UniRide Privacy Policy
Effective date: July 10, 2026
Contact: jatrabot.bd@gmail.com
UniRide is a ride-sharing platform exclusively for verified university students in Bangladesh. This policy explains what personal information we collect, why we collect it, how we use and share it, and the choices you have. If any of it isn't clear, email us at the address above.
1. Who we are
UniRide ("we", "us") is operated as a student project by the account holder of the ailogybd.xyz domain. Contact for privacy questions, data-access requests, or complaints: jatrabot.bd@gmail.com.
2. What we collect and why
We only collect what's needed to run the service safely.
2.1 Account information (required to sign in)
- University email address — proves you're a current student at an approved university, and used as your login and for password-reset codes.
- Full name — shown to your driver / passenger during a ride so you can find each other.
- Phone number (Bangladesh mobile,
+8801XXXXXXXXX) — used for in-app calling between driver and passenger, and to receive SMS from your emergency contacts if you trigger SOS during a ride. - Password — stored as a bcrypt hash. We never see or store your plain password.
2.2 Location (only while you're actively using the app)
- Live GPS location — used to match you with a nearby driver, to show the driver's live position to the passenger during a ride, and to compute distance-based fares. Location is streamed only while you have the app open and either (a) you are a driver who has toggled "online" or (b) you are a passenger with an active ride request or trip.
- We do not collect location in the background when the app is closed.
- We do not sell, rent, or trade your location data.
2.3 Driver-only: verification documents
If you apply to be a driver, we collect:
- Student ID, driving license, vehicle registration, insurance (if provided), vehicle photo, and a profile photo.
- These are stored on Cloudinary (our image host) and reviewed by a human admin. Only the reviewing admin sees them; other users see only your name, profile photo, vehicle model, and plate number.
2.4 Trip data
- Pickup and destination addresses, distance, duration, fare, timestamps, payment method, driver rating.
- Kept for accounting, dispute resolution, and legal compliance.
2.5 Emergency contacts (optional)
If you add emergency contacts, we store the name and phone number you enter. We only send them a message (SMS or system link) if you press the SOS button during a ride.
2.6 Automatically collected
- Device info (Android version, device model) — used for debugging and analytics on which devices need attention.
- Session tokens — cryptographic tokens stored on your device to keep you signed in. Not shared.
- Server logs — IP address, timestamps, endpoint, and status. Kept for up to 30 days for security and debugging.
3. What we do NOT collect
- We do not track you across other apps or websites.
- We do not collect your contact list from the phone (only the emergency contacts you explicitly add).
- We do not access your camera roll, microphone, or SMS inbox.
- We do not use third-party advertising SDKs.
4. Who we share it with
- The driver / passenger on your specific ride sees your name, profile photo, phone number, live location during the trip, and rating.
- Our infrastructure providers — Railway (backend hosting), MongoDB Atlas (database), Cloudinary (photos and documents), Resend (email delivery for OTPs and receipts). Each provider stores data on our behalf under their own security controls.
- Admin staff at your university — only if a report or SOS is filed, and only the specific incident detail.
- Law enforcement — only when we receive a valid legal request under Bangladeshi law.
We do not sell your personal information to anyone.
5. How long we keep it
- Account, phone, name — until you delete your account.
- Trip history — 3 years, for accounting.
- Verification documents — until you delete your account, then deleted within 30 days.
- Server logs — 30 days.
- Location during a trip — 30 days for support/dispute reasons, then deleted.
6. Your rights
You may:
- See the personal data we hold about you — email jatrabot.bd@gmail.com.
- Correct anything wrong — most fields are editable in-app; for the rest, email us.
- Delete your account and all associated data — email us; we complete deletion within 30 days.
- Withdraw driver documents — email us; we remove them within 30 days.
- Object to specific processing — email us and we'll explain what we can and can't turn off while still providing the service.
7. Security
- Passwords are stored as bcrypt hashes with cost factor 12.
- All API traffic is encrypted in transit (HTTPS/TLS).
- Session tokens are rotated on every refresh, and revoked immediately on password reset or explicit logout.
- Verification documents are stored on Cloudinary with private-access URLs.
- We follow standard practices; no service can guarantee absolute security.
8. Children
UniRide is only for verified university students, which in Bangladesh means adults 18+. We do not knowingly serve users under 18. If you believe a minor has an account, email jatrabot.bd@gmail.com and we'll delete it.
9. International transfer
Our servers are hosted with Railway in the United States and our email delivery uses Resend, also in the United States. By using UniRide you consent to this cross-border transfer under Bangladeshi personal data regulations.
10. Changes to this policy
We'll update this page and change the "Effective date" at the top. Material changes will be announced in-app.
11. Contact
For urgent safety issues during a live ride, use the in-app SOS button rather than email.