Privacy Policy

How we protect your personal data

Last updated: September 4, 2026

1. Who we are

Co-oto is a peer-to-peer car sharing application developed in French-speaking Switzerland. The data controller is:

Co-oto Sàrl
UID CHE-414.102.270
Chemin des Tines 5b, 1260 Nyon, Switzerland
Contact: info@co-oto.app

Deniz Ates serves as the point of contact for data protection matters.

2. Personal data collected

In the mobile app

Identification data

  • First name (required field for email sign-up)
  • Email address
  • Last name: only if you sign up via Google or Apple. The full name provided by these providers is retrieved and stored as-is. With standard email sign-up, the last name is never requested.
  • User role (owner or driver)
  • Preferred language and device platform (iOS / Android / Web)
  • Unique Firebase identifier and notification token (FCM)

Usage data and statistics

  • Trip and booking history
  • Aggregated statistics: number of logins, total number of trips, cumulative kilometers and expenses
  • Display preferences (identification color, hiding of trip names)

Shared vehicle data (entered by the owner)

  • Make, model, fuel type, number of seats
  • Annual vehicle costs (insurance, leasing, taxes, depreciation, other expenses)
  • Price per kilometer, optional hourly rate, price per liter, average consumption
  • Last parking position of the vehicle: recorded manually by circle members when parking, overwritten on each new parking event, no history kept

User-uploaded content

  • Photos taken with the device camera: odometer at the start and end of a trip, fuel receipts, expense receipts, vehicle inspection. The app does not access the photo gallery.
  • Text automatically extracted from odometer photos via character recognition (see §6)
  • Messages exchanged with other circle members (internal chat)
  • Free-form notes and comments associated with trips

Push notifications: enabled by default, can be disabled at any time in the device or app settings.

On the website

  • Contact form data: first name, email address, subject and message
  • Technical data via Matomo (only after consent)

Contact form data is transmitted via Web3Forms (Germany, EU) and kept for a maximum of 6 months after your request has been processed, unless a legal obligation applies.

3. Purposes of processing

The data is used to:

  • create and manage user accounts;
  • organize trips, bookings and cost-sharing calculations between members of a circle;
  • display the last parking position of the vehicle on a map;
  • enable internal communication between members of a circle;
  • automatically extract mileage from odometer photos to reduce manual entry;
  • send operational notifications (bookings, returns, alerts);
  • provide user support;
  • analyze overall use of the website and app in an aggregated manner.

Co-oto never sells or rents data to third parties and does not use your data for targeted advertising inside the app.

4. Legal basis

This policy covers the requirements of the General Data Protection Regulation (GDPR, European Union) and of the Swiss Federal Act on Data Protection (revised FADP, in force since September 1, 2023).

The legal bases relied on are:

  • Performance of the contract: account creation, trip management, bookings, cost sharing, support
  • Explicit consent: parking geolocation, push notifications, analytics cookies, optical character recognition processing of odometer photos
  • Legitimate interest: platform security (anti-bot protection, device integrity validation), processing of contact requests
  • Legal obligation: retention required by law

5. Data retention

Data is kept for as long as the account remains active.

Account deletion: you can delete your account at any time from the app. Upon deletion:

  • your first name, last name (if applicable) and email address are immediately replaced in our database with the value deleted, which effectively anonymizes your identity;
  • your Firebase authentication account is deleted: you can no longer sign in;
  • operational data linked to your technical identifier (trip history, chat messages, fuel purchases, uploaded photos) remains associated with the sharing circle you belonged to, in pseudonymized form, to preserve the consistency of other members' accounts;
  • automatic technical backups operated by Google Cloud (Firestore) are purged within that service's own retention periods, generally less than 30 days.

If you would like the full deletion of this pseudonymized operational data, you can request it at info@co-oto.app; we will act on it in accordance with Article 17 of the GDPR.

Inactive account: in accordance with article 16 of our terms of use, data from an account that has remained inactive for more than twelve months may be deleted after 30 days’ prior notice, sent by email to the address associated with the account. Signing in during that period cancels the deletion and resets the counter. If no sign-in occurs within that period:

  • if the sharing circle the account belongs to is also inactive, all of the circle's data is erased: vehicles, trips, bookings, expenses, messages and uploaded documents;
  • if the circle is still used by other members, only the inactive account is deleted and its identity removed from the history; the trips it recorded remain, in pseudonymised form, in the vehicle's logbook, as they are also the owner's data.

Accounts with an active subscription, and those covered by a partnership with a public authority, are not affected by this deletion.

Accounting records: documents that Swiss law requires us to keep, in particular records relating to a paid subscription, are retained for ten years in accordance with art. 958f of the Swiss Code of Obligations, regardless of account deletion.

