Car Cab Organization: Privacy Policy:

Last updated: April 7, 2026

Car Cab Org ("we," "us," or "our") operates the Car Cab Org mobile application (the "App") and the Car Cab Org website (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.

By using the Service you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the Service.

1. Information We Collect

Account Registration

Email address, phone number, account type (Customer or Driver), and password. Passwords are stored as a secure hash via Firebase Authentication — we never store plaintext passwords.

Identity & Compliance Documents

Government-issued photo ID or driver's license image, profile or face-verification photo, vehicle insurance documents (drivers), additional onboarding documents you choose to upload, and document expiry dates used for automated compliance reminders.

Community-Service Registration

Full name, phone number, email, shift selection and attendance records, and supporting documents you upload such as court-issued paperwork.

Trip & Location Data

Pickup and drop-off addresses you enter when requesting a ride, trip history, and real-time device location only while the App is in active use and only when you have granted location permission.

Payment Information

Membership and donation payments are processed by Stripe. We do not store your full card number, CVV, or bank account details on our servers. We retain a record of the transaction amount, type, and associated email address.

Communications

SMS one-time passcodes sent via Twilio for phone verification, and transactional emails (payment receipts, compliance reminders, court OTP codes) sent via SendGrid.

Technical Data

Device type, operating system, App version, IP address (used for security only), and crash logs that contain no personal identifiers.

2. How We Use Your Information

- Provide the Service — account creation, ride matching, trip management, driver dispatch.

- Verify identity — confirming phone numbers and reviewing documents to keep the community safe.

- Process payments — charging and recording memberships and donations through Stripe.

- Community service tracking — registering participants, recording shift attendance, and communicating scheduling information.

- Compliance reminders — sending automated email alerts when uploaded documents are nearing expiry.

- Safety and fraud prevention — detecting and blocking unauthorized access or misuse.

- Legal obligations — retaining records as required by applicable law.

3. How We Store Your Information

All user data, documents, and trip records are stored in Google Firebase (Firestore database and Firebase Storage), hosted on Google Cloud infrastructure in the United States. All data in transit is encrypted using TLS. Firebase Security Rules restrict read/write access to authenticated users and their own records. Service account credentials are stored as server-side environment variables and are never embedded in the App binary. Passwords are managed exclusively by Firebase Authentication and are never stored in plaintext.

4. Sharing of Your Information

We do not sell your personal information. We share data only in these limited circumstances:

- Service providers — Stripe, Twilio, SendGrid, and Google Firebase. Each processes data only as needed to perform their service.

- Drivers and customers — When a ride is matched, the driver receives the customer's pickup location and first name only. No additional contact information is shared through the App.

- Legal requirements — If required by law, court order, or to protect the rights and safety of users or the public.

- Business transfer — In the event of a merger, acquisition, or sale of assets, your data may transfer to the successor entity under the same privacy commitments.

5. Data Retention

- Active account data is retained for as long as your account remains open.

- Trip records are retained for a minimum of 12 months for safety and dispute-resolution purposes.

- Community-service attendance records are retained for the duration required by the referring court or agency.

- Payment records are retained for 7 years to comply with financial and tax regulations.

- Upon account deletion, personal profile data is removed within 30 days, except where retention is legally required.

6. Your Rights

Depending on your jurisdiction you may have the right to access, correct, or delete your personal data; receive your data in a portable format; object to or restrict certain processing activities; and withdraw consent at any time. To exercise any of these rights, please contact us at the address in Section 9.

7. Children's Privacy

The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it promptly.

8. App Permissions

Location (foreground) — To enable ride requests and driver dispatch. Only active while the App is in the foreground.

Camera — To capture profile photos and face-verification images during onboarding.

Photo Library / Media — To upload existing photos of identity documents and Community Service paperwork.

Notifications (optional) — To deliver ride status updates and compliance reminders. You can decline this permission.

9. Contact Us

Car Cab Organization

319 S. 17th Street, Suite 416

Omaha, NE 68102

Email: David@carcab.org

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top and, for material changes, notify you via the App or by email. Continued use of the Service after the effective date of any change constitutes your acceptance of the updated policy.