tanqo

Privacy Policy

Version: 2026-09-24

1. Data Controller

The controller of your personal data is Oleksii Kuznietsov, a private individual ("we"), reachable at [email protected].

We do not sell your personal data, we do not show advertising, and we do not use your data for automated decision-making or profiling.

2. Data We Collect

Analytics (cookieless): We use our own privacy-friendly analytics service. It records the page you visit, the referring site, your browser, operating system and device type, and your country, plus a few interactions: clicks on the button that opens the map (together with any utm_ campaign parameters in the link), the default fuel you choose, clicks on links to other sites, and form submissions (that a form was sent — never what you typed). It sets no cookies and stores nothing in your browser. To count unique visitors, it combines your IP address and browser User-Agent into a one-way hash with a salt that changes every 24 hours; the IP address itself is never stored, and yesterday's hash cannot be matched to today's, so it cannot recognise you across days. The data stays on our servers and is not shared with anyone.

Location ("near me"): When you use the "near me" search, your browser asks for your permission first. Your coordinates are sent to our API only as parameters of the search request and are never stored on our servers. In your browser they are kept in sessionStorage (see Section 3), which is cleared when you close the tab. You can revoke the permission at any time in your browser's site settings.

Account data: If you create a tanqo account, we store your email address (which is also your sign-in name), a one-way cryptographic hash of your password — never the password itself — the date the account was created, and the stations you save. We use this data to authenticate you, to send account-related emails (email verification, password reset, and a notice to your previous address whenever an email change is requested), and to keep your saved stations. You can change your email or password, and delete your account entirely, at any time from Account settings — see Section 7.

Sign in with Google: If you choose to sign in with Google, Google sends us a signed token after you approve the request on Google's page. We request only the openid email scope, and from that token we store only your Google account identifier and your email address, linked to your tanqo account. We do not receive your name, photo, contacts or any other Google data. Google processes your sign-in as an independent controller under the Google Privacy Policy.

Passkeys: You can add one or more passkeys to your account, or create an account with a passkey and no password at all. A passkey lets you sign in with your device's own screen lock — a fingerprint, face scan, or PIN. Your fingerprint, face scan, or PIN never leave your device and are never sent to us. For each passkey we store only a public key, a credential identifier, a signature counter, and a name you choose for it (for example, "work laptop") — none of which can be used to authenticate as you without your device. You can rename or remove a passkey at any time from Account settings; deleting your account removes every passkey. If you create an account with only a passkey, we still ask for your email address so that you can recover access if you lose every device.

Saved stations on this device (no account): You can star a station without creating an account. When you do, we store only that station's numeric id in your browser's localStorage, under the key tanqoFavourites. Nothing else is kept: no coordinates, no address, and no record of where or when you were — the id is a pointer into our public list of stations, not a location history. It never leaves your browser until you sign in, at which point the saved stations are copied into your account and the local copy is cleared.

Cookie notice record: When you first visit, we show a notice about cookies and this policy. Today we use only the strictly necessary cookies and browser storage listed in Section 3, so your choice does not switch any optional cookies on or off. We still record it, so we can show that you were informed and ask you again if we ever add optional cookies. The record contains: a random identifier created in your browser, your choice (Accept or Decline), the version and language of this policy, the country portal, the date and time, and a one-way SHA-256 hash of your browser's User-Agent string. It contains no name, email address or IP address.

Security and abuse protection: To limit repeated attempts at actions such as signing in, registering or requesting a password reset, our API turns your IP address into a one-way hash and keeps it only in server memory for the 15-minute rate-limit window. It is never written to a database or to a log. We do not keep IP access logs.

3. Cookies and Browser Storage

We use only strictly necessary cookies and storage, and preferences you set yourself. None of them are used for advertising or to track you across other websites.

Cookies:

Browser localStorage (stays until you remove it or clear your browser's site data):

Browser sessionStorage (cleared when you close the tab):

You can delete all of these at any time by clearing your browser's cookies and site data. Deleting tanqo_refresh_token signs you out.

4. Legal Basis

This policy is based on Law of Ukraine No. 2297-VI "On the Protection of Personal Data" (the "Law"). References below are to the grounds in Part 1 of Art. 11 of the Law.

Location: item 1 — your consent, given through your browser's permission prompt at the moment you use "near me".

