Vugo
Privacy Policy
Vugo, Inc. · 1161 Wayzata Blvd E, Suite 172, Wayzata, MN 55391 · privacy@govugo.com
1. What this policy covers
This policy explains what Vugo, Inc. (“Vugo“, “we”, “us”) collects, why, who receives it, and what choices you have.
It covers:
- www.govugo.com, our website;
- the Vugo advertiser portal, driver portal and fleet portal;
- the Vugo driver app;
- the screens Vugo places in vehicles; and
- vehicle wraps and the verification of them.
Different parts apply to different people. We have written it by who you are, so you can read only your part if you prefer:
| If you are | Read |
|---|---|
| A visitor to our website | Sections 3 and 9 |
| An advertiser or agency | Sections 4, 8, 9, 10 |
| A driver | Sections 5, 6, 8, 10 |
| A fleet operator | Sections 7, 8, 10 |
| A passenger in a vehicle carrying a Vugo screen | Sections 6, 8 and 11 |
Everyone should read Section 12 (retention), Section 14 (your rights) and Section 15 (state disclosures).
2. The short version
- We collect precise location from driver phones and in-vehicle screens. It is the core of what we do: it is how we prove an advertisement actually played in a real vehicle on a real trip, which is what advertisers pay for and drivers are paid on.
- We do not identify passengers, and no image or video of anyone ever leaves the vehicle. A screen may sense only whether someone is present or not. That happens on the device itself, and all that reaches us is a yes-or-no signal. We do not count people, do not use facial recognition, and do not create biometric identifiers.
- We receive trip information without knowing who the passenger is. Dispatch and rideshare trip feeds reach us without passenger names or contact details.
- We do not infer sensitive destinations. We do not record or derive that a trip went to a medical, religious or legal destination.
- We do not sell personal information for money, and we do not use it for cross-context behavioral advertising. We do create and may license de-identified and aggregated data.
- We do not knowingly collect anything from children.
- Our website uses Google Analytics and a cookie banner. Our apps and portals do not use advertising trackers.
3. Website visitors
When you visit www.govugo.com we collect standard web information — pages viewed, referring page, approximate location derived from IP address, browser and device type, and interactions with the site.
Google Analytics. We use Google Analytics 4 (measurement ID G-R40EYBDFF1) through the Google tag, to understand how the site is used and to improve it. Google Analytics sets cookies and processes an identifier for your browser. Analytics is the only destination configured for our Google tag — we do not run Google Ads remarketing, Meta, LinkedIn or other advertising pixels on our website. We have not enabled Google Signals, so our analytics data is not used for advertising personalisation or cross-device advertising.
Cookie choices. Our cookie banner lets you accept or decline categories — functional (always on), preferences, statistics and marketing. You can change your choice at any time through the banner’s preferences link.
Forms. Our “Get Started” and driver waitlist forms are hosted by HubSpot. What you type into them — name, email, phone, company and any message — goes to HubSpot and to us, and we use it to reply to you and to follow up about our services.
4. Advertisers and agencies
If you open an advertiser account we collect: your name, business email, phone, company name and type, billing contact and address; your campaign content, creative, landing pages, targeting choices and budgets; and payment details.
We do not receive or store your card number, or your bank account and routing numbers. Payments run through Stripe using their hosted checkout; we see only the card brand, last four digits and expiry, and a Stripe customer identifier.
We keep records of your acceptance of our Terms — which version, who accepted it, and when — and of your confirmation that you hold the rights in each creative asset you upload.
If you connect a design tool. You can connect your own Canva account so that you can design advertising creative without leaving Vugo. If you do, we store an access credential for your Canva account, encrypted, and we use it only to create a design at the correct specification for your campaign, to read the design you make, and to bring the finished file back into Vugo. We ask Canva for three permissions and no others: create designs, view design content, and view design metadata. We cannot delete anything in your Canva account, and we do not read designs unrelated to the campaign you are working on. You can disconnect at any time in Settings, which withdraws our access at Canva as well as deleting the credential from our systems.
