Cómo funcionaCómo funcionaOferta
Negocios
MunicipiosNegociosReal Estate Development
Acerca de
Acerca dePressCarreras
Download the app
Eindhoven
Cómo funciona
Oferta
Business
Municipalities
Business
Real Estate Development
About
About
Press
Careers

Privacy Statement

For the umob app, website and mobility services

Last updated: 26 August 2026

Controller: UMOB B.V. | Chamber of Commerce 82484724 | Rodezand 80, 3011 AL Rotterdam, the Netherlands | support@umob.app

This Privacy Statement applies to all users of the umob app, website and mobility services, regardless of the city, country, mobility provider or programme through which the service is used. It explains how UMOB B.V. ("umob", "we", "us") processes personal data, when another organisation is responsible, how long data is kept and which rights you have.

umob does not sell or rent personal data. We do not use precise trip or location history to build or share third-party behavioural advertising profiles. Campaign-source information is not stored in the umob customer profile or linked to trip, precise-location, payment or support history. Non-essential analytics, campaign measurement and marketing technologies are used only where a valid legal basis exists and, where required, after consent.

1. Who we are and what this statement covers

UMOB B.V. is a Dutch mobility-as-a-service company. Through the umob app, users can find, compare, book, use and pay for mobility services offered by different providers. Depending on the product, umob may act as seller, intermediary, technical platform and/or payment coordinator. The role applicable to a particular product is shown in the app before purchase or booking.

This statement applies when you use the umob app or website, create or manage an account, book or use a mobility service, purchase a subscription or mobility credit, participate in a business, public-sector, customer or guest programme, contact customer service, receive communications, apply for a role with umob, or otherwise interact with us.

This statement concerns personal data: information relating to an identified or identifiable person. Information that has been irreversibly anonymised so that a person can no longer reasonably be identified is not personal data. Pseudonymised data remains personal data.

UMOB B.V. is established in Rotterdam and registered with the Dutch Chamber of Commerce under number 82484724. Privacy and rights requests can be sent to support@umob.app. Customer support is also available through the in-app chat. Where another applicable privacy law gives you additional or stronger rights, umob will apply those rights.

2. Who is responsible for which processing

umob as controller

umob is normally the controller for the umob account, authentication, app and website operation, umob billing and subscriptions, customer support, platform security, consent management, umob communications and the integration of mobility services.

Mobility and transport providers

The mobility, taxi, public-transport or other service provider selected by you is normally an independent controller for the operation of the individual journey or rental, including vehicle access, safety, fleet operations, route or ride administration, insurance, incidents, traffic offences, legal duties and its own fraud prevention. The applicable provider and its relevant terms and privacy information are made available before the relevant booking or use.

umob shares only the data needed for the selected service. Depending on the provider and the situation, this may include a booking or ride identifier, contact details, eligibility status, payment status, vehicle information, trip details or information needed to handle support, an incident, damage, insurance, a fine or a legal request. Direct identifiers are avoided where a booking or pseudonymous identifier is sufficient.

A current overview of mobility service providers and links to their terms and privacy statements is available at https://umob.app/nl/legal/mobility-service-providers-terms-privacy-statements.

Employers, municipalities and other programme sponsors

An employer, municipality, transport authority, hotel, event organiser or other programme sponsor may determine eligibility, budgets, policy rules and reporting requirements for a programme. Depending on the actual arrangement, that organisation may be an independent controller, a joint controller with umob, or a controller for which umob processes a limited set of data as processor. The invitation, programme terms or separate notice explains the applicable roles and data fields where relevant.

Service providers acting for umob

umob uses service providers for functions such as hosting, databases, security, authentication, communications, customer support, payments, identity or driving-licence verification, mapping, analytics and campaign measurement. When they act as processors, they may use personal data only on umob’s documented instructions and under a data-processing agreement.

