Privacy Policy

CarPooling — Captain app

This policy explains what data the CarPooling captain app collects, including identity and vehicle documents and trip location, why we collect it, who it is shared with, and how you can delete it.

Captain app

Scope of this policy

This policy applies only to the CarPooling captain app. The customer app has a separate policy because it does not process identity or vehicle documents, or wallet and commission data.

By using the app you acknowledge that you have read this policy.

The platform's role

CarPooling is a technology platform that acts as an intermediary, connecting and coordinating customers and captains. This policy governs how we handle data only; it does not make CarPooling the provider of transportation.

How responsibility is allocated between the platform and its users is set out in the Terms of Use, in the section "Platform Role and User Responsibility". Nothing in this limits any right that cannot lawfully be excluded or waived under applicable law.

Account and sign-in data

The usual sign-in to a captain account is with your phone number and password.

A verification code (OTP) is used only in specific cases: verifying your phone number at registration, recovering a forgotten password, and verifying your email address when that is requested.

We do not keep your password in plain text, and no one at our end can see or retrieve it. Password verification data is stored using one-way verification mechanisms, so a password can be checked without it being possible to extract it.

We may ask you to confirm your email address before some features are enabled.

Identity and vehicle documents

To activate a captain account we ask for: a personal photo, a photo of your national ID, a photo of your driving licence, a photo of the vehicle licence, and a photo of the vehicle.

These documents are used only to verify your identity, your eligibility to drive and the validity of the vehicle, and to protect customers and the platform from fraud and impersonation.

Only the platform's dedicated review team can see them; they are not shown to customers or published anywhere in the app.

They are stored in Firebase Storage in a protected path linked to your account, and no other user can access them.

Vehicle and trip data

The declared vehicle details, the route and pickup and drop-off points, the number of seats, the trip time and status, and the history of trips, bookings and cancellations.

Location during a trip

Your location is used to show it to the customer linked to your trip, to follow the trip's progress, and to show requests near you.

The app collects location only while it is running in the foreground. Background location permission is not declared or used, and there is no location tracking after the app is closed.

You can refuse location permission or withdraw it in your device settings, but accepting requests and running a trip depend on it.

Wallet and commission

We keep a record of your wallet transactions: the commission deducted for completed trips, any cancellation penalties, and any settlements or compensation.

The app does not collect or store payment card data. The fare is collected directly between you and the customer outside the app.

Ratings

The app stores customers' ratings of your trips and their comments to calculate your average rating and to monitor service quality.

Ratings are shown to you without revealing which customer gave them.

The text of a written comment is kept for up to ninety (90) days from the date of the rating, after which the text is deleted automatically.

The numeric rating (stars) remains part of your average rating; deleting the comment text does not change the number of ratings or the average.

The ninety-day period is a policy set by CarPooling to limit the amount of data kept; it is not a requirement imposed by the app store.

Chats and attachments

Text and voice messages and attachments you exchange with customers or with the support team are stored to run the chat and to handle complaints and reports.

Microphone permission is requested only when you record a voice message, and camera or photos permission only when you take or attach a photo.

When a trip ends or is cancelled, that trip's chat is closed: neither the customer nor the captain can view it or its attachments any more.

We keep a protected administrative copy of that chat and its attachments, visible only to the authorised main administrator and used solely to handle complaints, verify reports, protect the safety of passengers and captains, investigate disputes and fraud attempts, and meet legal obligations.

This copy is kept for up to ninety (90) days after the trip ends and is then deleted. This period is set by CarPooling policy; it is not a requirement imposed by the app store.

A request to delete your account overrides this period: archived chats linked to your account are deleted within the announced deletion period, at most thirty (30) days from the request, even if the ninety days have not yet passed.

We do not keep these copies indefinitely.

Notifications and device identifiers

We store your device's notification token (FCM token) to send alerts about requests, bookings, messages and your account status.

This token is a technical device identifier, not an advertising identifier.

Technical and diagnostic data

We use Firebase Crashlytics to record crashes and Firebase Analytics to measure use of the app, in order to fix problems and improve performance.

We use Firebase App Check to verify that requests come from a genuine copy of the app, to protect your account and the platform's data.

What we do not collect

We do not access the contacts on your phone.

We do not track your location in the background or after the app is closed.

We do not collect payment card data.

We do not sell your data or use it for advertising.

Who data is shared with

The customer linked to your trip sees: your display name, your personal photo, the declared vehicle details, your rating, and your location during the current trip. They do not see your identity documents or licences.

We use Google Firebase as the infrastructure provider for authentication, database, storage, notifications, analytics and crash reporting, so data is processed on Google's servers.

We may disclose data where there is a legal obligation or an official request from a competent authority, or to investigate fraud or to protect people's safety.

Data retention

We keep account data and documents for as long as the captain account is active, because valid documents are a condition for staying active.

When you request deletion of your account, the account is deactivated immediately and scheduled for permanent deletion after thirty (30) days; during that period you can restore it by signing in.

When the period ends, your personal data and uploaded documents are permanently deleted.

Archived chats linked to your account are deleted within the same period, at most thirty (30) days from the deletion request, without waiting for the normal retention period described in the "Chats and attachments" section.

We keep an administrative snapshot of the trip details (the route, the seats, the vehicle used at the time, and the parties involved) for support and complaint review, for up to ninety (90) days from the trip date; the snapshot is then removed from the administrative record.

We keep problem reports sent through "Report a problem" and their content for up to ninety (90) days from the time the report is sent; they are then deleted automatically from the operational support systems. The copy of the report in the support chat and any attachments of its own are deleted with it, while the rest of the chat remains. This period applies whatever the report's status (new, in progress or resolved). If you request deletion of your account, this data may be deleted before the ninety days end, following the deletion period described above. This period is a CarPooling policy; it is not a period imposed by Google Play.

This does not include financial and accounting records, audit records and the captain's average rating; these are kept separately, for as long as their purpose requires, as described in this section.

Financial and accounting records required by law are kept for the required period, with your personal data such as your name, phone number and photos removed from them.

These records may retain an internal, non-public identifier (a technical ID that carries no name, phone number or email) to the extent needed for accounting, auditing, fraud prevention and platform protection, and legal obligations. We do not use this identifier to contact you or to rebuild your profile.

Your rights and control over your data

You can edit your profile data and update your documents from within the app.

You can delete your account from: Settings, then "Delete account", without needing to contact support.

You can also request deletion from outside the app through the account deletion request page.

You can control the location, notifications, camera and microphone permissions in your device's system settings at any time.

Data security

Data is transmitted over an encrypted connection (HTTPS/TLS).

Access is governed by server-side security rules for the database and storage, so that no user can read or change another captain's data.

No method of transmission or storage is 100% secure, so we cannot guarantee absolute security, but we are committed to appropriate protection measures and to reviewing them.

Children

The app is not directed at children. A captain account requires a valid driving licence, and therefore the legal driving age.

Updates to this policy

We may update this policy when the app's features or regulatory requirements change.

The date of the last update and the version number appear at the bottom of this page.

Contact us

For any question about privacy, your data or your documents, contact us at the email address below.

Contact

Official email for privacy and data requests:

Last updated: 2026-09-27 Version 1.0
العربية