5. Drivers
If you sign up to drive we collect:
- About you — name, email address, mobile number, and a password stored only as a cryptographic hash. We verify your phone by sending a one-time code by SMS.
- About your vehicle — make, model, year, colour, licence plate and state, and where applicable the vehicle identification number.
- Insurance — carrier, policy number and expiry date.
- Payment — a Stripe Connect account identifier. Your bank details and tax identification go directly to Stripe, not to us. Stripe collects your W-9 and issues your 1099 on our behalf where the IRS threshold is met.
- Location — see Section 6.
- Photographs you submit as proof that a wrap is installed, including the time and place they were taken.
- Your consent record for background location, and your app preference settings.
- Your market, derived once from your location so we can show you relevant campaigns.
We do not collect your Social Security number, date of birth, or driver’s licence number. Where identity verification is required for payouts, Stripe performs it directly.
6. Location data — the most important section
What we collect. While you are active in the Vugo driver app, we collect your device’s location at frequent intervals, including while the app is in the background. In-vehicle screens also report their location when an advertisement plays. We record latitude and longitude, accuracy, speed and time.
Why. Location is our verification mechanism. An advertisement is billable only if we can show it played during a real trip in a real vehicle: we compare the screen’s location against the driver’s phone and, where available, trip data from the rideshare platform. Without it, we could not bill advertisers honestly or pay drivers accurately.
We also use location to decide which advertisement to show — matching a campaign’s target area, ZIP code or metro to where the vehicle actually is — and to produce delivery reporting.
How precise. Precisely. We do not round, blur or truncate the coordinates we store. Precise geolocation is treated as sensitive personal information under California, Virginia, Colorado, Connecticut, Maryland and other state laws, and we handle it accordingly.
Driver choice. Background location cannot be switched off while you are participating in a campaign, because it is what verification depends on. Turning it off stops your campaigns and stops your earnings; it does not delete what we already hold. You consent to this collection when you enable it, and we record when you did.
What we do not do with it. We do not use location to monitor drivers outside campaign activity, to make employment or classification decisions about them, or to build advertising profiles of the people in the vehicle.
Sensitive destinations. Where a passenger’s stated destination is a medical, religious or legal venue, we do not record that category and do not derive it. Our systems are built to discard it at the point of lookup rather than store it.
Trip and dispatch data. We also receive information about trips from two other sources: rideshare platform accounts that drivers choose to connect, and dispatch systems operated by fleets and their technology providers, where those are integrated.
That information tells us a trip is underway, when it starts and ends, and where applicable the destination the passenger gave. It reaches us without the passenger’s name, contact details or account identifier — we are not told who the passenger is and we do not ask.
We use it for two purposes:
- TripIntent — choosing an advertisement that suits the context of the trip. A trip heading toward a stadium may see something different from one heading toward an airport. This is contextual: it is based on the trip in front of us, not on any profile of the person taking it, and nothing we learn from one trip is carried into another or attached to an individual.
- Verification — confirming that an advertisement played during a real trip, alongside the location signals described above.
The sensitive-destination exclusion above applies to dispatch data in the same way. We do not build passenger profiles, do not track anyone between trips, and do not combine trip data with information from other sources to work out who someone is.
7. Fleet operators
If you enroll vehicles we collect your business name, contact name, email, phone, billing address and tax identification; your vehicle roster including plate, state and where applicable VIN; your payout arrangements; and any content you publish to passenger screens.
Where you enroll a vehicle whose screen is bound to the vehicle rather than to a driver’s account, we still collect location and trip data from that vehicle while it operates, as described in Section 6, even though the driver is not using the Vugo driver app. Your agreement with us requires you to have told those drivers and, where the law requires it, obtained their consent.
8. Passengers, and in-vehicle screens
If you are riding in a vehicle carrying a Vugo screen, you do not have a Vugo account and we do not know who you are. We do not ask for your name, and we do not link what happens on the screen to your identity.
