Legal

Privacy Policy

Last updated: June 2025 · Caraaye (Hamsafar Technologies Pvt. Ltd.)

1. Who We Are

Caraaye is operated by Hamsafar Technologies Pvt. Ltd., a company incorporated in Pakistan. Our registered address is Karachi, Sindh, Pakistan. For privacy-related queries, contact: info@caraaye.com.

2. Data We Collect

We collect the following categories of personal data:

  • Identity data: Full name, CNIC verification hash (not the raw CNIC number), institutional email address.
  • Location data: Approximate home area (used for circle matching), GPS route completion data (stored for 90 days, then anonymised).
  • Usage data: Circle membership, attendance records, Trust Score components, payment records via CaraayePay.
  • Communications data: In-app messages between circle members (retained for 30 days).
  • Device data: IP address, device type, operating system, app version.

3. How We Use Your Data

We use personal data for the following purposes:

  • Forming and managing commute circles that match employees along shared routes.
  • Verifying identity and calculating Trust Scores for commuter safety.
  • Processing payments and splitting commute costs via CaraayePay.
  • Generating verified allowance reconciliation data for your employer's HR team.
  • Producing anonymised ESG and mobility reports for your organisation.
  • Sending service communications (onboarding, route changes, safety alerts).

4. Data Sharing

We do not sell personal data. We share data only as follows:

  • With your employer (HR admin): Verified route completion records, allowance reconciliation data, and aggregate mobility reports. Individual GPS coordinates are never shared with employers.
  • Within your circle: First name, initials, departure window, and Trust Score tier are visible to your circle members. Home address is never shared.
  • With payment processors: JazzCash and EasyPaisa process payment transactions under their own privacy policies.
  • With infrastructure providers: Google Maps Platform (routing and geolocation), cloud hosting providers operating within Pakistan.

5. Data Retention

GPS route data is retained for 90 days then anonymised. Payment records are retained for 7 years in compliance with Pakistani tax law. CNIC verification hashes are retained for the duration of your active account and deleted within 30 days of account closure. Communications data is retained for 30 days.

6. Your Rights

Under the Pakistan Personal Data Protection Act (PDPA), you have the right to: access your personal data, correct inaccuracies, request deletion (subject to legal retention requirements), and object to certain processing. To exercise any right, contact info@caraaye.com.

7. Security

All data is encrypted in transit (TLS 1.2+) and at rest. Access to personal data is restricted to authorised personnel on a need-to-know basis. CNIC data is stored as a one-way verification hash only — the raw CNIC number is never stored on Caraaye servers.

8. Changes to This Policy

We will notify active users of material changes to this policy via in-app notification and email at least 14 days before they take effect. Continued use of the platform after the effective date constitutes acceptance.

9. Contact

For any privacy-related queries: info@caraaye.com