Draft — awaiting legal review and approval. RidezHub remains under development.
Unapproved October 10 review copy. Not an effective policy or new rider acceptance.
RidezHub United States Privacy Notice
Riders prospective riders and permitted guest riders
Current review: RH-PRIV-2026-10-10-v5 | October 10, 2026 | Revised review draft carrying forward the October 4 approved business decisions. Not approved for publication.
DRAFT FOR ATTORNEY AND IMPLEMENTATION REVIEW — NOT APPROVED FOR PUBLICATION
Review copy: blue wording includes carried-forward revisions and October 10 updates; black wording is retained text. Yellow highlights identify open decisions. Deleted wording and comparison arrows are retained in the October 4 originals, not this clean review copy. This is not Word Track Changes. Do not publish this draft.
Business-information review October 10, 2026. Review preview for Pablo A. Otero III. San Antonio is the intended first market. RidezHub remains under development and in sandbox testing. Entity formation, the requested TVC letter response, provider authorization and legal publication remain pending in the reviewed records. No new email review or live launch is claimed. Blue text includes prior revisions and October 10 updates; the October 4 originals preserve prior comparisons.
This original notice describes the proposed privacy practices for RidezHub’s United States ride-booking model. It covers accounts, authorized provider bookings, payments, location, support, optional text updates and military/veteran benefits. RidezHub remains in development and test mode. Statements below are proposed operating commitments, not findings that production systems already perform them. The operator must verify the data inventory, vendors, controls and retention schedule before adopting this notice. Development and sandbox use can still involve real personal information, including account emails, support messages and device or location information. Test payments do not make all associated personal data fictional. A truthful notice for any actual collection is needed during testing, not only at production launch.
Proposed effective date: [Insert after approval]. Responsible operator: [CONFIRM full legal name and business form]. Business notice address: [CONFIRM mailing address]. Founder and creator: Pablo A. Otero III. Privacy contact: pablo.otero@ridezhub.com. RidezHub is the project name; this draft does not assert that a legal entity has been formed.
1 Scope and responsibilities
This notice applies to RidezHub’s own apps, website and support channels for services offered in the United States. It covers adult account holders and, where authorized guest booking is enabled, people whose rides are requested by another adult. RidezHub is designed to facilitate selection and booking through authorized transportation providers; the selected provider operates the transportation and determines driver or vehicle assignment.
Each independent transportation provider, payment processor and verification service may also process information under its own notice and legal responsibilities. This notice describes RidezHub’s practices and does not replace those notices or grant permission for an integration. When you leave RidezHub for a provider’s app or website, review that provider’s notice. No foreign-country supplement, foreign controller or international service offering is incorporated here.
Our U.S. service scope does not establish that every vendor, server or support worker is located in the United States. We must verify hosting and access locations and provide any legally required disclosure before launch. This notice does not promise U.S.-exclusive data storage or access.
2 Personal information you provide
Account and contact information: name, email address, telephone number, account identifier, authentication credentials protected as appropriate, and account settings. We seek an adult eligibility confirmation; we do not routinely collect a full birth date unless an approved verification need requires it. Do not submit another person’s information without appropriate permission.
If optional phone-number sign-in is introduced, we will use the supplied number and authentication delivery records to send and validate requested sign-in codes, alongside the email-and-password option. A request for a code is not consent to ride-update or marketing texts. Phone-code sign-in is not represented as currently enabled by this draft.
Booking details: pickup and destination addresses, scheduled time, selected provider and ride option, contact instructions and an accessibility request you choose to provide. An accessibility request may reveal sensitive information. Provide the assistance needed rather than a medical history. RidezHub will obtain required consent and limit use and disclosure to fulfilling the request or another lawful purpose.
Payment details: information submitted to the approved payment processor, billing information when needed, payment tokens, payment method type and limited display details, transaction references and status. The proposed design routes full card details to the processor rather than retaining them in RidezHub’s application database; this must be confirmed in the implemented integration. Do not send full card numbers or security codes to support.
