Home › Privacy Policy

Privacy Policy.

Last updated: 14 August 2026

The short version

  • Fab asks the apps you have connected for their prices. Your trip addresses are used for that, and nothing else.
  • Your login tokens are encrypted on our servers or stay on your device. Your provider passwords are never stored on our servers.
  • Our servers are in Europe.
  • No ads, no data selling, no advertising trackers. Our usage statistics stay internal.
  • Your location is only read while you use the app, never in the background.
  • Deleting your account erases everything, within 30 days at most. A question? contact@fabapp.fr

The full detail follows, section by section.

1. Data controller

The data controller is FAB, a simplified joint-stock company (société par actions simplifiée) under French law with a share capital of €1,000, registered with the Nanterre Trade and Companies Register under number 108 300 443, whose registered office is at 31B boulevard de la Saussaye, 92200 Neuilly-sur-Seine, France (“Fab”).

Contact: contact@fabapp.fr

The same company is identified in the legal notice as the publisher of the website. It is named here as the data controller: a separate requirement under article 13 of the GDPR, and the address to write to in order to exercise your rights.

2. Data we collect

Fab collects only the data necessary to run the service:

  • User account: email address, name (if provided via Google or Apple)
  • Trip addresses: pickup, drop-off and intermediate stops entered for comparison
  • Location data: GPS coordinates of your pickup point, while in use only, to autocomplete your address and adapt the service to your city. No background location tracking.
  • Phone number: only when connecting to a provider that authenticates by SMS (Bolt, Heetch, Freenow), passed to that provider to start authentication
  • Authentication tokens: provider login tokens. Depending on the provider, they are either encrypted before being stored on our servers (this is what lets you restore your connections on a new device) or kept only on your device.
  • Ride history: booked trips, prices, chosen provider
  • Internal usage analytics: product events linked to your account (onboarding steps completed, features used), used internally only to understand and improve the service. No advertising tracking, no profiling, no sharing with third parties.
  • Technical data: device type, OS and app version

3. Purposes of processing

  • Displaying and comparing the prices of the VTC providers whose accounts you have connected
  • Managing your account and preferences
  • Encrypted synchronisation of your provider connections across your devices
  • Tracking your ride history and spending
  • Sending account emails (address confirmation, password reset)
  • Continuous improvement of the service via our internal usage statistics

4. Legal basis

Processing your data relies on:

  • Performance of the contract: providing the price-comparison service
  • Your consent: voluntary connection of your provider accounts
  • Legitimate interest: app security and service improvement

5. Storage and security

  • Authentication and account emails: Supabase, project hosted in Europe
  • Backend infrastructure: Railway, West Europe region (Amsterdam), with TLS-encrypted communications
  • Provider tokens (server-side): AES-256 encryption before storage, never kept in plaintext at rest
  • Sensitive local storage: some information required to connect providers may be stored in the iOS Keychain or Android Keystore via Expo SecureStore
  • General local storage: some preferences and session data, including login tokens, may be stored locally on your device in the app sandbox
  • Geocoding: Google Maps Platform via our backend, with a short-lived technical cache of a few minutes
  • Server error monitoring: Sentry, on a project hosted in the European Union (Germany). When an error occurs on our servers, Sentry receives its message, the technical stack trace, and the method and path of the route involved. No IP address, no request headers, no cookies, no request content.
  • App crash monitoring: Sentry as well, on a separate project, also hosted in the European Union (Germany). When the app crashes or freezes, Sentry receives its message, the technical stack trace, the app version, the operating system and device model, and your Fab account identifier, never your name or your email address. The app sends no screenshot, no session recording and no request content: addresses, location coordinates and web address parameters are stripped before sending.

6. Data sharing

Fab never sells your data. No data is shared for advertising purposes. Your data is only shared with:

  • The VTC providers: trip addresses, as part of price requests
  • Supabase: authentication and encrypted storage, project hosted in the EU
  • Railway: backend infrastructure (West Europe)
  • Google Maps Platform: addresses and coordinates, for geocoding and autocomplete (our backend acts as intermediary)
  • Sentry: technical error messages from our servers and app crash reports, to diagnose and fix failures. Projects hosted in the European Union (Germany).

This list may evolve with the service: the version published on this page prevails, and any substantial change is announced in the app.

7. Transfers outside the European Union

Some processors may handle data outside the European Union, notably in the United States. This is the case for Google Maps Platform, as well as VTC providers established outside the Union when you compare their prices. Where necessary, Fab relies on the safeguards provided by the GDPR, such as the Data Privacy Framework where the provider participates, or standard contractual clauses.

8. Retention

  • Active account: data kept for the duration of use
  • Account deletion: full erasure within 30 days
  • Provider tokens: deleted immediately when you disconnect a provider or delete your account
  • Backend geocoding cache: a few minutes
  • Sentry error reports: 90 days

9. Your rights

Under the GDPR, you have the following rights:

  • Access: obtain a copy of all your data
  • Rectification: correct inaccurate information
  • Erasure: delete your account and all your data
  • Portability: receive your data in a structured format
  • Objection: object to certain processing
  • Restriction: request temporary restriction of certain processing

To exercise these rights, contact us at contact@fabapp.fr. Response time: one month maximum.

10. Minimum age

Fab is not intended for users under 16. We do not knowingly collect data about minors under 16.

11. Cookies and trackers

The Fab mobile app uses no cookies or advertising trackers. No third-party behavioural analytics (Google Analytics, Facebook Pixel, etc.). Our statistics rely solely on our own product events, linked to your account and never shared. The fabapp.fr website sets no cookies and uses no audience-measurement tool; its fonts are loaded from Google Fonts, which transmits the visitor's IP address to Google.

12. Installed-app detection

To adapt onboarding and suggest relevant VTC providers, Fab checks whether the apps of the providers available in Fab (Uber, Bolt, Freenow, G7, LeCab, Heetch, Comin, Lyft, Cabify, Waymo, Empower; the exact list depends on the platform) are installed on your phone via the system URL-scheme mechanism (iOS) or Package queries (Android). This check returns only a yes/no boolean per app: no usage data from those apps is read, and the check never leaves your device.

13. Apple Sign-In relay service

If you sign in with Apple Sign-In and choose to hide your email address, Apple generates a relay address (xxx@privaterelay.appleid.com) that forwards our emails to your real address. We only see the relay version; you keep control in your Apple ID settings.

14. Changes

This policy may be updated. In case of a substantial change, you will be informed via the app.

Questions about your data? Email contact@fabapp.fr. You may also lodge a complaint with the French data-protection authority, the CNIL.