Privacy Policy – TripTrack d.o.o.
Effective Date: 01.01.2026
TripTrack d.o.o. respects your privacy and is committed to protecting personal data in accordance with the EU General Data Protection Regulation (GDPR). This Privacy Policy explains how data is processed when using the TripTrack web application and mobile applications (Android & iOS).
1. Who We Are
Company: TripTrack d.o.o.
Registered in: Slovenia
Email: [email protected]
Role under GDPR: Data Processor
TripTrack provides a mileage and expense management platform for business customers.
2. Roles and Responsibilities
Our customers (companies) are the Data Controllers – they decide what data is collected and how it is used.
TripTrack d.o.o. acts solely as a Data Processor – we process data only to provide and operate the Service and strictly according to customer instructions.
3. What Data Is Processed
Our Service allows customers to store and manage mileage and expense-related data, including:
Web Application
- Employee Data: name, employment-related information, account details
- Vehicle Data: license plate number, VIN, vehicle model, assigned driver name
- Operational Data: trip logs, expenses, receipts, mileage records, approval status, system/account info
Mobile Applications (Android & iOS)
- Vehicle Identifiers: license plate numbers where applicable
- Operational Data: trip updates, expense entries, and scanned receipts
- Location Data: device location only when the driver starts a trip, taps Add Stop at a checkpoint, or ends a trip — to verify stop locations and calculate mileage. Location is not accessed continuously or in the background.
Important: The mobile apps do not display or collect sensitive personal identifiers beyond what is required for trip logging.
4. Purpose of Processing
We process data only to operate and support the mileage and expense processes of our customers, including:
- Trip logging and mileage calculation
- Expense and receipt capture
- Location verification at trip start, stops, and end (mobile apps)
- Mileage reimbursement, approvals, and reporting
We do not:
- Use data for analytics
- Use data for marketing
- Sell or share data
- Profile users
- Process data for any purpose outside the Service
5. Legal Basis
Customers are responsible for ensuring a valid legal basis (e.g., consent, legitimate interest, or legal obligation) for collecting and uploading personal data.
TripTrack processes data solely on behalf of customers under a contractual obligation.
6. Sensitive / Special Category Data
Some employment-related data uploaded by customers may qualify as special category data under GDPR:
TripTrack does not independently assess or classify data sensitivity.
Customers are solely responsible for lawful processing and compliance.
We process such data only to provide the Service.
7. Data Storage and Security
All data is stored and processed within the European Union (Germany).
Infrastructure providers used:
- Hetzner Online GmbH – servers
- DigitalOcean, LLC – database hosting
- Wasabi Technologies, Inc. – data storage
Security Measures
- Encryption in transit and at rest
- Role-based access control
- Secure backups
- Restricted internal access
8. Data Sharing
We do not share data with third parties except trusted infrastructure providers required to operate the Service.
All sub-processors are contractually bound to GDPR-compliant data protection obligations.
9. Data Retention and Deletion
Data is retained for the duration of the customer's subscription.
Upon termination or written request, customer data will be returned or deleted within 30 days, unless legally required otherwise.
TripTrack is not responsible for data loss caused by customer actions or third-party infrastructure failures.
10. Data Subject Rights
As TripTrack is a Data Processor, all GDPR rights (access, correction, deletion, restriction, portability) must be exercised through the customer, who is the Data Controller.
If you are an employee or driver, please contact your employer directly regarding your data.
11. Mobile Applications Data Use (Android & iOS)
The TripTrack mobile applications are used by drivers and employees to:
- Start and log business trips with stop-by-stop tracking
- Capture expenses and scan receipts on the spot
- Submit trips for manager approval and reimbursement
Data collected in mobile apps:
- Vehicle identifiers where applicable (license plate numbers)
- Operational data for trip and expense processing
- Location data – used only when the driver starts a trip, taps Add Stop, or ends a trip, to verify stop locations and calculate mileage. Location is not accessed continuously or in the background.
Key points:
- Mobile apps collect only the data needed for trip logging and expense capture.
- Data is processed only for mileage and expense functionality and is not used for marketing, analytics, or advertising.
12. International Data Transfers
Customer data is processed within the EU. Any transfer outside the EU is protected by GDPR-approved safeguards.
13. Changes to This Policy
We may update this Privacy Policy occasionally. The latest version will always be available on our website with the updated effective date.
14. Contact
For privacy or data protection questions, contact:
TripTrack d.o.o.
Email: [email protected]