Carpooling in India · Mobile app only
CoMiles Privacy Policy
Version 2026-09-11.1. Learn what data is used, why it is needed, who can access it, how long it is kept, and your choices.
1. Who is responsible and how to contact us
The CoMiles service is operated by COMILES PRIVATE LIMITED, a Private Limited Company with CIN U52290HR2026PTC148996 and registered office at Basement, Shop No. 1, MIE Part B, Delhi Rohtak Road, Bahadurgarh, Jhajjar, Haryana – 124507.
Privacy, access, correction, deletion, grievance, and security questions may be sent to support@comiles.in. CoMiles' Grievance Officer is Harshit Garg, Director. No customer-care or grievance phone number is currently available; publishing a dedicated company-controlled number remains a production-launch compliance input.
2. Data we collect
- Account and authentication data: account identifier, phone or identity-provider information, authentication events, legal acceptance, and account status.
- Profile and trust data: name, photo, bio, date of birth, gender, interests, ratings, work-email status, typed employer, LinkedIn context, blocks, and reports.
- Vehicle data: registration and self-attested or provider-returned vehicle details, verification state, and optional vehicle photo. CoMiles no longer collects an RC document upload in the current client flow.
- Journey data: offered or requested routes, approximate and precise points where permitted, schedules, stops, seats, luggage, bookings, cancellations, no-shows, ride state, and feedback.
- Communication data: in-app messages and media, conversation state, call records or provider metadata, notification tokens and delivery receipts, and support correspondence.
- Safety and settlement data: emergency contacts, SOS or incident records, active-trip location, time-limited trip-share records, direct-payment acknowledgements or disputes, and moderation actions.
- Technical data: app version, platform, device or installation identifiers, network/error diagnostics, security logs, and configured monitoring events.
3. Where data comes from
Data comes from you, your device permissions, other participants interacting with you, configured identity/work/vehicle providers, and technical providers used to deliver the service. Provider sign-in or a successful verification step supplies only the fields and status described in the app.
4. Why we use data
- Create and secure accounts, record consent, provide support, and process account closure.
- Match compatible routes, enforce seat and ride state, coordinate recurring/intercity journeys, and enable direct communication.
- Apply privacy, block, women-controlled preference, organization, moderation, and relationship rules.
- Provide ratings, clearly labelled trust signals, trip sharing, SOS, location health, alerts, notifications, and fraud/abuse prevention.
- Diagnose reliability, protect the platform, comply with law, resolve disputes, and improve the product using proportionate or aggregated analysis.
5. When data is shared
CoMiles does not sell personal data. Information is shared only for the relevant purpose and ride stage, with another participant, a configured service provider, an authorized support/safety operator, or a public authority where disclosure is required or permitted by law.
- Potential or confirmed co-riders receive only the profile, route, vehicle, trust, and relationship fields allowed for that stage. Phone numbers are not displayed to other users.
- Supabase, Stream, Expo, map/places, identity, work-email, vehicle, SMS, monitoring, and other configured providers process limited data needed for their service.
- A valid trip-share token can disclose the limited active-trip information attached to it to anyone who receives the link until expiry or revocation.
- Aggregated or genuinely anonymised information may be used for internal product, route-demand, reliability, safety, or impact analysis.
6. Location and ride-stage privacy
Discovery uses privacy-aware route context rather than an open directory of exact home or work locations. More precise pickup, destination, and live-location data is restricted to authorised relationships and ride stages. Active tracking requires device permission and is designed to end when the ride ends.
Location, SOS, and trip-share delivery depend on permissions, connectivity, operating-system behavior, and external providers. They are safety aids, not guaranteed emergency services.
7. Women-controlled preferences, work, and LinkedIn
Eligible women can apply supported women-only driver or passenger preferences; the server enforces that boundary. A signed-in female viewer may receive a limited same-gender cue only within an authorised ride context. Gender is not placed in the public profile directory.
A verified work email is distinct from a typed employer. LinkedIn sign-in or context does not prove employment, government identity, conduct, or safety. Post-ride LinkedIn profile exchange requires mutual choice.
8. Retention and deletion
Operational records are kept only for as long as reasonably needed for the feature, security, support, legal, or dispute purpose. Exact active-trip sharing ends with the ride; time-limited links and route-demand records expire under their configured rules; provider/security logs follow their configured retention.
Account deletion removes profile personal data, CoMiles-hosted assets, messages, saved places, and the authentication account. Stream call-related deletion may finish asynchronously. Narrow anonymised safety and settlement evidence may remain for 12 months and is then erased automatically; it excludes account, contact, ride, booking, precise location, message, media, free text, fare, and payment-reference identifiers.
9. Your choices and rights
- Use device settings to control location, camera, photo, microphone, calling, and notification permissions. Some features will not work without the relevant permission.
- Ask support@comiles.in for access to or correction of your personal data, or raise a privacy grievance. CoMiles may need proportionate verification before acting on a request.
- Delete your account in the mobile app and keep the deletion receipt for reference. Where applicable, you may withdraw consent, nominate another person, or use remedies available under Indian data-protection law.
- A request can be limited where retention or refusal is required or permitted by applicable law; CoMiles will explain the applicable reason where required.
10. Security and incidents
CoMiles uses encrypted network connections, authentication, role and relationship-based access controls, private Storage where appropriate, limited privileged workers, audit records, and monitoring designed to reduce unauthorized access. No service can guarantee absolute security.
If you suspect an account, privacy, or security incident, contact support@comiles.in. Do not send an OTP, password, UPI PIN, full payment credential, or unnecessary identity document. CoMiles will assess and notify affected people or authorities where applicable law requires it.
11. International processing and providers
Configured providers may process data outside your state or India. CoMiles will use provider contracts, settings, and other safeguards appropriate to the service and applicable law, and will update this Policy if a material processing arrangement changes.
12. Children
CoMiles is for adults aged 18 or older and is not intended for children. Do not create an account or arrange a ride for an unaccompanied minor through CoMiles. Contact support if you believe a child has provided personal data.
13. Public website and analytics
The public website does not provide ride search, ride offering, or account login. CoMiles has not silently added a third-party marketing analytics product in the current website build. If analytics, advertising, or non-essential cookies are introduced, the notice, consent behavior where required, provider list, and this Policy must be updated before collection begins.
14. Changes and contact
Material changes receive a new version and may require renewed in-app acceptance. Contact support@comiles.in with privacy questions, rights requests, or grievances. The Grievance Officer is Harshit Garg, Director. Company identity details are published in this Policy and on the Company details page. No customer-care or grievance phone number is currently available; publishing a dedicated company-controlled number remains a production-launch compliance input.