CarPooling — Customer app
This policy explains what data the CarPooling customer app collects, why we collect it, who it is shared with, and how you can control or delete it.
This policy applies only to the CarPooling customer app. The captain app has a separate privacy policy because the data it processes is different.
By using the app you acknowledge that you have read this policy. If you do not agree with it, please do not use the app.
CarPooling is a technology platform that acts as an intermediary, connecting and coordinating customers and captains. This policy governs how we handle data only; it does not make CarPooling the provider of transportation.
How responsibility is allocated between the platform and its users is set out in the Terms of Use, in the section "Platform Role and User Responsibility". Nothing in this limits any right that cannot lawfully be excluded or waived under applicable law.
When you create an account or sign in, we process: your email address, your password (managed and stored encrypted by Firebase Authentication; we cannot see it), and your phone number when you sign in with a verification code.
If you choose to sign in with Google or Facebook, we receive from that provider your identifier, name and the email address linked to that account. We do not receive your Google or Facebook password.
Social sign-in providers do not give us your phone number, so we ask you to enter it once after your first sign-in and to type it again to confirm. This number is contact data only: we do not verify it by text message and it never becomes a way to sign in to your account. We use it for one purpose: to let the captain assigned to your trip contact you during it. Your number is not shown to other captains.
Your display name, and a profile photo if you choose to upload one. The profile photo is entirely optional and the app works without it.
Uploaded photos are stored in Firebase Storage in a space linked to your account.
The app uses your location to set the pickup point, show nearby trips, and follow the current trip on the map.
We ask the operating system for location permission when it is actually needed, not when the app is first opened. You can refuse the permission or withdraw it later in your device settings; you can then still set a location manually on the map.
The customer app does not collect location in the background. Background location permission is not required and is not declared by the app.
Pickup and drop-off points, number of seats, trip times and status, the history of trips, bookings and cancellations, and the fares linked to them.
This data is used to carry out the booking, match you with a captain, calculate the fare, and resolve disputes and complaints.
Text messages, voice messages and attachments you send in the app - whether to the captain or to the support team - are stored by us to run the chat, handle complaints and verify reports.
Do not share sensitive data in the chat. The chat is not a secure channel for exchanging card numbers or passwords.
Microphone permission is requested only when you record a voice message, camera permission only when you take a photo in the chat, and photos/files permission only when you attach a file from your device.
When a trip ends or is cancelled, that trip's chat is closed: neither the customer nor the captain can view it or its attachments any more.
We keep a protected administrative copy of that chat and its attachments, visible only to the authorised main administrator and used solely to handle complaints, verify reports, protect the safety of passengers and captains, investigate disputes and fraud attempts, and meet legal obligations.
This copy is kept for up to ninety (90) days after the trip ends and is then deleted. This period is set by CarPooling policy; it is not a requirement imposed by the app store.
A request to delete your account overrides this period: archived chats linked to your account are deleted within the announced deletion period, at most thirty (30) days from the request, even if the ninety days have not yet passed.
We do not keep these copies indefinitely.
When you rate a captain, we store the rating and its comment to show it within the captain's average rating and to monitor service quality.
Ratings are shown to the captain without revealing who gave them.
The text of a written comment is kept for up to ninety (90) days from the date of the rating, after which the text is deleted automatically.
The numeric rating (stars) remains part of the captain's average rating; deleting the comment text does not change the number of ratings or the average.
The ninety-day period is a policy set by CarPooling to limit the amount of data kept; it is not a requirement imposed by the app store.
The app keeps an internal record of the transactions and loyalty points linked to your account.
The app does not collect or store payment card data. Payment is made outside the app, directly between the customer and the captain.
To send booking, trip and message notifications, we store your device's notification token (FCM token). This token is a technical device identifier, not an advertising identifier.
You can turn notifications off in your system settings at any time.
We use Firebase Crashlytics to record crashes and Firebase Analytics to measure the use of screens and flows in the app, in order to fix problems and improve performance.
We use Firebase App Check to verify that requests come from a genuine copy of the app, to protect your account and the platform's data from misuse.
We do not sell your personal data or share it for advertising.
The data needed to carry out the trip is shared with the captain linked to your booking (your display name, pickup and drop-off points, and what you write in the chat).
We use Google Firebase as the infrastructure provider for authentication, database, storage, notifications, analytics and crash reporting, so data is processed on Google's servers.
If you choose to sign in with Facebook, Facebook processes the sign-in under its own privacy policy.
We may disclose data where there is a legal obligation or an official request from a competent authority, or to investigate fraud or misuse or to protect people's safety.
We keep account data for as long as the account is active.
When you request deletion of your account, the account is deactivated immediately and scheduled for permanent deletion after thirty (30) days. During that period you can restore the account by signing in and choosing "Restore account".
When the period ends, your personal data is permanently deleted: your name, email, phone number, photos and the chats linked to you.
Archived chats linked to your account are deleted within the same period, at most thirty (30) days from the deletion request, without waiting for the normal retention period described in the "Chats and attachments" section.
We keep an administrative snapshot of the trip details (the route, the seats, the vehicle used at the time, and the parties involved) for support and complaint review, for up to ninety (90) days from the trip date; the snapshot is then removed from the administrative record.
We keep problem reports sent through "Report a problem" and their content for up to ninety (90) days from the time the report is sent; they are then deleted automatically from the operational support systems. The copy of the report in the support chat and any attachments of its own are deleted with it, while the rest of the chat remains. This period applies whatever the report's status (new, in progress or resolved). If you request deletion of your account, this data may be deleted before the ninety days end, following the deletion period described above. This period is a CarPooling policy; it is not a period imposed by Google Play.
This does not include financial and accounting records, audit records and the captain's average rating; these are kept separately, for as long as their purpose requires, as described in this section.
Financial and accounting records required by law are kept for the required period, with your personal data such as your name, phone number and photos removed from them.
These records may retain an internal, non-public identifier (a technical ID that carries no name, phone number or email) to the extent needed for accounting, auditing, fraud prevention and platform protection, and legal obligations. We do not use this identifier to contact you or to rebuild your profile.
You can edit your profile data from within the app.
You can delete your account and data from: Settings, then "Delete account". You do not need to contact support.
You can also request deletion from outside the app through the account deletion request page.
You can control the location, notifications, microphone and photos permissions in your device's system settings at any time.
You can write to us about your data at the email address shown at the end of this page.
Data is transmitted over an encrypted connection (HTTPS/TLS).
Access to data is governed by server-side security rules, so that no user can read or change another user's data.
No method of transmission or storage is 100% secure, so we cannot guarantee absolute security, but we are committed to appropriate protection measures and to reviewing them.
The app is not directed at children and may not be used by anyone under the legal age to enter into a contract in the country of use.
If we find that an account belongs to a child, we will close it and delete its data.
We may update this policy when the app's features or regulatory requirements change.
The date of the last update and the version number appear at the bottom of this page, and the updated version reaches you with the app update.
For any question about privacy or a request concerning your data, contact us at the email address below.
Official email for privacy and data requests: privacy@carpoolingonline.com