Confidential | Last Updated: March 9, 2026
Operated in Bangladesh | Effective Date: March 9, 2026 | Version 1.0
Trip24 is a technology-driven logistics platform operating in Bangladesh that connects cargo owners (customers) with truck owners and drivers through a transparent bidding and booking system. Trip24 is committed to safeguarding the personal information of all users who interact with our platform.
This Privacy Policy (“Policy”) describes in detail:
This Policy applies to all users of the Trip24 mobile application, website, APIs, and any related services (collectively, the “Services”). It governs data processed by Trip24 and its authorized data processors.
Trip24 operates in full recognition of the applicable legal framework in Bangladesh, including but not limited to: the Information and Communication Technology (ICT) Act, 2006 (as amended); the Digital Security Act (DSA), 2018; the Bangladesh Telecommunication Regulation Act, 2001; any forthcoming Personal Data Protection legislation in Bangladesh; and guidelines issued by the Bangladesh Telecommunication Regulatory Commission (BTRC).
Trip24 is a two-sided digital marketplace that facilitates the booking and management of freight transportation services across Bangladesh. The platform provides two distinct user roles:
Trip24 acts as an intermediary technology platform. We do not own or operate trucks ourselves. We provide the digital infrastructure, security framework, payment facilitation, and dispute resolution mechanisms to ensure safe and reliable logistics transactions between parties.
For the purposes of this Privacy Policy, the following definitions apply:
Trip24 practices “data minimisation” — we only collect data that is strictly necessary for the operation of our services, legal compliance, and user safety. Below is a comprehensive breakdown of every category of data we collect, the specific data points involved, and our lawful basis and purpose for collecting each.
Collected from: All users (Customers, Drivers, Vehicle Owners)
Why We Need This: Account data is required to create and maintain your Trip24 account, verify your identity, enable you to log in securely, and allow us to contact you for support, notifications, and service-related communications. This is the minimum necessary to operate any user account.
Collected from: Drivers and Vehicle Owners
Why We Need This: Identity verification is a legal and safety requirement. Trip24 is obligated to ensure that every driver operating on our platform is (a) a real, identifiable individual, (b) legally authorized to operate a motor vehicle under Bangladeshi law, and (c) not operating under a false identity. This protects customers’ goods and personal safety. Verified identities also enable law enforcement cooperation in the event of accidents, theft, or fraud.
Collected from: Drivers and Vehicle Owners
Why We Need This: Customers posting trip requests have specific transportation needs — certain cargo requires specific vehicle types, capacities, and compliance certificates. Vehicle documentation ensures our platform only facilitates legally roadworthy and appropriately insured vehicles. This protects customers’ cargo and ensures Trip24 does not facilitate illegal transport operations.
Collected from: All users
Why We Need This: Trip data is the operational core of the platform. It enables us to match drivers with customers, track ongoing deliveries, calculate distances and payments, resolve disputes, and maintain legally required records of commercial freight transactions.
Collected from: Drivers (during active trips); Customers (optional, for pickup coordination)
Why We Need This: Location data is detailed in Section 5 of this Policy. In summary, it powers live trip tracking, driver-trip matching, ETA calculations, safety monitoring, and dispute resolution. Location collection begins only when a trip is active and stops upon trip completion.
Collected from: All users
Why We Need This: Payment data enables us to process trip fees, disburse earnings to drivers and vehicle owners, issue refunds, generate invoices, and maintain financial audit trails required by Bangladeshi commercial and tax regulations (including the Income Tax Ordinance, 1984 and the VAT Act, 2012 where applicable).
Collected from: All users
Why We Need This: Communication records enable our support team to resolve disputes, mediate disagreements between parties, and investigate complaints. In-app communications also protect users’ personal phone numbers from being shared directly.
Collected from: All users (automatically)
Why We Need This: Technical data allows us to diagnose bugs, improve app performance, ensure compatibility across devices, detect fraudulent activity (e.g., multiple accounts from one device), and enhance the overall user experience.
Collected from: All users
Why We Need This: Ratings and reviews maintain platform quality and trust. They allow customers to make informed decisions when selecting drivers and incentivise all parties to maintain high service standards.
