← Back to homeHrvatski
Taximetar

Privacy Policy

Last updated: 14 September 2026

This policy describes how personal data is processed in the Taximetar Android app (package name com.magnamobilitas.taximetar) and on this public website.

1. Data controller

Mobilitas Magna j.d.o.o. za usluge
Croatian personal identification number (OIB): 48345455377
Ulica Ivana Šibla 17, 10000 Zagreb, Croatia
Email: taximetar.magnamobilitas@gmail.com
Website: www.mobilitasmagna.com

2. Data processed by the app

  • Account and business profile: email address, operator name and OIB, business premises, driver, operator and registered device data.
  • Location and trip: precise GPS coordinates, start and end times, origin, destination, confirmed stops, distance, duration and calculated fare.
  • Fiscal data: payment method, invoice number, ZKI, JIR, tax information and submission status. An invoice issued to a business customer also contains the buyer name, OIB and address.
  • Device and support: random installation ID, access approval, expiry date, active device count, saved Bluetooth printer and technical printing log.

The app does not use an IMEI, serial number or Android ID as its installation identifier and does not sell personal data.

3. Purposes and legal bases

  • App features and business account management: performance of a contract or steps requested by the user.
  • GPS measurement, trip calculation, address search and navigation: performance of a contract; Android permission is a technical requirement for location access.
  • Fiscalisation, tax records and invoice retention: compliance with legal obligations.
  • Access verification, security, abuse prevention and diagnostics: performance of a contract and legitimate interests in secure and reliable service operation.

4. Location, addresses and routes

When no trip is active, the app obtains the location once when the Taximeter or Precalculation screen is opened and when the user requests their location. During an active trip, GPS is monitored continuously, including the background operation required for fare calculation. Coordinates are converted to an address at the start of the trip, when a stop is confirmed and at the end of the trip.

Address search and route calculation requests are sent to our proxy service on Cloudflare, which forwards them to Geoapify. A request may contain search text, coordinates, language and route points. The Geoapify key is not stored in the app.

5. Recipients and service providers

  • Supabase: authentication, database, backups, certificates and server functions. The project is configured in a European Union region.
  • Cloudflare and Geoapify: request proxying, address search, reverse geocoding and route calculation.
  • Google Play: app distribution and updates. The app does not use Google Play purchases or subscriptions.
  • Croatian Tax Administration: legally required invoice data when fiscalisation is enabled.
  • Waze or Google Maps: a destination is shared only when the user expressly opens the selected navigation app.

Providers may use their own subprocessors and process limited technical data under their privacy terms and applicable safeguards.

If a provider processes data outside the European Economic Area, the transfer is made subject to safeguards required by applicable data protection law.

6. Local storage, retention and deletion

Tariffs, the active trip, settings and records are stored locally on the device. Users can delete an ordinary trip record and the printer log, or remove local data by clearing the app's data. A PDF is saved only to a location selected by the user. When a user shares a PDF receipt, the file is passed only to the app selected in the Android share sheet.

Business and fiscal data is retained for as long as necessary to provide the service and for the periods required by tax, accounting and other mandatory rules. We may not delete information that we are legally required to retain in response to an account deletion request.

7. Security

Data is transmitted over HTTPS. Access to business data is restricted by authentication, roles and database access policies. Fiscal certificates and their passwords are not embedded in the public app. Only authorised server processes can access them, and they are not displayed to drivers as readable secrets.

8. User rights

Subject to applicable law, users may request access, rectification, deletion, restriction of processing or data portability, or object to processing. Send requests to taximetar.magnamobilitas@gmail.com or use the Account deletion request page.

Users may also lodge a complaint with the Croatian Personal Data Protection Agency (AZOP), azop.hr.

9. Required data and automated checks

Sign-in, device registration, trip calculation and fiscalisation data is required when a user chooses to use those features. Without it, the relevant feature or access to the business account will not be available.

The app automatically checks access validity and device registration against the partner's settings. Users may request a review of such a decision through the contact address above.

10. Children and policy changes

The app is a business tool and is not intended for anyone under 18.

We may update this policy when features, providers or regulations change. The current revision date will always appear on this page.

11. Public website

This website does not use marketing cookies or analytics scripts. Cloudflare may process basic technical request logs to deliver, secure and maintain the reliability of the website.