Support and safety information: your inquiries, complaints, refund requests, feedback, and photos or documents you voluntarily provide to explain an issue. Do not submit unrelated identification, health information or information about bystanders. We do not offer public reviews or a social content feed under this model.
Program and consent records: military/veteran eligibility result, verification reference, benefit enrollment status, qualifying completed ride count, discounts, SMS choices, privacy consents, and the timestamp and version of accepted terms and the required safety disclosure. Verification document collection, if any, is governed by the authorized verifier’s disclosed process; RidezHub’s proposed design retains the eligibility result rather than copies of military IDs or full identity documents.
Optional passkeys support device fingerprint, face recognition or screen lock through the credential provider. RidezHub stores the credential identifier, public key, associated account identifier, counter, transports, creation time and last-use time. It does not receive the phone fingerprint or face image through this flow. Staging and production relying-party domains require separately valid credentials. Passkey enrollment does not accept revised terms or enroll the rider in SMS.
3 Information generated during use
Location: with your device permission and any additional consent required by law, RidezHub uses precise location to help identify your pickup and support an active booking. You may instead enter a pickup address manually where the feature is enabled. We do not propose continuous background tracking after the ride or location collection for advertising. Turning off device permission does not delete an address or earlier ride record already provided.
Trip and financial records: request, confirmation, verified arrival, pickup, completion and cancellation events, provider booking reference, disclosed estimates and final charges, RidezHub fee, discounts, receipts, refunds and disputes. The current standard RidezHub fee is $3.99; an eligible discount reduces the amount recorded. Precise driver or vehicle tracking is received only to the extent supplied by an authorized provider integration. RidezHub does not independently monitor all drivers.
Acknowledgment records include the Terms and safety/legal notice versions acknowledged for a booking, the acknowledgment date and time, and related account and booking identifiers. These records are distinct from any separate privacy, location or messaging consent that must be obtained.
Technical and security information: IP address, browser or app version, operating system, device or session identifier, access times, errors, authentication events and security logs reasonably needed for operation. An IP address can indicate approximate location. We do not propose collecting advertising identifiers, contact lists, device motion data or cross-app browsing histories.
Communications: messages and correspondence actually sent through RidezHub’s enabled support or booking channels, delivery status and timestamps. This draft does not authorize default recording of calls, microphones, camera feeds or in-vehicle audio or video. A rider may voluntarily submit relevant incident evidence. Any future recording feature requires separate review, notice and consent where required.
4 Information received from others
Authorized transportation providers may supply booking confirmations, driver or vehicle display information, trip progress, arrival and cancellation events, provider charges and relevant support or incident information. Payment processors may supply transaction tokens, limited method details, authorizations, settlement, refunds, disputes and fraud indicators. A maps provider may process addresses or coordinates to provide its enabled mapping service.
GOVX is the selected verifier for the planned military and veteran benefit. Commercial setup, approved fields, consent and production activation remain pending. An authorized verifier may provide eligibility and validity information under the final disclosed process. Cloud, messaging and support vendors may provide operational records needed for their contracted services. A booking account holder may provide the permitted guest’s name, contact and trip details. Others may provide evidence relevant to a safety report or dispute.
We do not propose buying consumer profiles from data brokers, inferring gender from names, obtaining employer account data merely from an email domain, or receiving credit-card spending histories unrelated to the RidezHub transaction. We validate authority and necessity before receiving personal information from an additional source.
5 Purposes of processing
We use the minimum information reasonably needed to create and secure accounts; display authorized provider options; submit and track selected bookings; calculate the disclosed RidezHub fee and approved discounts; facilitate approved payments; issue receipts; review arrival evidence, refunds and disputes; provide support; and maintain functioning apps and systems.
