Legal / Privacy Policy (Europe)

Privacy Policy

European edition

Version 1.0 Effective: 18 August 2026

About This Policy

This Privacy Policy explains how OnFire ("OnFire", "we", "us", "our") collects, uses, shares, and protects your personal data when you use the OnFire App and related services, including messaging, ride-hailing ("OnFire Rides"), delivery, e-vehicle rental, and business services (collectively, the "Services").

The company that operates OnFire and is the data controller responsible for your personal data, together with its registered office and the supervisory authority that oversees it, is identified in Section 15, Who We Are and How to Contact Us.

We are committed to protecting your privacy and processing your data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Irish Data Protection Act 2018, and all other applicable data protection legislation.

By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with how we process your personal data, please do not use our Services.

1. Data We Collect

We collect the following categories of personal data depending on how you interact with our Services:

1.1. Account Data

Information you provide when creating and maintaining your OnFire account:

  • Full name
  • Email address
  • Mobile phone number
  • Profile photo (optional)
  • Date of birth (where required for age verification)
  • Username or display name

1.2. Payment Data

Information related to transactions made through the Services:

  • Payment card details (collected and processed by our third-party payment processor; OnFire does not store full card numbers)
  • Billing address
  • Transaction history
  • Bank account details (for drivers, couriers, and merchants receiving payouts)

1.3. Location Data

Information about your geographic position:

  • Real-time GPS location (when using ride-hailing, delivery, or e-vehicle services)
  • Trip and delivery route data
  • Pick-up and drop-off locations
  • Delivery addresses
  • Approximate location derived from IP address

1.4. Communication Data

Information related to your communications through the Services:

  • Message metadata (timestamps, sender, recipient, message type)
  • Call metadata (duration, participants, timestamps)
  • Content of messages that are not end-to-end encrypted
  • Note: OnFire does not access the content of end-to-end encrypted messages
  • Support inquiries and correspondence with OnFire

1.5. Usage Data

Information about how you interact with our Services:

  • Features accessed and frequency of use
  • App settings and preferences
  • Search queries within the app
  • In-app actions and interactions
  • Referral and promotional code usage
  • Ratings and reviews provided

1.6. Device Data

Technical information about the device you use:

  • Device type, model, and manufacturer
  • Operating system and version
  • Unique device identifiers (e.g., advertising ID, device ID)
  • IP address
  • Mobile network information
  • App version
  • Language and timezone settings
  • Crash logs and diagnostic data

1.7. Driver and Courier Data

Additional data collected from individuals who provide transportation or delivery services through OnFire:

  • Driving licence details and validity
  • Vehicle registration and insurance information
  • Background check results and criminal record checks (where legally required)
  • Earnings and tax-related information
  • Performance ratings and feedback
  • Working hours and availability

1.8. Merchant Data

Additional data collected from businesses that offer goods or services through OnFire:

  • Business name and trading name
  • Business registration details
  • Business address and operating hours
  • Food safety certifications and hygiene ratings (where applicable)
  • Menu and product information
  • Banking and payout details

1.9. Data from Third Parties

We may receive personal data from third parties, including:

  • Identity verification providers
  • Background check service providers
  • Payment processors
  • Social media platforms (if you choose to link your account)
  • Publicly available sources (for fraud prevention)

3. How We Use Your Data

We use your personal data for the following purposes:

3.1. Service Provision

  • Enabling you to create and manage your account
  • Matching passengers with drivers and customers with couriers
  • Processing ride bookings, deliveries, and e-vehicle rentals
  • Calculating and processing fares, fees, and payments
  • Providing in-app messaging and communication features
  • Enabling ratings and reviews

3.2. Safety and Security

  • Verifying the identity of users, drivers, couriers, and merchants
  • Conducting background checks on drivers and couriers
  • Detecting and preventing fraud, abuse, and unauthorized access
  • Monitoring compliance with our Acceptable Use Policy
  • Investigating safety incidents and user reports
  • Sharing trip information with emergency contacts (when enabled by the user)

3.3. Improvement and Development

  • Analysing usage patterns to improve the Services
  • Developing new features and functionality
  • Conducting research and surveys (with appropriate safeguards)
  • Training and improving algorithms (using anonymised or aggregated data)
  • Testing and troubleshooting

3.4. Marketing and Communications

  • Sending service-related notifications (e.g., ride updates, delivery status)
  • Sending promotional offers and marketing communications (with your consent)
  • Showing you content and recommendations (note: no feed, search result or listing on OnFire is personalised to you or based on profiling of you)
  • Administering promotional campaigns, referral programmes, and loyalty schemes

3.5. Legal and Regulatory Compliance

  • Complying with tax, accounting, and regulatory obligations
  • Responding to legal requests and court orders
  • Establishing, exercising, or defending legal claims
  • Reporting to regulatory authorities as required by law

3.6. Advertising

We display ads. Ads are not targeted: the ad you see is selected at random from those currently running, and no interest, age, location or profiling data is used to choose it. Every ad is labelled “Sponsored” and shows who paid for it. We provide analytics to advertisers in aggregated form only. We do not sell your personal information to advertisers.

4. Data Sharing

We may share your personal data with the following categories of recipients:

4.1. Other Users of the Services

  • Drivers and couriers receive your name, pick-up/drop-off location, and contact information necessary to fulfil a ride or delivery. They do not receive your full profile or payment details.
  • Merchants receive order information, delivery address, and your name to fulfil orders.
  • Passengers receive the driver's name, vehicle details, photo, and rating.

4.2. Service Providers

We engage third-party service providers who process data on our behalf, including:

  • Payment processors (e.g., for card processing and payouts)
  • Cloud hosting and infrastructure providers
  • Customer support platforms
  • Identity verification and background check providers
  • Analytics and crash-reporting services
  • Push notification services
  • Email and SMS communication providers
  • Mapping and geolocation providers

All service providers are bound by data processing agreements in accordance with GDPR Article 28.

4.3. Law Enforcement and Regulatory Authorities

We may disclose personal data to law enforcement, regulatory authorities, or other governmental bodies when:

  • Required by applicable law, regulation, or court order
  • Necessary to protect the safety of any person
  • Needed to prevent, detect, or investigate criminal activity or fraud
  • Required to comply with a valid legal process

4.4. OnFire Group Companies

We may share personal data with our affiliated companies and subsidiaries for the purposes described in this Privacy Policy, subject to appropriate safeguards.

4.5. Business Transfers

In the event of a merger, acquisition, reorganisation, or sale of assets, your personal data may be transferred to the relevant third party, subject to this Privacy Policy.

4.6. No Sale of Personal Data

OnFire does not sell your personal data to third parties. We do not share personal data with third parties for their own direct marketing purposes without your explicit consent.

5. International Data Transfers

5.1. EU/EEA Storage

OnFire stores your personal data on servers located within the European Union and European Economic Area ("EU/EEA") wherever practicable.

5.2. Transfers Outside the EU/EEA

Where we transfer personal data outside the EU/EEA, we ensure that appropriate safeguards are in place, including:

  • Adequacy decisions: Transfers to countries that the European Commission has determined provide an adequate level of data protection.
  • Standard Contractual Clauses (SCCs): Transfers made subject to the European Commission's Standard Contractual Clauses.
  • Additional safeguards: Where required, we implement supplementary measures (such as encryption and access controls) to ensure the protection of your data.

5.3. Information on Safeguards

You may obtain further information about the safeguards applied to international transfers by contacting us at [email protected].

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:

Data CategoryRetention Period
Account dataDuration of account plus 3 years after deletion
Trip and delivery data3 years from the date of the trip or delivery
Payment and transaction records7 years (to comply with tax and accounting obligations)
Messages (non-encrypted)As per your account settings; deleted upon account deletion
Driver and courier recordsDuration of engagement plus 5 years
Merchant recordsDuration of engagement plus 5 years
Location data (real-time)Not retained after trip/delivery completion; route data retained for 3 years
Support correspondence3 years from resolution
Marketing consent recordsDuration of consent plus 1 year

After the applicable retention period, personal data is securely deleted or anonymised so that it can no longer be associated with you.

7. Your Rights Under GDPR

Under the GDPR, you have the following rights in relation to your personal data:

7.1. Right of Access (Article 15)

You have the right to obtain confirmation of whether we process your personal data and, if so, to request a copy of that data together with supplementary information about how it is processed.

7.2. Right to Rectification (Article 16)

You have the right to have inaccurate personal data corrected and incomplete data completed.

7.3. Right to Erasure (Article 17)

You have the right to request deletion of your personal data where:

  • The data is no longer necessary for the purpose for which it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

This right is subject to exceptions, including where retention is required for legal compliance or the establishment, exercise, or defence of legal claims.

7.4. Right to Restriction of Processing (Article 18)

You have the right to request that we restrict processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.

7.5. Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller, where processing is based on consent or contract and is carried out by automated means.

7.6. Right to Object (Article 21)

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.

7.7. Right to Withdraw Consent

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

7.8. Rights Relating to Automated Decision-Making (Article 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, unless the decision is necessary for a contract, authorised by law, or based on your explicit consent.

7.9. Exercising Your Rights

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within one month. In complex cases, we may extend this period by a further two months, and we will inform you of any such extension.

7.10. Right to Lodge a Complaint

If you are not satisfied with how we handle your personal data or your rights request, you have the right to lodge a complaint with the Irish Data Protection Commission:

Data Protection Commission 21 Fitzwilliam Square South Dublin 2, D02 RD28 Ireland Website: https://www.dataprotection.ie Email: [email protected] Phone: +353 (0)1 765 0100 / 1800 437 737

8. Cookies and Similar Technologies

Our website and app use cookies and similar technologies. For detailed information about the cookies we use, their purposes, and how to manage them, please refer to our Cookie Policy available at https://onfire.so/legal/cookie-policy.

9. Children's Privacy

Our Services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that data as soon as practicable.

If you believe that a child under 18 has provided us with personal data, please contact us at [email protected].

10. Child Safety Scanning & CSAM Protection

OnFire is committed to preventing child sexual exploitation and protecting minors from grooming and predatory behavior. We employ multiple layers of safety technology, including on-device artificial intelligence and server-side systems, to detect and respond to potential threats.

10.1 On-Device Safety Scanning

OnFire uses on-device AI classifiers to analyze conversation patterns for indicators of grooming behavior. This scanning occurs locally on your device, meaning conversation content is processed without being sent to our servers for this purpose. The AI model evaluates anonymized conversation metadata and patterns against known grooming indicators, including age probing, isolation tactics, secrecy requests, boundary testing, sexual escalation, and other recognized risk categories.

On-device scanning produces a risk assessment score. If the risk score falls below a safety threshold, no data leaves your device. Only when risk indicators exceed defined thresholds may limited safety event data (risk score, risk category, and conversation identifier — not the conversation content itself) be transmitted to our servers for review.

10.2 Server-Side Safety Systems

When on-device scanning identifies elevated risk, our server-side safety systems may perform additional analysis, including cloud-based AI confirmation of risk assessments. The capability to match uploaded images and video against known CSAM hash databases is built into OnFire but is not currently switched on, so uploads are not presently hash-matched. We describe it here because it exists and because we intend to enable it, not because it is running today. All safety processing is strictly limited to child safety purposes.

10.3 Safety Event Data

When safety systems detect potential risks, we may collect and process the following data:

  • Risk assessment scores and categories from on-device and cloud classifiers
  • Conversation identifiers (not message content) associated with safety events
  • Timestamps and metadata of safety events
  • Actions taken (e.g., conversation restrictions, review requests)
  • Evidence preserved for confirmed CSAM detections as required by law

Safety event data is retained for as long as necessary to fulfill legal obligations, complete investigations, and comply with reporting requirements. Evidence related to confirmed CSAM detections is retained in accordance with 18 U.S.C. § 2258A.

10.4 NCMEC Reporting

As a U.S. electronic service provider, OnFire is legally required under 18 U.S.C. § 2258A to report apparent child sexual abuse material (CSAM) to the National Center for Missing & Exploited Children (NCMEC) via the CyberTipline. When our systems detect confirmed or highly likely CSAM, we will:

  • Preserve evidence as required by law
  • Submit a CyberTipline report to NCMEC as soon as reasonably possible, as required by 18 U.S.C. § 2258A
  • Restrict the associated accounts and conversations
  • Cooperate with NCMEC, law enforcement, and other authorities as required

We are prohibited by law from notifying users when a CyberTipline report has been filed regarding their account.

10.5 Escalation and Conversation Restrictions

Our safety systems employ a tiered escalation model based on risk severity:

  • Low risk: Events are logged locally for pattern monitoring. No user-facing action is taken.
  • Elevated risk: Safety events are reported to our review team. Conversations may be placed under enhanced monitoring.
  • High risk: Both participants may be asked to complete age verification. The conversation may be temporarily paused pending verification.
  • Critical risk: The conversation is immediately locked for both participants. Our review team is notified with priority, and mandatory reporting obligations may be triggered.

Conversation restrictions are applied bilaterally to both participants in a flagged conversation. Users may request a review of safety restrictions through our support channels.

10.6 Apple Sensitive Content Analysis

OnFire supports Apple's Sensitive Content Analysis framework on supported Apple devices (iOS 17+), which detects potentially explicit images and video entirely on your own device using Apple's built-in technology. This integration is built but is not currently enabled, so it is not analysing content today. Where it is enabled, OnFire does not receive or process the content of images analysed by the framework; sensitive content is blurred and you are warned before choosing whether to view it.

Your Privacy: On-device safety scanning is designed to protect your privacy. Conversation content is analyzed locally and is not transmitted to our servers unless critical safety thresholds are exceeded. We do not use safety scanning data for advertising, profiling, or any purpose other than child protection and legal compliance.

11. Special Categories of Data

We may process certain sensitive information only with your explicit consent or as permitted by law, including biometric data (face recognition for verification), health information, religious or political views, and sexual orientation (only if you choose to include these in your profile).

You control whether to share sensitive information. Such data is processed only for the specific purposes you authorize.

12. Third-Party Services

OnFire may integrate with third-party services including payment processors, maps and location services, analytics providers, and communication APIs.

Our Service may contain links to external websites. We are not responsible for the privacy practices of third parties. We encourage you to review their privacy policies.

Note: If you interact with bots or third-party integrations, they may receive information you share with them. Their data practices are governed by their own policies. Use caution when sharing sensitive information.

13. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include:

  • Encryption of data in transit (TLS) and at rest
  • Access controls and authentication mechanisms
  • Regular security audits and vulnerability assessments
  • Employee training on data protection and security
  • Incident response and breach notification procedures
  • Pseudonymisation and anonymisation where appropriate

While we take all reasonable precautions, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of your data.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or Services.

Where changes are material, we will notify you by:

  • Sending a notification to the email address associated with your account
  • Displaying a prominent notice within the OnFire App
  • Posting the updated Privacy Policy on our website

Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you should stop using the Services and contact us to delete your account.

15. Who We Are and How to Contact Us

OnFire is operated by OnFire Messenger Ltd., registered in Ireland under company number 796932, which is the data controller responsible for your personal data. If you have any questions about this Privacy Policy, or if you wish to exercise your data protection rights, please contact us:

OnFire Messenger Ltd. Registered Office: 77 Camden Street Lower, Dublin, D02 XE80, Ireland Email: [email protected] Website: https://onfire.so

Data Protection Officer (if applicable): Email: [email protected]

Supervisory Authority: Data Protection Commission 21 Fitzwilliam Square South Dublin 2, D02 RD28, Ireland https://www.dataprotection.ie

This Privacy Policy was last updated on 14 April 2026.

Version 1.0 — effective 18 August 2026. Last updated 18 August 2026.