Version 2026-09-draft
Privacy policy
Draft for legal review. Values marked [to be confirmed] are not yet set by XRide.
Controller
XRide [legal entity and privacy contact to be confirmed] is responsible for your personal data.
What we collect
Mobile number and verification records; name and optional email; saved addresses and landmarks; trip details including airport, flight, passengers and luggage; passenger contact if you book for someone else; payment references; support messages; security logs such as IP address.
Why we use it
To verify your account, review and fulfil ride requests, contact you and your driver about a trip, record payments and refunds, provide support, prevent abuse, and meet legal obligations.
Who we share it with
Your assigned driver sees only the details needed for your trip. Service providers process data for us: SMS delivery (GENNET), hosting (Cloudflare), and payment providers when enabled.
International processing
Some providers may process data outside Bangladesh. [Transfer safeguards to be confirmed under the Personal Data Protection Act, 2026.]
How long we keep it
Account data while your account is active; trip and payment records for [period to be confirmed] to meet legal and accounting duties; verification codes are short-lived and stored only as secure digests.
Your rights
You can request access, correction or deletion. Some trip and financial records must be kept even after account deletion.
Marketing
Verification messages are not marketing. We send marketing only with your separate permission.
Security
We use encrypted connections, hashed verification codes and sessions, and role-based staff access with audit logs.
Changes
We will post changes here with a new version date.