Privacy Policy
Version: 2026-09-24
1. Data Controller
The controller of your personal data is Oleksii Kuznietsov, a private individual ("we"), reachable at [email protected].
We do not sell your personal data, we do not show advertising, and we do not use your data for automated decision-making or profiling.
2. Data We Collect
Analytics (cookieless): We use our own privacy-friendly analytics service. It records the page you visit, the referring site, your browser, operating system and device type, and your country, plus a few interactions: clicks on the button that opens the map (together with any utm_ campaign parameters in the link), the default fuel you choose, clicks on links to other sites, and form submissions (that a form was sent — never what you typed). It sets no cookies and stores nothing in your browser. To count unique visitors, it combines your IP address and browser User-Agent into a one-way hash with a salt that changes every 24 hours; the IP address itself is never stored, and yesterday's hash cannot be matched to today's, so it cannot recognise you across days. The data stays on our servers and is not shared with anyone.
Location ("near me"): When you use the "near me" search, your browser asks for your permission first. Your coordinates are sent to our API only as parameters of the search request and are never stored on our servers. In your browser they are kept in sessionStorage (see Section 3), which is cleared when you close the tab. You can revoke the permission at any time in your browser's site settings.
Account data: If you create a tanqo account, we store your email address (which is also your sign-in name), a one-way cryptographic hash of your password — never the password itself — the date the account was created, and the stations you save. We use this data to authenticate you, to send account-related emails (email verification, password reset, and a notice to your previous address whenever an email change is requested), and to keep your saved stations. You can change your email or password, and delete your account entirely, at any time from Account settings — see Section 7.
Sign in with Google: If you choose to sign in with Google, Google sends us a signed token after you approve the request on Google's page. We request only the openid email scope, and from that token we store only your Google account identifier and your email address, linked to your tanqo account. We do not receive your name, photo, contacts or any other Google data. Google processes your sign-in as an independent controller under the Google Privacy Policy.
Passkeys: You can add one or more passkeys to your account, or create an account with a passkey and no password at all. A passkey lets you sign in with your device's own screen lock — a fingerprint, face scan, or PIN. Your fingerprint, face scan, or PIN never leave your device and are never sent to us. For each passkey we store only a public key, a credential identifier, a signature counter, and a name you choose for it (for example, "work laptop") — none of which can be used to authenticate as you without your device. You can rename or remove a passkey at any time from Account settings; deleting your account removes every passkey. If you create an account with only a passkey, we still ask for your email address so that you can recover access if you lose every device.
Saved stations on this device (no account): You can star a station without creating an account. When you do, we store only that station's numeric id in your browser's localStorage, under the key tanqoFavourites. Nothing else is kept: no coordinates, no address, and no record of where or when you were — the id is a pointer into our public list of stations, not a location history. It never leaves your browser until you sign in, at which point the saved stations are copied into your account and the local copy is cleared.
Cookie notice record: When you first visit, we show a notice about cookies and this policy. Today we use only the strictly necessary cookies and browser storage listed in Section 3, so your choice does not switch any optional cookies on or off. We still record it, so we can show that you were informed and ask you again if we ever add optional cookies. The record contains: a random identifier created in your browser, your choice (Accept or Decline), the version and language of this policy, the country portal, the date and time, and a one-way SHA-256 hash of your browser's User-Agent string. It contains no name, email address or IP address.
Security and abuse protection: To limit repeated attempts at actions such as signing in, registering or requesting a password reset, our API turns your IP address into a one-way hash and keeps it only in server memory for the 15-minute rate-limit window. It is never written to a database or to a log. We do not keep IP access logs.
3. Cookies and Browser Storage
We use only strictly necessary cookies and storage, and preferences you set yourself. None of them are used for advertising or to track you across other websites.
Cookies:
tanqo_country(strictly necessary, set by us) — which country portal you use (UAorPL), so we show you the right prices and stations. It is chosen from the portal you open and, where enabled, from the two-letter country code Cloudflare adds to each request (CF-IPCountry); we never see your IP address for this. Kept for 1 year.tanqo_locale(preference, set by us) — the language you picked with the language switcher, for example"en"or"uk". Set only when you use the switcher. Kept for 1 year.tanqo_refresh_token(strictly necessary, set by us) — keeps you signed in between visits. Set only when you sign in. It ishttpOnly— JavaScript in your browser cannot read it — is sent only to our sign-in endpoints (/api/auth), holds a random session identifier and no personal data, and is replaced with a new value every time it is used. It is deleted when you sign out and expires 30 days after its last use. Your access token is held in memory only and is never written to storage or to a cookie.__cf_bm(strictly necessary, set by Cloudflare) — distinguishes people from automated bots to protect the site from abuse. Expires after 30 minutes.cf_clearance(strictly necessary, set by Cloudflare) — set only if you are shown and pass a Cloudflare security check, so you are not asked again straight away. It expires after the period set in our Cloudflare security settings.
Browser localStorage (stays until you remove it or clear your browser's site data):
tanqo_email_consent_UA— your choice in the cookie notice, so it is not shown again.tanqo_cookie_id— the random identifier sent with the cookie notice record (Section 2).tanqo_consent_id— the identifier of that record on our server.tanqoFavourites— stations you starred without an account.tanqo_default_fuel— the default fuel you chose.tanqo_policy_UA_en,tanqo_policy_UA_uk— the version date of this policy, cached until the end of the day. No personal data.tanqo-runtime-config— site settings, cached for 5 minutes. No personal data.
