Privacy Policy

XVIA USA – Privacy Policy

Intended Audience: Customers, passengers, website/app users, and corporate travelers
Legal Entity: Elevate Mobility Group LLC d/b/a XVIA USA
Principal Business Address: 45 S Broadway, Yonkers, NY 10701
Effective Date: August 8, 2026

1. Information We Collect

XVIA USA (“XVIA,” “we,” “us,” or “our”) collects personal information that is reasonably necessary to provide, operate, secure, support, and improve our transportation services and platform. The information we collect depends on how you interact with XVIA.

Account and Contact Information

This may include your name, phone number, email address, account credentials, saved addresses, and other account information you provide.

Trip and Reservation Information

This may include pickup and drop-off locations, requested and completed trips, dates and times, stops, special instructions, flight information, assigned transportation provider or vehicle information, and other details needed to arrange or provide transportation.

Location Information

XVIA may collect precise or approximate location information when needed for transportation, routing, pickup coordination, safety, fraud prevention, or location-based features, subject to device permissions and any notice or consent required by applicable law.

Payment and Transaction Information

This may include payment status, transaction history, billing information, payment tokens or processor identifiers, card brand/type, expiration information where provided by the processor, and the last four digits of a payment card.

XVIA does not directly store full payment-card numbers or card security codes in its own systems.

Device and Technical Information

This may include IP address, device type, operating system, app version, language, time zone, network information, identifiers used by the app or service, session/activity information, diagnostics, errors, crash reports, and performance information.

Communications and Support Information

This may include communications with XVIA, customer-support requests, trip-related communications, complaints, feedback, and information you voluntarily provide.

Corporate Travel Information

This may include information about the applicable corporate account, authorized booker or administrator, traveler, reservation, billing arrangement, and related business-travel records.

Other Information You Provide

This may include accommodation requests, photographs, documents, lost-property information, incident information, or other information you choose to submit.

XVIA does not intend to access device contacts, microphone recordings, government identification, advertising identifiers, or other sensitive device information unless a specific XVIA feature or legal/operational requirement makes that collection necessary. If XVIA begins collecting such information, it will provide any notice, permission request, or consent required by applicable law before or at the time of collection.

2. Location and Trip Information

XVIA may collect and use precise or approximate location information when reasonably necessary to provide, secure, and support transportation services. Collection may depend on the permissions selected on the user’s device and the features being used.

Location information may be used to:

  • Identify pickup and drop-off locations.

  • Calculate routes, distance, travel time, and estimated fares.

  • Coordinate pickups.

  • Provide trip status and transportation features.

  • Support passenger and provider safety.

  • Detect or prevent fraud and misuse.

  • Investigate complaints, incidents, payment disputes, or trip-related issues.

  • Maintain accurate transportation records.

Trip records may include requested and actual pickup/drop-off locations and times, routes, distance, duration, assigned provider and vehicle information, passenger information, flight details, stops, waiting time, tolls, airport or facility information, fares, payments, cancellations, no-shows, special instructions, trip-related communications, and customer-support records.

XVIA will not use precise location information for materially different purposes, including targeted advertising based on precise location, unless XVIA provides any notice, choice, or affirmative consent required by applicable law.

Location and trip information is retained only as long as reasonably necessary for the purposes described in this Policy, including service delivery, safety, fraud prevention, dispute resolution, insurance, accounting, recordkeeping, and legal or regulatory obligations.

3. Payments and Payment Information

Payments for XVIA services may be processed through authorized third-party payment processors. XVIA may use Adyen for payments processed through the XVIA platform and Square for certain invoices, manually initiated transactions, or other authorized payment arrangements, to the extent those processors are used in XVIA’s production services.

XVIA does not directly store full payment-card numbers or card security codes (CVV/CVC) in its own systems.

Payment credentials may be collected, processed, tokenized, and stored by authorized payment processors in accordance with their security practices and applicable payment-card standards.

XVIA may receive and retain limited payment and transaction information, such as payment tokens or processor identifiers, payment status, transaction amount, billing information, card brand/type, expiration information where supplied by the processor, last four digits, transaction history, and information necessary to administer payments and customer accounts.