We use consent and enrollment records to honor messaging preferences and verify legal and safety acknowledgments. Program records support eligibility and the five-ride reward cycle without changing provider fare. Security and incident information supports fraud prevention, safety investigations and lawful account restrictions. Relevant financial and dispute records support accounting, tax, insurance, regulatory obligations and responses to valid legal process.
We may examine limited service performance information to resolve errors and improve usability. We prefer aggregate or properly deidentified reporting. We will not attempt to reidentify information maintained as deidentified and will impose appropriate restrictions on recipients. Aggregated information is not automatically anonymous if individuals remain reasonably identifiable.
The proposed model does not use personal information for third-party targeted advertising, political outreach, unrelated consumer profiling or training general-purpose AI models. It does not sell personal information or share it for cross-context behavioral advertising. These commitments require verification of vendor contracts, SDKs, analytics and actual data flows before publication; disclosure to an independent vendor must be assessed under the applicable statutory definitions.
6 Automated booking pricing and security
RidezHub may automatically retrieve authorized provider options, apply the flat $3.99 fee and approved discounts, update qualifying ride counters, validate booking events and reject duplicate payment or refund events. The selected transportation provider performs driver matching and sets its fare under its own practices. RidezHub does not represent that it operates Uber’s matching or surge-pricing algorithms.
Reasonable security rules may flag unusual login or payment activity and temporarily restrict an action pending review. You can contact the privacy/support address for a review of an incorrect restriction. This model does not propose profiling to make decisions with legal or similarly significant effects. Any feature that qualifies as regulated automated decision-making must be assessed and separately disclosed with legally required rights before implementation.
7 Disclosures and recipients
Selected transportation provider: necessary rider or permitted guest identity/contact details, pickup and destination, requested timing, selected service and relevant assistance instructions. Providers may pass necessary details to their assigned driver or vehicle operator. We do not send your RidezHub password, complete payment credentials, military documents or unrelated trip history to a driver.
Payment processors: booking payment and limited billing information necessary to authorize charges, settle approved transactions, prevent payment fraud, process refunds and resolve disputes. An integration does not authorize RidezHub to collect provider fares without an approved commercial and funds-flow arrangement.
Operational service providers: cloud/database hosting, maps, transactional email, optional SMS, security, support and approved verification vendors receive only information appropriate for the contracted task. Contracts and access controls must restrict use as applicable. Independent providers may have separate obligations; a contract label alone does not determine their legal role.
Booking account holders and people you choose: if authorized guest booking is offered, its account holder receives the booking and payment information needed to manage the ride. The guest must be informed of this sharing. Any future trip-sharing feature must identify the chosen recipient and information disclosed before activation. There is no automatic sharing of rides with an employer, family group or referring person.
Legal, safety and professional recipients: we may disclose relevant information to authorized legal/accounting advisers, insurers for an actual claim, or authorities when required or otherwise permitted by law, including an imminent safety emergency. We evaluate requests for authority and scope. RidezHub does not promise automatic emergency dispatch or transmit every ride to police. Call 911 for an emergency.
Business transition: a legitimate business sale or restructuring may require limited confidential disclosures to advisers or a prospective successor, subject to appropriate safeguards and applicable law. We will provide required notice of a material change in control or privacy practices. This clause does not grant unrestricted resale rights in rider data.
8 Optional messages cookies and permissions
If enabled, RidezHub ride update texts require a separate, initially unchecked opt-in on the Review your ride screen. Consent is not required to book. You may opt out through available preferences or reply STOP; HELP provides assistance. Message frequency varies by ride activity, and message and data rates may apply. Any RidezHub notification charge is disclosed separately before opt-in and payment, with the resulting fee and total shown. Consent, revocation and delivery records are retained as necessary to administer the program and prove compliance. A guest’s required messaging consent cannot be supplied merely by an account holder accepting the privacy notice.
RidezHub does not sell or disclose telephone numbers, SMS opt-in data or consent records to third parties for their own marketing. Contracted messaging providers may process this information solely to deliver and administer RidezHub messages and for legally required purposes. Provider-generated texts are governed by the provider’s practices.
