litz

Privacy Policy

Effective 11 August 2026

1. Who we are

Strategic Success Lab d.o.o. (“Blitz”, “we”, “us”) operates the Blitz mobile application — a ride-hailing connector that links riders with independent drivers in Bosnia & Herzegovina and neighbouring markets.

We are the data controller for the personal data described in this policy. Our registered office is Prijakovci b.b., Banja Luka, Bosnia and Herzegovina. Contact us at ronald@strategicsuccesslab.com with any questions.

2. What we collect

We collect what is needed to operate, secure, and improve the service:

  • Name:provided during sign-up.
  • Blitz account ID:links the profile, rides, messages, support, ratings, driver records, and notification preferences.
  • Phone number:used for account creation and OTP verification.
  • Driver-applicant email:required only on the separate web driver-application form; mobile rider sign-in does not ask for email.
  • Precise or approximate location:collected during the app session to find your pickup point, show nearby drivers, and share your live position with your assigned driver during a ride; Android allows approximate-location access.
  • Addresses and place searches:pickup/destination addresses, search text sent to Google Places for suggestions, and optional saved places such as Home or Work.
  • Device identifiers:push notification token, stored to deliver ride and support notifications.
  • Communications and user content:rider/driver messages, support tickets and message reports, ratings, and free-text feedback.
  • Ride and transaction data:ride/GPS history, estimated and final fare, and a cash form-of-payment label; no payment-card, bank-account, or card-token credentials.
  • Driver verification data:taxi carrier licence number, taxi driver ID number, annual vehicle sticker number, vehicle details, typical driving availability, and image or PDF documents; when an applicant selects a taxi-legitimation image on the web form, a copy is sent immediately to Anthropic for editable OCR field suggestions.
  • Driver share analytics:a random attempt ID, the driver's account ID, whether the link was for a rider or driver, the app screen, operating system, app version, attempt time, the driver's own share code where relevant, and the limited result returned by the phone.
  • Driver application source:the new driver's account ID, the approved referring driver's ID, BL-XXXX code, source label, and application time.
  • Rider invitation and preferred-driver relationship:the phone number entered on the invitation page, inviting driver and BL-XXXX code, campaign source, acceptance time and status, and the confirmed preferred-driver relationship; an existing preferred driver is never replaced automatically.
  • Growth funnel data:the action type (for example campaign landing, store-button tap, notification permission, or first app open), coarse campaign labels and platform; device/session identifiers and push tokens are converted to a one-way HMAC before storage.
  • Mobile app analytics:Firebase Analytics records app opens, sessions, automatic app lifecycle and usage events, app version, device class, coarse region, and a random app-instance identifier to measure reliability and use; we do not send Blitz account ID, name, phone, email, advertising ID, trip location, invite code, or message content.
  • Diagnostic and crash data:a scrubbed error message and stack, app phase or screen, app/build/runtime/update version, operating system, device model or class, timestamps, occurrence count, and grouping fingerprint.

Share analytics do not contain the selected recipient, phone contacts, a recipient phone number, message content, chosen sharing app, or a device identifier. A native share result does not prove message delivery.

Growth funnel data does not contain a phone number, email, IP address, invite recipient, message content, raw push token, or raw browser/device identifier. A store-button tap is not labelled as a download; first app open is a separate fact.

Diagnostic reports intentionally exclude precise location, addresses, chat or support content, authentication tokens, phone numbers, account IDs, and ride IDs. Automated scrubbing also removes common email, secret, network-address, coordinate, and opaque-identifier patterns before a report is stored locally or sent.

We do not collect payment-card, bank-account, or card-token credentials. Fares are settled directly between riders and drivers, currently in cash; the ride record contains the fare and cash form-of-payment label. Driver platform fees are invoiced separately via the web portal. Billing records include the calculated fee, any explicit test-driver waiver, the charged amount, invoice issue and due dates, and operator-recorded payment allocations. A launch allowlist or phone number is not used as a billing waiver.

3. How we use your data

  • Create and manage your account
  • Match you with a nearby driver and share your pickup location with them
  • Provide turn-by-turn routing and live ETA
  • Calculate and display the ride fare
  • Enable in-app messaging between rider and driver during a ride
  • Send push notifications about ride status and support replies
  • Investigate safety incidents and support requests
  • Verify driver and taxi registrations with the relevant local authority
  • Measure whether the sharing controls are understandable and reliable
  • Internally identify which approved driver’s link led to a submitted new-driver application
  • Measure waitlist submissions, notification choices, reachable push tokens, and attributable first app opens by campaign source
  • Measure mobile app opens, sessions, automatic lifecycle/usage events, and technical reliability
  • Detect, group, and fix app crashes and critical active-ride tracking failures
  • Comply with legal obligations

Opening a share sheet, its result, or another driver’s referral does not affect account status or the decision to approve a driver application.

