Privacy Policy
- Last updated
- October 5, 2026
- Effective date
- October 5, 2026
Plain-English summary#
What this is. TAGO is a cost-sharing carpool app. Drivers are private people already making a trip; riders chip in toward the cost of that trip. TAGO takes no commission. We measure how far a car actually travelled so the shared cost can be worked out from real distance; how the cost share is calculated and capped is in the Terms of Service, not here.
Who can see where you went. Short answer: the person you are carpooling with, anyone you personally send a tracking link to, and TAGO staff. Nobody else.
Other TAGO users — people you are not carpooling with — can see only a small public card — your name, your photo and your rating — alongside any trip you chose to post to the board. That is the whole list. They cannot see your email address, your phone number, your date of birth, your saved addresses, your wallet, or any location of yours. A driver's live position is visible only to the rider that driver is actually matched with or has made an offer to, and it stops being visible the moment the ride ends.
The person you are carpooling with sees your pickup and drop-off, your name, your photo and your live position during the ride. Anyone you send a tracking link to sees one live coordinate for up to four hours. TAGO staff (administrators) can see all of it — §7.4 says exactly what that means.
We do not sell your personal information, and we never will. We do not share it for cross-context behavioral advertising. Any advertising we run is chosen from what is on the page — a route, a region, an event — and no profile, identifier or audience segment about you is sent to an advertiser or ad network. That is a design commitment, not a preference we can quietly change.
Location is the sensitive part, so it gets §3 to itself. Two things happen. While a ride is active, your phone sends a GPS point about every five seconds, and since August 2026 those points are kept as the ride's route trail (staff-only), and on iOS this keeps going in the background — that is how the shared cost is measured against real distance, and it stops by itself when the ride ends. Outside a ride, your phone takes a single position reading when you open the app, at most about once every five minutes, and never in the background. §3 explains both, and how to stop the second one.
We do not vet drivers, and we want you to know that. TAGO collects no driver's licence, runs no licence check, and performs no driver verification of any kind. A TAGO driver is a private person driving their own car on a trip they were already making. §4.2.
How long we keep it. Today, indefinitely, for almost everything. We have not yet built a retention schedule and we are not going to invent a date for one. §5 says what will govern it. Deleting your account erases your personal information. Five things outlive it, each with your name taken out: the money record (tax law), safety reports in both directions (they protect the other person), your side of a ride conversation (it is the other person's record too, and you show as a deleted user), your unsubscribes (kept as a fingerprint so we cannot mail you again), and staff attribution if you were an administrator. §6 is the exact list, and §6.4 names the places deletion cannot reach.
You are a Californian with real rights. You can ask what we hold, get a copy, correct it, delete it, and limit our use of sensitive information. Email [email protected]. We will not treat you worse for asking. §9.
Age and who can sign up. TAGO is for adults, 18 and over, and today it is for students — signing up requires a student email address. We ask your date of birth and our code does not yet enforce the age limit; we say so plainly rather than imply a check that does not exist. The student email address is an eligibility requirement, not a verification: it says something about the address, not about you, and we will never describe a TAGO user as a verified or vetted student. §11.
We provide no insurance of any kind. Drivers rely on their own personal auto policy. We hold no insurance data about anyone, because we have none to hold. (That belongs to the Terms of Service, but people look for it here.)
What you can do right now#
| To do this | Do this |
|---|---|
| Delete your account | In the app: Profile → Settings → Delete account (§6). Immediate, not a 30-day wait |
| Turn off marketing email and promotional push | In the app: Profile → Settings → Notifications (§4.6), or email us |
| Stop us keeping your last known location | Email [email protected] with "no background location" (§3.1d) — no reason needed |
| Kill a live tracking link you sent | Revoke it on the ride's safety screen in the app, or email us and we will kill it (§3.3) |
| Ask what we hold, get a copy, correct it, or erase the rest | Email [email protected] (§9) |
What changed on October 5, 2026. This update corrects these things to match how TAGO works today:
- we now describe the crash reports our apps send to help us fix bugs (§4.9);
- we added five service providers we already use: Amazon Web Services, Cloudflare, Vercel, Twilio and auto.dev. We also clarified what our staff-alert tool, Slack, receives (§7.1);
- administrator sign-in now requires a second factor (§7.4);
- we now describe the approximate location our analytics provider estimates from your IP address (§3.4, §7.2). This has been happening since we added analytics on August 13, 2026; our policy should have said so.
- Later on October 5, 2026 we switched off the IP-based location estimate in our analytics; it is no longer collected (§7.2).
- We corrected how we describe working out your region: your app sends the location reading to our server for the lookup, and the server does not keep it (§3.1d).
No new use of your information starts with this update.
What changed on October 4, 2026. We stopped using Google Gemini, the AI service we used internally to draft marketing copy, and removed it. No information about you is sent to any AI service (§7.3).
What changed on August 13, 2026. We added a first-party product-analytics tool (PostHog) to the app and our server. It records which TAGO features you use — as a fixed, named list of events we wrote by hand — under your account's internal ID. It never receives your name, email, phone number, messages, or your location: no coordinates ever leave for analytics, route lengths are rounded into broad buckets first, and when you search the ride board only the destination's public name is recorded — never where you started from. Nothing about you is tracked across other apps or websites, and nothing is shared with advertisers. §7.2 was rewritten from "there isn't any" to describe exactly this, PostHog was added to the §7.1 provider table, and the summary table above changed accordingly. (Corrected October 5, 2026: PostHog also added a rough location it estimated from your IP address until October 5, 2026 — see §7.2.) Applies to: the TAGO iOS app,
www.tagorides.com,app.tagorides.com, and our email and support channels.
1. Who we are#
TAGO is operated by Tago Rides, Inc., a Delaware C corporation (incorporated July 2, 2026). In this policy "TAGO", "we", "us" and "our" mean Tago Rides, Inc. "You" means the person using TAGO.
- Privacy questions and privacy-rights requests: [email protected]
- General support: [email protected]
- Notice of a legal claim (service of process only) must be sent to our registered agent: Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA. Please do not send privacy requests or support questions there — nobody at that address can act on them.
We are the business (under California law, the "controller") for the personal information described here. TAGO operates only in California today: the Sacramento region and the Bay Area are live, and Southern California is not.
TAGO is not a transportation carrier, taxi service, common carrier or transportation network company. We do not own, operate or control any vehicle and we do not provide transportation. We connect people who are already making a trip. This matters for privacy because it explains why our data is ride-coordination data, not commercial-passenger records.
2. The short version of what we collect#
| We collect | Because |
|---|---|
| Your email, name, phone, photo | So the person you are carpooling with knows who to meet |
| Your date of birth | Stated purpose: adults-only access. See §11 — it is not currently enforced |
| Optional profile details (bio, gender, school, major, graduation year) | You choose to show them |
| Optional accessibility needs | To match you with a suitable vehicle or a caregiver seat |
| Your vehicle details, if you drive | So a rider can identify the car, and because registered seat count is the denominator of our cost cap |
| Locations, routes, addresses and live GPS | Matching, navigation, pickup, and measuring distance for the cost share. §3 |
| Payment identifiers and a cent-amount ledger | To move the cost share. Card and bank details go to Stripe, never to us |
| Messages you send in the app | Coordinating the ride |
| Ratings and reports | Trust and safety |
| Names and phone numbers of people you add (trusted contacts, caregivers, companions) | Safety and companion seats. §12 |
| Push notification tokens | To notify you |
| No driver's licence, no background check, no insurance document | We do not vet drivers and never claimed to. §4.2 |
| Which TAGO features you use (a fixed list of named events — e.g. "opened search", "posted a trip") | To see which features work and which fail you (first-party analytics, §7.2). Still nothing about your behaviour across other apps or websites, and no advertising SDK at all |
The rest of this document is the long version.
3. Location data#
Location is the most sensitive thing TAGO holds, so it gets its own section first. Under California law, precise geolocation is "sensitive personal information" — see §9.4.
