Who we are
CoPAX is run by Lyxa Labs LLP, a limited liability partnership registered in India. Registered office: Lyxa Labs LLP, [registered office address].
In this policy, "CoPAX", "we" and "us" mean Lyxa Labs LLP. We decide how and why your information is used. In legal terms, that makes us the "data controller" (in India, the "data fiduciary").
CoPAX is a mobile app for professional networking with the people on your flight or train. It is not a dating app.
What we collect and why
Your mobile number
We use it to sign you in with a one-time code, to keep your account safe and to prevent abuse. Other travellers never see it. If you and a connection both agree to swap contact details, only the details you chose to share are shown to that one person.
Your profile
Your face photo, name, headline, company, city, and the topics you can help with and are looking for. We use it to show a limited profile to verified travellers in your own cabin or coach (see What other travellers can see). Your photo is checked on your phone for one clear face, and we keep a resized copy in private storage.
Verification
To make sure everyone on CoPAX is a real person, we check your phone number, a live photo, your phone and your LinkedIn account. How verification works explains each step and what we keep.
Your trips and seats
The flights and trains you add, with the coach or cabin and the seat. We use them to show you the people in your own cabin or coach, and to send you status updates such as delays, gate or platform changes.
- You can add a trip from a boarding pass, a ticket, a screenshot, a booking email you forward to your private CoPAX address, or by typing it in.
- Ticket files you upload are read and not stored. Forwarded emails are read and then thrown away; we keep only when one arrived and whether it could be read.
- From a ticket we keep the journey, the coach or cabin, the seat and a scrambled one-way code of the booking. We never keep the booking reference itself. A one-way code (sometimes called a "hash") can be compared with another code but cannot be turned back into the original.
- We check that the name on the ticket matches your verified name.
Hi requests, connections and messages
The Hi requests you send and receive, the connections you accept, and the ready-made messages you exchange. CoPAX has no free-text chat: every message and reply is chosen from a fixed list. We use this to run your conversations and to look into reports.
Reports and blocks
Reports you make or receive, people you block, and the outcome of our reviews. We use this to keep the community safe and professional. A person you report never learns who reported them.
Invitations
If you joined with an invitation code, we record which code you used. See How long we keep things for the small record we keep to prevent misuse of invitations.
Device and diagnostic data
A notification token so we can send you alerts, a device identifier, the result of checks that the app is genuine, and crash reports with personal details removed. We use this to deliver notifications, keep your account secure and fix problems.
What other travellers can see
- Only verified travellers can see profiles. People who have not finished verification cannot see anyone.
- Only your own cabin or coach. On a flight, people see others in their own cabin. On a train, people see others in their own coach.
- Before you accept a Hi, they see your photo, first name and the initial of your surname, headline, company, your "can help with" and "looking for" topics, and your verification badges.
- After you accept, that person also sees your full name.
- Contact details are shared only if you both agree, and only the ones you choose.
- If you block someone, you no longer see each other on any trip.
How verification works
Every person on CoPAX completes the same checks before they can see other travellers or say Hi.
Phone number
We send a one-time code by text message. A delivery partner receives your number and the code (see Who helps us run CoPAX).
Live photo
You take a short live photo in the app. Your phone checks that a real person is present, for example by asking you to blink or turn your head. Our own servers then compare the live photo with your profile photo. No outside company is involved. The live photo is deleted straight after the comparison and is never stored. We keep only the fact that the check passed and how closely the photos matched, until you change your profile photo.
Your phone
To stop stolen sign-ins, your account works on one phone at a time. Your phone creates a security key that never leaves its secure hardware. We keep the public part of that key, the type of phone, when it was verified and a summary of the check (its security level, whether the phone's system is unmodified, and that the app is genuine). We never collect your phone's serial number or IMEI. When you verify a new phone, your old phone is signed out and told why.
You sign in with LinkedIn. We check that the name matches your profile and keep a one-way code of your LinkedIn account. We do not keep your LinkedIn profile or email address.
Government ID
CoPAX does not ask for government ID at the moment. If we offer it in future, it will be optional, we will update this policy first, and we will never store your ID number or a copy of the document.
Why we are allowed to use your data
We use your information because you agree to it when you sign up (your "consent"), and you can withdraw that consent at any time by deleting your account. Where the law allows it, we also use limited information to keep CoPAX safe, prevent fraud and meet legal duties. In the EU and UK this is called our "legitimate interests" or a "legal obligation".
How long we keep things
- The people around you on a trip: 7 days after a trip arrives, we delete what describes the other travellers on it: their seats on the seat map, Hi requests that were never answered and seat checks. You keep your own trip and seat as history.
- Connections and conversations you accepted stay until you or the other person deletes their account.
