Legal

Privacy Policy

This Privacy Policy explains what personal information BoolRider collects, how we use it, who we share it with, and what rights you have regarding your data.

BoolRider LLC ("BoolRider," "we," "us," or "our") operates the BoolRider mobile application and website (www.boolrider.com) (collectively, the "Service"). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and what rights you have regarding your data.

By creating an account or using BoolRider, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.

1. Who We Are

BoolRider is a technology platform that facilitates cost-shared ridesharing arrangements among verified college students. We are a limited liability company organized under the laws of the State of Illinois. For privacy-related inquiries, you may contact us at:

2. Eligibility

BoolRider is intended for users who are at least 18 years of age and hold a valid .edu email address from a participating college or university. We do not knowingly collect personal information from anyone under the age of 18. If we learn that we have collected data from a person under 18, we will promptly delete that information.

3. Information We Collect

3.1 Information You Provide Directly

When you create an account and use BoolRider, you may provide us with:

  • Account Information: First name, .edu email address, password (stored only in hashed form), university name, and expected graduation year.
  • Profile Information: Profile photo, gender (self-reported, used for optional trip preference filtering), and optional social handles — Instagram, Spotify, and Apple Music. We store the handle only. We never ask for, receive, or store credentials for those services, and we do not connect to them on your behalf.
  • Identity Verification: For drivers, government-issued identification must be submitted through our payment processor, Stripe. As part of this verification process, you will be required to complete a live facial verification, which confirms you are the person depicted on the identification document you submit. BoolRider does not receive, access, or store your government-issued ID document or facial verification data. Both are processed entirely by Stripe in accordance with Stripe's privacy policy and terms of service. For more information about how Stripe collects and handles biometric data, please review Stripe's privacy policy at https://stripe.com/privacy.
  • Facial Verification (Drivers Only): To verify a driver's license, Stripe captures a live photo of your face and compares it to the photo on your license. BoolRider does not perform this scan and never stores it; Stripe does both. See Section 3.5 for the full explanation, including consent, retention, and deletion.
  • Driver Information: If you register as a driver, you may provide your driver's license number, vehicle make and model, vehicle color, license plate number, and proof of automobile insurance for the vehicle you use. License plate numbers are collected to support safety and incident reporting, and are masked in the app interface. Driver documents (such as a photo of your license or proof of insurance) are stored in private, access-controlled storage buckets and are accessible only to you and authorized BoolRider operations personnel via time-limited signed URLs.
  • Auto-Insurance Documents (Drivers Only): To post rides, you must upload proof of current automobile insurance — a photo or PDF of your insurance card or policy declaration. The file is stored in a separate private storage bucket and is reviewed by a BoolRider operations reviewer, not by an automated system. The review confirms only that a current policy exists for the vehicle; BoolRider does not verify the policy's coverage terms, including whether you are a covered driver or whether the policy permits carrying passengers in a cost-shared arrangement. From the document, the reviewer records the insurer's name, the policyholder's name, and the policy expiration date, so we can tell you before your coverage lapses. We also keep the file type, file size, and the original filename you submitted. We never place your name, filename, or any other personal detail into the stored file's path. Every submission you make is kept — including ones that were rejected or replaced — so the review has a history; all of them are deleted when you delete your account.
  • Payout Destination (Drivers Only): To be paid for a completed ride, you must give us a Venmo username or a Zelle handle. A Zelle handle is an email address or a U.S. mobile number, so if you choose Zelle you are giving us a contact detail. We store the handle only. We never ask for, receive, or store your bank account number, routing number, card number, or any login credential for Venmo, Zelle, or your bank, and we do not connect to those services on your behalf. Your payout handle is visible only to you and to authorized BoolRider operations personnel who send the payment; it is never shown to another user. See Section 4 for how payouts are made.
  • Trip Information: Pickup and drop-off locations, departure windows, date and time flexibility, number of bags, round-trip preferences, cost contribution, and any notes you include with a trip listing or booking request. Destination locations displayed on the map are coarsened to an approximate area and never reflect an exact address. When you type an address into the app's location search, the text you type is sent from your device to a third-party OpenStreetMap geocoding service to return suggestions. That request carries the search text only — it is not accompanied by your name, your account, or any BoolRider credential.
  • Communications: Messages you send through in-app chat (both pre-booking conversations and post-booking messaging). BoolRider does not facilitate communication via SMS, phone calls, or any channel outside the app. No phone numbers are shared between users.
  • Ratings and Reviews: Star ratings and optional written feedback you leave for other users after a completed trip.
  • Reports and Blocks: If you report or block another user, we store the details of that action for safety and moderation purposes.
  • Trip Preferences: Optional preferences such as "No smoking" or "Music ok" that are displayed on your profile.
  • Saved Destinations: If you save a frequent destination, we store an approximate area (not an exact address).
  • Payment Information: Riders pay by credit or debit card or through a digital wallet such as Apple Pay or Google Pay. Payment method details are collected and processed entirely by Stripe. BoolRider stores only non-sensitive display data — specifically, the card brand (e.g., "Visa"), last four digits, and wallet type (e.g., Apple Pay, Google Pay) — so you can recognize the method you saved. We never receive, transmit, or store full card numbers, CVCs, or expiration dates.

