Privacy Policy
Last updated:
This policy explains what personal data Octransfer processes, why, who we share it with, and what you can do about it. It covers the whole platform: the driver mobile app, the web app used by transfer companies, and this website.
We wrote it to be read. Where a legal term is unavoidable we explain it in plain language next to it.
1. Who we are
Octransfer provides software that transfer and chauffeur companies use to organise rides, assign drivers and track earnings. Our customers are those companies. Their drivers use our mobile app to see and complete the rides assigned to them.
For the purposes of this policy, the data controller is identified at the end of this page and can be reached at the address in the "Contact" section.
2. Our two roles
The same platform puts us in two different legal positions, and your rights depend on which one applies.
- We are the controller for the accounts we create and operate: drivers, company staff, and website visitors. We decide what is collected and why.
- We are a processor (an "operador" under Brazilian law) for the ride and passenger data that our customers put into the platform. The transfer company decides what to collect and how long to keep it; we only act on their instructions.
If you are a passenger and want your data corrected or deleted, contact the transfer company that arranged your ride. If you write to us instead, we will forward your request to them.
3. What we collect from drivers
A driver account is created by the transfer company, not by the driver. The app has no sign-up screen.
- Identification and contact: name, e-mail address, phone number, and the companies you are linked to.
- Authentication: your password, stored only as a hash that cannot be reversed. Access and refresh tokens are kept on your device.
- Ride activity: the rides assigned to you, completions, and no-show reports, including the photos and free-text note you submit as proof.
- Earnings: amounts, discounts and the notes an administrator attaches to them.
- Device data for notifications: a push token issued by the operating system, your platform (iOS or Android) and your app language.
- Location: your position while you are signed in to the app, and the route of the rides you carry out. Section 10 explains exactly how this works and who sees it.
The app runs no analytics or advertising SDKs and does not track you across other apps or websites. It does collect location, but only while you are signed in and only for the purposes in section 10.
4. What we collect from company users
- Account data: name, e-mail, role and the company you belong to.
- Operational records: the rides, drivers, assignments and messages you create or edit in the web app.
- Integration settings you configure, such as e-mail sender details and messaging credentials.
5. Passenger data
Transfer companies enter passenger details so a ride can be carried out: name, phone number, pick-up and drop-off addresses, flight number, luggage count and any observations.
Drivers see the passenger data for the rides assigned to them, and only for those rides. We process this data on behalf of the transfer company under the "processor" role described in section 2.
6. Website visitors
- What you type into the contact form: name, e-mail and message. It reaches us through Formspree, which delivers it to our inbox.
- Standard server and security logs, including IP address, date and time, and the pages requested.
This website does not use advertising or analytics cookies. See the "Cookies" section.
7. Why we process data, and on what legal basis
| Purpose | Data | Legal basis (LGPD / GDPR) |
|---|---|---|
| Give you access to the platform and keep your session secure | Account, authentication and device data | Performance of a contract — LGPD art. 7, V; GDPR art. 6(1)(b) |
| Show drivers their rides and let them report completion or no-show | Ride, passenger and no-show data | Performance of a contract; our customer's instructions as processor |
| Send push notifications when a ride is assigned or removed | Push token, platform, language | Performance of a contract; device permission granted in the operating system |
| Show the transfer company where its drivers are, and record the route of a ride | Driver location: current position and ride tracking points | Performance of a contract — LGPD art. 7, V; GDPR art. 6(1)(b) — and the transfer company's legitimate interest in running its fleet — LGPD art. 7, IX; GDPR art. 6(1)(f) |
| Send the ride's progress and position to the booking platform that sold it, so the passenger can follow it there and the driver does not have to run that platform's app as well | Driver location during the ride, and the stage the driver reported | Performance of a contract — the ride was booked through that platform; our customer's instructions as processor |
| Calculate and display earnings | Ride and financial records | Performance of a contract; LGPD art. 7, II for tax obligations |
| Keep the service secure, investigate abuse and fix defects | Access and error logs | Legitimate interests — LGPD art. 7, IX; GDPR art. 6(1)(f) |
| Answer messages sent through the website | Contact form data | Legitimate interests; steps taken at your request before a contract |
| Comply with legal, tax and record-keeping duties | Account and financial records, access logs | Legal obligation — LGPD art. 7, II; GDPR art. 6(1)(c) |
8. No-show photos
When a passenger does not show up, the driver documents it with photos taken in the app. Those images may show a location, a vehicle, a building entrance, and sometimes people.
We treat them as the sensitive records they are: they are visible only to the transfer company that owns the ride and to the driver who submitted them, they are stored inside our main database rather than in any public bucket, and they are deleted on the schedule in section 13.
