Skip to main content
Laffaلفة
العربية
Page theme

Back to home

Privacy policy

This policy explains what data the Laffa Passenger and Laffa Captain apps and this website collect, why, who we share it with, how long it is kept, and how you delete your account and exercise your rights.

Version:
2026-09-22
Effective date:

1. Scope and data controller

This policy applies to the Laffa Passenger app (net.laffaegypt.passenger), the Laffa Captain app (net.laffaegypt.captain), the website laffaegypt.net and the operations portal, and to everyone who uses them in the Arab Republic of Egypt.

The data controller is Laffa Egypt, the operator of the Laffa Passenger and Laffa Captain apps and of laffaegypt.net. Privacy contact: privacy@laffaegypt.net.

2. Data we collect

We collect only what the service needs, classify data by sensitivity and handle each class with matching controls:

  • Account data (passenger and captain): mobile number (the account identifier, verified with a one-time code), name, email (optional), profile photo (optional), preferred language.
  • Captain verification data (sensitive): national ID number, date of birth and address; national ID photos (front and back); a selfie for matching against the ID; driving licence; TukTuk licence and government registration papers; TukTuk details (plate, model, colour, seats); four TukTuk photos; and settlement details (bank account, mobile wallet or InstaPay).
  • Passenger precise location: only while the app is in use (in the foreground), to show nearby TukTuks, set the pickup point and follow the trip. The passenger app does not collect location in the background.
  • Captain precise location: only while you are Online or On a trip, including in the background (app minimised or screen off) through a foreground service with a visible, persistent notification. The position is sent every few seconds for request matching and to show your location to the passenger. Collection stops as soon as you tap Offline. We do not permanently store every update: only the latest position is kept, plus the route during a trip.
  • Trip data: pickup and destination, time, distance, fare and the pricing rules used, payment method, trip PIN (hashed), ratings and reports, and SOS events.
  • Financial data: wallet transactions, commissions, withdrawal and refund requests, and payment references from the licensed payment provider. We never store full card details.
  • Trusted contacts (passenger): up to three names and numbers you add yourself for emergencies and trip sharing. We do not read your phone address book.
  • Device and technical data: push token (Firebase Cloud Messaging), device type, operating system and app version, IP address, language, request ids, and technical logs for diagnosing faults that never contain one-time codes or documents.
  • Camera (captain): used only to photograph documents and the TukTuk during sign-up; only what you upload yourself is stored.
  • Your correspondence with support and reports you file or that are filed about you.

3. Why we use your data

  • Running the service: account creation and verification, trip matching, fare calculation, payments and the wallet, operational notifications (trip status, verification status, wallet alerts).
  • Verifying captains and their vehicles before they may take trips, re-checking documents periodically and tracking expiry.
  • Safety: the trip PIN, SOS, trip sharing, investigating reports and incidents, preventing fraud and blocking abusive accounts.
  • Legal and accounting obligations: keeping financial records and answering valid legal requests.
  • Improving the service: aggregated usage and crash statistics that are not used to track you across apps.

We do not sell your personal data, show no advertising, and use identity documents for nothing other than verification and compliance. We send marketing messages only with your consent, which you can withdraw at any time.

5. Who we share data with

We share your data only as needed to run the service, and with the following parties:

  • Between passenger and captain during a trip: first name, photo, rating, pickup and destination, the captain live position, and the TukTuk plate number. Your mobile number is not shown to the other party; masked calling will be supported when available.
  • Google Maps Platform (Google): to display maps, search places and compute routes; the coordinates and search text needed for that are sent to Google under the Google privacy policy.
  • Google Cloud (hosting): the servers, database and private document storage are hosted by Google Cloud, currently in the European Union region (europe-west1).
  • Firebase Cloud Messaging (Google): to deliver notifications; only the push token of your device is shared.
  • SMS provider (Twilio Inc. through its Twilio Verify service, or a licensed Egyptian SMS gateway): receives your mobile number only, to deliver the one-time code.
  • Payment providers licensed by the Central Bank of Egypt (once online payment is enabled): they process card or wallet details directly; we receive only the transaction reference and outcome.
  • Public authorities: where there is a legal obligation or a valid judicial request, or to protect the safety of a person in an emergency.
  • The trusted contacts you chose: when you use trip sharing or the SOS button.
  • Our operations team: with role-limited permissions and every view of sensitive documents logged.

6. Transfers outside Egypt

Platform data is currently hosted in data centres inside the European Union, and some data may be processed by service providers outside Egypt (Google). Transfers of personal data outside Egypt are subject to the Personal Data Protection Law No. 151 of 2020 and its executive regulations, including licensing requirements from the Personal Data Protection Centre.

We apply the safeguards the law requires to these transfers: contractual data-protection obligations on our providers, encryption in transit and at rest, and access limited to what the service needs. If the hosting region changes we will update this section and notify you under section 12.

7. Retention

  • Account data: for as long as the account is active, then deleted or anonymised after the 30-day grace period following a deletion request.
  • Verification documents, national ID number and settlement details: for as long as the captain works with Laffa, then permanently deleted with the account after the grace period — unless a law requires us to keep a specific record longer, in which case we keep only that record for that period.
  • Precise location: only the latest position is kept while online and is continuously overwritten; the trip route is kept to investigate any report about that trip and is deleted no later than 90 days after the trip ends, unless an investigation into such a report is still open.
  • Trip and financial records: kept in anonymised form for the period required by tax and accounting law.
  • Access logs for sensitive documents and security logs: every view by the operations team is recorded and kept for audit for at least one year.
  • Technical logs: at most 90 days, with any personal data removed.

8. Deleting your account

You can delete your account at any time from inside the app: Profile → Settings → Delete account. Your sessions end immediately, you have 30 days to change your mind by signing in again, and then your personal data and documents are deleted while trip and financial records are kept in anonymised form for as long as the law requires.

If you can no longer open the app you can request deletion without signing in from the account-deletion page on this site: /en/delete-account/ — we verify your identity first and then apply the same terms.

9. Your rights

  • View and correct your data inside the app, or request a copy by e-mail.
  • Delete your account (section 8), and object to or restrict a specific processing.
  • Withdraw consent for optional uses (location, notifications, marketing messages) at any time from the device or app settings, without affecting the lawfulness of earlier processing.
  • Lodge a complaint with the Personal Data Protection Centre in Egypt.

To exercise any of these rights, write to privacy@laffaegypt.net. We verify your identity before acting and aim to answer within 30 days.

10. Security

We use encryption in transit (HTTPS) and at rest, additional application-level encryption for the national ID number and settlement details, private document storage with no public links (temporary links valid for minutes), role-limited access with every view logged, and request rate limits. We never write passwords, one-time codes or document contents to technical logs. If a breach affects your data we will notify you and the competent authority as the law requires.

11. Minors

The service is intended for people aged 18 or older. We do not knowingly collect data from minors and delete any account found to belong to one.

12. Changes to this policy

We will notify you in the app of any material change before it takes effect, with the version number and effective date at the top of this page. Captains are asked to accept the current version in the app.

13. Contact

  • Privacy, data and deletion requests: privacy@laffaegypt.net
  • General support: support@laffaegypt.net