Privacy policy
Last updated: 2 August 2026
This policy covers the Ruta passenger app, the Ruta Driver app, the company portal used by taxi operators, and this website. It is written to be read, not to be survived — if anything in it is unclear, ask us and we will explain it.
1. The short version
Ruta connects you with licensed taxi companies and their drivers. To do that we need a small number of things: the phone number you sign in with, where you are being picked up and where you are going, and whatever you type into the app during a ride.
- We do not sell your data, do not share it for advertising, and run no advertising or analytics software of any kind in either app.
- We never ask passengers for a name, an email address, a date of birth or an identity document. A phone number is the whole account.
- We hold no payment card data. The fare is the regulated taxi meter tariff and is paid in cash, directly to the driver.
- Your data lives on servers in Frankfurt, Germany, in the European Union.
- Passengers can delete their account from inside the app, in a few taps, without asking anyone's permission.
Everything below is the detail behind those five statements, including the parts that are less flattering — what we keep even after you ask us to delete, and why.
2. What Ruta is, and is not
Ruta is a technology and dispatch platform. We connect passengers with independent, licensed taxi operators and their drivers. Ruta does not carry passengers, does not own vehicles, does not employ drivers and does not set the fare — the fare is the regulated taxi meter tariff, and it is paid directly to the driver.
This matters for your privacy because it settles who is answerable for what:
- Ruta is the data controller for everything described on this page. We decide what the apps collect, why, and how long it is kept, and we are the ones you hold to account for it.
- Taxi companies are not joint controllers with us. A taxi company receives only what dispatching and completing a ride requires, and only for its own rides — never another company's. In the software this is not a policy but a wall: every operator-owned query is confined to that operator both by the application and by the database itself.
- A taxi company remains responsible in its own right for the records it keeps as an employer and as a licensed carrier — its drivers' contracts, its vehicles, its own bookkeeping. That is its business and its responsibility, not something Ruta controls.
3. Who we are and how to reach us
Ruta is operated by the company below, which is the data controller for the purposes of the GDPR.
- Company
-
LOYALE PROGRAMMING AND GRAPHIC DESIGN W.L.L
لويال تصميم إجرافيك و برمجة ذ.م.م - Legal form
- With Limited Liability Company (W.L.L), Kingdom of Bahrain
- Commercial Registration
- CR 135962-1, issued by the Ministry of Industry and Commerce, Kingdom of Bahrain
- Registered address
- Flat/Shop 119, Building 10, Road 81, Block 419, Jidhafs, Kingdom of Bahrain
- Service operated in
- Sarajevo, Bosnia & Herzegovina
- Privacy contact
- [email protected]
- Data Protection Officer
- None appointed. Ruta does not carry out large-scale monitoring or process special-category data, so a statutory Data Protection Officer is not required; privacy requests go to the address above.
If you just need help with a ride or your account, use the support page — it is faster than writing to the privacy address.
4. The data we collect
We collect what a booking, a ride, or the safety of that ride actually needs, and stop there. It is easiest to follow if we split it by where it comes from.
4.1 What you give us
Your phone number
The mobile number you sign in with, in international format, and the fact that it has been verified by a one-time code. It is your account: it is how we recognise you when you come back, and how the sign-in code reaches you.
We do not ask passengers for a name, an email address, a date of birth or any identity document. Because we never ask, a driver who picks you up sees a generic label where a first name would be.
Where you are going
The pickup and destination of each ride — both the address text and the map coordinates — so we can price the ride, dispatch a car and give the driver somewhere to go. The same for a ride you schedule for later, plus the time you asked for.
Saved places. If you save a "Home" or "Work", we store its label, its address and its coordinates so you do not have to type it again. You can delete a saved place in the app at any time, and deleting it removes it outright.
Address search is not stored. While you are typing into the address box, what you type goes to our server, which asks Google Maps Platform for matching suggestions and hands them straight back to your screen. Nothing on the way keeps your search text — it is answered and discarded. Only the address you actually choose is saved, as part of your booking.
