Encrypted in transit
TLS 1.2/1.3 on all connections
Encrypted at rest
AES-256 via Supabase infrastructure
Data deletable
Full account deletion on request
Data Types Collected & Shared
The table below mirrors the exact categories in Google Play's Data Safety form.
| Data Type | Collected | Shared | Encrypted | Deletable | Purpose |
|---|---|---|---|---|---|
| Precise Location | Yes | Yes | Yes | No | Driver matching, fare calculation, ride tracking |
| Approx. Location | Yes | No | Yes | No | Fallback when GPS unavailable |
| Name | Yes | Yes | Yes | Yes | Account, driver identification |
| Phone Number | Yes | Yes | Yes | Yes | OTP login, driver contact |
| Email Address | Yes | No | Yes | Yes | Account management, comms |
| Profile Photo | Yes | No | Yes | Yes | Personalisation (optional) |
| Pickup/Dropoff Address | Yes | Yes | Yes | Yes | Ride booking, driver navigation |
| Ride History | Yes | No | Yes | Yes | App functionality, receipts |
| Parcel Details | Yes | Yes | Yes | Yes | Delivery (receiver name/phone/description) |
| Device/Push Token | Yes | Yes | Yes | Yes | Push notifications via Expo |
| Crash Logs | Yes | Yes | Yes | No | Analytics, bug fixing (anonymous) |
| Payment Info | No | No | Yes | No | N/A — cash-only app |
| Contacts | No | No | No | No | N/A — not accessed |
| Microphone/Audio | No | No | No | No | N/A — permission reserved for future SOS feature; not active |
| Background Location | No | No | No | No | N/A — never collected |
Location marked “not deletable” because it is transient (not stored post-ride). Crash logs are anonymous and cannot be linked back to a user account.
Purpose of Each Data Type
Third Parties We Share Data With
Assigned Driver (DriveKaro Platform)
Data shared: First name, phone, pickup/dropoff addresses
Why: Service delivery (ride/parcel fulfillment)
Supabase Inc.
Privacy policy →Data shared: Account data, ride data, location
Why: Database hosting, authentication, real-time sync
Google LLC
Privacy policy →Data shared: Location coordinates, address search queries
Why: Map display, geocoding, routing (Google Maps SDK)
Expo (expo.dev)
Privacy policy →Data shared: Device push token, crash/error logs
Why: Push notification delivery, error tracking
We do not share data with advertising networks, data brokers, or analytics companies for marketing purposes.
Android Permissions Explained
| Permission | Required | Why needed |
|---|---|---|
| ACCESS_FINE_LOCATION | Required | Precise GPS for driver matching, fare calc, and ride tracking |
| ACCESS_COARSE_LOCATION | Required | Network-based fallback when GPS is unavailable |
| INTERNET | Required | All server communication (rides, auth, maps, notifications) |
| VIBRATE | Required | Haptic alerts for driver arrival and ride status updates |
| READ_EXTERNAL_STORAGE | Optional | Read gallery image for profile photo upload (user-initiated) |
| WRITE_EXTERNAL_STORAGE | Optional | Required on Android ≤ 9 (API 28) for app cache; scoped storage on newer versions |
| RECORD_AUDIO | Optional | Reserved for future in-app SOS voice feature — NOT active in v1.0 |
| SYSTEM_ALERT_WINDOW | Optional | Show ride-status overlay when user switches apps during an active ride |
ACCESS_BACKGROUND_LOCATION is not declared — the app never tracks your location when closed.
Your Data Controls
Revoke location
Settings → Apps → DriveKaro Rider → Permissions → Location
Disable notifications
Settings → Apps → DriveKaro Rider → Notifications → Block all
Edit your profile
In-app → Drawer menu → Profile → Edit
Questions about your data?
Email syedshahwarhassan87@gmil.com with your registered phone number. We respond within 30 days. For account deletion visit drivekaro.site/delete-account.