πŸ”’
Plain English: We do not sell your data. We do not collect payment info.

Transit Mesh is a technology marketplace platform that connects authorized drivers and riders. This policy explains exactly what we collect, why, and what rights you have β€” broken down by the laws that apply where you are located.

Contents

  1. Who We Are
  2. What We Collect & Why
  3. What We Do NOT Collect
  4. How We Use Your Data
  5. Data Retention
  6. Biometric & Identity Data (Drivers)
  7. Data Security
  8. No Data Sales
  9. Jurisdiction-Specific Rights
  10. Children's Privacy
  11. Policy Changes
  12. Contact

1Who We Are

Transit Mesh ("Transit Mesh," "we," "us," "our") is a technology platform that operates a peer-to-peer rideshare marketplace. We provide software tools that allow authorized, independently licensed drivers to bid on trip requests posted by riders. Transit Mesh is a technology intermediary β€” we do not provide transportation services, employ drivers, or process payments between riders and drivers.

Platform contact: privacy@transit-mesh.net  Β·  transit-mesh.net

⚠️ Important Legal Distinction Transit Mesh operates as a technology marketplace, not a Transportation Network Company (TNC). Drivers who use this platform are independent, self-employed individuals who are solely responsible for obtaining and maintaining any licences, permits, insurance, and regulatory authorisations required by their local, state/provincial, and national laws.

2What We Collect & Why

We collect only the minimum data required to operate the platform safely and lawfully. The table below lists every category of personal data we collect.

Category Specific Data Why We Need It Legal Basis
Identity (basic) First name, last name Account identification; displayed to matched ride partners Contract performance
Contact Phone number (hashed in storage) Account authentication (OTP); ride coordination Contract performance
Location Pickup / drop-off coordinates (bucketed ~1 km grid) Match riders with nearby available drivers Contract performance; legitimate interest
Trip data Route, distance estimate, time, bid amounts, trip status Platform operations; safety audit trail Contract performance; legitimate interest
Device metadata Browser type, OS, screen resolution, timezone (no persistent ID) Platform compatibility; fraud prevention Legitimate interest
Verification status Pass/fail result of driver identity check; masked licence last-4 Safety β€” confirm drivers hold valid licences before operating Legal obligation; contract performance
Consent records Timestamp, jurisdiction, IP hash of biometric consent Legal compliance (BIPA, GDPR, PIPEDA, AU Privacy Act) Legal obligation
Safety contacts Emergency contact name & phone (optional, user-provided) In-app safety feature; not used for any other purpose Consent

3What We Do NOT Collect

🚫 We never collect any of the following

All raw biometric images (driver's licence photo, selfie) are stored for a maximum of 90 days for verification purposes and then permanently deleted. See Section 6 for full biometric data details.

4How We Use Your Data

We use personal data only for the following purposes:

We do not use your data for: advertising, credit scoring, insurance pricing, profiling for sale, cross-context behavioral advertising, or any purpose not listed above.

5Data Retention

Data CategoryRetention PeriodDeletion Method
Account data (name, phone hash)Duration of account; deleted within 30 days of closure requestPermanent deletion from all systems
Trip records (anonymized)24 months from trip dateIndividual identifiers removed; aggregate data retained
DL image & selfie photographMaximum 90 days from verification datePermanently deleted β€” automated nightly purge
Facial geometry scoreMaximum 90 days from verification datePermanently deleted
Masked licence last-4Duration of driver accountDeleted on account closure
Verification statusDuration of driver accountDeleted on account closure
Biometric consent recordsAccount duration + 1 year (legal audit)Permanently deleted
Safety / emergency contactsUntil deleted by userPermanently deleted on user request
OTP codes10 minutes (automatic expiry)Auto-purged from memory

Illinois drivers: biometric data destroyed within 90 days of last use OR within 3 years of collection, whichever is sooner β€” in compliance with BIPA (740 ILCS 14/15(a)).

6Biometric & Identity Data (Drivers Only)

To protect the safety of all platform members, drivers must complete a one-time identity verification before bidding. This involves processing biometric data as defined under applicable law. This section applies to drivers only β€” riders are not subject to biometric data collection.

πŸ”’ Core Commitment Biometric and identity data is never sold, rented, leased, traded, or shared with any third party for commercial purposes. All processing is local β€” no images are transmitted to external AI services or cloud vision APIs.

Data Collected for Verification

DataPurposeRetained
Driver's licence image (front)OCR: verify name, expiry, jurisdiction-specific format90 days β†’ permanently deleted
Selfie photographFacial comparison with DL photo to confirm identity90 days β†’ permanently deleted
Derived facial geometry scoreNumeric match confidence β€” not a facial template90 days β†’ permanently deleted
Licence number (masked)Format validation β€” last 4 digits only retainedDuration of account
Verification outcomeAllow/block driver access to bidding featuresDuration of account
Consent timestamp & jurisdictionLegal audit record (BIPA/GDPR/PIPEDA compliance)Account + 1 year

How Images Are Protected

Full details: Biometric & Identity Data Consent Notice β†’

7Data Security

In the event of a data breach affecting your personal information, we will notify affected users and relevant regulatory authorities within the timeframes required by applicable law (72 hours under UK GDPR; without unreasonable delay under PIPEDA; as required under applicable US state breach notification laws).

