SURERIDE PRIVACY POLICY

Last Updated: 18 August 2026

SureRide Pte. Ltd., trading as SureRide (“SureRide”, “we”, “us” or “our”), respects your privacy and is committed to protecting the personal data entrusted to us.

This Privacy Policy explains how we collect, use, disclose, process, store, transfer and protect personal data when you use our transportation services, websites, applications and other digital platforms.

Our privacy practices are designed to comply with the Singapore Personal Data Protection Act 2012 (“PDPA”) and, where applicable, the European Union General Data Protection Regulation (“GDPR”) and other applicable privacy and data protection laws.

 

1. Scope

This Privacy Policy applies to personal data processed through SureRide services and platforms, including:

  • Our website;
  • Mobile websites;
  • iOS and Android applications;
  • Booking platforms;
  • Customer portals;
  • APIs and integrations;
  • Customer service channels;
  • Email, telephone and electronic communications;
  • Payment and transaction systems; and
  • Chauffeured transportation services.

It applies to customers, passengers, website visitors, application users and other individuals whose personal data we process.

2. Personal Data We May Collect

Depending on how you interact with SureRide, we may collect information including:

Identity and Profile Information

  • Name;
  • Preferred name or alias;
  • Account identifier;
  • Company or organisation;
  • Customer profile information; and
  • Other information required to identify or service a Customer.

Contact Information

  • Email address;
  • Telephone number;
  • Billing address; and
  • Other contact information.

Booking and Journey Information

  • Pick-up location;
  • Destination;
  • Date and time of travel;
  • Flight number and flight information;
  • Vehicle preference;
  • Passenger numbers;
  • Luggage requirements;
  • Special service requests;
  • Booking history; and
  • Driver and vehicle information associated with a journey.

Location Information

Where necessary to provide transportation services, SureRide may process location information including:

  • Pick-up location;
  • Drop-off location;
  • Device location, where permission has been granted;
  • Vehicle location;
  • Driver location; and
  • Location information generated during an active journey.

Transaction Information

We may process:

  • Booking value;
  • Currency;
  • Payment status;
  • Transaction identifiers;
  • Refund information;
  • Invoices; and
  • Other financial transaction information.

Full payment card information may be processed by our authorised payment service providers rather than stored directly by SureRide.

Technical Information

Our digital platforms may collect:

  • IP address;
  • Device type;
  • Browser type;
  • Operating system;
  • Application version;
  • Device identifiers;
  • Login information;
  • Security events;
  • System logs;
  • Crash information;
  • Cookie identifiers; and
  • Usage information.

3. Why We Process Personal Data

We may collect, use, disclose or otherwise process personal data for purposes including:

  • Creating and managing Customer accounts;
  • Processing transportation bookings;
  • Matching bookings with vehicles and drivers;
  • Providing pick-up and transportation services;
  • Providing real-time journey functionality;
  • Processing payments and refunds;
  • Communicating with Customers and passengers;
  • Providing customer support;
  • Handling lost property;
  • Managing complaints and disputes;
  • Maintaining booking and transaction records;
  • Detecting and preventing fraud;
  • Maintaining platform and information security;
  • Improving our services and technology;
  • Analysing service performance;
  • Meeting insurance requirements;
  • Complying with legal and regulatory requirements;
  • Responding to lawful requests from government or regulatory authorities; and
  • Establishing, exercising or defending legal claims.

We will seek to limit collection, use and disclosure of personal data to purposes that are reasonable and appropriate in the circumstances and permitted by applicable law.

4. Consent and Other Legal Bases

Where required under the Singapore PDPA, SureRide will obtain consent for the collection, use or disclosure of personal data unless an applicable legal exception applies.

By voluntarily providing personal data for a particular purpose, you may consent or be deemed to consent to its reasonable use for that purpose where permitted by law.

Where the GDPR applies, our legal basis for processing may include:

  • Your consent;
  • Performance of a contract with you;
  • Steps requested by you before entering into a contract;
  • Compliance with a legal obligation;
  • Protection of vital interests;
  • Our legitimate interests or those of a third party, where those interests are not overridden by your rights and interests; or
  • Another lawful basis permitted by applicable law.

Where we rely on consent, you may withdraw that consent subject to applicable legal and contractual restrictions.

Withdrawal of consent does not affect processing lawfully undertaken before withdrawal.

Some information may be necessary for SureRide to provide a service. If you decline or withdraw consent for processing that is necessary to provide that service, we may be unable to provide some or all of the requested service.

5. Data Minimisation and Use of Aliases

SureRide seeks to collect only personal data reasonably necessary for the relevant purpose.

Where your legal identity is not reasonably required for the service, SureRide may permit Customers to provide or use a preferred name, display name or alias.