The camera and photo library permissions are used only for this. The app never opens your camera or reads your gallery in the background.
9. Biometric unlock
The app can be locked with Face ID, Touch ID or the Android equivalent. This is handled entirely by your device: the operating system tells the app "authenticated" or "not authenticated", and nothing else.
We never receive, see or store your fingerprint or face data. Turning the feature off in the app removes the lock; the biometric data itself was never ours to delete.
10. Location tracking
The driver app shares the driver's location with the transfer company while the driver is signed in. This is what lets a company see where its fleet is, reassign a ride when a flight is delayed, and show that a ride was carried out as agreed.
It also feeds the live tracking of the booking platform that sold the ride. That integration is what spares the driver from running the platform's own app alongside ours: the position and the ride's progress reach the passenger through the channel they booked with, sent from this app.
Tracking starts when the driver signs in and grants the operating system permission, and it stops at sign-out. It keeps running while the app is in the background or the screen is off — a driver at the wheel does not sit staring at the app — and the device says so the whole time: a permanent notification on Android, the location indicator on iOS.
- Outside a ride, a position is recorded about once a minute, so the company can see who is available and where.
- During a ride, about every five seconds — this is what produces the route of that ride.
- Each stage a driver reports ("on my way", "arrived", "ride started", "finished") is stored together with the position where it happened.
- We keep one current position per driver, plus the points belonging to each ride. Section 13 says how long each is kept.
Who sees it: administrators of the transfer company the driver works for and, when the ride comes from a booking platform we are integrated with, that platform — for that ride only. Location is never used for advertising or profiling and is never shared with anyone else. A driver who prefers not to be tracked can sign out; a driver who refuses the permission can still use the app, but cannot record ride stages, because the booking platforms require the position of each one.
12. International transfers
Our infrastructure runs outside Brazil, mostly in the United States. When personal data leaves your country we rely on the safeguards the law provides: standard contractual clauses with our providers under GDPR art. 46, and the equivalent mechanisms in LGPD art. 33.
We choose providers that commit contractually to protect the data at a level comparable to the one described in this policy.
13. How long we keep data
| Data | Retention |
|---|---|
| No-show photos | 30 days from the report, then permanently deleted. The written note and the no-show record stay with the ride |
| Account data (driver and company users) | While the account is active, then 5 years |
| Ride and earnings records | 5 years, to meet tax and accounting obligations |
| Push tokens | Until you log out, uninstall the app, or the token is invalidated |
| Driver's current position | One record per driver, overwritten by every new position — no history is built from it. Deleted with the account |
| Ride tracking points (the route of a ride) | 30 days from the ride, then permanently deleted |
| Access and security logs | 6 to 12 months |
| Contact form messages | 2 years from the last reply |
When a retention period ends, data is deleted or irreversibly anonymised. We may keep it longer only where a law or an ongoing legal claim requires it.
14. How we protect data
- All traffic between apps and our servers travels over HTTPS.
- Passwords are stored as irreversible hashes; nobody at Octransfer can read them.
- Session tokens on mobile devices are held in the platform keychain (Keychain on iOS, Keystore on Android), not in ordinary app storage.
- Access to production data is limited to the people who need it to operate the service.
- Drivers see only the rides assigned to them; company users see only their own company's data.
No system is perfectly secure. If a breach affects your data and creates a relevant risk, we will notify you and the competent authority as the law requires.
15. Your rights
Wherever you are, you can ask us to confirm what we hold about you, to correct it, to delete it, and to explain who we shared it with.
- Brazil (LGPD art. 18): confirmation of processing, access, correction, anonymisation or deletion of unnecessary data, portability, information about sharing, and the right to withdraw consent.
- European Union / United Kingdom (GDPR): access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and the right to lodge a complaint with a supervisory authority.
- United States: where state law applies, the right to know what we collect, to request deletion, to correct it, and not to be discriminated against for exercising these rights. We do not sell personal data, so there is nothing to opt out of.
16. How to exercise them
Write to the address in the "Contact" section describing what you want. We may ask for information that confirms your identity — we will not hand someone else your data on request.
We answer within 15 days for LGPD requests and within 30 days for GDPR requests. If a request is complex we will tell you before the deadline and explain the delay.
Drivers: your account belongs to the transfer company you work with. Requests to close it or delete your work history are forwarded to them, because those records are theirs.
18. Children
The platform is a professional tool and is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a minor gave us data, write to us and we will delete it.
19. Changes to this policy
When we change this policy we update the date at the top of the page. If a change materially affects your rights, we will announce it in the app or by e-mail before it takes effect.
20. Contact
For privacy questions and requests, or to reach the person responsible for data protection:
Octransfer contact@octransfer.com