Privacy Policy
Last updated: September 1, 2026
Thank you for your interest in the mobile application Barande (hereinafter "App") for iOS and Android as well as our web offerings at barande.app (hereinafter collectively "Platform"). Protecting your personal data and privacy is our highest priority.
Below we inform you in detail about what personal data we collect when using our platform and mobile app, the purposes for which we process it, the legal basis on which this is done, and what rights you are entitled to under the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Name and Contact Details of the Controller
The controller within the meaning of Art. 4 No. 7 GDPR for the collection, processing, and use of your personal data is:
Firma Barande
Owner: Samsoun Behaein
Grünhofer Weg 42
13581 Berlin
Germany
Email: connect@barande.app
Website: https://barande.app
Legal Notice: https://barande.app/legal/impressum
Tax ID: 19/222/01100
If you have questions regarding data privacy or the exercise of your data subject rights, you can contact us directly at any time.
2. Definitions
This Privacy Policy uses the terms defined in the General Data Protection Regulation (GDPR). For clarity, the most important terms are explained below:
- Personal Data (Art. 4 No. 1 GDPR): Any information relating to an identified or identifiable natural person (e.g., name, email address, location data, identity documents).
- Processing (Art. 4 No. 2 GDPR): Any operation performed on personal data (e.g., collection, storage, modification, transmission, erasure).
- Controller (Art. 4 No. 7 GDPR): The natural or legal person who determines the purposes and means of the processing of personal data.
- Processor (Art. 4 No. 8 GDPR): A natural or legal person who processes personal data on behalf of the controller.
- Sender: A registered user who posts or books a request for the transport of a luggage item or parcel on the platform.
- Traveler (Casual Courier): A registered user offering a trip and providing available luggage space to carry items.
3. Legal Bases of Processing
We always process your data in accordance with applicable data protection legislation. The key legal bases are:
- Art. 6(1)(a) GDPR (Consent): Where you have provided explicit consent (e.g., push notifications, location and camera permissions).
- Art. 6(1)(b) GDPR (Contract Performance & Pre-contractual Measures): Processing is necessary for the performance of the user and mediation contract or pre-contractual steps (e.g., user account, bookings, escrow management, chat).
- Art. 6(1)(c) GDPR (Legal Obligation): Processing is necessary for compliance with legal obligations (e.g., statutory tax and commercial retention under § 147 AO, § 257 HGB).
- Art. 6(1)(f) GDPR (Legitimate Interests): Processing is necessary for the purposes of legitimate interests pursued by us or third parties (e.g., fraud prevention, IT security, app stability).
- Art. 9(2)(a) GDPR (Special Categories of Data): Where you explicitly consent to biometric facial verification during voluntary identity verification (KYC).
4. Hosting & Technical Infrastructure
4.1 Website Hosting (Netlify)
We host our website at Netlify, Inc. (512 2nd Street, Suite 200, San Francisco, CA 94107, USA). When visiting our website, Netlify automatically collects server log files (IP address, date/time of access, browser type, operating system, referrer URL).
Legal Basis: Art. 6(1)(f) GDPR (legitimate interest in the secure and efficient provision of the website). Data transfer to the USA is covered by the EU-U.S. Data Privacy Framework (DPF) and standard contractual clauses (SCC). Netlify Privacy Policy: https://www.netlify.com/privacy/.
4.2 Backend Infrastructure, Database & Storage (Supabase)
For backend infrastructure, PostgreSQL database, user authentication, and file storage, we use Supabase (Supabase Inc., Singapore / Data center Frankfurt am Main, Germany, EU).
- All data is processed on European AWS servers in Frankfurt am Main.
- All database queries and file transfers are encrypted end-to-end via SSL/TLS (HTTPS).
- Data access is protected by strict PostgreSQL Row Level Security (RLS).
Legal Basis: Art. 6(1)(b) GDPR.
5. Cookies, Local Storage & Secure Device Storage
5.1 Website
Our website uses exclusively technically necessary cookies and storage mechanisms:
- Supabase Session Cookies: To maintain secure login status (Art. 6(1)(b)/(f) GDPR).
- Localization Cookie (
NEXT_LOCALE/user-language): To store language preferences (German, English, Persian/Farsi). - We do not use advertising or marketing tracking cookies that require consent.
5.2 Mobile App (Expo SecureStore & AsyncStorage)
No cookies are used in the mobile app. Instead, we use:
- Expo SecureStore: Encrypted storage of authentication tokens and session keys in hardware-backed storage (iOS Keychain, Android Keystore).
- AsyncStorage: Local storage of app preferences (e.g. language, onboarding status).
Legal Basis: Art. 6(1)(b) and (f) GDPR.