For example, an alias may be sufficient for certain passenger identification or driver-to-passenger communications.

However, SureRide may require a legal name or other identifying information where reasonably necessary for:

  • Payment processing;
  • Fraud prevention;
  • Legal or regulatory compliance;
  • Insurance;
  • Safety and security;
  • Corporate travel requirements;
  • Law enforcement requests; or
  • Verification of identity where legally permitted or required.

Use of an alias must not be used to impersonate another person, commit fraud, evade legal obligations or otherwise misuse SureRide services.

6. National Identification Numbers

SureRide does not seek to collect Singapore NRIC, FIN, passport numbers or other government-issued identification numbers unless reasonably necessary and permitted or required by law.

Where such information is required, SureRide will seek to:

  • Collect only the information reasonably necessary;
  • Restrict access to authorised personnel;
  • Protect the information using appropriate technical and organisational controls;
  • Avoid using identification numbers as passwords or authentication credentials; and
  • Retain such information only for as long as reasonably necessary or legally required.

7. Location Data

Location data is particularly relevant to providing SureRide’s transportation services.

Location information may be used to:

  • Locate a passenger;
  • Dispatch a driver;
  • Navigate to a pick-up point;
  • Facilitate a journey;
  • Provide estimated arrival times;
  • Support passenger and driver safety;
  • Investigate operational incidents; and
  • Prevent fraud or misuse.

Short-Term Precise Location Retention

Where SureRide collects precise or real-time device or vehicle location data, we aim to retain that precise location data for less than 24 hours after it is no longer operationally required.

After that period, precise location data will be deleted, anonymised or aggregated, unless longer retention is reasonably necessary or required for:

  • A safety incident;
  • An accident;
  • Fraud investigation;
  • A Customer complaint or dispute;
  • Insurance;
  • Legal proceedings;
  • Regulatory requirements; or
  • Compliance with law.

Booking records may continue to contain the Customer’s requested pick-up and drop-off locations after the 24-hour period because those locations form part of the booking and transaction record.

Accordingly, the less-than-24-hour policy relates primarily to precise tracking or telemetry data and does not necessarily require deletion of addresses forming part of a booking record.

8. Location Permissions

Where our mobile application requests access to device location services, you may control location permissions through your device settings.

Where reasonably practicable, SureRide will not require continuous location access where it is unnecessary to provide the requested service.

Disabling location access may affect certain functions, such as:

  • Automatically determining your current pick-up location;
  • Real-time driver/passenger location functionality; and
  • Location-based journey features.

 

9. Data Retention

SureRide retains personal data only for as long as there is a reasonable business or legal purpose for retaining it, subject to applicable law.

Retention periods may differ depending on:

  • The type of information;
  • Country or region;
  • Applicable law;
  • Tax and accounting obligations;
  • Regulatory requirements;
  • Insurance requirements;
  • Fraud prevention;
  • Contractual obligations;
  • Dispute resolution; and
  • Legal limitation periods.

Personal data will be deleted, anonymised, securely disposed of or otherwise placed beyond use when SureRide determines that retaining the data no longer serves a legal or business purpose for which retention is permitted.

Different regional retention requirements may therefore apply to different Customers.

10. Security

SureRide takes the security of personal data seriously.

We maintain technical and organisational security measures designed to protect personal data against:

  • Unauthorised access;
  • Unauthorised disclosure;
  • Accidental loss;
  • Theft;
  • Modification;
  • Destruction;
  • Misuse; and
  • Other security threats.

Depending on the system and nature of the information, these measures may include:

  • Strong encryption technologies;
  • Encryption of data in transit;
  • Encryption of appropriate data at rest;
  • Authentication controls;
  • Role-based access controls;
  • Least-privilege access;
  • Network security controls;
  • Security monitoring;
  • Logging and auditing;
  • Secure development practices;
  • Vulnerability management;
  • Backup and recovery controls; and
  • Incident response procedures.

SureRide seeks to use industry-leading encryption and security practices appropriate to the sensitivity and risk associated with the information being protected.

No electronic storage, transmission, application, network or security system can be guaranteed to be completely secure.

11. Access Controls

Access to personal data is restricted to authorised persons and service providers who require access for legitimate business, operational, security, support, legal or regulatory purposes.

SureRide maintains access controls intended to ensure that personnel and systems can access only information reasonably necessary to perform their authorised functions.

We may monitor and audit access to systems containing personal data where appropriate.

Unauthorised access, use or disclosure of personal data by SureRide personnel may result in disciplinary or other appropriate action.

12. Sharing Personal Data

SureRide does not sell personal data.

