Privacy Policy

Last updated: October 6, 2026

The short version

YauzaiSafar is a technology platform that connects drivers and passengers — we do not provide transportation ourselves. We collect only what is needed to run the service: your account details, contact numbers, ride information, and live location during active trips only. You may optionally sign in with Google or submit an ID document for verification; both are covered below. We do not sell your data, run advertising, or track you outside of trips. To keep rides available on more routes and at more times, we also show ride listings gathered from other sources — Section 3 explains what they contain and how to have one removed. If your number appears in one, we may also send you a WhatsApp message about YauzaiSafar; Section 12 explains how to have your number removed from our campaigns.

Section 1

Introduction

YauzaiSafar is owned and operated by Hizli System (hizlisystem.com). YauzaiSafar and Hizli System ("YauzaiSafar", "we", "our", or "us") operate a technology platform that allows users to create ride listings, search for available rides, book seats, and coordinate travel arrangements with other users. This Privacy Policy explains what information we collect when you use the YauzaiSafar application, why we collect it, how it is used, and what control you have over it.

This policy applies to everyone who creates a YauzaiSafar account, publishes a ride, books a seat, uses live trip tracking, or communicates with other users through the app. By using YauzaiSafar, you acknowledge that your information is handled as described here.

It also covers yauzaisafar.com, this website. Most of the site is ordinary marketing pages that collect nothing, but two things there do involve your information: confirming an email verification link, and completing a password reset. Both are described in Section 15. Accounts themselves are created in the app, not on this site.

We have written this policy to be readable, not just legally complete. If you have a question it does not answer, contact us at info@yauzaisafar.com.

Section 2

Our Platform Role

YauzaiSafar is a technology platform only. We connect users who want to travel — we are not a transportation company and we do not provide rides.

Specifically, YauzaiSafar:

  • Does not own or operate vehicles.
  • Does not employ drivers or any user who creates a ride listing.
  • Does not provide, guarantee, or arrange transportation directly.
  • Does not act as an agent for any user.
  • Does not control how users behave, communicate, or complete their travel.

All travel arrangements are made directly between users. YauzaiSafar provides the tools to discover rides, manage bookings, and coordinate — the decisions and actions that follow are between the users involved.

Users on YauzaiSafar may act as ride creators (offering available seats) or as passengers (booking seats). Both are referred to as "Users" throughout this policy.

Listings from other sources. So that a ride is almost always available to you, YauzaiSafar also shows ride offers and seat requests gathered from other sources where people share travel for a route, across the areas we serve. These are marked in the app as coming from another source. The people who posted them are not YauzaiSafar Users and have not been verified by us; any arrangement you make with them is between you and them.

Section 3

Information We Collect

We collect only the information that is necessary to operate the platform. We do not collect browsing history, purchase history, social media profiles, or device advertising identifiers.

Account Information
Supabase Authentication
  • Full name
  • Email address
  • Password (hashed, never readable)

Your name and email are used to identify your account and to log in. Passwords are managed entirely by Supabase Authentication using strong cryptographic hashing — we never store or access your password in readable form.

Google Sign-In Information
Google · Supabase Authentication
  • Google account name
  • Google account email address
  • Google account identifier

If you choose "Continue with Google" instead of creating a password, Google returns your name, email address, and a Google account identifier to YauzaiSafar so an account can be created or matched. We request only basic profile and email scope — we never receive your Google password, and we do not read your Gmail, Drive, contacts, or calendar. Google processes the sign-in itself under Google's Privacy Policy. Signing in with Google is entirely optional; email and password sign-up remains available. Because the app requires a mobile number that Google does not provide, you will be asked for yours the first time you sign in this way.

Identity Verification Documents
Supabase Storage (private bucket) & verification requests table
  • Photograph of your ID card
  • Submission timestamp
  • Verification status

Identity verification is entirely optional. If you choose to verify, the app uses your camera to capture a photo of your ID card, which is uploaded to a private storage bucket and reviewed manually by a member of our team. The photo is used for one purpose only — confirming that you are who you say you are — and is never shown to other users. Other users only ever see whether you carry a verified badge, never the document itself or anything read from it. The camera permission is used solely for this capture. You can delete the document at any time by deleting your account, which removes both the stored image and the verification record.

