Privacy policy — Laskar

Privacy Policy for Kardinal's Laskar Mobile App

Last updated — 23 February 2026

At KARDINAL, protecting your personal data is central to what we do. This Privacy Policy aims to explain clearly and in detail the types of data we collect, how they are processed, and your rights.

ARTICLE 01

Who we are

The Laskar application is published by KARDINAL, a simplified joint-stock company with share capital of €3,627.70, registered with the Paris Trade and Companies Register (RCS) under number 809 234 586, SIRET 809 234 586 00034, whose registered office is located at 10 rue de Penthièvre, 75008 Paris (France).

Publication Director: Mr. Jonathan Bouaziz.

If you have any questions, you may contact us at +33 1 85 76 20 29 or by email at contact@kardinal.ai.

For application support: support-app@kardinal.ai

As data controller, we comply with the provisions of the GDPR (EU Regulation 2016/679).

ARTICLE 02

Data we collect

When you install and use the Laskar Application, we only collect the information necessary for its operation and security.

2.1 Identification and account data

  • Phone number: may be requested at sign-up if you choose this login method.
  • Email address: collected when you choose to sign up/log in by email, or when you add it to your account. It is used (i) for account identification and management, (ii) to send service-related communications (e.g. important information, satisfaction surveys and feedback on upcoming features) and (iii) only with your consent, to send marketing communications.
  • First name: may optionally be provided to personalise your experience.
  • Technical account identifiers: internal user ID, sign-up method (phone/email/SSO), language/locale, and account-related flags (e.g. test account).

2.2 Usage, configuration and preference data

  • Onboarding responses (if provided): occupation/use case, route hours (start/end), number of stops, stop duration, vehicle type.
  • Navigation and route preferences: toll avoidance, traffic consideration, departure time, operating duration, break settings (duration and time window), navigation provider (e.g. Google Maps/Apple Maps/Waze), vehicle type, and other configuration settings.
  • Geographic coordinates (where applicable): certain preferences may include latitude/longitude coordinates associated with a start/end address saved as a preference. This is not continuous real-time tracking, but location information tied to a configuration setting.

2.3 Route and address data

Route addresses (entered to plan your itineraries) and favourite addresses: stored locally on your device. If the Application is uninstalled, this local data is automatically deleted.

2.4 User-generated content

  • Photos taken within the Application (e.g. package photos / proof of delivery).
  • Notes and comments associated with addresses.

Photos and notes you enter may contain information relating to third parties (e.g. recipients). We recommend that you do not include sensitive information in them (e.g. banking details, identity documents).

2.5 Subscription and payment data

To manage the Pro subscription, we process minimal transaction-related information via Google Play (in-app purchases) or the Apple App Store (in-app purchases), such as: technical transaction/order identifiers, subscription type, status (active/inactive), purchase, expiry or renewal dates, and trial period.

No credit card data is stored or accessible by KARDINAL: such data is processed exclusively by Google Play or Apple.

2.6 Technical and analytics data

  • Technical and performance data (pseudonymised): device type, operating system, IP address, performance metrics, error reports, collected via Firebase (e.g. Analytics / technical services).
  • Usage data (pseudonymised): frequency of use, in-app navigation paths, errors encountered, collected via Firebase.
ARTICLE 03

Sign-up and authentication

Sign-up and login to Laskar are handled via Google's Firebase Authentication, depending on the method chosen:

  • Phone number login: a one-time code (OTP) is sent by SMS when logging in. This code expires after 5 minutes and is not retained beyond its verification.
  • Email login: authentication is carried out via Firebase Authentication according to the methods offered within the Application.
  • Login via Google (SSO) or Apple (SSO): you may log in using your Google account or via "Sign in with Apple", according to the methods offered within the Application.

In the event of multiple failed attempts, Firebase applies a temporary lockout in accordance with its own security policy.

ARTICLE 04

Purposes and legal bases

Your data is processed to:

  • Provide and improve Laskar: account creation and management, route calculation, route optimisation, personalisation (onboarding, preferences), and development of new features.
  • Manage the subscription: activation, verification, renewal, trial management, fraud prevention and resolution of subscription-related incidents.
  • Provide customer support: handle your requests, answer your questions, manage tickets, diagnose and fix bugs, and ensure follow-up.
  • Conduct satisfaction surveys and product research: occasionally contact you (by email and/or phone) to gather your feedback on upcoming features to develop; you may object to this at any time.
  • Ensure security: verify accounts, detect fraudulent use and maintain technical stability.
  • Send transactional communications: sign-up confirmations, account-related notifications, subscription reminders, security alerts.
  • Marketing (with your consent): newsletters and targeted promotions (you may unsubscribe at any time).
  • Comply with our legal obligations and defend our interests: regulatory compliance, dispute management, fraud prevention, and any potential reorganisation transactions (mergers and acquisitions).

Depending on the case, this processing is based on:

  • performance of the contract (access to the Application, account management, support, subscription management),
  • your consent (marketing communications and, where applicable, certain communications according to your choices),
  • our legitimate interest (improving and securing the service, fraud prevention, product research),
  • and, where applicable, our legal obligations.

Processing related to customer support is based on performance of the contract (provision of the service) and/or our legitimate interest (providing assistance, and ensuring the quality and security of the service).

Satisfaction surveys and product research are based on our legitimate interest; you may object at any time via the link provided in the relevant email or by contacting us at rgpd@kardinal.ai.

ARTICLE 05

Recipients of your data

  • Our internal team authorised to process data.

Main subprocessors:

  • Google Firebase / Google Cloud (authentication, database, analytics and technical services)
  • Google Play (in-app purchases)
  • Apple App Store (in-app purchases)
  • Gmail / Google Workspace (support mailbox: support-app@kardinal.ai)
  • GitLab (management and tracking of support requests and bug reports)
  • WhatsApp Business (Meta) (management of support exchanges via messaging)

Emails and SMS (if used):

  • Brevo (management of email sending and unsubscribes, depending on the communications enabled)
  • SMSenvoi (management of SMS sending, depending on the communications enabled)

Note – WhatsApp: when you contact our support via WhatsApp, your messages are processed via the WhatsApp platform (Meta) under its own terms. We recommend that you do not share sensitive information (e.g. credit card details, identity documents) through this channel.

  • Public authorities, if required by law.

No transfer of data: KARDINAL undertakes not to sell, exchange or rent any of your collected personal data.

No transfer of your personal data is made outside the European Union without GDPR-compliant contractual safeguards.

ARTICLE 06

Retention period and inactivity

  • Your account and subscription information is retained for as long as your account remains active.
  • If your account is inactive for 24 consecutive months, we will delete your personal data, unless otherwise required by law or necessary in connection with a dispute.
  • Route and favourite address data resides on your device until manually deleted or until the Application is uninstalled.
  • Photos and notes: retained for as long as your account is active or until deleted from within the Application, then deleted/anonymised within a reasonable period (unless required by law or in the event of a dispute).
  • Marketing data: retained until you withdraw your consent (unsubscribe). Minimal information regarding your objection/unsubscription may be retained so that we no longer contact you.
  • Support tickets and exchanges: retained for 36 months after the request is closed, then deleted or anonymised, unless required by law or necessary for managing a dispute.
ARTICLE 07

Policy updates

KARDINAL reserves the right to amend this Privacy Policy at any time. The date of the last update is shown at the top of the document. We encourage you to review it regularly.

ARTICLE 08

Exercising your rights

In accordance with Regulation (EU) 2016/679 ("GDPR"), you have the following rights over your personal data: right of access, right to rectification, right to erasure, right to object, right to restriction of processing, right to data portability.

To exercise these rights, send your request to: rgpd@kardinal.ai

You may also lodge a complaint with the French Data Protection Authority (CNIL) via its website: https://www.cnil.fr

ARTICLE 09

Minors

The application is reserved for persons aged 18 and over, for professional use only.

By continuing to use the Laskar Application, you acknowledge that you have read this Privacy Policy and accept it in its most recent version.