Last updated: 2026-09-08
1. Who we are
The data controller responsible for your personal data is:
BOTOP LTD EOOD (trading as "Ordo")
Company No. (EIK): 208850878
D-U-N-S No.: 369865396
Registered in Bulgaria (European Union)
Registered office: 18 Shipchenski Prohod Blvd., Block A, Floor 3, Sofia 1113, Bulgaria
Privacy contact: [email protected]
2. What we collect
When you join the waitlist / founding beta, you give us:
Your email address (required) — so we can contact you about the beta and launch.
Your car(s) — make, model, and year, for each car you choose to add.
Your consent to receive beta and launch emails.
Beta questionnaire answers, if you choose to complete the screening questions.
Collected automatically when you use the website:
Attribution data — how you reached us (e.g. a referral link or campaign source) so we can credit referrals and understand which channels work.
Basic technical data — IP address, browser type, and request logs, kept for security and to keep the site running.
From your car and questionnaire answers we may derive a few things — for example whether your car is well-covered in our library, and whether you're a good fit for a particular beta cohort. These are used only to select and prioritise beta testers.
When you use the Ordo app (at launch), we collect:
Account identifiers: your email address and a hashed password.
Vehicle specifics: VIN, make, model, year, and current mileage for the cars you add.
User-generated logs: maintenance records, fuel logs, and custom reminders.
Your questions to the in-app assistant. Ordo is offline-first — most answers are produced on your device and never leave it. When a question does need our servers or a third-party AI model, we strip out obvious personal details first; and for questions answered by our AI assistant we keep an anonymised log of the question and answer, with no account or user identifier and with personal details automatically redacted, used only to measure and improve answer quality.
Photos: a photo of a car you add to your garage, and an odometer photo if you verify a service record. Receipt images and your profile picture (avatar) are handled entirely on your own device and are never uploaded to us. Section 3 sets out each of these in full — what happens to it, where it is stored, how long we keep it, who it is shared with, and how to delete it.
Anonymous product-analytics and crash events (for example, that an answer was served from your device's offline library, or that a screen was opened) through Google Firebase, plus anonymised crash reports via Sentry, to see which features work and to fix crashes; these events carry no account identifier and no raw question text.
Device and other identifiers: a Firebase installation identifier and a push-notification token for your device, used to run analytics and to deliver notifications you've asked for. These identify your device, not you by name, but they are technical identifiers we hold.
Subscriptions and one-time purchases are handled by the app stores and our billing provider — we never see your card number, but we do receive your purchase history (what you bought, when, and its current status) so we can grant and manage what you've paid for.
3. Photos and images
Ordo asks for camera and photo-library access, so this section sets out exactly what happens to each kind of photo. There are four, and two of them never leave your phone at all — so rather than lump them together, each is listed separately. We open your camera or photo library only at the moment you tap to add a photo: we never scan your library in the background, and we take nothing you have not picked.
Receipt images — THESE STAY ON YOUR DEVICE. When you scan a receipt, your phone reads the text out of the image and sends us only that text, with obvious personal details stripped out, so we can pull the amount, date and category into your record. The image itself is never uploaded and we never hold a copy of it.
Your profile picture (avatar) — THIS STAYS ON YOUR DEVICE. It is saved in the app's own storage on your phone to personalise your account, and is never uploaded to us.
Car photos — THESE ARE UPLOADED. A photo you add to a car in your garage is stored on our EU-hosted infrastructure, encrypted in transit, so the car looks like your car every time you open it. It is used for nothing else.
Odometer photos — THESE ARE UPLOADED. If you verify a service record, the odometer photo you take is stored on our EU-hosted infrastructure, encrypted in transit, as the evidence for that verification. It is used for nothing else.
Who we share them with: nobody. Your photos are not sold, not shared for advertising, and not shared with any third party beyond the infrastructure processors already named in section 5, which host them on our behalf and act only on our instructions. We do not use your photos to train models or to build a profile of you.
How long we keep them, and how to delete them: we keep the two uploaded kinds — car and odometer photos — for as long as your account is active. Deleting your account from the Settings menu deletes them, including the stored image files. To have one particular photo deleted without closing your account, email [email protected] and we will remove it — see section 8 for how we handle erasure requests. The two kinds that stay on your device go when you delete them in the app or uninstall Ordo; we cannot delete those for you, because we never had them.
4. Why we use it, and our legal basis (GDPR)
Beta and launch emails — to tell you when you're in and when we launch — your consent (Art. 6(1)(a)).
Your car(s) and questionnaire — to check coverage, select and prioritise beta testers — consent / our legitimate interest in running a fair beta (Art. 6(1)(f)).
Referral and attribution — to credit referrals and understand our channels — legitimate interest (Art. 6(1)(f)).
Security and server logs — to keep the service safe and available — legitimate interest (Art. 6(1)(f)).
Providing the app — to deliver the vehicle tracking and AI services you signed up for — performance of a contract (Art. 6(1)(b)).
Improving our vehicle database and AI accuracy — legitimate interest (Art. 6(1)(f)).
You can withdraw consent at any time — every email has an unsubscribe link, or just email us. Withdrawing consent doesn't affect processing we already did.
5. Who we share it with
We do not sell your personal data, and we do not share it for anyone else's advertising. We use a small number of trusted GDPR-compliant service providers ("processors") who act only on our instructions:
Email — Zoho (EU data centre), to send and manage our emails.
Infrastructure and delivery — Cloudflare (CDN/security) and our own EU-hosted servers, to run the website and store data.
App stores and billing (at launch) — Apple, Google, and our subscription provider, to process purchases.
In-app AI (at launch, only when a question can't be answered on your device) — our AI model provider, with obvious personal details removed first.
Product analytics and crash reporting — Google Firebase (anonymous in-app usage measurement) and Sentry (anonymised error monitoring); no account identifier, no question text.
We may also disclose data if required by law, or to protect our rights and users' safety.
6. Where your data is stored and international transfers
Your data is stored in the European Union. Some providers may process limited data outside the EU (for example, security, analytics, or AI services). Where that happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
7. How long we keep it
We keep waitlist and beta data until the beta ends and for a reasonable period afterwards, or until you ask us to delete it — whichever comes first. For app accounts, we retain your data for 3 years after your last login, or until you request deletion. If you unsubscribe or ask for erasure, we remove your data promptly, except anything we're legally required to keep. Security logs are kept only as long as needed for that purpose. Anonymised AI question-and-answer logs carry no identifier that ties them to you and are kept only as long as they're useful for improving answer quality.
8. Your rights
Under the GDPR, you have the right to:
Access the data we hold about you;
Correct data that's wrong or incomplete;
Delete your data ("right to be forgotten");
Restrict or object to how we use it;
Port your data to another service;
Withdraw consent at any time.
To exercise any of these, email [email protected], or delete your account and all associated data via the Settings menu in the app. We'll respond within one month. You also have the right to complain to your local data protection authority — in Bulgaria, the Commission for Personal Data Protection (CPDP, www.cpdp.bg).
9. Cookies and tracking
This website does not use advertising or third-party tracking cookies. Any referral or campaign information is passed in the page link itself, not stored as a tracking cookie. If we add analytics later, we'll update this policy and ask for consent where required.
10. Security
We protect your data with encryption in transit, access controls, and EU-hosted infrastructure. No system is perfectly secure, but we take reasonable steps to keep your information safe and will notify you and the authorities of a breach where the law requires.
11. Children
Ordo is not intended for children under 13. We don't knowingly collect data from them; if you believe a child has given us data, contact us and we'll delete it.
12. Changes to this policy
We'll update this page if our practices change and revise the "Last updated" date above. For material changes affecting the beta list, we'll email you.
13. Contact
Questions or requests about your privacy? Email [email protected] — we read every one.
14. EU Digital Services Act (DSA) — Trader Information
Botop Ltd. (EOOD)
EIK: 208850878
18 Shipchenski Prohod Blvd., Block A, Floor 3, Sofia 1113, Bulgaria
Email: [email protected]