3.2 Information Generated Through Use

As you use BoolRider, we automatically generate and store:

  • Trip History: Records of trips you have posted or booked, including routes, timestamps, and cost contributions.
  • Financial Records: An append-only ledger of all payment-related events (authorizations, captures, refunds, adjustments) associated with your bookings.
  • Reliability and Reputation Data: Your average rating, number of completed trips, response rate, and reliability score, calculated over a rolling window of your activity.
  • Price Quotes: For every booking request, the price you were shown and approved — the seat price, the service fee, and the total — kept as an immutable record so that what you were charged can always be matched to what you agreed to.
  • Notifications: Records of in-app notifications and push notifications sent to you (booking requests, acceptances, cancellations, messages, payout setup reminders, and insurance-expiration reminders), and the push-notification device token your device registers so those notifications can reach it.
  • Authentication Events: Hashed email verification and password reset tokens with expiration timestamps. Raw tokens are never stored.
  • Policy Acceptance Records: The version of the Terms of Service you accepted and when you accepted it, and — for drivers who verify a license — the facial-verification consent record described in Section 3.5. These are the record that you agreed to the documents in force at the time.
  • Safety and Moderation Records: If a message or listing you submit is refused by our content filter, we record that it was refused, which field it was in, and a masked excerpt — not the full text — so that repeated attempts can be reviewed by our operations team. We also record account enforcement state: whether an account is active, temporarily restricted from messaging or from posting and requesting rides, suspended, or banned.

3.3 Information from Third Parties

  • Stripe: Confirmation of identity verification status and payment processing results. BoolRider receives verification outcomes (passed, pending, or rejected) but not the underlying identity documents or biometric data. Stripe also notifies us of payment events on your bookings — successful and failed charges, refunds, and disputes or chargebacks raised through your bank or card issuer — which we record in the financial ledger described in Section 3.2.

3.4 Information We Do NOT Collect

  • We do not collect or store biometric data — no facial scans, fingerprints, voiceprints, or anything similar. Drivers who verify a license complete a live facial verification, but that is performed and stored entirely by Stripe, not by BoolRider; we receive only whether the check passed. See Section 3.5.
  • We do not collect real-time or continuous location data. We collect only the pickup and drop-off locations you provide for a specific trip.
  • We do not use cookies, web beacons, pixel tags, or similar tracking technologies. The app stores a small amount of data locally on your own device — your sign-in token and the version of our policies you last agreed to — so that you stay signed in. That data stays on your device, is not used to track you, and is cleared when you sign out.
  • We do not collect information from social media or music accounts beyond the Instagram, Spotify, and Apple Music handles you voluntarily provide. We never receive credentials for those accounts and never connect to them on your behalf.
  • We do not collect your bank account details, routing numbers, or payment credentials. For driver payouts we hold only a Venmo username or Zelle handle, as described in Section 3.1.
  • We do not currently use any analytics, advertising, or behavioral tracking tools in the app.