Contact Information
Users database table
  • Mobile number
  • WhatsApp number

Your mobile and WhatsApp numbers allow ride participants to coordinate with each other. Phone numbers are not publicly displayed — they are made available only to users involved in the same confirmed booking. Providing a separate WhatsApp number is optional; you may use the same number for both fields.

Ride Information
Rides database table
  • Starting location
  • Destination
  • Route details
  • Travel date and time
  • Vehicle details
  • Available seats

When you create a ride, this information is stored and shown to users searching for rides along the same route. It powers ride discovery and booking. Vehicle details help passengers identify the correct car at pickup.

Booking Information
Bookings database table
  • Booking records
  • Passenger participation
  • Booking history

When a passenger books a ride, we record the booking to manage seat availability, connect the ride creator with their passengers, and maintain a trip history for both parties.

Location Data
Trip locations database table
  • GPS latitude
  • GPS longitude
  • Heading / direction

During an active trip, YauzaiSafar collects real-time GPS coordinates (latitude, longitude, and heading) from the driver and/or passenger so the other trip participant can see live location for pickup and drop-off coordination. This sharing is temporary — it stops automatically when the trip ends or when location sharing is turned off. We may also request a single, one-time location reading when you create a ride or passenger request, solely to auto-detect your country and currency for the form — this reading is not stored as a location history. We do not track your location outside of these two scenarios.

Push Notification Token
Expo push service & Firebase Cloud Messaging (Android)
  • Device push token

We collect a device push notification token to send you booking-related alerts — new booking requests, confirmations, and cancellations. Delivery is handled by Expo's push notification service and, on Android devices, Google Firebase Cloud Messaging (FCM), both of which process your token solely to deliver these notifications. You can disable push notifications at any time from your device settings.

Map Tile Requests
OpenStreetMap & Carto — not stored by YauzaiSafar
  • IP address
  • Map area viewed

When you view a trip map, map tile images are loaded directly from OpenStreetMap and Carto. As part of standard tile-serving, these providers may receive your IP address and the map area being viewed. YauzaiSafar does not itself store this information.

Listings From Other Sources
Listings database table — reviewed before publishing
  • Route, pickup and drop-off areas
  • Travel date and time
  • Seats offered or needed, and fare if stated
  • The text of the original listing
  • The contact number published with it

We gather ride offers and seat requests from other sources where people share travel for a route, so you can find a ride on more routes and at more times. A member of our team reviews every listing before it appears in the app. We keep only what the listing itself contains and do not create an account for the person who posted it; their contact number also goes on our outreach list (below). To read the route, time, and seats from the original text we use an automated text-processing service (see Section 6); phone numbers are removed from the text before it is sent. If a listing shows your number and you want it removed, see Section 12.

Outreach List
Database table — visible only to our team
  • The contact number from a listing from another source, or one we added by hand
  • When it first and last appeared in a listing, how many listings, and where
  • Which of our messages it has been sent, and whether its owner asked us to stop

We use this list to tell people who share rides elsewhere about YauzaiSafar, with a WhatsApp message that a member of our team sends by hand — at most once per campaign, and never to anyone who has asked us to stop. Every message says how to stop. A number is deleted automatically 6 months after it last appears in a listing (one we added by hand, 6 months after we added it). It is never shared outside our team. To have your number removed sooner, see Section 12.

Section 4

How We Use Your Information

Every piece of information we collect has a specific purpose tied to running the platform. We do not use your information for advertising, profiling, or selling to third parties.

Information How it is used
Name Displayed on ride listings and to users involved in the same booking, so drivers and passengers can identify each other.
Email address Account login, email verification during sign-up, and support communications when you contact us.
Mobile number Shared with the ride creator or passengers on the same confirmed booking, for pickup coordination.
WhatsApp number Used to open a WhatsApp conversation when another user initiates contact via the "Contact" feature — only between participants of the same booking.
Ride details Powering the ride search feature, showing available seats, and enabling booking management.
Booking records Managing active reservations, tracking seat availability, and maintaining ride history.
Live location (active trips only) Displaying real-time trip progress to trip participants for safety and pickup coordination.
Push notification token Sending booking-related alerts — new requests, confirmations, and cancellations — to your device.
Google account details (if you use Google Sign-In) Creating or matching your YauzaiSafar account, and populating your name and email so you do not have to type them again. Nothing is written back to your Google account.
ID document photo (if you choose to verify) Manually reviewed once by our team to confirm your identity, after which your profile shows a verified badge. Never displayed to other users.
Listings from other sources Shown to signed-in users looking for the same route, so they can contact the person who posted the ride or seat request directly.
Outreach list Sending the person a WhatsApp message about YauzaiSafar, by hand, at most once per campaign. Every message says how to stop.
Section 5

How We Share Information

We do not sell, rent, or trade your personal information. Sharing happens only where it is necessary for the platform to function.