Marketing email or push notifications, if introduced, will have appropriate choices; marketing SMS requires separate consent where required. Essential account, policy and receipt notices may still be delivered through email or the app. Device settings control push, location and other permissions. Refusing an optional permission does not automatically remove the right to book.
Essential cookies or similar storage may maintain sessions, authenticate users, protect accounts and remember settings. Any nonessential analytics require a documented vendor review and appropriate consent or choices before deployment. This draft does not authorize advertising pixels, cross-site tracking or sale/sharing through SDKs. Browser controls can remove cookies but may affect sign-in. Applicable universal opt-out signals, including Global Privacy Control where required, must be honored for processing they cover. We do not claim every browser signal controls all operational data processing.
9 Retention deletion and security
We keep identifiable information only as reasonably necessary for the disclosed purpose or a valid legal obligation. Account records support an active account. Trip and charge records support booking, fee/refund verification and necessary tax or dispute records. Precise device-location samples and diagnostics should have shorter operational retention rather than being kept indefinitely merely because the account remains open. Consent and safety acknowledgment records are retained for applicable compliance needs.
After a deletion request, we verify authority, remove information no longer needed and instruct contracted processors as required. Limited records may remain for tax obligations, actual disputes, legal holds or a necessary and proportionate fraud/security restriction. We explain applicable exceptions; an outstanding issue is not a justification to keep all account data indefinitely. The approved backup schedule must provide for controlled expiry and restricted ordinary access. If backups are restored, applicable deletion instructions must be reapplied. [IMPLEMENTATION CHECK — backup expiry and deletion enforcement have not been verified by this review.]
A category-specific retention and backup schedule must be approved before publication; no seven-year blanket period or guaranteed 90-day erasure is asserted by this draft. The final notice must state retention periods or meaningful criteria required by applicable law and reflect actual deletion capabilities. Independent transportation providers retain their own records under their notices; deleting RidezHub data does not automatically delete provider accounts.
[DECISION REQUIRED — approve retention periods or specific criteria for each data category and test deletion, processor requests and backup handling. A general promise to delete is not evidence that these procedures already exist.]
Reasonable safeguards must be implemented, including appropriate access restrictions, protected credentials, encryption suitable to the data and system, secure provider credentials and incident response. Access to precise location, payment-related records and sensitive information is limited by role and purpose. No system is perfectly secure. RidezHub will provide legally required breach notices. This draft is not a certification that production safeguards have been tested.
10 Privacy choices and requests
Email pablo.otero@ridezhub.com with the subject “RidezHub Privacy Request.” State whether you seek access/a copy, correction, deletion, a consent withdrawal, a covered processing opt-out or review of a decision. You may submit a request without a RidezHub account, including as a guest. Provide only enough information to locate your record; do not send a password, complete payment credentials or identity documents unless a justified secure verification process is separately arranged.
We verify access, correction and deletion requests proportionately to the risk and applicable law, may seek limited confirmation, and explain a denial or exception. Authorized agents may submit requests where permitted; reasonable proof of authority may be required. We will not unlawfully penalize you for exercising privacy rights. Removing information essential to a requested service may prevent that service, but unrelated optional data uses are not a condition of booking.
We respond within applicable legal deadlines and notify you of a permitted extension and its reason. Where the Texas Data Privacy and Security Act applies, the ordinary response period is 45 days, with an additional 45 days when legally justified and timely explained. Other states may require different procedures or deadlines. Requests are generally free, subject only to legally permitted exceptions.
If your request is denied, email the same address with “RidezHub Privacy Appeal,” the request reference and your reason for appeal. We provide a written review and the applicable regulator complaint route, including the Texas Attorney General for covered Texas matters. Where the Texas Data Privacy and Security Act applies, we provide the written appeal decision and reasons within 60 days after receipt. If the appeal is denied, we provide the Texas Attorney General’s online complaint mechanism. Other applicable state requirements remain preserved. A finalized appeal workflow and any additional legally required request channels must be in place before release.
