Privacy Policy
2. Two roles: the company and us
3. What we store
4. What we do not store
5. Where the data is and who else sees it
6. How long we keep it
7. Legal bases
8. Your rights
9. Security
10. Cookies and browser storage
11. Children
12. Changes
1. Who we are
This policy applies to the website odoma.app and the web dashboard dashboard.odoma.app (the “dashboard”). Their operator is ODOMA SERVICES OSAÜHING, registry code 17589729, VAT number EE103025241, Tallinn, Harju maakond, Estonia (“we”).
The mobile apps Odoma Tracker and Odoma Checkit are published by the non-profit association Odoma Digipädevuse Selts (reg. no. 80659718). Everything the app does on the phone is described in the apps' privacy policy. This policy begins where data from the phone, by the person's decision, reaches their employer's dashboard.
For questions about data write to privacy@odoma.ee. We respond within 30 days.
2. Two roles: the company and us
The company is the controller. The company that opens an account in the dashboard decides which employees are connected, which trips, receipts, customers and invoices are kept in it, and which of its people get access. Within the meaning of the GDPR the company is the controller of this data and we are the processor acting on its instructions (Article 28). Using the dashboard for its intended purpose counts as the instruction; the processing terms are part of the terms of use. An employee whose data the company keeps turns first to the company for access, rectification or erasure; we help the company fulfil such a request.
We are the controller for the data needed for the account and the agreement to exist: the email address and name of the account owner, company details, plan invoices and their payment, support requests, technical logs of the service.
3. What we store
3.1 Account and company (we are the controller)
- Sign-in: email address, name from the profile, the identifier of sign-in via Google or Apple, or an account with a password. The password is stored by Google's Firebase Authentication; it never reaches our servers.
- Company: name, registry code, VAT number, address, IBAN, phone and email addresses for invoices; confirmation of email addresses (hash of the address, date).
- Plan and payment: the chosen plan, plan invoices with a permanent reference number, payment dates. You pay for the subscription by bank transfer; we have no card data of yours.
- Support: the text of requests and correspondence, who wrote and when.
- Usage and technical data: usage counters (people, devices, documents), server request logs, partial screen load events, an audit log of operator actions on the account.
3.2 Company data in the dashboard (the company is the controller, we are the processor)
- People: the device pseudonym (a random identifier the phone created itself), the label given by the company, where needed the first and last name, IBAN for paying compensation, hourly rate, roles and permissions.
- Work trips: date, start and end time, start and end addresses, distance, odometer readings, purpose of the trip, site, compensation amount and a simplified route line (no more than a few dozen points) from which the dashboard determines the site and the time on it. Trips come only from a phone the person has connected to the company themselves with an invitation code, and only those marked as work trips.
- Receipts: the photo of the receipt and the recognised fields (vendor, date, amount, VAT, payment method, last four digits of the card). The full card number is never stored.
- Sites and customers: names, addresses, contacts, company details.
- Invoices, quotes, work reports, payments: the contents of documents, the PDF “as sent”, e-invoices, to whom and when they were sent.
- Bank: statements the company uploads itself (CAMT, CSV), with the names and IBANs of counterparties from those statements.
- Incoming email: emails and attachments sent to the company's unique address of the form docs+code@odoma.app, and the invoices recognised from them.
- Online payment of invoices: if the company connects Montonio, we store its Montonio access keys and records of received payments (amount, order number, date). The payer's data is processed by Montonio.
3.3 Phone diagnostic logs
The phone sends us diagnostic logs only in developer mode, which the person enables themselves in the app settings. Such logs may contain coordinates and details of the tracker's operation and are needed to investigate errors. In normal operation they are not sent to the server.
4. What we do not store
- Personal trips. A trip marked as personal is not transferred to the dashboard. If a work trip is changed to personal, the server copy is deleted.
- Passwords and full card numbers. See above.
- Data for advertising. The website and the dashboard have no advertising networks, third-party visitor counters or trackers. We do not sell data and do not pass it to brokers.
