What we log, what we do not, and why
A platform that moves people accumulates sensitive information. Restraint is a design decision.
A movement platform knows where people go. That is not incidental; it is the product. Which makes restraint about what is kept, and who can see it, a design decision rather than a compliance afterthought.
What has to exist
Trips, with their routes, times and fares. Without them there is no receipt, no dispute resolution, no safety investigation and no driver earnings record.
Payment records, for the same reasons. Support tickets and safety reports, attached to the trips they concern.
What we keep deliberately narrow
Contact details between riders and drivers. In-app calling and messaging exist so a trip does not require either party to hand over a personal number. That is a decision to hold less, not more.
Trip sharing links are scoped to one trip and expire. A permanent link would be simpler to build and considerably worse.
Who can see what
Not everyone in an operations team needs access to everything, and access in the admin panel is scoped by role rather than granted wholesale. A support agent handling a ticket, a finance user reconciling a payout and a safety officer working an incident need different views of the same trip.
Actions that touch money or safety are recorded, so there is an answer to who did what.
Driver-facing information
A driver sees what they need to complete the job: who they are collecting, where, and any note the booker wrote. On a guardian-managed booking they are told the passenger is a ward and given the guardian's number and an emergency contact, because those are needed at the kerb.
What they do not get is a rider's history.
What we will not claim
We are not going to describe this page as a privacy guarantee. It is a description of choices. The meaningful commitments are in the privacy policy and the data rights process, both linked in the footer, and those are the documents to hold us to.