Privacy Policy
Privacy Policy
Updated at 2025-11-25
About Baxi
Baxi is a non-commercial ride-sharing platform created as a hobby project to help colleagues coordinate carpools to work. It is a digital version of our original Excel sheet where people could write: "I am driving to work at 7AM every morning from this part of town" and find others to share rides with.
Important: Baxi is operated by a private individual (not a company) and is provided as-is to help our community deal with unreliable public transport.
What Baxi Is and Isn't
Baxi is:
- A simple coordination tool for colleagues
- A digital replacement for our shared Excel sheet
- Free and non-commercial
- Run as a hobby project
Baxi is NOT:
- A commercial taxi or ride-hailing service
- Operated by a company
- Sending marketing emails
- Sharing data with advertisers or third parties
- Making any profit
What Information Do We Collect?
We collect only the minimum information necessary to coordinate rides:
- Name / Username
- Email address
- Contact info (optional)
- Password (encrypted)
- Ride information (ads, pickup locations, routes, available seats)
- Chat messages
- Technical data (IP, browser type, etc.)
All data is stored in a MySQL database hosted on our server.
Legal Basis for Processing (GDPR Article 6)
We process your data based on:
- Consent – You voluntarily create an account and post ride information.
- Legitimate Interest – Basic security, system functionality, and automated route matching.
You can withdraw consent at any time by deleting your account.
How Do We Use Your Information?
Your information is used ONLY for:
- Displaying ride offers/requests
- Showing pickup locations and routes on Google Maps
- Automated route matching
- Chat coordination between colleagues
- Email notifications (messages and match alerts)
- Account management and login
- Security, spam prevention, and moderation
- Technical system operation
We do NOT send marketing emails, share data with third parties, or track users for advertising.
Important Privacy Recommendations
Use public pickup points like train stations, road junctions, shopping centers, or landmarks.
⚠️ Share only what's necessary.
⚠️ Use good judgment. Only share rides with colleagues you trust.
Who Can See Your Information?
Other users can see:
- Your name/username
- Your ride ads
- Pickup locations
- Contact info you choose to share
- Your chat messages with them
You can see:
- Your own settings
- Your chats
- Your encrypted password
Admins can access:
- Reported conversations (for safety review)
- Technical logs
- Database contents (only when necessary)
Do We Share Data with Third Parties?
No commercial sharing.
Technical services:
- Strato (hosting provider): Stores the MySQL database
- Google Maps API: Provides map functionality
Safety and moderation:
Reported content may be emailed to the admin for review.
Legal requirements:
Data may be disclosed if legally required.
How Long Do We Keep Your Data?
- Active accounts: kept indefinitely
- Deleted accounts: removed within 60 days
- Chats: Retained but attributed to “Deleted User”
- Backups: up to 6 months
- Reported content: up to 1 year
Your Rights Under GDPR
You have the right to:
- Access your data
- Rectify inaccurate information
- Delete your account
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent
To exercise your rights, email gulyaskata99@gmail.com.
Right to Lodge a Complaint
German Data Protection Authority (BfDI)
Graurheindorfer Str. 153, 53117 Bonn, Germany
Phone: +49 (0)228-997799-0
Email: poststelle@bfdi.bund.de
How Do We Protect Your Data?
- Encrypted passwords
- HTTPS
- Security updates
- Access controls
- Registration password required
- Backups
This is a hobby project, not a professional security operation.
Data Breach Notification
If a serious breach occurs, we will notify authorities within 72 hours and inform all users by email.
International Data Transfers
Data is stored in Germany (Strato). Google Maps may process some data internationally.
Cookies
Only essential cookies are used:
- Session cookie
- Security token
No analytics or advertising cookies.
Google Maps API
Used for location selection, map display, and route visualization.
No Marketing Communications
We never send marketing emails—only essential and functional notifications.
Children's Privacy
This service is for working adults. No accounts under age 16.
Automated Decision-Making
Route matching is automated but has no legal or significant impact—just suggestions.
Community Safety and Moderation
Reported ads and chats may be reviewed. Registration requires a safety password.
This Is a Hobby Project
Provided as-is with no warranty or guaranteed uptime.
Changes to This Privacy Policy
Users will be notified 30 days before changes.
Deleting Your Account
Use Profile → Delete Account, or email the admin.
Contact
Email: gulyaskata99@gmail.com
Philosophy
Baxi exists because public transport is unreliable. Privacy and community safety are core values.