We may disclose personal data where reasonably necessary to:

  • Drivers;
  • Authorised transportation operators;
  • Corporate travel partners;
  • Payment processors;
  • Cloud infrastructure providers;
  • Technology providers;
  • Communications providers;
  • Mapping and navigation providers;
  • Customer support providers;
  • Professional advisers;
  • Insurers;
  • Auditors;
  • Regulators;
  • Courts;
  • Law enforcement agencies; and
  • Other parties where required or permitted by law.

We seek to limit information shared with third parties to what is reasonably necessary for the relevant purpose.

Where service providers process personal data on our behalf, we seek to impose appropriate contractual, confidentiality and security requirements.

13. International Data Transfers

SureRide operates technology services that may involve processing or storing personal data outside the country in which it was collected.

Where Singapore personal data is transferred outside Singapore, SureRide will take appropriate steps to ensure that the transferred data receives a standard of protection comparable to that required under the PDPA, as required by applicable law.

Where the GDPR applies to international transfers, SureRide will use an appropriate transfer mechanism where required, which may include:

  • An adequacy decision;
  • Standard Contractual Clauses;
  • Binding Corporate Rules, where applicable; or
  • Another legally recognised transfer mechanism.

14. Cookies and Similar Technologies

Our websites and applications may use cookies, SDKs, local storage, pixels or similar technologies.

These technologies may be used for:

  • Authentication;
  • Security;
  • Session management;
  • User preferences;
  • Platform functionality;
  • Performance monitoring;
  • Analytics;
  • Fraud prevention; and
  • Service improvement.

Where required by applicable law, non-essential cookies or tracking technologies will be subject to appropriate notice and consent mechanisms.

Users may be able to manage cookies through their browser, device or our available privacy controls.

Disabling certain technologies may affect platform functionality.

15. Analytics

SureRide may analyse aggregated, anonymised or appropriately pseudonymised information to:

  • Understand service demand;
  • Improve fleet operations;
  • Improve application performance;
  • Analyse service reliability;
  • Identify technical problems;
  • Develop new services; and
  • Improve the Customer experience.

Where information has been properly anonymised such that an individual can no longer reasonably be identified, it may no longer constitute personal data under applicable privacy laws.

16. Marketing Communications

Where permitted by law, SureRide may communicate with Customers regarding its products, services, promotions or updates.

Where consent is required for electronic direct marketing, we will seek appropriate consent.

Customers may unsubscribe or withdraw their marketing consent using the mechanism provided in the relevant communication or by contacting SureRide.

Operational communications necessary to provide a booked service are not marketing communications and may continue even where a Customer has opted out of marketing.

17. Singapore PDPA Rights

Subject to the PDPA and applicable exceptions, individuals may request:

  • Access to personal data held about them;
  • Information regarding how certain personal data has been used or disclosed;
  • Correction of inaccurate or incomplete personal data; and
  • Withdrawal of consent for certain collection, use or disclosure.

Requests may be subject to identity verification and other procedures permitted or required under applicable law.

SureRide will respond to valid requests in accordance with applicable statutory requirements.

18. GDPR Rights

Where the GDPR applies to the processing of your personal data, you may have rights including:

  • Right of access — obtain information about and a copy of your personal data;
  • Right to rectification — correct inaccurate or incomplete information;
  • Right to erasure — request deletion in applicable circumstances;
  • Right to restriction — request restriction of processing in applicable circumstances;
  • Right to data portability — receive certain information in a structured, commonly used and machine-readable format;
  • Right to object — object to certain processing, including certain processing based on legitimate interests;
  • Direct marketing rights — object to processing for direct marketing;
  • Rights concerning automated decision-making — where applicable;
  • Right to withdraw consent — where processing relies upon consent; and
  • Right to lodge a complaint with an applicable supervisory authority.

These rights are subject to the conditions, limitations and exemptions contained in applicable law.

19. Automated Decision-Making

SureRide may use automated systems to support functions such as:

  • Dispatch;
  • Vehicle matching;
  • Fraud detection;
  • Pricing;
  • Security;
  • Journey estimation; and
  • Service optimisation.

Where the GDPR or another applicable law provides specific rights relating to solely automated decisions that produce legal or similarly significant effects, SureRide will comply with those requirements.

20. Data Security

SureRide maintains procedures for identifying, assessing, containing and responding to suspected personal data breaches.

Where a breach meets applicable legal notification thresholds, SureRide will notify the Personal Data Protection Commission (“PDPC”), affected individuals, applicable GDPR supervisory authorities or other relevant parties as required by law.

We may also take steps including:

  • Containing the incident;
  • Securing affected systems;
  • Investigating the cause;
  • Assessing affected data;
  • Resetting credentials;
  • Notifying affected parties where required; and
  • Implementing remediation measures.