What is recorded during a trip is: the vehicle’s location, the advertisements played and when, and the trip’s start and end. Where a stated destination is available, we resolve it to a general venue type for relevance — excluding medical, religious and legal venues, which we discard. See “Trip and dispatch data” in Section 6 for where that information comes from.
Passenger presence sensing. Advertising is worth showing only when someone is there to see it, so a Vugo screen may sense whether the vehicle is occupied.
- It senses presence only. The question the screen asks is “is someone there, yes or no.” We do not count how many people are in the vehicle.
- Nothing that could depict or identify you leaves the vehicle. Any sensing runs on the device itself. All that is transmitted to Vugo is that yes-or-no signal. No image, no video, no audio and no template is transmitted, and none is stored by Vugo.
- No facial recognition, and no measurement of anyone’s face or body. We do not scan or compute face geometry or any other physical characteristic. We do not attempt to work out who you are, your age, your gender, your mood or anything else about you, and we do not match you against any database or recognise you between trips.
- We do not retain images. There is nowhere in the Vugo platform that images of passengers are stored, because we never receive them.
QR codes. If you scan a code shown on the screen, we record the scan — which advertisement, which trip, the time, and your browser’s user-agent string — before sending you on to the advertiser’s site. We use this to tell the advertiser how many people responded. We do not receive your name from it, and we do not attempt to identify you.
9. How we use information
- To operate the service: run campaigns, decide which advertisement to show, and display it — including TripIntent, our contextual matching of an advertisement to the trip in front of the screen.
- To verify delivery and prevent fraud: confirm an advertisement played in a real vehicle on a real trip with someone in it, and detect invalid or artificially generated activity.
- To bill advertisers and pay drivers and fleets, and to keep the financial records that requires.
- To provide reporting to advertisers (see Section 10).
- To communicate with you about your account, campaigns, earnings, payouts and support.
- To improve the service, understand how it is used, and develop new features.
- To create de-identified and aggregated data — see Section 10.
- To comply with law, enforce our Terms, and protect the rights and safety of users and the public.
10. Who receives information
Advertisers. Advertisers see how their campaign performed. That includes impression counts, the locations where their advertisement played, campaign heatmaps, and — for wrap campaigns — photographs submitted by drivers showing the wrap on the vehicle, and the route coverage those vehicles achieved.
Be aware of what this means: an advertiser running a wrap campaign can see where the vehicles carrying their advertisement travelled. We require advertisers by contract not to attempt to identify any individual driver, vehicle or passenger from this reporting, not to combine it with other data for that purpose, not to redistribute or sell it, and not to use it to build a competing product. Advertisers never receive your name, contact details or account information.
Service providers. We use service providers who act on our instructions and are contractually restricted to using information only to perform services for us. They fall into these categories:
| Category | What reaches them |
|---|---|
| Cloud hosting and database providers | Platform data, to run the service |
| Payment processing and payouts | Advertiser billing contact and a payment token; driver identity, bank and tax details, collected by the processor directly rather than by us |
| Communications — email and SMS delivery | Recipient address or mobile number, and the message |
| Mapping and geospatial services | Map usage from the browser; map views may include delivery locations |
| Media hosting and delivery | Advertising creative |
| Weather data | Coordinates for a contextual lookup |
| Website analytics and marketing forms | Website usage and what you enter into a form — see Section 3 |
| Error monitoring and security tooling | Technical diagnostics, which may incidentally include an identifier |
| Design tools you choose to connect | The design you create there, and the account you connected — see Section 4 |
We name Stripe, which handles payments and payouts and collects card, bank and tax details directly; Google Analytics, which measures use of our website; and Canva, where you may choose to design your advertising creative — because you interact with all three of them directly.
You can ask us for the specific providers. Email privacy@govugo.com and we will tell you which providers are currently in each category, and which have received your personal information.
De-identified and aggregated data. We create data derived from platform activity that does not identify anyone — for example counts of advertising exposures by area and time period, coverage measures, and verification attestations. We may use and license this. We do not license individual-level records or raw location traces, and we do not attempt to re-identify de-identified data or permit others to do so.
