Arligo

Privacy Policy

Gültig ab: 2026-08-04

This policy is published in English. Translations are provided for convenience; in the event of any discrepancy, the English version prevails.

1. Who is responsible

The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:

Arli's Trans GmbH
Salzburger Straße 68, 4600 Wels, Austria
FN 654729m (Landesgericht Wels)
[email protected]

We have not appointed a Data Protection Officer, as we do not meet the criteria in Art. 37(1) GDPR. Data protection enquiries go to the address above.

2. Whose data this covers

Arligo is used by four kinds of account holder and one group without an account:

  • Couriers — deliver orders. The most data is processed about this group.
  • Restaurants — send out orders.
  • Dispatchers and moderators — operate the platform.
  • Customers — the person receiving a delivery. Customers do not have an Arligo account. Their details reach us from the restaurant that took the order, or from a food-ordering platform we are connected to. Sections 3.5, 6 and 8 apply to them.

3. What we collect, why, and on what legal basis

3.1 Account and identity

Your phone number is your account. It is the only way to sign in: we send a one-time code by SMS and verify it. We do not use passwords and we do not store any.

DataWhoWhyLegal basis
Phone numberAll account holdersAccount identity and sign-inArt. 6(1)(b) — performance of a contract
NameAll account holdersShown to the people you work with on an orderArt. 6(1)(b)
Email addressCouriers, restaurantsRecorded during onboardingArt. 6(1)(b)
Role, account status, approval decision and the moderator's noteCouriers, restaurantsDeciding and recording whether an account may operateArt. 6(1)(b)
App languageAll account holdersSending notifications in your languageArt. 6(1)(b)

3.2 Onboarding documents and official numbers

To work as a courier or operate as a restaurant on Arligo, we collect documents and numbers needed to establish that you may lawfully do so:

  • Couriers: identity document, driving licence, insurance document, vehicle registration, a profile photo, your Austrian social security number (SVNR), and your IBAN and BIC for payment of your earnings.
  • Restaurants: business registration documents, tax number, registered business name, and the owner's full name and identity number.

Legal basis: Art. 6(1)(b) for the contractual relationship and Art. 6(1)(c) where we are under a legal obligation to establish your status. These documents are visible to our moderators only.

3.3 Location — couriers only

This is the most sensitive thing we process, so we describe it precisely. It applies only to couriers. We do not collect location from restaurants, dispatchers, moderators or customers.

  • While you are online, or have off-shift delivery mode switched on, your device sends its GPS position to us every 30 seconds, at high accuracy.
  • This happens for as long as you are online — not only while you have an active delivery. Going offline stops it.
  • We keep your most recent position only. We do not build a location history, and we do not store a trail of where you have been.
  • Your current position is visible to our dispatchers and moderators, and — while a delivery is on its way — to the customer waiting for that delivery, through their tracking link.
  • On the map screen the app also reads your position in the background so the map can follow you. Android shows a permanent notification while this is running. That background reading stays on your device and is not sent to us; the 30-second reporting above is separate.
  • When you confirm a pickup, we compare your position with the restaurant's to check that you are actually there.

Legal basis: Art. 6(1)(b). Assigning deliveries and confirming that they happened is the service itself and cannot be done without knowing where couriers are. You control this by going offline; the app cannot report a position when you are not online.

Your position is erased automatically once it is 30 minutes old, and immediately when your account is deleted. It is not erased the second you go offline, because the dispatcher screen keeps you visible for a short while after your last update so a delivery in progress does not lose track of you.

3.4 Photos and the camera

The camera is used for two things: scanning the pickup QR code on the restaurant's receipt, and taking a proof-of-delivery photo when an order is handed over. Scanned QR codes are not stored. Delivery photos are stored and can be viewed by moderators, and by the restaurant that sent the order, to resolve disputes.

We do not access your photo library, and we do not save anything to it. The app can only use a picture taken in the moment.

3.5 Order and delivery data

For each order we process the customer's name, phone number, delivery address (including floor and apartment details and its map coordinates), any note left for the courier, the contents and value of the order, and the times at which each step happened. We also keep a record per customer phone number that groups their previous addresses and order history, so a repeat order does not have to be typed again.

Legal basis: Art. 6(1)(f) — our legitimate interest, and the restaurant's, in delivering an order that the customer has asked for. The restaurant that took the order remains responsible for how it obtained those details.

3.6 Technical and diagnostic data

  • Push notification token — an identifier issued by Google for your device, so we can notify you about offers and order changes.
  • Error reports — when something goes wrong, a diagnostic report is sent to our error-tracking provider. We have switched off the automatic collection of personal identifiers in those reports, and delivery PINs are removed before sending. Session recording is switched off.
  • Security logs — sign-ins, one-time-code requests and similar events, which include the phone number involved. These are deleted automatically after 90 days.

Legal basis: Art. 6(1)(b) and Art. 6(1)(f) — keeping the service working and secure.

3.7 What we do NOT do

  • We do not use analytics or advertising, and there are no advertising SDKs in the app.
  • We do not sell personal data, and we do not share it with data brokers.
  • We do not set tracking or advertising cookies.
  • We do not process payments, and we never see card details.
  • We do not send marketing email. The app sends no email at all.
  • We do not track you across other companies' apps or websites.

