Safra

Privacy — draft

LOCAL DRAFT — owner facts pending. This is not a final policy or a deletion-request channel.

Source-grounded draft, not a final policy or compliance statement. The owner supplied safra.sy as a website; no verified support/privacy receiver follows from that. UNRESOLVED: legal operator/developer, approved contact/hours, retention periods, legal bases, processor/location details, owner-controlled privacy/deletion URLs, child policy and store disclosures. Owner-approved facts and legal review are required before publication.

The current source handles account/authentication/profile/preferences, saved travelers, bookings, physical seats and tickets. The existing traveler snapshot includes name, traveler type/gender, calendar birth date, phone, identity and optional email. This draft does not authorize additional mandatory collection. Multi-seat bookings carry independent traveler snapshots. Cash due differs from funds received; a cash booking is not evidence of an electronic payment.

Source integrations include Firebase Authentication, Firestore, Cloud Functions, App Check, Crashlytics and Shorebird code updates. Actual delivery settings, storage regions, analytics consent/collection, retention and external flows require separate verification; an installed SDK alone does not prove each feature runs. Local tests do not prove FCM/SMS/email delivery.

Account-scoped local storage can retain journey/traveler/ticket information for recovery and offline display. The opaque QR is a sensitive ticket credential; sharing it may permit ticket use and should be limited to intended recipients. Authoritative validation checks current booking/ticket/role/company/trip. This is not a claim of offline cryptographic validation or live tracking.

The local proposed deletion flow requires recent authentication, records a server-private intent/retained write fence, clears five known subcollections in bounded work, removes the Auth account and anonymizes existing profile fields. Trusted resume is fault-tested. Historical booking, ticket, audit/accounting records are retained by this implementation. Their duration/exceptions, rights/request/complaint handling and real deletion contact are unresolved. New Functions/Rules are not deployed, so this cannot be described as proven production behavior.

Public discovery uses allowlisted trip data and omits private driver/account/audit/traveler information. Accepted local audit evidence covers tenant isolation of activity logs; cloud deployment and production runtime remain NOT VERIFIED by these local tests. Approve accurate permissions/notification/support/deletion policy, complete legal review and verify public links before publishing this draft.