- Raw GPS tracks from the phone. Only the simplified line of a work trip described in 3.2 reaches the dashboard, not a stream of coordinates.
5. Where the data is and who else sees it
| Who | Why | Where |
|---|---|---|
| Google Cloud / Firebase | database, files (receipt photos, PDFs, logs), server, account sign-in | database — region europe-west2 (London, United Kingdom; transfer on the basis of the European Commission's adequacy decision, valid until 27.12.2031); files and server — europe-west3 (Frankfurt, EU) |
| Brevo (Sendinblue) | sending email: invoices to the company's customers, plan emails, address confirmations; receiving email to odoma.app addresses | EU |
| Google Cloud Translation | translating support requests into Russian for the operator | EU / under Google Cloud rules |
| Telegram | a copy of support requests goes to the operator in Telegram so that we can reply quickly | Telegram servers |
| Apple, Google | account sign-in via the “Sign in with…” button | under the sign-in provider's rules |
| Montonio | online payment of invoices by the company's customers — only if the company has connected it | EU |
| Estonian Business Register | suggesting the company name and code from open data | open data, not personal |
Database backups are made automatically: daily backups are kept for 7 days, weekly for 98 days; once a week a copy is exported to a separate storage in the EU with a 30-day deletion lock, and old copies are deleted no later than 12 months.
6. How long we keep it
- While the account exists — all company data. After the end of the trial or paid period the dashboard switches to view-only mode, the data is not deleted; the phones keep recording.
- At least 90 days after the end of the paid period we keep the data unchanged. After that we may archive or delete it, having given at least 30 days' notice by email to the account address.
- Deleting the company is done by the account owner in the settings. For 30 days the data is frozen and the deletion can be cancelled, then everything is deleted irreversibly; the data disappears from backups as they expire.
- Plan invoices we issued to the company — 7 years under the Estonian Accounting Act.
- Email suppression list (addresses that returned a delivery failure or a complaint) — as a hash, until the address is confirmed again.
- Service records: keys for repeated requests — 30 days, interface event counters — 90 days, links in emails — from 48 hours to 7 days.
7. Legal bases
- Contract (Art. 6(1)(b) GDPR) — account, plan, invoices, support.
- The company's instructions (Art. 28 GDPR) — data of the company's employees, trips, receipts, customers and documents.
- Legal obligation (Art. 6(1)(c)) — keeping our invoices and accounting records.
- Legitimate interest (Art. 6(1)(f)) — security of the service, protection against abuse, technical logs, a copy of support requests to the operator.
8. Your rights
The account owner can at any time in the dashboard: export all company data as a single archive (Settings → Data → Export: records, receipt photos, invoice PDFs), correct company details and records, delete the company with a 30-day cancellation window. An employee of a company turns to their company; if the company does not respond, write to us and we will help.
Access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20), objection (21) — by email to privacy@odoma.ee. A complaint can be lodged with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee).
9. Security
- Connections only over HTTPS; sign-in via Firebase Authentication with email address confirmation; roles and permissions within the company.
- Sending invoices and emails is closed until the sender's address is confirmed; limits on emails and requests.
- Operator actions on accounts are recorded in an audit log; the database can be restored to any point in time within 7 days; the backups described above.
- Company employees appear in the dashboard under device pseudonyms; names are added only by the company itself.
10. Cookies and browser storage
The website odoma.app sets no cookies and uses no counters. The dashboard stores sign-in data (Firebase Authentication) and your screen settings in the browser's localStorage; there are no third-party cookies.
11. Children
The dashboard is intended for companies and their employees. We do not open accounts for persons under 16.
12. Changes
We announce material changes by email to the account address and update the date at the top of the page.
This policy is drawn up in Estonian, Russian and English; in the event of a discrepancy between the versions, the Estonian version prevails.
Change log
- 2026-09-04 — first version for ODOMA SERVICES OSAÜHING (dashboard and website odoma.app).
- 2026-09-14 — English translation of the Russian version of 2026-09-04; added to section 12: in the event of a discrepancy, the Estonian version prevails.