21. Limitation of Liability for Security Incidents

SureRide takes reasonable steps to protect personal data but no information system can be guaranteed to be completely secure.

To the maximum extent permitted by applicable law, SureRide will not be liable for indirect, incidental, special, consequential or economic loss arising from a cybersecurity incident, unauthorised access, third-party attack, system compromise or personal data breach that occurs despite reasonable security measures.

SureRide will not be responsible for security incidents caused by circumstances outside its reasonable control, including compromise of a Customer’s own device, credentials, email account, network or third-party service.

Nothing in this Privacy Policy excludes, restricts or limits any liability, statutory obligation or individual right that cannot lawfully be excluded, restricted or limited under the Singapore PDPA, GDPR or other applicable law.

22. Children’s Personal Data

SureRide’s digital services are not intended to enable children to independently purchase transportation services where they do not have legal capacity to do so.

Where personal data concerning a child is provided in connection with a legitimate transportation booking, SureRide will seek to process only information reasonably necessary to provide the service or meet legal and safety requirements.

Where applicable law requires parental or guardian consent, SureRide may require appropriate consent before processing the relevant information.

 

23. Third-Party Websites and Services

SureRide platforms may contain links to, or integrate with, third-party services.

These third parties may operate under their own privacy policies and terms.

SureRide is not responsible for the independent privacy practices of third parties except to the extent that responsibility cannot lawfully be excluded.

Customers should review the privacy policies of third-party services they choose to use.

 

24. Corporate Customers and Bookings Made for Others

A company, travel manager, hotel, travel agent, family member or another person may book transportation for a passenger.

In these circumstances, SureRide may receive personal data about the passenger from the person or organisation making the booking.

The party providing the information is responsible for having appropriate authority or another lawful basis to provide the relevant information to SureRide.

SureRide will process the information in accordance with this Privacy Policy and applicable law.

 

25. Accuracy of Personal Data

Customers should provide accurate and current information.

You should notify SureRide if information relevant to your account or booking changes.

SureRide will make reasonable efforts to ensure personal data used to make decisions affecting individuals, or disclosed to another organisation, is accurate and complete as required by applicable law.

 

26. Privacy by Design

Where reasonably practicable, SureRide incorporates privacy and data protection considerations into the design and operation of its digital services.

This may include:

  • Data minimisation;
  • Purpose limitation;
  • Short retention periods for sensitive operational data;
  • Pseudonymisation;
  • Encryption;
  • Access segregation;
  • Secure application development;
  • Security testing; and
  • Privacy impact assessments where appropriate.

 

27. Data Protection Officer

SureRide will designate a Data Protection Officer (“DPO”) responsible for overseeing compliance with applicable Singapore data protection requirements.

The DPO may be contacted regarding:

  • Privacy enquiries;
  • Access requests;
  • Correction requests;
  • Withdrawal of consent;
  • Privacy complaints;
  • Data protection concerns; and
  • Questions regarding this Privacy Policy.

Data Protection Officer
SureRide Pte. Ltd.
Singapore
Email: contact@sureridehq.com

SureRide will publish appropriate DPO business contact information as required under Singapore law.

28. GDPR Representative

Where SureRide is required under the GDPR to appoint a representative in the European Union or European Economic Area, the relevant representative’s contact information will be made available through this Privacy Policy or another appropriate privacy notice.

29. Complaints

Privacy complaints should first be directed to SureRide’s Data Protection Officer.

We will investigate and respond to complaints in accordance with applicable law.

Individuals may also have the right to submit complaints to:

  • The Personal Data Protection Commission of Singapore; or
  • An applicable EU/EEA data protection supervisory authority where the GDPR applies.

 

30. Changes to this Privacy Policy

SureRide may update this Privacy Policy from time to time to reflect:

  • Changes to our services;
  • Changes to our technology;
  • Changes to our data practices;
  • Security developments;
  • Regulatory requirements; or
  • Changes to applicable law.

The latest version will be published on our website or otherwise made available through our platforms.

Where required by applicable law, we will provide additional notice or obtain consent before materially changing how existing personal data is processed.

31. Governing Law

This Privacy Policy is governed by the laws of the Republic of Singapore, subject to mandatory rights and protections that may apply under the GDPR or other applicable laws.

Nothing in this Privacy Policy is intended to prevent an individual from exercising rights or remedies available under mandatory data protection legislation.

32. Contact Us

For questions about this Privacy Policy or SureRide’s handling of personal data, please contact:

Data Protection Officer
SureRide Pte. Ltd.

Email: contact@sureridehq.com

 

© 2026 SureRide Pte. Ltd. All rights reserved.