3. Personal data we collect and where it comes from

Data you provide

  • Account and contact details, such as name, email address, telephone number, country, language and address details where needed for a provider, invoice, programme or legal requirement.
  • Authentication and account-security information, including login identifiers, one-time codes and social-login information made available by the chosen login provider.
  • Payment and billing information, such as payment method, payment token or reference, account-holder details where needed, transaction status, invoice details, mobility credits and subscriptions. Full card credentials are normally held by the payment provider rather than umob.
  • Identity, age, eligibility or driving-licence information where required for a service, including document data, verification result, licence class and expiry date. Source documents, selfies or short videos may be processed by a specialised verification provider.
  • Messages, support requests, complaints, survey responses and other communications.
  • Photos or videos you upload, for example to show how a vehicle was parked, report damage or document an incident. You should avoid capturing bystanders or unrelated personal data where possible.
  • Preferences and permissions, including language, notification choices, cookie or SDK choices, marketing consent and records of consent or withdrawal.
  • Programme data, such as a work email address, employee or participant identifier, eligibility code, mobility budget, cost centre or invitation code.
  • Job-application data, such as contact details, CV or resume, cover letter, employment and education history, qualifications, availability, interview or assessment information, references and right-to-work information where required.

Data generated when you use the services

  • Current device location when you actively use a location-based feature, and the location or hub associated with a booking or ride.
  • Booking and journey data, such as provider, booking or ride identifier, vehicle or service, start and end point, date and time, duration, distance where available, status and price.
  • Usage, performance and diagnostic data, such as app events, feature interactions, crash reports, response times and unsuccessful booking or payment events.
  • Technical and security data, such as IP address, device and operating-system information, app version, browser type, session identifiers, authentication events, security logs and fraud signals.
  • Communication data, such as delivery, opening or interaction status for service messages and, where permitted, marketing messages.
  • Programme and reporting data, such as use of a credit, allowance or subscription, the applicable programme, costs and sustainability indicators.

Data obtained from other organisations

  • Mobility and transport providers, for example vehicle availability, booking and ride status, trip details, operational support information, incidents, damage, insurance or fines.
  • Payment, identity, authentication and verification providers, such as payment status, risk signals and verification results.
  • Employers, municipalities and other programme sponsors, such as eligibility, budget, policy or participant information.
  • App stores, device platforms and communication providers, such as installation status, purchase or delivery confirmation and technical diagnostics.
  • Insurers, advisers, authorities or other parties involved in an incident, claim, complaint, dispute or legal obligation.
  • Recruitment agencies, referees or professional sources where relevant to an application and permitted by law.

If umob receives personal data about you from another organisation, this statement and any relevant programme or provider notice explain the source and purpose. We will provide additional information where Articles 13 or 14 GDPR require it.

4. Purposes, legal bases and retention periods

Operate website/app; security

Personal data
IP, device/browser/app data, session data, necessary storage, logs, error/security events
Legal basis
Legitimate interests (Art. 6(1)(f)); contract where necessary (Art. 6(1)(b))
Retention
Routine technical/security logs normally up to 90 days; never over 12 months unless required for a documented incident.

Create and manage account

Personal data
Name, contact, language, login and authentication data
Legal basis
Contract (Art. 6(1)(b)); legitimate interests in account security (Art. 6(1)(f))
Retention
Active relationship + no later than 12 months after it ends, unless shorter.

Plan, book, unlock, use and end mobility service

Personal data
Current location, provider/vehicle/service data, booking/ride identifiers, start/end, time, status, price
Legal basis
Contract (Art. 6(1)(b)); legal obligation where applicable (Art. 6(1)(c))
Retention
Transient current location where possible; booking/ride records active relationship + no later than 12 months after it ends.

Payments, refunds, subscriptions, credits and invoices

Personal data
Payment token/reference, method, payer details where needed, amount, status, invoice/subscription/credit data
Legal basis
Contract (Art. 6(1)(b)); tax/accounting law (Art. 6(1)(c)); legitimate interests for reconciliation/charge management (Art. 6(1)(f))
Retention
Operational payment data: active relationship + no later than 12 months. Core statutory accounting records: 7 years, separated from operational profile.