Here is exactly when your information becomes visible to other users:

  • Ride listings: When you publish a ride, your name and ride details (route, date, time, vehicle, available seats) are visible to users searching for rides. Your contact numbers are not shown at this stage.
  • After a booking is confirmed: The ride creator and the booked passenger can see each other's name, mobile number, and WhatsApp number to coordinate the journey. This is visible only to participants of that specific booking.
  • WhatsApp contact: When you tap "Contact," the app uses the recipient's WhatsApp number to open WhatsApp on your device. This is user-initiated — we do not transmit the number to WhatsApp independently.
  • Live location: During an active trip, your real-time GPS coordinates are shared only with the ride creator and confirmed passengers on that same trip, for pickup and drop-off coordination. No other users and no one outside the app can see your location. This sharing stops when the trip ends or when location sharing is turned off.
  • One-time location for auto-detect: When creating a ride or passenger request, we may request a single location reading to auto-detect your country and currency for the form. This reading is not shared with other users and is not stored as a location history.
  • Push notifications: Your device push token is shared with Expo's push notification service and, on Android, Google Firebase Cloud Messaging, solely to deliver booking-related alerts to your device.
  • Map tiles: When you view a trip map, map tile images are loaded from OpenStreetMap and Carto. These providers may receive your IP address and the map area being viewed, as part of standard tile-serving.
  • Google Sign-In: If you sign in with Google, the sign-in itself happens with Google, which will know that you signed in to YauzaiSafar. We receive your name, email, and Google account identifier in return. We send Google nothing about your rides, bookings, location, or activity in the app.
  • Identity verification documents: Your ID photo is visible only to the YauzaiSafar team member reviewing it. It is never shared with other users, never shown on your profile, and never given to any third party except where legally compelled.
  • Listings from other sources: These are visible to signed-in users, together with the contact number that was published with the original listing, so users can get in touch directly. They are not shown to anyone who is not signed in.
  • Legal requirements: We may disclose information if required by law or court order, but will not go beyond what is legally required.
Section 6

Third-Party Services

YauzaiSafar uses a small number of third-party services to operate. We have described each one clearly below.

Supabase
Authentication and database infrastructure

Supabase provides the backend infrastructure used to authenticate users and store application data — including account credentials, profile information, ride records, booking history, and trip location data. Supabase infrastructure runs on cloud providers such as Amazon Web Services (AWS). As a data processor, Supabase handles your data only as directed by YauzaiSafar and operates under its own security practices. You can review their privacy policy at supabase.com/privacy.

WhatsApp (Meta)
User-initiated communication only — no integrated SDK

YauzaiSafar does not embed a WhatsApp SDK or integrate with Meta's advertising or analytics systems. When you tap "Contact via WhatsApp," your device opens WhatsApp using a standard deep link (wa.me) with the recipient's number. This action happens on your device and is initiated by you. Once WhatsApp opens, that conversation is between you and the other user, governed by WhatsApp's own terms and privacy policy. YauzaiSafar does not monitor, log, or store WhatsApp conversations.

Expo Push Notifications & Firebase Cloud Messaging
Push notification delivery

YauzaiSafar uses Expo's push notification service to deliver booking-related alerts to your device. On Android devices, delivery is routed through Google Firebase Cloud Messaging (FCM). Both services process your device's push token solely to deliver notifications — they are not used for analytics or advertising. You can disable push notifications at any time from your device settings.

OpenStreetMap & Carto
Map tile imagery

When you view a trip map, map tile images are loaded directly from OpenStreetMap and Carto. As part of standard tile-serving, these providers may receive your IP address and the map area being viewed. YauzaiSafar does not control or store this data.

