Privacy Policy
Last updated: 18 September 2026
This Privacy Policy describes our policies and procedures on the collection, use and disclosure of your information when you use the Service, and informs you about your privacy rights and how the law protects you.
We use your personal data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this policy, in general or with any part of it, you should not access the website, the app, or use our services.
1. Definitions
For the purposes of this Privacy Policy:
- Account – every user must create and use an account in order to use the BLUE app and access BLUE's services.
- Application – the software program provided by the Company, downloaded onto any electronic device, referred to as the BLUE app.
- Company (referred to as "BLUE", "the Company", "we", "us" or "our" in this document) refers to BLUE TECHNOLOGY S.R.L. For GDPR purposes, the Company is the Data Controller.
- Cookies – small files placed on your computer, mobile device or any other device by a website, containing details of your browsing history on that website, among other uses.
- Data Controller, for the purposes of the GDPR (General Data Protection Regulation), refers to the Company as the legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
- Device – any device that can access the Service, such as a computer, a mobile phone or a digital tablet.
- Personal data – any information that relates to an identified or identifiable individual, as described under "Types of data collected" below.
- Service refers to the Application and/or the Website (www.blue.ro).
- Service Provider – any natural or legal person who processes data on behalf of the Company: third-party companies or individuals employed by the Company to facilitate the Service, to provide it on the Company's behalf, to perform related services, or to assist the Company in analysing how the Service is used. For GDPR purposes, Service Providers are considered Data Processors. This also includes third-party drivers.
- User – anyone who downloads and uses the BLUE app. Usage Data – data collected automatically, either generated by the use of the Service or from the Service's own infrastructure (for example, the duration of a page visit).
- You – the individual accessing or using the Service, or the company or other legal entity on behalf of which such individual is accessing or using the Service, as applicable. Under the GDPR, you may be referred to as the "data subject" or "user", as you are the person using the Service.
2. Collecting and using your personal data
Types of personal data collected
While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you. This may include, without limitation:
- email address;
- first and last name;
- phone number;
- address and other waypoints for a booking;
- bank card information, for payment of products and/or services within the Service;
- device identifiers (token) and usage data;
- device advertising identifiers;
- passenger information (first name, last name, phone number).
When you pay for a product and/or service by bank transfer, we may ask you for additional information to facilitate the transaction and verify your identity, such as: date of birth, passport or identity card, bank card statement, or other address-related information. Once a booking is confirmed, these details are securely recorded in the BLUE booking system, hosted by a third party subject to the same data-protection obligations under the GDPR as BLUE. Such data may be anonymised.
Usage data
Usage data is collected automatically when you use the Service and may include: your device's IP address, browser type and version, the pages of the Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.
When you access the Service through a mobile device, we may automatically collect: the type of mobile device, the unique ID of your device, the IP address of your mobile device, your mobile operating system, the type of mobile browser you use, unique device identifiers, and other diagnostic data.
Information collected while using the app
To provide the app's features, we may collect, with your prior permission, information relating to your location. We use this information to provide and improve the Service's features; it may be uploaded to the Company's and/or a Service Provider's servers, or it may be stored only on your device.
When you use location-based services, we may collect and process data about your actual location, necessary for the app to function optimally. You may withdraw this consent at any time by disabling the location services on your device, but we cannot guarantee that we will still be able to provide the Service under the same conditions. For further details, you may contact our Data Protection Officer at [email protected].
Tracking technologies and cookies
We use cookies and similar tracking technologies (beacons, tags and scripts) to track activity on our Service, to store certain information, and to improve and analyse it. The technologies we use may include:
- Browser cookies. You can ask your browser to refuse all cookies or to warn you when a cookie is being sent. If you do not accept cookies, you may not be able to use some parts of our Service.
- Flash cookies. Certain features may use locally stored objects to retain your preferences or activity on our Service; these are not managed through the same browser settings used for regular cookies.
- Web beacons. Small electronic files (also known as clear gifs, pixel tags or single-pixel gifs) that permit the Company, for example, to count users who have visited a page or opened an email, and for other related website statistics.
Cookies can be "persistent" or "session" cookies. Persistent cookies remain on your device even after you go offline, while session cookies are deleted as soon as you close your web browser. We use both session and persistent cookies for the purposes set out below:
- Necessary / essential cookies (persistent, administered by us) – help authenticate users and prevent fraudulent use of user accounts. Without these, the services you have asked for cannot be provided.
- Cookies policy acceptance cookies (persistent, administered by us) – identify whether you have already accepted the use of cookies on the website.
- Functionality cookies (persistent, administered by us) – allow us to remember choices you make when you use the website, such as remembering your login details or language preference, for a more personal experience.
- Tracking and performance cookies (persistent, administered by third parties) – track information about traffic to the website and how users use it; they may be associated with a pseudonymous identifier linked to your device. We may also use them to test new pages or features.