11 United States state rights and sensitive information
Depending on residence and whether a law applies to RidezHub, you may have rights to know/access personal information, obtain a portable copy, correct errors, request deletion, opt out of sale or covered targeted advertising, limit certain sensitive-information uses, or opt out of covered profiling/automated decisions. Rights and exceptions differ by state. This notice does not require arbitration of regulator complaints or waive privacy rights.
For covered Texas consumers, the request and appeal process above applies. Precise location is treated as sensitive information where law requires. Required consent must be obtained before sensitive processing; device permission alone is not automatically sufficient for every statutory requirement. RidezHub’s size and statutory exemptions must be evaluated rather than assumed.
For covered California consumers, the categories, sources, purposes and recipients described above form the basis of the notice at collection. You may request applicable access, correction, deletion, sale/sharing opt-out and sensitive-use limitations without unlawful discrimination. We do not propose selling personal information or sharing it for cross-context behavioral advertising, including information about minors. If any such practice is introduced, the required notices, links and signal handling must be operational first.
The proposed military/veteran benefit uses verified eligibility and qualifying completed ride records to administer a discount. At the current $3.99 fee, approved discounts produce $3.59 on qualifying rides 1–4 and $3.19 on ride 5 before applicable taxes. It is not represented as payment for selling your data. You may decline enrollment or withdraw optional verification consent, which can prevent future eligibility verification. Counsel must determine whether a financial incentive notice or other program-specific disclosure is required before enrollment; such a notice must describe the actual data practices and valuation if applicable.
12 Adults children and future features
RidezHub accounts are for adults 18 or older. This draft does not offer teen accounts or unaccompanied-minor booking and is not directed to children under 13. Where minors accompany an adult, collect no unnecessary child-specific identifiers. If RidezHub learns that child information was collected in circumstances requiring protections under law, it will restrict further processing and take appropriate deletion or other required action. Contact the privacy address with concerns.
No biometric identity checks, facial recognition, autonomous-vehicle cabin recordings, stored-value wallet, cryptocurrency, medical transport program or general-purpose AI training is authorized by this notice. If a relevant new feature is later proposed, its data practices need separate verification, legal review and notice/consent before launch. Transportation providers may have their own recordings and practices, which must not be misrepresented as RidezHub’s collection.
13 Updates and contact
We date and version material changes and notify affected users in advance where required, through email or the app. A notice describes practices; continued use does not automatically supply a consent that law requires to be affirmative or separate. We obtain any required fresh consent before a materially different use of previously collected information. Privacy questions and requests may be sent to pablo.otero@ridezhub.com. Final operator details and request channels must be verified before publication.
Review memorandum for the founder and attorney
Internal appendix only — not part of the published rider privacy notice. The source was the Uber privacy notice pasted in this conversation, with no verified effective date. This is original RidezHub language rather than a substitution of company names. It reflects the available RidezHub checklist and the founder’s $3.99 fee instruction; it does not establish live implementation or update historical project archives.
What was removed and why
Removed all foreign-country lists, foreign controller entities, overseas DPO contacts, GDPR legal-basis charts, international certification claims and global service language. Also removed food and retail delivery, freight, restaurants, alcohol and other restricted goods, rentals, bikes/scooters, loyalty cards, employer/family/teen accounts, referral data, public merchant reviews and Uber-specific navigation paths.
Removed broad advertising audiences, data reseller enrichment, inferred gender, biometric selfies, default recordings, provider matching guarantees, political messages and AI model training. These activities are not established RidezHub functions. The draft retains only the relevant booking, payment, maps, security, support, eligibility, consent and legal-record functions, with optional guest booking conditional on authorization.