3.0 The two modes, in one place#
Everything below is one of two things. If you read nothing else in this section, read this.
| Foreground snapshot | Ride tracking | |
|---|---|---|
| When | You open the app, or tap a TAGO notification, while signed in | Only while a ride of yours is active |
| How often | One reading, then nothing. Throttled to at most about once every five minutes | About every five seconds |
| In the background? | Never. The app must be on your screen | Yes, on iOS, for the duration of the ride only |
| What it is for | Working out which region you are in, showing you nearby events and places, and seeding matching. Your phone does that part itself. A copy of the point is also stored on our side — see (d) | Measuring the distance actually travelled, so the shared cost is real; showing the other person where you are; the divergence safety net |
| How to stop it | Email us, or turn TAGO's location access off in iOS Settings. §3.1(d) | It stops itself when the ride ends. You can also end or cancel the ride |
The blue iOS location indicator is the honest signal: it is on for the whole of ride tracking, and it is not on the rest of the time.
3.1 The four times your location is collected#
(a) When you search or post a trip. The addresses or map points you enter, and the route between them. If you save a home or work address for quick picking, we store it until you delete it.
(b) While a ride is active — continuous background tracking. Both the driver's phone and the rider's phone send a GPS point roughly every five seconds, in every non-finished ride state (including before pickup). This is the one place TAGO tracks you continuously, and it exists for two reasons: billing — the shared cost is worked out from distance actually travelled, not from a map estimate — and safety, because the other person can see you coming, and because if the two phones diverge by more than 500 metres for more than two minutes the system flags it and can end the ride automatically.
Those points are kept, not just counted. Until August 2026 each point was folded into a distance total and the coordinates discarded; since August 2026 the points themselves are stored as part of the ride's record — the actual path the car and each phone took. We keep them so a fare, an automatically ended ride, or a safety incident can be reviewed afterwards against what really happened. The trail is visible only to TAGO staff on the internal ride record — never to the other person on the ride or to any other user — it is retained with the ride's own record, and deleting your account erases your points along with the rest of your location data (§9).
On iOS this continues in the background only while a ride's status is active. iOS shows the blue location indicator the whole time background tracking is on, and it turns itself off when the ride completes or is cancelled. There is no other circumstance in which TAGO reads your location while the app is not on screen.
About "Always" location — we do ask, in one place. The app requests "While Using the App" as standard. Separately, if a driver force-quits the app during a ride, the app can show a prompt with an Allow button that asks for "Always" location, so measurement resumes by itself instead of the ride going dark. That prompt is optional: declining it does not stop you driving on TAGO, and granting it does not start any collection outside the four cases in this section. We are naming it because "we never ask for Always Allow" would have been false — the permission string for it is declared in the app and the prompt is reachable by a driver.
(c) When you scan the QR code at pickup and at drop-off, we record the coordinates and time of each scan. Those two points define the start and end of the measured trip and are the evidence we use if there is a dispute.
(d) Every time you open the app while signed in — one snapshot, foreground only. Your phone takes a single position reading, throttled to at most about once every five minutes, including when you arrive by tapping a notification. This is not tracking: it is one point, taken while the app is on your screen, and only the latest one is kept — we do not build a history or a trail from it.
Two different things happen with that reading, and they deserve separating.
- To work out your region, the app sends that reading to our server, which looks up which region it falls in and sends the answer back; the server does not keep the coordinates from this lookup. Your region then drives what you see: the home screen, nearby events and places, the trip board you are shown, and matching.
- On our side, the point itself is also stored, overwriting the previous one. To be straight about why: that stored copy exists for operational visibility for TAGO staff — an internal "where is this user?" map used for support and incident investigation — not a feature you can see. Our own engineering notes said this had to be disclosed here before real users were onboarded, and it had not been. This paragraph is that disclosure.
You can switch (d) off without losing the app. Email [email protected] with the words "no background location" and we will blank your stored point and stop keeping it. Matching, pickup and distance measurement keep working, because those use location during a ride. You do not have to justify the request and we will not ask why. Today this is a manual switch; an in-app toggle is on our fix list.
Turning off iOS location for TAGO entirely also works — iOS Settings → Privacy & Security → Location Services → Tago — but it degrades pickup, matching and distance measurement, so it is the worse option. Signing out or keeping the app closed also stops it.
3.2 Every place location lives#
TAGO keeps location in six distinct stores. Naming them all is the honest way to answer "what do you have on me".
| Store | What it is | How long |
|---|---|---|
| Your last known point | One latitude/longitude/timestamp on your profile row, overwritten each time (§3.1d) | Latest value only; never expires, never blanked |
| Driver live position | One row per driver with position, heading, speed and online state, written while a driver is online | Latest value only |
| Rider pickup position | One row per ride, written while you walk to the pickup | The row is not deleted when the ride ends, even though its own schema comment says it is meaningless afterwards |
| Ride GPS columns | Accumulated distance plus the last point from each phone, on the ride record | Indefinite |
| Scan forensics | Pickup and drop-off scan coordinates and times | Indefinite |
| Offline GPS batch receipt | A receipt that a batch of points buffered offline was uploaded once, so a flaky reconnection cannot double-count the distance. It holds no coordinates — a count, a total distance, and which ride and account it belonged to | Indefinite. It has no automatic link back to your account record, so deleting it has to be done deliberately rather than by cascade (§6) |
Alongside those we keep the stated geography of your trips: origin and destination points and names, pickup and drop-off points, notes, encoded route lines, board post addresses, recurring commute routines (days, times, route), saved addresses, and multi-rider trip segments.
There is also a legacy home_location point on the profile record from an
earlier version of matching. We could not find any code that still reads it. We
are treating it as data to delete rather than data to justify.
One more place an approximate location may exist: until October 5, 2026, our analytics provider added a rough location estimated from your internet (IP) address to analytics events (§7.2). It no longer does. Events recorded before then still carry that estimate. It is city-level, not your actual position, and it is held by PostHog, not in our database.
3.3 Who your location goes to#
- The person you are carpooling with, for the ride you share.
- Anyone you give a tracking link to. You can generate a link and send it yourself (through your own Messages app — TAGO does not send it). The link needs no login and returns one live coordinate and timestamp for one ride. It expires after four hours and you can revoke it sooner — on the ride's safety screen in the app, where you created it; or email [email protected] and we will kill it for you. The link is usable from the moment a ride is requested, not only while it is moving, and it works for anyone it is forwarded to, with no login. The link record itself is not deleted when it expires; it stops working.
- Map and routing providers, to draw routes and measure distance — Google Maps Platform (Routes, Directions, Geocoding, Places) and Apple Maps Server API. They receive coordinates or address text. They do not receive any identifier for you.
- TAGO administrators, including a live map of every user's last known point with name and email attached. §7.4.
- Not other TAGO users. A signed-in account that is not carpooling with you gets your name, photo and rating and nothing else. It cannot read your saved addresses, your last known point, or your position. A driver's live position resolves only for the rider they are matched with, or a rider they have an open offer out to, and only while that ride or offer is live. §4.3.
- Not an AI service. We do not send your location, or anything else about you, to any AI service — see §7.3.
- Anonymous visitors to our public trip board — but only through a redaction layer. An unauthenticated search never receives a name, exact coordinates, exact time, phone number, user id, row id or address. Those fields are absent from the response, not hidden by styling. On top of that, if fewer than three trips match a search, the caller gets an honest count and no rows at all, because in a town the size of Davis one match from one address at 8am identifies a specific person. This is the part of our system we are proudest of.
3.4 What we do not do with location#
We do not sell it. We do not share it with data brokers, advertisers or ad networks. We do not use it to build an advertising profile, we do not derive inferences about you from it, and we do not track you across other apps or websites. Our product analytics (§7.2) never receives your GPS location: no position from your phone, route lengths only after rounding into broad distance buckets, and a searched destination only as its public name — never where you started from. Until October 5, 2026, PostHog also added a rough location it estimated from your internet (IP) address; it stopped on that date, and it does not keep your IP address. There is no background stream of your movements going anywhere.