6. Local Fonts (Google Fonts Hosted Locally)
For cohesive and clean typography, we use fonts that are fully hosted locally on our servers and in the app. Loading fonts establishes no connection to Google servers and transmits no IP address to Google.
7. Registration, User Account & Profile Management
7.1 Registration via Email and Password
During regular registration, we collect your email address, chosen username, and password (stored as a one-way cryptographic hash). Legal basis: Art. 6(1)(b) GDPR.
7.2 Social Sign-In
- Google Sign-In (Google Ireland Limited, Dublin, Ireland): We receive your Google ID, name, email address, and profile picture. Privacy Policy: https://policies.google.com/privacy. Legal basis: Art. 6(1)(a) & (b) GDPR.
- Apple Sign-In (Apple Inc., Cupertino, CA, USA): We receive an anonymized Apple user ID, your email address (or Apple relay address), and name. Privacy Policy: https://www.apple.com/legal/privacy/. Legal basis: Art. 6(1)(a) & (b) GDPR.
7.3 Profile Details & Public Visibility
Publicly visible to other users are only: username, profile picture (avatar), verification badge, average rating and review count, as well as public trip listings and shipment requests.
8. Identity Verification (KYC), ID Documents & AI Face Matching (OpenAI GPT-4o)
For elevated security and unlocking verified features, we offer and require a KYC verification process.
8.1 Collected Documents & Secure Storage
- Photo of official ID (ID card, passport, driver's license).
- Portrait photo (selfie) with neutral facial expression.
- Live selfie holding the ID document next to the face.
- Storage: These files are stored in the private cloud bucket
id_documents. Only the user and authorized administrators have access via RLS.
8.2 Automated AI Verification via OpenAI GPT-4o Vision
For automated document checks (verify-identity-ai), images are temporarily sent to the API of OpenAI (OpenAI OpCo, LLC, San Francisco, CA, USA):
- Checks confirm document authenticity and match the portrait selfie with the ID photo.
- The system generates an advisory recommendation (
APPROVE,REJECT,MANUAL_REVIEW). - In ambiguous cases, manual human review is conducted. You have the right to request human intervention (Art. 22(3) GDPR).
Legal Basis: Art. 6(1)(b) GDPR, Art. 6(1)(f) GDPR, and Art. 9(2)(a) GDPR.
9. Trip Matchmaking, Shipment Orders & Customs Documentation
9.1 Trip Data & Shipment Data
- Travelers: Departure and destination, travel date, flight number, available weight, price per kg, meeting points.
- Senders: Package description, weight, categories (documents, clothes, electronics, cosmetics, food, etc.), photos, declared value, recipient details.
9.2 Digital Declaration & Customs Manifest
Senders submit a binding customs declaration at booking. The system generates an official transport manifest (customs_manifest_code, e.g. BRD-2026-XXXXXX) with timestamp, documenting flight, item, and verification data for customs and safety controls.
Legal Basis: Art. 6(1)(b) and (c) GDPR.
10. Payment Processing, Escrow & PIN Handover System
10.1 Payment Providers
- PayPal (PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg): Transaction details are processed by PayPal. Privacy policy: https://www.paypal.com/de/webapps/mpp/ua/privacy-full.
- Stripe (Stripe Technology Europe, Ltd., Ireland): Card and payout data are processed by Stripe. Privacy policy: https://stripe.com/privacy.
10.2 Escrow & 4-Digit Security PIN
Deposited funds are held in escrow (held_in_escrow) until delivery is completed.
- The platform generates a 4-digit confirmation PIN (
delivery_pin). - Only after the traveler inputs this PIN at handoff (
verify_delivery_pin) is payment unlocked (ready_for_payout). - After 5 incorrect PIN attempts, the transaction is automatically locked for safety.
Legal Basis: Art. 6(1)(b) GDPR.
11. Invoicing, PDF Generation & Statutory Retention
For each booking, our Edge Function (generate-invoice) automatically generates tax-compliant PDF invoices:
- Sender invoice (showing 19% VAT on mediation fee; transport fee as transitory item under § 10(1) s. 5 UStG).
- Traveler payout receipt.
- Tax authority voucher.
Pursuant to § 147 German Fiscal Code (AO) and § 257 German Commercial Code (HGB), we are legally required to retain invoices and booking data for 10 years.
Legal Basis: Art. 6(1)(c) GDPR.
12. In-App Chat, Notifications & Moderation
12.1 Real-Time Chat
Messages between booking parties are transmitted in real time over encrypted WebSockets (Supabase Realtime) and automatically filtered for offensive keywords (contentFilter).
12.2 Push Notifications (Expo)
For status updates, we use Expo Push Notifications (650 Industries, Inc. / Expo, USA) along with APNs (Apple) and FCM (Google). Device push tokens (expo_push_token) can be disabled in device settings at any time.
