Privacy Policy
Last updated: 5 August 2026
This policy explains what personal data Bargito collects, why we process it, who it is shared with and what rights you have. We operate in line with the Georgian Law on Personal Data Protection and the EU GDPR.
1. Who we are
Bargito is an online platform connecting parcel senders with travellers. We are the data controller. Contact: support@bargito.ge.
2. What data we collect
| Category | Specifically | Source |
|---|---|---|
| Account | Email, first and last name, profile photo, password hash or Google sign-in identifier | From you |
| Contact | Phone number (confirmed by SMS code) | From you |
| Identity | Passport or ID card photo — only if you choose to get verified | From you, optional |
| Financial | Bank account number (IBAN) — travellers only, to receive payment | From you |
| Listings and bookings | Route, date, flight number, parcel description, weight, price, status | From you |
| Communication | In-platform chat messages, correspondence with support | From you |
| Reputation | Ratings and comments other users leave for you | From other users |
| Technical | Push notification identifier (FCM token), browser type, IP address, error logs | Automatically |
| Analytics | Page views and events in Google Analytics — only after your consent | Automatically, with consent |
3. Why we process it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating your account and running the platform | Performance of a contract |
| Processing bookings, payments and traveller payouts | Performance of a contract |
| Phone and passport verification, fraud prevention | Legitimate interest — user safety |
| Sending booking and delivery emails and push notifications | Performance of a contract |
| Handling disputes and retaining evidence | Legitimate interest and legal obligation |
| Bookkeeping and tax reporting | Legal obligation |
| Analytics and improving the site | Your consent (cookie banner) |
4. What other users can see
A public listing shows your name, profile photo, rating, verification badge and the listing content itself (route, date, price).
Your phone number is shared only after a booking — the sender sees the traveller's number and the traveller sees the sender's — so the two can reach each other. Your email, passport and IBAN are never public.
5. Who we share data with
We do not sell your data and never share it for advertising. We use only the services needed to run the platform:
| Service | Purpose | What is shared |
|---|---|---|
| Google Firebase (Ireland, EU) | Authentication, database, file storage, push notifications | Almost all data — this is our infrastructure |
| Bank of Georgia — iPay | Card payments and refunds | Amount and booking reference. The bank processes the card directly |
| Resend | Sending email | Email address, name, message content |
| AviationStack | Verifying flight numbers | Flight number and date only |
| Google Analytics | Site statistics | Anonymous usage data — with consent only |
We will also disclose data where required by law or court order.
6. International transfers
Our servers are in Google's European region (europe-west1, Belgium). Some processors may handle data outside the EU; where they do, transfers rely on the European Commission's Standard Contractual Clauses.
7. How long we keep data
| Data | Retention |
|---|---|
| Account data | While the account is active |
| Completed bookings and payments | 6 years — required by tax law |
| Chat messages | 12 months after the booking ends |
| Passport photo | Until verification completes, then until account deletion |
| Technical error logs | 90 days |
8. Your rights
- Access — ask what data we hold about you
- Rectification — correct inaccurate data in your profile or with our help
- Erasure — request deletion of your account and data
- Restriction and objection to processing
- Portability — receive your data in a machine-readable format
- Withdraw consent at any time, for example in cookie settings
- Complain to the Personal Data Protection Service of Georgia
For any request write to support@bargito.ge. We respond within 30 calendar days.
9. Security
Data travels over encrypted HTTPS and is stored encrypted at rest. Access is restricted at the rules layer: passports and IBANs are visible only to their owner and administration, and booking details only to the parties to that deal. Passwords are never stored in plain text.
10. Children
The platform is for people aged 18 and over. If we find an account belongs to a minor, we delete it.
11. Cookies
Essential cookies keep you signed in — without them logging in is impossible. Analytics cookies load only after your consent; before that, Google Analytics is blocked (Google Consent Mode v2). You can withdraw consent at any time by clearing your browser data.
12. Changes to this policy
When we update this policy we change the date on this page. For material changes we will also notify you by email or in the app.
13. Contact
For any privacy question: support@bargito.ge