Privacy Policy
Last updated: July 22, 2026
1. Information We Collect
We collect account information (name, email, phone number, company data), usage data (platform interactions, activity logs), location data (GPS from drivers and passengers during active trips), payment information (processed by PCI-DSS certified providers), and device data (type, operating system, app version).
2. How We Use Your Information
We use the collected information to provide, maintain, and improve the Service; process trips, payments, and communications between users; send service-related notifications; ensure security and prevent fraud; comply with legal obligations; and generate anonymized statistics.
3. Categories of Recipients
We do not sell your personal information. We share data only with: (a) other service users when necessary to complete a trip or order (driver name and phone, real-time location); (b) infrastructure providers: Stripe (payment processing), Mailgun and SendGrid (email), Twilio and Meta's WhatsApp Business API (messaging), Google Firebase (push notifications and authentication), Cloudflare (CDN and protection), Vercel (hosting), Neon (database), Sentry (error monitoring); (c) local tax processors as required by country; (d) authorities when required by law; (e) in emergencies to protect user safety; (f) third-party applications you have authorized via OAuth (see Section 11).
4. Data Security
We implement technical and organizational security measures including encryption in transit (TLS), secure storage, role-based access control, and continuous monitoring.
5. Data Retention Timelines
We apply the following timelines: (a) operator, driver, or rider account data: while the account is active, plus up to 30 days after a deletion request for backup cleanup; (b) trip and payment transaction records: 7 years for tax requirements (Mexico, Argentina, Colombia, Peru, Chile) or as required by local law; (c) activity logs and technical logs: 90 days by default, up to 12 months for fraud or security investigation; (d) in-app messages between users: 90 days or until both parties delete them; (e) anonymized data for statistical purposes: indefinitely; (f) encrypted backups: 35 days on rotation. You may request earlier deletion at [email protected] — some data may be retained for legal obligations that we will explicitly notify you of.
6. Your Rights
Depending on your jurisdiction, you may have the right to access your personal data, correct inaccurate data, request deletion of your data, object to processing, request data portability, and withdraw your consent at any time.
7. Cookies and Similar Technologies
We use cookies and similar technologies to maintain user sessions, remember preferences, and analyze Service usage. You can configure your browser to reject cookies, although this may affect functionality.
8. International Transfers
Your data may be processed on servers located in different countries. We ensure these transfers comply with applicable data protection laws through appropriate contractual clauses.
9. Minors
The Service is not directed at individuals under 18 years of age. We do not intentionally collect information from minors. If we detect that we have collected data from a minor, we will delete it immediately.
10. Changes to this Policy
We may update this Privacy Policy periodically. We will notify you of significant changes through the Service or by email.
11. AI Agents and Third-party Applications (OAuth)
You may authorize third-party applications — including AI assistants like Claude Desktop, ChatGPT, or other MCP clients — to access your account via OAuth 2.0. Before authorizing, we show you exactly which scopes (permissions) the application requests; you decide what to grant. The application can only access the data those scopes allow. You can revoke access at any time from Dashboard → Settings → Authorized apps. Once revoked, every token issued to that application is invalidated immediately and the app can no longer act on your behalf. Requests those applications make are logged with their application ID for auditing. We do NOT share your credentials (password, OTP codes) with those applications — the OAuth flow guarantees that only scoped tokens are exchanged.
12. Cabgo Plugin for OpenAI
The public Cabgo plugin for OpenAI is limited to creating and configuring an app workspace. Its inputs are limited to business type, brand name and optional brand color, workspace selection, branding and service-type configuration, and app-build actions. This surface does not solicit or process rider or driver records, precise location, identity documents, government identifiers, biometric or health data, payment-card or financial-account data, passwords, authentication codes, or API keys. OpenAI receives a limited OAuth token, not your Cabgo credentials. Configuration data is retained while the workspace is active and follows the timelines in Section 5.
13. Contact
To exercise your rights or for any inquiries, contact us via WhatsApp (+1 484 445-8210) or by email at [email protected].