ႵႠ
🌙
Go to site

Privacy Policy

Last updated: 5 August 2026

This policy explains what personal data Bargito collects, why we process it, who it is shared with and what rights you have. We operate in line with the Georgian Law on Personal Data Protection and the EU GDPR.

1. Who we are

Bargito is an online platform connecting parcel senders with travellers. We are the data controller. Contact: support@bargito.ge.

2. What data we collect

CategorySpecificallySource
AccountEmail, first and last name, profile photo, password hash or Google sign-in identifierFrom you
ContactPhone number (confirmed by SMS code)From you
IdentityPassport or ID card photo — only if you choose to get verifiedFrom you, optional
FinancialBank account number (IBAN) — travellers only, to receive paymentFrom you
Listings and bookingsRoute, date, flight number, parcel description, weight, price, statusFrom you
CommunicationIn-platform chat messages, correspondence with supportFrom you
ReputationRatings and comments other users leave for youFrom other users
TechnicalPush notification identifier (FCM token), browser type, IP address, error logsAutomatically
AnalyticsPage views and events in Google Analytics — only after your consentAutomatically, with consent
💳 We never store card data. Payment happens entirely on Bank of Georgia's secure iPay page. Your card number, expiry date and CVV never reach our servers — we only receive the outcome (success or failure) and a transaction identifier.
🔒 Special category data. Passport photos and IBANs are stored in a separate, restricted collection visible only to you and our administration. They are never shown to other users.

3. Why we process it, and on what legal basis

PurposeLegal basis
Creating your account and running the platformPerformance of a contract
Processing bookings, payments and traveller payoutsPerformance of a contract
Phone and passport verification, fraud preventionLegitimate interest — user safety
Sending booking and delivery emails and push notificationsPerformance of a contract
Handling disputes and retaining evidenceLegitimate interest and legal obligation
Bookkeeping and tax reportingLegal obligation
Analytics and improving the siteYour consent (cookie banner)

4. What other users can see

A public listing shows your name, profile photo, rating, verification badge and the listing content itself (route, date, price).

Your phone number is shared only after a booking — the sender sees the traveller's number and the traveller sees the sender's — so the two can reach each other. Your email, passport and IBAN are never public.

5. Who we share data with

We do not sell your data and never share it for advertising. We use only the services needed to run the platform:

ServicePurposeWhat is shared
Google Firebase (Ireland, EU)Authentication, database, file storage, push notificationsAlmost all data — this is our infrastructure
Bank of Georgia — iPayCard payments and refundsAmount and booking reference. The bank processes the card directly
ResendSending emailEmail address, name, message content
AviationStackVerifying flight numbersFlight number and date only
Google AnalyticsSite statisticsAnonymous usage data — with consent only

We will also disclose data where required by law or court order.

6. International transfers

Our servers are in Google's European region (europe-west1, Belgium). Some processors may handle data outside the EU; where they do, transfers rely on the European Commission's Standard Contractual Clauses.

7. How long we keep data

DataRetention
Account dataWhile the account is active
Completed bookings and payments6 years — required by tax law
Chat messages12 months after the booking ends
Passport photoUntil verification completes, then until account deletion
Technical error logs90 days

8. Your rights

For any request write to support@bargito.ge. We respond within 30 calendar days.

🗑️ Deleting your account. You can delete your account directly in the app — Profile → Danger zone — or from the website. Full details of what is deleted and what is kept: account deletion page.

9. Security

Data travels over encrypted HTTPS and is stored encrypted at rest. Access is restricted at the rules layer: passports and IBANs are visible only to their owner and administration, and booking details only to the parties to that deal. Passwords are never stored in plain text.

10. Children

The platform is for people aged 18 and over. If we find an account belongs to a minor, we delete it.

11. Cookies

Essential cookies keep you signed in — without them logging in is impossible. Analytics cookies load only after your consent; before that, Google Analytics is blocked (Google Consent Mode v2). You can withdraw consent at any time by clearing your browser data.

12. Changes to this policy

When we update this policy we change the date on this page. For material changes we will also notify you by email or in the app.

13. Contact

For any privacy question: support@bargito.ge