Browser sessionStorage (cleared when you close the tab):
tanqoMapState— the map's position, zoom and filters, so going back restores your view.tanqoUserPosition— your location, only if you used "near me".tanqoFavouritePromptSeen— whether we already suggested signing in after you starred a station.
You can delete all of these at any time by clearing your browser's cookies and site data. Deleting tanqo_refresh_token signs you out.
4. Legal Basis
This policy is based on Law of Ukraine No. 2297-VI "On the Protection of Personal Data" (the "Law"). References below are to the grounds in Part 1 of Art. 11 of the Law.
Location: item 1 — your consent, given through your browser's permission prompt at the moment you use "near me".
Account data, sign in with Google, passkeys and account emails: item 3 — processing necessary to provide the account service you asked us to create. Account-security emails are also based on item 6 — our legitimate interest in protecting accounts from unauthorised access.
Analytics: item 6 — our legitimate interest in understanding, in aggregate, how the site is used so we can improve it. The analytics collect no data that identifies you and set no cookies.
Cookie notice record: item 6 — our legitimate interest in being able to show that you were informed about cookies and this policy.
Security and abuse protection (IP hashing and Cloudflare's __cf_bm and cf_clearance): item 6 — our legitimate interest in keeping the service and your account safe.
Strictly necessary cookies and storage (tanqo_country, tanqo_refresh_token, and the browser storage listed in Section 3): item 3 — needed to provide the service you requested. Strictly necessary cookies do not require consent.
Language preference and saved stations on this device: item 3 — stored because you asked us to remember them.
5. Recipients and Cross-Border Transfer
Our servers: tanqo, including the analytics, runs on servers located in the European Union.
Cloudflare, Inc. (USA): Every request to tanqo passes through Cloudflare's network, which protects the site and connects it to our servers. Cloudflare therefore processes your IP address and request data on our behalf, runs the automated bot protection described in Section 3, and delivers the emails we send you. See Cloudflare's Privacy Policy.
Google: only if you choose to sign in with Google — see Section 2.
OpenStreetMap (OpenStreetMap Foundation, United Kingdom): The map displays tiles loaded from *.tile.openstreetmap.org. When the map loads, your browser sends your IP address to OpenStreetMap's servers as part of the standard HTTP request. We do not receive or store this data. See OpenStreetMap's Privacy Policy.
Cross-border transfer (Art. 29 of the Law): Our servers are in the European Union, which provides an adequate level of personal-data protection under Art. 29 of the Law. Cloudflare's network is global, so request data and emails may also be processed in other countries, including the USA. Cloudflare protects this data under its data processing terms, which include the European Commission's Standard Contractual Clauses; the transfer is necessary to deliver the service you requested. OpenStreetMap is in the United Kingdom, a party to the Council of Europe Convention 108 on data protection.
We do not share your data with anyone else, unless the law requires us to.
6. Data Retention
Analytics: Aggregated statistics are kept for 365 days. The daily visitor hash is discarded after 24 hours.
Location: Not stored on our servers. In your browser, until you close the tab.
Account data: Kept for as long as your account exists. When you delete your account, your email address, sign-in name and password hash are erased immediately, along with every active session, every Google sign-in link and every registered passkey. We keep a residual record with no contact details — identified only by a randomly generated two-word pseudonym (for example, "wise-otter") — so that any contributions you make to the shared station data remain attributable to a stable pseudonym rather than being silently rewritten. This record cannot be linked back to you. The deleted email address becomes immediately available to register a new, unrelated account.
Session cookie: Up to 30 days from its last use. It is deleted immediately when you sign out or delete your account. Changing your password replaces it with a new one on the device you changed it from, and ends every session on your other devices at the same time — the cookie stored in each of those browsers cannot be erased remotely, but the server stops honouring it immediately, so it can no longer keep you signed in.
Cookie notice record: Kept for 5 years from the date of your choice, as evidence that you were informed, and then deleted. It contains no name, email address or IP address.
Hashed IP addresses (security): Held in server memory only for the 15-minute rate-limit window, then discarded.
Other cookies and browser storage: For the periods listed in Section 3.
7. Your Rights
Under Art. 8 of the Law, you have the right to:
- Know where your personal data is, why it is processed and who receives it
- Access the personal data we hold about you — we reply within 30 days
- Have inaccurate data corrected
- Have your data deleted
- Restrict processing
- Object to processing
- Withdraw your consent at any time — for location, by revoking the permission in your browser's site settings; withdrawal does not affect the lawfulness of processing before it. You can change your cookie notice choice at any time: the "Privacy Policy" link in the page footer opens the notice again
- Lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights (ombudsman.gov.ua) or go to court
Deleting your account. If you have an account, you can erase it yourself at any time: open Account settings, choose Delete account, and confirm. The deletion is immediate and irreversible, and it takes effect without us needing to act. As described in Section 6, this erases your email address, sign-in name, password and sessions; only an anonymised, non-identifiable record is retained.
If you cannot sign in — for example, you have lost access to your mailbox — you can still ask us to delete your account by writing to [email protected] from the address the account is registered to, or otherwise providing enough information for us to identify the account. We will action the request without undue delay and within one month.
To exercise any of the other rights above, contact us at [email protected].
8. Changes to This Policy
We may update this policy from time to time. The "Last updated" date at the top of the page will reflect any changes. If we ever add cookies that are not strictly necessary, we will ask for your consent before setting them.
9. Contact
Oleksii Kuznietsov — [email protected]
Data controller: Oleksii Kuznietsov, [email protected]