Legal · Rider privacy

Svaggy Rider — Privacy Policy

Applies to the Svaggy Rider mobile application (iOS and Android), used by riders delivering with Svaggy in Finland.

1. Who we are

Svaggy is the data controller for the personal data processed through the Svaggy Rider app, except where this policy specifies a third-party processor acting on our behalf.

Contact for privacy questions: privacy@svaggy.com (EU residents may also contact our Data Protection Officer at dpo@svaggy.com).

2. What data we collect, why, and on what legal basis

We collect only the data we need to operate a delivery platform. Each category below explains what we collect, why we collect it, and the legal basis under GDPR Article 6 or 9.

2.1 Identity and contact information

What: name, email address, phone number, date of birth, address, profile photo.

Why: to identify you as a registered rider, communicate with you, verify your eligibility to work with us, and pay you.

Legal basis: contract performance (Art. 6(1)(b)), and compliance with Finnish labour and tax law (Art. 6(1)(c)).

Linked to your identity: yes.

2.2 KYC documents

What: photo of national ID, driving licence, vehicle registration, vehicle insurance, work permit (when applicable), business certificate (for self-employed riders).

Why: to verify your right to work, vehicle ownership and insurance, and (for vehicle-bound deliveries) a valid driving licence.

Legal basis: contract performance (Art. 6(1)(b)), legal obligation (Art. 6(1)(c)), and — for biometric ID elements — your explicit consent (Art. 9(2)(a)).

Linked to your identity: yes.

Retention: 6 months after you leave the platform, or longer if a regulatory window requires (e.g. tax-relevant earnings rows are retained 6 years per Finnish bookkeeping law). KYC documents specifically are deleted automatically by an automated retention sweep.

2.3 Bank and payout information

What: Finnish IBAN, account holder name, social security number (henkilötunnus) where required by Finnish payroll regulations.

Why: to pay your earnings and meet tax-reporting obligations.

Legal basis: contract performance (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).

Linked to your identity: yes.

Storage: social security numbers are encrypted at rest using a dedicated key.

2.4 Location data

What: your phone's GPS location, sampled approximately every 10 seconds while you are online (i.e. signed into the rider app and toggled to active). Foreground and background location.

Why: to assign you to nearby orders, give the customer a live ETA, and verify pickup and drop-off proximity for proof of delivery.

Legal basis: contract performance (Art. 6(1)(b)).

Linked to your identity: yes.

What we do NOT do: track your location when you are signed out, when you have toggled offline, or for cross-app tracking. We do not sell, share, or use your location data for advertising.

Retention: location pings older than 90 days are aggregated to per-shift summaries; raw pings are deleted.

2.5 Delivery photos and proof of delivery

What: photos you take during pickup and drop-off (parcel and receipt photos, when applicable); customer-side OTP confirmations.

Why: to document successful delivery, resolve disputes, and meet our merchants' contractual evidence requirements.

Legal basis: contract performance (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f) — defending the platform against false claims).

Linked to your identity: yes (the rider who took the photo is recorded).

Retention: 90 days, except where a dispute is open (until 30 days after dispute resolution).

2.6 Identifiers and device data

What: rider ID (assigned by us), device ID (FCM token plus Apple or Google advertising identifier where the OS permits), device model and OS version.

Why: to send you push notifications about offers and lifecycle events, to debug app crashes, and to associate analytics events with your account.

Legal basis: contract performance (Art. 6(1)(b)) and — for analytics — legitimate interest (Art. 6(1)(f)).

Linked to your identity: yes.

2.7 Diagnostics and analytics

What: crash logs, performance metrics, in-app event analytics (e.g. "rider opened earnings tab"), session duration.

Why: to improve the app, debug issues, and measure feature adoption.

Legal basis: legitimate interest (Art. 6(1)(f)).

Linked to your identity: no — analytics are pseudonymized via a randomly generated PostHog distinct ID; crash logs include rider ID for triage but never include OTP codes, photos, or location.

2.8 Communication content

What: in-app chat messages between you and customers, support messages between you and Svaggy ops.

Why: to deliver the conversation, resolve disputes, and improve support.

Legal basis: contract performance (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)).