4. What we collect, by category#
4.1 Account and identity#
| What | Why | Required? |
|---|---|---|
| Email address and password | Sign-in. The password is handled by our authentication provider; we never see it in usable form | Required |
| Full name | Shown to the person you carpool with; split into first/last for Stripe when a driver sets up reimbursement | Required |
| Phone number | Contact at pickup, safety | Required |
| Profile photo | So you are recognisable at the kerb | Optional |
| Date of birth | Stated purpose is adults-only access. See §11 | Required to finish onboarding |
| Bio, gender, school, major, graduation year | Optional social profile shown on trip cards and in the waiting room | Optional |
| Accessibility needs (wheelchair, caregiver required, free-text notes) | Matching you to a suitable vehicle or seat | Optional |
| Onboarding progress, last active time, suspension state | Running the service and enforcing the Terms | Automatic |
| Referral code and who referred you | Referral rewards | Automatic if you use a referral |
Two honest notes on this table:
- We do not verify your phone number. There is a "verified" flag on the account record, but a client app can set it itself; there is no code that actually confirms possession of the number. Do not read a verified badge as proof of anything, and we will not describe phone numbers as verified.
- The free-text accessibility notes field does not change matching. It was added as product-research input. If you would rather not provide it, don't — nothing depends on it.
4.2 Vehicle information (drivers only)#
Make, model, year, colour, licence plate, body type, seat count, accessibility features, an optional photo of the car, and the vehicle identification number (VIN).
We collect no driver's licence, and we do not vet drivers. No licence number, no licence photograph, no background check, no driving record, no insurance document. There is no such field anywhere in our systems, so there is nothing for us to lose, leak or hand over. If you were looking for the answer to "how does TAGO vet its drivers" — it does not. A TAGO driver is a private person driving their own car on a trip they were already making, and we would rather you knew that than assume a check we never ran. What you get instead is what a carpool actually offers: you see who they are and what car they drive before you accept, you can rate them afterwards, and you can report them.
Historical note, because it was true until recently: an early version of vehicle onboarding uploaded photographs of licence plates. That feature was removed in May 2026. The column that held those images was dropped from our database at the same time and nothing has been able to write one since; the stored files and the bucket holding them are being removed through our storage provider. We will say "removed" here in the past tense when the bucket is confirmed empty and gone, and not before.
The registered seat count matters legally: it is the denominator used when capping what a driver may be reimbursed per seat, which is what keeps a full car from multiplying a driver's recovery. The trip total is clamped so a full car recovers the cost of the trip and no more — a fourth rider splits the same 100% four ways rather than pushing the driver above the ceiling. A $2.00 per-seat minimum used to sit inside that calculation and could lift the cap above the mileage ceiling on short trips; it was removed on 1 August 2026 and survives only as the lowest price a driver may be shown on the price slider, never in what is actually charged or settled. That is a pricing matter rather than a privacy one; Terms of Service §6.2 describes the cap.
The VIN is a problem we are naming, not defending. We collect a full VIN and we could not find a single place in our code that reads it — not matching, not the cost share, not safety, not display. A VIN identifies a vehicle and, through public records, its owner. It is on our list to delete.
4.3 What other TAGO users can see about you#
There are three tiers, and it is worth knowing which one a given person is in.
Tier 1 — any signed-in TAGO user. From your personal record: your name, your profile photo and your rating (its average and how many ratings it is based on). That is the complete list from that record. Your email address, your phone number, your date of birth, your saved addresses, your wallet and payment identifiers, your last known location and every coordinate we hold about you are not in it and cannot be reached by another account.
If you drive, some of your car is in Tier 1 too. A signed-in user can see the make, model, year, colour, body type, seat count, accessibility features and photo of a car attached to a posted trip — that is how a rider decides whether a car suits them before they ask for a seat. Your licence plate is not in that list, and neither is your VIN. Until 1 August 2026 the plate was readable by any signed-in account; that was a leftover from an earlier access model, it was the same category of over-broad permission we closed for personal records on 31 July, and it is now closed. The plate is released only to the person you are actually carpooling with, or to a driver who has a live offer out on your request — they need it to identify the car at the kerb — and never to anyone else.
One honest qualification, because the tidy version would be misleading. Your car photo is stored in a public bucket, which means the image file can be fetched by anyone who has its address, without signing in. Most people photograph their car from an angle that includes the plate. So if your photo shows your plate, your plate is reachable through the photo even though it is no longer readable as a data field. We are working on closing that, and until we do, the practical advice is simple: photograph your car so the plate is not legible, or crop it out. We would rather tell you this than let the paragraph above imply a protection the photo route defeats.
Your posted trips are also visible to signed-in users, because publishing a trip to the board is the point of posting it. To anonymous visitors they appear only through the redaction layer in §3.3. An open instant ride request is likewise readable by accounts marked as drivers, because that is how a driver finds a request to accept — and we should say that the driver marking is something an account sets on itself rather than something we verify.
Tier 2 — the person you are actually carpooling with. Everything in Tier 1, plus the trip's pickup and drop-off, your live position during the ride, your messages in that thread, and — only if you chose to provide them — the accessibility needs relevant to the ride. A driver's live position is readable by the rider they are matched with, or a rider they have an open offer out to, and it stops resolving when the ride completes or is cancelled. Accessibility information, which is health-adjacent, is deliberately kept out of Tier 1 so it can never be swept up across the platform.
Tier 3 — TAGO administrators. Everything. §7.4 lists it item by item, and does not flatter us.
How this is enforced, without drawing you an attack map. Access is enforced in the database itself, not in the app: your own record answers only to you, and everyone else reaches you through narrow, purpose-built projections that expose exactly the fields above and cannot be widened by a client asking nicely. We are deliberately not publishing table names, policy names or migration numbers, because a precise public description of an access model is a map for someone attacking it.
An earlier draft of this policy said something worse, and we are noting the change rather than quietly deleting it. Until 31 July 2026 a signed-in account could read far more of another user's record than the product ever displayed — including contact details, date of birth and last known position. That is closed, for personal records and for drivers' live positions, which now resolve only to the rider actually matched with that driver and stop resolving when the ride ends. The same permission on vehicle records — the one that made every driver's plate readable — was closed on 1 August 2026, and the paragraph above describes what replaced it. If you read a previous version of this policy and left fields blank because of it, you can fill them in now. What remains open is the car photo, for the reason given above.
Profile photos and car photos are stored in public buckets. They are served from web addresses that need no login, and the file name is derived from your account id, so a determined party could guess a path. Treat your TAGO profile photo as a public photo. We intend to move these to private storage with short-lived signed links. This one is still open.
4.4 Payments#
We never receive your card number, bank account number, Social Security number, or the identity documents Stripe asks drivers for. Those go directly to Stripe, which collects them in its own interface and holds them under its own retention rules. We searched all 196 of our database migrations: there is no column anywhere for a card number, a bank number, an SSN, or a KYC address.
What we hold ourselves:
| What | Why |
|---|---|
| Stripe customer / connected-account identifiers, whether onboarding finished, default payment method id | To charge a rider and to send a driver their reimbursement |
| A ledger of cent amounts: type, amount, resulting balance, description, ride, source | The cost-share record and the audit trail |
| Wallet balance and non-withdrawable promotional credit | Balances you can see in the app |
| Ride payment state: payment intent id, status, the processing-fee estimate, amounts | Settling a ride |
| Loyalty points, ledger entries and cash-out records | The points feature |
When a driver sets up reimbursement, we pre-fill Stripe with the driver's email and a first/last split of their name. We deliberately do not pass the phone number. We read back only a payout-method last-four and label to show in the app.
4.5 Messages#
Messages you send in a ride thread, in a pre-match offer thread, or in a group thread are stored with your account id, the ride or thread, the text, and the time.
Three honest facts about them:
- No AI reads your messages. No automated moderation reads your messages. There is a placeholder function for scrubbing contact details out of pre-match messages and it currently does nothing at all; the post-match ride chat is explicitly never scrubbed.
- A TAGO administrator can read them in the course of a safety investigation. §7.4.
- They are kept indefinitely. A message whose usefulness expired the moment the ride ended is still in our database. We do not think that is right, and it is on the retention list in §5.
- Deleting your account does not work the same way for all of them. Board, offer and group messages you sent are deleted. Ride chat is kept with your name replaced by a deleted user, because the other person's copy of a conversation is their record too — §6.2 sets out the reasoning and the limit.
4.6 Notifications and email#
We store your device push tokens, the notifications we have sent you (title, body, data, read state), and your notification preferences.
Marketing email and promotional push are currently ON by default — they default to on for a new account, and you have to turn them off. Ride-related push is also on by default; SMS alerts default to off.