Messages you send during a ride
The text of messages exchanged between passenger and driver in the in-app chat, who sent them and when. They are kept with the trip so that if there is later a complaint about what was agreed — "I said the blue door" — there is a record.
Phone numbers are never exchanged. The driver does not see your number and you do not see theirs. Chat is the only channel between you. Masked in-app calling exists in the platform but is switched off and has no telephony vendor behind it; if that ever changes, this page will change first.
Ratings, comments and complaints
The star rating you give after a ride and any comment you write with it. The driver can rate you in the same way. If you open a complaint about a ride, we store its category, the notes you write and how it was resolved.
If you use a promotional code
The code you entered, the ride it applied to and the discount given — the minimum needed to stop the same code being used twice.
4.2 What we are given by others
If you are a driver
A driver's name, phone number, driving-licence number and licence expiry date, and any licence, identity or medical document the operator uploads, are entered by the taxi company that employs or contracts the driver, in that company's own portal. They are not collected by the driver app: the driver app itself only ever asks for a phone number to sign in. We also hold the vehicle a driver is assigned to, and that vehicle's plate and paperwork.
A driver with a question about that data can ask their operator or ask us directly at the privacy contact above; see section 9 for how a driver's data is erased.
If you work for a taxi company
A company-portal login holds the user's name, email address, optional phone number, role, when they last signed in, and — where the account uses one — a securely hashed password and a second-factor secret. These are created and managed by the operator's own administrator.
From the other person on your ride
The rating and any comment the other party writes about you. Those words are theirs, not yours — which has a consequence for erasure, explained in section 9.
4.3 What we collect automatically
Location
This is the part that differs most between the two apps.
In the passenger app:
- Your device's location is used only while the app is open, to place your pickup pin and show you the vehicle approaching. The passenger app has no permission to read your location in the background. When it is closed or behind another app, it cannot see where you are — this is a property of how the app is built, not a setting we could quietly flip.
- Location is optional. Refuse the permission and the app still works: you type an address or drop a pin instead.
In the driver app:
- While a driver is online or on a trip, the app sends their position continuously, including in the background — behind the navigation app, or with the screen off. A dispatch service cannot match the nearest car, or show you your car on the map, without this.
- The phone shows its own location indicator the whole time this is happening, and the driver can see it.
- When a driver goes offline, the app stops sending location. Not "sends less" — stops.
Your device, so we can reach it
The anonymous push identifier your phone's operating system issues, and which platform it is, so a notification can be delivered to that specific device. Plus a record of the notifications we sent you and whether they were delivered — which is how we answer "the app never told me my car arrived".
Crash and diagnostic reports
When the app crashes or hits an error, a technical report goes to our error-tracking service: what failed, on which screen, which app version, what kind of device.
What is deliberately stripped out. Phone numbers, one-time codes, access tokens, passwords and coordinates are removed on your device, before the report is sent; web addresses have their query strings cut off, because that is where coordinates leak. The reporting tool is configured never to attach your IP address or an identifier of its own, and performance tracing is switched off entirely. These are guarantees written into the app's code, not intentions stated on a webpage.
Technical and security records
Sign-in sessions. When a session started, a truncated description of the device or browser, and a keyed one-way hash of the IP address — never the address itself. It is enough to notice "this account is suddenly being used from somewhere new", and not enough to locate you.
The audit log. Every time Ruta staff or a taxi company's portal user takes an action on personal data, we write a permanent record: who did it, what they did, to which record, when, and the IP address of the person who did it. To be exact: this is the IP of the staff or portal user acting, not of the passenger being acted upon. It is the log that lets us answer "who looked at this?", so it is deliberately hard to erase — see section 8.
Your IP address in transit. Like any internet service, our servers and the security provider in front of them necessarily see the IP address your device connects from, and use it briefly to rate-limit requests and block attacks. It is not stored against your account.
4.4 What we do not collect
To be explicit, neither app asks for or receives:
- your contacts, photos, camera, microphone or calendar;
- health or fitness data;
- your browsing history;
- any advertising identifier — there is no advertising, analytics or attribution software in either app, from any vendor;
- any payment card, bank or wallet detail. Fares are paid in cash directly to the driver, so no card ever passes through Ruta at all.