Identity, age, eligibility or driving-licence verification

Personal data
Document/licence data, source images/video at verification provider, verification result, licence class/expiry
Legal basis
Contract (Art. 6(1)(b)); legitimate interests in fraud/safety (Art. 6(1)(f)); valid Art. 9 condition if biometric data is used
Retention
Verification source images/video normally deleted by the verification provider as soon as no longer needed and, as UMOB policy, targeted for deletion no later than 30 days after final verification unless a documented exception applies. UMOB result/metadata: active relationship + no later than 12 months.

Customer support and complaints

Personal data
Contact, messages, booking/ride reference, evidence, case status
Legal basis
Contract (Art. 6(1)(b)); legitimate interests for non-customer enquiries/service quality (Art. 6(1)(f)); legal obligation where applicable
Retention
Until case closes and no later than 12 months after relationship ends, unless active legal matter.

Incidents, damage, insurance, fines, debt and legal claims

Personal data
Identity/contact, trip/vehicle, photos, statements, damage/fine/payment/insurance/claim records
Legal basis
Contract; legal obligation; legitimate interests in claims/recovery; Art. 9(2)(f) where strictly necessary
Retention
No later than 12 months after relationship ends, except strictly necessary records for a concrete active claim/dispute/investigation until final resolution.

Fraud, misuse and security

Personal data
Authentication, device/session, payment-risk, booking/ride, incident/security data
Legal basis
Legitimate interests in safety, fraud prevention, service integrity and security; legal obligation where applicable
Retention
Raw signals normally up to 90 days and no later than 12 months except documented active incident/claim.

Business/public-sector/customer/guest programmes

Personal data
Work/participant ID, eligibility, programme, budget/credit, transaction, cost/reporting data
Legal basis
Contract; legitimate interests in administration; legal obligation; or sponsor instructions where umob acts as processor
Retention
Participation + no later than 12 months after it ends. Statutory accounting records 7 years. Shorter programme periods may apply.

Service and safety communications

Personal data
Contact, language, booking/account context, delivery status/preferences
Legal basis
Contract; legal obligation; legitimate interests for important non-promotional service information
Retention
Only as needed and no later than 12 months after relationship ends unless part of active case.

Diagnostics and service improvement

Personal data
Limited usage events, feature interactions, crash/performance data, aggregated statistics
Legal basis
Legitimate interests for strictly necessary first-party diagnostics; consent for non-essential analytics where required
Retention
Raw diagnostic/event data normally up to 90 days and no later than 12 months. Irreversibly anonymised statistics may be kept longer.

Campaign measurement, marketing and surveys

Personal data
Contact/preference data, consent record, message interaction, campaign click or aggregate conversion result
Legal basis
Consent where required; applicable electronic-communications rules; legitimate interests for appropriate non-promotional research
Retention
Until withdrawal/opt-out and no later than 12 months after inactivity. Minimal suppression record may remain to honour opt-out. Cookie/SDK lifetimes shown in preference centre.

Recruitment

Personal data
Contact, CV/resume, cover letter, history, qualifications, interview/assessment, references, right-to-work where needed
Legal basis
Pre-contract steps (Art. 6(1)(b)); legitimate interests in fair recruitment (Art. 6(1)(f)); legal obligation or Art. 9 condition where applicable
Retention
180 days from the relevant recruitment process or candidate activity. 30 days before expiry, candidates may be invited by email to consent to a renewed/extended retention period. Expired candidate records are automatically deleted, except while the person is hired, part of an active vacancy, part of an active talent pool, or has relevant email activity in the preceding 30 days. Any extension must have a documented legal basis and a new expiry date.

Law, audits, regulatory requests and corporate transactions

Personal data
Data relevant to duty/audit/request/due diligence/transaction
Legal basis
Legal obligation; legitimate interests in governance and lawful transactions
Retention
Legally required period or duration of specific matter, minimised and access-restricted.

