EnviRyde Data Retention and Deletion Policy

Effective Date: September 1st, 2025

Last Updated: August 30th, 2028

Applies to: All users, partners, employees, and service providers associated with EnviRyde.

1. Policy Purpose

This Data Retention Policy outlines how EnviRyde collects, stores, retains, and deletes data specifically GPS and trip data in a manner that ensures: 

  • User privacy and security   
  • Legal and regulatory compliance 
  • Operational efficiency 
  • Support for sustainability goals and carbon tracking

2. Scope of the Policy

This policy applies to all data categories generated or collected through the EnviRyde platform, including but not limited to:

  • GPS and location data
  • Trip metadata
  • User profile and account data
  • Communication logs
  • Payment and transaction records
  • Carbon emissions data
  • Device and technical telemetry

3. Data Categories & Retention Schedule

Data CategoryRetention PeriodStorage TypeReason
Live GPS DataDuration of active trip onlyIn-memory (e.g., Redis)Real-time navigation and trip tracking
Trip Summary Data7 yearsSQL/NoSQL databaseHistorical records, reporting, emissions tracking
Full GPS Trail Archives90 days (default), extendableObject storage (e.g., Azure Blob)Optional storage for disputes, analytics
User Profile DataLife of account + 30 daysEncrypted DBAccount management and authentication
Messages & Support Logs2 yearsDatabaseQuality assurance and dispute resolution
Payment & Billing Data7 years (per tax laws)Encrypted DBTaxation and auditing purposes
Carbon Emission Data10 yearsDatabase + ArchiveRegulatory reporting and climate credits validation
Corporate Account Logs7 yearsDatabaseCompliance and contract record keeping
Crash & Diagnostic Logs30 daysLogging serviceDebugging and performance improvement

Data Retention Strategy Post Profile/Account Deletion

Data TypeRetention Duration After DeletionJustification
Personal Identifiable Info (PII) (Name, email, phone, etc.)30 days (auto-deletion)GDPR/CCPA requires full erasure after user-initiated deletion
Trip History & Carbon Data2-3 years (anonymized after 30-60 days)Needed for carbon credit verification, audits, platform analytics
Payment & Transaction Logs7 yearsRequired for tax, accounting, and anti-fraud compliance
Dispute or Legal Hold DataUntil dispute is resolved or legally releasedProtected under legal obligation or active investigation
Support Tickets / Messages1 year (anonymized or pseudonymized)Useful for quality assurance or internal records

4. Legal and Regulatory Compliance

EnviRyde adheres to the following standards and laws:

  • GDPR (EU)

    • Lawful basis for processing 
    • Right to access, correction, portability, and erasure  
    • Data minimization and purpose limitation  
    • Default deletion of personal data upon request (within 30 days) 
  • CCPA (California)

    • Right to know what data is collected and why 
    • Right to opt-out of data sale (EnviRyde does not sell personal data) 
    • Right to delete personal data   
  • PIPEDA (Canada)

    • Transparent data handling   
    • Right to withdraw consent 
    • Accountability and safeguards
  • HIPAA (U.S., if applicable in future)

    • If the platform collects health-related trip data (e.g., for accessibility programs), all such data will be stored and protected per HIPAA regulations  

5. Data Deletion and Archiving

  • Trip Data:   Automatically purged from live systems after 7 years unless otherwise required (e.g., legal hold)
  • Full GPS Trails:   Deleted from blob storage after 90 days unless extended by user or flagged for review 
  • User-Initiated Deletion:   Users can request full deletion of their data via the app or by emailing privacy@enviryde.com 
  • Scheduled Cleanup:   A weekly automated task will permanently delete expired or orphaned data  
  • Backup Retention:   Encrypted backups are stored for 30 days for disaster recovery only  

6. Data Security Measures

  • Encryption:   All data is encrypted in transit (TLS 1.2+) and at rest (AES-256) 
  • Access Control:   Role-based access to data with audit trails 
  • Redundancy:  Secure, geographically distributed backup 
  • Monitoring:   Real-time alerts for data breach or unauthorized access 

7. Data Access & Audit 

  • Data access is logged and reviewed quarterly. 
  • Third-party audits (SOC 2 / ISO 27001) are planned as part of EnviRyde’s maturity roadmap.
  • Only authorized employees may access sensitive data under NDA. 

8. User Rights and Requests 

Users can at any time:

  • Request a copy of all data stored about them 
  • Request corrections to inaccuracies 
  • Request complete deletion (Right to Be Forgotten) 
  • Opt-out of certain data collection features via the app settings 

9. Third-Party Data Sharing 

We do not sell user data. Third-party access is limited to:

  • Cloud Infrastructure Providers (e.g., Azure)  
  • Payment Processors (e.g., Stripe) 
  • Analytics Partners (aggregated, anonymized only) 
  • Carbon Credit Registries (non-personal emissions data only) 

Each vendor is under contract with strict Data Processing Agreements (DPA).

10. Policy Review and Updates

This policy is reviewed annually or upon a major regulatory change or platform update. Users will be notified of material changes through in-app alerts and email.

Contact Information

For questions, requests, or concerns related to this policy, please contact:

EnviRyde Privacy Officer  

hq@enviryde.com 

Response Time: Within 7 business days