3. How we use your data
The Company may use personal data for the following purposes:
- to provide and maintain the Service, including to monitor the usage of the Service and to ensure it is presented in the most effective manner for you and for your device;
- to manage your account and your registration as a user of the Service, giving you access to different functionalities available to registered users;
- for the performance of a contract: the development, compliance and undertaking of the purchase contract for any booking you have made, which may include sharing data with third-party processors;
- to contact you by email, phone calls, SMS, or other equivalent forms of electronic communication (including push notifications) regarding updates or informative communications related to features, products or contracted services, including security updates;
- to provide you with information, products or services that you request from us, or that we consider may interest you, where you have given your consent to that end;
- to manage your requests, create records of your bookings and to send you confirmations, invoices and account statements;
- to provide you with targeted advertising, tailored to your interests and/or location, including by working with third-party providers, and to measure its effectiveness;
- for business transfers: we may use your information to evaluate or conduct a merger, divestiture, restructuring, reorganisation, dissolution, or other sale or transfer of our assets, including in the context of bankruptcy or liquidation proceedings;
- for other purposes, such as data analysis, identifying usage trends, evaluating the effectiveness of our promotional campaigns, and to improve our Service, products and your experience;
- to notify you about updates and changes to the Service;
- to respond to customer service requests and to handle complaints and feedback.
If you do not want us to use your data in this way, please let us know by contacting our Data Protection Officer at [email protected]. We may also use and analyse aggregated data from which individual identities or characteristics have been removed, to run, support, improve and develop our business.
4. Who we share your data with
We work only with trusted partners and authorities, and we limit sharing to what is necessary. We do not sell your personal data. We may share your personal data in the following situations:
- with third-party providers necessary to provide the Service, such as drivers and fleet operators, payment-processing providers, storage providers, marketing agencies or social media platform providers, and our marketing and research partners;
- in connection with business transfers: we may share or transfer your information in connection with, or during negotiations of, any merger, sale of Company assets, financing, or acquisition of all or a portion of our business by another company;
- with companies within our group, whom we will require to comply with this Privacy Policy;
- with our business partners, to offer you certain products, services or promotions;
- with your consent, for any other purpose;
- where we are legally required to, in order to comply with a legal obligation, a request or proceeding, to enforce or defend our terms and conditions and/or other agreements, or to protect the rights, property or safety of the Company, our customers, or others (including exchanging information with other organisations for the purposes of fraud protection and credit-risk reduction).
5. How long we retain your data
The Company retains your personal data only for as long as necessary for the purposes set out in this policy, and to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our agreements and policies. Usage data is generally retained for a shorter period, except when it is used to strengthen security, improve the functionality of the Service, or when we are legally required to retain it longer.
To determine the retention period, we consider criteria such as: the reason we hold the data; applicable legal obligations (including Romanian legislation and legislation on digitalisation); whether you are a regular customer; whether you have opted in for marketing communications or have the app installed; whether you no longer actively interact with us or have requested that your data be deleted or amended; and our legitimate interests in defending against potential claims. Specifically:
- your user profile and account information (including technical usage data) is retained for as long as you have an active account, or for 3 years from your last use of our services; if we close your account, your data is deleted in accordance with our retention policy, unless it is still needed for legal, accounting, dispute-resolution or fraud-prevention purposes;
- in the case of a payment dispute, data is retained until the claim is resolved or the applicable limitation period expires;
- records of bookings, lost property and complaints are retained for a minimum of 12 months, or as required by law;
- data required for accounting purposes is retained for ten years from the last trip;
- in the case of a suspected criminal offence, fraudulent activity or false information, all relevant data may be retained for up to 10 years.
6. Storage and transfer of your data
The data we collect from you may be stored on servers located in the European Economic Area (EEA). Where necessary, it may be transferred to third parties for processing, under our agreements with them. We require any third party to whom we disclose personal data to enter into an agreement with us that includes strict confidentiality obligations.
Your data may also be processed by our staff or by staff of our providers, involved, among other things, in processing your booking and providing support services. By submitting your personal data, you agree to this transfer, storage or processing.
The Company will take all reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy, and no transfer of your personal data will take place to an organisation or a country unless adequate safeguards are in place, including the security of your data.
7. Disclosure of your personal data
Business transactions. If the Company is involved in a merger, acquisition or asset sale, your personal data may be transferred. We will notify you before your personal data is transferred and becomes subject to a different Privacy Policy.
Law enforcement. Under certain circumstances, the Company may be required to disclose your personal data if required to do so by law, or in response to valid requests by public authorities (for example, a court or a government agency).
Other legal requirements. The Company may disclose your personal data in the good-faith belief that such action is necessary to: comply with a legal obligation; protect and defend the rights or property of the Company; prevent or investigate possible wrongdoing in connection with the Service; protect the personal safety of users of the Service or the public; or protect against legal liability.
While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security. Third-party service providers we use may have access to your personal data; these providers collect, store, use and process information about your activity on the Service in accordance with their own privacy policies.
