Privacy Policy
Your privacy matters to us. Learn how CarKro collects, uses, and protects your information.
Overview
CarKro ("we", "us", "our") operates a ride-hailing and mobility platform connecting drivers and riders across Pakistan. This Privacy Policy explains how we collect, use, store, and protect personal information when you use the CarKro mobile application, web portal, or any related services.
By registering or using CarKro, you agree to the collection and use of information as described in this Policy. If you do not agree, please discontinue use of our services.
Information We Collect
We collect information in several ways depending on how you interact with CarKro:
Information You Provide Directly
- Account Registration: Full name, phone number, email address, CNIC number (drivers), date of birth, and profile photo.
- Driver Onboarding: Vehicle registration number, model, year, color; driving license number and expiry; vehicle inspection documents; insurance certificates.
- Ride Requests: Pickup and drop-off addresses, ride notes, and service type preferences.
- Payment Information: Bank account details or mobile wallet identifiers (JazzCash, EasyPaisa, NayaPay, SadaPay). We do not store full card numbers.
- Support Tickets: Messages, attachments, and communication records submitted via support channels.
Information We Collect Automatically
- Location Data: Real-time GPS coordinates while the app is in use or in background (drivers during active sessions).
- Device Information: Device model, operating system version, unique device identifiers, mobile network information.
- Usage Data: App interactions, feature usage, session timestamps, crash logs, and diagnostic data.
- Driving Behaviour: Speed, braking events, route deviations recorded via telematics during active rides.
- Firebase Cloud Messaging (FCM) Tokens: Push notification tokens for delivering ride alerts and updates.
How We Use Your Data
We use your information to provide, improve, and secure our platform. Specific uses include:
Location Data
Location is central to CarKro's service. Here is how we handle it:
- Riders: Location is accessed only when the app is open and you are booking or tracking a ride. We do not track rider location in the background.
- Drivers (Active Session): Real-time GPS is collected continuously while you are online or in an active ride to enable matching, ETA calculation, and safety monitoring. Location updates are sent every 5–15 seconds depending on battery level.
- Drivers (Offline): When you go offline, location tracking stops immediately.
- Heatmaps: Aggregate anonymised location data is used to generate demand heatmaps shown to drivers. No individual is identifiable in these heatmaps.
- Retention: Raw GPS logs are retained for 90 days for dispute resolution, then permanently deleted.
Payment Information
CarKro processes subscription fees for drivers via integrated payment gateways. We apply the following safeguards:
- Payment card numbers are never stored on CarKro servers. All card data is tokenised by the payment processor.
- Bank account and mobile wallet identifiers are encrypted at rest using AES-256 encryption.
- Transaction records (amount, date, subscription tier) are retained for 7 years for accounting and regulatory compliance.
- All payment API communications occur over TLS 1.3 encrypted connections.
Notifications & FCM Tokens
CarKro uses Google Firebase Cloud Messaging (FCM) to deliver push notifications including ride requests, OTP codes, safety alerts, and promotional campaigns.
- Your FCM token is collected upon app installation and stored securely in our database.
- FCM tokens are rotated automatically by Firebase and updated in our system to ensure delivery.
- You may disable push notifications in your device settings. Critical safety notifications (SOS alerts) cannot be individually disabled.
- WhatsApp messages may be sent via opt-in for ride receipts and promotional campaigns. You may opt out at any time by messaging "STOP" to the CarKro WhatsApp number.
Data Retention
| Data Category | Retention Period | Reason |
|---|---|---|
| Account Information | Duration of account + 2 years | Service continuity |
| Ride History | 5 years | Dispute resolution, tax compliance |
| Raw GPS Logs | 90 days | Safety & dispute investigation |
| Payment Records | 7 years | Accounting & regulatory |
| Support Tickets | 3 years | Quality assurance |
| Telematics / Driving Events | 90 days | Safety analysis |
| FCM Tokens | Active account lifetime | Push notification delivery |
Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Update inaccurate or incomplete information via your profile settings or by contacting support.
- Deletion: Request deletion of your account and associated data. We will comply within 30 days, subject to legal retention requirements.
- Portability: Request your ride history and account data in a machine-readable format (JSON/CSV).
- Withdraw Consent: Withdraw consent for optional data processing (e.g., marketing communications) at any time.
- Object: Object to processing of your data for certain purposes, including direct marketing.
To exercise any of these rights, contact privacy@carkro.com. We will respond within 30 days.
Security
CarKro implements industry-standard security measures to protect your data:
- All data in transit is encrypted using TLS 1.3.
- Sensitive data at rest is encrypted with AES-256.
- Access to production systems is restricted to authorised personnel with multi-factor authentication.
- Regular security audits and vulnerability assessments are conducted.
- An automated fraud detection system monitors for suspicious account activity.
- Incident response procedures are in place; affected users will be notified within 72 hours of a confirmed data breach.
Children's Privacy
CarKro services are intended for users aged 18 and above. We do not knowingly collect personal information from individuals under 18. The School Rides feature ("Guardian" accounts) allows parents or guardians to manage rides for minors — the guardian's data is collected, not the child's.
If we become aware that a person under 18 has registered without guardian consent, we will promptly delete their account. To report such a case, contact privacy@carkro.com.
Policy Changes
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notification and/or email at least 14 days before the changes take effect. Continued use of CarKro after the effective date constitutes acceptance of the updated Policy.
The version history of this Policy is available upon request from our Data Protection Officer.
Contact Us
For privacy-related enquiries, data subject requests, or to reach our Data Protection Officer: