Legal
Security.
How Urvo protects account and trip data, and how to report a vulnerability if you find one.
Effective 10 August 2026
Our approach
A ride-hailing marketplace holds information people care about: where they went, what they paid, and documents proving who they are. We treat that as the reason security has to be part of how the product is built rather than something added afterwards.
This page describes the practices we hold ourselves to. It is not a certification claim, and we will say so plainly here if and when we obtain a formal audit.
How we protect data
What we will never ask you for
Urvo will never ask for your password, a one-time verification code, or full card or bank details — not by phone, email, message or in person. Anyone asking for those is not Urvo, however convincing they sound.
If someone contacts you claiming to be Urvo and asks for any of the above, end the conversation and report it to us.
Keeping your account safe
Reporting a vulnerability
If you believe you have found a security vulnerability in Urvo, we want to hear about it. Report it privately through the Security reports channel on our contact page, with enough detail to reproduce the issue — the affected endpoint or screen, the steps you took, and what you observed.
Please give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly. We will acknowledge your report, keep you updated while we work on it, and confirm when it is resolved.
Testing responsibly
If you are researching in good faith and follow the guidance below, we will not pursue action against you for your research.
More from legal