5. Why we use it, and our legal basis
Under the GDPR every use of personal data needs a lawful basis. Here is ours, purpose by purpose, with nothing bundled together to hide it.
| What we do | Using | Legal basis |
|---|---|---|
| Create your account and sign you in | Phone number, one-time code | Contract — Art. 6(1)(b). We cannot give you an account without it. |
| Price a ride, dispatch a car, show it approaching | Pickup and destination, live location, vehicle position | Contract — Art. 6(1)(b) |
| Save your Home and Work | Saved places | Contract — Art. 6(1)(b) |
| Let you and the driver message each other | Chat messages | Contract — Art. 6(1)(b); and our legitimate interest (Art. 6(1)(f)) in having a record if a ride is later disputed |
| Ratings, and acting on a persistent problem | Ratings and comments | Contract — Art. 6(1)(b); and legitimate interest (Art. 6(1)(f)) in service quality and the safety of both sides |
| Handle a complaint about a ride | Complaint notes, the trip record, chat | Contract — Art. 6(1)(b); and legitimate interest (Art. 6(1)(f)) in resolving disputes fairly |
| Tell you your ride was accepted, or your car has arrived | Push token, phone number | Contract — Art. 6(1)(b) |
| Send you marketing messages | Push token, phone number | Your consent — Art. 6(1)(a). Off unless you switch it on, and withdrawable at any time. |
| Fix crashes and keep the app working | Scrubbed crash and error reports | Legitimate interest — Art. 6(1)(f) |
| Detect account takeover, abuse and fraud; keep the audit trail | Session records, audit log, rate-limit counters | Legitimate interest — Art. 6(1)(f) in the security of the service and of everyone using it |
| Keep invoices, payment and accounting records | Taxi companies' billing data; trip and fare records | Legal obligation — Art. 6(1)(c). We are not permitted to delete these on request. |
| Bill taxi companies for their Ruta subscription | Company billing contact name and email | Contract — Art. 6(1)(b) with that company, and legal obligation (Art. 6(1)(c)) for the invoice itself |
| Answer a lawful order from a court or the police | Whatever the order compels | Legal obligation — Art. 6(1)(c); or vital interests (Art. 6(1)(d)) where someone's life or safety is at stake |
Where the basis is legitimate interest, we have weighed it against your interests and you can object — see section 9. Where the basis is consent, you can withdraw it and we stop.
6. Who else sees it
We do not sell your data. We do not share it for advertising. We do not profile you, score you, or build a picture of you as a person.
The other person on your ride
The driver assigned to you sees your first name only — and since we never ask passengers for a name, in practice that is a generic label — together with your rating, the pickup and destination, and your chat messages. The driver never sees your phone number.
You see the driver's name, the vehicle and its plate, their rating and their live position on the map. You do not see their number either.
The taxi company operating your ride
So it can run its own dispatch and handle complaints about its own drivers, the operator's portal shows the ride: pickup and destination, status, the vehicle's live position, the ratings, the chat and any complaint. It shows a masked version of your phone number — the dialling code and the last two digits, nothing between.
A taxi company can only ever see its own rides. That is enforced twice over: once by the application, and again by the database, which will not return another operator's rows even if the application asks.
Ruta staff
Strictly where the job needs it — support handling your complaint, finance reconciling an invoice. Access is default-deny and tied to a role, every staff look-up at personal data writes a permanent audit record, and unusual bursts of access raise an alert automatically.
