Privacy
隱私權政策
生效日:2026 年 8 月 25 日
1本政策的適用範圍
本隱私權政策說明出車寶 MeterGo 行動應用程式(下稱「本 App」)及其相關雲端服務如何蒐集、處理、利用與保護你的資料。使用本 App 即表示你已閱讀並同意本政策。本政策不適用於車行(車隊)自行對其司機所為的資料處理——該部分由車行擔任資料控管者。
2我們蒐集與處理的資料
儲存在你裝置上的資料
- 行程紀錄:起訖時間、里程、延滯秒數、車資分項與實收、乘客人數、當時費率方案的快照。
- 行駛軌跡:抽稀後的座標點,用於在地圖上回看路線。
- 費率方案:你自訂的包車價、機場價等。
- 進行中的跳錶快照:約每 5 秒寫入一次,供 App 被系統結束後自動續錶。
- 偏好設定:錶面配色、語言、日間模式、進位方式等。
備份到伺服器的資料
- 行程紀錄與軌跡、費率方案(即上列前三項),詳見第 4 節。
- 裝置配對資訊:配對碼與上傳憑證(由伺服器產生,不含姓名、電話等個人資訊)、裝置平台與 App 版本。
- 手機號碼:僅在你選擇於「設定 → 帳號」綁定手機號(用於換機取回紀錄),或建立車隊、成為車隊管理者時,用於身分驗證(見第 5 節)。不綁定亦可完整使用計費功能。
我們不蒐集姓名、身分證件、通訊錄、相簿或廣告識別碼。
3位置資料
定位是計程車跳錶的核心:里程與低速等待計時都由它計算。
- 只在跳錶期間取用。未開錶時,本 App 不存取你的位置。
- 背景定位:跳錶中切至背景或鎖屏仍需持續定位,否則錶會停。iOS 會顯示系統定位指示,Android 會顯示常駐通知,讓你隨時知道定位進行中。
- 用途限定:軌跡座標只用於計費、里程校正與行程備份(見第 4 節),不作其他用途。
- 地址顯示:行程起訖點地址由作業系統內建的地理編碼服務將座標轉為文字(iOS 由 Apple 處理、Android 由 Google 處理),適用其各自的隱私政策。
4網路傳輸與雲端備份
本 App 在下列三種情況與我們的伺服器通訊:
① 測速照相資料更新
測速照相點來自政府開放資料,App 內建一份並定期向伺服器比對版本。此請求只送出資料版本編號,不含位置與行程;測速提醒永遠在你的裝置上判定。
② 雲端備份(出車寶服務的一部分)
首次啟動時,裝置會向伺服器註冊並領取一組配對碼與上傳憑證(由伺服器產生,不含任何個人資訊)。此後行程紀錄與費率方案會自動備份至伺服器,重裝或換機時可憑同一憑證取回。備份請求會附帶裝置平台與 App 版本,用於相容性判斷。
已備份的資料可依第 8 節請求刪除。
③ 路網里程校正
跳錶中,App 會將最近一段行駛軌跡送至我們的伺服器,由伺服器代為呼叫 Google 路網服務,將軌跡吸附至實際道路以校正里程。API 金鑰保存在伺服器端。網路不可用或伺服器未回應時,自動改用裝置本機計算值,計費不中斷。
5車隊功能
車隊為選配功能:你輸入車行提供的邀請碼提出申請、經車行核准後生效。
- 金額是否共享,由你決定。共享等級選「趟數與里程」時,車行後台看不到任何金額——欄位顯示「未共享」而非 0;選「連金額」才會顯示實收。
- 車行可見範圍:你在隊期間的行程趟數、里程、時間,以及你在裝置上設定的備註名稱。
- 一台裝置同一時間只屬於一支車隊。你可隨時退出;退出後之後的行程不再共享給該車行,既有紀錄仍保留在你的 App 中。
- 手機驗證:建立車隊(成為管理者)需以手機號碼完成驗證,驗證由 Google Firebase Authentication 執行,適用 Google 的隱私政策;本 App 僅保存驗證後的號碼作為管理者帳號識別。
6裝置憑證與鑰匙圈
上傳憑證除一般儲存外,另存一份於 iOS 鑰匙圈(Keychain)。這是刻意設計:鑰匙圈不隨刪除 App 而消失,重裝後才能識別回同一台裝置、取回你的歷史紀錄;否則伺服器將視之為一台全新的裝置,歷史紀錄無法自動接回。Android 的金鑰庫隨 App 刪除而清除,重裝後無法自動識別。
7資料安全
- App 與伺服器間的所有傳輸均以 HTTPS(TLS)加密。
- 上傳憑證以裝置安全儲存區(iOS Keychain/Android Keystore)保護。
- 伺服器存取採最小權限原則,僅限維運必要人員。
8資料保存與刪除
- 裝置本機資料:由你掌握,刪除 App 即一併刪除(iOS 鑰匙圈中的憑證除外,見第 6 節)。
- 伺服器上的備份:保存至你請求刪除為止。你可透過 App 內「設定 → 客服」(請求會自動附帶裝置識別資訊)或來信向我們請求刪除該裝置的行程與費率備份。
- 車隊關聯:退出車隊後,該車行即不再取得你之後的行程資料。
9第三方服務
- Google 路網服務:用於路網里程校正,由我們的伺服器代為呼叫(見第 4 節)。
- Google Firebase Authentication:僅用於手機號碼驗證(帳號綁定與車隊管理者,見第 5 節)。
- 作業系統地理編碼:座標轉地址(Apple/Google)。
- 系統語音合成:測速提醒使用裝置內建 TTS,於本機運作、不外送任何內容。
除上述服務外,本 App 不嵌入任何廣告 SDK、行為分析或追蹤工具,亦不會將你的資料販售或出租予任何第三方。
10你的權利
依中華民國《個人資料保護法》,你就我們保有之個人資料,得請求查詢、閱覽、製給複製本、補充或更正、停止蒐集處理利用,以及請求刪除。由於出車寶不強制使用帳號,我們以伺服器核發的裝置識別資訊作為身分核對依據;請求時建議透過 App 內「設定 → 客服」提出(會自動附帶該資訊),或來信由我們引導完成核對。
