Tayer Rider · Privacy
Tayer Rider Privacy Policy
This notice explains what Tayer Rider actually collects, why it is used, where it is shared, and the choices and rights available to you.
Who is responsible and what this notice covers
Otlob Tech, the operator of Tayer ("Tayer", "we", "us"), determines how personal data is used for Tayer Rider and is the data controller unless a provider acts as an independent controller under its own notice. This policy covers the Rider app, rider accounts, trips, support, safety, and related Firebase services.
It does not replace the separate Driver Privacy Policy. A driver receives only the rider and trip information needed to perform an assigned trip and comply with law.
Data we collect
We collect data you provide, data created when you use the app, and limited data received from sign-in, mapping, device, security, and communications providers.
- Account and identity: name, email, Egyptian phone number, optional gender, language, sign-in provider, phone-verification status, acceptance timestamps, and provider profile photo where available.
- Location and places: precise current or last-known coordinates while the app is in use; pickup and destination coordinates and addresses; typed place searches; saved addresses, labels, default status, and use counts.
- Trip and transaction: quotes, offered/agreed cash fare, distance and duration estimates, driver match, order status and timeline, cancellations, ratings, cash settlement, and coarse public pickup/drop-off references.
- Device and communications: push token, authentication/session tokens stored securely on your device, app language, operating environment, and messages or emails you send to support.
- Security and diagnostics: app errors, performance traces, security-integrity signals, suspected tampering or abuse, IP/network and device context included by service providers, and threat reports. Production Sentry is configured not to send default PII, but an error report can still contain technical context.
Precise location — foreground use only
Tayer Rider requests foreground precise or approximate Android location. It uses location while you are actively using location-dependent screens to center the map, show nearby availability, select pickup, calculate a route or quote, and follow the assigned driver during an active trip. Rider does not request Android background-location permission and does not run a Rider background-location service.
Pickup and destination are precise in restricted trip records. Before assignment, the driver-discovery view uses a rounded or jittered area rather than exposing an idle driver’s exact coordinates. After assignment, the rider and assigned driver can access the exact trip details needed to meet and complete the trip.
Google Places and Maps requests may receive your typed query, selected place ID, coordinates, language, and route endpoints. You can deny location permission and manually choose locations, although some features may be less accurate.
Why we use data and our legal bases
We use data to create and secure your account; verify your phone; show maps and places; quote, match, operate, support, and record trips; enable cash settlement and ratings; send transactional notifications; prevent fraud and abuse; investigate safety incidents; enforce terms; improve reliability; comply with transport, tax, consumer, insurance, court, and lawful authority requirements; and establish or defend legal claims.
Depending on the activity, processing is necessary to perform your contract, comply with a legal obligation, protect life or other vital interests, pursue a documented legitimate interest that does not override your rights, or act on your specific consent. Permission to access device location is separate from consent for unrelated uses. We do not use Rider data for third-party advertising or sell it for money.
Who receives data
We disclose only what is reasonably necessary for the stated purpose, subject to contracts and access controls where applicable.
- Assigned drivers receive your first name, pickup/destination, trip status, agreed fare, and contact details needed after assignment. They must use it only for the trip, safety, support, or law.
- Google/Firebase processes authentication, databases, cloud functions, storage infrastructure, app integrity, and push messaging; Google Maps Platform processes maps, places, geocoding, and routes.
- Apple or Google receives data when you choose its sign-in service. Sentry receives configured error, performance, and security diagnostics.
- Authorized Tayer personnel and advisers may access data for operations, support, safety, security, legal, audit, or insurance purposes on a need-to-know basis.
- Police, courts, regulators, the Ministry of Transport, the Personal Data Protection Center, Consumer Protection Authority, tax or insurance bodies may receive data when a valid legal requirement applies. Ride and route records may be supplied as required by Law 87/2018 and its regulations.
- A successor may receive data in a merger, financing, restructuring, or asset transfer, subject to law and continued protection.
International processing
Cloud, maps, sign-in, push, and diagnostics providers may process data outside Egypt, including in the United States, European Economic Area, and other provider locations. The exact country can depend on provider configuration, routing, support, and backup systems.
Where Egyptian law requires it, cross-border processing will depend on the appropriate Personal Data Protection Center license or permit, your consent where required, and contractual and technical safeguards intended to provide adequate protection. Provider location and transfer records must be kept current; contact us for the latest applicable destination information.
Retention and what account deletion currently does
We retain data according to purpose, legal minimums, safety and fraud needs, limitation periods, unresolved claims, and valid authority requests. Egyptian ride-hailing rules require trip and route records to be kept for at least six months. Some financial, incident, consent, and legal records may need to be kept longer. Authentication credentials and push tokens are kept only while needed for account access and notifications.
In the current Firebase MVP, using Delete Account deletes your Firebase Authentication credential and marks the main profile as deleted. It does not yet automatically erase the profile document, saved-address subcollection, trip/order history, event records, or legally retained records. Those records may therefore remain until a verified manual deletion or anonymization process is completed, except where retention is legally required or necessary for claims, safety, fraud prevention, or public interest.
This technical limitation does not remove your statutory right to request erasure or restriction. Email us after deleting the account if you want the remaining eligible records reviewed. We will verify identity, explain any lawful exception, and confirm the action taken. Backups may persist for a limited restoration cycle and are isolated from ordinary use.
Your privacy rights
Subject to Egyptian law and lawful exceptions, you may ask to know whether we process your data; access or obtain a copy; correct or complete it; erase it; restrict or stop processing; object to certain processing; withdraw consent without affecting earlier lawful use; and challenge a decision based solely on automated processing where applicable. You may also complain to the Egyptian Personal Data Protection Center.
Send a request from the email or phone associated with your account. We may request proportionate verification and may withhold information that would expose another person’s data, compromise security, violate law, or prejudice a protected investigation. We will explain a refusal where legally permitted.
Security and incident response
We use Firebase access rules, separation of exact private trip details from coarse discovery data, encrypted transport, secure on-device token storage, App Check, integrity monitoring, restricted administrative access, and logging. No connected service is completely secure, so keep your device and account protected and report suspicious activity promptly.
If a personal-data breach requires notice, we will notify the Personal Data Protection Center and affected people within the periods and by the methods required by applicable law, and will take steps to contain and remediate it.
Ratings, safety signals, and automated support
The system calculates ratings and may use rule-based signals such as repeated cancellations, invalid requests, app tampering, or abnormal activity to prevent fraud and protect trips. A serious restriction should be reviewable by support. We do not currently use solely automated decisions to make legal or similarly significant decisions about riders without a review path.
Children
Rider accounts are intended for people aged 18 or older. Do not create an account for an unaccompanied child or submit a child’s data without lawful authority. If we learn that we collected a child’s account data improperly, we will restrict it and take appropriate deletion or protection steps, subject to safety and legal recordkeeping.
Changes to this notice
We may update this notice when features, providers, locations, or laws change. We will publish the new effective date and provide prominent notice or request consent where required. Materially new data uses will not be hidden in a routine update.
Privacy contact
Send privacy questions or rights requests to support@otlobtech.com with “Rider privacy” in the subject. Do not email passwords or full identity documents unless we provide a secure verification method.
support@otlobtech.com