PRIVACY POLICY FOR BYBORDER
Version: 0.1
Effective Date: September 30, 2026
ByBorder (the "Application", "we", "us", or "our") is committed to respecting and protecting your personal data and privacy. This Privacy Policy explains how we collect, use, process, and safeguard your personal data when you access or use our mobile application.
This Privacy Policy is drafted in strict compliance with the European Union General Data Protection Regulation (Regulation (EU) 2016/679, hereinafter "GDPR"), the Polish Act on Personal Data Protection, and applicable mobile app marketplace guidelines.
1. DATA CONTROLLER IDENTIFICATION
The Data Controller responsible for your personal data under this Privacy Policy is:
- Legal Entity / Business Form: Sky Stork sp. z.o.o.
- Country of Registration: Poland
- Official Contact Email: dev@sky-stork.com.
- Registered Address: 29, Długa str., 00-238 Warszawa
- Tax ID (NIP / REGON): 5252927176
- Lead Supervisory Authority: President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych — UODO), Warsaw, Poland.
2. CATEGORIES OF PERSONAL DATA WE COLLECT AND PROCESS
To provide our services, authenticate users, deliver navigation features, and predict border crossing wait times, we process the following categories of personal data:
A. Account Authentication Data (Google Sign-In)
- Data Types: Google OAuth Profile Data (specifically: account name, primary email address, and Google Account ID / OAuth Token).
- Purpose & Usage: Creating and authenticating your user account, securing system endpoints, identifying user sessions, and processing user requests (such as account deletion under Art. 17 GDPR).
- Legal basis: Performance of Contract (Art. 6(1)(b) GDPR). Necessary to identify, authenticate, and manage your account to provide access to the Application.
B. Precise Location & Navigation Data (GPS)
- Data Types: Precise geographic coordinates (latitude, longitude), speed, bearing/heading, altitude, and associated timestamps.
- Purpose & Usage:
- Route Guidance: Assistance in choosing the best possible route from user’s location to the destination through existent EU-Belarus border crossing points (CPPs).
- Border Queue Analytics & Forecasting: Detecting vehicle arrival/movement in designated border checkpoint queue zones, tracking velocity, and calculating real-time estimated crossing times.
- Foreground & Background Processing: Location tracking operates actively in the foreground while using the app. Background location tracking operates when enabled by the user to allow continuous queue monitoring while the device screen is locked or the app is minimized.
- Legal basis: Consent (Art. 6(1)(a) GDPR). Explicit consent provided by the user via onboarding screens and OS device permission prompts.
C. Technical Identifiers & Device Telemetry
- Data Types: Device model, operating system version, mobile network status, Push notification tokens (Firebase Cloud Messaging - FCM), and temporary session tokens.
- Purpose & Usage: Delivering push notifications (e.g., queue updates and navigation alerts), maintaining session security, preventing location spoofing, and ensuring system stability.
- Legal basis: Legitimate Interest (Art. 6(1)(f) GDPR). Maintaining server infrastructure integrity, preventing fraudulent GPS manipulation, and mitigating security threats.
D. User Feedback Data (Optional)
- Data Types: Optional user-submitted reports regarding app performance or border conditions, wait durations which could help us to improve the prognostic capabilities of the app.
- Purpose & Usage: Processed strictly for app improvement and predictive algorithm enhancement. Feedback is kept internal and is never published or shared publicly.
- Legal basis: Consent (Art. 6(1)(a) GDPR). Feedback is voluntary and serves as the means of communication between us and users.
3. DATA STORAGE, INFRASTRUCTURE, AND RETENTION PERIODS
A. Proprietary Managed Server Infrastructure
All core personal data, user account profiles, session telemetry, and location records are stored and processed on our proprietary, secured server infrastructure directly owned, operated, and controlled by the Data Controller within the European Economic Area (EEA). All data stored within our internal server infrastructure is protected by strict technical measures.
B. Data Retention Limits
- Google Profile & Account Data: Stored for as long as your account remains active. If you delete your account, all associated Google profile data, User IDs, and linked identifiers will be permanently erased within 30 days.
- GPS Telemetry & Session Tracks: Raw GPS coordinates are retained on our server infrastructure for a maximum of 18 months following the end of a session, after which raw points are either purged or pseudonymized or anonymized.
- Technical Logs: Operational backend logs and security diagnostic records are purged on a rolling 30-day schedule.
4. THIRD-PARTY RECIPIENTS AND PROCESSORS
We do not sell, rent, or trade your personal data. We share pseudonymized or authentication data only with essential third-party service providers bound by strict Data Processing Agreements (DPAs) compliant with Article 28 of the GDPR:
Google Ireland Limited
- Role: Identity Provider (Google Sign-In) & Push/Analytics
- Data Shared: OAuth authentication tokens, FCM push tokens, OS metadata, crash logs
- Safeguards & Location: EEA / Global. Governed by Standard Contractual Clauses (SCCs) and GDPR Data Processing Terms.
OpenStreetMap
- Role: Map Rendering Provider
- Data Shared: Anonymized tile request coordinates
- Safeguards & Location: Open-source mapping layers. No persistent user identifiers transmitted.
5. TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
In accordance with Article 32 of the GDPR, we enforce comprehensive physical, technical, and administrative safeguards:
- Encryption: All external API communications enforce TLS 1.3 (HTTPS). Databases and internal storage employ AES-256 bit encryption.
- OAuth Security: Authentication is handled strictly via official Google Identity SDKs; credentials are tokenized and validated without storing sensitive user credentials.
- Access Controls: Administrative access to our managed server infrastructure is strictly restricted to authorized engineering personnel.
6. YOUR RIGHTS UNDER GDPR (DATA SUBJECT RIGHTS)
Under GDPR, you possess the following statutory rights regarding your personal data:
- Right of Access (Art. 15 GDPR): Request confirmation and access to a copy of your personal data processed by us.
- Right to Rectification (Art. 16 GDPR): Request correction of inaccurate personal data.
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): Delete your personal data and account directly through in-app account settings.
- Right to Withdraw Consent (Art. 7(3) GDPR): Revoke location tracking consent at any time via device OS settings or in-app permission toggles without affecting prior lawful processing.
- Right to Restriction & Data Portability (Art. 18, 20 GDPR): Request restricted processing or export your data in a structured, machine-readable format.
- Right to Lodge a Complaint: File a complaint with a supervisory authority mentioned in the Chapter 1 of this Policy.
7. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect functional updates or legal adjustments. Revisions will be published inside the Application with an updated "Effective Date" and "Version" tag.
8. CONTACT INFORMATION
For questions or privacy requests, please contact:
Sky Stork sp. z.o.o.
Topic: Personal data protection
Email: dev@sky-stork.com
Address: 29, Długa str., 00-238 Warszawa
Country: Poland