3.5 Facial Verification (Drivers Only)

This section applies only to users who verify a driver's license in order to post rides. BoolRider does not perform facial scans and does not store them. The verification is performed entirely by Stripe, Inc., our identity and payment processor. This section explains what happens, because you are entitled to know what is done with your face even when we are not the ones doing it.

What happens. When you verify your license, Stripe Identity captures a live photo of your face and photographs of the front and back of your driver's license, reads the information printed on the license, and compares your live photo to your license photo. That comparison produces a scan of your facial geometry, which is a biometric identifier under Illinois law and the law of several other states.

Who does it, and who holds it. Stripe. Every part of it — the capture, the comparison, and the storage — happens on Stripe's systems under Stripe's Privacy Policy (https://stripe.com/privacy). BoolRider receives only the outcome: passed, pending, or rejected. We never receive, view, or store your photographs, your license images, or your facial geometry scan, and there is nowhere in our systems that any of them could be kept.

Why. Solely to confirm your identity and your eligibility to drive on BoolRider, so that riders are sharing a car with the person the profile claims, and to prevent fraud and impersonation. Neither we nor Stripe, acting for us, use it for advertising or profiling.

Your consent, before anything happens. We ask for your agreement before any verification can start. You are shown a specific notice explaining the facial verification, and only after you agree do we open a verification session with Stripe. This is enforced by our servers, not merely by the app, so the check cannot begin without your consent on file. When you agree, we record your account identifier, the version of the notice you were shown, the version of this Privacy Policy in force at that moment, and the date and time. If we materially change either document, your earlier agreement stops being sufficient and we ask again before any further verification.

Retention and deletion. Because Stripe holds this data, Stripe's retention schedule governs it. Under our agreement with Stripe it is retained while your account is active and for up to three (3) years after your account closes, or until the purpose of the collection has been satisfied — whichever comes first — and is then permanently destroyed, unless a longer period is required by law. You may request deletion at any time by contacting us at privacy@boolrider.com and Stripe at privacy@stripe.com. We will pass your request on; the deletion itself is Stripe's to perform.

Your consent record. We keep the record that you consented — the notice version, the policy version, and the date — including after you delete your account, attached to an anonymized account identifier. It is the only proof that we asked before anything happened. It contains no biometric data and cannot be used to identify or re-identify you.

4. How We Use Your Information

We use the information we collect for the following purposes:

  • To Provide the Service: Matching riders with drivers who have posted compatible trips, facilitating communication, processing cost-sharing payments, and managing bookings.
  • To Verify Your Identity: Confirming your .edu email address to ensure you are an enrolled student, and facilitating government ID verification through Stripe for drivers.
  • To Verify Driver Insurance: Reviewing the auto-insurance document you upload, recording the insurer, policyholder name, and expiration date read from it, and reminding you before the policy expires. This review is performed by a person on our operations team.
  • To Ensure Safety and Trust: Calculating reliability and reputation scores, enabling user-to-user blocking and reporting, filtering and reviewing flagged content, and enforcing our Terms of Service — including restricting, suspending, or banning accounts.
  • To Process Payments: Authorizing, capturing, and refunding cost-sharing contributions and service fees through Stripe.
  • To Pay Drivers: Sending a driver's earnings to the Venmo or Zelle handle they provided. Payouts are made manually by our operations team from a BoolRider business account; we do not transmit your handle to Stripe, and there is no automated payout integration that draws on your account.
  • To Communicate With You: Sending transactional emails (account verification, password resets, trip-related notifications) and in-app notifications.
  • To Maintain and Improve the Service: Debugging issues, monitoring system performance, and developing new features.
  • To Comply With Legal Obligations: Responding to lawful requests from law enforcement or government agencies, and retaining financial records as required by applicable law.

