Privacy Policy
Effective: 2026-05-03
1. What we collect
- Account data: name, email, password (hashed), profile photo, location, bio.
- Phone number, when you choose to verify it (required to drive).
- Vehicle details for drivers: make, model, color, year.
- Payout links for drivers: Stripe Payment Link or PayPal.me URL.
- Ride and offer content you post (route, date, budget, notes, offer messages).
- Ratings you give and receive (1–5 stars, no written text).
- Technical data: IP address, browser, login timestamps, basic server logs.
2. How we use it
- To operate the marketplace — show your posts to other users, deliver matches, send notifications.
- To process the unlock fee through Stripe.
- To verify your phone via Twilio (when you initiate phone verification).
- To prevent abuse (rate-limiting login attempts, blocking spam, banning bad actors).
- To respond to legal process when required.
3. What we share, and who we don't share with
We use the following service providers, each of whom processes data on our behalf:
- Stripe — for the unlock fee. You enter your payment details on Stripe's site; Stripe's privacy policy applies.
- Twilio — for SMS verification. Phone number and verification code are sent through Twilio.
- Cloudflare Turnstile — for anti-bot checks on forms.
- Our email provider (IONOS SMTP) — to deliver transactional emails.
We do not sell your personal information. We do not share your contact info with anyone except the matched counterparty after they pay the unlock fee.
4. Contact info masking
To preserve the unlock-fee model, we automatically mask anything that looks like a phone number, email address, or messaging-app handle in user-supplied free text (ride notes, offer messages, bios) until a match is unlocked. This is part of how the platform works; do not attempt to bypass it.
5. Cookies and sessions
We set a single session cookie (rc_sess) to keep you signed in. We don't run third-party advertising or analytics cookies on the site.
6. Your rights
You can update or delete your profile from your account page at any time. If you delete your account, your user record and posted content are removed; ratings you gave or received remain but are no longer attributed to you. To request a copy of your data, email info@rollycar.com.
7. Data retention
We retain account and ride data for as long as your account is active. Audit-log entries and payment records are kept for accounting and legal purposes.
8. Children
Rollycar is not intended for users under 18. We do not knowingly collect data from anyone under 18. If you believe a minor has registered, contact us and we'll remove the account.
9. Changes
We may update this Privacy Policy from time to time. The "Effective" date above shows when the current version took effect.
This is a starting template, not legal advice. Please have it reviewed by qualified counsel before relying on it in production.
Questions? Contact us at info@rollycar.com.