4. Location data

Precise or approximate location is collected only while the app is in use(foreground or active ride foreground service). Android lets you grant approximate rather than precise access. We do not track your location when the app is closed or in the background outside of an active ride.

Your operational location is shared with your assigned driver only for the duration of the trip. GPS points needed for the trip record, billing, safety, and dispute handling are retained as historical ride records under section 6.

5. Who we share your data with

We share personal data only where necessary:

  • Your assigned driver — name and live pickup location, for the duration of the trip
  • Supabase — database and authentication infrastructure (EU-hosted)
  • Vercel — website and backend API hosting
  • Twilio Verify through Supabase Auth — phone number, to deliver OTP verification codes
  • Expo / Apple / Google — push notification token, to deliver ride alerts
  • Google Maps — address-search text and relevant pickup/destination coordinates for place suggestions, geocoding, routing, and ETA
  • Anthropic — editable OCR field suggestions from the taxi- legitimation image selected on the web driver-application form
  • Resend — transactional email, support-form delivery, driver- application email, and ride receipts where requested
  • Twilio — OTP verification through Supabase Auth, Blitz transactional/admin SMS, and configured call functions
  • Sentry — scrubbed crash and error diagnostics processed in the EU region
  • Firebase Analytics in the mobile app — part of normal app operation; receives app opens, sessions, automatic app lifecycle and usage events, app version, device class, coarse region, and a random app-instance identifier. We do not send phone/email, Blitz account ID, advertising ID, trip location, invite recipient/code, or message content. Advertising storage, personalization, and cross-app tracking always remain disabled.
  • Google Analytics on the website — loads only after your explicit website choice; advertising storage and personalization remain disabled.

We do not sell your data. We do not share it with advertisers or data brokers.

6. How long we keep your data

When you delete your account, we remove account access and the active name, phone, email, notification token, current location, saved places, and stored payment tokens. Name and phone are also removed from ordinary waitlist and invite copies; the business fact and attribution remain without those direct identifiers.

Historical ride/GPS, billing and payment, message and support, rating, feedback, diagnostic, driver-application, referral, and share-attempt records are not erased by account deletion. They remain under their published retention periods for business records, safety, fraud prevention, contractual duties, and legal obligations.

For a driver, original identity, application details, vehicle, taxi ID, and original documents remain in a restricted legal record available only to authorized staff for the driver contract, legal claims, and reapplication review. The active driver profile is anonymized and cannot sign in or receive rides. Legal-record access is logged.

Raw notification tokens and current location are removed from the active account. Historical trip GPS remains part of the retained ride record.

Share-attempt records are kept for no more than 90 days and are then deleted automatically. Driver-application source attribution is kept with the application for internal records; deleting the account does not erase that historical attribution.

Detailed first-party growth-funnel events are kept for no more than 180 days. Inactive HMAC push-token state is deleted after 180 days; an active operational push token is retained only while it is needed to deliver notifications.

Mobile Firebase Analytics data and optional website Google Analytics data follow the retention period configured in the Firebase/GA4 property. You can change the website analytics choice in your browser; the mobile app does not offer a switch for its regular app analytics.

Undelivered diagnostic reports stay in a bounded on-device queue for no more than 7 days. The in-house copy of a delivered report is removed after 30 days by a daily automated job; the Sentry copy follows the retention period configured in the Sentry project.

7. Your rights

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Remove account access and active profile data — use the in-app Settings → Delete account, or our web deletion page (available even after uninstalling the app); retained business and legal records are described in section 6
  • Object to or restrict certain processing
  • Lodge a complaint with your national data protection authority

To exercise any right other than deletion, email us at ronald@strategicsuccesslab.com. We respond within 30 days.

8. Security

All data is encrypted in transit using TLS. Database access is restricted to authenticated services using least-privilege credentials. We do not store OTP codes — they expire immediately after use.

9. Children

Blitz is not directed at anyone under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us and we will remove account access and active profile data; retained business and legal records remain as described in section 6.

10. Changes to this policy

We will notify you via the app or email if we make material changes. The effective date at the top of this page will always reflect the latest version. Continued use of the app after a change means you accept the updated policy.

11. Contact

Strategic Success Lab d.o.o.
Prijakovci b.b., Banja Luka, Bosnia and Herzegovina
ronald@strategicsuccesslab.com

© 2026 Strategic Success Lab d.o.o.. All rights reserved.

Help us understand what brings people to Blitz?

Optional Google Analytics uses coarse campaign activity. Blitz’s own signup counts work either way. No phone, email, invite recipient or referral code is sent to Google.