Location access is one of the most sensitive permissions a mobile application can request. Trip24 takes this responsibility seriously and only accesses location data when there is a clear, necessary, and proportionate reason to do so.
Driver location is accessed only when the driver is logged in and has an active trip in progress. Location collection pauses automatically when a trip is completed or cancelled. Background location (when the app is not open) may be used for drivers with an active trip to ensure continuous tracking. Customer location is requested optionally to auto-fill the pickup address. Customers can manually enter their address without granting location permission.
When a driver opens the app and browses available trips, we use their location to prioritise and surface nearby trip postings. This reduces empty miles, saves fuel, and enables faster response times for customers.
Once a trip begins, customers can track the precise real-time location of their goods on a live map. This provides peace of mind, allows for coordination at the delivery point, and reduces customer anxiety about cargo safety.
GPS data combined with road network data allows Trip24 to compute accurate ETAs for deliveries. This helps customers plan their operations and allows drivers to communicate realistic timelines.
The GPS route log of a completed trip is preserved as a tamper-resistant record. In the event of a dispute (e.g., a driver claiming they completed a delivery while a customer claims they did not), the stored route data provides objective evidence.
In the event of an accident, breakdown, or emergency, the last known GPS location of the driver is available to our safety team and, where legally required, to law enforcement. This can be critical in facilitating rapid emergency response.
Trip24 uses geofencing technology to automatically detect and confirm when a driver arrives at the pickup location and when they arrive at the drop-off point. This creates automatic, verifiable timestamps for billing and legal record purposes.
Location data helps Trip24 identify anomalous patterns that may indicate GPS spoofing, fake trip completions, or other fraudulent activities. This protects the financial interests of both customers and honest drivers.
The protection of sensitive personal data is the highest-priority security obligation for Trip24. We implement a multi-layered security architecture that combines technical, administrative, and physical safeguards.
Trip24 classifies all data into the following tiers:
Each tier is subject to progressively elevated access controls, encryption standards, and audit requirements.
All data transmitted between the Trip24 app and our servers is encrypted using TLS 1.2 or TLS 1.3 — the industry-standard encryption protocol. Certificate pinning is implemented in the mobile app to prevent man-in-the-middle attacks. All API endpoints are served exclusively over HTTPS. Unencrypted HTTP connections are rejected.
All Tier 1 sensitive documents (NID, driving license, vehicle documents, selfies) are stored in encrypted object storage using AES-256 encryption. Database fields containing personal identifiers (phone numbers, NID numbers) are encrypted at the column level. Encryption keys are managed separately from the encrypted data and are rotated periodically. Backups of sensitive data are also encrypted with separate keys.
Role-Based Access Control (RBAC) is enforced across all internal systems. An employee can only access the data necessary for their specific job function. Tier 1 sensitive documents are accessible only to the verification team and senior security personnel. General customer support agents cannot view NID images or license documents. All administrative access to sensitive data requires multi-factor authentication (MFA). Access sessions expire automatically after a period of inactivity. Third-party data processors are contractually prohibited from accessing data beyond the scope of their designated service.
These documents represent the most sensitive category of data on our platform. We apply the following specific measures:
Phone numbers are used as primary account identifiers but are not displayed publicly on the platform. When a customer needs to contact a driver (or vice versa), communications are routed through an in-app messaging or anonymised call relay system, preventing direct phone number disclosure. Email addresses are not publicly visible and are used only for account communications and support.
GPS data is streamed over encrypted channels (TLS 1.3). Historical GPS route data is retained only for the duration specified in Section 8 (Data Retention). Access to real-time GPS data is restricted to the active parties in a trip (the customer who booked and the driver who accepted). Historical GPS logs are accessible only to authorised internal personnel for dispute resolution and to law enforcement upon lawful request.
Trip24 maintains a formal Data Breach Incident Response Plan that includes:
All access to sensitive data is logged, including who accessed it, when, from which IP address, and what action was taken. Audit logs are immutable and stored separately from operational systems. Trip24 conducts regular internal security reviews and periodic third-party security audits. Penetration testing is performed at least annually on all critical systems.
