Mero Rides Legal

Mero Rides Data Inventory (User & Rider Apps)

This document supports App Store / Google Play disclosures and the in-app privacy policy by listing what data is collected, why, and for how long.

Overview

Please read this policy carefully. It explains how the Mero Rides rider and driver apps work with your data and safety.

1. Apps Covered

  • User App (Riders)sparsha-uber/user-app
  • Rider App (Drivers)sparsha-uber/rider-app

Both apps talk to the same backend and share core services (auth, rides, wallet/payments, notifications, maps).

2. Data Categories – User App (Riders)

The table below summarises the main data categories collected by the rider app, together with purposes, retention, legal basis, and typical third parties.

  • Account Identity: First name, last name, nationality, phone number, profile photo URL – used to create and manage rider accounts and identify riders to drivers and support. Retained while the account is active, with some records kept for legal/accounting after deletion. Shared with drivers during trips, support tools, and infrastructure providers.
  • Contact Details: Phone number (and email if added later) – used for login / verification, trip coordination, and support communications. Shared with SMS/telephony, email providers, and support tooling.
  • Location (Foreground): Precise GPS, coarse location, pickup/drop-off coordinates – used to find nearby drivers, estimate pickup times, match rides, and provide live trip tracking. Trip data is kept as ride history; raw GPS samples may be trimmed/aggregated over time.
  • Location (Background): Background location while a trip is active or the app is in ride state – used to maintain live tracking and safety signals when the app is backgrounded. Limited to trip windows with logs retained as part of trip history.
  • Ride & Trip History: Trip IDs, timestamps, pickup/drop-off, route summary, fare, driver mapping – used for trip history, dispute resolution, safety investigations, and analytics. Retained for legal, accounting, and safety periods.
  • Ratings & Feedback: Ratings, written feedback, complaint categories – used for quality control and platform improvements. Kept while relevant then anonymised/aggregated.
  • Wallet & Payments: Wallet balance, transaction history, Stripe PaymentIntent IDs, last4 (if shown) – used to manage USA Points and payments.
  • Device & Diagnostics: Device model, OS version, app version, crash logs, performance metrics – used to debug and improve stability. Raw logs retained for a limited period then aggregated/anonymised.
  • Notifications: Push token, notification delivery/open events – used to deliver trip updates, safety alerts, and account notifications.
  • Sensitive / Safety: Optional blood group, emergency contact details, safety notes – used only for emergency and safety workflows, with explicit explanation and strict access controls.

3. Data Categories – Rider App (Drivers)

The driver app shares many categories with the rider app but includes additional fields for eligibility, vehicle information, and payouts.

  • Driver Identity & Profile: First/last name, phone, nationality, profile photo, bio – identifies drivers to riders and support.
  • Vehicle & Documents: Vehicle make/model, plate number, registration docs, license details, verification photos – used to verify eligibility and comply with policies and law.
  • Banking / Payout Details: Bank account token/ID, payout preferences – for earnings payouts via payment processors.
  • Location (Foreground & Background): Continuous GPS while online and during trips – used for trip offers, live movement, and safety features; retained as part of work-session and trip records.
  • Trips & Earnings: Completed trips, statuses, timestamps, fare breakdown, earnings, deductions, bonuses – used for statements, payouts, and disputes.
  • Wallet & Deductions: Balances, pay-offs, penalties – used to manage USA Points, settle negative balances, and unblock access based on wallet status.
  • Notifications, Diagnostics, and Sensitive / Safety – similar to the rider app, but focused on driver workflows and safety investigations.

4. Third-Party Processors & SDKs (Both Apps)

The following categories summarise how core third-party services interact with Mero Rides data:

  • Stripe: Payments & wallet top-ups – processes payment method tokens, PaymentIntent IDs, and limited card metadata. Full card numbers/CVV are handled only by Stripe.
  • Google Maps SDK: Maps & geolocation – processes device location, map viewport, and search queries for navigation and routing (not for ads).
  • Expo/Firebase Push: Push notifications – processes push tokens and notification metadata for trip and safety alerts.
  • Crash/Analytics Providers: Stability & performance diagnostics – process device info, app version, and anonymised usage events.
  • Hosting/Infrastructure: Backend infrastructure (DB, storage, etc.) – host and process server-side data under data processing and security agreements.

5. High-Level Retention & Deletion Rules

  • Accounts – deleted on user/driver request, subject to retention of specific records for legal, accounting, fraud-prevention, and safety obligations.
  • Trips & Payments – retained for required legal and audit periods, then anonymised or deleted.
  • Location Traces – full-resolution GPS stored only as needed for active trips, investigations, and limited historical analysis; may be down-sampled or aggregated over time.
  • Diagnostics – crash logs and technical metrics retained for a limited period before aggregation/anonymisation.

6. Usage Summary For Store Disclosures

  • Location – collected (precise + coarse), including background for both apps, strictly for core ride-hailing functionality, navigation, and safety; not used for advertising or data sale.
  • Personal Info – collected to create and manage accounts and support trips and payouts.
  • Financial Info – limited payment metadata; full card data handled by Stripe.
  • Sensitive Info – optional safety fields (e.g. blood group) used only for emergencies and safety workflows, with explicit explanation.
  • Device/Diagnostics – collected to keep the apps reliable and secure.

This inventory should be kept in sync with the public Privacy Policy, App Store "App Privacy" forms, and Google Play "Data Safety" declarations.