4. Where your data is stored and who processes it for us

Our servers are in the European Union. The following providers process data on our behalf in order to run the service. Where a provider processes data outside the EU, the transfer relies on the European Commission's Standard Contractual Clauses.

ProviderWhat it receivesPurposeLocation
Google (Firebase Cloud Messaging)Device push token, notification textDelivering push notificationsEU / USA
Google (Maps, Geocoding, Routes)Delivery addresses and coordinatesTurning an address into map coordinates and estimating routesEU / USA
Cloudflare R2Uploaded documents and delivery photosFile storage and deliveryEU
PreludePhone numberSending the sign-in one-time codeSee provider terms
BirdCustomer phone number, order status textSending the delivery notification SMS to customersSee provider terms
SentryDiagnostic error reportsFinding and fixing faultsUSA
Food-ordering platforms you are connected toOrder and status informationReceiving orders and reporting their progressSee platform terms

Files held with Cloudflare R2 are not publicly readable. They are fetched only through a link our servers issue to someone already authorised to see that specific file, and the link stops working after an hour.

5. Who else sees your data

  • Restaurants see the order they sent, including the customer's details and the assigned courier's name and phone number.
  • Couriers see the delivery address, the customer's name and phone number, and the order contents for deliveries assigned to them.
  • Customers see the courier's first name and current position while a delivery is on its way, through their tracking link.
  • Dispatchers and moderators see operational data across the platform, including courier positions and onboarding documents.
  • Authorities, where we are legally required to disclose.

6. How deliveries are assigned

Offers are assigned automatically. The system considers how far you are from the pickup point, your vehicle type, how many orders you are already carrying and your recent activity, then offers the delivery to the best-placed courier. You are free to decline an offer; declining passes it to the next courier.

This affects how much work you are offered, so we tell you about it plainly. It is not used to make decisions about your account — suspension and approval decisions are made by a person.

7. How long we keep things

DataKept for
Security and sign-in logs90 days, deleted automatically
In-app notifications30 days, deleted automatically
Replaced uploads (when you re-upload a document)48 hours, then deleted
Address lookups we have cached180 days
Your last reported position (couriers)30 minutes after your last update
Public order tracking links24 hours after the order is completed
Delivery photos1 year, then deleted
Customer records and address history2 years after the last order
Orders, deliveries, shift and earnings records7 years (§ 132 BAO), then stripped of personal details and kept only as commercial records
Account, profile and onboarding documentsFor as long as the account exists (see Section 8)

These periods are enforced automatically by a scheduled task, not applied by hand. Once the seven-year bookkeeping obligation has passed, an order keeps only what makes it a commercial record — what was delivered, when, for how much — and loses the name, phone number, street address and coordinates attached to it. A record with no personal data in it is no longer personal data.

You can ask us to delete data before any of these periods expire, under Section 8.

8. Your rights

Under the GDPR you have the right to:

  • ask what data we hold about you and get a copy (Art. 15);
  • have inaccurate data corrected (Art. 16);
  • have data erased (Art. 17);
  • have processing restricted (Art. 18);
  • receive your data in a portable format (Art. 20);
  • object to processing based on legitimate interests (Art. 21);
  • withdraw consent at any time, where processing is based on consent.

If you have an account, you can download a copy of your data at any time from Account → Download my data. It contains everything we hold about you, in a machine-readable format. Details belonging to other people involved in the same delivery are not included, because their rights apply too.

For anything else — correction, restriction, objection, or a request from someone without an account — write to [email protected]. We answer within one month, as Art. 12(3) requires.

Deleting your account

Account holders: see the account deletion instructions on our support page.

Customers, who do not have an account: write to [email protected] from the phone number or about the order concerned, and we will verify your identity before acting — we will ask you to confirm details of an order that only you would know, so that nobody else can have your data erased or disclosed.

What deletion does and does not remove. We delete your account, your profile and your uploaded documents. Some records remain: completed orders, shift and earnings records that we are required to keep for tax purposes, and records of contracts you signed. Where we must keep a record, we keep only what the obligation requires. Tell us if you want the remaining records anonymised where the law allows it.

Complaints

You can complain to the Austrian data protection authority (Art. 77 GDPR):
Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Wien, Austria
[email protected] · https://www.dsb.gv.at

9. Security

Traffic between the app and our servers is encrypted in transit. Access to onboarding documents is limited to moderators. Sign-in requires a one-time code sent to your phone; there is no password to steal or reuse. Signing out ends the session on our servers, not only on your device.

Your bank details, your Austrian social security number and a restaurant owner's identity number are additionally encrypted where they are stored, so they are unreadable in a database copy or backup without a separate key.

Uploaded documents and delivery photos are not reachable by URL. They are served only through a link that is issued to an authorised viewer, names one file, and stops working after an hour — so a link that is forwarded or left in a browser history is already dead.

10. Children

Arligo is a tool for people doing paid work and is not directed at children. You must be old enough to work lawfully as a courier, or to represent a business, to hold an account. We do not knowingly process data of children. If you believe a child has provided us with personal data, write to [email protected] and we will delete it.

11. Changes to this policy

If we change how we process personal data, we will update this page and change the effective date at the top. Where a change materially affects you, we will notify you in the app.

Arli's Trans GmbH · Salzburger Straße 68, 4600 Wels, Austria
[email protected]