Legal

Privacy policy

Effective 30 Sep 2026.

Terms of use

This page explains what personal data Cabaro holds, why, who else sees it, how long it is kept, and how to have it corrected or removed. It covers the Cabaro app, the request pages and links operators send their customers and drivers, and the Cabaro website.

Cabaro is made by Triplli. Three kinds of people are involved. Cab operators use Cabaro to run their business; this page calls each one the operator. The operator's customers ask for trips on the operator's request page. The operator's drivers open a trip sheet on a link.

1In short

  • A customer's or a driver's details belong to the operator. We keep them for the operator and use them for nothing else.
  • We never message customers or drivers, sell data, use it for advertising, or use it to train a model.
  • No file is ever uploaded, no photo of a person or a document is kept, and no Aadhaar number is asked for.
  • Everything is stored with Cloudflare. Google sees the addresses typed into address search, never a customer's name or phone.
  • There is no analytics on the app, the request pages or the website.
  • A customer or driver who wants their details corrected or removed can ask the operator, or us.

2Who is responsible for what

Under India's Digital Personal Data Protection Act, 2023, the operator decides why its customers' and drivers' details are collected and what they are used for, and it is answerable to them for those details. We store and process them on the operator's behalf, on its instructions, and do nothing with them on our own.

For the operator's own details, its account and its sign-in, we decide and we are answerable.

3What we hold about the operator

  • From Settings: the business name, city, phone number and email, the brand colour, the trip types offered, the operator's own words on what is included, what is extra and its terms, and how it takes payment: a UPI ID, a payment link, bank account details, or cash.
  • Its fleet and prices: car categories, price rows, and each car's plate, model, colour, year and the expiry dates of its papers.
  • Its plan and the Google calls used each month.
  • The notifications Cabaro makes for it, in the app and by email.

4Sign-in and devices

The username, and the password stored only as a salted hash, which cannot be turned back into the password. Nobody at Triplli can read it.

For each device signed in we keep when it signed in, when it was last used, its browser, and the IP address it signed in from. The record is deleted at sign-out, or once the device has gone 30 days unused, and after a year at most.

Wrong passwords are counted per account, and per IP address for an hour, to slow down guessing.

5What we hold about drivers

What the operator types: the driver's name, phone number, licence number, the expiry dates of the licence and badge, and the languages spoken. Then, for each trip, what the driver records at the end on their link: the km, the times, toll, parking, permit, other charges, and anything collected from the customer.

6What we hold about customers

What the customer types on the operator's request page, or the operator types for them:

  • Name, mobile number and, if given, email.
  • The trip: the date and time, the return date, the pickup, any stops and the drop, how many are travelling, the luggage, and the customer's own note.
  • For an address found with address search: Google's place reference and the position on the map. With Use my location: the position the phone gives, only when the customer taps it.
  • The estimate, the operator's quote, how the customer chose to pay, the payments the operator marks received, the final bill, and any note the customer leaves with Something's wrong.
  • The operator's notes on the trip, for itself and for the driver. The customer never sees these.

7Who sees what

The operator sees everything about its own business. Nobody else using Cabaro sees any of it.

A customer's link shows that customer's trip, the operator's price and terms, and once assigned, the car's plate and the driver's name and phone. It never shows the operator's notes.

A driver's link shows the trip they are on: the customer's name and phone, the passengers and luggage, the addresses, the operator's notes for the driver, and the fare only if the operator chooses. It never shows the customer's email, their own note or the payments.

These links work without a password: anyone who has one can open it. A customer's link stops working 10 days after the trip, and a driver's 7 days after the trip is closed, or when the operator takes that driver off the trip.

8Keeping the request page safe

To stop automated spam and protect the operator's Google allowance, the request page runs Cloudflare Turnstile, a check that looks at the browser and device without asking anything. It also counts per IP address and per phone number:

  • A visit gets a pass that holds the IP address, shortened for IPv6, for three hours.
  • Requests sent are counted per IP address, and the count is deleted within two hours.
  • Distances measured and visits that use address search are counted per IP address and per phone number for the day, and deleted after two days.

9What it is used for

A customer's and a driver's details are used to request, price, run and bill that trip, and to show the operator its own trips, customers, reminders and money. Nothing else.

The operator's details are used to run its account: signing in, its plan, its notifications, and help when it asks for it.

The operator reads its data. We look at it only when the operator asks us to, to fix a problem or to help set up its account, or when the law requires it.

10What we never do

  • Message a customer or a driver, by WhatsApp, SMS, email or anything else. Every message comes from the operator's own phone.
  • Give a customer or a driver an account, or contact them for any reason.
  • Take or hold a customer's money. Payment goes straight to the operator.
  • Sell the data, or share it with anyone for their own use.
  • Use it for advertising, ours or anyone else's, or to train a model of any kind.

11Other companies involved

Cloudflare runs Cabaro: the app, the request pages, the website and the database. It holds everything on this page on our behalf, under its own privacy policy, and sees the IP address and browser of every visit as part of serving the page. It also runs Turnstile on the request page.

Google Maps provides address search, the map and the distance. Address search sends Google what is typed into an address box, from the third character, and the place picked. The distance sends Google the positions of the pickup, stops and drop. Both go from our server, so Google does not see the customer's IP address, name or phone. The map, opened only when a customer taps Adjust on map, loads from Google in the customer's browser, so Google sees their IP address and browser then. Google's own Privacy Policy applies to what it receives.

Zoho Mail, in its Canada data centre, sends the operator's notification emails. A new request's email carries the customer's name, phone, the date, the route and their note. Emails go only to the operator's own address.

No other company receives the data. The car pictures and the fonts are served by us, not loaded from anyone else.

12Where it is stored

In Cloudflare's database in its Asia-Pacific region, which may be outside India. Notification emails pass through Zoho in Canada.

13Cookies

When the operator signs in, the app sets one cookie that keeps that device signed in. It holds a random key, is sent only to Cabaro, cannot be read by scripts on the page, and is removed at sign-out.

The request page, the customer's link, the driver's link and the website set no cookie of ours.

14Keeping it safe

Passwords are stored only as one-way hashes, and a signed-in device is known by a hash of its key, never the key itself. Every page tells the browser exactly where it may load code from, and the browser refuses anything else.

When something goes wrong, the error record names the page and what failed, and is seen live only. We keep no log of requests.

If we learn that someone has reached data they should not have, we tell the operator as soon as we know, with what happened and what it touched, so it can tell its customers and drivers.

15How long we keep it

As long as the account is open. The operator can delete its cars, drivers, categories and price rows in the app. Customers and trips cannot yet be deleted in the app; the operator asks us and we delete them.

Some records go on their own, as described above: sign-in records, the request page's counts and passes, and the links, which stop working.

What is deleted can stay in Cloudflare's database history for up to 30 days, and is then gone. When an account closes, everything is deleted within 30 days of the request.

16Your rights

A customer or driver who wants to know what an operator holds about them, have it corrected, or have it removed, asks the operator; its phone number is on the request page and on every link. Anyone who writes to us directly gets the same result: we pass the request to the operator and help it carry it out.

An operator can see and correct nearly everything in the app. For a copy of its data as a file, a deletion, or to close the account, it writes to us.

Anyone not satisfied with the answer can complain to the Data Protection Board of India.

17Changes to this page

When what we do with data changes, this page changes with it. The date at the top moves and a line at the foot says what changed.

18Contact

Questions about this page, a correction, a copy of the data, or a deletion: privacy@triplli.com..

Changes

  • 30 Sep 2026: First version.