Privacy notice

How TIRAVA handles ride request data, tracking links, messages, location sharing and driver assignment.

Controller

The controller for this website is Aldi Xhema, operating TIRAVA Taxi & Chauffeur. Privacy and ride-request questions can be sent to the contact details listed in the legal notice.

Data we collect

Why we use the data

Legal basis

Under Article 7(1) of Albanian Law No. 124/2024, ride-request and contact data are processed to take steps requested before a possible contract; optional analytics and live-location sharing rely on consent; service security, fraud prevention and limited operational records rely on legitimate interests after balancing the guest's rights; and accounting, tax or authority requests rely on applicable legal obligations.

The site does not use the ride request data for unrelated marketing unless separate consent is requested and recorded.

Recipients and service providers

If a traveler uses the optional TIRAVA connector in ChatGPT, OpenAI processes the conversation under the traveler's ChatGPT relationship. TIRAVA receives only the ride and contact details the traveler explicitly confirms for sharing.

Request data is available to the operator and, where operationally necessary, dispatchers and drivers who handle the request. Driver access is for ride handling, pickup coordination, customer communication and status updates, not for unrelated use.

Technical providers may process data for hosting, API operation, database storage, backups, email, Telegram notifications, maps, geocoding, routing, security and maintenance. The browser loads versioned OpenMapTiles data derived from OpenStreetMap through TIRAVA's map host; address search and route preview are sent only to the TIRAVA API, which uses configured private geocoding and routing services. Hosting and API traffic may be processed by infrastructure such as Netlify, Cloudflare and the configured server environment. Customer emails are sent through Brevo (Sendinblue) from a no-reply address. If analytics is accepted, Google Analytics 4 (delivered via Google Tag Manager) may process public site usage events under the applicable Analytics and data-processing terms.

Cloudflare Turnstile protects the ride-request form against automated abuse. Cloudflare may process browser and security signals, the visitor IP address and a short-lived verification token. The TIRAVA API sends that token and IP address to Cloudflare Siteverify, but does not store the token with the ride request.

Retention

Open requests remain available through the tracking page while the request is active. Closed or canceled requests are kept only for operational review, complaint handling, accounting, tax, fraud prevention or legal defense, then deleted, archived with restricted access or anonymized.

Live location data is used for pickup coordination and active ride safety. It is not intended as continuous background tracking and should be retained only for the shortest period needed for the ride workflow, safety review or dispute handling.

Operational targets are 24 hours for live-location coordinates after the active ride, 24 months for closed request and message data, and 35 days for access-controlled database backups. Application logs are size-limited through rotation; infrastructure providers may retain their own security logs under the configured service terms. Data may be kept longer only where accounting, tax, complaint, fraud-prevention or legal-defense duties require it.

Your rights

Under Articles 12–20 of Albanian Law No. 124/2024, guests may request access, correction, deletion, restriction, objection, data portability where applicable, withdrawal of consent for future processing, and protection from solely automated significant decisions. The operator may request proportionate identity verification and must normally respond free of charge within 30 days; any lawful extension and its reasons must be communicated within that initial period.

Complaints may be addressed to the operator or to the Albanian data protection authority: Information and Data Protection Commissioner / Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale (IDPC), Rr. Abdi Toptani, Nd. 5, 1001 Tirana, Albania, info@idp.al, +355 42 23 7200, https://idp.al.

Controller duties under Albanian Law No. 124/2024

Aldi Xhema acts as controller for the personal data processed through this website because it determines the purpose and means of processing ride requests, tracking links, messages, driver assignment and operational records.

Processors and technical providers may process data only for the operational purposes described here: hosting, database, backups, email, Telegram notifications, map search, routing, security, authentication and maintenance. Access is to be limited to people who need it for the ride, support, safety, accounting or legal compliance.

The operator is expected to apply data minimisation, purpose limitation, accuracy, confidentiality, access control and retention limitation. Data subjects may exercise rights available under Albanian personal-data protection law, including access, correction, erasure, restriction, objection and complaint to the IDP where applicable.

No sensitive-data request and no automatic legal decision

The booking form is not designed to collect special-category data such as health, religion, political opinions or identity documents. Guests should not enter sensitive information unless it is genuinely needed for safe pickup or accessibility and should keep such notes minimal.

Route pricing and status automation support the workflow but do not create a fully automated legally binding decision. Acceptance, refusal, assignment, change approval and final practical confirmation remain subject to manual operator or driver review.

Where consent is the legal basis for an online service used by a person under 16, Albanian Law No. 124/2024 requires authorization from a parent or legal guardian. Ride requests for minors should therefore be submitted or authorized by an adult.

Sources and required information

Most data comes directly from the guest, the guest's device or map selection. Additional status, message, assignment and live-location data may come from the operator or assigned driver; ChatGPT supplies data only after the traveler confirms sharing it.

Route, pickup, destination where applicable, date, time, passenger count, name and a working contact channel are needed to review the request. Without required information TIRAVA cannot process or confirm it. Email, flight details, notes, live location and analytics are optional unless a particular ride objectively requires clarification.

International transfers

Some providers may process data outside Albania. Under Articles 39–42 of Law No. 124/2024, TIRAVA must use a destination covered by an Albanian adequacy decision or another lawful safeguard, such as applicable standard contractual or equivalent enforceable protections; a specific statutory exception is used only where its conditions are met.

Information about the destination and applicable safeguard, and a copy or description where legally available, can be requested at booking@tirava.app. Map and route lookups may send technical route data to the selected provider before a ride request is submitted.

Detailed processing matrix

Tracking links, messages and live location

A tracking link includes a request reference and token. Anyone with the exact link may be able to see the request status and conversation, so guests should not publish it. If a link appears to have been shared with the wrong person, the guest should contact the operator so the request can be closed, changed or reissued where technically possible.

Live location is not collected by default. The browser or device asks for permission; if permission is denied, the ride can still be handled through address, hotel, airport meeting point or direct communication. Location accuracy depends on the device, browser, network and map provider.

Security, confidentiality and access

Operational access is limited to the operator, dispatchers and drivers with a role in handling requests. Accounts and sessions are personal to the authorised user and must not be shared; access should be removed when a person no longer needs it.

The service uses a combination of technical and organisational measures such as HTTPS, server-side authentication, hashed passwords or token hashes, role-based permissions, private database access, restricted backups, no-index/no-store rules for private pages and operational logging.

These controls reduce risk but do not remove all risk from online communication. Guests and drivers should avoid placing unnecessary sensitive information in address fields, notes or messages, and suspected unauthorised access should be reported promptly.

Retention schedule

International processing and providers

Some providers used for hosting, routing, map search, email, notifications, tunnel/security or backups may process data outside Albania. The operator should use providers and settings that give appropriate confidentiality, access control and contractual safeguards for the type of data involved.

Address search and route-preview requests are sent by POST only to the TIRAVA API and may include route-related technical data before a ride request is sent. The browser does not send those values to a public geocoder or routing provider. Avoid entering sensitive personal information into address or notes fields unless it is needed for the ride.