Required verification before publication
Identify the operator and notice address. Inventory actual fields, cookies, SDKs, diagnostic logs, OAuth scopes and provider webhook payloads. Confirm provider agreements and data rights. Name actual payment, cloud, map, email, SMS, support and verification vendors in the final vendor disclosures as appropriate; sandbox use of Stripe and selection of GOVX with commercial setup pending do not establish approved production arrangements.
Development inventory to verify: Namecheap/cPanel hosting is shown in the project setup; Stripe sandbox checkout has been demonstrated; inspected local code contains Resend password-reset email delivery; the RidezHub support mailbox uses Google Workspace. Confirm the actual deployment, data sent to each service, contractual role, subprocessors, access locations and retention before converting this inventory into public vendor disclosures. No SMS or military-verification production provider is confirmed by this review.
Validate all no-sale/no-sharing, no-ad-tracking and no-AI-training commitments against contracts and vendor defaults. Confirm precise location consent, stopping collection, manual address entry, sensitive assistance data and revocation. Validate that full card details do not enter RidezHub logs or databases and eligibility documents remain with the approved verifier where intended. Confirm whether U.S.-only hosting/access is actually required and configured; U.S.-only operations are a separate issue.
Approve actual retention periods by category, backup expiry and deletion mechanisms, legal hold controls, security assessments and response ownership. Publish truthful notices at or before collection; do not use this draft’s unresolved retention statements as a substitute for a final policy. Establish rights verification, agent handling, regulator escalation, state deadlines and appeal procedures. Add a toll-free or other request method where applicable law requires it; do not invent a phone number or privacy center.
[RETENTION DECISIONS REQUIRED] Account and authentication records: approve the active-account and post-closure rule, including credential removal. Trip, charge and refund records: identify the applicable tax, accounting and dispute basis and duration. Precise location, quotes and diagnostic/security logs: set the shortest justified operational or security period. Support and safety reports: set a case-based period and narrowly scoped legal holds.
Consent and acknowledgment records: set a justified compliance-evidence period and restrict reuse. Eligibility results and reward records: set the enrollment, withdrawal and dispute rules; do not collect identity documents merely to populate this draft. Backups: approve the rotation/expiry period, access restriction and reapplication of deletion after restoration. For every category, record the data owner, deletion trigger, maximum period or meaningful criteria, vendor handling and a tested deletion method.
[REQUEST WORKFLOW REQUIRED] Assign the monitored RidezHub mailbox and a responsible reviewer; log requests and deadlines, use proportionate identity verification, coordinate with vendors, document exceptions and provide appeals. Determine whether additional request methods are legally required for the actual service. Do not represent email alone as universally sufficient or invent a toll-free number.
Determine which U.S. state laws apply based on consumers, business size, processing and exemptions, including Texas and California. Review precise geolocation and accessibility data as sensitive, children’s information, reward/financial incentive disclosures, provider recordings and any future automated decision-making. Complete applicable data assessments and processor contracts. A national expansion requires a wider state-law review than the examples in this document.
Publication and versioning note: this comparison edits Word drafts only. It does not add a privacy page, alter consent controls, implement deletion or change a vendor contract. Publish the approved notice at or before applicable collection; keep a dated archive. A privacy acknowledgment is not blanket consent. Keep this internal appendix and the review annotations out of the future public notice.
SMS implementation note: keep authentication messages, optional ride updates and any future marketing consent separate. Confirm the provider, delivery and opt-out controls, costs and pre-payment disclosures before enabling texts. The prior branding instruction “Thank You for Riding with RidezHub” remains an internal implementation preference wherever legally and technically permitted; required carrier and legal content takes precedence.
Revision summary: replaced the personal contact with the RidezHub mailbox; addressed real data during sandbox use; clarified acknowledgment records and optional phone-code authentication; made SMS conditional; qualified the unselected verification vendor; added the covered Texas appeal deadline and explicit retention, deletion and vendor checks. No production capability or compliance certification is asserted.
