Gareeda
PrivacyTermsSupport

Privacy Policy

Last updated: 2026-08-19

This Privacy Policy explains how Gareeda ("Gareeda", "we", "us", or "our") collects, uses, shares, and protects your personal information when you use the Gareeda mobile application and related services (the "App").

Gareeda is a school and commute transport booking platform operating in Iraq (Kurdistan Region). The App connects parents, guardians, and adult passengers with drivers to arrange real-world transportation.

The App is operated by Gareeda, Star Towers ST-C-3-4, Erbil, Kurdistan Region, Iraq.

By creating an account and using the App, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the App.


1. Summary of Our Privacy Commitments

We want to be direct about the things people care about most:

  • We do not use analytics or advertising SDKs for marketing or profiling. (We use Sentry only for technical crash/error diagnostics — see Section 5.)
  • We do not use advertising SDKs and we do not show ads.
  • We do not track you across other companies' apps or websites, and we do not use your data for Apple App Tracking Transparency (ATT) cross-app tracking.
  • We never sell your personal data.
  • We do not track your location in the background. Location is only accessed while you are actively using the App.

We collect only the information we need to arrange transportation, process payments, keep rides safe, and operate the App.


2. Information We Collect

We collect the following categories of information. For each, we explain what it is and why we collect it.

2.1 Account Information

When you register and manage your account, we collect:

  • First name and last name — to identify you to drivers, staff, and other authorized users, and to display on your profile.
  • Phone number (stored in international +964 E.164 format) — used as your primary login identifier, to send one-time verification codes, and to enable ride-related contact.
  • Email address (optional) — used, if provided, for account recovery and important service communications.
  • Password — stored only as a secure bcrypt hash; we never store your password in plain text and cannot see it.
  • Gender — used to support features such as same-gender ride matching where offered, and to correctly address you in the App.

2.2 Children's Information (entered by the parent or guardian)

If you are a parent or guardian arranging transport for a child, you may add a child profile that includes:

  • Child's first name and last name
  • Gender
  • Grade
  • Date of birth
  • School
  • Home pickup address and school drop-off address

This information is provided by you, the parent or guardian, and is used solely to arrange and manage the child's transportation (for example, matching to the correct school route, scheduling pickups and drop-offs, and giving the assigned driver the information needed to complete the ride safely). See Section 8 (Children's Information) for full details.

2.3 Location Information

We collect precise GPS coordinates in the following situations:

  • When you set a pickup or drop-off point on the map.
  • During an active trip, to provide live driver and passenger trip tracking (so a driver can navigate to the passenger and an authorized parent/passenger can follow the ride in progress).

Location is collected only in the foreground — while you are actively using the App. We do not collect your location in the background and we do not track your movements when the App is not in use.

2.4 Photos and Images

  • Profile picture — an optional image you may upload to your profile.
  • Images sent in chat — photos you choose to send within in-App messages.

Images are stored and delivered through our storage / CDN provider, Bunny.net (see Section 5).

2.5 User-Generated Content

  • Chat messages — text and images exchanged between parents/adult passengers and drivers to coordinate rides.
  • Ratings and reviews — star ratings and written reviews you submit about drivers, used to maintain service quality and safety.

2.6 Device Information

  • Push notification token — a device identifier issued by your operating system that lets us deliver ride and booking notifications (for example, driver assigned, driver arriving, trip completed). Used only to deliver notifications you have enabled.

2.7 Payment Information

  • Records of online payments made through FIB (First Iraqi Bank) and records of cash fares paid to the driver.
  • Invoices generated for your bookings.

Online card/bank payment processing is handled by FIB (First Iraqi Bank). We receive and store transaction records (such as amount, status, and a payment reference) so we can confirm payment, generate invoices, and provide support. See Section 5.

2.8 Driver Information (collected during driver onboarding only)

If you register as a driver, we additionally collect, for identity verification and legal compliance:

  • Government ID number
  • ID card photographs (front and back)
  • Driving license details

This information is used to verify a driver's identity and eligibility to provide transport services and to meet legal and safety obligations.


3. How We Use Your Information

We use the information described above to:

  • Create, authenticate, and manage your account (including sending one-time login codes).
  • Arrange, schedule, and manage transportation bookings and school routes.
  • Match passengers and children to appropriate drivers and routes.
  • Provide live trip tracking and ride coordination between passengers and drivers.
  • Enable in-App messaging between authorized users and drivers.
  • Process and confirm payments and generate invoices.
  • Verify driver identity and eligibility.
  • Send you service and ride-related notifications.
  • Maintain safety and quality through ratings, reviews, and content moderation.
  • Respond to your support requests.
  • Detect, prevent, and address fraud, abuse, security incidents, and violations of our Terms of Use.
  • Comply with applicable legal, accounting, and regulatory obligations.

