Effective August 4, 2026
1. Summary
Hako Systems, Inc. (“Hako,” “we,” “us,” or “our”) provides the CheckCheckRide iPhone application and this website. CheckCheckRide does not require a Hako account. If you choose to connect a supported ride-provider account, sign-in occurs on that provider’s controlled authorization screen; CheckCheckRide does not ask for or receive your provider password or multi-factor authentication code.
The short version: product analytics begin when you use the app and cannot be turned off in CheckCheckRide. We associate events with a random installation ID, retain raw events indefinitely, and let authorized Hako administrators review an installation’s event history. We do not sell this information or track you across other companies’ apps or websites.
2. Information stored on your device
CheckCheckRide stores information needed to provide its features:
- opaque tokens representing apps chosen through Apple’s Screen Time picker;
- Screen Time and notification authorization states and one-hour unlock state;
- onboarding answers used for the illustrative savings estimate;
- provider-issued OAuth access and refresh tokens in the iPhone Keychain, plus provider profile, quote, and ride-history data needed to display connected features;
- an on-device counter of successful reminder continues used to show estimated ride and savings progress;
- the state needed by Screen Time extensions to show, remove, and restore the reminder; and
- a random analytics installation ID, a server-issued upload credential, app and device context, and a SQLite queue of events awaiting delivery.
The app and extensions coordinate through CheckCheckRide’s private Apple App Group. Successfully delivered events leave the queue. Undelivered events remain queued subject to a 5,000-event device safety limit.
Initial Uber authorization is exchanged by the Uber SDK on the device. When an Uber session expires, the app sends its provider-issued refresh token to Hako’s narrowly scoped refresh endpoint. For Lyft, the app sends a one-use authorization code or provider refresh token to a separate narrowly scoped endpoint. These endpoints use Hako’s server-side provider client secrets, return the provider token response to the app over HTTPS, and are designed not to store or log provider authorization codes or tokens. A short-lived, one-way digest derived from the request IP address is stored for abuse prevention.
3. Always-on first-party analytics
Analytics are part of CheckCheckRide and begin on first use. The app does not show an analytics consent prompt, provide an analytics switch, or support an in-app analytics opt-out.
We may collect:
- a random installation UUID; uninstalling and reinstalling normally creates a new UUID;
- iPhone hardware model, iOS version, CheckCheckRide version and build, language, region, time zone, and time-zone offset;
- raw IP address and IP-derived city, region, country, and continent supplied with analytics API requests;
- first open, app sessions, onboarding steps viewed and completed, revisits, onboarding completion, and time spent on each step;
- rideshare start year, normalized one-way rides per month, and the number of private Screen Time application tokens selected;
- notification and Screen Time permission prompts, outcomes, and current authorization states;
- whether a shield action selected compare/unlock or close, plus local unlock, reminder scheduling, and shield restoration results; and
- bounded delivery-health information and event timestamps.
We use these records to measure audience size, onboarding drop-off, retention, permission behavior, feature use, reliability, and geographic product adoption. IP-derived geographic trends may inform where Hako markets or advertises CheckCheckRide. IP location is approximate and may reflect a carrier gateway, relay, or VPN.
The analytics system does not collect provider OAuth tokens, passwords, MFA codes, ride fares, routes, bookings, ride history, Screen Time token values, time spent in other apps, or the illustrative spend and savings amounts. We also do not collect most other onboarding question selections. The separate Uber and Lyft token exchanges described above process OAuth material in transit but are not analytics events.
4. Apple Screen Time and Family Controls
CheckCheckRide asks separately for individual authorization to Apple’s Screen Time and Family Controls features. You decide whether to grant that permission and which apps to select in Apple’s picker.
Apple normally gives CheckCheckRide opaque application tokens. The app can count and use those tokens to apply or remove a shield, but it does not transmit the token values or infer app identities from them. Names you explicitly choose or type during CheckCheckRide onboarding are separate analytics fields and are transmitted. CheckCheckRide does not receive your Screen Time history or what you view or enter inside another app.
5. Notifications and APNs tokens
CheckCheckRide asks separately for notification permission. Local reminders can be scheduled on your iPhone. When remote notification registration is active, Apple may provide an app-specific APNs token, which CheckCheckRide sends to Hako.
APNs tokens are stored in plaintext in the managed database so Hako can send notifications. They are kept in a separate table from raw events and are visible only within the password-protected installation detail dashboard. Invalid tokens are removed after their cleanup period. Notification permission can be changed in iOS Settings.
6. Sharing, sale, and tracking
Hako uses Vercel for web and API hosting and Neon for managed Postgres storage. Those providers process information for Hako to provide the service. Lyft and Uber process account authorization and ride-provider requests under their own privacy policies. We do not sell or rent analytics information, share it for cross-context behavioral advertising, use an advertising identifier, or combine it with third-party data to track you across apps or websites.
The app does not include a third-party advertising or analytics SDK. The individual and aggregate analytics dashboards are restricted to authorized Hako administrators.
7. Retention, controls, and deletion
Raw analytics events and installation records are retained indefinitely unless Hako deletes them or deletion is required by law. Aggregate summaries may also be kept indefinitely. Active APNs tokens are retained while needed; invalid tokens are periodically deleted.
CheckCheckRide Settings can reset local onboarding answers, selected Screen Time tokens, provider sessions, account-derived local data, unlock state, and shields. A local reset does not change the analytics installation UUID or delete its event history. You can revoke Screen Time or notification access in iOS Settings. Uninstalling removes local app data subject to Apple’s platform behavior and normally causes a later reinstall to create a new analytics installation.
Depending on where you live, applicable law may give you privacy rights. Because CheckCheckRide has no account and uses a random installation ID, Hako may need that ID or other information to locate a record. Contact us to make a legally applicable request.
8. Security
CheckCheckRide uses HTTPS in transit and device-only Keychain protection for provider-issued OAuth sessions. Registration uses the installation UUID to issue an installation-scoped bearer credential derived with a server-only secret. The API validates a fixed event catalog, limits request size and frequency, prevents one credential from writing for a different installation ID, and uses event UUIDs for idempotent retries. Administrator access is password-protected. No security measure is perfect.
9. This website
The public marketing and support pages do not set advertising cookies or use visitor analytics. The website hosts the private app analytics API and administrator dashboard described above. If you email us, we receive the address, message, and other information you choose to include and use it to respond.
10. Children
CheckCheckRide is not directed to children under 13, and we do not knowingly collect personal information from children. Contact us if you believe a child has provided information so we can investigate.
11. Changes to this policy
We may update this policy when CheckCheckRide’s features or legal obligations change. We will post the revised policy here and change the effective date.
12. Contact us
For privacy questions or requests, email Hako Systems, Inc. at developer@hako.systems.