We do not use your personal information for advertising, behavioral profiling, or sale to third parties.

5. Information Visible to Other Users

When you use BoolRider, certain profile information is visible to other users of the platform:

  • All Users Can See: Your first name, profile photo, gender, graduation year, university, average rating, number of completed trips, reliability score, trip preferences, whether your student status is verified, and your Instagram, Spotify, and Apple Music handles (if provided).
  • Matched Riders and Drivers Additionally See: Approximate pickup and drop-off areas for a shared trip, and in-app messages exchanged in the context of a booking inquiry or confirmed trip.
  • Drivers Can See: Details of your booking request (pickup area, destination zone, departure window, flexibility, number of bags, and any notes).
  • Riders Can See: Details of a driver's posted trip (origin hub, destination zone, departure window, cost contribution, available seats) and vehicle information (make/model, color). License plate numbers are masked in the app interface.

No user ever sees your email address, phone number, full date of birth, government ID, insurance document or any detail read from it, payout handle (Venmo username or Zelle handle), payment details, or exact home address through the BoolRider platform. Riders see that a driver has met our requirements; they do not see the documents behind that.

5.1 Access by BoolRider Personnel

Some information is not visible to other users but is visible to authorized members of the BoolRider operations team, who need it to run the platform. This is limited to what a specific job requires:

  • Verification reviewers open your driver's license and auto-insurance documents to decide whether to approve them, using links that expire within minutes.
  • Payout operators see your name, .edu email address, payout handle, and the amount owed, in order to send your money.
  • Support and safety staff see reports, blocks, flagged content, and account enforcement history when investigating a report.

Operations actions — approving or rejecting a document, marking a payout paid, restricting an account — are recorded in an internal audit log that identifies who took the action and when.

6. How We Share Your Information

We do not sell, rent, or trade your personal information. We share data only in the following circumstances:

6.1 Service Providers

We use the following third-party service providers to operate BoolRider. Each processes data only as necessary to perform their function on our behalf.

When you complete driver verification, Stripe collects and processes your government-issued ID and performs the live facial verification. BoolRider does not receive or store your facial biometric data. Stripe handles it in accordance with its own privacy policy and applicable biometric privacy laws, including Illinois's Biometric Information Privacy Act (BIPA). Section 3.5 explains the arrangement in full.

ProviderPurposeData They Receive
StripePayment processing (authorizations, captures, refunds, disputes) and, for drivers, identity and driver's-license verification including the live facial verificationName, email, government ID, and the live photo and facial-geometry comparison for drivers who verify a license — collected and held by Stripe, never by us (see Section 3.5); payment method details; transaction amounts
SupabaseDatabase hosting, private file storage (driver's license documents, auto-insurance documents, profile photos), and private database backupsAll data stored by BoolRider (hosted infrastructure)
RenderApplication hostingAll data processed by the BoolRider server (hosted infrastructure)
ResendTransactional email deliveryRecipient email address, email subject and content
Apple (Apple Push Notification service)Delivering push notifications to your deviceYour device's push token and the contents of the notification
Venmo / PayPalDriver payouts, sent manually by our operations teamThe driver's Venmo username and the payout amount
Zelle (through our bank)Driver payouts, sent manually by our operations teamThe driver's Zelle handle — an email address or mobile number — and the payout amount
Photon (komoot) / OpenStreetMapAddress search suggestions in the appThe address text you type (no user identifiers, no BoolRider credentials)
CARTO / OpenStreetMapMap tile renderingMap tile requests containing geographic coordinates (no user identifiers)

Payouts are the only circumstance in which we hand a personal detail of yours to Venmo, PayPal, or Zelle, and we do so only to send you money you are owed. We never send them your ride history, your messages, or your documents.

