App Privacy Policy
Strela 2000 mobile application and services · Last updated: September 2026 · Effective: September 2026
This Privacy Policy explains how "Strela 2000" EOOD ("Strela 2000", "we", "us", "our") collects, uses, shares, and protects your personal data when you use the Strela 2000 mobile application (the "App") and our electric car-sharing and rental services (together, the "Services"). It also describes your rights under Regulation (EU) 2016/679 ("GDPR") and applicable Bulgarian data protection law, and how you can access and delete your data and account.
By downloading, accessing, or using the App, you confirm that you have read and understood this Policy. If you do not agree with it, please do not use the App or the Services.
1. Who we are (Data Controller)
- Controller: "Strela 2000" EOOD
- Address: Sveti Sedmochislenitsi 8 str., Sofia, Bulgaria
- Email: strela2000b2b@gmail.com
- Phone: +359 877 718 393
2. Scope of this Policy
This Policy applies to personal data we process through the Strela 2000 App (distributed via Google Play and/or App store) and through our booking, rental, and customer-support channels. It does not apply to third-party websites, apps, or services that we do not control (see Section 14).
3. What personal data we collect
3.1 Data you provide to us
- Account & identification data: name, nationality, date of birth, driver's licence and/or ID document details, and signature — used to verify your identity and enter into the rental agreement.
- Contact details: phone number and email address.
- Booking data: selected plan, rental period, pick-up and drop-off details, and chosen partner hotel.
- Payment data: billing details and transaction information processed through our payment providers. We do not store full card numbers.
- Communications: messages, support requests, and feedback you send us.
3.2 Data we collect automatically when you use the App
- Device & technical data: device model, operating system version, language, app version, unique device/app identifiers, and mobile-network information.
- Usage & analytics data: in-app actions, features used, and session information.
- Crash & diagnostic data: crash reports, error logs, and performance data used to keep the App stable and secure.
3.3 Location data
- Vehicle location: the location of the rented or shared vehicle during a booking, collected via the vehicle's GPS, for safety, fleet management, and theft prevention.
- Device location: with your permission, the App may access your device's precise or approximate location to show nearby available cars, pick-up points, and partner hotels. You can enable or disable this at any time in your device settings; disabling it may limit certain features.
3.4 Camera and photos
- With your permission, the App may use your camera or photo library so you can upload your driver's licence/ID for verification of identity and account, or document vehicle condition, damage, or incidents when ending your session.
3.5 Incident data
- Information about damages, accidents, traffic violations, and related reports from you, insurers, or public authorities.
We do not intentionally collect special categories of data (e.g., health or biometric data). Please do not send us such data unless strictly necessary.
4. Device permissions
The App may request the permissions below. You can grant or revoke each of them at any time in your device settings:
- Location — to find nearby cars and manage active rentals.
- Camera / Photos — to verify identity and document vehicle condition.
- Notifications — to send booking, payment, and service updates.
We request each permission only when it is needed for a feature, and we show an in-app explanation immediately before the system permission prompt. Update this list so it matches exactly the permissions your app requests.
5. Why we process your data and our legal bases
- Providing the Services, your account, and bookings — Art. 6(1)(b) GDPR (performance of a contract).
- Identity/licence verification and fraud prevention — Art. 6(1)(b) and Art. 6(1)(f) (legitimate interest in a secure service).
- Vehicle safety, security, and fleet management (incl. GPS) — Art. 6(1)(f) (legitimate interest).
- Processing payments and preventing payment fraud — Art. 6(1)(b) and 6(1)(c).
- Accounting, tax, and other legal obligations — Art. 6(1)(c) (legal obligation).
- Handling incidents, insurance, and legal claims — Art. 6(1)(c) and 6(1)(f) (establishing or defending legal claims).
- App analytics, diagnostics, and improvement — Art. 6(1)(f) (legitimate interest), or consent where required.
- Marketing communications — only with your explicit consent, Art. 6(1)(a). You may withdraw consent at any time.
6. Consent and in-app disclosure
Where the law requires consent (for example, marketing, certain analytics, or access to sensitive device data), we ask for it clearly and separately, and you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Access to sensitive permissions such as precise location or camera is always preceded by an in-app disclosure and the system permission request, and the data is used only for the purposes described in this Policy.
7. Who we share your data with
We do not sell your personal data. We share it only where necessary, with:
- Partner hotels — where necessary for customer identification and vehicle handover for your booking.
- Payment processors — Visa, Mastercard, Apple Pay, Google Pay, and our payment/acquiring provider Revolut — to process payments securely.
- Service providers (processors) who help us operate the App and Services, for example:
- Google (Firebase / Google Play services) — app analytics, crash reporting, and push notifications; Google Maps for map and location features.
- Hosting and IT infrastructure providers.
- Customer-support and communication tools.
- Insurers, police, and public authorities — only where there is a valid legal basis or legal obligation, or to establish, exercise, or defend legal claims.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
Critical for approval: list here the ACTUAL third-party SDKs your app uses (e.g., Firebase Analytics, Firebase Crashlytics, Google Maps SDK, and any ads/attribution SDKs). This section must match your Google Play Data Safety form exactly — mismatches are a leading rejection cause.
8. International data transfers
Your data is primarily processed within the European Economic Area (EEA). Some service providers (such as Google) may process data outside the EEA. Where this happens, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses or an adequacy decision, to protect your data.
9. How long we keep your data
- Booking and contract data: up to 5 years (accounting/tax requirements).
- GPS / vehicle location logs: up to 6 months after the rental.
- Damage / incident data: until the related insurance or legal process is completed, plus any applicable limitation period.
- Account data: while your account is active; deleted or anonymised after closure, subject to legal retention obligations.
- Analytics / diagnostic data: [retention period — e.g., up to 14 months].
- Marketing data: until you withdraw consent.
When a retention period ends, we securely delete or anonymise the data.
10. Data security
We apply appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS/TLS), access controls that limit access to authorised personnel, secure servers, and locked storage for any paper records. No method of transmission or storage is completely secure, but we work to protect your data and review our measures regularly.
11. Your rights
Under the GDPR, you have the right to:
- access your personal data;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten");
- restrict or object to processing (including GPS tracking outside service provision, and direct marketing);
- data portability;
- withdraw consent at any time.
To exercise these rights, contact us at strela2000b2b@gmail.com. You also have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, www.cpdp.bg.
12. Account and data deletion
You can request deletion of your account and associated personal data at any time:
- In the App: go to Settings → Account → Delete account and follow the steps.
- Online or by email: submit a request at https://www.strela2000.com/contact or email support.s2k@gmail.com with the subject "Account deletion".
Once we verify your request, we will delete or anonymise your personal data, except where we are required to keep certain data to comply with legal obligations (for example, accounting/tax records or an ongoing insurance or legal matter). We will confirm once your request has been completed.
13. Children's privacy
The App and Services are intended for users who are of legal driving age and at least 18 years old. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
14. Third-party links and services
The App may contain links to third-party websites or services (for example, partner hotels and payment providers). We are not responsible for their privacy practices. Please review their privacy policies before providing them with your data.
15. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, where appropriate, notify you in the App. Your continued use of the App after an update means you accept the revised Policy.
16. Contact us
"Strela 2000" EOOD
Address: Sveti Sedmochislenitsi 8 str., Sofia, Bulgaria
Email: strela2000b2b@gmail.com / support.s2k@gmail.com
Phone: +359 877 718 393



