Accounts and trip data
Carpool uses a separate account database. We store your email, display name, password hash, email verification status, ride offers, seat requests, messages, moderation reports and payment references. Your email is not shown to other members. Signed-in members can see ride areas, departure times, the driver’s display name and vehicle description. Only the driver and accepted passengers can see pickup instructions.
Messages and access
Trip conversations are visible only to their two participants through the application. Messages are not end-to-end encrypted; hosting operators can access stored data. Administrators can review accounts, rides, submitted reports and payment status. Blocking prevents new interaction and cancels shared requests.
Services and storage
We use an essential, scoped session cookie. Authentication emails use the existing Resend service. Maps request tiles from OpenStreetMap and use a local GeoNames city directory; map providers receive your IP address and the viewed map area. We do not request device GPS or track trips in the background. The public visitor map uses the same local IP-location database as IICSM. It counts one IP per UTC day, stores aggregate approximate locations and short-lived keyed identifiers rather than raw IP addresses, and displays public location totals only after three daily visits. Carpool totals are independent of other websites. Optional Stripe checkout collects payment details on Stripe, not here.
Request-rate identifiers are keyed hashes and expire within their configured hour or shorter window. Email tokens expire within 24 hours (verification) or one hour (recovery). Account/trip records remain until an administrator handles a data request; hosting backups may retain prior copies. Deactivate through Account to stop participation and cancel active trips. Contact admin for access or deletion requests. The Home Screen app caches only its public offline page and icons, never private rides or messages.
