Privacy Policy

Effective Date: April 14, 2026 Last Updated: August 6, 2026

OnRoady LLC, a California limited liability company ("OnRoady," "we," "us," or "our"), operates the OnRoady mobile application and website at onroady.app (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and your rights regarding your data.

By using the Service, you agree to the practices described in this policy.


1. Information We Collect

1.1 Information You Provide

Data Why We Collect It
Phone number Account creation and login via SMS OTP
Email address Account identification and notifications
First name, last name, display name Profile and in-app identity
Profile photo Optional — displayed on your public profile
Driver's license number and image Identity verification (KYC) required to receive payouts
W-9 tax information (legal name, address, SSN/EIN last 4 digits, tax ID type) IRS compliance for payments over $600/year

1.2 Information Collected Automatically

Data Why We Collect It
GPS / precise location Matching drivers to bounties near their route; map display
Video recordings Dashcam footage uploaded in response to bounties
Device identifiers and app usage data Error tracking and service improvement
IP address and request metadata Security, fraud prevention, rate limiting

1.3 Payment Information

Payment card details are entered directly into Stripe's secure form and never pass through or stored on our servers. We store only:


2. How We Use Your Information

We do not sell your personal information to third parties.


3. Location Data

We request access to your precise GPS location to:

Location is collected only while the app is in use (foreground). We do not track your location in the background without explicit consent. You can revoke location permission at any time in your device settings, though this will limit core app functionality.


4. Camera and Video

We request camera access to record dashcam footage. Videos you upload are:

We apply automated face and licence plate blurring to protect bystanders in uploaded footage.

Biometric Data Notice (BIPA / CUBI / WBITA). The automated blurring process uses computer vision to detect and obscure facial geometry and vehicle-identifier features in video frames. This constitutes processing of biometric identifiers under the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, and the Washington Biometric Identifiers Act. By uploading footage through the Service, you consent to this processing solely for the purpose of privacy protection. We do not retain, sell, or share raw biometric data; the source video is deleted within 30 days of bounty resolution, and facial-geometry / plate-detection vectors are destroyed within 24 hours of pipeline completion. Full details, including the retention and destruction schedule required by 740 ILCS 14/15(a), are set out in our Biometric Information Retention & Destruction Schedule. Illinois, Texas, and Washington residents will see an additional one-tap consent screen before their first upload.


5. How We Store and Protect Your Data

Despite these measures, no system is 100% secure. We encourage you to use a strong, unique password and to contact us immediately if you suspect unauthorised access to your account.


6. Data Retention

Data Type Retention Period
Active account data Until you delete your account
Audit logs 2 years
Stripe webhook events 90 days
Payment / wallet transaction records 7 years (IRS requirement)
Soft-deleted account data Anonymised immediately on deletion; identifiers removed
Videos (expired/rejected bounties) Deleted within 30 days of expiry
User appeals (post-erasure) Deleted immediately on account erasure; the reviewer's decision is retained in the audit log without personal identifiers, per GDPR Art. 17.
Background-check records (post-erasure) Retained as a financial-compliance audit record with your identity fields (user link, Checkr candidate and report identifiers, and invitation URL) set to null immediately on account erasure. We separately request Checkr to scrub its copy of the underlying report within 30 days, per GDPR Art. 17.
Legal / rights requests submitted through the in-app inbox (DMCA, CCPA, GDPR, privacy) after your account is erased The request record is retained as evidence that we responded to your rights request, but the subject, body, contact email, our resolver notes, and the link to your account are erased and replaced with a tombstone marker referring to GDPR Art. 17. Non-legal in-app requests (support / feedback) are deleted outright at erasure.

For the full field-by-field retention schedule, including the Checkr operator-scrub follow-up service level, see our Data Retention Policy.


7. Third-Party Services

We share data with the following third parties only to the extent necessary to operate the Service:

