Privacy Policy

Effective 22 August 2026

This Privacy Policy explains how Nabogo ApS (“Nabogo”, “we”, “our” or “us”) collects and processes your personal data when you use our app, make purchases through it, contact us, or visit our website.

1. Who we are and how to contact us

Nabogo is the data controller for the personal data described in this policy. Users sign up directly with us, and we determine how and why your data is processed.

Nabogo ApS, CVR-39404060, Lysholt Allé 8, 7100 Vejle, Denmark.

For any privacy question, or to exercise your rights, contact us at ‘anders [at] nabogo.com’.

We operate as a single Danish company in Denmark, Norway, Sweden, Belgium and the Netherlands. You can lodge a complaint with your local data protection authority: Denmark — Datatilsynet; Norway — Datatilsynet; Sweden — IMY (Integritetsskyddsmyndigheten); Belgium — GBA / APD (Gegevensbeschermingsautoriteit / Autorité de protection des données); Netherlands — AP (Autoriteit Persoonsgegevens). As Nabogo is established in Denmark, Datatilsynet (DK) is our lead supervisory authority under the one-stop-shop mechanism.

2. What we collect, why, and how long we keep it

What we collect depends on how you use nabogo — not everything below applies to everyone. Most of it is data a feature needs in order to work; without it, that feature cannot be provided. Where local regulation or our risk assessment requires it, you cannot carpool without sharing your location during the trip, and a Lift Provider cannot offer lifts or receive payouts without completing verification. Our service is not directed at children.

Your account

Account details — the details you give us when you sign up, such as your name, email address, postcode, profile picture and telephone number. What we ask for depends on how you sign up. Why: to create and manage your account. Kept: 90 days after you delete your account.

Identity verification — proof that you are who you say you are, either automatically through an electronic ID (eID) provider or, where that is not possible, by a manual review. We do not store your documents, only the outcome of the check. Why: to confirm your identity where local regulation or our risk assessment requires it. Kept: while your account exists, then only as long as a legal obligation requires.

Using the app

App usage — the trips you take, the addresses and routes you enter — including any home or work address you save — which services you use and how, and your IP address. Why: to provide the service. Kept: as long as the other participants of a trip need the record. When you delete your account your name and contact details are removed from it; the trip details stay visible to the people you travelled with.

Location — where you are while you use nabogo. Why: to verify trips, and to unlock features that then run automatically instead of needing you to confirm them by hand. For some trips you have to share your location while the trip is running in order to use those features. When we need your location while the app is closed, we collect it only from two hours before the trip is due to start until the trip ends, and at no other time. Kept: for as long as the trip it belongs to is kept. Where it has been used to verify a trip and an audit obligation applies to that trip, up to 5 years.

Driver’s licence and vehicle details — confirmation that a Lift Provider holds a valid driver’s licence and that the vehicle they offer trips in is registered and legal to drive, checked either automatically through a verification provider or, where that is not possible, by a manual review. We do not store your documents, only the outcome of the check. This verification is only available in some countries, and only required for some users. Why: to confirm that both the driver and the vehicle are legal for the trips offered, where local regulation or our risk assessment requires it. Kept: while your account exists, then only as long as a legal obligation requires.

Messages to other users — what you write to other users in the app. Why: to let you arrange trips. We do not read your messages as a matter of course. In unusual cases we may do so where it is necessary to enforce our rules, investigate reported misuse, or comply with a legal obligation. Kept: for as long as the trip record they relate to is kept. When you delete your account your identifiers are removed and the messages stay visible to the other party.

Ratings — the ratings you give and the ratings you receive after a trip. Why: to help users judge who they travel with. Ratings you give are confidential: the other person sees only their overall average, never your individual rating. Likewise, others see only your overall average — across all your trips, as driver or passenger — never who rated you. Kept: ratings are not deleted. If you delete your account you are anonymised as a rater; the rating and the other person’s average remain.

Payments and payouts

Payments and payouts — a record of what you pay and what you are paid. When you pay, your card and other payment details go directly to a payment service provider certified under the card industry’s security standard (PCI-DSS); we never see or store them. When we pay you, we store the bank account number you give us ourselves, as we make the payouts. Why: to take payment, pay out, and keep our accounts. Kept: 5 years, as required by the Danish Bookkeeping Act (Bogføringsloven). This applies to your bank account number too.