Google Sign-In
Optional authentication method

If you choose "Continue with Google," Google authenticates you and returns your name, email address, and a Google account identifier to YauzaiSafar. We request basic profile and email scope only — never your Gmail, Drive, contacts, calendar, or password. Google's handling of the sign-in is governed by Google's Privacy Policy. This is optional: email and password sign-up works exactly the same way. Google Play Services is also present on Android to support this sign-in method and push notification delivery.

Google Play
App distribution

The YauzaiSafar Android app is distributed through the Google Play Store. Google collects installation, update, and crash information as part of operating the store, under its own policies. YauzaiSafar receives only aggregate, anonymous statistics from Google Play — such as install counts — that cannot identify you individually.

Google Gemini
Reading listings from other sources

When we prepare listings from other sources (Section 3), the text of each listing — with phone numbers removed — is processed by Google's Gemini service to pick out the route, date, time, and seats. Nothing about YauzaiSafar users, accounts, or app activity is ever sent to it. Under Google's terms for this service, Google may use the submitted text to improve its products, which is why phone numbers are removed first. See Google's Privacy Policy.

What we do not use:

  • Advertising networks or mobile advertising SDKs
  • Analytics platforms such as Google Analytics, Firebase Analytics, or Mixpanel
  • Crash reporting services that transmit user data externally
  • Any service that buys, receives, or uses your personal data commercially
Section 7

Location Data Usage

Real-time location is the most sensitive data YauzaiSafar handles. Here is a precise account of how it works.

  • When location is collected: GPS coordinates (latitude, longitude, and heading) are collected in two scenarios only: (1) during an active trip — after the journey has started and before it is marked as complete or cancelled — so the other trip participant can see live location for pickup and drop-off coordination; and (2) as a single, one-time reading when you create a ride or passenger request, used solely to auto-detect your country and currency for the form. The app does not access your location outside of these two scenarios.
  • One-time location for auto-detect: This reading is used only to pre-fill your country and currency on the ride or passenger request form. It is not stored as a location history and is not shared with other users.
  • Who can see your location: Only the ride creator and confirmed passengers on that specific trip. No other users, and no one outside the app, can see your location while it is live.
  • When collection stops: Live location access ends automatically when the trip is marked complete or cancelled, or when location sharing is turned off.
  • How long it is stored: Trip location records are not retained permanently. Data is cleared at or shortly after trip completion. We do not build or archive a history of your movements.
  • What we do not do: We do not track your location in the background, outside of active trips, or for any purpose other than live trip coordination.

Device permissions: Location access is requested through your device's standard permission prompt. You can deny or revoke it at any time in your device settings. Doing so will disable live trip tracking and the country/currency auto-detect feature — all core features of the app, including posting, browsing, and booking rides, will continue to work normally.

Section 8

Communication and WhatsApp Sharing

After a booking is confirmed, the ride creator and passenger need a way to coordinate pickup details. YauzaiSafar makes contact information available between participants for this purpose.

What is shared between booking participants:

  • Your name
  • Your mobile number (with country code)
  • Your WhatsApp number (which may be the same as your mobile number)

This information is only visible to users who are part of the same confirmed booking. It is not visible to users browsing listings, to other ride creators, or to anyone not connected to that specific ride.

How the WhatsApp feature works: When a participant taps "Contact," YauzaiSafar generates a wa.me deep link using the recipient's WhatsApp number and opens WhatsApp on your device. This is an action you initiate. The app does not send messages on your behalf, does not store the conversation, and does not pass your number to Meta independently. Once WhatsApp is open, the conversation is between you and the other user.

Your choice: You provide your WhatsApp number when registering. You can use the same number as your mobile number, or a different one. If you have concerns about contact sharing, email support@yauzaisafar.com.