5. Retention rules and deletion

  • The periods above are maximum periods, not default targets. umob deletes or irreversibly anonymises data earlier when it is no longer needed.
  • General ceiling: operational account, booking, trip, location, payment, support, fine, insurance and programme data is deleted or irreversibly anonymised no later than 12 months after the customer relationship ends and outstanding operational obligations are settled.
  • Accounting exception: only the core invoice and accounting records required by law are kept for seven years. The full customer profile, precise location history and support file are not retained merely because an invoice must be kept.
  • Recruitment: candidate records use a 180-day retention cycle. Thirty days before expiry, the candidate may be invited to consent to an extension. Records whose retention period has expired are automatically deleted, except for hired candidates, candidates in an active vacancy, candidates in an active talent pool, or candidates with relevant email activity in the preceding 30 days. Any continued retention must have a documented legal basis and an updated expiry date.
  • Legal hold: a general possibility of future litigation is not enough. Only records necessary for an already existing claim, dispute, insurance matter, investigation or legal request may be ring-fenced until final resolution. Access is restricted and the hold is reviewed.
  • Consent and marketing: data used only on the basis of consent is no longer used after withdrawal. A minimal suppression record may be retained so that umob does not contact you again against your wishes.
  • Anonymous statistics: information may be kept longer after irreversible anonymisation. umob treats aggregated data as anonymous only when re-identification is no longer reasonably possible.

Closing or deleting an account does not automatically erase data that umob must temporarily retain under these rules. The account will no longer be available for normal use.

6. When data is required and the choices you have

Some information is required to create an account, make a booking, process a payment, verify eligibility or comply with provider and legal requirements. If you do not provide it, the relevant service or feature may not be available. The app identifies mandatory fields and explains service-specific requirements before use.

Location permission is a device control. When current location is necessary to show nearby options, reserve, unlock or end a ride, the GDPR legal basis is normally performance of the contract rather than the device permission itself. You can disable location access, but location-dependent features may then not work. Optional location use, if offered, requires the legal basis and choice shown in the app.

Marketing, non-essential analytics, campaign measurement and non-essential cookies or SDKs are optional. Refusing or withdrawing consent does not prevent access to the core mobility service. You can change these choices in the app, cookie preference centre, message settings or device settings, as applicable.

7. Who receives personal data

umob does not sell or rent personal data and does not disclose personal data to third parties for their own behavioural advertising purposes. Personal data may be disclosed only where necessary and proportionate to the purposes in this statement, including to:

  • The mobility, taxi, public-transport or other provider selected for the booking or journey.
  • Payment, banking and fraud-prevention providers. Some may be independent controllers for their own legal, payment-network and fraud obligations.
  • Identity, age or driving-licence verification providers.
  • Cloud hosting, database, authentication, mapping, communications, customer-support, security, monitoring, analytics and campaign-measurement providers acting for umob.
  • Employers, municipalities and other programme sponsors, but only for the fields and purposes described in the programme information and subject to role-appropriate agreements.
  • Insurers, professional advisers, debt-recovery providers, auditors and parties involved in a complaint, incident, dispute or claim.
  • Recruitment platforms, assessment providers, referees and professional advisers used to manage a job application.
  • Courts, regulators, tax authorities, law-enforcement agencies or other authorities where disclosure is required or permitted by law.
  • A prospective buyer, investor or successor in a merger, financing, reorganisation or sale, subject to confidentiality, necessity and applicable law.

A current overview of affiliated mobility and transport providers and links to their applicable terms and privacy statements is available at https://umob.app/nl/legal/mobility-service-providers-terms-privacy-statements. The exact provider for a journey is shown before booking or use.

8. International transfers

umob selects processing in the EEA where reasonably available and appropriate. However, some service providers, mobility providers, group companies or support teams may process personal data in, or access it from, a country outside the European Economic Area (EEA). A European contract party or EU data centre does not by itself exclude a third-country transfer.