This information may be used to:

  • Process fares and other authorized charges.

  • Maintain authorized payment methods.

  • Process refunds and credits.

  • Process cancellation/no-show charges.

  • Process cleaning or damage charges.

  • Process tolls and applicable fees.

  • Maintain accounting records.

  • Prevent or investigate fraud.

  • Resolve payment disputes or chargebacks.

  • Meet legal, tax, accounting, or regulatory obligations.

When a customer authorizes a payment method for future transactions, the payment processor may securely store or tokenize that method. XVIA may use the resulting token or processor identifier for future charges authorized by the customer or otherwise permitted under the applicable customer agreement.

Third-party payment processors handle payment information under their own terms, privacy policies, security practices, and applicable law.

XVIA may add or replace payment processors as its services evolve and will update this Policy when a change materially affects the privacy practices described here.

4. Device, Analytics, Diagnostics and Advertising

XVIA and authorized service providers may automatically collect device and usage information, including device type, operating system, app version, IP address, language, time zone, network information, app/service identifiers, session and activity information, interactions with the platform, diagnostics, errors, crash reports, and performance data.

XVIA may use this information to:

  • Operate and maintain the platform.

  • Authenticate users.

  • Protect security and integrity.

  • Prevent, detect, and investigate fraud or misuse.

  • Diagnose technical problems.

  • Analyze usage and performance.

  • Improve features.

  • Provide support.

  • Develop XVIA’s services.

XVIA may use analytics, attribution, marketing, advertising, or promotional service providers to understand how users discover and interact with XVIA and to measure campaigns.

XVIA will not represent that information is used only for service operations if it is also used for advertising or marketing. Where required, XVIA will provide appropriate notice, consent mechanisms, or privacy choices before collecting, using, or sharing information for advertising, attribution, or similar purposes.

Precise location information will not be shared for targeted advertising unless such processing is clearly disclosed and any legally required consent has been obtained.

XVIA may add, replace, or discontinue these providers. If a change materially alters the categories of information collected, purposes of use, or disclosures described in this Policy, XVIA will update this Policy and provide additional notice where required.

5. Mapping, Communications, Cloud and Other Service Providers

XVIA relies on third-party service providers and technology partners to operate, maintain, secure, and provide its services.

These may include:

  • Mapping and routing services.

  • Cloud and hosting providers.

  • Communications and notification providers.

  • Customer-support platforms.

  • Payment processors.

  • Fraud-prevention and security providers.

  • Identity-verification services.

  • Analytics and diagnostic providers.

  • Professional advisers.

  • Other vendors performing services for XVIA.

XVIA may provide these parties with personal information reasonably necessary for the applicable service, including account/contact information, trip/reservation information, location information, device/technical information, transaction information, communications, and other relevant information.

XVIA seeks to limit access to information reasonably appropriate for the service being performed and uses contractual, organizational, and technical controls appropriate to the vendor relationship.

Service providers processing personal information on XVIA’s behalf are expected to comply with applicable contractual obligations, security requirements, and law.

XVIA may change service providers as its technology and operations evolve. Material changes affecting the privacy practices described in this Policy will be reflected in an updated Policy where appropriate.

6. Drivers, Transportation Providers and Screening

XVIA collects and processes information relating to drivers, transportation providers, and applicants as reasonably necessary to evaluate eligibility, administer platform access or affiliation, meet legal/regulatory requirements, facilitate transportation services and payments, maintain safety/security, and operate the platform.

Information may include:

  • Identity and contact information.

  • Driver’s license and other identification information.

  • Transportation licenses and permits.

  • Vehicle and insurance information.

  • Photographs.

  • Driving records.

  • Background-screening information.

  • Tax/payment and payout information.

  • Trip/reservation and location information.

  • Platform activity.

  • Ratings and feedback.

  • Complaints and safety information.

  • Other information reasonably necessary for the provider relationship.

XVIA may obtain or verify information through governmental agencies, licensing authorities, insurance providers, screening or identity-verification providers, publicly available records, and other authorized sources, as permitted by law.

