Privacy Policy

Effective date: September 1, 2026

1. Who We Are

BOSSX GLOBAL LIMITED, a company incorporated in Hong Kong ("BossX", "we", "us", "our"), is the data controller responsible for your personal data when you use the BossX and BossDriver applications (the "Service").

For privacy inquiries, contact us at privacy@bossx.app.

2. Information We Collect

2.1 Information You Provide

2.2 Information Collected Automatically

2.3 Information We Do Not Collect

3. How We Use Your Information

Purpose Legal Basis
Provide the Service (connect Bosses and Drivers, enable messaging, display locations) Performance of contract
Send ride status notifications and push alerts Performance of contract
Monitor and improve service stability (crash reporting, error tracking) Legitimate interest
Respond to support requests Performance of contract
Enforce our Terms and prevent abuse Legitimate interest
Comply with legal obligations Legal obligation
Send product updates and optional marketing (with opt-out) Consent

4. How We Share Your Information

We do not sell your personal information. We share data only in these circumstances:

4.1 Between Users

When you are connected via the Service, Bosses and Drivers can see each other's name, profile photo, and real-time location during active rides. Chat messages are visible only to the parties in the conversation.

A trip's live location feed is scoped to that trip's participants. Our real-time database rules permit reads of a trip's location and status only to the Boss and the Driver recorded on that trip, and to a holder of that trip's share link (see below). It is not readable by other users of the Service.

4.2 Trip Share Links

A Driver or a Boss can generate a share link for a trip (a track.bossx.app address). Anyone who holds that link can open a web page showing the trip's pickup point, the Driver's name and photo, and the Driver's live position, without signing in or installing the app. The link is a bearer credential: treat it like a password and share it only with people you want to have that view. Links expire — see the retention table in Section 6.

4.3 Service Providers

We use third-party providers to operate the Service. These providers process data on our behalf under contractual obligations to protect your information. The table below names each provider and the categories of data it receives:

Provider What it receives
Google Cloud Platform (Cloud Run, Cloud SQL, Cloud Storage) — Singapore, asia-southeast1 Account and profile records, trip records (pickup, drop-off, timestamps, status), the content of your chat messages — message text, sender and recipient identifiers and timestamps — the image and voice-message files you send in chat, and server logs.
Firebase Authentication (Google) Your phone number and email address, and the sign-in credentials and session tokens used to authenticate you.
Firebase Realtime Database (Google) — Singapore, asia-southeast1 Live GPS coordinates and trip status while a trip is in progress, plus the participant list used to enforce access to them.
Firebase Analytics (Google) App usage telemetry (screen views, feature interactions, device and app version), tagged with your BossX account identifier and your role. See Section 11.
Firebase Crashlytics (Google) Crash stack traces, device state, and diagnostic log breadcrumbs, tagged with your BossX account identifier and, where a trip is in progress, that trip's identifier. Breadcrumbs contain shortened record identifiers, not message content. See Section 11.
Google Maps Platform (Google) Location queries: the coordinates and the text of the address searches you run, and the coordinates we render on a map or use to look up a route or a place name.
Stream (Stream.io, chat infrastructure) Your user identifier, display name and profile image, and chat channel and membership metadata — who is in a conversation, group names, and whether a conversation is blocked. Stream also still holds the content of messages sent through older versions of our apps, before chat moved to our own infrastructure. Messages sent through current versions are stored by us on Google Cloud Platform, not by Stream. See Section 9.
Apple Push Notification service (Apple) and Firebase Cloud Messaging (Google) Your device's push token and the content of each notification we send you, which can include a sender's name and a preview of a message.
RevenueCat (subscription management) Subscription purchase, renewal, and cancellation records, the app store's transaction identifiers, and an app user identifier. We never receive your card or bank details.
Apple App Store / Google Play Your subscription purchase, processed entirely by Apple or Google under their own privacy policies. We receive the resulting subscription status, never your payment details.
Resend (transactional email) Your email address and the content of the emails we send you (for example account and trip notices).

4.4 Legal Requirements

We may disclose your information if required by law, legal process, or government request, or if we believe disclosure is necessary to protect the rights, safety, or property of BossX, our users, or the public.

5. International Data Transfers

Your data is primarily processed and stored on servers in Singapore (Google Cloud Platform, asia-southeast1). If you are located outside Singapore, your data will be transferred internationally.

We ensure appropriate safeguards for international transfers through:

6. Data Retention

Data Type Retention Period
Account information Until you delete your account, then removed within 30 days
Trip data 2 years from the trip date, or until account deletion
Chat messages Until you delete your account, then removed within 30 days
Live location during a trip Streamed to the trip's participants in real time. We do not keep a location trail: the only coordinate that persists is the most recent one. A trip's real-time data node (its last coordinate, status, and participant list) is purged by a daily job once the trip has been finished for at least 8 days. A Driver's latest coordinate is also held as a single last-known position that each new update overwrites, and that is deleted with the account.
Trip pickup / drop-off locations Follows trip data retention above
Trip share links A link expires 24 hours after it is created (for a scheduled trip, 24 hours after the scheduled pickup time). When a trip completes, its link is extended so it stays viewable for 7 days after completion, then stops working. A cancelled or declined trip's link is not extended and expires on its original schedule.
Crash reports and analytics 12 months
Device and push tokens Until you delete your account or revoke permissions

We may retain data longer if required by law or to resolve disputes.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, contact us at privacy@bossx.app. We will respond within 30 days.

8. California Residents (CCPA)

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA):

To make a request, email privacy@bossx.app with the subject line "CCPA Request".

9. Data Security

9.1 What Encryption of Your Chat Does and Does Not Cover

We want to be precise here, because it affects what you should feel comfortable sending. Your chat messages are encrypted in transit — between your device and our servers, and between our servers and the recipient's device. They are not end-to-end encrypted: they are not encrypted in a way that hides their contents from us.

In practice this means: the text of a message leaves your device readable and can be read by authorised BossX staff — for example when we investigate a safety report, respond to a support request, or comply with a legal obligation under Section 4.4. Messages sent through current versions of our apps are stored by us on Google Cloud Platform. Messages sent through older versions were stored on the infrastructure of our previous chat provider, Stream, and can also be read by Stream (see Section 4.3). Please do not send passwords, payment card numbers, identity document numbers, or similar secrets through in-app chat.

No system is 100% secure. While we take reasonable measures to protect your data, we cannot guarantee absolute security.

10. Data Breach Notification

In the event of a data breach that is likely to result in a risk to your rights, we will:

11. Analytics and Crash Reporting

We use the following services to understand app usage and improve stability:

You can limit analytics data collection through your device settings.

12. Children

The Service is not intended for persons under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected data from a child under 18, we will promptly delete it. If you believe a child has provided us with personal data, contact us at privacy@bossx.app.

13. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies.

14. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app or by email at least 14 days before the changes take effect. The "Effective date" at the top of this page indicates the latest revision.

15. Contact

If you have questions or concerns about this Privacy Policy or our data practices:

BOSSX GLOBAL LIMITED
Privacy inquiries: privacy@bossx.app
General: contact@bossx.app