To turn them off: in the app, Profile → Settings → Notifications, and switch off the promotional push and marketing-email options (ride notifications and SMS are separate switches on the same screen); or email [email protected] and we will do it for you. Every marketing email also carries an unsubscribe link. We are naming the default because a default is a choice, and this one is opt-out rather than opt-in — which is on our list to reconsider.
For email we store which template was sent to you and when, and your per-template opt-outs. Inbound replies to support become part of a support thread.
TAGO does not send text messages. We have no SMS provider at all. When you use "text my trusted contacts", your own phone's Messages app opens with the text pre-filled and you send it. Caregiver and companion "text" and "call" buttons open your phone's own apps. The emergency button dials 911 from your phone. We record only that you were handed a pre-filled composer — not the content and not whether you sent it.
4.7 Safety, ratings and reports#
- Ratings: stars, tags and an optional comment, in both directions.
- Reports: category, your description, the thread of messages between you and our safety staff (including internal notes we add), and any files you attach.
- Ride safety signals: whether the two phones diverged, when a warning fired, who responded, whether the ride was auto-ended and why.
When a report or emergency alert comes in, a summary — including the report text and identifiers — is posted to a TAGO staff channel in Slack so a human sees it quickly.
Report content includes free-text allegations about other people. It is kept indefinitely, and it survives the deletion of either person's account — the account links are removed from both sides, but the text is not. §6.2 explains why a safety record is kept for the other person's sake, and §6.4 is honest about the consequence: prose we keep may still contain a name we cannot reliably find.
If a report has been filed about you, you have rights over it too. Reports about you fall inside your right to know (§9.2): you can ask us what has been alleged, and you can give us your own account of what happened, which we keep alongside it and read if we act. We may withhold the reporter's identity and details that would identify them, because a safety report a person is afraid to file is worse than no report, and we may withhold information where disclosure would harm someone else or an open investigation.
4.8 Our websites#
On www.tagorides.com we collect what you type into a form: a waitlist entry
(email, which kind of waitlist, a region hint, where you came from) or a
business/university enquiry (company, contact name, work email, size hint,
region hint, message).
These entries are not connected to any TAGO account, even if you used the same email address. Nothing joins them to you, which means deleting your account does not reach them — email [email protected] and we will delete them by hand (§6.4).
Public event pages return marketing fields only — name, description, image, city, region, date, status. No user information, no waitlist, no driver plans.
4.9 Device and technical data#
The app stores non-sensitive preferences on your device, reads file timestamps for its image and caching code, reads system uptime, and checks available disk space for cache management. These are declared to Apple with the reason codes Apple requires.
Crash reports. If the TAGO app crashes, it saves a crash report on your phone and sends it to our analytics provider, PostHog (§7.2), the next time you open the app. The iOS app has done this since September 5, 2026, and the Android app since its launch; on Android this includes crashes in the app's native code. A crash report contains a technical stack trace, the type of error, the app and operating-system version, where available the screen you were on, and your internal TAGO account ID. It contains no messages, location, payment details, name or email. We use crash reports only to find and fix bugs. We do not collect performance diagnostics.
5. How long we keep things#
The honest headline: today, we keep nearly everything indefinitely. There is no scheduled purge, no time-to-live and no retention sweep anywhere in our system for rides, messages, GPS data, trips, transactions, reports or profile records. One of our own migration files literally says "data retention sweep, if one is ever added". We are not going to describe a retention schedule we have not built.
| Category | What actually happens today |
|---|---|
| Account, profile, vehicle | Kept until you delete your account |
| Rides, routes, addresses, board posts, routines, trips | Kept indefinitely |
| All six location stores | Kept indefinitely; the "last known point" and driver position hold the latest value only, the rest accumulate |
| Messages (all thread types) | Kept indefinitely. On deletion, board/offer/group messages go; ride chat stays with the sender shown as a deleted user — §6.2 |
| Ratings | Kept indefinitely; deleted with the account, both directions |
| Reports and report attachments | Kept indefinitely, and they outlive the account with every name unlinked — §6.2 says why |
| Email opt-outs | Kept indefinitely, and they outlive the account as a one-way fingerprint of the address — §6.2 |
| Payment ledger, wallet, loyalty | Kept indefinitely, and the ledger outlives the account with your name removed from it — §6.2 says why |
| Notifications | Kept indefinitely (one narrow cleanup exists for a deleted ride) |
| Tracking-link records | Stop working after 4 hours; the record itself remains until account deletion |
| Push tokens | Deleted when Apple or Google rejects them; the "push to start" variety is pruned at about 30 days; Live Activity tokens are removed when the ride finishes |
| Operational caches (request idempotency keys, suggestion cache) | Short-lived by design |
Note the one place with real retention discipline is push tokens — the least sensitive thing on the list. We are aware of the irony.
What governs retention, since we are not giving you a date we cannot keep. California law asks a business to state either the period it keeps each category for, or — if it cannot — the criteria it uses to work that period out. We cannot honestly state periods yet, so here are the criteria, and they are the ones we will actually apply:
- How long the record is needed to run the service you asked for. A ride's GPS points matter until the cost share is settled and any dispute window has passed. After that they are cost, not value.
- How long a legal obligation requires it. Financial records are the clear case: the IRS baseline for records supporting a return is three years, and seven is the practical standard for payment records. That is why the money ledger outlives an account (§6), and it is the only category where a legal obligation currently pushes retention up.
- Whether it is still needed to keep someone safe — an open safety report, or a pattern of reports, outlives the ride it came from.
- How sensitive it is. The more sensitive a category, the shorter its life should be. Precise location and message content are the first two categories we will put on a clock, precisely because they are the two that would hurt most if we lost them.
- Whether the record is still linked to a person at all. Aggregate and de-identified figures are not on this clock, because they are not about you.
And what we will not do. We will not invent a deadline here to look better than we are. We will publish a category-by-category schedule as the service grows, and when we do it goes in this section with a "last updated" date. You need not wait for it — you can ask us to delete any record today (§9), and that is exactly what the right to delete is for.
5A. Cookies, local storage, and tracking on our website#
The short version: we set no advertising or analytics cookies, we run no third-party trackers, and nothing we store follows you to another website. That is why you are not being asked to dismiss a cookie banner. The paragraphs below list every single thing we store in your browser, by name, so you can check.
5A.1 Cookies#
Two, both first-party (set by us, readable only by us), both HttpOnly (a script cannot read them, including a script injected by an attacker), both SameSite=Lax (they are not sent when another site links into ours).
| Cookie | What it is for | How long it lasts |
|---|---|---|
tago_ps | Counts your free searches on the public site — three a day, so the site can tell you when you have used them without making you sign in. It holds a count and a date, and it is signed so it cannot be edited to grant more. It contains no identifier for you. It is only ever sent to /api/public. | 2 days |
tago_rt | Keeps you signed in on the web app, if you use it. It holds a session token, nothing else. It is not set unless you sign in. | 30 days |
That is the complete list. There is no _ga, no _fbp, no advertising
identifier, and no cookie that is shared with, or readable by, anyone else.
5A.2 Things stored in your browser that are not cookies#
Three values in local storage — a browser feature that keeps a setting on your own device and, unlike a cookie, is never transmitted to us at all:
| Key | What it holds |
|---|---|
tago-theme | Light or dark, so the site does not flash the wrong one at you |
tago-region | Which region you last looked at |
tago-offers-dismissed | That you closed the banner at the top, so it stays closed |
You can clear all three from your browser's settings at any time. Nothing breaks; you get the defaults back.
5A.3 What we deliberately do not do#
- No analytics product. No Google Analytics, no Plausible, no heat-mapping, no session recording. We do not know which pages you read.
- No advertising pixels or conversion tags. Nothing from a social network or ad network is loaded on our pages.
- No cross-site tracking, so no "Do Not Track" or GPC signal to honour here. There is nothing to opt out of, because there is nothing following you. §8 explains the same point for advertising generally: any promotion you see is chosen from the page you are on, never from a profile of you.
- No fonts, scripts or images loaded from someone else's server on our marketing site, which is the quiet way most sites leak your IP address to a third party. Ours does not.