Legal Basis: Art. 6(1)(a) & (b) GDPR.
12.3 Reporting and Blocking
Users can report inappropriate content (reportContent) or block individuals (blockUser). Reports are reviewed within 24 hours.
13. Maps, Geolocation & Flight Tracking
13.1 Google Maps & Places Autocomplete
We use APIs from Google Ireland Limited for map rendering, address lookup, and meeting location suggestions. GPS access is optional and requires consent.
Legal Basis: Art. 6(1)(a) & (f) GDPR.
13.2 Flight Tracking (Aviationstack API)
To check flight status and delays, the app calls the API of Aviationstack (apilayer GmbH, Austria) using only the flight number without personal data.
14. Analytics & Error Monitoring
14.1 Sentry (Crash & Error Reports)
We use Sentry (Functional Software, Inc., San Francisco, CA, USA) routing to European servers (de.sentry.io). Crash logs, stack traces, device parameters, and user IDs are processed for debugging.
Legal Basis: Art. 6(1)(f) GDPR.
14.2 PostHog (Product Analytics)
We use PostHog (PostHog Inc., San Francisco, CA, USA) on European servers (https://eu.i.posthog.com) to collect pseudonymized usage analytics.
Legal Basis: Art. 6(1)(f) GDPR.
15. Protection of Minors (Minimum Age 18)
Our platform is exclusively intended for individuals aged 18 and older. We do not knowingly collect personal data from minors. Any discovered minor data is deleted promptly.
16. Storage Duration & Account Deletion (Right to be Forgotten)
You may permanently delete your account in the app under Settings > Danger Zone > Delete Account:
- Safety Check: Deletion is locked if there are active, uncompleted trips or shipments.
- Purge: Unbooked trips and open requests are deleted immediately.
- Anonymization: To meet the 10-year statutory tax retention duty (§ 147 AO), completed booking and invoice records are anonymized (username converted to
Deleted User [ID], ID documents and personal info deleted). - Auth Deletion: The user record is fully deleted from authentication servers.
17. Overview of Third-Country Transfers
| Service | Provider | Country / Server Location | Legal Basis / Safeguard |
|---|---|---|---|
| Netlify | Netlify, Inc. | USA | Standard Contractual Clauses (SCC) / DPF |
| Supabase | Supabase Inc. | EU (Frankfurt am Main, DE) | EU Data Center / RLS Encryption |
| Sentry | Functional Software, Inc. | EU Ingest (de.sentry.io) / USA | Standard Contractual Clauses (SCC) / DPF |
| PostHog | PostHog Inc. | EU Cloud (eu.i.posthog.com) | EU Server / Standard Contractual Clauses |
| Google (OAuth, Maps) | Google Ireland Ltd. / Google LLC | Ireland / USA | Standard Contractual Clauses (SCC) / DPF |
| Apple (Sign-In, APNs) | Apple Inc. | USA | Standard Contractual Clauses (SCC) / DPF |
| OpenAI (KYC GPT-4o) | OpenAI OpCo, LLC | USA | Standard Contractual Clauses (SCC) / Art. 9 GDPR |
| PayPal | PayPal (Europe) S.à r.l. et Cie | Luxembourg (EU) | Contract Performance (Art. 6(1)(b) GDPR) |
| Stripe | Stripe Technology Europe, Ltd. | Ireland (EU) | Contract Performance (Art. 6(1)(b) GDPR) |
| Expo (Push Tokens) | 650 Industries, Inc. | USA | Standard Contractual Clauses (SCC) |
| Aviationstack | apilayer GmbH | Austria (EU) | Anonymized flight data query |
18. Your Rights as a Data Subject
Under the GDPR, you have the following rights at any time:
- Right of Access (Art. 15 GDPR)
- Right to Rectification (Art. 16 GDPR)
- Right to Erasure (Art. 17 GDPR)
- Right to Restriction of Processing (Art. 18 GDPR)
- Right to Data Portability (Art. 20 GDPR)
- Right to Withdraw Consent (Art. 7(3) GDPR)
- Right to Object (Art. 21 GDPR)
- Right to Lodge a Complaint with a Supervisory Authority (Art. 77 GDPR)
To exercise your rights, simply contact us via email at: connect@barande.app.
19. Competent Data Protection Supervisory Authority
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61
10555 Berlin
Phone: +49 (0)30 13889-0
Email: mailbox@datenschutz-berlin.de
Website: https://www.datenschutz-berlin.de
20. Validity and Changes
This Privacy Policy is currently valid and dated September 1, 2026. Revisions may become necessary due to ongoing platform developments or regulatory changes. The latest version is always available in the app and at https://barande.app/legal/privacy.