Official sources checked on October 2 2026
Texas Attorney General, Texas Data Privacy and Security Act: https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint/consumer-privacy-rights/texas-data-privacy-and-security-act. Supports Texas rights, sensitive data handling, request deadlines and applicability review.
Additional source checked October 3, 2026: Texas Business and Commerce Code Sections 541.052–541.055, especially the 60-day appeal-response rule in Section 541.053(c) and complaint mechanism in Section 541.053(d): https://tcss.legis.texas.gov/resources/BC/htm/BC.541.htm. Applicability remains subject to review.
California Attorney General, California Consumer Privacy Act: https://oag.ca.gov/privacy/ccpa. Supports covered consumers’ rights, notice at collection, sale/sharing choices and sensitive-information limitations. California Privacy Protection Agency resources: https://cppa.ca.gov/faq.html. Applicability and current implementing requirements must be confirmed for the actual launch.
Federal Trade Commission, Children’s Online Privacy Protection Rule: https://www.ftc.gov/legal-library/browse/rules/childrens-online-privacy-protection-rule-coppa. Supports review of child-directed services and actual knowledge of collection from children under 13. Adult eligibility language alone does not resolve all children’s privacy duties.
Prepared for Pablo A. Otero III. This package is a review draft, not a legal opinion, privacy compliance certification, approved vendor agreement or authorization for a public launch.
October 4 San Antonio-first review
The RidezHub LLC is not yet established. Texas Veterans Two-Step correspondence asks the founder to obtain the official Texas Veterans Commission Veteran Verification Letter directly and forward it for the filing process. That letter has been requested, but receipt and LLC filing are not confirmed in the supplied record. A VA benefits/service summary is a different document and must not be represented as the requested TVC letter. Do not publish final legal notices or identify an unformed LLC as the contracting party.
San Antonio is the intended initial operating market. U.S. state-rights provisions remain conditional on applicability and are not a claim of a national rollout. Verify the actual vendor and data inventory before publication; business-document updates do not implement privacy controls.
October 10 review requirements
Business-information review October 10, 2026. Review preview for Pablo A. Otero III. San Antonio is the intended first market. RidezHub remains under development and in sandbox testing. Entity formation, the requested TVC letter response, provider authorization and legal publication remain pending in the reviewed records. No new email review or live launch is claimed. Blue text includes prior revisions and October 10 updates; the October 4 originals preserve prior comparisons.
RidezHub separately sells its own service through standard Stripe Payments. The transportation provider independently collects its fare and handles its fare refunds. A RidezHub payment does not settle the provider fare. Connect is a conditional future alternative only if executed provider agreements and approved operations require it.
Approved processing payer: the rider pays the permitted processing charge separately, preserving RidezHub’s service fee. Absorbing processing is a sensitivity comparison only. No exact rider processing amount is approved by this review.
The base RidezHub fee remains $3.99 before an eligible discount and applicable tax. Rider-paid processing is desired but remains subject to Stripe, card-network and legal confirmation. No universal flat processing fee or $4.42 price is approved. Card brand and wallet name do not identify credit, debit or prepaid funding. Unknown funding must not receive a credit-card surcharge.
GOVX is the selected military and veteran verification vendor. Commercial setup, approved data fields, consent and production activation remain pending. SheerID was declined. No live verification or provider endorsement is asserted.
Optional passkeys support device fingerprint, face recognition or screen lock through the credential provider. RidezHub stores the credential identifier, public key, associated account identifier, counter, transports, creation time and last-use time. It does not receive the phone fingerprint or face image through this flow. Staging and production relying-party domains require separately valid credentials. Passkey enrollment does not accept revised terms or enroll the rider in SMS.
Implementation review updated October 10, 2026: the current local checkout has separate, initially unchecked Terms and safety controls. The local server defaults to terms-draft-2026-10-10 and safety-draft-2026-10-10. This records the current local implementation, not legal approval or verification of the new-domain deployment. These review documents do not create a new acceptance or change historical records.