5A.4 The one exception, and it is not on the website#
Our iOS app uses Apple's App Store and push infrastructure, and our servers run on infrastructure operated by the providers listed in §7. Those are service providers, not trackers, and none of them receives a browsing profile. Our Apple privacy disclosures are shown on the App Store listing.
6. Deleting your account — exactly what happens#
You can delete your account from inside the app (Profile → Settings → Delete account), or by emailing [email protected]. Deletion is immediate and permanent, not a 30-day soft delete. You cannot delete while you are in the middle of a ride — the app refuses and asks you to finish or cancel it first, because tearing down a live ride would take the other person's ride down with yours.
What follows is written from the deletion routine itself, table by table. It is a description of what the code does, not a statement of what we intend it to do. The routine also checks afterwards that your account row is actually gone and reports a failure if it is not, so "deleted" is never a guess.
6.1 What is erased#
- Your account and profile — name, email, phone, photo, date of birth, bio, school, major, graduation year, accessibility information, referral links, and your sign-in identity itself.
- Your vehicles, including licence plate and VIN.
- All of your location data — saved addresses, your last known point, your driver position row, your rider pickup rows, the GPS on your rides, the pickup and drop-off scan coordinates, and the offline batch receipts in §3.2. Those receipts have no automatic link back to your account record, so they are removed by a step written specifically to catch them rather than being left to a database cascade.
- Your photos, from storage and not merely unlinked — your profile photo, the photos you added for a caregiver or companion, and your car photos are deleted as files. The one exception is a file attached to a safety report (§6.4).
- Your trips and posts — the rides you took or drove, board posts, driver and rider routines, the offers you made and received, destination requests, waitlists and plans, ride suggestions, decline reasons, board runs and read receipts.
- Your notifications, push tokens, Live Activity tokens, notification preferences, and the log of emails we sent you.
- Ratings you gave and ratings you received, and your loyalty balance and points history.
- The internal bookkeeping behind any automatic refund you were part of, including the reference numbers that tie it to Stripe. The money itself stays in the ledger described in §6.2; only our cross-reference to Stripe's own record goes.
- The details of other people you gave us — trusted contacts, caregivers and companions.
- Your messages in board threads, offer threads and group threads. Ride chat is the one thread type handled differently, and §6.2 explains why.
6.2 What is kept, and exactly why#
Five things survive a deletion. In every case, what survives has had you taken out of it.
1. The money ledger, with your name taken off it. Your transactions — the amounts, the dates, the type of each entry — survive account deletion. What does not survive is the link to you: the account reference on each row is removed, the ride reference is removed with the ride, and in their place we store a one-way cryptographic fingerprint derived from your former account id. That fingerprint cannot be turned back into your identity, and it is not reused anywhere else in our systems. Its only job is to let one former account's rows be reconciled as a group, so our books balance. The per-rider split behind each entry is kept on the same terms, with every name removed, because a ledger line nobody can check is not much of a record.
Why we keep it rather than delete it: a business must be able to produce the records behind its tax return. The IRS baseline is three years and the practical standard for payment records is seven. If a real name is ever needed for tax reporting, it comes from Stripe, which holds the verified identity record — not from us, because after deletion we no longer have one.
Our promise about that fingerprint. Keeping something with your name taken off it is only meaningful if we then leave it that way, so here is the commitment, and we mean it as a promise rather than a caveat:
We do not try to work out who de-identified data belonged to. We will not attempt to reverse the fingerprint, and we will not match it against anything else we hold — an old log, a backup, a support email, our payment processor's records — to work out that these rows were yours. We do not let anyone else do it either: if we ever share de-identified information with a third party, we require them in writing to keep it de-identified and never to re-identify it. And we keep it that way in practice, not just on paper — the fingerprint is one-way by design, we hold no key that would undo it, and the rules above are written into the code and the schema definitions that hold these rows, so the next engineer meets them before they meet the data.
The single exception, and the only one we will ever take: we may test our own de-identification to confirm it is actually working. That is us checking our homework, not us looking you up.
Where that promise is currently a promise rather than a locked door, stated plainly. A commitment like this should rest on more than our word, so here is exactly how much of it is enforced by the way the system is built and how much is still only undertaking. Enforced: the fingerprint is a one-way hash and we hold no key that reverses it; the reference we now give our payment processor for a new record is a random number, not anything computed from your account, and the only table that ever mapped it to you is your account row — which deletion destroys, so after you leave, that number correlates with nothing we hold. Not yet enforced: payment records created before August 2026 still carry our internal account number in the processor's own metadata, and our internal account number is what the ledger fingerprint is derived from. So for those older records the link is, technically, still reconstructable by us. The code that clears that older metadata is written and has not yet been run. Until it has, the commitment above is what stands between those records and a re-identification, and we would rather you knew which parts are a wall and which parts are a promise.
Anything we hand to a partner or publish is aggregate rather than row-level — see §9.5, where the same promise covers our statistics.
2. Safety reports, in both directions. A report about you stays, and a report you filed stays. Your name comes off both: the reporter, the subject, the assigned staff member and the resolver are all unlinked, the messages in the investigation thread keep their text with the author unlinked, attached evidence keeps the file with the uploader unlinked, and the log of who did what to the report keeps the actions with the actor unlinked. The content is not deleted, because the content is the entire point of a safety record.
Until 1 August 2026 this ran backwards — a report about you survived while a report you filed was destroyed, which is exactly the wrong way round, since the report you filed is the record protecting somebody else. We fixed it rather than quietly leaving it.
3. Your side of a ride conversation, shown as a deleted user. Ride chat is not only yours; it is also the record of the person you carpooled with, and deleting your half leaves them holding a one-sided conversation with their own replies to statements that no longer exist. So the messages stay and your name is replaced — the app shows a deleted user where you were. This is how Airbnb, Uber, Slack and Discord treat a shared conversation, and it is the answer that respects both people rather than only the one who left.
There is a real limit on this and it works in your favour: a ride chat belongs to a ride, and your rides are deleted, which takes their chat with them. The only place one of these placeholders survives is on a ride belonging to the other person. Everywhere else, the conversation is simply gone.
4. Your unsubscribes — as a fingerprint, never as an address. If you turned marketing email off, that instruction outlives your account. It has to: a suppression record that dies with the account means the next list import or re-signup mails somebody who explicitly asked not to be mailed. We keep it as a one-way fingerprint of your email address and nothing else — no address in readable form, no account link, and any note attached to the opt-out is cleared. The row can prove "do not mail this address" without holding the address, and our mailer checks it before every send.
5. Staff attribution, if you were a TAGO administrator. Published items an administrator created — a mileage rate, an email template, a curated listing, an entry in an audit log — keep the item and drop the person. This applies to staff accounts, not to riders and drivers.
Beyond those five: anything needed to finish a transaction already in flight, and anything else the law requires us to keep for as long as it requires it. Aggregate and de-identified figures — how many trips ran on a corridor in a month — are not affected by deletion, because they are not about you (§9.5).
6.3 Why anything is kept at all#
It would be easy to write "we delete everything" and quietly not. Here is the honest version instead.
Both California's privacy law and Europe's say the same thing about erasure, in almost the same words: the right to have your data deleted does not extend to records a business needs in order to keep people safe, to deal with fraud and abuse, or to satisfy an obligation the law itself imposes — a tax obligation being the obvious one. This is not a loophole a company invokes to keep what it likes. It is written into the right, because a right to erasure without it would mean that filing a safety report and then closing your account erases the report, and that closing your account erases the records behind a tax return.
So the shape of the carve-out is narrow, and worth stating plainly:
- Safety records are kept because they protect the other person, not because they are useful to us. A report exists to warn about a pattern. If a person could delete the report they filed by closing their account, the person they warned us about gets a clean slate; if they could delete a report filed about them, the same thing happens more directly. Neither is a privacy win — the cost falls on somebody else entirely.
- Financial records are kept because a business has to be able to show its work. Not to profile you, not to market to you, not to sell — to answer a tax authority asking what a payment was.
- A conversation is two people's record, not one. Your name comes off it; the other person keeps what they took part in.
- An unsubscribe is kept because deleting it would hurt you. It is the one case where erasing data is the harmful option.
And the test we hold ourselves to: in every one of those cases the record survives and the person does not. We are not keeping "your data with a note attached" — we remove the account link, and where a fingerprint replaces it, that fingerprint is one-way and useless for finding you. What we cannot do that for, we say so in §6.4 rather than implying otherwise.