6. Subprocessors and international transfers

To provide the service, Co-oto relies on the following subprocessors:

Category Use
Website hosting
Hostpoint (Switzerland)
Hosting of web pages and sending of transactional emails (SMTP)
Contact form
Web3Forms (Germany)
Transmission of messages sent via the form
Google Cloud services
Database in European region
Authentication, database, photo storage, push notifications, mapping, optical mileage recognition, QR code reading, anti-bot protection
Subscription management
RevenueCat, Apple App Store, Google Play
Technical tracking of subscription status. Financial transactions and banking data remain with Apple and Google; Co-oto has no access to them.
Usage statistics
Matomo (self-hosted, Switzerland)
Website usage statistics, hosted by us in Switzerland, no transmission to any third party, enabled only after your consent

Some services involve processing by entities located outside the EU/Switzerland. These transfers are governed by the safeguards provided for under the GDPR: EU-US Data Privacy Framework and Standard Contractual Clauses.

7. Data security

Measures in place:

  • Website and app secured with HTTPS/TLS, SSL certificates kept valid at all times
  • Encryption of data in transit and at rest (native Google Cloud encryption)
  • Secure Firebase authentication, with support for Google Sign-In and Apple Sign-In
  • Strict Firestore access rules: a user can only access the circles they are a member of
  • Firebase Storage access rules: a file (photo) is only accessible to members of the circle that uploaded it
  • Anti-bot protection via Firebase App Check
  • Internal access restricted to authorized personnel

Co-oto does not make any automated decision that has a legal or significant effect on users.

8. Your rights

In accordance with the GDPR and the Swiss Federal Act on Data Protection (revised FADP, in force since September 1, 2023), you have the following rights: access, rectification, erasure, portability, restriction, objection, and withdrawal of consent.

To exercise your rights, write to info@co-oto.app. We respond to any request within 30 days, free of charge.

If you believe your rights are not being respected, you may lodge a complaint with the competent supervisory authority: the Federal Data Protection and Information Commissioner (FDPIC) in Switzerland, or the national authority of your country of residence in the European Union (CNIL in France, AEPD in Spain, Garante in Italy, BfDI in Germany, AP in the Netherlands, etc.).

9. Cookies and analytics

This website uses a cookie consent banner. You can change or withdraw your consent at any time via the "Manage my cookies" link in the footer. Consent is valid for a maximum of 13 months, after which it is requested again.

Necessary cookies

Essential to the operation of the website, they do not collect any personal data and do not require consent.

Analytics cookies (Matomo)

Enabled only with your consent. Matomo, hosted by us in Switzerland (no data transmitted to any third party), collects the pages visited, session duration, geographic origin (country/city, never a precise address) and the device/browser type. IP addresses are anonymized before storage. Retention: 14 months maximum. Cookies set: _pk_id (13 months), _pk_ses (30 minutes), _pk_ref (6 months).

10. Native permissions requested by the mobile app

The app requests the following permissions on your device:

  • Notifications: to inform you about bookings, returns and alerts (can be disabled)
  • Camera: to take photos of the odometer, fuel receipts and expense receipts. The app never accesses your existing photo gallery.
  • Location (when the app is in use): used only at your explicit request, in two limited situations: manually recording the vehicle's parking position, and the one-time residency check when activating a municipal partnership code (see section 11). No background tracking, no history kept.

The app does not request any access to your contacts, microphone, biometric data, photo gallery or location history.

11. Residency verification under a partnership with a public authority

When a municipality or other public authority takes out a Co-oto plan for the benefit of its residents (see article 35 of the terms of use), the activation of the code by each resident triggers a specific processing operation aimed at verifying their eligibility.

Purpose

To confirm that the person activating the code is physically present within the partner public authority's territory at the moment of activation, in order to prevent fraudulent use of a benefit funded by a public authority for its residents only.

Data processed

  • Geographic coordinates of the device at the unique moment of activation
  • Identifier of the partner public authority associated with the code
  • Verification result (validated or not validated)
  • Activation timestamp
  • Sworn declaration of residence (ticked by the user)

Legal bases

  • Performance of the contract: opening of the Plus access provided for in article 35 of the terms of use
  • Explicit consent: authorization of geolocation and ticking of the sworn declaration
  • Legitimate interest: preventing fraud to the detriment of a public authority and of Co-oto

Retention period

The raw geographic coordinates are deleted as soon as the verification is completed and are never stored persistently. Only the aggregated result (validation, partner public authority, activation date) is kept throughout the duration of the user's municipal Plus access, then archived for the applicable civil limitation period (10 years in Switzerland, in accordance with art. 127 of the Swiss Code of Obligations) for evidentiary purposes in case of a dispute concerning fraudulent use. After that period, the result is deleted.

Recipients

This data is for strictly internal Co-oto use. The partner public authority receives no personal information and has no access to individual verification results; only aggregated adoption statistics (for example the total number of activations) may be shared with it.

Specific rights

You can request the erasure of this data at any time under the conditions of section 8. Erasure automatically results in the end of the Plus access granted via the municipal partnership, as eligibility can no longer be substantiated.

12. Minimum age

The use of Co-oto is restricted to adults (18 years and older). This limit arises from the requirements associated with driving a vehicle and with contractual liability.

13. Data breach

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours and inform the affected users directly when the risk is high.

14. Updates

This policy may be updated. Registered users are notified of significant changes by email.

15. Contact

For any question regarding this policy, contact us via our contact form or by email at info@co-oto.app.