8. Third-party services we use
Analytics
We may use third-party providers to monitor and analyse the use of our Service, such as Google Analytics, a web analytics service offered by Google that tracks and reports website traffic. Google may use the data collected to contextualise and personalise the ads of its own advertising network. You can opt out of having your activity on the Service made available to Google Analytics by installing the Google Analytics opt-out browser add-on, or through your mobile device settings, or by following the instructions in Google's Privacy Policy.
Email marketing
We may use your personal data to contact you with newsletters, marketing or promotional materials, and other information that may be of interest to you. You may opt out of receiving any, or all, of these communications from us by following the unsubscribe link or instructions provided in any email we send, or by contacting us directly. We may use third-party email marketing service providers to manage and send these communications.
Payments
We may provide paid products and/or services within the Service. In that case, we use third-party services for payment processing. We do not store or collect your payment card details — that information is provided directly to our third-party payment processors, whose use of your information is governed by their own privacy policies, aligned with PCI-DSS standards (Visa, Mastercard, American Express, Discover). For in-app payments made via the App Store or Google Play, the privacy policies of Apple and Google, respectively, apply.
Behavioural remarketing
The Company uses remarketing services to advertise to you after you have accessed or visited our Service. We and our third-party providers use cookies and non-cookie technologies to recognise your device and to understand how you use the Service so that we can improve it in relation to your interests, and serve you advertising that is relevant to you. You can opt out of personalised advertising by enabling the privacy features on your mobile device (for example, Ad Tracking Limitation on iOS or Ads Personalisation on Android). Third-party providers we use include:
- Google Ads (AdWords) — you can manage your preferences in Google Ads Settings.
- Facebook — you can learn more about interest-based advertising and how to opt out in the Facebook Privacy Policy.
- YouTube — governed by Google's privacy policy.
9. Legal basis for processing your data (GDPR)
We may process personal data when:
- you have given us your consent to process it for one or more specific purposes;
- processing is necessary for the performance of a contract with you, or for pre-contractual steps taken at your request;
- processing is necessary for compliance with a legal obligation to which the Company is subject;
- processing is necessary in order to protect your vital interests or the vital interests of another natural person;
- processing is related to a task carried out in the public interest, or in the exercise of official authority vested in the Company;
- processing is necessary for the purposes of the legitimate interests pursued by the Company.
10. Your rights under the GDPR
The Company is committed to respecting the confidentiality of your personal data and to ensuring that you can exercise your rights. If you are located in the EU, you have the right to:
- access, update or delete the information we hold about you — whenever possible, you can do this directly within your account settings section, or by contacting us for assistance; this also enables you to receive a copy of your personal data;
- request correction of any incomplete or inaccurate personal data we hold about you;
- object to the processing of your personal data, where we rely on a legitimate interest as the legal basis, as well as where we process your data for direct marketing purposes;
- request erasure of your personal data, where there is no valid reason for us to continue processing it;
- request the transfer (portability) of your personal data, in a structured, commonly used and machine-readable format — applicable only to data for which you originally gave your consent and which we use to fulfil a contract with you;
- withdraw your consent to the use of your personal data, at any time — bearing in mind that, following withdrawal, we may no longer be able to give you access to certain features of the Service. Uninstalling the app does not automatically delete your data; you must expressly request its erasure, and that erasure will only apply to data we are not otherwise required to retain.
Exercising your rights
You may exercise your rights of access, rectification, erasure and objection by contacting us. We may ask you to verify your identity before responding to such a request. We will make every effort to respond to you as promptly as possible. You may contact our Data Protection Officer at [email protected].
You also have the right to lodge a complaint with a supervisory authority regarding the collection and use of your personal data. If you are located in the European Economic Area, you may contact your local data protection authority.
11. Joint controller for our Facebook page
The Company is the Controller of your personal data collected while you use the Service. As the administrator of the Facebook page facebook.com/Blue, the Company and Facebook are joint controllers. The Company has entered into agreements with Facebook that define, among other things, the terms of use of the page, largely based on Facebook's Terms and Conditions.
We use the Facebook Insights feature, on a GDPR-compliant basis, to obtain anonymised statistical data about our users. For this purpose, Facebook places a cookie on the device of any user who visits our Facebook page, active for a period of two years unless deleted sooner. For details, see the Facebook Privacy Policy.
12. Links to other websites
Our Service may contain links to other websites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit — we have no control over, and assume no responsibility for, the content, privacy policies or practices of any third-party sites or services.
13. Changes to this policy
We may update our Privacy Policy from time to time. We will notify you by email and/or a prominent notice within the Service, before the change becomes effective, and we will update the "Last updated" date at the top of this page. You are advised to review this Privacy Policy periodically for any changes — changes take effect from the moment they are posted on this page.
14. Contact
Questions, comments and requests regarding this Privacy Policy are welcome and can be addressed to our Data Protection Officer at [email protected] or via our contact page.