11未成年人
本 App 為職業駕駛工具,服務對象為成年使用者,不以未滿十八歲者為對象。
12政策修訂
我們可能因法令或功能調整修訂本政策,修訂後將更新本頁生效日;重大變更將於 App 內另行告知。
13聯絡我們
對本政策或資料處理有任何疑問、或欲行使第 10 節之權利,請經由 metergo.app/support 與我們聯繫。
Privacy
Privacy Policy
Effective date: August 25, 2026
1Scope of This Policy
This Privacy Policy describes how the MeterGo mobile application (the "App") and its companion cloud services collect, process, use, and protect your data. By using the App you acknowledge and agree to this Policy. It does not cover data processing carried out independently by a fleet operator toward its drivers — for that processing, the fleet operator acts as the data controller.
2Data We Collect and Process
Stored on your device
- Trip records: start/end times, distance, waiting time, fare breakdown and amount received, passenger count, and a snapshot of the fare profile in use.
- Route traces: simplified coordinate points used to review the route on a map.
- Fare profiles: your custom charter, airport, and other rates.
- In-progress meter snapshot: written about every 5 seconds so the meter can resume if the system terminates the App.
- Preferences: theme, language, day mode, rounding, and similar settings.
Backed up to our servers
- Trip records, route traces, and fare profiles (the first three items above) — see Section 4.
- Device pairing data: a pairing code and upload credential (generated server-side; they contain no name, phone number, or other personal details), plus device platform and App version.
- Phone number: only if you choose to link one under "Settings → Account" (to recover records on a new phone), or create a fleet and become its administrator, for identity verification (see Section 5). The metering features work fully without linking a number.
We do not collect names, government IDs, contacts, photos, or advertising identifiers.
3Location Data
Location is the heart of a taxi meter: distance and low-speed waiting time are both computed from it.
- Used only while the meter is running. When the meter is off, the App does not access your location.
- Background location: while metering, the App keeps using location in the background or with the screen locked — otherwise the meter would stop. iOS shows its system location indicator and Android shows a persistent notification, so you always know it is active.
