Hopp til hovedinnholdSkip to main content

    Privacy Policy and Terms

    Last updated: 8 September 2026

    Note: this page is an English translation provided for information only. The legally binding original is the Norwegian version at www.asapp.tech/personvern. In case of any discrepancy between this translation and the Norwegian original, the Norwegian version prevails.

    Privacy Policy

    This is an English translation of our Privacy Policy, provided for information only. The Norwegian version at www.asapp.tech/personvern is the legally binding original and prevails in case of any discrepancy.

    1. Data controller

    The data controller for the personal data described in this policy is:

    Asapp! AS
    Org. no: 935 112 397
    Dybwads gate 3, 0367 Oslo
    Email: hello@asapp.tech

    2. Introduction

    Asapp! AS ("we", "us", "our") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use and protect your personal data when you use our services.

    We take privacy seriously. All personal data is processed in accordance with applicable law, including the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven).

    3. Legal basis for processing

    We process personal data based on the following legal bases (GDPR Article 6):

    • Contract (Art. 6(1)(b)) – Processing necessary to perform the delivery service you have ordered: contact details, addresses, payment data and communication about the delivery.
    • Legal obligation (Art. 6(1)(c)) – Retention of order and payment data for 5 years pursuant to the Norwegian Bookkeeping Act (bokføringsloven).
    • Legitimate interest (Art. 6(1)(f)) – Processing of the recipient's name, phone number and address (the recipient is not a party to the agreement with us, but the processing is necessary to carry out the delivery you have ordered), as well as improvement of our services, troubleshooting, security and aggregated analysis. You may object to this processing.
    • Consent (Art. 6(1)(a)) – Analytics cookies (Google Analytics) and marketing cookies (HubSpot, Google Ads). You can withdraw your consent at any time via the cookie settings.

    4. What information we collect

    We may collect the following types of personal data:

    • Contact information (name, email, phone number, address)
    • Business information for the sender and recipient (company name, organisation number)
    • Delivery information (addresses, delivery instructions)
    • Payment information (processed by our payment provider)
    • Usage information (log of use of our services)
    • GPS data for delivery and tracking
    • Locally stored information in your browser (see section 11 on cookies)

    5. How we use the information

    We use your personal data to:

    • Deliver and administer our services
    • Communicate with you about deliveries
    • Invoice and handle payments
    • Improve our services
    • Comply with legal obligations

    6. Sharing information with third parties

    To deliver our services, we share necessary personal data with the following third parties. We have entered into data processing agreements (DPAs) with all third parties that process personal data on our behalf, in accordance with GDPR Article 28.

    • Oslo Taxi AS – Our transport partner receives the pick-up and delivery address, the sender's phone number and any delivery instructions in order to carry out the delivery.
    • Stripe – Our payment provider processes payment information (card number, amount). All payments require BankID/3D Secure verification. Asapp does not store card details. See Stripe's privacy policy.
    • LinkMobility – The recipient's phone number is shared to send text message notifications about the delivery, including the tracking link.
    • Resend – Our email provider, which sends order confirmations and receipts to the sender's given email address.
    • HubSpot – CRM system that stores contact information (name, email, phone, company) for order handling and customer follow-up. This CRM use is based on the legal basis of performance of a contract (Art. 6(1)(b)). HubSpot is additionally activated for marketing and analytics on the website with your consent (see section 11).
    • Digtective – Our advertising agency, which receives anonymised conversion data from Google Ads to optimise marketing campaigns. No direct personal data is shared.
    • HappyPath – Address lookup for precise navigation to the delivery location. No personal data is shared, only address searches.
    • Google Ads – Conversion tracking via anonymised click IDs (gclid). Activated only with consent (see section 11).
    • Netlify – Our hosting provider, which distributes the website globally via its CDN network. Netlify processes access logs that may contain IP addresses and user-agent strings. Data is processed in the USA and the EU.

    We never share personal data with third parties for their own marketing purposes. Sharing only takes place when necessary to perform the service you have ordered, or when required by law.