Our service providers
These companies handle data only on our instructions and only to run the service. They are processors: they may not use your data for their own purposes.
| Provider | What it does for us | What it receives |
|---|---|---|
| DigitalOcean | Hosts the servers, the database, the backups and the uploaded documents. | Everything described on this page. Frankfurt, Germany (EU). Should we ever have to fail over to a standby site, it is Amsterdam — also in the EU. |
| Google — Maps Platform | Address search, geocoding, distances and routes; and the map itself, which your phone draws by talking to Google directly. | The address text you type while searching, and pickup/destination coordinates. Google's global infrastructure. |
| Google — Firebase Cloud Messaging | Delivers push notifications to your device through Apple's push service. | Your device's push token and the notification text. Google's global infrastructure. |
| Infobip | Sends your one-time sign-in code, and ride SMS, by text. | Your phone number and the message. |
| Sentry | Receives crash and error reports, already scrubbed on your device as described in 4.3. | Technical diagnostics only. Sentry's European (Germany) region — verified against the account, not assumed. |
| Cloudflare | Sits in front of our servers for DNS, encryption and protection against attacks. | Connection metadata, including the IP address you connect from. Global edge network. |
| Postmark | Sends transactional email — only for taxi-company billing and receipts, never to passengers or drivers. | The company contact's email address and the message. |
| Paddle | Handles taxi companies' subscription payments to Ruta. | The company's billing contact name and email. No passenger or driver data, and no card details reach Ruta. |
A note about navigation. When a driver starts a trip, the driver app hands the destination to the Google Maps app already on their phone. From that moment Google Maps is being used by the driver as an ordinary Google user, under Google's own privacy policy — not under ours.
Authorities, and other people's rights
We disclose data where the law compels us to — a court order, a lawful request from the police — and where it is necessary to protect someone's life or safety. We will tell you when that happens unless we are legally forbidden from doing so.
If Ruta itself changes hands
If the service is ever sold, merged or transferred, your data would move with it. We would tell you before that happened, and the new owner would be bound by this policy until it published its own.
7. Where your data goes
Three facts, stated plainly, because they do not all point the same way:
- Your data is stored and processed in the European Union. The servers, the database, the backups and the uploaded documents are in Frankfurt, Germany. Crash reports go to a European (Germany) region.
- The service operates in Sarajevo, Bosnia & Herzegovina, which is where the rides happen and where the taxi companies are licensed.
- The company that runs Ruta is registered in the Kingdom of Bahrain (see section 3). Its own staff administer the service, which means personal data can be accessed from Bahrain — a country outside the EEA.
Some of the providers in section 6 also operate globally. Wherever personal data leaves the European Economic Area — including access from Bahrain — it may only do so under a lawful transfer safeguard: an adequacy decision, or contractual clauses approved for that purpose, under Chapter V of the GDPR. If you want to know which mechanism covers a specific provider, ask the privacy contact and we will tell you.
8. How long we keep it
Every row below is enforced by an automatic nightly job, not by somebody remembering.
| What | How long |
|---|---|
| Raw location — the second-by-second track of a vehicle, and drivers' position pings | 90 days, then deleted automatically. |
| Notification delivery records | 180 days, then deleted automatically. |
| Your account — phone number, saved places, notification settings | For as long as your account exists. See section 9 for deletion. |
| Inactive accounts | Anonymised automatically after 3 years with no activity — no ride, no price quote, no scheduled ride and, for a driver, no time online. An account with a ride still in progress, money unsettled or a complaint open is never swept. The system refuses to run this on a window shorter than a year, so it cannot be misconfigured into deleting active people. |
| Ride records — the booking, the trip, the fare, ratings and chat | Kept for as long as the commercial and accounting records that point at them must be kept. The moment you erase your account — or the inactivity sweep reaches it — they are stripped of everything identifying you, so what remains is no longer personal data about you. |
| Financial records — invoices, payments, subscriptions, the accounting ledger | For the period tax and accounting law requires. These survive an erasure request; we are not permitted to delete them. |
| Audit records of staff and portal access to personal data | Kept indefinitely and never deleted — they are append-only, and exist to prove who looked at what. The acting person's IP address is cleared after 12 months, and the database itself refuses to clear one less than 30 days old, so the trail survives even someone with the keys to the application. |
| Driver documents — licence, identity, medical | Held while the driver record exists; deleted from file storage and from the database when that record is erased. |
| Sign-in sessions | Expire automatically. Nothing survives expiry, and there is nothing to sweep. |
9. Your rights, and how to use them
Under the GDPR you have the rights below. Using them is free. We answer within one month; for a genuinely complex request we may extend that by up to two further months, and we will tell you if we do, and why.