Others. We may disclose information in connection with a merger, acquisition or sale of assets; to comply with law or valid legal process; and to protect our rights, our users, or the public.
11. Advertising, “sale” and “sharing”
We do not sell personal information for money.
We do not use or disclose personal information for cross-context behavioral advertising. Advertising on Vugo screens is targeted by where the vehicle is and the context of the trip — not by tracking an individual across websites and apps.
Our website uses Google Analytics. Some state laws take a broad view of what counts as “sharing” when analytics cookies are used, so we honor opt-out signals as described in Section 13 and give you cookie choices on the site.
12. How long we keep information
Different categories are kept for different periods.
Short-lived security and operational data is deleted automatically: one-time sign-in codes after 7 days; password reset and email verification tokens after 30 days; device pairing codes after 30 days; device diagnostic logs after 90 days; payment processor event records after 90 days.
Records of advertising delivery — impressions, the decisions behind them, location associated with them, QR scans, and the financial records built on them — are retained as business records for as long as they are needed for billing, verification, dispute resolution, measurement, and our legal and tax obligations. We do not currently apply a fixed deletion date to these records.
Account information is retained while your account is open and afterwards for as long as needed to meet our legal, tax and record-keeping obligations.
Credentials for services you connect are held until you disconnect the service or close your account, and are deleted at that point. Disconnecting also withdraws our access at the service itself.
You can ask us to delete information about you as described in Section 14, and we will do so except where we are required or permitted to keep it.
13. Your choices
Cookies. Use the banner on our website to accept or decline preference, statistics and marketing cookies, and to change your choice later.
Global Privacy Control. If your browser or extension broadcasts a GPC signal, we treat it as a request to opt out of any sale or sharing of your personal information and of targeted advertising on our website.
Driver app. You can manage notification and analytics preferences in the app. Background location cannot be disabled while you are running a campaign, as explained in Section 6.
Marketing email. Unsubscribe using the link in any marketing message. We will still send you messages about your account, campaigns, earnings and payouts.
14. Your privacy rights
Depending on where you live, you may have the right to:
- know what personal information we hold about you and how we use it;
- access a copy of it;
- correct it if it is inaccurate;
- delete it;
- take it with you in a portable format;
- opt out of sale, sharing, targeted advertising, or profiling that produces legal or similarly significant effects; and
- not be discriminated against for exercising these rights. Exercising them will not affect your account, your rates, or your standing with Vugo.
How to exercise them. Email privacy@govugo.com with what you want and enough detail for us to find your records. You may also write to us at the postal address at the top of this policy.
Verification. We will ask you to verify your identity, ordinarily by confirming control of the email address or phone number on your account. We ask for the minimum needed and do not use it for anything else.
Timing. We respond within 45 days. If we need more time we will tell you within that period and may take up to a further 45 days.
Authorized agents. You may use an authorized agent. We will ask for proof of authorization and may ask you to confirm it directly.
Appeals. If we decline your request, you may appeal by replying to our decision or emailing privacy@govugo.com with “Appeal” in the subject line. We will respond to the appeal within 45 days and, if we again decline, tell you how to complain to your state Attorney General.
15. State-specific disclosures
These apply to residents of states with comprehensive privacy laws, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island.
Categories we collect. Identifiers (name, email, phone, account identifiers); commercial information (transactions, billing); internet activity (website usage); precise geolocation; professional information (vehicle and insurance details for drivers); financial identifiers held by our payment processor; and inferences drawn for advertising relevance.
Categories we disclose to service providers for a business purpose, in the last 12 months: identifiers, commercial information, internet activity, and precise geolocation — to the categories of provider described in Section 10. You may ask us for the specific providers.
Sensitive personal information. We collect precise geolocation. We use it only for the purposes described in Section 6 — delivering and verifying advertising, and reporting on it — and not to infer characteristics about anyone. We do not sell or share it.
