This Privacy Policy explains what XOOM collects, why, who we share it with, and how you can control it. It applies to everyone who uses the XOOM apps (Passenger and Captain) and the websites at xoomrides.com.
We collect what we need to match you with rides, keep both sides safe, and operate the platform — your phone, name, profile, location during a ride, and ride history. Captains additionally provide KYC documents. We do not sell your data, do not run third-party ad tracking, and only share with law enforcement when legally compelled. You can request a copy or deletion of your data anytime.
XOOM ("we", "us", "the Platform") is a technology platform operated in Karachi, Pakistan. For the purposes of this Policy, we are the data controller of personal information you provide while using XOOM Passenger or XOOM Captain.
If you have any questions about this Policy or how your data is handled, contact us at privacy@xoomrides.com.
When a ride is accepted, the Captain and Passenger see each other's name, profile picture, phone number (so you can call before pickup), and live location. The Captain sees the Passenger's pickup and drop-off; the Passenger sees the Captain's vehicle make, model, colour, and registration number.
We share data with Pakistani authorities only when legally compelled by a court order, FIA notice, or valid request under the Prevention of Electronic Crimes Act 2016 (PECA). We may also voluntarily share data in genuine safety emergencies (e.g. a ride in progress where a Passenger or Captain is in danger).
We do not share your data with marketing companies, social networks, data brokers, or analytics platforms that build user profiles for advertising.
Location is the most sensitive data we handle. Here is exactly what we do:
Your data is stored on encrypted servers operated by XOOM. Servers are physically located in data centres operated by reputable hosting providers; the location may be in Europe or in Pakistan, depending on infrastructure availability. All data is encrypted in transit (HTTPS / TLS 1.2+) and encrypted at rest in our database.
We use the same data, with the same protections, regardless of where you live or where your trip happens.
If you request account deletion, we delete or irreversibly anonymise everything we are not legally required to retain, within 30 days of the request.
You always have the right to:
We respond to verified rights requests at no cost. If a request is excessive or repeated, we may charge a reasonable fee or decline, and we will explain why.
No system is perfectly secure. If we ever detect a breach that materially affects you, we will notify you directly within 72 hours of becoming aware, by SMS or email, with an explanation of what happened and what you should do.
XOOM is intended for users 18 or older. We do not knowingly create accounts for or collect data from children under 18. If you believe a child has registered with us, contact privacy@xoomrides.com and we will close the account and delete the data immediately.
The XOOM apps use a small number of standard mechanisms:
The xoomrides.com website uses only essential cookies needed to operate. We do not use third-party tracking, analytics, or advertising cookies.
We may update this Policy as the service evolves or as the law changes. The date at the top of this page reflects the latest version. Material changes (anything affecting your rights or what data we collect) will be notified in-app and by SMS or email at least 14 days before they take effect. Continued use after the notice period means you accept the update.
This Policy is governed by the laws of the Islamic Republic of Pakistan, including the Electronic Transactions Ordinance 2002, the Prevention of Electronic Crimes Act 2016 (PECA), and applicable consumer-protection legislation. Disputes will be heard in the courts of Karachi.