Account data, sign in with Google, passkeys and account emails: item 3 — processing necessary to provide the account service you asked us to create. Account-security emails are also based on item 6 — our legitimate interest in protecting accounts from unauthorised access.

Analytics: item 6 — our legitimate interest in understanding, in aggregate, how the site is used so we can improve it. The analytics collect no data that identifies you and set no cookies.

Cookie notice record: item 6 — our legitimate interest in being able to show that you were informed about cookies and this policy.

Security and abuse protection (IP hashing and Cloudflare's __cf_bm and cf_clearance): item 6 — our legitimate interest in keeping the service and your account safe.

Strictly necessary cookies and storage (tanqo_country, tanqo_refresh_token, and the browser storage listed in Section 3): item 3 — needed to provide the service you requested. Strictly necessary cookies do not require consent.

Language preference and saved stations on this device: item 3 — stored because you asked us to remember them.

5. Recipients and Cross-Border Transfer

Our servers: tanqo, including the analytics, runs on servers located in the European Union.

Cloudflare, Inc. (USA): Every request to tanqo passes through Cloudflare's network, which protects the site and connects it to our servers. Cloudflare therefore processes your IP address and request data on our behalf, runs the automated bot protection described in Section 3, and delivers the emails we send you. See Cloudflare's Privacy Policy.

Google: only if you choose to sign in with Google — see Section 2.

OpenStreetMap (OpenStreetMap Foundation, United Kingdom): The map displays tiles loaded from *.tile.openstreetmap.org. When the map loads, your browser sends your IP address to OpenStreetMap's servers as part of the standard HTTP request. We do not receive or store this data. See OpenStreetMap's Privacy Policy.

Cross-border transfer (Art. 29 of the Law): Our servers are in the European Union, which provides an adequate level of personal-data protection under Art. 29 of the Law. Cloudflare's network is global, so request data and emails may also be processed in other countries, including the USA. Cloudflare protects this data under its data processing terms, which include the European Commission's Standard Contractual Clauses; the transfer is necessary to deliver the service you requested. OpenStreetMap is in the United Kingdom, a party to the Council of Europe Convention 108 on data protection.

We do not share your data with anyone else, unless the law requires us to.

6. Data Retention

Analytics: Aggregated statistics are kept for 365 days. The daily visitor hash is discarded after 24 hours.

Location: Not stored on our servers. In your browser, until you close the tab.

Account data: Kept for as long as your account exists. When you delete your account, your email address, sign-in name and password hash are erased immediately, along with every active session, every Google sign-in link and every registered passkey. We keep a residual record with no contact details — identified only by a randomly generated two-word pseudonym (for example, "wise-otter") — so that any contributions you make to the shared station data remain attributable to a stable pseudonym rather than being silently rewritten. This record cannot be linked back to you. The deleted email address becomes immediately available to register a new, unrelated account.

Session cookie: Up to 30 days from its last use. It is deleted immediately when you sign out or delete your account. Changing your password replaces it with a new one on the device you changed it from, and ends every session on your other devices at the same time — the cookie stored in each of those browsers cannot be erased remotely, but the server stops honouring it immediately, so it can no longer keep you signed in.

Cookie notice record: Kept for 5 years from the date of your choice, as evidence that you were informed, and then deleted. It contains no name, email address or IP address.

Hashed IP addresses (security): Held in server memory only for the 15-minute rate-limit window, then discarded.

Other cookies and browser storage: For the periods listed in Section 3.

7. Your Rights

Under Art. 8 of the Law, you have the right to:

Deleting your account. If you have an account, you can erase it yourself at any time: open Account settings, choose Delete account, and confirm. The deletion is immediate and irreversible, and it takes effect without us needing to act. As described in Section 6, this erases your email address, sign-in name, password and sessions; only an anonymised, non-identifiable record is retained.

If you cannot sign in — for example, you have lost access to your mailbox — you can still ask us to delete your account by writing to [email protected] from the address the account is registered to, or otherwise providing enough information for us to identify the account. We will action the request without undue delay and within one month.

To exercise any of the other rights above, contact us at [email protected].

8. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top of the page will reflect any changes. If we ever add cookies that are not strictly necessary, we will ask for your consent before setting them.

9. Contact

Oleksii Kuznietsov — [email protected]

Data controller: Oleksii Kuznietsov, [email protected]