- Your live photo: never stored. It is deleted straight after the check.
- Uploaded ticket files and forwarded emails: not kept after they are read.
- Sign-in codes, text-message delivery records and scrambled network addresses (used to stop abuse): deleted after 1 day.
- When you delete your account: your profile is hidden at once and you are signed out everywhere. Your data is erased within 30 days, and copies in our backups are removed within 14 days after that. In chats with you, your name and photo are removed and your messages show as "Deleted user". The other person keeps the chat, but it is ended. Contact details you shared are wiped.
- Safety record: after an account is erased we may keep a minimal safety record (for example, how many warnings the account had and the date of the last one), linked to a one-way code of the mobile number, for up to 12 months where the law requires or allows it.
- Invitations: if a deleted account had joined through an invitation and counted towards it, we keep a scrambled one-way fingerprint of its verified identity (for example, its LinkedIn account) for 12 months, to prevent misuse of invitations. It holds no name or ID number, cannot be turned back into a person and is used for nothing else.
- Records of your privacy requests (that you asked for a download or deletion, and when): kept for 3 years.
- Server logs and crash reports: kept only as long as we need them to run and fix the service.
Who helps us run CoPAX
We use a small number of service providers ("processors"). They handle data only on our instructions and only for the job described.
- Cloud hosting — Google Cloud: our servers, database, file storage and server logs.
- Text-message delivery — MSG91 (India) and Twilio (USA): receive your mobile number and the sign-in code. Which one is used depends on your country.
- Genuine-app checks — Google Play Integrity: checks that requests come from the real CoPAX app. It receives an app token, not your details.
- Notifications — Google (Firebase Cloud Messaging): delivers notifications to your phone.
- Crash reporting — Sentry (European Union): receives crash reports with personal details removed.
- Forwarded booking emails — Postmark: receives the booking emails you forward to your CoPAX address.
- Flight and train status — our travel-data providers (for flights, AeroDataBox): receive only the flight or train number and date, never your details.
- LinkedIn: used when you verify with LinkedIn.
We may also share information when the law requires it, for example in response to a valid request from the police or a court, or to protect someone's safety. If CoPAX is ever sold or merged, your information would move to the new owner under the same protections, and we would tell you first.
Where your data is stored
Our servers, database and file storage are in Google Cloud in Mumbai, India. If you use CoPAX from another country, your information is sent to India. Some of the providers listed above work in other countries, including the USA and the European Union.
When we send information across borders, we do so only as the law allows, and we use the protections it requires. For people in the EU and UK, we use the safeguards those laws require for international transfers. You can write to us to ask about them.
Your rights and choices
Depending on where you live, you have some or all of these rights:
- See your data. In the app, go to Profile, then Privacy & data, and download a copy of your data as a file.
- Correct your data. Write to us and we will fix anything that is wrong.
- Delete your data. In the app, go to Profile, then Privacy & data, and delete your account. You can also ask us by email; the Support page explains how.
- Take your data elsewhere. The download is a standard file you can keep or move.
- Withdraw consent. Deleting your account withdraws your consent. This does not affect what we did before.
- In the EU and UK, you can also ask us to limit how we use your data, or object to uses based on our legitimate interests.
- In India, you can also name a person to exercise your rights if you die or cannot act yourself (a "nominee"), and you can raise a grievance with us (see below).
We reply within the time set by the law of your country. We may ask you to confirm the request comes from you, usually by sending a code to your registered number.
Questions and complaints
Write to privacy@copax.app with any question about your data.
India: our grievance officer can be reached at grievance@copax.app. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.
UK: you may complain to the Information Commissioner's Office (ICO). EU: you may complain to the data protection authority in the country where you live or work. We would appreciate the chance to help first.
Age
CoPAX is only for adults. When you sign up you confirm that you are 18 or older. We do not knowingly collect information from anyone under 18. If you believe someone under 18 has an account, please tell us at privacy@copax.app and we will delete it.
Security
We protect your information with encryption in transit, private storage for photos, and short-lived links to view them. Every moderation decision is recorded so it can be checked. No system is perfectly secure, but if a breach affects you, we will tell you and the authorities as the law requires.
This website
This website (copax.app) uses no cookies, no analytics and no tracking. Like any website, our hosting provider (Google) briefly records basic technical details such as your network address when you visit, to deliver the page and protect it from abuse.
Changes to this policy
If we change this policy, we will update the date at the top. If a change is important, we will tell you in the app before it applies and, where needed, ask you to agree again.
Contact us
Lyxa Labs LLP, [registered office address]
Privacy questions: privacy@copax.app
Grievance officer (India): grievance@copax.app
Anything else: support@copax.app