Linked to your identity: yes.

Retention: 30 days for customer chat, 1 year for ops support tickets.

3. Algorithmic management disclosures (EU Platform Work Directive 2024/2831)

Per EU Directive 2024/2831, we disclose how automated systems make decisions affecting you:

  • Order assignment uses your distance to the merchant, current load (whether you're already on an order), recent acceptance rate, direction of travel, and rating to choose which rider receives an offer. The full algorithm is documented in the in-app Work Directive screen under Menu → Settings → Work Directive.

  • Acceptance rate, completion rate, and rating can affect which offers you receive in the future. We disclose your scores to you in the app and re-disclose any change of more than 10%.

  • Account suspension or termination decisions involving algorithmic input are reviewed by a human ops member before taking effect. You may appeal any algorithmic decision through the in-app Help flow.

4. Who we share your data with

We do not sell your data. We share it only with the following processors, each under a Data Processing Agreement (DPA):

4. Who we share your data with
ProcessorWhat they receiveWhyLocation

Better Auth (auth provider)

email, phone, hashed password

sign-in and session management

EU

PostHog (analytics)

pseudonymized event data, no rider name or email

product analytics, feature flags

EU (Frankfurt)

Sentry (error reporting)

crash logs, rider ID, no OTP, photo, or location

debugging

EU (Frankfurt)

Stripe (payments)

bank account details, payout records

rider payouts

EU and US (under SCCs)

Cloudinary (media storage)

KYC documents, proof-of-delivery photos

media hosting

EU (Frankfurt)

Firebase Cloud Messaging (push)

device token (no message body content)

push delivery

US (under SCCs)

Resend (email)

email address, message body

transactional email delivery

EU

Twilio (SMS)

phone number, message body

OTP and SMS

global (under SCCs for non-EU)

Better Stack (status and on-call)

aggregate health signals, no rider PII

platform observability

EU

5. Security

  • All data is encrypted in transit (TLS 1.2 or higher).

  • Sensitive fields at rest: social security numbers are encrypted using a dedicated key; passwords are hashed with bcrypt; KYC documents are stored in Cloudinary signed-URL-only with a short TTL.

  • Access to personal data is logged in our internal audit log; admin views of KYC documents are recorded specifically.

  • We follow SOC 2-aligned access controls and rotate secrets quarterly.

6. Retention

  • Active rider data: retained while you have an active account.

  • KYC documents: automatically deleted 6 months after you leave the platform.

  • Earnings and tax-relevant records: retained 6 years per Finnish bookkeeping law (Kirjanpitolaki 1336/1997 Ch. 2 § 10).

  • Location pings: raw 90 days; aggregated indefinitely.

  • Communication content: customer chat 30 days; ops support 1 year.

  • Analytics events: 13 months (PostHog default), then aggregated.

7. Your rights

Under GDPR you have the right to:

  • Access — request a copy of your data. In-app: Menu → Settings → Privacy → Download my data. The export bundle is delivered via secure link within 30 days (typically minutes).

  • Erasure — request deletion of your data. In-app: Menu → Settings → Privacy → Delete my account. Earnings and tax records are retained for the legal window above; everything else is deleted within 30 days.

  • Rectification — correct inaccurate data via the in-app profile editor or by contacting privacy@svaggy.com.

  • Object — object to processing based on legitimate interest. Contact privacy@svaggy.com.

  • Portability — receive your data in a machine-readable format. Same flow as Access above.

  • Withdraw consent — where processing is based on consent, you can withdraw it. Note this may end your eligibility to use the platform.

  • Lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) — https://tietosuoja.fi/.

8. International transfers

Where processors are located outside the EU/EEA, transfers are protected by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, supplementary measures (encryption, data minimization).

9. Children

Svaggy Rider is not intended for users under 18. We do not knowingly collect data from minors.

10. Changes to this policy

If we make material changes to this policy, we will notify you in-app and require explicit re-acceptance before you continue using the rider app.

11. Contact

  • Privacy questions: privacy@svaggy.com

  • Data Protection Officer: dpo@svaggy.com

  • Finnish supervisory authority: https://tietosuoja.fi/