Where umob is responsible for a transfer outside the EEA, we use a mechanism permitted by Chapter V GDPR. Depending on the destination and recipient this may include an adequacy decision under Article 45 GDPR, the European Commission Standard Contractual Clauses under Article 46 GDPR and, where required, supplementary contractual, organisational and technical measures. Article 49 derogations are used only where the conditions for an exceptional derogation are met.

Where a recipient relies on an adequacy decision, the transfer is made on that basis for as long as the decision remains applicable. Where Standard Contractual Clauses or another Article 46 safeguard is used, you may request information about the relevant safeguard and, where legally available, a copy of it by contacting support@umob.app. Where an independent mobility, payment or transport provider receives data, that provider’s privacy notice explains its own international transfers.

9. Cookies, SDKs, analytics and campaign measurement

The website and app use cookies, local storage, software development kits (SDKs) and similar technologies. Strictly necessary technologies support functions such as login, security, language, consent storage, payment flow and service continuity. They are used without consent only where applicable ePrivacy and electronic-communications rules allow this.

Optional analytics, advertising or campaign-measurement technologies are activated only after consent where required. The preference centre or app settings explain the relevant categories, purpose and duration. Consent can be withdrawn at any time without affecting the lawfulness of processing before withdrawal.

umob may measure how many clicks, app installs, registrations or purchases result from a campaign. umob has deliberately chosen not to store the individual campaign source in the umob customer profile or link it to trip, precise-location, payment or support history. We use aggregate campaign results to understand campaign performance. Limited technical request data may still be processed by a campaign-measurement provider; where this is not strictly necessary, the applicable consent requirements are followed.

umob does not use precise trip or location history to create third-party behavioural advertising profiles. Links to third-party websites, app stores or social platforms are governed by the privacy practices of those parties once you leave the umob service.

10. Location, verification, photos and special-category data

Location and journey data

Precise location and journey data can reveal sensitive patterns. umob therefore limits access, uses it only for defined mobility, safety, support, fraud and legal purposes, and applies the retention limits above. umob does not collect device location in the background. If this changes for a genuinely necessary feature, umob will provide prior feature-specific information and request the required device permission and consent where applicable.

Identity and driving-licence checks

Where a service requires verification, a specialised provider may process an identity or driving-licence document and a selfie or short video. umob normally receives the result and the minimum metadata needed for eligibility, such as licence class and expiry. The provider may also need to detect document fraud or compare the document photo with the live image.

If a verification step involves biometric data within Article 9 GDPR, umob will not activate that processing unless a valid Article 9 condition applies, the processing is necessary and proportionate, and the user receives a clear just-in-time notice. Where explicit consent is relied on, a suitable non-biometric alternative must be available.

Photos, incidents and health information

Parking and damage photos may be checked manually or with automated image analysis to confirm parking, vehicle condition or an incident. This analysis is not used to identify bystanders. Health or injury information is processed only where necessary for an emergency, insurance or legal claim and under the applicable Article 9 condition, such as vital interests or the establishment, exercise or defence of legal claims. Information relating to criminal convictions or offences is processed only where authorised by applicable EU or national law and with the required safeguards.

11. Business, employer and public-sector programmes

umob supports mobility budgets, subscriptions, credits, discounts and access programmes for employees, residents, visitors, customers and guests. Depending on the programme, the sponsor may provide eligibility data and receive information needed to fund, administer and evaluate the programme.

Programme reporting may include registration or participation status, budget or credit use, transaction amounts, mode of transport, date or period, team or cost centre, and sustainability indicators. umob limits reporting to what the sponsor needs and uses aggregated or de-identified reporting where the purpose allows. The exact individual-level fields, role allocation and legal basis are described in the invitation, programme terms or separate privacy information.

For municipal and policy dashboards, umob uses aggregated or anonymised information wherever possible. Data is called anonymous only after an objective assessment shows that a person can no longer reasonably be identified, including through combination with other reasonably available information. If a dashboard or report remains directly or indirectly identifiable, umob treats it as personal data and applies the GDPR, access restrictions, purpose limitations and the appropriate controller or processor arrangement.