6.4 The limits — what deletion does not reach#
Every one of these is a real gap. We would rather you learned about them here.
- Free text inside a safety report may still name you. Report titles, report bodies and the messages in an investigation thread are prose written by a person, and we keep them because that is the record. If somebody wrote your name in one, unlinking your account does not remove the name, and there is no automated scrub of prose we would trust to find it. If this matters to you, email [email protected] and a person will look at the specific report.
- The counterparty's copy of a ride conversation keeps what you wrote, with you shown as a deleted user (§6.2, item 3). If you named yourself in a message, that text stays in their thread.
- Files attached to a safety report stay in storage. Your profile and car photos are swept from storage; a photo attached to a report is not, because deleting the evidence would defeat keeping the report. The link to your account is removed.
- Waitlist and business-enquiry entries from our website are not reached by
account deletion. If you joined a waitlist at
www.tagorides.comor sent a business enquiry, that entry holds the email address you typed and has no link to any TAGO account — nothing joins it to you, so deleting your account cannot find it. Email [email protected] and we will delete it by hand; it is a manual step because of how the form was built, not because we are reluctant. Fixing that link is on our list. - Marketing posters created by staff keep the creator's raw account id. This affects staff accounts only, and the id no longer resolves to anybody.
- Stripe keeps its own copy. Stripe holds the payment and refund records it processed, and — for drivers — the identity documents it collected for verification. That is Stripe's record under Stripe's retention rules, not ours, and we cannot delete it for you. Contact Stripe directly about it. Our own cross-reference to those records is deleted with your account.
- Backups. We have not audited what our database provider's backups and point-in-time recovery retain after a deletion, so we are not going to make a claim about them. It is on our list, and when we know, this bullet changes to the answer.
6.5 Rows that belong to somebody else#
If you added a trusted contact, a caregiver or a companion, you gave us another living person's name and phone number. Deleting your account deletes the copy you gave us. But the reverse also holds and matters more: if you are one of those people, you have a removal right of your own and you do not need a TAGO account to use it. Email [email protected] and we will remove the details after reasonable verification that they are yours — we will not tell you who added you unless doing so is safe and lawful, and we will not need to. §12.
The same runs the other way, and it is the reason for §6.2 and §6.4. If another person added you as their trusted contact, caregiver or companion, that row is theirs — it lives on their account and is deleted when they remove it or delete their account, not when you delete yours. You can still ask us to remove it, and we will. Likewise a safety report naming you, or a message they sent in a ride you shared, is that person's record as well as yours. We will not delete a third party's own record of a shared event on your say-so, but you can ask what has been alleged, correct it, and add your own account of it (§4.7).
6.6 If any of that fails#
If you email [email protected] and ask for full erasure, a person will complete it by hand. Any gap in our automation is our problem, not a limit on your right. That request runs on the §9.3 clock: we acknowledge within 10 business days and complete it, or refuse in writing with reasons, within 45 calendar days, subject to verifying the request is yours and to the retention carve-outs in §6.2. The items in §6.4 are exactly the ones that need this route: a name inside a report, a website waitlist entry, a file on a safety record. Ask, and a person deals with it.
If the automated deletion cannot finish — if some part of your account will not come away — we do not report it as done. The routine checks and fails loudly, and we retry.
7. Who receives your information#
We do not sell it (§8). We do share it with the providers below and with the people you carpool with. These are service providers in California's sense — they process information on our behalf, for our purposes, under a contract. Some providers receive nothing about you at all — for example a public US government energy price reference that we query with a two-letter state abbreviation for a driver-facing informational display.
7.1 Service providers, and exactly what each one gets#
| Provider | What it does for us | What it receives |
|---|---|---|
| Supabase | Our database, authentication, file storage and realtime updates | Everything described in this policy. It is our primary sub-processor |
| Stripe | Payments and driver reimbursement | Rider: card details entered in Stripe's own interface, email, customer id. Driver: email, first/last name, and everything Stripe collects itself for identity verification. Plus amounts and our internal account id as metadata |
| Google Maps Platform (Routes, Directions, Geocoding, Places) | Routes, distance, address search | Coordinates, address text, and the search string you typed, with a California location bias. No identifier for you |
| Apple Maps Server API | ETAs and geocoding | Coordinates. No identifier for you |
| Firebase Cloud Messaging (Google) | Delivering push notifications to Apple | Your device push token and the notification content — which routinely contains the other person's first name, route labels and a ride id |
| Apple (APNs, Live Activities) | Notification and Live Activity delivery | Push token, notification and Live Activity content, activity id |
| Resend | Sending our email and receiving replies | Your email address and the full subject and body, which may contain your first name and trip details |
| PostHog (PostHog, Inc., US cloud) | First-party product analytics (§7.2) | Named feature-usage events under your internal account ID. Never: your name, email, phone, messages, payment details, or coordinates from your device (until October 5, 2026 PostHog added a rough location estimated from your IP address; it no longer does, §7.2). Distances arrive as broad buckets; searched destinations as public place names only |
| Slack | Alerting our safety and operations staff, in a staff-only channel | Report and emergency alert text, including the reporter's name or email and the report's text; for safety reports, the location attached to the report; and payment alerts with internal account and ride identifiers and amounts |
| Amazon Web Services | Hosts our API server (US) | Everything that passes between the app and our database while our server processes it, plus our server's logs |
| Cloudflare | Network security and delivery for our API and websites | All traffic between your device and our servers, including your IP address. Cloudflare decrypts it in transit to filter attacks and route it |
| Vercel | Hosts our website and our internal admin tools | For website visits: your IP address, request details and the referral cookie (§5A), plus any requests the website passes on to our API |
| Twilio | Sends sign-in codes by text message, through our authentication provider | Your phone number and the one-time code |
| auto.dev | Looks up a vehicle's details from its licence plate when a driver adds a car | The licence plate and state you enter. No name or account identifier; it sees our server, not your device |
7.2 Analytics: first-party, feature-usage only (changed August 13, 2026)#
Until August 13, 2026 this section said "there isn't any", and that was true. It changed, and here is exactly what changed and what did not.
What we added. The TAGO app and our own server now send product-analytics events to PostHog (PostHog, Inc., hosted in the US). Every event is one we wrote by hand, from a fixed named list in our code — "opened search", "posted a trip", "joined an event waitlist", "a ride completed" — with automatic capture of screens and taps OFF, session recording OFF, and screen-sniffing OFF. If an action is not on that list, nothing is sent — with one exception: if the app crashes, a crash report is sent automatically (§4.9). We use this to answer questions like "do people who find no rides give up, or post their own?" — questions we previously could not answer and were guessing at.
What an event carries. Your internal account ID (a random string we assigned you — a pseudonym; PostHog is never given your name, email, or phone number), the event's name, and a few properties of the action itself: a result count, a role, a payment outcome, a route length after rounding into broad buckets (such as "5–15 km"). When you search the ride board, the destination's public name is recorded (say, a campus or a transit station) — never where you started from, because a starting point is usually a home address, and the app never sends coordinates of any kind, in either direction.
Approximate location from your IP address — stopped October 5, 2026. Until that date, when an event reached PostHog, PostHog estimated a location from the internet (IP) address it came from — typically city, region and country, plus approximate coordinates for that area — and added it to the event. On October 5, 2026 we switched this off, and PostHog no longer keeps the IP address itself. Events recorded before then still carry the estimate until we delete them, and for no longer than 7 years, PostHog's retention period for event data. If you want yours removed sooner, email [email protected] and we will delete them by hand.
What did not change. No tracking across other apps or websites. No
advertising SDK, no ad identifiers, no audiences, no data brokers, no selling —
all of §8 stands word for word. The app's Apple privacy manifest still declares
NSPrivacyTracking = false, and that is still accurate: first-party analytics
under a pseudonym is not cross-context tracking. PostHog is a contractually
bound service provider like every other row in §7.1, processing this data only
for us.
Separately and unchanged: PostHog also runs inside our internal staff console (no user identification there at all), and our own server keeps two internal counters that are not linked to you — one counts our paid map and geocoding calls so we can watch our own bill; the other counts how many times a promotional placement was shown or tapped, per placement per day (§8.2).