Section 9

Your Responsibilities as a User

Because YauzaiSafar connects users directly, how you use the platform and treat other users matters. By using YauzaiSafar, you agree to:

  • Provide accurate information. The name, contact details, and ride information you enter must be truthful. Misleading other users through false information is prohibited.
  • Use contact information responsibly. Phone numbers and WhatsApp details shared through the platform are provided for the purpose of coordinating travel. Using this information to harass, spam, or contact users outside the context of a specific booking is not permitted.
  • Respect other users. Abusive, threatening, or discriminatory communication through the platform is prohibited.
  • Follow applicable laws. You are responsible for complying with the laws of your country or region when using the platform and when travelling.
  • Use the platform for its intended purpose. YauzaiSafar is for coordinating shared travel. Using the platform to collect user information for any other purpose is strictly prohibited.
Section 10

Data Security

We use reasonable and industry-standard practices to protect your information. Here is what is specifically in place:

  • Password security: Passwords are managed by Supabase Authentication and hashed using strong cryptographic algorithms. YauzaiSafar never stores or accesses your password in readable form.
  • Session management: User sessions use authenticated tokens that are scoped and expire, limiting exposure if a session is compromised.
  • Database access controls: Your data is stored in a Supabase-managed database, accessible only through authenticated API requests made by the YauzaiSafar application.
  • Contact information protection: Mobile and WhatsApp numbers are not exposed to arbitrary users — they are only available to participants of a confirmed booking, and only after the booking is confirmed.
  • Location data: Live location is transmitted securely and made available only to trip participants in real time.

No internet-connected system is completely secure. We cannot guarantee that unauthorised access will never occur. Use a strong, unique password for your YauzaiSafar account. If you suspect your account has been compromised, contact us at support@yauzaisafar.com immediately.

Section 11

Data Retention

We keep your information only as long as it is needed to provide the service, meet legal obligations, resolve disputes, or maintain security.

Data type How long we keep it
Account information Name, email address Deleted immediately when you use in-app account deletion. If requested by email, deleted within 45 business days. See Section 13.
Contact information Mobile, WhatsApp number Until you delete your account or update it from your profile settings.
Ride information Routes, dates, vehicle details Deleted automatically once the travel date has passed, or earlier when you cancel the ride or delete your account.
Booking records Booking and participation history Deleted together with their ride once its travel date has passed, or on account deletion.
Listings from other sources Route, time, seats, original text, contact number Deleted automatically once the travel date has passed, or sooner on request (see Section 12).
Outreach list Contact numbers from listings from other sources Deleted automatically 6 months after the number last appears in a listing (or 6 months after we added it by hand). Removed from all campaigns within 7 working days if you ask (see Section 12). If you ask us to stop, we keep only the number and the date you asked, so that it is never added back or messaged again.
Live location data GPS coordinates during active trips Not retained permanently. Cleared at or shortly after trip completion. No movement history is stored.
Identity verification documents ID card photograph Kept while your account is active so verification can be re-checked if disputed. Deleted along with the verification record on account deletion.
Push notification token Device identifier for notification delivery Until you delete your account, reinstall the app, or turn off notifications in device settings, whichever happens first.

When you delete your account, your personal information is removed within a reasonable timeframe. In some cases, anonymised or aggregated records may be kept for operational or legal purposes, but these cannot be linked back to you as an individual.

Section 12

Your Privacy Rights

You have the following rights over your information:

  • View your information Access your account details, profile, and ride history within the app at any time.
  • Update your information Update your name, mobile number, and WhatsApp number from your profile settings at any time.
  • Request deletion of your data Request removal of your personal information. See Section 13 for the process.
  • Contact us with privacy concerns Ask what data we hold about you, request corrections, or raise any privacy question. We will respond within a reasonable timeframe.
  • Revoke location permission Deny or withdraw location access at any time from your device settings. This only affects live trip tracking and the country/currency auto-detect feature — all other app features continue to work.
  • Remove a listing that shows your number If a listing from another source shows your phone number, email info@yauzaisafar.com with that number. We remove its listings and stop showing new ones with it. You do not need an account to ask.
  • Remove your number from our campaigns If you want your number deleted from all our campaigns, email info@yauzaisafar.com with that number and we will delete it within 7 working days. You can also reply to any message from us asking us to stop. Either way, we keep only the number and the date you asked, so that it is never added back or messaged again. You do not need an account to ask.

If you are located in a jurisdiction with specific data protection laws (such as the EU GDPR or similar), you may have additional rights including data portability and the right to lodge a complaint with a supervisory authority. We aim to respect the spirit of these rights for all users, regardless of location.

Section 13

Account Deletion

You can permanently delete your YauzaiSafar account and personal data at any time.

