Mero Rides Legal

Mero Rides Store Privacy Metadata Checklist

This checklist helps keep App Store and Google Play privacy metadata in sync with the actual behaviour of the Mero Rides rider and driver apps.

Overview

Please read this policy carefully. It explains how the Mero Rides rider and driver apps work with your data and safety.

This checklist is primarily for the team that prepares and maintains App Store (Apple) and Google Play listings for the Mero Rides rider and driver apps. It should be reviewed before each major release that changes data collection, processing, or sharing.

1. App Privacy / Data Safety Forms

  • Confirm that the data categories selected in the store forms match the Mero Rides Data Inventory and the Privacy Policy.
  • Ensure that location is correctly flagged as:
    • Precise and/or coarse
    • Collected in the background (for active trips and online drivers)
    • Used for core app functionality and safety, not for advertising or sale
  • Verify that payment and financial data is described accurately, with Stripe listed as a processor where required by the platforms.

2. Purpose Declarations

  • Double-check that declared purposes (e.g. "App functionality", "Analytics", "Fraud prevention") align with what the apps actually do.
  • Confirm that no categories are marked for "Advertising" or "Data broker / sale" unless a genuine advertising SDK or data sale is introduced.

3. Optional / Sensitive Data

  • If emergency contacts or optional safety data (such as blood group) are enabled, ensure that these are listed correctly as sensitive data, with purposes limited to safety and emergency response.
  • Make sure that "health" or "medical" data is not claimed more broadly than what the apps actually collect.

4. Account Deletion & User Rights

  • In the store forms, confirm that users are told they can close their account and/or delete data via in-app options and via the web form at /mero-rides/legal#request-form.
  • Verify that the retention explanations in the forms match the Data Deletion & Account Closure Policy and Data Inventory.

5. SDK & Library Audit

  • Maintain an up-to-date list of all third-party SDKs included in the rider and driver apps (analytics, crash reporting, maps, notifications, payments, etc.).
  • For each SDK, identify:
    • What data it collects
    • Whether data is linked to users or devices
    • Whether data is used for tracking or advertising
  • Ensure that any changes to SDK configuration (e.g. enabling ad features) are reflected in the store privacy metadata before release.

6. Release Checklist

  • Re-run the QA Privacy & Permissions Checklist on a near-final build.
  • Compare the behaviour of that build with the latest privacy questionnaire answers in both app stores.
  • If anything has changed (new fields, new screens, new uses of data), update the Data Inventory, Privacy Policy, and store metadata accordingly.

Keeping store metadata accurate is critical for compliance and trust. This checklist should be part of the standard release process for Mero Rides.