Before acting we have to be sure the request is really from you — otherwise the right of access becomes a way for someone else to read your data. We verify through the account itself wherever we can, and by contacting the registered number otherwise. We ask for the least we can get away with, and we do not keep the proof afterwards.
The right to a copy of your data (access and portability)
Email the privacy contact in section 3 and we will send you a machine-readable file containing your profile, your notification settings, your bookings and trips, the ratings you gave and received, your complaints, your saved places, your scheduled rides, your notification history and the chat messages you sent.
Anyone else who necessarily appears in your file — the driver on a ride you took — appears masked: their name reduced to initials and their number to a dialling code and two digits. Yours is masked the same way in theirs.
Being straight with you about how this works today. The export is a built, automated function — a request runs it and produces the file directly from the live system. What does not exist yet is a button for it inside the apps, so today you ask by email and we run it for you. When a self-service download ships, this page will say so.
The right to correction
If something we hold about you is wrong, tell the privacy contact and we will fix it. Passengers can edit their saved places directly in the app. Drivers should ask their taxi company first, since the company enters and maintains driver records — including the licence details it is legally required to hold.
The right to erasure ("the right to be forgotten")
If you are a passenger
You can delete your account yourself, from inside the app, without asking us:
- Open the Account tab.
- Tap Delete account.
- Read what happens, then tap Continue.
- Type the confirmation code we text to your number. That code is the last step, and it exists so that a stranger holding your unlocked phone cannot close your account.
Nothing is erased until you enter the code. Once you do, deletion is immediate and cannot be undone. You cannot delete while a ride is in progress or a scheduled ride is still pending — finish or cancel it first, so that nobody disappears mid-trip.
If you have already uninstalled the app, or would rather not reinstall it, the email route is on the support page.
If you are a driver
A driver account is not self-service, and the driver app says so rather than showing a button that would fail. The account is created by the taxi company you drive for and carries the licence details and documents that company is legally required to hold as the actual carrier; a driver erasing it unilaterally would silently rewrite another company's regulated records.
So ask the company you drive for to request deletion, or write to us directly if it will not act. Either way we complete it within 30 days, and the erasure that runs is exactly the same one the app performs for passengers.
What actually happens when an account is erased
- Your name, phone number and email are replaced with an irreversible token. You can no longer sign in, and nobody — us included — can work backwards from the token to your number.
- Your saved places are deleted outright.
- The addresses and coordinates on your past bookings and price quotes are erased. Where a record cannot legally be left empty, the coordinates are blurred to roughly a one-kilometre area instead.
- The second-by-second location trail of your trips is deleted immediately, rather than waiting for the 90-day sweep.
- Text you wrote — a rating comment, a chat message, a complaint — is redacted.
- Your notification history and settings are deleted, and your contact details are scrubbed out of any message still queued to be sent to you.
- For a driver, the uploaded licence and identity documents are deleted from file storage as well as from the database.
- Every sign-in session is revoked, on every device.
- You disappear from dispatch, from fleet lists and from staff search.
What survives, and why
- Invoices, payments, subscriptions and accounting-ledger entries. Tax and accounting law requires businesses to keep them; we are not permitted to delete them.
- The audit record of the erasure itself — proof that an account was erased, by whom and when. It carries no name and no number.
- The ride and booking rows themselves, because a payment or a rating record points at them — but stripped of everything that identifies you.
- Comments other people wrote about you. Those are that person's own words and their own record. Erasing them would take away someone else's rights, not exercise yours.
None of what survives carries your name, your number or your address.
The right to object, and to restrict processing
Where we rely on legitimate interests — the rows marked as such in section 5 — you can object. Tell us why and we will stop, unless we can show compelling grounds that override your objection, or we need the data to establish or defend a legal claim.
You can also ask us to freeze processing while a dispute about accuracy or lawfulness is being worked out. We will hold the data and not use it while that is unresolved.
