PoolTransit — Privacy Policy
Effective date: 26 July 2026. Last updated: 24 September 2026. Data Fiduciary: PoolTransit. Grievance Officer: the PoolTransit team — [email protected].
PoolTransit ("we", "us") helps commuters share rides between fixed stops ("hubs"), one-to-one or in small groups of up to four. This policy explains what personal data we collect, why, how we share it, how long we keep it, and your rights. The service is for adults (18+).
1. Data we collect
| Data | Why |
|---|---|
| Phone number | Account identity — passwordless sign-in via a one-time code on WhatsApp (or SMS). |
| Google account name & email (if you use "Continue with Google", offered during our testing phase) | Passwordless sign-in; Google's Privacy Policy governs Google's processing. |
| Email address (optional) | Only if email sign-in is enabled — passwordless one-time code. |
| First name (and last name if entered) | Shown as first name only to a co-rider after you match. |
| Gender | Set once at sign-up; used to offer same-gender matching. |
| UPI ID (optional) | Shown to co-riders only when you use fare split, so they can pay you. We never hold money. |
| Two-wheeler details (optional) — whether you ride a two-wheeler, your bike number (registration plate), and an optional description | Only if you choose to offer pillion rides ("Ride Together"). Your bike number is shown to the one co-rider you match with, so they can identify you at the stop. |
| Travel preference (optional) — e.g. share an auto, ride pillion, or "anything" | Your last choice is remembered on your device to pre-fill the next trip. |
| City & default hubs (optional) | Scope the stop list and pre-fill trips. |
| Trip data — hubs, bookings, matches, chat messages, fare splits | To match you and coordinate the ride. |
| Community Chat content (optional) — your pseudonymous handle (e.g. "Rider_1234"), and the messages, reactions, and mentions you post in the public city-wide chat | To run the optional Community Chat. Your handle is a nickname, not your real name. These posts are public to other signed-in members in your city — don't post private information there. |
| Safety & conduct records — reports, no-show reports, temporary restrictions | To keep rides safe and act on abuse. Restrictions expire automatically. |
| Referral data — your referral code, Founding Member number, and who-invited-whom | To run our optional Founding Members Program (recognition only, no money). |
| Approximate device location (only when you tap "Use my location") | Computed on your device to suggest the nearest stop. Not stored. |
| Precise location — only during "Find each other", when you turn it on | To help you and your matched co-rider meet at the stop. Shared live with that co-rider only, near the stop only, never stored. |
| Device push token | To send ride notifications (Firebase Cloud Messaging). |
| Diagnostic / usage events and feedback you send | To keep the service working and safe. |
We collect only what these features need.
2. What we do not do
- We do not hold, process, or transfer money. Fare split only calculates a share and hands off to your UPI app.
- We do not track your ride. "Find each other" shares live location only if you turn it on, only near the stop, and never stores it.
- We do not sell your personal data or use it for third-party advertising.
3. Legal basis (DPDP)
We process your data on the basis of your consent, given when you sign up and use each feature, to provide the ride-sharing service you request. You may withdraw consent at any time (see Your rights).
4. How your data is shared
- With your co-rider(s) (after a match): your first name and photo/initials only — never your email, phone, or last name. If you use fare split, your UPI ID is shown to that ride's co-riders. If you offer a pillion ride, your bike number (registration plate) is shown to the one co-rider you match with, so they can spot you — never to anyone else.
- In Community Chat (if you use it): your handle and anything you post — messages and reactions — is public to all signed-in members in your city, not just co-riders. It is not tied to your real name; do not share personal or private information there.
- PoolTransit controls and is responsible for your data. To run the app we rely on a few infrastructure providers — for database hosting, delivering your one-time login code, and push notifications. They act strictly on our instructions. Your core account and ride data are hosted in India; some may process limited data outside India, as DPDP permits.
- Legal: we may disclose data where required by law or to protect safety.
5. How long we keep it
- Ride chat messages: limited to a 24-hour window per ride.
- Community Chat messages: cleared automatically on a regular schedule (about weekly); we do not keep them long-term.
- Profile, account, safety, and referral data: kept while your account is active; temporary restrictions expire on their own.
- When you delete your account, we erase your personal data promptly and irreversibly. De-identified analytics that no longer identify you may be retained.
6. Your rights (DPDP)
You can, at any time: access your data; correct it (edit your profile);
delete your account and all associated data (Profile → Delete my account, or
https://pooltransit.com/delete-account — immediate and permanent); withdraw
consent (deleting your account does this); nominate someone to exercise your
rights on incapacity/death; and raise a grievance with our Grievance Officer
(above), including to the Data Protection Board of India.
7. Security
We use industry-standard measures (encrypted transport, row-level access controls, restricted backend access). No system is perfectly secure; in a personal-data breach we will notify the Data Protection Board and affected users as required by DPDP.
8. Changes
We may update this policy; we will post the new effective date here and, for material changes, notify you in-app.
9. Contact
PoolTransit — Grievance Officer: [email protected].