Commuter pass images — the photo of the pass you upload, where a commuter pass can be used as payment. Why: to confirm the pass is valid and prevent misuse. We review the images, including periodic spot checks of users who have paid this way. Kept: while the pass is valid and for as long as the spot-check period for trips paid with it requires.

Safety and fraud prevention

Device and fraud-prevention data — technical details about your device and how it interacts with us, including characteristics that let us recognise a device across sessions. Why: to prevent fraud and secure accounts. Kept: while your account exists; afterwards only where an open fraud investigation or a related legal claim still requires it.

Support, marketing and our website

Support — your name, contact details, which services you use, and what you write to us when you contact support. Why: to answer you and resolve your issue. Kept: 3 years after the ticket is closed.

Newsletter and marketing — your consent, and which marketing messages you open and click. Why: to send you marketing that is relevant to you. Kept: while your consent is active; deleted when you withdraw it or delete your account.

Campaign attribution — which link, advert or campaign first brought you to us, and the match between your visit to our website and your later sign-up in the app. We make this match ourselves; your telephone number and other contact details are never sent to advertising platforms. Why: to measure how well our website and marketing campaigns work. Kept: while your account exists.

Website visits — data about your device and your use of nabogo.com, such as browser type, search terms, IP address and network location. Why: to run, improve and promote the site. Kept: as set out in our Cookie Policy, which governs this use.

Why we are allowed to hold this data. Most of it we hold because we need it to deliver the service you signed up for. We hold payment and accounting records, and complete the verifications described above where local regulation requires them, because the law requires it. We send you marketing only if you said yes, and you can withdraw that at any time. Where we rely on a legitimate interest of our own — keeping the service secure and free of fraud, keeping the platform safe for other users including verifications we require on our own risk assessment, and understanding how people find us — you can object at any time; see section 5. In the terms used by the GDPR these are Article 6(1)(b), 6(1)(c), 6(1)(a) and 6(1)(f).

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. A person reviews every failed verification, withheld payout and account block.

3. Who we share data with

  • Other users. To arrange a shared trip, we pass your name, telephone number, meeting point and destination to the user you carpool with.
  • Payment processing. Payment service providers handle inbound payments and store card details under the PCI-DSS standard; we do not have access to them. A bank executes driver payouts to the account number we hold.
  • Identity, driver’s licence and vehicle verification. Verification providers, as described in section 2.
  • Infrastructure. Application-hosting and data-warehousing providers, on servers in the EU.
  • Communications and support. Providers of email, SMS and push notification services for transactional and marketing communications, and our customer support platform and error-monitoring tools.
  • Analytics and advertising. Web and app analytics providers, and the advertising platforms we run campaigns on, to measure how well our website and campaigns work. Where cookies are involved, our Cookie Policy governs this.
  • Integration partners. Limited trip data is made available to journey-planning partners in the countries where they operate, restricted to public meeting-point information. No personal details, and not your start or destination address, are shared.

Providers that process data on our behalf are bound by written data processing agreements and may use the data solely to provide their service to us. Payment service providers, banks, eID providers and advertising platforms are independent controllers for their own part of the processing. If you would like to know which specific providers we use, contact us at ‘anders [at] nabogo.com’.

4. International transfers

Most of our service providers process personal data within the EEA. For providers that may transfer data outside the EEA — primarily US-based services — we rely on the EU-US Data Privacy Framework where the provider is certified, or the European Commission’s Standard Contractual Clauses, supplemented by appropriate technical and organisational measures such as encryption and access controls. You can request a copy of these safeguards at ‘anders [at] nabogo.com’.

5. Your rights

You have the right to access the personal data we hold about you and to receive a copy of it; to rectification of inaccurate data; to erasure of your data in certain circumstances; to restriction of our processing in certain circumstances; to data portability for the data you have provided to us; and to withdraw consent at any time, including consent to receive our newsletter (this does not affect processing already carried out).

Where a copy of your data would reveal personal data about someone else, we may withhold that part. In particular, we do not disclose who gave you a specific rating: ratings are given in confidence. Your overall average rating is always visible to you in the app.

You also have the right to object at any time to processing based on our legitimate interests, and to direct marketing. If you object to direct marketing, we will stop.

To exercise any of these rights, write to ‘anders [at] nabogo.com’. We may ask you to verify your identity. You also have the right to lodge a complaint with a supervisory authority — see section 1.

6. Security

We have implemented appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or misuse. Only employees with a legitimate need to do so, in order to perform their work, have access to your personal data.

7. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will inform you in the app and on nabogo.com, and update the effective date shown on this policy.