In-app self-service deletion. YauzaiSafar provides in-app self-service account deletion:

  1. Open the app and go to your Profile screen.
  2. Tap "Delete Account."
  3. Confirm the deletion. Your account is deleted immediately and permanently.

Confirming deletion:

  • Deletes your profile and login credentials, including the link to your Google account if you signed in with Google.
  • Deletes your identity verification record and the ID document photo you submitted.
  • Deletes your push notification token, so notifications stop immediately.
  • Deletes all ride posts and passenger requests you created.
  • Deletes all bookings you made as a passenger, and all bookings on rides you posted as a driver.
  • Deletes all offers you sent or received.
  • Deletes any live trip-coordination data associated with you, including active trip location sharing and trip participant records.

This cannot be undone. Once confirmed, your data is permanently removed and cannot be recovered.

Unable to access the app? If you cannot use in-app deletion, you can alternatively request deletion by emailing info@yauzaisafar.com from your registered address. We will delete your account and associated data within 45 business days, except where certain information must be retained for legal, safety, or fraud-prevention purposes as described in Section 11.

If you have an active booking or ongoing trip at the time of your request, we recommend completing or cancelling it first to avoid disruption for other participants. A standalone summary of both deletion routes is also available on our account deletion page.

Section 14

Children's Privacy

YauzaiSafar is a ride-sharing and travel coordination platform intended for adults. We do not knowingly collect personal information from anyone under the age of 18. The platform is not designed for or marketed to minors.

If you believe a user under 18 has created an account on YauzaiSafar, please contact us at info@yauzaisafar.com. We will investigate and take appropriate action, including removing the account and associated data if confirmed.

Section 15

Cookies and Local Storage

We do not use tracking cookies, advertising cookies, or analytics cookies — on the app or on this website. Nothing here follows you between sites.

The YauzaiSafar mobile app does not use cookies at all. It stores your login session on your own device, using the operating system's secure storage, so that you are not asked to sign in every time you open it. That session is removed when you log out or delete the app.

This website stores only the following, and only in your own browser:

  • Your theme preference. When you switch this site between light and dark mode, that single choice is saved in your browser's local storage so the site remembers it next visit. It contains no personal information and is never sent to us.
  • A short-lived sign-in token, on the password reset page only. When you open a password reset link from your email, the reset token in that link is held in memory just long enough to set your new password, and is discarded as soon as the page finishes. It is not persisted between visits.

Clearing your browser data removes both. The site continues to work normally without them — you will simply see the default theme.

Section 16

International Data Transfers

YauzaiSafar is operated from Pakistan, but the infrastructure it runs on is not necessarily located there. Your information is stored and processed by Supabase, which runs on cloud providers such as Amazon Web Services, and may be held on servers outside your own country. Push notifications are routed through Expo and, on Android, Google Firebase Cloud Messaging, which operate globally.

This means that by using YauzaiSafar you are asking us to process your information in the way described in this policy, wherever the underlying servers happen to be. Wherever your data is held:

  • It is protected by the same measures described in Section 10.
  • It is handled only for the purposes described in Section 4, and is never sold or used for advertising.
  • Our processors act only on our instructions, under their own contractual and security obligations.
  • Your rights in Section 12 — including deletion — apply to your data regardless of the country it is stored in.

If you would like to know where a specific category of your data is currently held, write to info@yauzaisafar.com and we will tell you.

Section 17

Changes to This Privacy Policy

We may update this Privacy Policy as the platform evolves or as requirements change. When we do:

  • We will update the "Last updated" date at the top of this document.
  • For significant changes, we will notify registered users via email or an in-app notice before the change takes effect, giving you the opportunity to review it.

Continued use of YauzaiSafar after an update constitutes acknowledgement of the revised policy. If you disagree with material changes, you can stop using the app and request account deletion before they take effect.

Section 18

Contact Information

For questions about this policy, data rights requests, or privacy concerns, use the contacts below. We aim to respond to all privacy-related requests within a reasonable timeframe. For data access, correction, or deletion requests, include your registered email address so we can verify your identity before taking action.

General enquiries info@yauzaisafar.com
Support & account issues support@yauzaisafar.com
Privacy requests support@yauzaisafar.com

Platform: YauzaiSafar  ·  App: YauzaiSafar  ·  Owned and operated by Hizli System