This Privacy Policy explains how Poolzy (“Poolzy”, “we”, “us”) collects, uses, stores, shares, and protects personal data when you use the Poolzy mobile application and related services in India.
Poolzy is a technology platform for verified professionals who share daily commutes within a trusted community. Poolzy is not a taxi company or transport operator.
1. Who this policy applies to
This policy applies to users of the Poolzy app who create an account, browse or publish rides, subscribe to Poolzy Plus, or otherwise interact with our services. Poolzy is intended for working professionals aged 18 and above.
2. Data we collect
We collect only data reasonably necessary to operate a trusted commute community for professionals. The table below reflects data processed in our current product.
| Category | Examples | Why we collect it |
|---|---|---|
| Account & identity | Name, profile photo, user ID, account status, linked sign-in providers | Create and secure your account; display your profile to ride partners |
| Contact (required) | Mobile number (required at sign-up) and work email address (required before you can search, book, or host rides) | Account authentication, professional verification, and ride coordination with confirmed partners |
| Emergency contact (optional) | Emergency contact name and phone number, if you add them in Edit Profile | Display in Safety center and pre-fill call/SMS actions on your device. Not required to use Poolzy. |
| Professional profile | Company name, job title / designation, optional gender (for women-only rides) | Trust, matching, and community safety features |
| Verification status | Phone verified, work email verified, professional verification flags | Gate platform participation and reduce fraud |
| Commute & places | Home/work addresses and geocoded coordinates you enter, ride routes, pickup/drop points, saved corridors, recent place picks cached on device | Search, publish, match rides, and enforce service-area rules. Poolzy does not continuously track your device GPS in the background. |
| Vehicle (hosts) | Car brand/model, vehicle registration number | Display on ride listings; self-declared by hosts |
| Payments | Host UPI VPA and payment display name; Poolzy Plus subscription metadata (order ID, payment ID, amounts, GST); optional UPI transaction reference for ride settlements | Peer-to-peer ride contributions and subscription billing. We do not store card numbers or UPI PINs. |
| Rides & bookings | Ride listings, booking requests, statuses, fares, cancellation/no-show records, payment dispute records | Operate matching, payments workflow, trust scoring, and support |
| Communications | In-app chat messages between host and rider for a ride | Coordinate pickups and commute details |
| Trust & feedback | Trust score, trust pillars, ride completion/cancellation/no-show rates, commute feedback tags and notes, trust dispute submissions | Platform integrity and user transparency |
| Referrals | Referral code, referrer/referee relationships, qualified referral counts, waiver months earned/redeemed | Operate the referral rewards program |
| Subscription | Poolzy Plus plan, status, billing period, payment source (Razorpay, pilot grant, referral waiver) | Provide paid platform features (search, booking, hosting) |
| Safety center | Emergency contact details you save; optional product analytics when you use Safety center actions | Let you call or open a pre-filled SMS on your phone. Poolzy does not send SMS, place calls, or monitor your location for safety alerts. |
| Device & app | Push notification token (FCM), device/platform signals for App Check attestation, app version | Deliver notifications, protect APIs, maintain security |
| Analytics & diagnostics | Product analytics events (e.g. signup, ride booked, payment confirmed); crash and error diagnostics | Improve reliability and understand feature usage |
| Preferences (on device) | Onboarding state, notification toggles, analytics opt-out, cached recent places, corridor templates | Personalize your experience; stored locally in encrypted preferences where supported |
3. Required vs optional information
- Required: mobile number (sign-up), name, and work email verification to participate in rides. Poolzy Plus subscription (or eligible waiver) is also required to search, book, or host.
- Optional: profile photo, gender, emergency contact, home/work addresses (until you add them for matching), host vehicle and UPI details (required only if you host rides and accept payments), and usage analytics (on by default; you may opt out in Settings).
4. How we collect data
- From you: when you register, complete your profile, publish or book rides, chat, pay, submit feedback, or change settings.
- Automatically: when you use notifications, analytics, or crash reporting.
- From service providers: authentication (Firebase), payment confirmation (Razorpay webhooks), and email delivery (work-email OTP).
- From other users: feedback, booking interactions, and messages sent to you through the platform.