7.3 Artificial intelligence#
We do not use any AI service to process your information. Nothing about you — not your profile, your trips, your location, or your messages — is sent to an AI provider, and no AI reads your chat. (Until October 4, 2026 we used Google Gemini internally to draft marketing copy; that feature and its code have been removed.)
7.4 TAGO staff#
Access is gated on an administrator flag on the account record, checked server-side on every administrative request, and administrative changes are written to an audit log.
An administrator can see: your entire profile record including date of birth, wallet balance and Stripe identifiers; a live map of every user's last known position with name and email; your wallet and full transaction ledger; your notifications and raw push tokens; the names and phone numbers of trusted contacts you added; your vehicle details including licence plate; complete ride records including GPS and scan data and cancellation reasons; and full safety report threads with internal notes and attachments.
There are no least-privilege tiers. Administrator is a single flag: every administrator can see everything on that list. Since October 3, 2026, signing in to the admin panel requires a second factor or a passkey for every administrator.
7.5 Other disclosures#
We may disclose information when we are legally required to, to respond to lawful process, to protect someone's safety, to enforce our Terms, or in connection with a merger or sale of the business — in which case this policy continues to apply to the transferred information until you are given notice of a change.
8. How TAGO makes money — and what that means for your data#
This section exists because "how does a free app pay for itself" is the question behind most privacy worries. Here is the whole answer.
8.1 Not from your data. Ever.#
We do not sell personal information. Not for money, not for anything else of value. We do not share personal information for cross-context behavioral advertising. In California's statutory language, we do not "sell" and we do not "share".
We do not sell your personal information and we will not. That is a firm commitment, not a current-practice statement we intend to revise, and Tarun Gautam has recorded it as a founder decision. If it ever changed, this policy would have to be rewritten and you would have to be told first.
One qualification so the sentence stays true: "we do not sell or share" is about selling and about cross-context behavioural advertising. Every company we use is a contractually bound service provider (§7.1).
This matches the code. No advertising SDK is linked into the TAGO app. No audience, segment, cohort, hashed email,
advertising identifier or device advertising id leaves our systems in any
repository we maintain. The app's Apple privacy manifest declares
NSPrivacyTracking = false with an empty tracking-domains list, and that is
accurate.
Two entries in the app's dependency lock file mention Google Ads and Google App Measurement. They are resolved as indirect dependencies of the Firebase package and are not linked into the app. We mention them so that anyone who inspects the file and worries has an answer.
We take no commission on rides. The platform fee rate in our code is zero, every settlement path sets it to zero, and an invariant check refuses to credit a driver if the arithmetic does not add up. So there is no per-ride revenue, which is exactly why the rest of this section exists.
8.2 Advertising is contextual only — now and as a rule#
All TAGO advertising is contextual. Contextual advertising means the ad is chosen from the page, not from the person. The classic comparison: a petrol advertisement in a car magazine is contextual — it is there because of what you are reading, and the magazine does not know or care who you are. Behavioural advertising is the opposite: it follows a profile of you from page to page. TAGO does the first and will not do the second.
Concretely:
- An ad is selected from what is on the screen or in the request — the region being viewed, the corridor or route being browsed, the event page you are on, the general category of the page.
- No identifier for you is sent to an advertiser or ad network. Not your account id, not a device identifier, not an advertising id, not a hashed email, not a cookie that follows you, not an audience segment, not an inference about you.
- No profile is built. We do not combine your trips into a person-level profile for ad selection, and we do not let anyone else do so.
- Nothing is sent about you across contexts. An advertiser learns that someone looked at a page about Sacramento-to-Davis carpools. It does not learn that you did, and it cannot recognise you somewhere else.
- This is not a setting. There is no configuration switch that would turn contextual selection into targeted selection, because there is nothing about you in the selection at all. Changing that would mean building something new, and building it would mean rewriting this section and telling you first.
This is a commitment about system design, and it is the reason the next paragraph is true.
What exists in the app today. There is no third-party ad SDK and no ad network in TAGO — no outside company receives a request from your device to fill a slot. What does exist is our own promotional placements: cards we create and serve ourselves into four named surfaces in the app (the home screen, the two "see all" screens for events and places, and search results). Which cards you see is chosen from the surface you are on and the region being viewed — nothing else. The app reports back how many times a card was shown or tapped, per card, per day, per surface. That report carries no account id and no device identifier, so it tells us a card was seen, not that you saw it. If we ever add an outside ad network, or select a placement using anything about you, this policy is updated before that ships.
8.3 Why there is no "Do Not Sell or Share My Personal Information" link#
California requires that link when a business sells personal information or shares it for cross-context behavioral advertising. We do neither, so there is nothing for the link to opt you out of. We have also not built Global-Privacy-Control handling for the same reason.
We want to be clear about the direction of that logic. The absence of the link is a consequence of the design, not a shortcut around the law. If TAGO ever adopted targeted advertising, the link and honest Global Privacy Control support would have to come first — and we are stating here that we do not intend to adopt targeted advertising at all. If you want to tell us not to sell or share your information regardless, email [email protected] and we will record it, even though there is nothing to stop.
8.4 Where our revenue is planned to come from#
- Contextual advertising and sponsorship, as described in §8.2.
- Affiliate and marketing arrangements. If we recommend a product or service and are paid when someone follows the link, that is an affiliate arrangement. Our commitment: an affiliate link passes no personal information about you to the partner — following a link is your action, and what you then give the partner is between you and them under their privacy policy. We do not have affiliate arrangements in place today.
- Arrangements with universities and businesses. A campus or employer may pay us to make carpooling available to their community — for example, funding a corridor, sponsoring an event, or running a commute programme. Our commitments here: we provide such partners aggregate, de-identified reporting only, and no partner-reporting or data-export path exists in our systems today (for example, how many trips ran on a corridor); we will not hand a university or employer an individual's trip history, and we will not tell them whether a named person uses TAGO, without that person's separate, specific consent. Today the only thing we collect for this is the enquiry forms in §4.8.
- Possibly, later, an optional paid subscription for drivers. It does not exist today. If it ships, it would be processed by Stripe like any other payment and would not change what we collect or who receives it. If it ever did, we would say so here first.
Note the structural point: because we take no commission, your data has no route to becoming our revenue. There is no mechanism in our system by which personal information is exchanged for money, and we are not building one.
9. Your California privacy rights#
TAGO is a business subject to the California Consumer Privacy Act as amended by the California Privacy Rights Act. If you live in California, the rights below are yours. We extend the same rights to everyone using TAGO, because operating two standards would be silly for a company operating only in California.
9.1 Notice at collection#
This document is our notice at collection. §4 lists every category we collect and why; §5 says how long we keep each category (today: indefinitely, with the exceptions listed); §7 says who receives it; §8 states that we neither sell nor share it.
Mapped to California's statutory categories, we collect:
| Statutory category | Do we? | What |
|---|---|---|
| Identifiers | Yes | Name, email, phone, account id, device push token |
| Customer records | Yes | Payment identifiers, transaction ledger |
| Protected classification characteristics | Some | Date of birth; gender if you provide it; disability-related accessibility information if you provide it |
| Commercial information | Yes | Rides taken and given, wallet and loyalty history |
| Biometric information | No | We collect none |
| Internet or network activity | Yes | Server request logs, and first-party feature-usage analytics under a pseudonymous account ID (§7.2); no cross-site tracking |
| Geolocation data | Yes, extensively | §3 |
| Sensory information | Yes | Profile and vehicle photos, report attachments |
| Professional or employment information | No | We do not collect employment information |
| Education information | Self-reported only | School, major, graduation year if you provide them. These are not education records from an institution |
| Inferences / profiles | No | We do not build profiles or derive inferences about you |
| Sensitive personal information | Yes | Precise geolocation; account log-in credentials; disability-related information; arguably the contents of your in-app messages. See §9.4 |
9.2 Your rights#
- Right to know. Ask us what categories we collect, where we got them, why, who we disclose them to, and what specific pieces we hold about you.
- Right to a copy (access). Get a portable copy of the personal information you gave us.
- Right to delete. Ask us to delete your personal information. §6 explains exactly what is erased, the short list of what is retained without your name on it, and why.
