NDG Reports & Insights / Founder Notes

Privacy in Mobility & Travel Data

Why this is worth writing about

Most companies that talk about data privacy are talking about something abstract — an account, a browsing history, a set of preferences. Building in mobility and travel, the data is different. It’s where you were and when. Who you were traveling with. Whether you were at a hospital, a place of worship, someone else’s home. That’s a different category of information than most software companies handle, and I don’t think it gets treated differently enough across the industry.

What the regulators are already telling us

This isn’t a hypothetical concern. In January 2026, the FTC finalized a settlement with General Motors and OnStar that included a five-year ban on sharing geolocation and driver-behavior data with consumer reporting agencies. The FTC was explicit about the principle behind it: location data deserves the same heightened protection as phone tracking, undisclosed sharing of sensitive data is treated as an unfair practice on its own, and using that data in automated decisions can be unlawful if it produces discriminatory outcomes.

Around the same time, Consumer Reports published model legislation — the State Location Privacy Act, building on laws already passed in Oregon and Maryland — built around a single idea: companies should collect and use location data only when it’s actually needed to provide the product or service someone asked for. Not “opt in and then anything goes.” The two-pager is blunt about why: location data on hospital visits, political rallies, and places of worship has already been sold to marketers, insurers, and worse.

I read both of these less as warnings and more as a preview of where the baseline is heading. “We only collect what the trip actually requires” is going to stop being a competitive claim and start being the minimum expectation.

The mobility question

For a company running a private transportation service, the honest version of this question isn’t “are we secure” — it’s narrower and more useful: do we collect location only for the length of an active trip, for the purpose of the trip, or does it linger and get used for something else afterward? That’s the standard I want us held to, and it’s the standard I think the regulatory direction above is going to make universal. I’m not going to claim here that we’ve already fully answered that question in a way that’s been reviewed and confirmed — our privacy documentation is still in draft, working through exactly these specifics before it’s published. I’d rather say that plainly than round up.

The travel question

Group and corporate travel has a different privacy problem, and it’s one the industry doesn’t talk about enough: often the person whose data you’re collecting isn’t the person who agreed to anything. A trip organizer submits names, sometimes travel documents, sometimes accessibility needs, for people who never saw a privacy policy or clicked “I agree.” IATA — the international air transport association — describes this as a structural feature of the entire travel industry: airlines routinely share passenger data with “other airlines, airports, ground handlers, travel agents, and border control authorities,” including passengers who booked through an intermediary rather than directly. It’s not a solved problem industry-wide, and I don’t think it’s honest to pretend it is anywhere, including for us. The responsibility has to sit clearly with whoever’s doing the organizing, and the platform has to make that responsibility visible rather than quietly assume it away.

Where this leaves us

This is the first of what I intend to be an ongoing set of notes, not a one-time statement. I’d rather build a track record of specific, honest positions on privacy questions as they come up than make one broad claim and move on. The next installment will likely get more specific as our own privacy documentation moves from draft to published and counsel-reviewed — at that point I can speak to our own practices with more confidence than I can today.

Sources

  • Nelson Mullins, “Privacy Regulation of Auto Industry to Accelerate in 2026 – Part 1”
  • Consumer Reports Advocacy, “State Location Privacy Act” (January 2026)
  • IATA, “Data Protection & Privacy”
Marcus Allen
Founder & Owner, Nexus Diversity Group