Passenga
Legal

Privacy Policy

Structured placeholder policy that mirrors what Passenga actually collects and does today, ready for counsel to convert into final wording.

Placeholder page

The final wording is being drafted by the Passenga team. Each section below is a TODO and should not be relied on as legal advice.

1. Who we are

Passenga is the data controller for the personal data described here. The registered operating entity, address and Data Protection Officer contact will be published once confirmed by counsel. Until then, privacy queries can be raised through in-app support.

2. Data we collect

Account data: name, email, phone (if provided), avatar and country. KYC data (hosts, providers, withdrawals): government ID images, selfie, business registration documents and bank account details. Pool activity: pools you create, back or comment on, votes, itinerary contributions and reviews. Payment metadata: payment gateway ids, last-4 digits, currency and amount — Passenga does not store full card numbers. Device/log data: IP address, user agent and coarse location for security. Cookies and local storage as described in section 8.

3. How we use your data

To operate the platform: create accounts, run KYC, route payments to gateways, hold funds in escrow, execute payouts, deliver notifications, run reviews and reputation, and provide support. To keep the platform safe: fraud detection, rate limiting, staff moderation and dispute resolution. To improve the product: aggregated analytics on how features are used. To comply with legal obligations: tax records, AML checks, responding to lawful requests.

5. Payment data and USD processing

Card details are collected and stored by the routed payment gateway (currently Stripe for USD/global; local providers where enabled). Passenga receives only tokens, last-4 digits and gateway ids. USD payments made from LKR cards are converted by the payment gateway at its own reference rate; Passenga does not set that rate and does not store your card. On-site LKR equivalents next to USD amounts are indicative only and use a reference rate for display.

6. Storage, encryption and location

Data is stored on managed cloud infrastructure with encryption in transit and at rest. KYC documents are held in private buckets with row-level access. Bank account numbers are encrypted at the application layer with a rotating symmetric key. Data may be processed in regions outside your country of residence subject to appropriate safeguards.

7. Who we share data with

Payment gateways (to process contributions, refunds and payouts). Verified Providers (only what is needed to fulfil a confirmed booking: your name, contact details agreed in-app and the service address). Email delivery provider (Resend). Fraud, analytics and error monitoring vendors listed in the cookie notice. Law enforcement and regulators when we are legally required to respond. We do not sell your personal data.

8. Cookies and analytics

Essential cookies keep you signed in, remember your country scope, and protect against abuse — these are always on. With your consent (via the cookie banner) we also use product analytics (PostHog) and error monitoring (Sentry) to improve the product. You can change your choice at any time from the “Cookie preferences” link in the footer. Non-essential cookies are off by default until you accept them.

9. Your rights (including PDPA)

Under Sri Lanka's Personal Data Protection Act, GDPR (where it applies) and comparable laws you have the right to: access the data we hold about you; correct inaccuracies; request deletion (subject to legal retention below); object to or restrict certain processing; port your data; withdraw consent for non-essential processing; and lodge a complaint with the Data Protection Authority of Sri Lanka or the equivalent regulator in your jurisdiction. To exercise any of these rights use in-app support; we will respond within statutory timelines.

10. Retention and deletion

Account and pool records are retained while your account is active. KYC and payment records are retained for the period required by AML and tax law (typically 6–7 years) even if you close your account. Notification and log data is retained for up to 12 months. When you request deletion we anonymise remaining records that must be kept for legal reasons and remove everything else within 30 days.

11. Automated decision-making

Rate limits, fraud heuristics and the reports auto-hide threshold are automated. These are safety controls and do not produce legal effects on you; final KYC, refund and moderation decisions are made by human staff.

12. Children

Passenga is not intended for users under 18. If you believe a child has provided personal data please contact support so we can remove the account.

13. Changes to this policy

Material changes will be notified in-app or by email at least 14 days before they take effect. The date at the top of this page shows the current version.