- Purpose-bound: trace coordinates are used solely for fare computation, distance correction, and trip backup (see Section 4) — nothing else.
- Addresses: trip start/end addresses are produced by the operating system's built-in geocoding service (Apple on iOS, Google on Android), subject to their respective privacy policies.
4Network Transfers and Cloud Backup
The App communicates with our servers in exactly three situations:
① Speed-camera data updates
Speed-camera locations come from government open data. The App ships with a copy and periodically checks the server for a newer version. This request sends only the version number of the data you already have — no location, no trips. Camera alerts are always evaluated on your device.
② Cloud backup (part of the MeterGo service)
On first launch, the device registers with our server and receives a pairing code and an upload credential (generated server-side; they contain no personal details). Trip records and fare profiles are then backed up to the server automatically, and can be restored to the same device after a reinstall or to a new phone. Backup requests include the device platform and App version for compatibility purposes.
You can request deletion of backed-up data as described in Section 8.
③ Road-network distance correction
While metering, the App sends the most recent segment of the route trace to our server, which calls Google's road-network service on the App's behalf to snap the trace to actual roads and correct the measured distance. API keys stay on the server. If the network or server is unavailable, the App silently falls back to on-device computation and metering is never interrupted.
5Fleet Features
Fleets are optional: you apply by entering an invitation code from a fleet operator, and membership takes effect only after the operator approves it.
- You decide whether amounts are shared. At the "trips & distance" sharing level the fleet console sees no monetary amounts at all — fields read "not shared", not 0. Only the "including amounts" level reveals received fares.
- What the operator can see: your trip counts, distance, and times during your membership, and the display name you set on your device.
- One device belongs to at most one fleet at a time. You may leave at any time; trips after leaving are no longer shared, and your existing records remain in your own App.
- Phone verification: creating a fleet (becoming its administrator) requires phone-number verification, performed by Google Firebase Authentication under Google's privacy policy. The App stores the verified number only as the administrator account identifier.
6Device Credentials and the Keychain
In addition to regular storage, the upload credential is kept in the iOS Keychain. This is deliberate: the Keychain survives App deletion, so a reinstall can be recognized as the same device and recover your history — otherwise the server would treat it as a brand-new device and your history could not be reconnected automatically. On Android, the keystore is cleared when the App is deleted, so a reinstall cannot be automatically recognized.
7Data Security
- All traffic between the App and our servers is encrypted with HTTPS (TLS).
- Upload credentials are protected by the device's secure storage (iOS Keychain / Android Keystore).
- Server access follows the principle of least privilege and is limited to personnel required for operations.
8Retention and Deletion
- On-device data: under your control; deleting the App deletes it (except the Keychain credential — see Section 6).
- Server backups: retained until you request deletion. Request deletion of that device's trip and fare-profile backups via "Settings → Support" inside the App (the request automatically carries the device identification) or by email.
- Fleet association: after you leave a fleet, the operator no longer receives your subsequent trip data.
9Third-Party Services
- Google road-network service: used for distance correction, called by our server on the App's behalf (Section 4).
- Google Firebase Authentication: used only for phone-number verification (account linking and fleet administrators, Section 5).
- Operating-system geocoding: coordinates to addresses (Apple / Google).
- System text-to-speech: camera alerts use the device's built-in TTS, which runs locally and sends nothing off the device.
Beyond the services listed above, the App embeds no advertising SDKs, no behavioral analytics, and no tracking tools, and we never sell or rent your data to anyone.
10Your Rights
Under Taiwan's Personal Data Protection Act, you may request access to, a copy of, supplementation or correction of, cessation of the collection, processing, or use of, and deletion of the personal data we hold about you. Because MeterGo does not require a user account, we verify requests using the server-issued device identification; the easiest way is to submit the request via "Settings → Support" inside the App (it carries that identification automatically), or email us and we will guide you through verification.
11Children
The App is a tool for professional drivers, intended for adult users. It is not directed at anyone under 18.
12Changes to This Policy
We may revise this Policy to reflect legal or product changes, updating the effective date above. Material changes will additionally be announced in the App.
13Contact Us
For questions about this Policy or our data practices, or to exercise the rights in Section 10, contact us via metergo.app/support.