- Right to correct. Ask us to fix inaccurate information. Most profile fields you can correct yourself in the app.
- Right to limit use of sensitive personal information. §9.4.
- Right to opt out of sale or sharing. There is nothing to opt out of, because we do neither (§8). Ask anyway if you want it on record.
- Right to non-discrimination. We will not deny you service, charge you differently, or give you a worse experience for exercising any of these rights. We run no financial-incentive programme in exchange for your data.
- Right to appeal. If we refuse a request, we will tell you why, and you can reply to that email to have a different person review it.
9.3 How to exercise them#
Email [email protected] with what you want. You can also delete your account yourself in the app at any time (Settings → Delete account).
- We will acknowledge within 10 business days and respond substantively within 45 calendar days, extendable once by another 45 days if we tell you why.
- Verification. For a request about specific pieces of information, we will verify you by requiring you to be signed in to the account, and we may ask you to confirm details we already hold. We will not ask you for new sensitive information in order to verify a privacy request.
- Authorized agents. You may use an authorized agent. We will ask for written permission signed by you and may still ask you to confirm the request directly.
- We operate online only and communicate with users by email, so email is our designated request channel. If you need a different channel because of a disability or any other reason, say so and we will arrange one.
9.4 Sensitive personal information, and the right to limit#
We collect these categories of sensitive personal information:
- Precise geolocation — the core of the product (§3).
- Account log-in credentials — handled by our authentication provider.
- Disability-related information — the accessibility needs you choose to provide.
- Possibly the contents of your messages to other users, where TAGO is not the intended recipient. We treat them as sensitive.
We use sensitive personal information only to provide the service you asked for, to keep people safe, and to comply with law. We do not use it to infer characteristics about you, we do not use it for advertising, and we do not sell or share it. Because our use stays inside the purposes California permits without a limitation right attaching, there is no separate "limit the use of my sensitive personal information" toggle in the app — but you can email [email protected] and ask us to limit it. Here is the floor on what that gets you: we will always stop every non-essential use, including keeping your last known location (§3.1d). The only uses we will decline to stop are location during a live ride and use for safety and legal compliance, and if we decline we will name which uses and why, in writing.
9.5 De-identified and aggregate information#
We may produce aggregate, de-identified statistics — trip counts on a corridor, how many trips ran for an event — and use them for reporting and partner conversations (§8.4).
The same promise we make in §6.2 about the retained payment ledger covers these figures, and it covers every piece of de-identified information we hold: we do not attempt to re-identify it, we maintain it and use it only in de-identified form, we keep the technical and organisational measures that hold it that way, and anyone we share it with is contractually required to do the same. Testing that our own de-identification works is the only exception.
10. Security#
What is actually in place:
- All traffic between the app and our servers is encrypted in transit.
- Application endpoints that return your data are designed to require a signed session token. The surfaces that deliberately answer without a login are: the redacted public trip board search (§3.3); a tracking link you generated yourself (§3.3); public event and marketing pages, which return marketing fields only; a signed one-click email-unsubscribe link; and inbound webhooks from our payment and email providers, which are verified by signature. Each of those returns redacted, marketing-only, or signed-token-scoped content rather than a general view of user data.
- QR codes used to start and end rides are cryptographically signed to prevent forgery and replay.
- Card and bank details live in Stripe's PCI environment and never reach our servers.
- Access control is enforced in the database, not just in the app. Your own record answers to you; every other account reaches you only through a narrow projection carrying the fields in §4.3 and nothing more. A driver's live position resolves only for a rider actually paired with them, and only while that pairing is live. Payment writes by client apps are forbidden outright at the database level. This is the layer that holds even if a client app is tampered with.
- Administrative actions are written to an audit log.
- Report attachments live in a private bucket.
- We hold no card numbers, no bank details, no government identity documents and no driver's licences — the strongest security control available is not collecting the data (§4.2, §4.4).
What is not in place, stated here rather than buried:
- Public buckets for profile and car photos — and because a car photo often shows a licence plate, that is currently the one route by which a plate is still reachable without signing in (§4.3).
- No least-privilege tiers for staff access (§7.4).
- No retention schedule (§5).
- A VIN we collect and never read (§4.2).
We will not claim that our security is perfect, and no online service can guarantee absolute security.
11. Who can use TAGO — age and eligibility#
TAGO is for adults. You must be 18 or older to use it.
Today TAGO is also for students. Signing up requires a student email address. That is an eligibility requirement, and we are careful about the word: a student address tells us something about the address, not about you. We do not verify, vet or confirm that anyone is a student, and you will never see TAGO describe a user as a verified student. Today the requirement is applied in the app at sign-up rather than enforced on our servers, which we are being explicit about rather than letting the word "requirement" imply more than it should.
This is expected to widen. Eligibility is currently limited to student email domains, and it may be extended to corporate and university staff addresses, and later to the general public. Widening who may sign up does not change what we collect or who receives it; if it ever did, §13 says how you would hear about it.
We ask for your date of birth and we do not currently verify it. To be specific, because vagueness here would be a kind of lie: our iOS app checks only that you picked a date, and our server checks only that the text looks like a date. No code anywhere computes your age or rejects a birth date that makes you a minor. A person under 18 can complete sign-up today.
Two consequences we accept:
- We are implementing an enforced 18+ check. Until it ships, the sentence above is the accurate description and we will not replace it with an implied guarantee.
- We do not knowingly collect personal information from anyone under 18. If we learn that an account belongs to a minor, we will close it and delete the information, after reasonable verification. If you are a parent or guardian and believe your child has an account, email [email protected] and we will act on it.
We do not offer a minors tier, and we do not permit unaccompanied minors as riders. TAGO provides no insurance of any kind, and drivers rely on their own personal auto policies, which is precisely why that line is firm.
12. People you name who are not TAGO users#
You can add trusted contacts (name and phone), caregivers (name, relationship, phone, notes, photo) and companions (name, relationship, phone, notes, photo). Caregiver and companion names and phone numbers are shown to the driver of a ride they are on.
Two honest points:
- TAGO never contacts these people. No message, call or email is sent to them by us. If a trusted contact gets a tracking link, it is because your own phone's Messages app sent it.
- They did not agree to be in our database. You gave us another person's name and phone number, and we store it. Please add someone only if they would be fine with it, and tell them. If you are one of those people and you want your details removed, email [email protected] — you do not need a TAGO account to ask, and we will remove them after reasonable verification that the details are yours.
13. Changes to this policy#
We will update this policy when what we do changes. When a change is significant — a new category of collection, a new recipient, a new use, or anything touching advertising — we will change the "Last updated" date, describe what changed at the top of the document, and notify signed-in users in the app or by email before it takes effect. We will not start a materially new use of information already collected without telling you first.
14. Contact#
- Privacy and privacy-rights requests: [email protected]
- Support: [email protected]
- Legal notice / service of process only: Tago Rides, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA
We deliberately do not publish a phone number. A phone number is not required for a privacy policy, and the one we have is not a staffed business line — email reaches a person faster.
15. Relationship to our Terms of Service#
This policy explains what we do with information. Our Terms of Service is the agreement between us, and the two documents are meant to be read together.
- The Terms control the legal relationship. The limitation of liability (Terms §18), the indemnity (§19), the governing law — California — (§22.3), and the dispute-resolution process (§22) apply to any dispute arising out of this policy as well. There is no forced arbitration and no class-action waiver; there is a required 60-day written notice step before either of us starts a proceeding, small claims court is expressly preserved, and there is a one-year limit on most claims. Terms §22 is the full text, and it is short.
- This policy is a description and a set of commitments about our practices. It is not a warranty, and other than the rights California law gives you and the commitments stated in it, it does not create contractual rights beyond the Terms.
- Drivers are not TAGO's employees, agents or contractors. They are private individuals sharing the cost of a trip they were already taking. TAGO does not dispatch, assign, route or supervise anyone. Where this policy describes the system noticing that two phones have drifted apart and ending a ride, that is an automated safety signal, not supervision of a worker — see Terms §13.
- TAGO provides no insurance of any kind (Terms §12).
- If this policy and the Terms genuinely conflict about privacy, this policy governs the privacy question. Tell us at [email protected], because a conflict is a bug in our documents and we will fix it.