1. What We Collect
Categories of personal data processed by Kopa Balloon.
We collect only the data that is strictly necessary to operate your
booking, deliver the service and improve the platform:
- Identity: name, email, phone, nationality, photo (optional)
- Booking: tour, date, passengers, hotel, pickup location
- Payment: gateway transaction reference (we never store full card numbers)
- Location: precise GPS location (and approximate location derived from it) collected only while an active booking is in progress and you grant location permission
- Device: FCM push token, IP address, device model, app version
- Support: chat messages, ratings and complaint records
2. Location Data
How we access, use and control location information.
a) We may collect your device location to operate pickup and trip
tracking features. This includes precise location
(GPS/network-based coordinates) and the
approximate location derived from it.
b) Location is used only for service purposes such as assigning the
nearest driver, showing live driver/passenger position during pickup,
validating pickup completion, trip safety, and support troubleshooting.
We do not sell location data.
c) Collection timing: location is collected while you
are using the app for an active booking, and may continue for a limited
period in the background only where required to complete active pickup
and routing workflows.
d) Sharing: only the minimum location details needed to
deliver the service are visible to assigned operational parties
(for example, your assigned driver/company operations team) and to
technical providers acting on our behalf.
e) Controls: you can deny or revoke location access at
any time from your device settings. If location access is disabled,
some features (live pickup tracking, nearest-driver assignment, and
certain real-time updates) may not work correctly.
3. How We Use Your Data
Lawful purposes for processing.
a) Performing the contract: confirming your booking, dispatching a
driver, issuing the QR boarding pass, sending flight reminders and
delivering your certificate.
b) Legal obligations: passenger manifests required by civil-aviation
authorities, tax invoices and accounting records.
c) Legitimate interests: fraud prevention, platform analytics, service
improvement and security.
d) With your consent: marketing emails, push notifications and
loyalty offers. You may withdraw consent at any time from the app
settings or by emailing
[email protected].
4. Sharing & Driver Visibility
Who can see your information.
a) Operating companies, pilots, ground crew, drivers and guides
assigned to your flight see only the minimum data needed to deliver
the service: your name, pickup location, passenger count and a contact
channel through the app.
b) Phone-sharing toggle: Your real phone number is
only revealed to the assigned driver if you enable the
“Share my phone with the driver” option at checkout.
Otherwise the driver contacts you through a masked in-app channel.
c) We share data with payment processors (PayTabs, Paymob, MyFatoorah),
push-notification services (Firebase) and government authorities only
where required by law or to operate the service. We never sell your
personal data.
5. Retention & Security
How long we keep your data and how we protect it.
a) Booking and accounting records are retained for the period required
by tax and aviation regulations (typically up to 7 years). Marketing
consent records are kept until you withdraw your consent. Live
location data is deleted within 24 hours of trip completion.
b) We protect your data using TLS in transit, encryption at rest,
role-based access control and routine security audits. No system is
100% secure; you should keep your account password confidential and
notify us immediately of any suspected unauthorised access.
6. Your Rights
Control over your personal data.
Subject to applicable law (including the Egyptian Personal Data
Protection Law No. 151/2020 and the GDPR where it applies), you have
the right to:
- Access a copy of the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your account and associated data (right to be forgotten)
- Object to or restrict certain processing activities
- Port your data to another service in a structured format
- Withdraw a previously-given consent
Exercise any of these rights by emailing
[email protected]. We will
respond within 30 days.