Privacy Policy
Last updated: August 29, 2026
SabKi Sawari ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, retain, and protect information when you use our mobile application, admin tools, and website (the "Platform").
1. Information We Collect
We collect the following categories of information, depending on whether you use SabKi Sawari as a passenger, driver, or administrator:
- Account and profile information: Name, phone number, email address where provided, role, profile photo, gender where needed for seating and safety rules, emergency contact details, profile settings, and account status.
- Identity and verification information: Passenger CNIC information where required, and driver CNIC, driving licence, vehicle, and verification documents submitted for review.
- Location data: Approximate or precise GPS coordinates used for route search, pickup/drop-off coordination, safety/SOS, driver online availability, and live trip tracking.
- Trip, booking, and seating data: Routes, stops, trip times, booking history, cancellations, seat selections, seating-rule metadata, passenger counts, and trip status.
- Wallet, payment, and payout data: Wallet balances, deposits, holds, refunds, withdrawal requests, transaction records, mobile wallet details, and bank/payout information where provided.
- Device and notification data: Device identifiers generated by the app, FCM push tokens, app version, platform, and notification state.
- Usage, diagnostics, and support data: App events, screens and features used, crash/error diagnostics, support tickets, disputes, SOS reports, reviews, ratings, and communications with support.
2. How We Use Your Information
We use the information we collect to:
- Create, secure, and manage passenger, driver, and admin accounts
- Verify identity, driver eligibility, vehicle information, and account safety
- Match passengers with drivers, manage bookings, assign or validate seats, and coordinate stops
- Enable driver online availability, route matching, pickup coordination, SOS, and live trip tracking
- Operate wallet holds, refunds, withdrawals, commission records, and financial reconciliation
- Send OTP, booking, trip, support, wallet, safety, and service notifications
- Investigate complaints, disputes, cancellations, fraud, safety incidents, and policy violations
- Maintain, debug, secure, and improve the Platform
- Comply with legal, regulatory, accounting, tax, fraud-prevention, and safety obligations
3. Sharing of Information
We do not sell your personal data. We share information only where needed to operate, secure, or legally protect the Platform:
- Drivers and passengers: We share only information needed for the trip, such as names, pickup/drop-off context, booking status, limited contact or coordination details where required, and live location for relevant active trips.
- Administrators and support staff: Authorized team members may access account, verification, trip, support, wallet, and safety records to operate and protect the Platform.
- Supabase: We use Supabase/Postgres for primary application data and Supabase Storage for images and documents.
- Firebase (Google): We use Firebase Authentication for phone OTP sign-in and Firebase Cloud Messaging for push notifications. We do not use Firebase Firestore as the primary trip, booking, or user database.
- Mapbox: We use Mapbox for maps, route/location display, and geolocation-related app features.
- Sentry and hosting services: When configured, error and performance diagnostics help us monitor reliability. The public marketing website does not currently load optional analytics scripts.
- Email and payment providers: We use email providers for operational notices. Payment gateway code exists for supported wallet/payment workflows, but external gateway processing is used only when valid provider credentials and the feature are enabled.
- Legal and safety purposes: We may disclose information to law enforcement, regulators, courts, emergency responders, or other authorities when required by law or necessary for safety.
4. Data Storage and Security
Primary application data is stored in Supabase/Postgres. Images and documents are stored in access-controlled Supabase Storage. Firebase is used for authentication and push notifications. We use HTTPS/TLS for network communication, role-based access controls, private storage controls, encrypted or hashed handling for sensitive identity and payout fields where implemented, and administrative audit controls.
No method of electronic storage is 100% secure. While we work to protect personal information, we cannot guarantee absolute security. If a data breach affects your rights, we will notify you as required by applicable law.
5. Location Data and Background Location
Location access is used for core Platform functionality:
- Driver location may be collected while the driver is Online, including when the app is in the background, so the Platform can support driver availability, route matching, safety, and live trip operations.
- During an active trip, driver location may be shared with relevant booked passengers for live tracking.
- Passenger location may be used for pickup/drop-off coordination, active-trip tracking, SOS, and route features.
- Location sharing should stop when the driver goes Offline, logs out, is no longer authorized, or when the related trip purpose ends, subject to temporary operational logs needed for safety, support, fraud prevention, or dispute review.
You can withdraw location permission through device settings at any time, though this will limit features that depend on location.
6. Third-Party Services
We use the following services, each governed by their own privacy terms:
- Supabase/Postgres: Primary application database
- Supabase Storage: Profile, vehicle, CNIC, licence, and other uploaded files, with private access controls where required
- Firebase Authentication: Phone number OTP login
- Firebase Cloud Messaging (FCM): Push notifications
- Firebase: Phone authentication and push notification delivery
- Mapbox: Maps, geocoding, routing, and location display
- Sentry: Error monitoring and diagnostics
- Vercel: Website hosting and delivery
- Resend or email providers: Operational and support email notifications
- Payment/wallet providers: Payment gateway or payout processing only when the relevant provider credentials and feature are enabled
7. Data Retention
We retain personal data while your account is active and as needed for Platform operation. When an account deletion request is approved, direct profile identifiers such as name, email, phone number, profile photo, and emergency contact are removed or anonymized where technically and legally possible. Trip, booking, wallet, financial, support, dispute, safety, verification, audit, and transaction records may be retained for limited legal, accounting, tax, fraud-prevention, regulatory, dispute-resolution, and platform-safety purposes. See our Account Deletion page for more detail.
8. Your Rights
Subject to applicable law, you may request access to your personal data, correction of inaccurate data, deletion or anonymization subject to retention obligations, withdrawal of optional permissions, and support for privacy questions.
To exercise these rights, contact us at support@sabkisawari.com.
9. Children's Privacy
The Platform is not directed at children under 18 creating independent accounts. Trip bookings may include child passenger counts or seating context where needed for family travel, safety, or seating rules. We do not intentionally collect unnecessary child identity data.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date and, where appropriate, provide in-app notice.
11. Contact
For privacy-related questions or requests, contact support@sabkisawari.com. We process verified requests as promptly as practical and within any period required by applicable law.