01. Overview & Privacy Principles
At BirdieGlobal, privacy and safety are core architectural commitments, not afterthoughts. We operate a community-first ride-sharing marketplace serving Hampton Roads, Virginia, where riders set their desired fare and vetted drivers bid openly.
Our systems are deliberately engineered to minimize unnecessary data collection. We do not sell personal data, we do not participate in third-party behavioral advertising tracking networks, and we never store raw credit card numbers or sensitive payment card secrets on our application servers.
02. Information We Collect & How We Collect It
We collect information directly from you when you register, use our mobile applications, complete trips, or contact our support team. The specific data categories collected in accordance with our data model include:
Phone Number: We require your mobile phone number formatted according to the E.164 international standard (e.g., +17575550199). Authentication is conducted via 6-digit one-time SMS verification codes (OTP). Verification codes are ephemeral and are never stored in plaintext format. Optional profile fields include first and last name, email address, and profile photo.
Rider Location: When requesting a trip, we record your origin and destination coordinates as GeoJSON Point coordinates ([longitude, latitude]) along with human-readable street labels and optional saved favorite places (e.g., Home, Work).
Driver Telemetry: While online or on an active trip, driver mobile devices transmit real-time GPS coordinates. High-frequency pings are processed in in-memory geospatial indexes (Redis) with automatic time-to-live (TTL) expiration. Once a trip concludes, the final route audit trail and distance/duration calculations are recorded in trip records to settle fares, calculate commission, and resolve disputes.
To ensure community safety, driver applicants must submit photographic verification of their valid driver's license, vehicle registration, personal automobile liability insurance, and background check authorization. These documents are encrypted in transit and at rest using dedicated, secure cloud storage (Cloudinary) and are manually reviewed by authorized BirdieGlobal administrators before a driver profile is activated.
We also collect vehicle details including vehicle identification number (VIN), make, model, model year, exterior color, license plate number, and seating capacity.
All credit and debit card transactions are processed securely through Stripe Connect, a PCI-DSS Level 1 certified payment processor. BirdieGlobal never collects, processes, transmits, or stores full card numbers, CVVs, or expiration dates on its servers. We store only tokenized identifiers (such as Stripe Customer IDs, Payment Intent IDs, and masked card brand/last 4 digits) for transaction history, receipts, and dispute resolution.
For drivers receiving direct bank transfers or debit payouts, payout account details are handled directly through Stripe Connect onboarding. All internal ledger entries and driver wallet balances are recorded as immutable integer cents.
Push Notification Tokens: We collect Firebase Cloud Messaging (FCM) device tokens to deliver critical transactional trip alerts, driver arrival notifications, and fare bids.
Device Fingerprinting: To prevent multi-account coupon abuse, account takeovers, and fraudulent bidding, we generate cryptographic device fingerprint hashes.
Pickup Verification PIN: Each matched trip creates a unique, single-use 4-digit PIN. The trip cannot commence until the driver successfully verifies the PIN provided by the rider.
In-Trip Communications & Trusted Contacts: Ephemeral in-app chat messages between rider and driver are retained for trip completion and safety review. Riders may designate trusted contact phone numbers to receive automated trip progress links.
03. How We Use Your Information
- Facilitating reverse-auction trip matching: broadcasting trip origin/destination to nearby drivers and delivering driver bids to riders without algorithmic surge pricing.
- Validating driver credentials, motor vehicle records, and vehicle safety compliance.
- Enforcing in-trip safety features including 4-digit pickup PIN validation and emergency trusted contact telemetry broadcasts.
- Calculating immutable platform commissions (deducted exclusively from driver earnings) and processing electronic payments through Stripe Connect.
- Detecting, investigating, and preventing fraud, unauthorized account access, GPS spoofing, or safety violations.
- Providing customer support and investigating safety incident reports submitted by riders or drivers.
- Complying with applicable municipal transportation regulations, tax reporting, and lawful legal processes.
04. Sharing & Third-Party Processors
We do not sell, rent, or trade your personal data. We disclose information strictly to authorized service providers under contractual confidentiality agreements:
- Stripe, Inc.: Payment card tokenization, charge processing, and driver automated bank payouts.
- Cloudinary: Secure, encrypted cloud storage for driver verification documents and profile imagery.
- Twilio / Telephony Providers: Delivery of automated SMS one-time authentication codes.
- Google Firebase (FCM): Push notification delivery for real-time trip status updates.
- Map & Routing APIs (OSRM / Mapbox): Road network distance and duration calculations.
- Legal Authorities: Only when legally required by a valid subpoena, court order, or verifiable life-threatening emergency.
05. Data Retention & Disposition
We adhere to strict data retention schedules based on legal necessity and architectural requirements:
- Ephemeral Telemetry: In-memory GPS location coordinates stored in Redis expire automatically after a driver goes offline or completes a trip.
- Account Profiles: User profiles and device tokens are maintained while the account remains active and will be purged upon verified deletion request.
- Statutory Financial Records: Completed trip financial records, transaction receipts, driver wallet ledger entries, and tax documentation are retained for the statutory financial audit period (typically 7 years) as required by federal, state, and local accounting laws.
- Safety & Incident Records: Records relating to verified safety incidents, traffic collisions, or active legal disputes are preserved until the dispute has reached final resolution.
06. Your Rights & Account Deletion
Depending on your state or jurisdiction of residence, you may have the right to request access to your personal information, request correction of inaccurate records, or request permanent deletion of your account.
For full details on our account deletion procedure and data disposition schedule, please review our dedicated Account Deletion & Data Rights Page or email our privacy team directly at privacy@birdieglobal.tech.
07. Contacting Our Privacy Team
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us:
[Company Legal Name]
Attn: Data Protection / Privacy Officer
Address: [Registered Address], [Jurisdiction]
Email: privacy@birdieglobal.tech
