1. Scope and operator
This policy covers the CoRide mobile app and its marketing website. CoRide helps people share an existing commute and its costs. The app and website handle different information, as explained below.
CoRide’s legal operator name, address and official privacy contact are not yet published. During private testing, contact the person or team who provided your test access with privacy questions. A verified contact and request process must be published before public launch.
2. Account and profile information
The app handles your phone number for sign-in; work email, employer and verification status for workplace verification; and profile details you provide, such as name, gender, photo and UPI ID. It also stores account identifiers, authentication sessions, ratings and a device push-notification token where notifications are enabled.
When Firebase phone authentication is used, your phone number is sent to and stored by Google for authentication and spam/abuse prevention across Google services. Other configured SMS or email providers process the details needed to deliver verification codes.
3. Routes, location and vehicle information
The app handles places you search for, pickup and destination addresses and coordinates, saved commute preferences, travel days and departure times. These details are used to find nearby routes and coordinate rides. Choosing your current location uses your device’s location permission; you can search for a place manually instead. The current app does not implement continuous background location tracking.
Hosts provide vehicle information such as registration number, make, model, colour, type and available seats. Where registration verification is enabled, Cashfree processes the registration number; CoRide stores verification results, owner information and the returned registration data. A verification badge is not a criminal-background or personal-safety guarantee.
4. Trips, conversations and payments
CoRide stores ride offers, seat requests, booking status, trip dates, cost contributions and ratings. Ride-group messages are stored so participants can see conversation history. In-app voice calls, when enabled, use LiveKit and require microphone permission; audio is transmitted to connect participants. The current CoRide implementation has no call-recording feature.
Razorpay processes enabled in-app payments. CoRide stores transaction references, amounts and payment status associated with bookings. Payment credentials entered in the provider’s checkout are handled by that provider; CoRide’s own database is not designed to store card numbers, CVVs or UPI PINs. Never put such information in chat.
5. What other people can see
Relevant users can see profile and ride information needed for matching and coordination, such as name, profile photo, workplace, ratings, vehicle details, route, time and available seats. Your ride’s group chat is visible to authorised participants.
A booking’s host and guest can see each other’s phone number when the booking is accepted or paid. They may then contact one another outside the app. Do not share a home address or sensitive information beyond what is needed for the pickup. Workplace verification does not imply employer endorsement.
6. Service providers and technical information
Depending on enabled features, providers include Firebase/Google for authentication and notifications; Google Maps/Places/Directions or OpenStreetMap-based services for place and route lookup; Cloudinary for profile photos; LiveKit for voice calls; Razorpay for payments; Cashfree for vehicle verification; and configured SMS, email, hosting and database services.
Providers receive information necessary for the feature they deliver and may process it in other countries under their own terms. Servers and providers may handle IP addresses, request times, device/network information and error or security logs. The current app has no integrated advertising or behavioural analytics SDK. Deployment-specific provider settings and locations must be confirmed before public launch.
7. The website and cookies
The current marketing website has no account form, payment checkout, advertising tracker or analytics script. Its commute calculator runs locally in your browser; the values are not sent to CoRide. Fonts and images are served with the website.
The website host may process ordinary connection logs. Accessing a private preview may require the hosting platform’s sign-in and cookies under that platform’s privacy terms. This policy does not mean the hosting platform stores no information.
8. Storage, security and retention
The app uses authenticated API requests and access restrictions for bookings, chat and calls. Authentication tokens are stored using the device’s secure-storage integration. No system can guarantee absolute security.
Account, trip, message and transaction records remain in the service until removed under an applicable process. Short-lived authentication and call state expire separately. A documented retention schedule, deletion workflow and backup-erasure timing have not yet been implemented or confirmed for public release. Payment providers may keep records for their own legal and operational obligations. Logging out or uninstalling the app does not delete server records.
9. Your choices and requests
You can edit available profile fields, remove your profile photo or saved vehicle, and change device permissions. You can deny microphone access and use chat, deny location access and search manually, or disable notifications in device settings. A disabled permission may make the related feature unavailable.
Access, correction, deletion, consent withdrawal and other requests must be handled through a verified privacy channel once published, subject to applicable law and necessary identity checks. There is currently no self-service account-deletion control or public request form. During private testing, contact your test organiser; see Data & account deletion for the current limitations. Revoking a device permission does not erase previously stored records.
10. Age and updates
CoRide is intended for adults aged 18 or older. If a child’s information has been provided during testing, tell your test organiser so it can be addressed. The public release must provide an official reporting channel.
This policy will be updated when the operator, contact details or data practices change. The revision date and version appear on this page. Material changes should be communicated before new processing starts where required by applicable law.
Back to CoRide