The right to withdraw consent
Marketing messages are off unless you switch them on. That is not a setting we default for you — it is enforced on our servers: with no explicit opt-in recorded, the marketing channel is treated as off and nothing is sent. To turn it on or off, email the privacy contact and we act immediately.
Again, being straight about how this works today. There is no marketing toggle inside the apps yet — the setting exists and is honoured, but changing it goes through us. Because the default is off, nobody is being messaged who has not asked to be. When an in-app toggle ships, this page will say so.
Location permission is withdrawn in your phone's own settings and takes effect straight away. Withdrawing consent does not undo anything we lawfully did before you withdrew it.
Automated decision-making
Ruta matches a booking to the nearest suitable available driver automatically. That is a routine dispatch calculation over distance and availability. It produces no legal effect and nothing similarly significant for you, and there is no profiling, scoring, or automated decision-making about you as a person.
10. Cookies and similar technology
This website sets no cookies at all. It runs no analytics, loads no fonts, scripts, images or styles from any other host, and is blocked from doing so by its own security policy — which is checked automatically before the site can be published. There is no consent banner because there is nothing to consent to.
The apps use no cookies either. Your sign-in token is held in your phone's own secure storage — the Keychain on iPhone — not in ordinary app settings.
The taxi-company portal and Ruta's internal admin tool do use cookies, and only strictly necessary ones: a session cookie, a refresh cookie and an anti-forgery cookie that stops a malicious site acting on a logged-in user's behalf. None of them tracks anybody.
11. How we protect it
Everything travels over encrypted connections, and everything at rest — database, backups, uploaded files — is encrypted. Sign-in codes are stored only as a strong one-way hash, are single-use, and are capped and rate-limited so they cannot be guessed. Access inside Ruta is default-deny and role-based, staff access to personal data is logged, unusual bursts of access raise an automatic alert, and each taxi company's data is walled off from every other one at both the application and the database level. We keep our software dependencies patched, block secrets from ever reaching the codebase, bound how long any single database query may run, and scan the running system automatically for known weaknesses.
No system is perfectly secure. If a breach ever puts your rights at risk, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and tell you directly where the law requires it.
12. Children
Ruta is not for children. You must be at least 18 to hold an account. We do not knowingly collect data about children; if we learn that we have, we delete it. If you believe a child is using Ruta, tell the privacy contact and we will act.
13. Changes to this policy
If we change how we handle your data, we will update this page and change the "Last updated" date at the top. Where a change materially affects you, we will tell you in the app or by message before it takes effect — we do not change the rules quietly. Where a change needs your consent, we will ask for it rather than assume it.
14. Which law applies, and how to complain
Come to us first, at the privacy contact in section 3. We would much rather fix a problem than have you take it to a regulator, and we can usually fix it faster.
If that does not resolve it, you have the right to complain to a data protection authority. Which authority, and which law governs this service, follows from the three facts in section 7: the controller is registered in Bahrain, the service operates in Bosnia & Herzegovina, and personal data is hosted in the European Union.
Rather than pick one and hope, we have written this policy to the GDPR — the strictest of the three regimes, and the one the software already implements. If you are in the EU or the EEA, you may complain to the supervisory authority in the country where you live or work, or where the problem happened. If you are in Bosnia & Herzegovina, the national personal-data protection authority is the route. We will not use a jurisdictional argument to avoid honouring any right described on this page.
Legal review outstanding. The governing-law clause and the identification of the competent supervisory authority are the two points on this page that a qualified lawyer must settle and sign off, because they turn on facts about corporate presence that are a genuine legal question rather than an engineering one. Everything else on this page describes what the software actually does and has been checked against it. Until that sign-off, treat this section as a statement of the facts and of our commitment — not as a determination of which law governs.
15. Contact
- Privacy and data requests
- [email protected]
- Everything else
- rutaapp.co/support
- Controller
- LOYALE PROGRAMMING AND GRAPHIC DESIGN W.L.L · CR 135962-1 · Flat/Shop 119, Building 10, Road 81, Block 419, Jidhafs, Kingdom of Bahrain
Last updated: 2 August 2026