Privacy Policy — b-tarikak

Last updated: 23 August 2026

Controller: Mohamad Kaddour, Margarethenstraße 22, 65239 Hochheim am Main, Germany

Contact: support@b-tarikak.de

b-tarikak ("the app") connects travelers with people who want to send small

items with them. This policy explains what personal data we process and why.

1. Data we collect

DataWhenWhy (purpose)Legal basis (GDPR Art. 6)
Email addressRegistrationAccount identity, login, one-time codesContract (6(1)(b))
Full nameRegistrationShown to trip/agreement partnersContract
Password (hashed, bcrypt)RegistrationAuthenticationContract
Phone number (optional)Profile, at any timeContact detail you choose to record. Not verified, and never shown to other users — visible only to you and to our administratorsConsent (6(1)(a))
Profile photo (optional)ProfileTrust between usersConsent (6(1)(a))
Receiving address — street, house number, postal code, city, countryPublishing a trip / profilePickup logistics. The house number is never shown publicly; the rest may be shown to matched usersContract
Approximate coordinates (geocoded from the address)Publishing a trip"Near me" distance in searchLegitimate interest (6(1)(f))
Live GPS location (optional, one-off)When you tap "use my location"Center the search near you; not storedConsent
Photograph of your passport data pageAccount verification, if you choose to request itConfirming the name and date of birth you gave us, for the "verified" badgeConsent (6(1)(a))
Name, date of birth and nationality read from the passportDuring that checkCompared with what you typed, so a reviewer can see whether they agreeConsent
A one-way fingerprint of the passport number (HMAC with a secret key)On approvalDetecting one passport being used to verify several accounts. The passport number itself is never stored, and the fingerprint cannot be turned back into itLegitimate interest (6(1)(f))
Feedback message, app version, device typeWhen you send feedback from the "About Us" screenImproving the app and replying to youLegitimate interest (6(1)(f))
IP address attached to feedbackWhen you send feedbackInvestigating abuse of the feedback form only. Erased after 90 daysLegitimate interest
Trips, agreements, item details, chat messages, ratings, reportsUsing the appProviding the serviceContract
Device push tokenIf push is enabledNotificationsConsent
Technical logs (IP, request metadata)Every requestSecurity, abuse prevention, debuggingLegitimate interest
Error records — failing address, error text, and the account id involved (no IP)When a server error occursDiagnosing faults. Deleted after 30 daysLegitimate interest (6(1)(f))
Aggregate daily counters — how often an ad was shown or tapped, which routes were searchedUsing the appStatistics and advertiser reporting. No user identifier, no IP, and no way to link a count back to a personLegitimate interest (6(1)(f))
Campaign code from the link you arrived through, plus your account id and the word "registration"Only once, if you reached the website through one of our campaign links and then created an accountKnowing which campaign brought people who actually signed up. Sent to our own server at go.b-tarikak.deLegitimate interest (6(1)(f))

We do not process payment data in the app (any payment is arranged

off-app between users, or off-app for advertising).

2. Third parties (processors / recipients)

database are located in Germany; no user data is stored outside the EU by us.

Only the place text you type / your address is sent; identified with our

contact email per their usage policy.

That route is removed: passport photographs now go only to our own server in

Germany, over an encrypted connection, and no document is sent to Telegram or

any other messaging service.

infrastructure in Germany. It receives the single registration event

described in the table above. It is ours, not a third party's, and no

advertising network receives it.

to deliver registration and password-reset codes.

or advertising SDK in the app.

We do not sell personal data.

3. Retention & deletion

soft-deleted and then anonymized (name, email and phone scrubbed) while

transaction records needed for disputes/legal obligations are retained for

the legally required period.

deleted the moment a reviewer decides — approved or rejected, the image

and the details read from it are erased together. Anything never reviewed is

deleted automatically after 90 days. Sending one is entirely voluntary:

verification is optional and the app works fully without it.

machine-readable strip first and offers an opinion, but it can neither verify

nor refuse an account on its own — so there is no solely automated decision

about you in the sense of Art. 22 GDPR.

long as the account exists, and is deleted with it. It is a keyed one-way

value: it cannot be turned back into your passport number.

The feedback text itself is kept, as it carries no network identifier once

the IP is gone.

debugging require.

involved — no IP) are deleted automatically after 30 days.

We do not collect your location when you send feedback.

4. Your rights (GDPR)

Access, rectification, erasure, restriction, portability, objection, and the

right to lodge a complaint with a supervisory authority

(for our seat: Der Hessische Beauftragte für Datenschutz und

Informationsfreiheit, Postfach 3163, 65021 Wiesbaden). Contact:

support@b-tarikak.de.

5. Security

Passwords are hashed (bcrypt). Sessions use short-lived access tokens with

rotating refresh tokens. Traffic is encrypted in transit (HTTPS). Access to

production data is restricted.

Passport photographs are additionally encrypted where they are stored, with a

key held outside the database, and every time an administrator opens one it is

recorded — who looked, at whose document, and when.

6. Children

The app is not directed at children under 16, and accounts may only be created

by adults (see the Terms of Service).

7. Changes

We may update this policy; material changes will be announced in-app.