We encourage you to review the privacy policies of these providers. BoolRider has no control over and assumes no responsibility for the privacy practices of third-party services.

6.2 Legal Requirements

We may disclose your information if we believe in good faith that disclosure is necessary to comply with applicable law, regulation, legal process, or governmental request; to enforce our Terms of Service; to protect the safety, rights, or property of BoolRider, our users, or the public; or to detect, prevent, or address fraud, security issues, or technical problems.

6.3 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will notify you via email or a prominent notice within the app before your information becomes subject to a different privacy policy.

7. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you the Service. Specific retention practices include:

  • Account Data: Retained until you delete your account.
  • Ride History and Trip Data: Retained for the life of your account.
  • Financial Records: Anonymized transaction records (bookings, ledger events, refunds, adjustments, chargebacks) are retained indefinitely after account deletion, as required for legal, tax, and financial compliance purposes. These records are linked only to an anonymized user identifier and cannot be used to re-identify you.
  • Messages: Retained for the life of your account.
  • Driver Documents and Profile Photos: The stored files are deleted from our cloud storage provider upon account deletion, along with the database records referencing them. See Section 8.
  • Auto-Insurance Documents: Retained for the life of your account, including superseded and rejected submissions, so that a verification decision can be explained. They carry no financial-record obligation, so on account deletion both the files and the records — the insurer, policyholder name, expiration date, reviewer notes, and reminder history — are deleted outright. Nothing about them is kept in anonymized form.
  • Payout Handles and Payout Records: Your Venmo username or Zelle handle is retained until you change or remove it, or until you delete your account, at which point it is erased. The payout record itself — that an amount was owed and paid, and the handle it was sent to at the time — is part of the financial ledger and is retained on the anonymized basis described above, because it is the record of money actually sent.
  • Safety and Moderation Records: Reports, blocks, masked records of refused content, and account enforcement history are retained for the life of your account. Blocks are removed on deletion; see Section 8.
  • Backups: We take a snapshot of our database daily and keep snapshots for 30 days (and never fewer than the 7 most recent). A backup is a point-in-time copy, so information you delete can persist in an unrestored backup until the snapshots containing it age out. Backups are stored in a private, access-controlled bucket, are used only to restore the Service after a failure, and are never mined, searched, or used to repopulate an account you deleted.
  • Facial Verification Data (Drivers): Not held by BoolRider at all. Stripe retains it while your account is active and for up to three (3) years after your account closes, or until the purpose of the collection has been satisfied — whichever occurs first — then permanently destroys it. See Section 3.5.
  • Ratings and Reviews: Retained for the life of your account. Ratings you have left for others remain associated with your anonymized profile after account deletion.

8. Account Deletion

You may delete your account at any time from within the app. When you request deletion:

  • Your personal information (name, email, phone, photo, gender, university, graduation year, Instagram, Spotify and Apple Music handles, preferences, saved destinations, and payment methods) is permanently erased or replaced with anonymized placeholder values.
  • Your payout destination — your payout method and your Venmo username or Zelle handle — is erased.
  • Your driver profile details (vehicle information, license plate) are erased.
  • Your auto-insurance submissions are deleted: every submission, not only the most recent one, together with the insurer, policyholder name, expiration date, reviewer notes, and expiration-reminder history.
  • Your uploaded files are deleted from storage, not merely unlinked. This covers your profile photo and every verification document you uploaded (driver's license, auto-insurance documents, student ID) — including documents from submissions that were rejected or replaced. The files are erased from our cloud storage provider, normally within seconds of your request. Because storage is a separate system from our database, a temporary storage outage can delay this: in that case the deletion is queued and retried automatically until the files are gone, and your account deletion still completes immediately.
  • Your authentication tokens, notifications, and push-notification device registrations are deleted, so the app on your device stops receiving notifications for the account.
  • Any open booking requests or trip listings are closed or cancelled.
  • User blocks associated with your account are removed.
  • Anonymized financial records (bookings and ledger events) are retained as described in Section 7.
  • Your facial-verification consent record — the notice version, the policy version, and the date you agreed — is kept against your anonymized account identifier as proof that we asked before anything happened. It contains no biometric data. The verification data itself is held and destroyed by Stripe on the schedule in Section 3.5; to have it destroyed sooner, contact privacy@boolrider.com and privacy@stripe.com.

Deletion applies to our live systems. As described in Section 7, backup snapshots taken before your deletion may still contain your information until those snapshots age out, which takes up to 30 days. Backups are never used to bring a deleted account back.

Account deletion cannot be processed if you have active bookings with money attached (e.g., trips that have been accepted, captured, or are awaiting confirmation). You will need to cancel or complete those trips before deletion can proceed.

Once deleted, your account cannot be recovered. However, your .edu email address is released and may be used to create a new account in the future.

9. Data Security

We implement technical and organizational measures designed to protect your personal information, including:

  • Passwords are hashed using bcrypt before storage. We never store plaintext passwords.
  • Authentication and password reset tokens are stored as SHA-256 hashes. The raw token exists only in the email sent to you.
  • Driver's license documents, auto-insurance documents, and profile photos are stored in private storage buckets — never public ones — and are reachable only through signed links that expire in minutes.
  • Stored file paths are generated by us and never contain your name, your filename, or any other personal detail, so nothing sensitive leaks through a file listing or a log line.
  • Photos you upload are re-encoded on your device before they are sent. That removes the EXIF metadata a phone camera embeds — including the GPS coordinates of where the photo was taken, which for a document photographed at home is your home address. Files we cannot re-encode, such as a PDF, are uploaded as you supplied them, so if you submit a PDF, any metadata it carries travels with it.
  • Server-side rate limiting is applied to authentication and API endpoints, and per-account limits apply to messaging.
  • Changing your password, resetting it, or choosing "sign out everywhere" invalidates every existing session on every device at once.
  • Security headers are enforced via Helmet middleware.
  • Payment card data is handled entirely by Stripe and never touches BoolRider servers (PCI DSS compliant).
  • Database backups are written to a private, access-controlled bucket, and support encryption at rest with AES-256-GCM.

No method of electronic transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee its absolute security. If we become aware of a data breach that affects your personal information, we will notify you by email promptly and in accordance with applicable law.

10. Your Privacy Rights

Depending on your state of residence, you may have certain rights regarding your personal information.

10.1 All Users

All BoolRider users, regardless of location, may:

  • Access and review the personal information associated with their account through the app.
  • Update or correct their profile information at any time.
  • Delete their account and associated personal data as described in Section 8.
  • Contact us at privacy@boolrider.com with questions or concerns about their data.

10.2 California Residents (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, use, and disclose; to request deletion of your personal information; to opt out of the sale or sharing of your personal information (BoolRider does not sell or share personal information for cross-context behavioral advertising); and to not be discriminated against for exercising your privacy rights. To exercise these rights, contact us at privacy@boolrider.com.

10.3 Residents of Other States With Privacy Laws

If you reside in Virginia, Colorado, Connecticut, Texas, Oregon, Montana, or another state with a comprehensive consumer privacy law, you may have additional rights such as the right to access, correct, delete, or obtain a portable copy of your personal information, and the right to opt out of targeted advertising or profiling. BoolRider does not engage in targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects. To exercise any applicable rights, contact us at privacy@boolrider.com.

11. Third-Party Links

The Service may contain links to third-party websites or services, including Instagram, Spotify, and Apple Music profiles voluntarily shared by users. We are not responsible for the privacy practices of any third party. We encourage you to review the privacy policy of any external site you visit.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Last Updated" date at the top of this policy and, where appropriate, by providing additional notice within the app or by email. Your continued use of BoolRider after a change constitutes your acceptance of the updated policy.

13. Contact Us

If you have any questions, concerns, or requests related to this Privacy Policy or our data practices, please contact us: