Privacy Policy
Version 2026-09-21
How Skilliyo, Zopfweg 29b, 5033 Buchs AG, Switzerland, handles personal data in Taxi P — Driver & Dispatch. This policy follows the revised Swiss Federal Act on Data Protection (FADP). Where the GDPR applies — for example to passengers or partners in the EU — we also meet its requirements.
1. Who is responsible
For the account data of the companies and users who register with us, the controller is Skilliyo, taxi@skilliyo.com.
For the data that a company enters about its passengers, drivers and partners, the company itself is the controller and we act as its processor. We process that data only on the company's instructions and only to operate the Service. Companies subject to the GDPR can obtain a data processing agreement from us on request.
2. What we process
Account: name, email address, language, role in the company, and the times of sign-in and activity.
Company: company name, address, contact details, VAT and bank details, plan and subscription status.
Operations: trips with pickup and destination, times, passenger name and contact details where entered, flight number, notes, status history, vehicles and drivers.
Location: while a trip is running and location sharing is switched on, the driver's position is recorded at intervals. It is used to show dispatch where the vehicle is and to estimate distances.
Money: prices, shares, expenses with receipt photographs, invoices and settlements.
Technical: server logs kept by our hosting providers for operation and security.
3. Why we process it, and on what basis
To perform the contract with you: providing the Service, invoicing, support.
To meet legal obligations: keeping business records for the period required by Swiss law.
Our legitimate interest: security of the Service, prevention of abuse, and improving the software.
We do not sell personal data, we do not use it for advertising, and we do not profile people.
4. Who receives data
Hosting and application: Vercel Inc. (application), Supabase (database, authentication and file storage). Depending on the project region, data may be stored in the European Union or elsewhere.
Email delivery: Resend, for sending invoices and notifications.
Push notifications are delivered through the browser vendor of the recipient's device.
These providers act as our processors. Where data leaves Switzerland or the European Economic Area, transfer is based on the European Commission's standard contractual clauses together with the Swiss addendum.
5. How long we keep it
Location traces: deleted automatically after 90 days.
Trips, invoices and settlements: for as long as the account exists, and thereafter for the retention period required by Swiss commercial law (ten years for accounting records).
Account data: deleted within 90 days after the account ends, unless retention is legally required.
Consent records: for as long as the account exists, as proof that the terms were accepted.
6. Cookies
The Service uses only cookies that are strictly necessary to keep you signed in and to keep the session secure. There is no advertising, no analytics and no tracking across other websites.
Because no non-essential cookies are set, no consent banner is required. If you block these cookies, signing in will not work.
The app may also store small amounts of data in your browser — for example your language choice, or trip data kept for offline use on a phone. That data stays on the device.
7. Your rights
You may ask for information about the data we hold about you, for its correction or deletion, and for a copy in a common format.
Where the GDPR applies, you may also object to processing based on legitimate interest and ask for processing to be restricted.
Write to taxi@skilliyo.com. If your request concerns data that a company entered about you — for example as a driver or a passenger — we will pass it to that company, because it is the controller for that data.
You may also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or to the supervisory authority of your country if the GDPR applies.
8. Security
Traffic is encrypted in transit. Access to data is limited by role, and separation between companies is enforced in the database itself, not only in the application.
Receipt photographs and documents are stored in a private area and are only reachable through short-lived signed links.
9. Changes
We may update this policy. The current version is always shown here with its date; substantial changes are announced in the application.