Pliho.← Back to home

Legal

Privacy Policy

Effective June 19, 2026

Pliho is a cost-sharing carpooling marketplace, not a rideshare company or transportation network company. This policy explains how we collect, use, and protect your information in connection with the Pliho mobile app and related services.

1. Who We Are2. Information We Collect3. How We Use Your Information4. Location Data5. Third-Party Processors6. Data Sharing7. Driver Insurance Documents8. Data Retention9. Minor Users (Under 18)10. Your Rights (California Residents, CCPA)11. Security12. Contact

1. Who We Are

Pliho Technologies, LLC ("Pliho," "we," "our") operates a peer-to-peer cost-sharing carpooling marketplace. Pliho is not a Transportation Network Company (TNC), common carrier, or transportation service provider. We operate a technology platform that connects volunteer drivers with riders who share the real cost of trips the driver was already taking.

2. Information We Collect

Account data: name, email address, phone number, date of birth, and profile photo provided during registration.

Identity verification data: government-issued ID, biometric data (liveness check photo), and vehicle information collected during driver or rider verification via Didit, our identity verification processor.

Trip data: origin, destination, route, distance, timestamps, seat cost-share amounts, and booking history.

Location data: GPS coordinates collected only during active trips when you have granted location permission. We do not track your location outside of active trip sessions.

Payment data: payment method metadata (last four digits, card type, billing ZIP). Full card numbers are never stored by Pliho, all payment processing is handled by Stripe, Inc.

Insurance data: insurance declarations pages and documents uploaded by drivers are stored in encrypted, access-controlled storage.

Communications: in-app chat messages between riders and drivers, which are stored for dispute resolution purposes.

Device and usage data: device identifiers, IP address, app version, session activity, and crash logs for platform security and fraud detection.

3. How We Use Your Information

We use collected information to: match drivers and riders on compatible routes; process cost-share payments and manage Stripe escrow; verify driver identity, insurance, and vehicle eligibility; send trip-related push notifications and emails; validate GPS-timestamped no-show events for dispute resolution; detect and prevent fraud, duplicate accounts, and platform abuse; and comply with applicable federal and state law.

We do not use your personal information for advertising, and we do not sell your data to third parties under any circumstances.

4. Location Data

Location access is requested only when you initiate an active trip session. GPS data is used solely to: (a) display live trip progress to trip participants; (b) validate driver or rider presence at the meetup point for no-show dispute resolution; and (c) confirm trip route for IRS mileage compliance records.

Location data is not collected, stored, or shared when you are not in an active trip session. We do not use location for advertising, analytics profiling, or any purpose unrelated to trip operations.

5. Third-Party Processors

Stripe, Inc., payment authorization, escrow, and payout processing. Your card data is transmitted directly to Stripe under their Privacy Policy (stripe.com/privacy).

Didit, government ID verification and biometric liveness checks during driver and rider onboarding. Biometric data is processed per Didit's data processing terms.

Supabase, secure database and storage infrastructure hosted on industry-standard cloud infrastructure with encryption at rest and in transit.

Google Maps Platform, route distance calculation used for IRS mileage ceiling enforcement. No personal data is shared beyond anonymized route coordinates.

6. Data Sharing

We share only the minimum information necessary to facilitate a confirmed trip: rider first name and rating with the driver, and driver first name, vehicle make/model/color, and rating with the rider. Full contact information is never shared, communication is handled through the in-app messaging system.

We may disclose your information: to comply with a valid legal process (court order, subpoena, or government demand); to protect the safety of any person; to investigate suspected fraud or platform violations; or as part of a merger, acquisition, or asset sale, subject to standard confidentiality protections.

7. Driver Insurance Documents

Insurance documents uploaded by drivers are stored in an encrypted, access-controlled private storage bucket accessible only to authorized Pliho operations staff for verification purposes. These documents are retained for the duration of the driver's active account plus three years for compliance recordkeeping. Drivers may request deletion of insurance documents upon account closure, subject to applicable legal retention requirements.

8. Data Retention

Trip records and cost-share transaction logs are retained for seven (7) years to comply with IRS recordkeeping requirements applicable to mileage reimbursement and cost-recovery arrangements. Account data is retained while your account is active and for 30 days following account deletion to complete any pending transactions or disputes. You may request deletion of your account and personal data by contacting privacy@pliho.com. Financial records required for tax compliance will be retained for the legally required period regardless of account deletion.

9. Minor Users (Under 18)

Users under 18 years of age must complete parental account linking during onboarding. A parent or legal guardian must verify their identity and provide OTP authorization before the minor's account is activated. We do not knowingly collect personal information from children under 13 without verifiable parental consent. If you believe a child under 13 has created an account without parental consent, contact privacy@pliho.com immediately and we will delete the account.

10. Your Rights (California Residents, CCPA)

Under the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.), California residents have the right to: know what personal information we collect and how it is used; request deletion of personal information (subject to legal exceptions); opt out of the sale of personal information (Pliho does not sell personal information); and non-discrimination for exercising these rights.

To exercise your rights, submit a verifiable consumer request to privacy@pliho.com. We will respond within 45 days as required by law.

11. Security

We implement industry-standard technical and organizational safeguards including TLS encryption for data in transit, AES-256 encryption for sensitive data at rest, access controls and audit logs for internal systems, and regular security reviews. No system is perfectly secure. In the event of a data breach affecting your rights, we will notify you as required by applicable law.

12. Contact

Privacy questions, data requests, or concerns:

Email: privacy@pliho.com

For California CCPA requests, include "CCPA Request" in your subject line.

More legal documents

Terms and Conditions →Referral Agreement →Important Disclosures →
© 2026 PLIHO TECHNOLOGIES · ALL RIGHTS RESERVED