12. Automated checks and account restrictions

umob may use automated rules to identify unusual logins, payment risk, suspected fraud, duplicate accounts, unsafe or prohibited use, or failure to meet service eligibility. A rule may generate a flag, request additional verification, temporarily pause a transaction or refer a case for review.

umob does not make a decision based solely on automated processing that produces legal effects or similarly significantly affects you unless Article 22 GDPR permits it and the required safeguards apply. Where an automated or partly automated decision materially restricts access to a service, you may ask for the reason, request human review, provide your point of view and contest the decision, subject to lawful security and fraud limitations.

13. Security and confidentiality

umob applies technical and organisational measures appropriate to the risks, including access controls based on role and need-to-know, multi-factor authentication where appropriate, encryption in transit and at rest where appropriate, logging, monitoring, vulnerability management, secure development, supplier due diligence, backups, incident response and periodic review of access rights.

No system can be guaranteed to be completely secure. If a personal-data breach creates a legal notification duty, umob will notify the competent supervisory authority and affected individuals as required by Articles 33 and 34 GDPR.

14. Your privacy rights

Subject to the conditions and exceptions in the GDPR, you may have the right to:

  • receive clear information about the processing of your personal data;
  • access your personal data and receive a copy (Article 15);
  • correct inaccurate or incomplete data (Article 16);
  • have data erased in the circumstances provided by law (Article 17);
  • restrict processing (Article 18);
  • receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where the portability conditions apply (Article 20);
  • object to processing based on legitimate interests, including profiling based on that ground (Article 21);
  • object at any time to direct marketing;
  • withdraw consent at any time for future processing (Article 7(3));
  • request the safeguards described for a significant automated decision (Article 22); and
  • lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority in the EEA country where you live, work or believe an infringement occurred (Article 77).

Send a request to support@umob.app. umob may ask for proportionate information to verify your identity and protect your account. We respond without undue delay and normally within one month. Where a request is complex or numerous, the GDPR permits an extension of up to two additional months; we will explain this within the first month.

Rights are not absolute. For example, umob may need to retain limited data for a statutory accounting duty, an active legal claim or the rights of another person. If we cannot fully grant a request, we will explain why and describe the available complaint and judicial-remedy options. For processing carried out independently by a mobility, payment or programme provider, you may also exercise your rights directly with that organisation. umob will reasonably help identify the correct organisation.

15. Children and age limits

The minimum age and eligibility rules depend on the mobility service, provider and local law and are shown before use. The minimum age for a general umob account and use of umob services is 18, unless a specific programme or product lawfully provides otherwise. Services requiring a driving licence are available only to users who meet the applicable age, licence and experience requirements.

umob does not knowingly create accounts for children below the applicable minimum age without the authorisation required by law. umob does not intentionally use children’s data for behavioural advertising. A parent or guardian who believes a child has provided data contrary to these rules should contact support@umob.app.

16. Changes to this statement and contact

umob may update this statement when services, technology, legal requirements or processing practices change. The current version and last-updated date are published on the website and made available in the app. If a change materially affects your rights or the way data is used, umob will provide an appropriate notice before the change takes effect where required.

Questions, complaints and rights requests may be sent to support@umob.app or through the in-app customer-service chat.

Controller: UMOB B.V. | Chamber of Commerce 82484724 | Rodezand 80, 3011 AL Rotterdam, the Netherlands.

260+ cities, 20+countries

Todo lo que necesitas en una sola aplicación

Desde el 5 de marzo es una manera en la que se voortbeweegt in Eindhoven. Bicicletas eléctricas, bicicletas eléctricas, patinetes, billetes de autobús y taxis, todo ello disponible en una sola aplicación.

Producto
Cómo funcionaOpciones de movilidadOfertaMembresías
Negocios
MunicipiosNegociosReal Estate Development
Acerca de
Acerca de umobPulsarCarreras
Ayuda
ContactoPreguntas frecuentes
© 2026 timoba
Créditos web
Este es un sitio web BORING
Política de privacidadTérminos y condiciones