When a background check or other regulated screening process requires a separate disclosure, authorization, notice, or other procedure, XVIA will provide or obtain the applicable documentation separately from this Privacy Policy.

7. How We Disclose Information

XVIA may disclose personal information to service providers, contractors, processors, transportation providers, technology vendors, payment processors, mapping/location providers, communications providers, cloud providers, analytics providers, support providers, fraud-prevention providers, screening providers, professional advisers, insurers, and other parties when reasonably necessary for the purposes described in this Policy.

Providing access to information does not transfer ownership of XVIA customer information or give a recipient unrestricted authority to use it for unrelated purposes. Recipients are subject to applicable contractual restrictions, their independent legal obligations, or both.

XVIA may disclose information:

  • To an assigned transportation provider as needed to perform a trip.

  • To a corporate customer or authorized administrator for eligible corporate travel, administration, and billing.

  • To insurers or claims administrators in connection with incidents.

  • To courts, regulators, law enforcement, or governmental authorities when required or permitted by applicable law.

XVIA may preserve relevant records when reasonably necessary for safety, fraud prevention, disputes, litigation holds, insurance matters, regulatory compliance, or enforcement of agreements.

8. Data Retention

XVIA retains personal information only for as long as reasonably necessary for the purposes for which it was collected or otherwise lawfully processed, including providing services, completing transactions, maintaining trip and business records, safety and fraud prevention, resolving complaints or disputes, insurance matters, and legal, tax, accounting, regulatory, or contractual obligations.

Retention periods vary by information type and purpose.

When information is no longer reasonably necessary, XVIA will take reasonable steps to delete, de-identify, anonymize, or securely dispose of it, subject to applicable retention obligations, litigation holds, security needs, and other lawful exceptions.

9. Security

XVIA maintains reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, acquisition, loss, misuse, alteration, destruction, or disclosure.

Safeguards may include access controls, security monitoring, vendor-management practices, employee or contractor controls, and secure disposal practices appropriate to the nature of the information and XVIA’s operations.

No electronic transmission, storage system, or security measure can guarantee absolute security.

10. Privacy Rights and Choices

Depending on applicable law and the individual’s place of residence, a person may have rights concerning personal information, including rights to request access to, correction of, deletion of, or a copy of certain information, and other rights provided by applicable privacy laws.

XVIA will review and respond to valid privacy requests in accordance with applicable law and may take reasonable steps to verify the identity and authority of the requester before providing access to, correcting, or deleting information.

Where applicable, individuals may be permitted to use an authorized agent and may have a right to appeal certain decisions concerning privacy requests.

XVIA will not discriminate or retaliate against an individual for exercising a privacy right protected by applicable law. This statement concerns the exercise of privacy rights and is separate from XVIA’s broader nondiscrimination obligations.

Users may also manage certain device permissions, such as location permissions, through their device settings. Disabling a permission may affect features that depend on that information.

11. Children

XVIA accounts are intended for adults.

XVIA does not knowingly permit children to create individual customer accounts or knowingly collect personal information directly from children in a manner that would require parental consent under applicable law.

Transportation involving minors is subject to XVIA’s separate passenger and booking rules.

If XVIA learns that it collected personal information from a child in a manner inconsistent with applicable law, XVIA will take appropriate steps to address the information.

12. Changes to This Privacy Policy

XVIA may update this Privacy Policy to reflect changes in its services, technology, vendors, legal requirements, or privacy practices.

The effective date at the top of the Policy will be updated when a revised version takes effect.

XVIA will provide additional notice when required by applicable law or when a change materially affects how personal information is collected, used, or disclosed.

13. Contact

Privacy questions and requests may be submitted to Support@xvia.com until XVIA designates a dedicated privacy email address.

Requests should include sufficient information for XVIA to identify the account or information involved and understand the request.

Please do not send passwords, full payment-card numbers, or other unnecessary sensitive information by email.

Legal Notice Mailing Address:
411 Theodore Fremd Ave., STE 206
Rye, NY 10580