EU GDPR Compliance Statement
Privacy Policy
Effective Date: August 10, 2026 | Finderreelrom Finland Oy
1. Data Controller Identity
Finderreelrom Finland Oy (Business ID / Y-tunnus: FI3498201-9) operates the website Finderreelrom.com and related mobile applications. Our registered address is Mannerheimintie 12B, 00100 Helsinki, Finland. For any privacy queries, email our Data Protection Officer at [email protected].
2. Categories of Personal Data Collected
When you register, request, or share a ride through Finderreelrom, we process the following categories of personal information:
- Identity & Account Data: Full name, verified mobile phone number, email address, and profile preferences.
- Geolocation Data: Precise device GPS coordinates transmitted during ride matching, pick-up navigation, and active ride tracking.
- Financial & Payment Records: Encrypted payment token identifiers processed through PCI-DSS compliant gateways. Credit card numbers are never stored directly on our servers.
- Usage & Technical Diagnostics: IP address, browser user-agent, app crash telemetry, and device operating system version.
3. Legal Bases for Data Processing under GDPR
We process your personal data under strict compliance with Article 6 of the EU General Data Protection Regulation (GDPR):
- Contractual Necessity: Processing location and contact data is mandatory to connect co-riders and dispatch Traficom-licensed taxis to complete your commute.
- Legal Compliance: Retaining trip logs and payment invoices to meet Finnish tax and transportation laws.
- Legitimate Interests: Enhancing platform security, preventing fare fraud, and optimizing cab routing algorithms.
4. Data Storage, Encryption & Security
All user data is encrypted in transit using TLS 1.3 encryption and at rest using AES-256 standard encryption algorithms. Our primary infrastructure is hosted inside secure EU data centers situated in Frankfurt (Germany) and Helsinki (Finland). Data is strictly retained only as long as necessary to fulfill operational or legal requirements.
5. Your Rights as a Data Subject
Under GDPR regulation, Finnish and EU citizens enjoy the following enforceable privacy rights:
- Right of Access to receive a portable copy of your stored account data.
- Right to Rectification of inaccurate account details.
- Right to Erasure ("Right to be Forgotten") subject to statutory record-retention duties.
- Right to Restriction or Withdrawal of Marketing Consent at any time.