EnviRyde Data Retention and Deletion Policy
Effective Date: September 1st, 2025
Last Updated: August 30th, 2028
Applies to: All users, partners, employees, and service providers associated with EnviRyde.
1. Policy Purpose
This Data Retention Policy outlines how EnviRyde collects, stores, retains, and deletes data specifically GPS and trip data in a manner that ensures:
- User privacy and security
- Legal and regulatory compliance
- Operational efficiency
- Support for sustainability goals and carbon tracking
2. Scope of the Policy
This policy applies to all data categories generated or collected through the EnviRyde platform, including but not limited to:
- GPS and location data
- Trip metadata
- User profile and account data
- Communication logs
- Payment and transaction records
- Carbon emissions data
- Device and technical telemetry
3. Data Categories & Retention Schedule
| Data Category | Retention Period | Storage Type | Reason |
|---|---|---|---|
| Live GPS Data | Duration of active trip only | In-memory (e.g., Redis) | Real-time navigation and trip tracking |
| Trip Summary Data | 7 years | SQL/NoSQL database | Historical records, reporting, emissions tracking |
| Full GPS Trail Archives | 90 days (default), extendable | Object storage (e.g., Azure Blob) | Optional storage for disputes, analytics |
| User Profile Data | Life of account + 30 days | Encrypted DB | Account management and authentication |
| Messages & Support Logs | 2 years | Database | Quality assurance and dispute resolution |
| Payment & Billing Data | 7 years (per tax laws) | Encrypted DB | Taxation and auditing purposes |
| Carbon Emission Data | 10 years | Database + Archive | Regulatory reporting and climate credits validation |
| Corporate Account Logs | 7 years | Database | Compliance and contract record keeping |
| Crash & Diagnostic Logs | 30 days | Logging service | Debugging and performance improvement |
Data Retention Strategy Post Profile/Account Deletion
| Data Type | Retention Duration After Deletion | Justification |
|---|---|---|
| Personal Identifiable Info (PII) (Name, email, phone, etc.) | 30 days (auto-deletion) | GDPR/CCPA requires full erasure after user-initiated deletion |
| Trip History & Carbon Data | 2-3 years (anonymized after 30-60 days) | Needed for carbon credit verification, audits, platform analytics |
| Payment & Transaction Logs | 7 years | Required for tax, accounting, and anti-fraud compliance |
| Dispute or Legal Hold Data | Until dispute is resolved or legally released | Protected under legal obligation or active investigation |
| Support Tickets / Messages | 1 year (anonymized or pseudonymized) | Useful for quality assurance or internal records |
4. Legal and Regulatory Compliance
EnviRyde adheres to the following standards and laws:
GDPR (EU)
- Lawful basis for processing
- Right to access, correction, portability, and erasure
- Data minimization and purpose limitation
- Default deletion of personal data upon request (within 30 days)
CCPA (California)
- Right to know what data is collected and why
- Right to opt-out of data sale (EnviRyde does not sell personal data)
- Right to delete personal data
PIPEDA (Canada)
- Transparent data handling
- Right to withdraw consent
- Accountability and safeguards
HIPAA (U.S., if applicable in future)
- If the platform collects health-related trip data (e.g., for accessibility programs), all such data will be stored and protected per HIPAA regulations
5. Data Deletion and Archiving
- Trip Data: Automatically purged from live systems after 7 years unless otherwise required (e.g., legal hold)
- Full GPS Trails: Deleted from blob storage after 90 days unless extended by user or flagged for review
- User-Initiated Deletion: Users can request full deletion of their data via the app or by emailing privacy@enviryde.com
- Scheduled Cleanup: A weekly automated task will permanently delete expired or orphaned data
- Backup Retention: Encrypted backups are stored for 30 days for disaster recovery only
6. Data Security Measures
- Encryption: All data is encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Access Control: Role-based access to data with audit trails
- Redundancy: Secure, geographically distributed backup
- Monitoring: Real-time alerts for data breach or unauthorized access
7. Data Access & Audit
- Data access is logged and reviewed quarterly.
- Third-party audits (SOC 2 / ISO 27001) are planned as part of EnviRyde’s maturity roadmap.
- Only authorized employees may access sensitive data under NDA.
8. User Rights and Requests
Users can at any time:
- Request a copy of all data stored about them
- Request corrections to inaccuracies
- Request complete deletion (Right to Be Forgotten)
- Opt-out of certain data collection features via the app settings
9. Third-Party Data Sharing
We do not sell user data. Third-party access is limited to:
- Cloud Infrastructure Providers (e.g., Azure)
- Payment Processors (e.g., Stripe)
- Analytics Partners (aggregated, anonymized only)
- Carbon Credit Registries (non-personal emissions data only)
Each vendor is under contract with strict Data Processing Agreements (DPA).
10. Policy Review and Updates
This policy is reviewed annually or upon a major regulatory change or platform update. Users will be notified of material changes through in-app alerts and email.
Contact Information
For questions, requests, or concerns related to this policy, please contact:
EnviRyde Privacy Officer
hq@enviryde.com
Response Time: Within 7 business days