Handover
PrivacyTermsSupportDelete account

Privacy policy

Last updated: 4 August 2026

This page says what personal data Handover processes, why, where it is held and for how long. It describes what the app actually does, not what an app of this kind might one day do.

Who is responsible

Handover is provided by MCODE, obrt za računalno programiranje, D. Cesarica 76, 31550 Valpovo, Hrvatska, Croatian tax number (OIB) 58358056658.

For anything to do with personal data, write to hello@mcode.hr.

Data that a rental operator enters about a guest belongs to that operator: the operator is the controller and decided to collect it, and we are the processor acting on the operator’s instructions. For the operator’s own account we are the controller.

Whose data this is about

The user of the app is the rental operator — the owner of the business and their staff. The guest installs nothing: a member of staff types the guest’s details in and the guest signs on the staff member’s phone.

So two groups of people are described here. The guest is not a user of the app, but data about the guest is still personal data and this policy covers it.

What is collected

Operator account
Sign-in e-mail address and password, the staff member’s name, their role in the company and an account identifier. Without these there is no sign-in and no separation of one company’s data from another’s.
Guest details
First and last name, and the language the record is issued in. Optionally an e-mail address, a phone number, the type of identity document (ID card, passport, driving licence or other), its number and the issuing country. All of it is typed in by staff, and it is what ties the record to a particular person.
Handover photographs
Photographs of the vehicle, boat or piece of equipment at check-out and at check-in. This is the evidence itself, and the reason the app exists.
Photo location
GPS coordinates, estimated accuracy, altitude and the time of the fix, stored with each photograph. They are taken only at the moment a photo is captured and only while the app is open. There is no background location.
Signatures
The guest’s and the staff member’s signatures as images, the signer’s name, their role and the time of signing.
Condition of the unit
Fuel level, odometer or engine hours, marked damage with a description and an amount, and the deposit settlement.
Device details
Platform (iOS or Android), operating-system version, device model, app version, time zone and UTC offset. They are stored with the capture so that it is later possible to say what took the photo and on whose clock.
The PDF record
A document containing all of the above, produced on our server when a handover is completed.
Subscription
Company name, billing e-mail address, the chosen plan and a Stripe customer identifier. Card details never pass through the app or through our servers — payment happens on Stripe’s own page.

Why it is collected

Every field above exists for one reason: so that the handover record is usable as evidence afterwards. A timestamp without a location does not show where the vehicle was, a photograph without a signature does not show that the guest saw it, and a record without a name does not show who it concerns.

None of it is used to measure user behaviour, to personalise anything, or for advertising.

Legal basis

  • The operator account and the subscription — performance of the contract the operator has with us.
  • Guest data — performance of the rental agreement and the operator’s legitimate interest in being able to prove the condition in which a unit was handed over and returned. The operator decides on that processing and has to explain it to their guest.
  • Invoices and payment records — compliance with tax and accounting law.

What the app does not have

This list is shorter than is usual for a mobile app, and deliberately so. The app contains:

  • no analytics of any kind — no Firebase Analytics, no Google Analytics, nothing that measures how the app is used;
  • no crash reporting and no performance monitoring — no Crashlytics, no Sentry;
  • no advertising SDK and no advertising identifier;
  • no third-party trackers, pixels or tracking cookies;
  • no access to contacts, calendar or microphone.

Nothing is sold, traded or passed to data brokers. The only outside companies that see any of this are the ones the app cannot run without, and they are named in the next section.

Where the data is held

Data is held with Google, in Firebase services (Authentication, Firestore, Cloud Storage and Cloud Functions), in the europe-west1 region — that is, inside the European Union. In that role Google is our processor, not a recipient using the data for its own purposes.

Subscriptions are billed through Stripe. Stripe receives the company name and the billing e-mail address. Nothing from a handover record — no photograph, no guest name, no location — goes to Stripe.

Traffic between the device and the server is HTTPS throughout. Anything not yet uploaded stays on the phone itself until the network returns, because the app is built to work without a signal.

The link the guest receives

The record is given to the guest as a link they open in a browser, with no account and without installing anything. The link contains a random token; the token itself carries no guest data, it only points at the record.

The link stops working when the retention period set by the operator expires, and the operator can revoke it sooner.

Sending the record by e-mail

If a member of staff enters the guest’s e-mail address, it is stored on the record so that the record can be sent to them.

That sending is currently switched off. The system has no outgoing mail server configured, so no message is sent to anyone — instead of being sent, it is written to a service log on our server. Until that changes, a guest e-mail address that has been entered simply sits on the record and is erased with the rest of the guest’s data when the retention period expires.

When sending is switched on, this page will be updated before the first message goes out.

How long it is kept

The operator sets the retention period for their own company. The default is 24 months and it can be set anywhere between 1 and 120 months.

When the period expires the record is not deleted; it is anonymised automatically. The split is deliberate:

Removed
The guest’s first and last name, e-mail address, phone number, identity-document type and number, issuing country, the name search key, the image of the guest’s signature and the signer’s name.
Kept
The photographs and their cryptographic hashes, capture times and GPS, damage marks and descriptions, settlement amounts, device details and the language of the record. That is evidence about the condition of the unit, and after anonymisation it no longer points to anyone.

Why not deletion: a chargeback or an insurer’s question can arrive years later, and what has to be shown then is the condition the vehicle was in — not who was driving it. The guest’s link expires at the same moment.

Your rights

Anyone whose data is processed here has the right to ask for access to it, for it to be corrected or erased, for processing to be restricted, for the data to be transferred to another controller, and to object to the processing.

Requests go to hello@mcode.hr. We answer within one month at the latest, as the General Data Protection Regulation requires.

If you are a guest whose details were entered by a rental business, contact that business first — it is the controller and it decides. If they do not reply, or you do not know who to ask, write to us and we will pass the request on and act on it.

You may also complain to a supervisory authority. In Croatia that is the Personal Data Protection Agency (AZOP, azop.hr).

Children

Handover is a tool for business use. It is not directed at children and is not offered to them.

Changes to this policy

When what the app does with data changes, this page changes with it. The date at the top shows when it was last edited.

Also on this site:HomeTermsSupportDelete account
Language:HrvatskiEnglishDeutsch