8No Data Sales β€” Ever

πŸ”’ We do not sell, rent, lease, or share your personal data for commercial purposes. We do not engage in cross-context behavioral advertising, targeted advertising based on your profile, or data brokerage. We do not share personal data with data aggregators, advertising networks, or analytics companies.

The only circumstances where we may disclose data are:

9Your Rights β€” By Jurisdiction

Your privacy rights depend on where you are located. Find your jurisdiction below. To exercise any right, contact privacy@transit-mesh.net β€” we respond within 30 days (or the shorter deadline required by your jurisdiction's law).

πŸ‡ΊπŸ‡Έ
California, USA
California Consumer Privacy Act / CPRA β€” Cal. Civ. Code Β§ 1798.100–1798.199.100

California residents have the following rights under the CCPA as amended by the California Privacy Rights Act (CPRA, effective January 1, 2023):

  • Know β€” Request disclosure of the categories and specific pieces of personal information we have collected about you
  • Delete β€” Request deletion of your personal information, subject to legal exceptions
  • Correct β€” Request correction of inaccurate personal information
  • Opt Out of Sale/Sharing β€” We do not sell or share personal data; this right is automatically honored
  • Limit Sensitive Data Use β€” Limit use of sensitive personal information to necessary purposes only
  • Non-Discrimination β€” We will not discriminate against you for exercising these rights
  • Portability β€” Receive a copy of your data in a portable, machine-readable format

Response deadline: 45 days (extendable 45 days with notice). To opt out: privacy@transit-mesh.net

πŸ‡ΊπŸ‡Έ
Illinois, USA
Biometric Information Privacy Act β€” 740 ILCS 14/1 et seq. | Personal Information Protection Act β€” 815 ILCS 530

Illinois residents have specific biometric data rights under BIPA:

  • Right to Refuse β€” You may refuse biometric data collection; this will prevent you from using driver features but will not affect your rider access
  • Written Policy β€” This page and the Biometric Consent Notice constitute the required written policy
  • Retention Schedule β€” Biometric data destroyed within 90 days of last use or account deletion, whichever is sooner (BIPA Β§ 15(a))
  • No Sale or Trade β€” Biometric data will not be sold, leased, traded, or profited from in any way (BIPA Β§ 15(c))
  • No Disclosure β€” Biometric data not disclosed to third parties without separate written consent (BIPA Β§ 15(d))
  • Data Breach Notification β€” Notification under PIPA (815 ILCS 530) if your personal information is compromised

BIPA private right of action: $1,000–$5,000 per intentional violation. We take Illinois compliance seriously.

πŸ‡ΊπŸ‡Έ
Texas, USA
Texas Data Privacy and Security Act β€” Tex. Bus. & Com. Code Ch. 541 (eff. July 1, 2024)

Texas residents have the following rights under the TDPSA:

  • Access β€” Confirm whether we process your personal data and obtain a copy
  • Correct β€” Request correction of inaccurate personal data
  • Delete β€” Request deletion of personal data you have provided or we have collected
  • Portability β€” Obtain a portable copy of personal data in a commonly used format
  • Opt Out β€” Opt out of processing for targeted advertising, sale, or profiling (we do none of these)

Response deadline: 45 days. Enforcement by Texas Attorney General only (no private right of action).

Texas biometric data: We collect biometric identifiers from drivers as defined under Tex. Bus. & Com. Code Β§ 503.001 (Texas Capture or Use of Biometric Identifier Act). Such data is used solely for identity verification and not sold or disclosed to third parties.

πŸ‡ΊπŸ‡Έ
Other U.S. States
Virginia VCDPA (Va. Code Β§ 59.1-571) Β· Colorado CPA (C.R.S. Β§ 6-1-1301) Β· Connecticut CTDPA Β· Florida FDBR Β· Oregon OCPA Β· Montana MCDPA Β· Indiana IDPL Β· Tennessee TIPA

Residents of these states have similar privacy rights under their respective state consumer data protection laws, including rights to access, correct, delete, and opt out of sale or targeted advertising. All such requests are honored within 45 days.

We do not sell personal data, engage in targeted advertising, or use profiling for decisions with significant legal effects. Residents of all these states benefit from these baseline protections regardless of whether their specific state law has a private right of action.

Washington State residents: Additional protections apply under the Washington My Health MY Data Act (SB 1155, eff. March 2024) for any health-related data. Transit Mesh does not collect health data.

Federal baseline: All U.S. residents are protected by the Driver's Privacy Protection Act (18 U.S.C. Β§ 2721) regarding driver's licence information, which is used solely for the permissible purpose of identity verification.

