Legal
Privacy Policy
Information on the processing of personal data under Article 13 GDPR. Version: 20 September 2026
1. Controller
The controller under the GDPR is:
Fare Mobility Pre-launch: information will be added before public launch.
Pre-launch: information will be added before public launch.
Pre-launch: information will be added before public launch.
Germany
Email: info@fare-mobility.de
Phone: Pre-launch: information will be added before public launch.
Pre-launch: information will be added before public launch.
2. Data we process
We process the following categories of personal data:
- Account data: email address, first and last name, encrypted password
- Profile data: phone number, address, date of birth and selected plan
- Identification data (KYC): document type and verification status; image data is stored only by the KYC provider
- Trip data: bookings, routes and usage times
- Payment data: payment status and invoice amount; card data is processed only by Stripe
- Consent records: timestamps and versions of accepted terms and policies
- Log data: anonymised IP address after 30 days, browser type and access times
- Communication data: contact requests submitted through the form
3. Purposes and legal bases
Contract performance (Article 6(1)(b) GDPR)
Registration, authentication, billing, provision of mobility services and customer support.
Legal obligations (Article 6(1)(c) GDPR)
Retention of booking and invoice data, KYC duties and anti-money-laundering prevention.
Consent (Article 6(1)(a) GDPR)
Page analytics only where you selected “Accept all”. You can withdraw consent at any time:
Legitimate interests (Article 6(1)(f) GDPR)
Operation and security of IT infrastructure, handling enquiries and abuse prevention.
4. Processors and service providers
We use the following processors for the purposes described in the German policy: Supabase (database and authentication, Frankfurt EU-Central), Vercel (hosting), Vercel Analytics (anonymous analytics), Resend (transactional email), Stripe (payments) and a KYC provider Pre-launch: information will be added before public launch.. The applicable GDPR legal bases and provider privacy policies remain unchanged.
6. Retention periods
- Account data: until account deletion, then pseudonymised
- Booking and invoice data: 10 years under German retention rules
- KYC records: Pre-launch: information will be added before public launch.
- Logs: IP addresses anonymised after 30 days and logs deleted after 90 days
- Consent records: 3 years after withdrawal
- Contact requests: 6 months after handling is complete
7. Your rights
You have the rights of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20) and objection (Article 21) under the GDPR. You may also complain to the competent data protection supervisory authority: Pre-launch: information will be added before public launch..
8. International transfers
Core user data is stored with Supabase in Frankfurt, EU-Central. Where providers process data in the USA, the policy relies on standard contractual clauses and, where applicable, the EU-US Data Privacy Framework.
9. Security
We use encryption in transit and at rest, access controls, authenticated sessions and technical measures to protect personal data. No security measure can guarantee absolute protection.
10. AI and automated decisions
Fare may use AI systems for identity verification. Further information is available in our AI Policy. Where an automated decision has a legal or similarly significant effect, you may request human review under Article 22 GDPR by contacting info@fare-mobility.de.
This policy reflects the current pre-launch technology and is not legal advice. It should be reviewed by a data protection lawyer before launch. Last updated: 20 September 2026.