Privacy Policy

Last updated: April 20, 2026

Payfair (“we”, “our”, “us”) operates the payfair.cash website, the Payfair Android application, and the Payfair iOS application (together, the “Service”). This policy explains what information we collect, how we use it, and your rights regarding that data.

Information We Collect

Account Information (Mobile Apps)

When you create an account on the Android or iOS app, we collect:

  • Email address — for authentication and account recovery.
  • Phone number — for SMS-based authentication.
  • Full name — for your profile.
  • Date of birth — to verify you meet the minimum age requirement (16+).
  • Sex and ethnicity (optional) — voluntarily provided for demographic research; you may select “prefer not to say”.
  • Profile photo (optional) — stored securely on our servers.

If you sign in with Google or Apple, we receive your name and email address from the respective provider. Google Sign-In may also provide your profile picture.

Location Data

  • Pickup and drop-off coordinates that you provide when comparing fares.
  • Approximate device location — only when you explicitly grant location permission and tap the “Detect Location” button. We never collect location in the background.

Location coordinates are used to calculate routes, estimate fares, and improve price accuracy. Coordinates from fare comparisons are stored in our analytics database to improve fare estimates over time.

Fare Comparison Data

When you compare fares (on the app or website), we collect:

  • Pickup and drop-off coordinates.
  • Fare quotes returned by ride-hailing providers (price, tier, ETA, surge status).
  • Route distance and duration.
  • An anonymous per-session identifier (UUID) that is not linked to your account and is not persisted across sessions.
  • App version and platform (Android or iOS).

Device Information (Mobile Apps)

We collect basic device information including manufacturer, model, and operating system version. This information is used for compatibility purposes and may be forwarded to ride-hailing provider APIs during authentication.

Website Usage

  • Local storage — we store recent searches and display preferences (e.g., weather effects toggle) in your browser’s local storage. No cookies are used for tracking.
  • Analytics — we use Ahrefs Analytics to collect aggregated, anonymized website traffic data (page views, referrer, browser type). Ahrefs does not use cookies or track individual users.

How We Use Information

  • Provide fare estimates and comparisons across ride-hailing services.
  • Improve the accuracy of our fare estimation models using anonymized comparison data.
  • Authenticate your account and verify your identity.
  • Send one-time verification codes via SMS or email.
  • Maintain security, prevent abuse, and enforce rate limits.
  • Display relevant advertisements.

SMS Messaging Program

When you sign up or sign in to the Payfair mobile apps using your phone number, we send you a one-time verification code via SMS. This is a strictly transactional Two-Factor Authentication (2FA) program operated by SSD Technologies LLC.

  • Purpose: One-time passcode (OTP) delivery for account sign-up and sign-in. No marketing, promotional, or newsletter messages are ever sent on this program.
  • Frequency: Recurring messages are not sent. One SMS is delivered per user-initiated sign-up or sign-in attempt (including taps on “Resend Code”).
  • Rates: Message and data rates may apply. Payfair does not charge for these messages, but your mobile carrier may.
  • HELP: Reply HELP to any message or email hi@payfair.cash.
  • STOP: Reply STOP to any message at any time to opt out of the SMS program.
  • Message content: Messages contain no embedded links. Every message identifies the sender as “Payfair” and states its purpose (“verification code”).

Mobile information & consent data — non-sharing

No mobile information — including phone numbers, opt-in data, and consent — will be shared with any third parties or affiliates for marketing or promotional purposes. All other personal-data categories described in this policy exclude text messaging originator opt-in data and consent; that information is never shared with any third parties.

Phone numbers used for SMS verification are transmitted only to Twilio Inc., acting solely as a processor under a data processing agreement to deliver the verification code. Twilio is contractually prohibited from secondary use of this data. A public reference of the full in-app consent flow is available at payfair.cash/sms-consent/.

Third-Party Services & Processors

Payfair relies on processor relationships with third-party service providers for mapping and routing, analytics, SMS delivery (Twilio), email delivery (Brevo), authentication, and advertising. Processors receive only the minimum data necessary to perform the requested function (such as coordinates for route calculation, a phone number to deliver an SMS OTP, or an email address to send an email OTP). Processors are contractually restricted from using that data for their own marketing or promotional purposes, and therefore do not constitute “third-party sharing” under the SMS non-sharing clause above. Each processor handles data in accordance with its own privacy terms and our data processing agreement.

Data Storage and Security

  • Account data is stored in encrypted databases hosted on Railway (cloud infrastructure).
  • On-device data (Android) is stored using Android’s EncryptedSharedPreferences with AES-256 encryption.
  • On-device data (iOS) is stored using the iOS Keychain with kSecAttrAccessibleWhenPasscodeSetThisDeviceOnly protection. Sensitive tokens are never stored in plain text.
  • Fare comparison data is stored in PostgreSQL for analytics. This data is associated with anonymous session identifiers, not user accounts.
  • Passwords are never stored — we use one-time verification codes for authentication.
  • All data in transit is encrypted via HTTPS/TLS. Certificate pinning is used for connections to payfair.cash servers.

Data Retention

  • Account data — retained until you delete your account.
  • Fare comparison analytics — retained indefinitely in anonymized form to improve fare estimates.
  • Verification codes — automatically deleted after 10 minutes.
  • Local storage (website) — recent searches are retained until you clear browser data. Last route is automatically cleared after 24 hours.

Data We Do Not Collect

  • We do not collect your advertising ID (IDFA on iOS or Advertising ID on Android).
  • We do not track your location in the background.
  • We do not use tracking cookies on the website.
  • We do not sell your personal data to third parties.
  • We do not share mobile opt-in data or SMS consent with any third parties or affiliates for marketing or promotional purposes.
  • We do not collect IMEI, hardware serial numbers, or MAC addresses.

Your Rights

  • Access — view your account data in the app’s Profile screen.
  • Correction — update your profile information at any time in the app.
  • Deletion — request account deletion via payfair.cash/deletemeplease or the “Delete Account” option in the app. Your data will be permanently removed within 30 days. Signing in again within this period cancels the deletion.
  • Portability — contact us to request an export of your data.

App Permissions

Android

PermissionWhy We Need It
InternetRequired to fetch fare estimates and communicate with our servers.
LocationUsed only when you tap “Detect Location” to auto-fill your pickup address. Never accessed in the background.
CameraOptional — used only if you choose to take a profile photo.
NotificationsOptional — for price alerts and updates if you enable them.

iOS

PermissionWhy We Need It
Location When In UseUsed to set your pickup location and compare nearby ride quotes. Never accessed in the background.
CameraOptional — used only if you choose to take a profile photo during registration.
Photo LibraryOptional — used only if you choose to select a profile photo from your gallery.

Children’s Privacy

Payfair is not intended for users under the age of 16. We do not knowingly collect data from children. If you believe a child has provided us with personal information, please contact us and we will delete it.

Changes to This Policy

We may update this policy from time to time. Material changes will be noted with an updated “Last updated” date at the top of this page.

Contact

If you have questions about this policy or wish to exercise your data rights, contact us at hi@payfair.cash.