Privacy Policy - Got Ride?
Last Updated: July 19, 2026
Data Controller: Got Ride? LLC ("The Company")
Got Ride? LLC (hereinafter, "The Company"), with its legal address for the purposes of this notice at the headquarters of its corporate incorporation, recognizes the importance of privacy, confidentiality, and security regarding the personal data of its users. In compliance with applicable United States federal laws, state privacy frameworks based on the user's location, the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) in Mexico, as well as the global directives required by the Apple App Store and Google Play Store, this Privacy and Confidentiality Notice (hereinafter, the "Notice") is hereby issued.
This document regulates how we collect, store, treat, transfer, and protect the information of Passengers ("Users") and Independent Private Drivers ("Drivers") within our technological platform (hereinafter, the "Platform").
1. Personal Data We Collect
To guarantee the proper operation of the transportation intermediation service, The Company will collect the following data based on the account profile:
1.1. From Users (Passengers)
- Identification and Contact Data: Full name, email address, mobile phone number, and profile picture (optional).
- Financial Data (Transactional): Credit or debit card information (managed in an encrypted manner through external payment gateways).
- Operational Data: History of trips taken, routes, frequent destinations, ratings submitted, and technical support reports.
1.2. From Drivers
- Identification and Legal Verification Data: Full name, email address, phone number, official ID photo, valid driver's license, Social Security Number (SSN) for US identity verification, and criminal background check clearance. In the United States, all background screenings and Motor Vehicle Record (MVR) checks are conducted through accredited consumer reporting agencies in strict compliance with the Fair Credit Reporting Act (FCRA). Drivers will receive appropriate disclosures and authorization forms prior to screening, as well as pre-adverse action notices if a report flags disqualifying offenses.
- Vehicle Data: Vehicle registration, license plates, model, year, color, and a valid comprehensive auto insurance policy explicitly covering passenger transportation via tech apps (Ridesharing/ERT Insurance or equivalent).
- Financial Data: Bank account information and tax registration details for the disbursement of earnings and corresponding tax withholdings.
2. Critical Use of Geolocation and Background GPS
The core functionality of the Platform requires the processing of exact geographic location data in real time.
Background Geolocation (Drivers): Specifically for Drivers, the Platform will collect, transmit, and process geographic location data via the device's GPS even when the application is closed, minimized, or not in direct operational use. This is strictly necessary for efficient ride dispatching, real-time safety monitoring of routes, accurate fare calculation, and fraud prevention.
Foreground Geolocation (Users): Passenger location data is collected upon opening the app to identify the starting point of the transfer and plot the navigation route for the trip.
The user or driver may disable geolocation permissions in their operating system settings; however, doing so will completely disable the operational use of the Platform.
2.1. Right to Limit the Use of Sensitive Personal Information (US Residents)
Under US state privacy laws (including the California Consumer Privacy Act - CCPA/CPRA), precise real-time geolocation is classified as "Sensitive Personal Information." While the Platform requires this data to perform core ridesharing operations (matching, navigation, and trip safety), users have the right to limit the use of sensitive data if it is used for secondary commercial purposes. The Company only processes precise geolocation for essential operational and safety services as permitted by law.
3. Purposes of Data Processing
The personal data collected will be used for the following necessary purposes:
- Manage registration, identity validation, and account maintenance within the Platform.
- Digitally connect Users with available nearby Independent Drivers.
- Securely process fare collections, cancellation fees, commission disbursements, and billing through the integrated payment gateway.
- Monitor the physical safety of transits and handle support reports, emergencies, or disputes.
- Design analytical improvements and software optimizations through aggregated and anonymous metrics.
4. Data Transfer and Third-Party Processing
The Company does not sell, rent, or trade the personal data of its users with third-party companies for advertising purposes. Information transfers are strictly limited to the following scenarios necessary for the operation:
- External Payment Gateways (Stripe): Bank card and billing data are transferred directly to third-party payment processors under PCI-DSS security standards. The Company does not store card numbers or security codes on its servers.
- Cloud Infrastructure and Map Providers: Transfer of technical data to storage servers (e.g., Azure or AWS) and map APIs (e.g., Google Maps API) for correct route rendering and navigation.
- Competent Authorities: In the event of traffic accidents, criminal investigations, or formal judicial requests, The Company will cooperate with law enforcement authorities by delivering the information required by law.
4.1. US State Privacy Disclosures: "Selling" or "Sharing" of Personal Information
The Company does not sell your personal data for monetary compensation. However, under certain US state laws (e.g., California, Virginia, Colorado), disclosing information to third-party partners for cross-context behavioral or targeted advertising purposes may be defined as "selling" or "sharing."
- Categories of Data Disclosed: We may share device identifiers, usage analytics, and general location indicators with advertising partners to deliver personalized promotional offers.
- Right to Opt-Out: US users have the right to opt-out of the "sale" or "sharing" of their personal information for targeted advertising. You can exercise this right at any time by unchecking the "Data Sharing / Personalized Ads" toggle inside your app privacy settings, or by broadcasting a legally recognized browser preference signal such as the Global Privacy Control (GPC).
5. Strict Confidentiality Policy Between Parties
To safeguard the integrity of the community, the software establishes strict confidentiality rules regarding data shared during a service:
Anonymization and Restriction: During the trip, the Driver will only have access to the User's first name and the pickup/drop-off locations. Once the transit is completed, direct contact details remain completely hidden.
Prohibition of Data Use: Drivers and Users are strictly prohibited from storing, writing down, photographing, using, or sharing the personal information, phone numbers, or destinations of the other party for purposes foreign to the strict execution of the requested ride. Any attempt to contact a passenger outside the Platform for personal, commercial, or harassment purposes will be sanctioned with immediate and permanent termination from the system, without prejudice to applicable civil or criminal legal actions.
6. Privacy Rights (ARCO) and Account Deletion
In accordance with data protection regulations, data subjects have the right to Access, Rectify, Cancel, or Oppose the processing of their personal data.
Direct Deletion Mechanism: To comply with the mandatory policies of Apple and Google, the Platform features a visible and direct button within the user profile configuration panel that allows requesting "Account Deletion."
Upon processing the request, the system will deactivate the account and proceed to permanently delete or irreversibly anonymize all personal data of the data subject from active databases, except for those financial or tax records that The Company is legally obliged to retain for statutory audit periods.
6.1. Additional Rights for US Consumers
Depending on your US state of residence, you may possess specific statutory rights regarding your personal information, which include:
- Right to Know and Access: The right to request confirmation of whether we process your data and to access the specific pieces of personal information collected.
- Right to Delete: The right to request the deletion of personal data, subject to legal exceptions (such as maintaining financial/tax records for mandatory audit periods).
- Right to Correct: The right to request that inaccurate or incomplete personal information be rectified.
- Right to Non-Discrimination: The Company will not discriminate, deny services, or alter pricing tiers if you choose to exercise any of your privacy rights.
To submit a privacy request, users can contact our Data Protection Office or utilize the dedicated privacy self-service tools available within the Platform's settings menu.
7. Technological Security Measures
The Company and its partner software factory implement advanced administrative, technical, and physical security measures (including data encryption in transit via SSL/TLS, encrypted storage, secure JWT authentication tokens, and restricted access policies) to protect information against loss, theft, alteration, or unauthorized access.
8. Amendments to the Privacy Notice
The Company reserves the right to update or modify this Notice at any time to adapt it to new legislative reforms or technical updates of the application. Amendments will be available immediately through a public link on the app's landing page and within the informational menu of the Platform.
By registering an account and using Got Ride? services, you grant your express consent for the treatment, geolocation, and transfer of your personal data under the conditions established in this Privacy and Confidentiality Notice.
9. Children's Privacy Policy (COPPA Compliance)
The Platform is strictly intended for individuals who are 18 years of age or older (or the legal age of majority in their jurisdiction). We do not knowingly collect, maintain, or process personal information from children under the age of 13, in strict compliance with the US Children's Online Privacy Protection Act (COPPA). If we discover that a minor under 13 has provided personal data without verified parental consent, we will take immediate steps to permanently delete that information and terminate the associated account.