchange data with them, and do not share any user data with them. The surge information shown in the app is derived from our own monitoring infrastructure.
5. Security
All traffic between the app and our backend is encrypted in transit (HTTPS/TLS).
Realtime Database access rules restrict each user's record to that user's authenticated ID; subscription, entitlement, and administrator fields are writable only by trusted server-side code (Cloud Functions running with administrative privileges).
We store only identifiers and preferences — no passwords, no payment cards, no sensitive personal data.
App requests to our backend are protected by Google Play Integrity attestation (Firebase App Check) to deter abuse.
6. Your rights
If you are in the European Economic Area, the United Kingdom, or another jurisdiction that grants comparable data-protection rights, you have the right to:
Access your data — request a copy of the personal data we hold about you.
Erase your data — we will delete your Firebase Authentication account and the Realtime Database record associated with it within 30 days of a verified request.
Correct inaccurate data.
Object to processing and opt out of non-essential collection (you may disable analytics by uninstalling the app or by requesting we exclude your account).
Portability — receive your data in a machine-readable format.
Withdraw consent — you can sign out of Google at any time and uninstall the app to stop further processing.
Lodge a complaint with a supervisory authority (in Croatia: the Croatian Personal Data Protection Agency, AZOP).
To exercise any of these rights, contact us at the address in Section 11. You can also cancel your subscription at any time from Google Play (Account → Payments & subscriptions → Subscriptions).
7. Data retention
Active accounts: retained while you continue to use the app.
Inactive accounts: we may delete accounts with no activity for 12 months.
Deletion requests: executed within 30 days.
Crash logs: retained by Firebase Crashlytics for up to 90 days (Google's default retention).
Analytics events: retained per Google Analytics retention settings (default 2 months for event-level data).
Subscription records: retained as long as required by tax and consumer-protection law in your jurisdiction (typically up to 10 years for invoicing).
8. International transfers
Our primary data is stored in Google's European region (europe-west1). Some processors (Firebase Cloud Functions, RevenueCat) operate from the United States. These transfers are made under Google's and RevenueCat's standard contractual clauses and other adequacy mechanisms recognised under the GDPR.
9. Children
TaxiRadar is intended for taxi and ride-hailing drivers, a population of working adults. It is not directed at children under 16 and we do not knowingly collect personal data from them. If we learn that we have collected personal data from a child under 16 we will delete it.
10. Changes to this policy
We may revise this policy as the app evolves. The "Last updated" date at the top of this document is authoritative. We will surface material changes in-app before they take effect.
11. Contact
For privacy questions or to exercise any of the rights above, please contact us at: