PRIVACY POLICY

Last updated: December 30, 2025

This Privacy Policy explains how Cafu Oass Services OÜ doing business as Belgrade E-pass ("Belgrade E-pass", "we", "us", "our") collects, uses, stores, and shares personal information when you use our services (the "Services"), including when you:

  • Visit our website at privacy policy page 
  • Interact with us in other ways related to the Services, such as customer support, sales, marketing, or events

Questions or concerns? Reviewing this Policy helps you understand your privacy rights and options. If you disagree with our practices, please do not use our Services. For questions, contact us at belgrade@belgradeepass.com .

SUMMARY OF KEY POINTS

This overview highlights key items from this Policy. You can read more about each topic by using the links in the Table of Contents.

  • What personal data do we handle? We may process personal information depending on how you use our Services, what you choose, and which features you use.
  • Do we process sensitive data? No. We do not intentionally collect or process sensitive personal information.
  • Do we obtain data from third parties? No. We do not receive personal information from third parties.
  • Why do we process your information? To provide and operate the Services, improve and administer them, communicate with you, prevent fraud, maintain security, and comply with legal obligations. We may also process data with your consent.
  • When do we share information? We may disclose information in limited scenarios and with certain service providers, as described below.
  • How do we protect information? We use organizational and technical safeguards, but no online method can be guaranteed 100% secure.
  • What rights do you have? Depending on where you live, data protection laws may grant you rights (access, deletion, correction, objection, etc.).
  • How do you use your rights? You can submit a data subject request or contact us using the details in this Policy.

Want the full details? Continue reading below.

TABLE OF CONTENTS

  1. WHAT INFORMATION DO WE COLLECT?
  2. HOW DO WE USE YOUR INFORMATION?
  3. WHAT LEGAL BASES DO WE RELY ON?
  4. WHEN AND WITH WHOM DO WE SHARE INFORMATION?
  5. DO WE USE COOKIES AND SIMILAR TECHNOLOGIES?
  6. HOW LONG DO WE KEEP YOUR INFORMATION?
  7. HOW DO WE SECURE YOUR INFORMATION?
  8. DO WE COLLECT INFORMATION FROM MINORS?
  9. WHAT ARE YOUR PRIVACY RIGHTS?
  10. DO-NOT-TRACK CONTROLS
  11. DO UNITED STATES RESIDENTS HAVE SPECIAL RIGHTS?
  12. DO OTHER REGIONS PROVIDE ADDITIONAL RIGHTS?
  13. DO WE UPDATE THIS POLICY?
  14. HOW CAN YOU CONTACT US?
  15. HOW CAN YOU REVIEW, UPDATE, OR DELETE YOUR DATA?

1. WHAT INFORMATION DO WE COLLECT?

Personal information you provide

In short: We collect personal information you choose to share with us.

We collect information you provide voluntarily when you request information about our Services, make a purchase, contact support, participate in promotions, or otherwise communicate with us.

Examples of information you may provide include:

  • Name
  • Email address
  • Phone number
  • Mailing address
  • Billing address

Sensitive information: We do not intentionally process sensitive personal information.

Payment information

If you make a purchase, we may collect data required to process your payment (for example, a payment card number and its associated security code). Payment data is stored and processed by our payment partners, such as Stripe. Please review your payment provider’s privacy policy for details.

You are responsible for ensuring the information you submit is accurate and up to date, and for letting us know when it changes.

Information collected automatically

In short: Certain technical details are captured automatically when you use our Services.

When you visit or use the Services, we may automatically collect device and usage information that does not directly identify you (such as your name) but can include:

  • IP address
  • Browser type and settings
  • Device characteristics
  • Operating system
  • Language preferences
  • Referring URLs
  • Country and approximate location (based on IP)
  • Pages viewed, actions taken, and time stamps
  • Diagnostic and performance data (including error reports)

We use this information to keep the Services running, maintain security, and perform analytics and reporting.

Log and usage data

Our servers may record service-related activity data such as the pages you view, searches you perform, features you use, and related time stamps.

Device data

We may collect information about the device you use (computer, phone, tablet), which can include IP address (or proxy server), device identifiers, and basic system configuration details.

Location data

We may infer approximate location based on IP address. Some devices may allow more precise location controls. You can disable location permissions in your device settings; however, certain features may not work properly if location is turned off.

We may also use cookies and similar technologies. See Section 5 for details and our Cookie Notice.

2. HOW DO WE USE YOUR INFORMATION?

In short: We use your information to operate, improve, protect, and support the Services, and to meet legal requirements.

Depending on how you interact with Belgrade E-pass, we may process information to:

  • Provide and deliver the Services you request
  • Respond to questions and provide customer support
  • Send service messages (order confirmations, policy updates, account notices)
  • Process purchases, payments, refunds, and exchanges
  • Enable optional user-to-user features (where offered)
  • Request feedback and improve the user experience
  • Send marketing messages (where permitted and based on your preferences)
  • Measure the effectiveness of marketing campaigns
  • Prevent fraud, enhance security, and protect vital interests where necessary

3. WHAT LEGAL BASES DO WE RELY ON?

In short: We process personal information only when we have a lawful basis under applicable data protection laws.

If you are located in the European Economic Area (EEA) or the United Kingdom, the GDPR/UK GDPR requires that we explain the legal grounds used for processing. Belgrade E-pass may rely on:

  • Consent: You can withdraw consent at any time.
  • Contract: Processing needed to provide the Services or to take steps at your request before entering a contract.
  • Legitimate interests: Processing that supports our business where your rights do not override those interests (e.g., improving Services, offering promotions, understanding usage).
  • Legal obligations: Processing needed to comply with laws and regulatory requirements.
  • Vital interests: Processing needed to protect someone’s safety in urgent situations.

If you are located in Canada, we may rely on express or implied consent depending on the situation, and you may withdraw consent. In certain cases, laws may permit processing without consent (e.g., fraud prevention, legal compliance, business transactions).

4. WHEN AND WITH WHOM DO WE SHARE INFORMATION?

In short: We may share information in limited circumstances and with selected partners.

We may disclose personal information in these scenarios:

  • Business transfers: In connection with mergers, financing, restructuring, or sale of assets.
  • Analytics: If we use analytics services (e.g., Google Analytics) to understand usage and improve the Services.
  • Affiliates: With affiliated companies under common control, subject to this Policy.
  • Service providers: With vendors who help us run the Services (payment processing, hosting, email delivery), under contract.

If you want to opt out of certain analytics tracking, you may use tools offered by the analytics provider or adjust your browser settings where available.

5. DO WE USE COOKIES AND SIMILAR TECHNOLOGIES?

In short: Yes, we may use cookies and related technologies to store and retrieve information.

We may use cookies, pixels, and similar tools to help operate the Services, remember preferences, measure performance, and support analytics. You can learn more, including how to manage choices, in our Cookie Notice .

6. HOW LONG DO WE KEEP YOUR INFORMATION?

In short: We keep personal information only as long as needed for the purposes described, unless law requires more.

We retain personal information for as long as necessary to deliver the Services and meet the purposes in this Policy, unless a longer period is required or permitted (for example, tax, accounting, or legal obligations). When we no longer have a business need, we delete, anonymize, or securely store the data until it can be deleted.

7. HOW DO WE SECURE YOUR INFORMATION?

In short: We use appropriate safeguards, but no system is perfectly secure.

We apply reasonable administrative, technical, and organizational measures designed to protect personal information. However, internet transmissions and storage systems cannot be guaranteed as completely secure. You use the Services at your own risk and should access them from a trusted environment.

8. DO WE COLLECT INFORMATION FROM MINORS?

In short: We do not knowingly collect data from, or market to, individuals under 18.

Belgrade E-pass does not intentionally gather personal information from children under 18. By using the Services, you confirm you are at least 18 (or you are a parent/guardian authorizing a dependent’s use). If we discover we collected data from a minor, we will take steps to delete it. If you believe a minor has provided data to us, contact belgrade@belgradeepass.com .

9. WHAT ARE YOUR PRIVACY RIGHTS?

In short: Depending on your location, you may have rights to access, correct, delete, or object to certain processing.

In some regions (including the EEA, UK, Switzerland, and Canada), you may have rights under applicable laws, such as:

  • Request access to your personal information
  • Request correction or deletion
  • Request restriction of processing
  • Request data portability (where applicable)
  • Object to processing (in certain circumstances)
  • Not be subject to certain automated decisions (where applicable)

To exercise these rights, contact us using the details in Section 14. We will respond in line with applicable laws.

Complaints: If you are in the EEA/UK and believe your data is processed unlawfully, you may contact your local data protection authority.

Withdrawing consent: If we rely on consent, you may withdraw it at any time. This does not affect processing that occurred before withdrawal.

Marketing choices: You can opt out of promotional emails using the unsubscribe link or by contacting us. We may still send essential service communications.

Cookies: Most browsers accept cookies by default. You can remove or block cookies through browser settings, which may affect site functionality.

10. DO-NOT-TRACK CONTROLS

Some browsers and mobile systems offer a Do-Not-Track (DNT) setting. There is no agreed standard for recognizing DNT signals at this time, so we do not currently respond to DNT signals. If a standard is adopted in the future, we will update this Policy.

11. DO UNITED STATES RESIDENTS HAVE SPECIAL RIGHTS?

In short: If you are a resident of certain US states, you may have additional privacy rights.

If US state privacy laws apply to you (for example, Utah), you may have specific rights regarding access, deletion, copies of your data, and opting out of certain uses (such as targeted advertising). To submit a request, contact us at belgrade@belgradeepass.com .

Categories of personal information

We may collect identifiers (e.g., name, email), and commercial information (e.g., transactions and payment details). We do not intentionally collect sensitive personal information.

We do not sell or share personal information for cross-context behavioral advertising as defined by applicable laws.

12. DO OTHER REGIONS PROVIDE ADDITIONAL RIGHTS?

In short: Yes. Your rights may vary depending on your country.

Australia and New Zealand

We process personal information in line with applicable privacy laws. You may request access to, or correction of, your personal information by contacting us.

Republic of South Africa

You may request access to or correction of your personal information. If you believe your rights have been infringed, you may contact the relevant supervisory authority in South Africa.

13. DO WE UPDATE THIS POLICY?

In short: Yes. We may revise this Policy to remain compliant and accurate.

We may amend this Policy periodically. The revised version will be indicated by an updated "Last updated" date and will take effect once posted. If changes are significant, we may notify you by posting a prominent notice or sending a message where appropriate.

14. HOW CAN YOU CONTACT US?

If you have questions about this Policy, contact us:

  • Email: belgrade@belgradeepass.com
  • Post: Cafu Pass Servises OÜ

    Sakala tn 7-2 Kesklinna linnaosa,
    Harju maakond
    Tallinn 10141
    Estonia

15. HOW CAN YOU REVIEW, UPDATE, OR DELETE YOUR DATA?

Depending on local laws, you may request access to the personal information we hold about you, ask us to correct it, or request deletion. To submit a request, contact us using the details in Section 14.