    7. Transfer of data outside the EU/EEA

    The following third-party providers may process personal data outside the EU/EEA:

    ProviderData transferredCountryTransfer basis
    StripePayment dataUSAEU-US DPF
    HubSpotContact info (CRM + marketing)USAEU-US DPF
    Google AnalyticsAnonymised user dataUSAEU-US DPF
    Google AdsConversion data (gclid)USAEU-US DPF
    ResendEmail address (receipts)USASCCs
    NetlifyIP address, access logsUSA / EUEU-US DPF + SCCs

    For providers certified under the EU-US Data Privacy Framework (DPF), transfers take place under that framework. For other transfers outside the EU/EEA, the EU Standard Contractual Clauses (SCCs) are used as the transfer basis, in accordance with GDPR Chapter V.

    8. Retention period

    We retain personal data only for as long as necessary for the purpose it was collected for:

    • Order data – Retained for 5 years after delivery, in accordance with the Bookkeeping Act.
    • Payment information – Processed by Stripe and not retained by us.
    • Contact information for leads – Retained for up to 24 months after the last contact, unless you request deletion.
    • Marketing data (cookies) – Deleted in accordance with your cookie settings and the provider's policies (see the cookie table in section 11).
    • Locally stored sender information – Stored in your browser until you remove it manually or clear your browser data.

    9. Security

    We implement appropriate technical and organisational measures to protect your personal data:

    • All communication between your browser and our servers is encrypted using TLS/HTTPS
    • Access control with role-based security on all database tables
    • Rate limiting on all API endpoints to prevent misuse
    • Payment data is handled exclusively by Stripe (PCI DSS certified) – we never store card details
    • Personal data is masked in publicly available responses
    • Security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy) are configured on all pages

    10. Your rights

    Under GDPR and the Norwegian Personal Data Act, you have the right to:

    • Access your personal data
    • Correct inaccurate information
    • Delete your data
    • Restrict processing
    • Object to processing
    • Move your data (data portability)

    We respond to all privacy enquiries within one month, with the possibility of extension for complex cases, in accordance with GDPR Article 12(3). If you believe that we are not processing your personal data in accordance with the rules, you have the right to lodge a complaint with Datatilsynet (the Norwegian Data Protection Authority). You can contact Datatilsynet at www.datatilsynet.no.

    11. Cookies and local storage

    We use cookies to ensure the website works correctly, and – with your consent – for analytics and marketing. Tracking and marketing scripts are not loaded until you have given consent via our cookie banner. No third-party services are contacted before consent is given.

    Overview of cookies

    CategoryCookie / serviceProviderPurposeLifetimeThird country
    Necessaryasapp_cookie_consentAsapp! (first party)Stores your cookie choicesPermanent (localStorage)No – local storage only
    asapp_sender_infoAsapp! (first party)Remembers sender details for "Remember me" (name, phone, email, company)Permanent until you delete it (localStorage)No – local storage only
    Analytics_gaGoogle AnalyticsDistinguishes unique users2 yearsUSA (DPF-certified)
    _ga_FRN3H4X4P0Google AnalyticsMaintains session state2 yearsUSA (DPF-certified)
    _gidGoogle AnalyticsDistinguishes unique users (24h)24 hoursUSA (DPF-certified)
    Marketing__hssc, __hssrc, __hstcHubSpotSession tracking and visit analysis30 min – 13 monthsUSA (DPF-certified)
    hubspotutkHubSpotIdentifies repeat visitors13 monthsUSA (DPF-certified)
    _gcl_auGoogle AdsConversion tracking (gclid)90 daysUSA (DPF-certified)

    Google Fonts: we do not use Google Fonts. The website uses self-hosted and system fonts, so no data is transferred to Google for font loading.

    You can change your cookie settings at any time by clicking "Change cookies" at the bottom of the page.

    12. Data protection impact assessment (DPIA)

    Our current processing does not involve systematic monitoring of large areas or special categories of personal data. We have therefore not carried out a formal DPIA under GDPR Article 35. If we later introduce processing that could pose a high risk to the rights and freedoms of data subjects, we will carry out such an assessment before that processing begins.

    13. Delete local data

    You can delete all locally stored information (sender details, cookie choices and temporary form data) by clicking the button below. This does not affect data already sent to us or our partners.

    14. Contact

    If you have questions about our privacy policy or would like to exercise your rights, please contact us at:

    Email: hello@asapp.tech
    Address: Asapp! AS, Dybwads gate 3, 0367 Oslo