We do not use your information for advertising, third-party analytics, or cross-app tracking.


4. Legal Bases for Processing

Where applicable data-protection principles apply, we rely on the following bases:

  • Performance of a contract — to provide the transport booking service you request.
  • Consent — for optional features (such as location access, push notifications, and, for parents, providing a child's information).
  • Legal obligation — to retain transaction and identity records as required by law.
  • Legitimate interests — to keep the service safe, prevent abuse, and improve reliability, balanced against your rights.

You may withdraw consent at any time (see Section 9).


Technical and diagnostic data. To keep the service secure and reliable, our servers automatically collect technical data such as your IP address, request logs, device and app version, and error/crash diagnostics. We use this for security, abuse prevention, debugging, and reliability. Crash and error diagnostics may be processed by our error-monitoring provider, Sentry (see Section 5).


5. Third Parties Who Process Data on Our Behalf

We share limited information with the following service providers strictly so they can perform services for us. We do not sell your data, and these providers are permitted to use the data only to provide their service to Gareeda.

Provider What they receive Purpose Privacy policy
Bunny.net Profile pictures, chat images, and driver ID document images File storage and CDN delivery https://bunny.net/privacy
Expo push notification service (delivering to Apple APNs / Google FCM) Device push notification token Deliver ride and booking push notifications https://expo.dev/privacy · https://www.apple.com/legal/privacy · https://policies.google.com/privacy
OTPIQ Phone number Send SMS / WhatsApp one-time login codes https://otpiq.com/privacy
FIB (First Iraqi Bank) Payment/transaction information for online payments Process online ride payments https://fib.iq/privacy-policy
Google Maps Platform Location queries (coordinates, addresses, and search terms) Maps, geocoding, and routing https://policies.google.com/privacy
Hetzner (cloud hosting, EU) with a MySQL database The categories of data described in this Policy Secure hosting and storage of App data https://www.hetzner.com/legal/privacy-policy
Sentry (error monitoring) Diagnostic/error reports and technical logs (may include IP address, device/app version, and error context) Detect, diagnose, and fix crashes and errors https://sentry.io/privacy/

We may also disclose information where required to comply with the law, enforce our Terms of Use, or protect the rights, property, or safety of our users, our drivers, or the public.


6. What We Do NOT Do

To be explicit:

  • We do not use third-party analytics services for advertising or marketing profiling. (We use Sentry solely for technical error monitoring and crash diagnostics — see Section 5.)
  • We do not use advertising networks or advertising SDKs, and we do not display ads.
  • We do not track you across other apps or websites, and we do not engage in App Tracking Transparency (ATT) cross-app tracking.
  • We do not sell your personal information to anyone.

7. Data Retention and Deletion

  • Account and profile data (including children's profiles you have created) is retained until you delete your account. You can delete your account at any time in the App: Settings → Account → Delete Account. Deleting your account removes your account profile and the child profiles you created, subject to the limited legal retention described below.
  • Transaction and invoice records are retained for a limited period as required to meet legal, tax, and accounting obligations, even after account deletion, and are then deleted or anonymized.
  • Driver identity and license records are retained for as long as the driver account is active and for any additional period required by law, after which they are deleted.

When data is no longer needed for the purposes described in this Policy or to meet a legal obligation, we delete or anonymize it.


8. Children's Information

Gareeda is designed for adults (parents, guardians, and adult passengers). Children do not hold accounts and do not use the App directly. A child's information is added and managed by a parent or guardian.

  • Provided by, and consented to by, the parent or guardian. When you add a child, you confirm that you are the child's parent or legal guardian (or are otherwise authorized) and that you consent, on the child's behalf, to the collection and use of that child's information as described here.
  • Purpose limited to transport. Children's data (name, gender, grade, date of birth, school, home pickup and school drop-off addresses) is used only to arrange and carry out the child's transportation and related safety and coordination functions.
  • Never used for advertising or analytics. We do not use children's data for advertising, third-party analytics, profiling for marketing, or any purpose unrelated to arranging the child's transport.
  • No selling. We never sell children's data.
  • Parental control and deletion. You can view, edit, or delete a child's profile in the App at any time, or delete all children's data by deleting your account (Settings → Account → Delete Account).
  • Who can see a child's details. A child's profile is visible to you, to the driver assigned to that booking — who needs to know whom to collect and from where — and to authorised staff. On a shared ride, the other families travelling on the same booking can see who else is travelling with them; sharing a vehicle necessarily means knowing who is in it. If you would rather your child's details were not visible to other families, book a private ride instead of a shared one.
  • Standards. We handle children's information consistent with children's-privacy principles reflected in laws such as COPPA and GDPR (including the principles of parental consent, data minimization, purpose limitation, and no advertising or behavioral profiling of children).