Trip24 does not sell personal data. We do not permit advertisers to purchase user information. We share data only in the following circumstances:
When a customer posts a trip, their pickup and drop-off locations and cargo details are shared with drivers who are browsing available trips. When a driver’s bid is accepted, their name, phone number (via relay), vehicle type, and license plate are shared with the booking customer. Customer ratings and driver ratings are visible to relevant parties as part of the trust system.
Trip24 engages third-party service providers who process data on our behalf under strict data processing agreements (DPAs) that prohibit them from using the data for any purpose beyond the agreed service. These include:
Trip24 may disclose personal data when required to do so by law, including:
Trip24 will, to the extent permitted by law, notify affected users before complying with government data requests unless prohibited from doing so.
In the event of a merger, acquisition, corporate restructuring, or sale of Trip24 assets, personal data may be transferred to the acquiring entity. Users will be notified in advance of any such transfer, and the new entity will be required to honour this Privacy Policy or obtain fresh consent if material changes are made.
Trip24 retains personal data only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal obligations, and to resolve disputes. The following retention periods apply:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account registration data | Duration of account + 3 years after deletion | Legal obligation, dispute resolution |
| NID and Driving License documents | Duration of account + 5 years after deletion | Legal compliance, fraud prevention |
| Vehicle registration documents | Duration of vehicle registration on platform + 5 years | Legal compliance |
| Trip and booking records | 7 years from trip date | Commercial / tax / accounting law |
| Payment transaction records | 7 years from transaction date | Bangladesh tax and financial regulations |
| GPS location data (active trip) | 90 days after trip completion | Dispute resolution |
| In-app communications | 2 years from message date | Dispute resolution, safety |
| Device/analytics data | 12 months on a rolling basis | Performance optimisation |
| Ratings and reviews | For the lifetime of the account | Platform trust system |
After the applicable retention period expires, data is permanently and irreversibly deleted or anonymised so that it can no longer be linked to any individual. Deletion is performed using secure deletion methods that prevent recovery.
As a user of Trip24, you have the following rights with respect to your personal data. These rights are consistent with internationally recognised data protection standards and are upheld by Trip24 to the fullest extent practicable under Bangladeshi law.
To exercise any of these rights, please contact our Data Protection Officer at the contact details provided in Section 15.
The Trip24 mobile application does not use browser cookies. However, we use the following tracking technologies within the app:
We do not use any advertising tracking technologies, third-party advertising SDKs, or cross-app tracking mechanisms.
Trip24 is a commercial logistics platform intended exclusively for adults. Our Services are not directed at, and we do not knowingly collect personal data from, individuals under the age of 18.
By creating an account, you represent and warrant that you are at least 18 years of age and legally competent to enter into binding agreements under Bangladeshi law.
If we discover or are notified that we have collected personal data from a minor, we will immediately delete such data from our records. If you believe a minor has registered on Trip24, please contact us immediately at the details in Section 15.
Trip24 integrates with certain third-party services to deliver its core functionality. These services have their own privacy policies, and we encourage users to review them:
Trip24 is not responsible for the privacy practices of third-party services. We select partners who meet our security standards and are bound by contractual data protection obligations.
Trip24 reserves the right to update or modify this Privacy Policy at any time. When we make material changes, we will:
Your continued use of Trip24 after a Policy update constitutes your acceptance of the revised terms. If you do not agree with any changes, you must discontinue use of the platform and may request deletion of your account.
This Privacy Policy is governed by and construed in accordance with the laws of the People’s Republic of Bangladesh, including the Information and Communication Technology Act, 2006 and the Digital Security Act, 2018.
Any dispute arising from or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the competent courts of Bangladesh.
Trip24 is committed to resolving privacy complaints in a fair and transparent manner. We encourage users to contact us directly before escalating any dispute to regulatory authorities.
If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal data, please contact our Data Protection Officer:
Trip24 — Data Protection Officer
Email: privacy@trip24.com.bd
Phone: +880-XXXX-XXXXXX
Address: [Company Address], Dhaka, Bangladesh
Support Hours: Sunday – Thursday, 9:00 AM – 6:00 PM (BST)
Response Time: We aim to respond to all privacy-related inquiries within 3 business days. For formal data access or deletion requests, response time is within 30 days.
By using Trip24, you agree to this Privacy Policy.
Trip24 © 2026. All Rights Reserved. Operated in Bangladesh.