We do not collect biometric information. Where a screen senses whether a vehicle is occupied, the sensing occurs on the device and only a yes-or-no signal is transmitted; no image or template is transmitted to or stored by Vugo, we do not count occupants, and we perform no facial recognition, face or body measurement, or identification.
Sale and sharing. We have not sold personal information for money. See Section 11 for advertising and analytics.
Automated decision-making. We use automated processing to select which advertisement to display and to validate whether an impression is billable. These decisions do not produce legal or similarly significant effects concerning any individual. We do not use automated processing to make decisions about employment, credit, housing, education, healthcare or insurance.
Minnesota residents may additionally request a list of the specific third parties to which we have disclosed personal information, and may question the result of profiling. Email privacy@govugo.com.
California residents may also request the information described in California Civil Code §1798.83 once per year.
16. Security
We protect information with measures appropriate to its sensitivity, including encryption of data in transit, hashed storage of passwords and one-time codes, database-level access controls that restrict each account to its own records, short-lived access tokens, rate limiting, audit logging of administrative actions, and encryption at rest of credentials you authorise us to hold for a service you have connected. Card and bank details are handled by Stripe and do not reach our servers.
No system is perfectly secure, and we cannot guarantee absolute security.
17. Children
The Vugo service is for adults. We do not knowingly collect personal information from anyone under 18, we do not direct any part of our service to children, and we do not knowingly use anyone’s information for targeted advertising where we know them to be under 18. If you believe a child has provided us with information, email privacy@govugo.com and we will delete it.
Passengers in vehicles carrying Vugo screens are not identified by us and no account is created for them, whatever their age.
18. International
Vugo is headquartered in the United States and our systems are located there. Wherever you use or access the service from, your information may be processed in the United States and in other countries where Vugo, our operators or our service providers operate. Those countries may have data protection laws different from those in your own.
Where you connect a service based outside the United States, information you send to it is processed in that country. Canva, which you may connect to design creative, is based in Australia.
Where we operate in a country whose law gives you additional rights, those rights apply to you and we will describe how to exercise them.
19. Changes to this policy
We may update this policy. We will change the version date at the top, keep prior versions available, and — where changes are material — notify account holders by email before they take effect. Continued use after a change takes effect means you accept the updated policy.
20. Contact
Privacy requests: privacy@govugo.com
General support: support@govugo.com
Post: Vugo, Inc., 1161 Wayzata Blvd E, Suite 172, Wayzata, MN 55391
Change log
| Version | Published | Summary |
|---|---|---|
| 2026-08-31 | 31 Aug 2026 | Discloses design tools you can connect to your account, and Canva as the first of them: the access credential we store, that it is held encrypted, the three permissions we request, that we cannot delete anything in your Canva account, and that disconnecting withdraws our access at Canva as well as deleting the credential (Section 4). Adds a service-provider category for connected design tools and names Canva alongside Stripe and Google Analytics (Section 10). States how long a connected-service credential is kept and when it is deleted (Section 12). Adds encryption at rest of those credentials to the security measures listed (Section 16). Notes that a service you connect may process information outside the United States, and that Canva is based in Australia (Section 18). Removes the rideshare-account credential entry from the driver section, which described a connection Vugo does not currently offer. |
| 2026-08-17 | 17 Aug 2026 | Rewrite. Replaces the named third parties, which described advertising vendors Vugo does not use, with categories of provider and a named-list-on-request commitment; describes passenger-presence sensing as on-device and presence-only, and rules out counting, facial recognition, face or body measurement, identification and image retention; describes trip and dispatch feeds arriving without passenger identifiers and their use for TripIntent contextual matching; states that sensitive destination categories are not recorded; describes what advertisers actually receive, including wrap route coverage; adds a de-identified and aggregated data section; adds a working rights channel with verification, timing, authorized agents and appeals; adds a multi-state disclosures section and automated decision-making statement; states retention by category rather than generically; removes the security claims the platform does not support. |
| 2023-05-14 | 14 May 2023 | Prior published version. |