Pliho.
← Back to home

Legal

Privacy Policy

Effective September 26, 2026 · Pliho Technologies, LLC

Pliho is a cost-sharing carpooling marketplace, not a rideshare company or transportation network company. This policy explains how we collect, use, and protect your information in connection with the Pliho mobile app and related services.

1. Who We Are2. Information We Collect3. How We Use Your Information4. Location Data5. Third-Party Processors6. Data Sharing7. Driver Insurance Documents8. Data Retention9. Users Under 1810. Your Rights (California Residents, CCPA)11. Security12. Contact

1. Who We Are

Pliho Technologies, LLC ("Pliho," "we," "our") operates a peer-to-peer cost-sharing carpooling marketplace. Pliho is not a Transportation Network Company (TNC), common carrier, or transportation service provider. We operate a technology platform that connects volunteer drivers with riders who share the real cost of trips the driver was already taking.

2. Information We Collect

Account data: name, email address, phone number, date of birth, and profile photo provided during registration.

Identity verification data: government-issued ID, biometric data (liveness check photo), and vehicle information collected during driver or rider verification via Didit, our identity verification processor.

Trip data: origin, destination, route, distance, timestamps, seat cost-share amounts, and booking history.

Location data: GPS coordinates collected only during active trips when you have granted location permission. We do not track your location outside of active trip sessions.

Payment data: payment method metadata (last four digits, card type, billing ZIP). Full card numbers are never stored by Pliho, all payment processing is handled by Stripe, Inc.

Insurance data: insurance declarations pages and documents uploaded by drivers are stored in encrypted, access-controlled storage.

Communications: in-app chat messages between riders and drivers, which are stored for dispute resolution purposes.

Ask window summaries: when you type a trip into the Adventures ask window, we keep a generalised summary of it: whether you were looking for a trip or hosting one, the kind of trip, the destination, and a rough timeframe such as "this weekend". We do not keep the words you typed for this purpose, and the summary is stored with a one-way code rather than your name or account, which lets us count how many different people asked for the same thing without knowing who they are. Tapping a suggested sentence is not recorded this way.

Device and usage data: device identifiers, IP address, app version, session activity, and crash logs for platform security and fraud detection.

3. How We Use Your Information

We use collected information to: match drivers and riders on compatible routes; process cost-share payments and manage Stripe escrow; verify driver identity, insurance, and vehicle eligibility; send trip-related push notifications and emails; validate GPS-timestamped no-show events for dispute resolution; detect and prevent fraud, duplicate accounts, and platform abuse; suggest trips in the ask window that at least three different people have asked for, written as a general sentence and never shown with anyone's name or words; and comply with applicable federal and state law.

We do not use your personal information for advertising, and we do not sell your data to third parties under any circumstances.

4. Location Data

Location access is requested only when you initiate an active trip session. GPS data is used solely to: (a) display live trip progress to trip participants; (b) validate driver or rider presence at the meetup point for no-show dispute resolution; and (c) confirm trip route for IRS mileage compliance records.

Location data is not collected, stored, or shared when you are not in an active trip session. We do not use location for advertising, analytics profiling, or any purpose unrelated to trip operations.

5. Third-Party Processors

Stripe, Inc., payment authorization, escrow, and payout processing. Your card data is transmitted directly to Stripe under their Privacy Policy (stripe.com/privacy).

Didit, government ID verification and biometric liveness checks during driver and rider onboarding. Biometric data is processed per Didit's data processing terms.

Supabase, secure database and storage infrastructure hosted on industry-standard cloud infrastructure with encryption at rest and in transit.

PayPal, an alternative payment method at checkout where you choose to use it. Your PayPal credentials are never seen by Pliho.

Google Maps Platform, route distance calculation used for IRS mileage ceiling enforcement. No personal data is shared beyond anonymized route coordinates.

Amazon Web Services (Amazon SES), delivery of transactional email such as sign-in codes, booking confirmations, and receipts. Your email address and the contents of that message are processed to send it.

Resend, delivery of certain account emails, including email address change confirmations.

Expo, delivery of push notifications. Your device push token is held by Expo's notification service in order to reach your device.

DeepSeek, AI text processing for Pliho's writing and search helpers: the words you type into the Adventures ask window, messages you send to in-app AI help, the trip details you enter when you ask Pliho to write an Adventure post, and the domain of a school or work email address (the part after the @) so the app can name the institution. Your name, email address, phone number and account are not sent with them.

6. Data Sharing

We share only the minimum information necessary to facilitate a confirmed trip: rider first name and rating with the driver, and driver first name, vehicle make/model/color, and rating with the rider. Full contact information is never shared, communication is handled through the in-app messaging system.

We may disclose your information: to comply with a valid legal process (court order, subpoena, or government demand); to protect the safety of any person; to investigate suspected fraud or platform violations; or as part of a merger, acquisition, or asset sale, subject to standard confidentiality protections.

7. Driver Insurance Documents

Insurance documents uploaded by drivers are stored in an encrypted, access-controlled private storage bucket accessible only to authorized Pliho operations staff for verification purposes. These documents are retained for the duration of the driver's active account plus three years for compliance recordkeeping. Drivers may request deletion of insurance documents upon account closure, subject to applicable legal retention requirements.

8. Data Retention

Trip records and cost-share transaction logs, including Adventure payments and payouts with the organiser fee recorded separately, are retained for seven (7) years to comply with IRS recordkeeping requirements applicable to mileage reimbursement and cost-recovery arrangements. Account data is retained while your account is active and for 30 days following account deletion to complete any pending transactions or disputes. Ask window summaries are deleted automatically 30 days after the ask. You may request deletion of your account and personal data by contacting . Financial records required for tax compliance will be retained for the legally required period regardless of account deletion.

9. Users Under 18

Pliho accounts are for adults. You must be at least 18 years of age to create an account, and sign-up does not accept a date of birth less than 18 years ago. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has created an account, contact and we will delete the account and the information held with it.

10. Your Rights (California Residents, CCPA)

Under the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.), California residents have the right to: know what personal information we collect and how it is used; request deletion of personal information (subject to legal exceptions); opt out of the sale of personal information (Pliho does not sell personal information); and non-discrimination for exercising these rights.

To exercise your rights, submit a verifiable consumer request to . We will respond within 45 days as required by law.

11. Security

We implement industry-standard technical and organizational safeguards including TLS encryption for data in transit, AES-256 encryption for sensitive data at rest, access controls and audit logs for internal systems, and regular security reviews. No system is perfectly secure. In the event of a data breach affecting your rights, we will notify you as required by applicable law.

12. Contact

Privacy questions, data requests, or concerns:

Email:

For California CCPA requests, include "CCPA Request" in your subject line.

More legal documents

Terms and Conditions →Referral Agreement →Important Disclosures →
© 2026 PLIHO TECHNOLOGIES · ALL RIGHTS RESERVED