GoFast

Privacy Policy

Last updated: 4 May 2026 · Effective: 4 May 2026

1. Who we are

This Privacy Policy describes how George Lorentzos ("GoFast", "we", "us", "our") processes personal data in connection with the GoFast app, the GoFast Driver app, and the GoFast admin web panel (together, the "Service").

Operator: George Lorentzos (natural person, sole operator)
Country: Greece
Email: georgelorentzos@icloud.com
Phone: +30 694 599 5603

We comply with Regulation (EU) 2016/679 (GDPR) and Greek Law 4624/2019. For the purposes of GDPR, the data controller is George Lorentzos.

2. About the Service

GoFast is a technology platform that connects passengers with independent drivers. We are not a transport carrier and do not provide transport services ourselves. Drivers are independent and operate under their own licences and insurance.

The Service has two distinct user groups, treated very differently:

3. What data we collect

a) Passengers (no account)

The passenger app does not require registration. We do not collect, store, or persist any personal data about passengers on our servers. Specifically:

b) Drivers

For each driver account we store the following in our database:

While a driver is online in the Driver app, the device transmits GPS data (latitude, longitude, speed, heading) to our server every few seconds, including in the background while driving. This is necessary so passengers can see nearby drivers in real time. This location data is held only in volatile server memory with a 20-second time-to-live and is never written to a database, file, or log. When the driver goes offline, swipes the app away, or stops sending updates, the location is removed automatically.

c) Admin web panel

The admin panel is used by authorised administrators (currently only the operator) to create and manage driver accounts. Admins see the same driver fields listed above. There is no separate data collected for admin users — they are also drivers with the admin flag.

d) Driver document expiry tracking

When a driver is registered, the operator records only the expiry dates of the driver's driving licence (Δίπλωμα οδήγησης) and Special Taxi Driving Permit (Ειδική Άδεια Οδήγησης Ταξί / ΕΔΧ). These two expiry dates are used to know when a driver's documents are about to lapse so the account can be deactivated in time. We do not request, upload, scan, photograph, or otherwise store copies of the licence, the ΕΔΧ, the identity card, the vehicle registration, the insurance certificate, or the ΚΤΕΟ. Drivers remain personally responsible for holding all such valid documents under Greek law (see the Terms of Service).

4. Why we process this data (legal bases under GDPR Art. 6)

Purpose Legal basis
Create and operate driver accounts Contract — Art. 6(1)(b)
Send sign-in codes by email Contract
Match a passenger with the nearest online driver Legitimate interest — Art. 6(1)(f) — operating the Service
Show driver name and phone to a passenger requesting a ride Legitimate interest — enabling contact between users
Track driving-licence and ΕΔΧ expiry dates so accounts can be deactivated when documents lapse Legitimate interest + legal obligation
Prevent fraud, abuse, or technical attacks Legitimate interest
Meet tax, accounting, or legal record-keeping requirements (if monetisation begins) Legal obligation — Art. 6(1)(c)
Defend against or bring legal claims Legitimate interest

5. Where data is stored and who we share it with

We do not sell personal data. We do not run advertising. There are no analytics or tracking SDKs in the apps.

6. International transfers

Server infrastructure is in the EU (Stockholm). However, our email provider (Google) and certain Apple/Google push-notification services may transfer data to the United States. These transfers are covered by the EU–US Data Privacy Framework and/or Standard Contractual Clauses approved by the European Commission.

7. How long we keep data

8. Your rights (GDPR)

You can, at any time:

To exercise any right, email georgelorentzos@icloud.com. We respond within 30 days at no cost.

9. Security

No system is 100% secure. If a personal-data breach occurs, we will notify the Hellenic DPA and affected users within 72 hours, as required by GDPR Art. 33–34.

10. Children

The Service is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a minor's data has been collected, contact us and we will delete it.

11. Changes to this policy

We may update this Privacy Policy as the Service evolves (for example, when payments are added or when the operator forms a legal entity). Material changes will be communicated in-app or by email at least 30 days in advance.

12. Contact

George Lorentzos · Greece
Email: georgelorentzos@icloud.com · Phone: +30 694 599 5603

© 2026 GoFast. All rights reserved. · Terms of Service