Last updated: 8 June 2026.
Misy Technology SARLU is committed to protecting your personal data. This policy explains what data we process, why, on what legal basis, for how long, with whom, and your rights. It follows the standards of the EU General Data Protection Regulation (GDPR) and Malagasy law no. 2014-038 on the protection of personal data.
1. Data controller and contact
Controller: Misy Technology SARLU, Ambohimamory AB 739/III, Antanety, Bemasoandro, Antananarivo Atsimondrano (Madagascar). For any data question or to exercise your rights: contact@misy.app.
Identity and account: first/last name, phone number, email, password (encrypted), profile photo, date of birth, gender.
Ride data: origin, destination, distance, duration, route, price, ride history.
2. Data we process
Location: GPS position, for matching and ride tracking (see §6).
Payment: saved payment methods and transaction history.
Drivers: documents and licence, insurance, vehicle information, bank details, operating area, tax identifiers (TIN/STAT).
3. Purposes and legal bases
Device and usage: model, OS, app version, technical identifiers, usage and stability (crash) data.
Account creation/management and service delivery (matching, fare calculation, ride tracking, payment) — basis: performance of the contract.
Location for the ride — basis: performance of the contract and your consent (device permission).
4. Recipients and processors
Security, fraud and abuse prevention — basis: legitimate interest.
Analytics, advertising and personalisation (including location for advertising) — basis: consent, withdrawable at any time.
Accounting, tax and legal obligations — basis: legal obligation.
5. International data transfers
We do not sell or rent your data. We share it only with:
drivers/providers, to perform your ride (strictly necessary data);
our technical processors: Google / Firebase (authentication, database, storage, analytics, Google Maps & Places, crash reporting) and Meta / Facebook (sign-in and ad measurement), bound to protect your data;
6. Location
authorities, where legally required or to protect rights or people's safety.
Some data is processed by our processors (Google, Meta) whose servers may be located outside Madagascar and the European Union, notably in the United States. These transfers are covered by the appropriate safeguards required by applicable law (including providers' standard contractual clauses). Learn more: contact@misy.app.
We use your location to match you with the nearest driver and track your ride in real time. The driver app may use background location (while "online") to receive ride requests. Any use of location for advertising relies on your consent and aggregated/anonymised data; we never share your precise position with advertisers. You control location via your device permissions; disabling it may limit some features.
8. Retention periods
Precise location: for the ride and a short period, then anonymised/aggregated.
Technical logs: up to 12 months.
Marketing data (consent): until you withdraw consent.
9. Security
We implement appropriate technical and organisational measures (access control, password encryption, secure hosting) to protect your data against unauthorised access, disclosure, alteration or destruction.
You have the rights of access, rectification, erasure, restriction, objection, portability, and to withdraw consent at any time. Exercise them at contact@misy.app; we respond within one month. You may also lodge a complaint with the competent data protection authority (the Malagasy data protection authority, or your national authority within the European Union).
Our service is not intended for persons under 16, and we do not knowingly collect their data. If you are a parent or guardian and believe a minor has provided us data, contact contact@misy.app for deletion.
10. Your rights
We may update this policy. Material changes will be notified in the App and on the website.
For any question about this policy or your data: contact@misy.app.