Provider Purpose Privacy Policy
Stripe Payment processing, escrow, driver payouts, identity verification (Stripe Identity) stripe.com/privacy
Supabase Database and authentication supabase.com/privacy
Cloudflare R2 Video and image storage cloudflare.com/privacypolicy
Twilio SMS OTP delivery twilio.com/legal/privacy
Sentry Error tracking and crash reporting sentry.io/privacy
OpenAI Automated reading of driver's-license photos to extract name, date of birth, license number, expiry, and state (identity verification only). Images and extracted text are sent via the OpenAI API and are not used to train OpenAI models under our API terms. openai.com/policies/privacy-policy
Amazon Web Services (Rekognition) Automated face comparison between your selfie and your driver's-license photo, and detection of glasses / sunglasses in the selfie (identity verification only). See §4 and our Biometric Information Retention & Destruction Schedule for details on biometric handling. aws.amazon.com/privacy
Resend Transactional email delivery (verification, payout confirmations, dispute notices) resend.com/legal/privacy-policy
PostHog Product analytics (in-app feature-usage events such as sign-up, video upload, payout request) linked to a pseudonymous account identifier. We do not send license photos, selfies, message content, or payment details to PostHog. Data is hosted in the United States. posthog.com/privacy
Expo Application Services (Expo, Inc.) Mobile-app runtime, over-the-air JavaScript update delivery, and push-notification token registration + delivery. Receives your Expo push token, device model, OS version, and app version. Push-message content is generated by us and relayed through Expo's push service to Apple / Google. expo.dev/privacy
Checkr, Inc. Driver background-check processing (motor-vehicle record and criminal-history screening, invoked after Stripe Identity verification). Receives your first name, last name, email address, and, when the report requires it, date of birth and driver's-license number. We receive back a report status (clear / consider / suspended / canceled) and never receive raw underlying records. Checkr signs webhook callbacks to us with HMAC-SHA256 for integrity. checkr.com/privacy-policy

Each provider processes personal information only under a written data-processing agreement (or equivalent) that restricts use to the purposes we direct. None of them are permitted to use your data for their own marketing or to train unrelated products.

We do not use advertising networks or sell data to data brokers.

7.1 Automated Decision-Making

Some parts of the identity-verification pipeline described in §2 make automated decisions about your account status:

In every case where the automated outcome is rejection, you have the right to:

We keep the source images (license photo and selfie) and the machine-readable outputs of these checks only for the retention periods listed in §6 and in the Biometric Information Retention & Destruction Schedule.

Copyright Infringement (DMCA)

If you believe content on the Service infringes your copyright, see our DMCA Copyright Policy for the full takedown and counter-notice procedure. Notices may be sent to our designated agent at dmca@onroady.app.


8. Children's Privacy

The Service is not directed to children under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal data, please contact us and we will delete it promptly.


9. Your Rights

Depending on where you live, you may have the following rights:

All Users

California Residents (CCPA / CPRA)

Under the California Consumer Privacy Act and California Privacy Rights Act, California residents have the right to:

Do Not Sell or Share My Personal Information

We do not sell or share your personal information for cross-context behavioural advertising, and we have not done so in the preceding 12 months. Under the CPRA's broader definition of "sharing," disclosing personal information to a third party for that party's own targeted-advertising purposes counts as sharing — we do not do this. We do not use advertising networks, ad SDKs, or data brokers.

The third parties listed in Section 7 receive personal information only as service providers under written agreements that prohibit them from using your data for their own marketing or behavioural advertising.

Even though we do not sell or share, you have the right to direct us not to. To exercise this right or any other CCPA/CPRA right:

We will confirm receipt within 10 business days and respond substantively within 45 calendar days (extendable once by 45 days if reasonably necessary). You may designate an authorised agent to act on your behalf; we may require proof of authorisation.

Other US State Privacy Rights

Residents of the following US states have privacy rights under state law that are substantively similar to the CCPA/CPRA rights described above (access, deletion, correction, portability, and opt-out of certain uses), together with additional rights such as opt-out of targeted advertising, opt-out of profiling that produces legal or similarly significant effects, and appeal of denied requests:

To exercise any of these rights, submit a request through Settings → Privacy in the app, or by email to privacy@onroady.app. We do not use your personal data for targeted advertising or for automated profiling that produces legal or similarly significant effects, so opt-outs of those specific activities are inapplicable to our processing; however, we confirm our position in writing on request. If we deny a rights request, you may appeal by replying to our written response within 60 days; we will respond to the appeal within 45 days. Where state law provides a right to submit a complaint to a state attorney general or regulator, contact information for the applicable office is available on that office's website.

EEA / UK Residents (GDPR)

You have the right to data portability, the right to restrict processing, and the right to lodge a complaint with your local supervisory authority. Our lawful basis for processing is: contract performance (providing the Service), legal obligation (tax reporting), and legitimate interest (security and fraud prevention).


10. Push Notifications and Marketing

We may send you push notifications about bounty matches and payment updates. You can disable these in your device settings at any time.

We will only send marketing messages (promotions, new features) if you have explicitly opted in. You can opt out at any time via the app or by emailing us.


11. Changes to This Policy

We may update this policy from time to time. When we do, we will update the "Last Updated" date at the top of this page. For material changes, we will notify you via the app or email at least 14 days before the change takes effect.


12. Contact Us

If you have questions about this policy or want to exercise your rights, contact us at:

Email: privacy@onroady.app Mailing Address: OnRoady LLC, 101 E. San Fernando St Suite 138, San Jose, CA 95112

For account deletion requests, you can also use Settings → Delete Account directly in the app.


OnRoady is committed to handling your data responsibly. We collect only what we need, protect it carefully, and never sell it.