5. How we use your data
- Create, authenticate, and manage your account
- Verify phone number and work email; enforce professional eligibility
- Match hosts and riders; enforce market and service-area rules
- Facilitate ride coordination, in-app chat, and optional Safety center actions on your device
- Process Poolzy Plus subscriptions and record peer-to-peer payment status between users
- Calculate trust scores, handle cancellations/no-shows, and operate referral rewards
- Send push and in-app notifications (respecting your notification preferences)
- Detect abuse, enforce Terms of Service, and protect platform security (including Firebase App Check)
- Improve the app through analytics (where enabled) and crash diagnostics
- Comply with law and respond to valid legal requests
6. Legal basis (India)
We process personal data consistent with applicable Indian law, including the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000, based on:
- Consent: when you sign up, accept this policy, enable optional features, or opt in to analytics
- Contractual necessity: to provide the Poolzy service you request
- Legitimate interests: fraud prevention, security, trust scoring, and service improvement, balanced against your rights
- Legal obligation: where required by applicable law (e.g. tax or payment record retention)
7. Who can see your data
7.1 Other Poolzy users
- Public discovery profile: a limited subset (e.g. name, photo, company, designation, verification badges, trust metrics, vehicle model, host payment display details) may be visible when browsing rides or profiles. Home/work addresses, phone, email, and emergency contact are not shown publicly.
- Confirmed ride partners: when a booking is accepted or confirmed, counterparties may see contact phone numbers and other details needed to complete the commute and settle payment.
7.2 Service providers (processors)
We use trusted third parties who process data on our behalf:
- Google Firebase — Authentication, Firestore database, Cloud Storage, Cloud Functions, Cloud Messaging, Analytics, Crashlytics, and App Check
- Google Maps Platform — Places autocomplete, geocoding, and routing for addresses you search or enter
- OpenRouteService — routing fallback (where configured)
- Razorpay — Poolzy Plus subscription payments (UPI checkout)
- Resend — delivery of work-email verification OTP messages from verify@poolzy.in
These providers may process data on servers located outside India. We require them to protect data under their terms and applicable law.
7.3 Legal and safety
We may disclose data if required by law, court order, or government authority, or when necessary to protect the rights, safety, or property of Poolzy, our users, or the public.
We do not sell your personal data.
8. Permissions and device features
The app may request the following permissions. You can decline non-essential permissions, though some features may not work.
- Notifications: ride updates, chat messages, payments, and system alerts
- Camera / photo library: profile photo upload
- Internet: required for all core features
Poolzy does not request continuous or background device location access in the current app version. Safety center actions (call and SMS) use your phone’s dialer and messaging apps — you choose whether to send a message or place a call.
9. Analytics, crash reporting, and your choices
- Usage analytics (Firebase Analytics): On by default. You may opt out anytime in Settings → Usage analytics. When disabled, we stop collecting analytics events from your device.
- Crash reporting (Firebase Crashlytics): Enabled to diagnose app crashes and stability issues. This is not currently user-toggleable because it is essential for reliability.
- Push notifications: You can disable ride-update and chat-message pushes in Settings. System and payment-related notifications may still be sent where necessary for service operation.
10. Data retention
- Active accounts: we retain data while your account is active and as needed to provide the service.
- OTP challenges: work-email verification codes are stored in hashed form and automatically deleted after expiry (typically within minutes) or successful verification.
- Rate-limit records: automatically purged after approximately 7 days.
- Payment records: subscription payment metadata may be retained as required for accounting, tax, and dispute resolution.
- After account deletion: see Section 11 below.
11. Account deletion
You may permanently delete your account in Settings → Delete account by typing DELETE to confirm. Deletion is blocked while you have upcoming confirmed ride commitments.
What we delete: your user profile, public profile, profile photo, phone/work-email directory entries, referral code mapping, notifications, wallet transaction history, subscription document, trust event subcollections, commute templates, waitlist entries, and your Firebase Authentication account.
What may remain: for legal, safety, fraud-prevention, or operational integrity, we may retain certain records that reference your past activity in anonymized or pseudonymous form, including historical ride and booking records, chat messages tied to completed rides, commute feedback, referral attribution logs, and subscription payment records. Where feasible, personal identifiers in those records are removed or disassociated from your deleted account.
12. Security
We use industry-standard measures including encryption in transit (HTTPS/TLS), Firebase security rules, server-side validation for sensitive operations (OTP, payments, account deletion), Firebase App Check on production builds, and access controls limiting data reads/writes by role. No method of transmission or storage is 100% secure.
13. Your rights
Subject to applicable law (including the DPDP Act), you may:
- Access and update profile information in the app
- Withdraw consent for optional processing (e.g. analytics) via in-app settings
- Request correction of inaccurate data
- Delete your account as described above
- Lodge a grievance with our contact below
We will respond to verified requests within timelines required by applicable law.
14. Children
Poolzy is not directed at persons under 18. We do not knowingly collect personal data from children. If you believe a minor has provided data, contact us and we will take appropriate steps to delete it.
15. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated in-app, by email where appropriate, or by updating the effective date above. Continued use after changes constitutes acceptance where permitted by law.
16. Contact & grievance redressal
For privacy questions, data requests, support, or grievances under the DPDP Act:
Email: poolzy.in@gmail.com
Location: Pune, Maharashtra, India
We aim to acknowledge grievances within 24 hours and resolve them within timelines prescribed by applicable law.