πŸ‡¨πŸ‡¦
Canada
PIPEDA β€” S.C. 2000, c. 5 Β· Quebec Law 25 / An Act to Modernize Legislative Provisions Respecting the Protection of Personal Information (SQ 2021, c 25, eff. Sept 2023) Β· Alberta PIPA (SA 2003, c P-6.5) Β· BC PIPA (SBC 2003, c 63)

Canadian residents have the following rights:

  • Access β€” Request access to personal information we hold about you (PIPEDA Principle 9)
  • Correction β€” Request correction of inaccurate or incomplete personal information
  • Withdrawal of Consent β€” Withdraw consent at any time, subject to legal or contractual restrictions
  • Complaint β€” File a complaint with the Office of the Privacy Commissioner of Canada (OPC)

Quebec residents (Law 25): Additional rights include the right to data portability (eff. Sept 2024), the right to be de-indexed, and the right to object to automated decision-making. Biometric data is considered "sensitive information" under Law 25 and receives the highest level of protection.

A Privacy Impact Assessment (PIA) is maintained as required by Quebec Law 25 for systems involving biometric data. Contact the Privacy Officer for a summary: privacy@transit-mesh.net

πŸ‡¬πŸ‡§
United Kingdom
UK GDPR (as retained by Data Protection, Privacy and Electronic Communications Regulations 2020) Β· Data Protection Act 2018 Β· ICO oversight

Lawful basis for processing:

  • General personal data: Article 6(1)(b) β€” contract performance; Article 6(1)(f) β€” legitimate interests
  • Biometric data (special category): Article 9(2)(a) β€” explicit consent obtained before any biometric processing

Your rights under UK GDPR:

  • Access (Article 15) Β· Rectification (Article 16) Β· Erasure / "Right to be forgotten" (Article 17)
  • Restriction of processing (Article 18) Β· Data portability (Article 20) Β· Object (Article 21)
  • Not be subject to solely automated decisions with significant effects (Article 22)
  • Withdraw consent at any time without affecting lawfulness of prior processing

Response deadline: 1 month (extendable 2 months for complex requests). Complaint: Information Commissioner's Office (ICO)

Data is processed and stored on servers located in the United States (AWS US-East). We rely on standard data transfer provisions for UK-to-US transfers as permitted under the UK-US Data Bridge (eff. Oct 2023).

πŸ‡¦πŸ‡Ί
Australia
Privacy Act 1988 (Cth) Β· Australian Privacy Principles (Schedule 1) Β· Privacy Amendment (Enhancing Privacy Protection) Act 2012

Australian residents have rights under the Australian Privacy Principles (APPs):

  • APP 3 β€” Data collected only for the primary purpose of identity verification (driver safety)
  • APP 5 β€” Notification of collection (this policy)
  • APP 6 β€” Data not used or disclosed for secondary purposes without consent
  • APP 11 β€” Reasonable steps to protect against misuse, interference, loss, and unauthorized access
  • APP 12 β€” Right to access personal information we hold about you
  • APP 13 β€” Right to request correction of inaccurate, out-of-date, or incomplete information

Complaint: Office of the Australian Information Commissioner (OAIC) at oaic.gov.au

For biometric data, we comply with the OAIC's guidance on biometric technologies and the applicable APPs. Sensitive information (including biometric data) is handled with a higher duty of care.

Note on state/territory laws: Australian state and territory privacy laws (e.g., NSW Privacy and Personal Information Protection Act 1998; Information Privacy Act 2009 (Qld)) apply to state government agencies, not private companies. The federal Privacy Act 1988 governs our operations.

🌐
All Other Jurisdictions
OECD Privacy Guidelines Β· UN Guidelines on Privacy Β· Applicable local law

Regardless of where you are located, we apply the following baseline protections to all users:

  • Data minimization β€” collect only what is necessary
  • Purpose limitation β€” use data only for stated purposes
  • Accuracy β€” keep data reasonably accurate and up to date
  • Storage limitation β€” delete data when no longer needed
  • Security β€” appropriate technical and organizational measures
  • No sale β€” personal data never sold for commercial purposes

If your jurisdiction has specific privacy laws not listed here, contact privacy@transit-mesh.net and we will advise on applicable rights.

10Children's Privacy

Transit Mesh is not directed at, and does not knowingly collect personal information from, anyone under the age of 18. Use of the platform β€” whether as a driver or rider β€” requires that you are 18 years of age or older and legally authorized to enter into binding agreements in your jurisdiction.

We comply with the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. Β§ 6501 et seq.) in the United States, and equivalent laws in other jurisdictions. If you believe a person under 18 has created an account, contact us immediately at privacy@transit-mesh.net and we will delete the account and associated data promptly.

11Policy Changes

We may update this Privacy Policy as the platform evolves or as legal requirements change. When material changes are made, we will:

Continued use of the platform after the effective date of a material change constitutes acceptance of the updated policy, except where law requires affirmative re-consent.

12Contact & Exercising Your Rights

Privacy Contact Email: privacy@transit-mesh.net
Response time: 30 days (or shorter deadline required by your jurisdiction's law)
Platform: Transit Mesh Β· transit-mesh.net

You may exercise your rights (access, correction, deletion, portability, consent withdrawal, opt-out) at any time by emailing the address above. Please include your registered phone number (so we can locate your account) and specify the right you wish to exercise. We may ask for additional information to verify your identity before processing certain requests.

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority:

Related documents: Terms of Service Β· Biometric & Identity Data Consent Notice