Robotaxi Connect
Privacy notice
How Robotaxi Connect processes personal data, why it is needed and what rights you have.
Version: 2026-09-17-v2
1. Controller and contact
The controller is Sebastian Neumeier, sole proprietor, Leinenbrunnen 12, 71083 Herrenberg, Germany. Contact: info@robotaxi-connect.de, +49 177 8333142. Please use these details for privacy requests as well.
2. Visiting the website
Technical connection data, including IP address, request time, requested address, browser and device information, is processed to deliver and secure the website and diagnose errors. The legal basis is Article 6(1)(f) GDPR, reflecting our legitimate interest in secure and reliable operation.
Railway hosts the application in EU West (Amsterdam); the Supabase database is located in Frankfurt. Support and subprocessors may nevertheless involve processing outside the European Economic Area, including the United States. See section 7.
3. Accounts and company profiles
Accounts involve first and last name, business email address, language and authentication data required for login, email confirmation and password recovery. Authentication is provided by Supabase.
Company profiles contain name, address, business contact details, optional website, company type, fleet size, expansion potential, time frame and requirements, together with user membership and review status.
Where you are personally our contracting party, necessary processing is based on Article 6(1)(b) GDPR for contractual or pre-contractual purposes. Business contact data of employees and representatives is processed under Article 6(1)(f) GDPR for the requested business relationship. Required account or profile features cannot be provided without the necessary information.
Registration also records the version of the terms and privacy notice acknowledged and the confirmation time to document the business agreement. Acknowledging the privacy notice is not blanket consent to additional processing.
Technology companies may create an account with their company name, contact details, address, website, solution and target markets. This area shows only their own provider profile and provides no access to taxi businesses or the internal network.
4. Personal introductions and a private network
Each taxi or fleet business can access only its own profile and records released to that business. Other registered businesses and their contacts are not visible. There is no public member directory or messaging between businesses. Technology providers have no access to the network or protected profiles.
We personally assess suitable providers. Before each disclosure, we discuss the specific recipient, purpose and data with the business concerned and obtain its approval. Registration alone does not authorise disclosure. Introductions then take place through targeted email communication.
Only information necessary for the approved introduction is shared, such as company name, location, fleet information, requirements and business contacts. Necessary processing for an introduction you commission as our contracting party is based on Article 6(1)(b) GDPR. Business contact data requires a separate assessment of legitimate interests under Article 6(1)(f). Where personal consent is required, it is obtained separately before disclosure; company approval does not replace it.
Approval is documented with the recipient, data scope and date. The receiving technology provider acts as an independent controller when handling the business enquiry. No approval grants general access to other profiles.
5. Communication and documents
Messages, contact details and attachments are processed to respond to enquiries. Contractual enquiries are handled under Article 6(1)(b) GDPR; other business enquiries under our legitimate interest in responding, Article 6(1)(f).
Cooperation may involve referral histories, contracts, released documents, activities and commercial agreements. Documents are access-controlled by company membership and release permissions. Submit only information you are authorised to share and avoid unnecessary sensitive data.
Authentication and recovery emails are sent through Supabase Auth and STRATO. Personal business correspondence uses STRATO. The technology company form prepares an email draft locally; your details reach us only when you send it using your email application.
6. Session cookies and security
Cookies named or prefixed robotaxi-auth are necessary to recognise login sessions and provide protected account access. In production they use Secure, HttpOnly and SameSite=Lax. Necessary device access is based on Section 25(2)(2) TDDDG; personal data processing follows the account purposes described above. The configured maximum cookie lifetime is 400 days and may restart when a session is refreshed. Signing out removes the authentication cookies. Cookie lifetime is distinct from access-token validity.
The application currently includes no advertising pixels or analytics tools. Images are local and system fonts are used.
Rate limits and records of security-relevant changes and delivery attempts help prevent misuse under Article 6(1)(f) GDPR. Retention is determined by the need to detect and investigate faults or abuse and retain necessary evidence. Personal log data that is no longer required must be deleted; incident records are needed until resolution and, where applicable, for legal claims.
Videos are provided as external links. Opening a link takes you to YouTube, where the provider’s privacy notice applies. Our knowledge pages do not load YouTube video players.
7. Providers and international processing
Technical providers are Railway for hosting, Supabase for authentication, database and document storage, and STRATO for email. The Supabase database region is Frankfurt. Hosting, support and subprocessors may nevertheless involve processing outside the European Economic Area.
The providers’ data processing agreements govern processing on our behalf. For transfers to countries without an applicable adequacy decision, the Railway and Supabase contractual frameworks provide in particular for EU Standard Contractual Clauses. An EU hosting region does not exclude such transfers. Contact info@robotaxi-connect.de for information and a copy of the safeguards used for your data. Providers publish their terms and subprocessor lists on their websites.
8. Retention and deletion
Account and profile information is needed for the requested business relationship. Afterwards, data must be assessed for deletion or continued retention under statutory obligations (Article 6(1)(c) GDPR) or for legal claims (Article 6(1)(f)). Further use must be limited to the relevant purpose.
You can permanently delete your account after confirming with your current password. This removes your login and personal profile from the active system. If you are the last user of a taxi company, its platform data and files are also deleted. Shared company data remains when other users exist; your membership is removed. Provider profiles are deleted with their accounts. Emails already sent to recipients and provider backups are not immediately removed by this action. Previously requested deletions must be reapplied after restoration. You may continue to send additional privacy requests by email. Business documents held outside the user account that are subject to statutory retention duties remain subject to those duties.
9. Your rights
Subject to statutory conditions, you have rights of access, rectification, erasure, restriction and data portability. Consent may be withdrawn for the future without affecting the lawfulness of processing before withdrawal.
You may object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation. You may object to direct marketing at any time.
You may complain to a supervisory authority, including the Baden-Württemberg Commissioner for Data Protection and Freedom of Information, Heilbronner Straße 35, 70191 Stuttgart, Germany; www.baden-wuerttemberg.datenschutz.de.
10. Sources and decisions
Information comes from your submissions, communications and documented business activities. Contact details may also be supplied by an employer or in a business enquiry. Those individuals must receive information about the specific source and processing.
Introductions are assessed personally. There are no solely automated decisions with legal or similarly significant effects.