If you believe a child's information has been provided without proper authorization, contact us at privacy@gareeda.app and we will investigate and delete it as appropriate.


9. Your Rights and Choices

Depending on your location, you may have the right to access, correct, delete, or restrict the processing of your personal information, and to object to certain processing or request a copy of your data. To exercise these rights, contact privacy@gareeda.app.

You can also control your data directly:

  • Revoke consent by deleting your account — Settings → Account → Delete Account removes your account and the child profiles you created (subject to the limited legal retention in Section 7).
  • Disable push notifications — turn off notifications for Gareeda in your device settings (or by declining the notification permission). This stops delivery of ride/booking push notifications.
  • Deny or revoke location access — deny the location permission, or turn it off in your device settings. Note that pickup/drop-off selection and live trip tracking rely on location, so some features may not work without it.

We will respond to verified requests within the time required by applicable law.


10. How We Protect Your Information

Security is described here in specifics rather than generalities, so you can judge it rather than take our word for it.

10.1 In transit and at rest

  • Every connection between the App, the dashboard and our servers uses TLS (HTTPS). The App will not send your data over an unencrypted connection.
  • Passwords are stored only as bcrypt hashes. We cannot read your password, and it is never written to logs.
  • The database runs on dedicated infrastructure (Hetzner, EU) and is backed up automatically, with backups verified by restore.

10.2 Your session

  • Access tokens are short-lived (15 minutes) and renewed automatically, so a captured token has a small window of use.
  • Only one session is active per account. Signing in anywhere immediately revokes the previous session. If someone else signs into your account, your device is signed out — which is how you find out.
  • On a phone, session tokens are held in the operating system's secure store (iOS Keychain / Android Keystore), not in ordinary app storage.
  • A reinstall never inherits a previous session. Deleting an app on iOS does not erase its Keychain entries, so a reinstalled app can silently resume the previous owner's account. On first launch after installation we erase any credentials left behind — which matters for a resold, shared or second-hand handset.

10.3 Sign-in and one-time codes

  • One-time codes are stored hashed, expire, can be used once, and are capped at a small number of wrong attempts before they are burned.
  • Each code is bound to the purpose it was issued for. A code sent to sign you in cannot be used to delete your account, and vice versa.
  • Repeated sign-in and code requests are rate limited per source, so an automated guessing attempt is throttled rather than unlimited.
  • Staff accounts on the dashboard support two-factor authentication with an authenticator app and single-use recovery codes.

10.4 Who can see what

  • Every read of a booking, its route and its live location checks membership: the booking's owner, an approved passenger on it, the assigned driver, and authorised staff. Nobody else can retrieve it, including by guessing an identifier.
  • Staff access is limited by role and position — an employee sees only what their role requires.
  • The dashboard is protected against cross-site request forgery, so a malicious page cannot cause an action using a signed-in administrator's session.

10.5 Diagnostics without identity

We collect crash and performance data to fix faults. Our crash reporting is deliberately configured not to attach personal information — no name, phone number or email travels with a crash report.

10.6 If something goes wrong

No system is completely secure, and we will not claim otherwise. If a breach occurs that affects your personal data, we will investigate it, take steps to contain it, and notify affected users and any competent authority as required by applicable law, without undue delay.

You can report a suspected vulnerability or misuse to privacy@gareeda.app. We will not pursue legal action against anyone who reports a genuine security issue to us in good faith and gives us reasonable time to fix it.


11. International Data Transfers

Our service providers (such as Bunny.net, Expo/APNs/FCM, Google Maps Platform, and Hetzner) may process data on servers located outside Iraq. Where information is transferred internationally, we take steps to ensure it remains protected consistent with this Policy and applicable law.


12. Data Retention After You Stop Using the App

If you stop using the App without deleting your account, we retain your information until you delete your account or request deletion, except where a longer retention period is required by law. You may request deletion at any time (see Sections 7 and 9).


13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the App. Your continued use of the App after an update means you accept the revised Policy.


14. Governing Law

This Privacy Policy is governed by the laws of Iraq (Kurdistan Region), without regard to conflict-of-laws principles.


15. Contact Us

If you have questions or requests regarding this Privacy Policy or your personal data:

  • Privacy inquiries: privacy@gareeda.app
  • General support: support@gareeda.app
  • Operator: Gareeda, Star Towers ST-C-3-4, Erbil, Kurdistan Region, Iraq

We will do our best to respond promptly.