Scope
This policy covers the Doz rider mobile application, rider account services, scooter and ride operations, customer support, and the public pages that support those services.
It describes the data handled by the current product. It does not create a fixed retention period or a promise about infrastructure controls that are not stated below.
Information we handle
Account and sign-in data
- Name, phone number, email address when supplied, account status, language, and a Google profile photo when that sign-in flow provides one.
- Doz account identifiers and Google or Apple provider subject identifiers used to verify and link sign-in.
- Verification and session records, including OTP activity, refresh tokens, and security-related device information.
Location, rides, and saved places
- Precise location for nearby vehicles, ride start and end, route and active-ride updates, zone enforcement, billing, and parking checks. Background location is used only during an active ride when the feature and permission are enabled.
- Saved home, work, or favorite place labels, addresses, and coordinates.
- Ride history, vehicle identifiers and telemetry, start and end addresses, route points, ratings, comments, and optional or required parking-proof photos with submitted coordinates or address.
- IP address exposure to third-party IP-geolocation services used to suggest a country during phone enrollment; those services return country information.
Payments and account value
When a card is added, Checkout.com Frames runs inside an app-controlled WebView. Card number, expiry, and security code are entered into Checkout-hosted fields. The app receives a Checkout token plus cardholder name, last four digits, expiry, and card scheme and sends those values to the Doz API. Doz also handles payment, transaction, 3DS, wallet, top-up, subscription, discount, loyalty, and purchase records.
Support and other content
- Support subjects, chat messages, ratings, comments, attachment details, optional support photos, and optional support voice recordings.
- Search terms sent for map or address search, deletion reasons when supplied, and other content entered into rider features.
Device and diagnostics
- Device model, operating system and version, app version, generated installation or device identifiers, Expo push token, notification preferences, and app interaction records.
- Crash and performance events when a non-development build has a Sentry DSN configured. Sentry is configured not to send default PII, but the exact fields and provider retention depend on the deployed Sentry project.
- Requests made to app update, map, geocoding, routing, media, authentication, messaging, and hosting providers as those features are used.
How information is used
- Create and secure accounts, complete phone or social sign-in, and maintain sessions.
- Show available vehicles, start and operate rides, calculate charges, enforce service and parking zones, and investigate ride or safety issues.
- Tokenize payment cards, fund wallets, process transactions, and maintain subscription, discount, and loyalty features.
- Answer support requests, deliver messages and notifications, diagnose failures, and operate or improve product features.
- Prevent misuse, enforce terms, resolve disputes, maintain required records, and respond to applicable legal or safety requests.
Permissions and choices
- Location permissions can be changed in device settings. Core rental actions require location; background access is requested for active-ride operation, not general browsing.
- Camera and photo-library access are requested when scanning a vehicle or choosing parking or support media. Microphone access is requested only when recording a support voice message.
- Push notifications can be declined or changed in device settings. Some service communications may still be delivered by another configured channel.
- Saved places and payment methods can be managed in the app. Optional support media and an optional deletion reason do not need to be supplied.
- The reviewed Rider source contains no advertising SDK or personalized-ad feature. Provider practices still need to be assessed separately under store tracking rules.
Retention and account deletion
An authenticated rider can request deletion in the app. A request schedules account-identifier erasure after a 10-day grace period and can be cancelled during that period. An active ride or unsettled payment blocks the request, and processing is deferred if one of those blockers exists when the request becomes due.
When processing completes, direct account fields and sign-in credentials are erased or replaced, access is disabled, and selected saved-place, payment-method, device, push-token, session, and OTP records are purged. Subscription renewal, wallets, and loyalty activity are disabled.
Financial, ride, wallet, subscription, support, loyalty-history, audit, and marketing-suppression records are retained against the anonymized account where the current deletion process requires them. Support text or media, parking proof, ride locations, ratings, and suppression records may still contain information connected to the former account.
For Apple sign-ins with a stored current authorization record, Doz attempts to revoke the Apple authorization when deletion is processed. Older Apple-linked accounts without the stored revocation credential receive instructions to remove Doz from Sign in with Apple in iPhone settings.
No single fixed period for every retained database row, provider object, log, or backup is published in this policy. The accountable owner must approve the record and provider lifecycles that apply to the deployed service.
Security boundaries
The app stores selected credentials in platform secure storage. Release configuration requires HTTPS for the Doz API and configured Sentry endpoint, and Checkout-hosted payment fields use HTTPS. These controls do not prove encryption at rest for every database, object store, log, backup, or provider system.
No online or storage system can guarantee absolute security. Contact us if you believe your account or information has been exposed.
Age limits
The rider service is intended for people who meet the minimum age and other eligibility rules shown in the applicable terms and in-app requirements. Contact us if information may have been submitted by a person who was not eligible to create an account.
Privacy requests
Use the in-app controls for account deletion, permissions, saved places, payment methods, and notification settings. You can also contact us to ask about access, correction, or another privacy request. The available response and any limits depend on the request, retained record, account status, and applicable requirements.
Policy changes
This page may be updated when product behavior, providers, or legal requirements change. The date at the top identifies the version currently published.
Contact us
Questions or privacy requests can be sent to: