FBOTRIP™

Privacy Policy

This draft explains the personal information involved in FBOTRIP, owned and operated by Blackwaze Ltd under the Blackwaze Luxury Transportation service brand. It describes the currently implemented service, not an assurance of global legal compliance.

1. Responsible operator and privacy contact

Blackwaze Ltd owns and operates FBOTRIP under the Blackwaze Luxury Transportation service brand. The operator states that Blackwaze Ltd is registered in Canada and the United Kingdom under the same name. The Canadian or UK entity acting as data controller for each relevant service, its registered address and privacy contact email must be identified and published before this draft is adopted.

Until those details are verified, this document is not a completed operational privacy notice. Do not send identity documents, payment-card details or other sensitive information to an unverified contact.

2. Information involved in the service

Provider qualification includes verified contact information, current signed agreements, driver licensing and any identity, tax or screening evidence required by the configured lawful jurisdiction, company-registration evidence, vehicle registration/commercial-use authority, commercial insurance with verified coverage dates, and vehicle photographs with readable plates. Optional public-profile photographs require consent and approval. These records are stored privately and access is limited to the relevant person and authorized verification personnel.

Manual bank-transfer payee verification uses restricted Void Cheque / Direct Deposit Verification documents in the private application and finance review area. Banking documents are not published in a chauffeur dashboard or public profile, and no card/CVV or raw bank-account-number form is provided. Approved affiliates are paid through the verified contracting company. Provider payments are manual bank transfers every two weeks, not automated Stripe payouts.

Account and contact information may include names, email addresses, phone numbers, company details, authentication identifiers and role assignments. Booking records include pickup/drop-off addresses and coordinates, requested times, vehicle category, passenger and luggage counts, flight or aircraft details, requested services and instructions.

Quote and transaction records include currency, fare components, taxes, gratuity, quote identifiers, booking references, payment-provider references and authorization, capture or refund status. Card data is handled by Stripe; the booking service does not need to receive or store full card numbers or card security codes.

Approved chauffeur profiles may contain operational and vehicle information. Location reporting, when enabled, provides chauffeur coordinates, timestamps and accuracy information to determine service availability. Technical information may include request, error and security logs and browser/network information received by the providers you access.

3. Purposes and legal bases

Information is used to resolve addresses and routes, calculate pickup-based fares and taxes, assess vehicle and chauffeur availability, manage requests and confirmed services, process authorized payments and refunds, maintain appropriate booking records, and protect the service against fraud and misuse.

Where applicable, processing may rely on steps requested before a contract and performance of the transportation contract, legal obligations, proportionate legitimate operational/security interests, or consent for optional features where consent is required. The operator must confirm the applicable legal bases, retention duties and legitimate-interest assessments for its actual jurisdictions before publication.

4. Location information

A customer may permit browser location to bias address suggestions. This does not determine the tax or currency jurisdiction: pricing is based on the selected pickup location. Device permissions may be declined or withdrawn; addresses can still be entered manually.

Chauffeur location reporting is an optional, explicit operational feature for approved chauffeurs. Online reporting supports availability checks near pickup. Disabling reporting stops further app location updates; previously recorded information may remain subject to the operator’s verified retention rules. Do not describe a last-known location as continuous live tracking.

5. Service providers and sharing

Clerk provides account authentication and session management and receives the information needed for those functions. Stripe handles card authorization, payment and refund processing and associated transaction information.

Mapbox receives relevant search queries, addresses or coordinates for location suggestions, geocoding, maps and routes, together with network metadata associated with those requests. The Blackwaze pricing service receives pickup city, region and country for the tax lookup; that lookup is not intended to receive exact passenger addresses or passenger details.

Google Fonts serves typography resources and may receive browser/network metadata when fonts are requested; Google Maps is not the mapping provider.

Hosting and data infrastructure, including the Replit development environment and Railway where deployed, may process service records and technical logs. The final production provider list, locations and contracts must be verified. Authorized Operations staff and assigned chauffeurs receive only information needed for their responsibilities. Authorities or professional advisers may receive information when lawfully required.

6. Cookies and browser storage

Authentication uses session-related technologies. Browser storage supports app functions such as the last booking receipt and preferences. These records may remain on a shared device; sign out and clear browser data where appropriate.

This draft does not authorize advertising tracking or session recording. Before adding non-essential analytics, advertising or other tracking, the operator must assess disclosure and consent requirements and implement the appropriate controls. Provider diagnostics and development telemetry must also be assessed for the final production configuration.

7. Security, retention and international transfers

The service uses role-based access and provider-managed authentication and payment processing. These measures reduce risk but do not guarantee absolute security. The operator must verify production safeguards, access reviews, incident procedures and provider agreements rather than assume development configuration is production-ready.

Information should be retained only as needed for the stated service purposes, applicable accounting/regulatory obligations and proportionate dispute/security needs. The exact retention schedule and deletion process have not yet been verified; this draft does not promise a fixed deletion deadline.

Service providers may process information outside the passenger’s country. Before publication, the operator must identify relevant locations and implement any legally required transfer safeguards and contractual arrangements.

8. Privacy rights and complaints

Depending on applicable law, individuals may request access, correction, deletion, portability, restriction or objection, withdraw consent where consent is the basis, and complain to the competent data-protection authority. Some records may need to be retained where legally required. Appropriate identity verification may be needed before disclosure.

The operator must publish a verified privacy contact and workable request procedure before adopting this policy. Do not collect excessive identity evidence to handle a request, and do not require an individual to give up statutory rights as a condition of using the service.

9. Children and sensitive information

Bookings for children must be arranged by an authorized adult. The service is not intended for children to independently create contractual bookings. Share only information needed for lawful transportation and safety arrangements.

Avoid unnecessary health, identity-document or other sensitive details in booking instructions. Where special assistance requires sensitive information, the operator must establish an appropriate lawful basis, safeguards and access limits.

10. Updates

The operator should publish a dated, reviewed privacy notice and communicate material changes where legally required. The “draft prepared” date is not an adopted effective date. Any expansion of purposes, providers or tracking must be reviewed and reflected in the notice before implementation.