Passi Technologies, S.R.L.
Last updated: September 10, 2026
This Security Policy of Passi Technologies, S.R.L. (doing business as “Passi”, “we”, “us” or “our”) describes the principles and measures we use to protect the Services, user information, and transactions processed through our platform.
This Policy applies to our mobile application, the website https://www.gopassi.com and other systems, functionalities, and channels operated directly by Passi.
Passi is a technological marketplace that connects Clients with independent Hosts and Providers. This Policy refers to the systems and processes under Passi's control. Devices, networks, equipment, or technologies independently operated by Hosts, users, or other third parties are subject to the obligations and practices of those third parties, unless expressly indicated otherwise.
Need to report a security issue? You can write to us at info@gopassi.com.
This Policy describes security measures applicable to the systems and processes that Passi directly controls.
Passi Technologies, S.R.L., RNC 133131021, operates a marketplace for vehicle, boat, yacht, shuttle, and other mobility and leisure service bookings.
The scope of this Policy includes the reasonable protection of accounts, personal information, booking operations, payment integrations, administrative systems, and communications processed by Passi.
This Policy does not constitute an exhaustive description of our architecture, internal configurations, detection mechanisms, or security controls. Passi may keep certain details confidential when their disclosure could increase the risk to the Services or its users.
Our security strategy is based on reducing exposure, limiting access, and using specialized providers for sensitive functions.
The specific implementation of each principle may vary depending on the system, the level of risk, available technology, and applicable obligations.
Passi uses reasonable controls to protect accounts and reduce the risk of unauthorized access.
Authentication methods may change over time. Passi does not guarantee that a specific authentication mechanism, including multi-factor authentication, will be available for all accounts, users, or functionalities at all times.
Passi seeks to develop, operate, and maintain its systems consistently with reasonable security practices.
The existence of these measures does not mean that the software is free from vulnerabilities, errors, or interruptions.
Passi uses Azul as a specialized provider for card processing and tokenization.
When a user registers or updates a card, Passi may use a page or WebView operated by Azul, so the capture of sensitive card data occurs in the payment provider's environment.
Azul may tokenize and store payment information through services such as Data Vault. Passi may receive a token or reference, masked data, and permitted transactional metadata to manage bookings, authorized charges, refunds, chargebacks, reconciliation, and support.
Subsequent transactions may be initiated from Passi's systems using the corresponding token when there is a contractual basis or valid authorization. Passi seeks to ensure that the transaction amount is determined and validated from its systems and that the provider's responses are verified before modifying a booking's status.
The availability of cardholder authentication, 3D Secure, DCC, or other controls depends on Azul, issuers, card networks, integration configuration, and transaction characteristics.
Passi designs its flow to minimize direct exposure to sensitive card data.
Passi does not intend to directly store the full card number (PAN) or the security code (CVV/CVC). Sensitive card data is handled by Azul and other payment ecosystem participants according to their own standards and obligations.
Passi may store limited permitted data, such as tokens, references, card brand, last digits, expiration date when available, transaction identifiers, statuses, response codes, and other metadata necessary to operate the service.
Azul establishes security requirements associated with PCI DSS for affiliates and e-commerce integrations. Passi seeks to comply with the requirements corresponding to its architecture and final integration. This Policy does not constitute a representation that Passi possesses a specific PCI DSS certification, nor does it replace questionnaires, attestations, validations, or certifications that Azul or card brands may require.
Passi may use Stripe Identity as an external tool to verify identity or driver's license.
In certain flows, Stripe Identity may directly collect documents, images, information extracted from such documents, and technical data necessary to perform the verification.
Passi may receive the verification result and certain information reasonably necessary to manage the account, prevent fraud, verify eligibility, or handle incidents.
The result of an automated or assisted verification does not constitute an absolute guarantee of identity, documentary authenticity, driving ability, future conduct, or absence of fraud. Stripe maintains its own controls and obligations regarding the processing it performs.
Access to systems and information is reasonably limited according to functions and need.
Details of roles, access matrices, and internal configurations are considered operational security information and are not published in this Policy.
Passi seeks to protect information transmitted across public networks using appropriate encryption protocols.
Connections to web services, APIs, sites, and external providers handling sensitive or transactional information are designed to use encrypted connections when applicable.
Azul documents the use of HTTPS/TLS and other authentication and security mechanisms in its integrations. The final configuration of Passi's integration will be implemented according to the provider's technical specifications and applicable validations.
No internet transmission method is completely infallible. Users should avoid compromised networks or devices and verify they are using official Passi channels.
Passi seeks to protect technical credentials, keys, secrets, and privileged access.
Passi may modify these practices as its infrastructure evolves or adopts new tools.
We use logs and observability tools to detect technical issues, fraud, and relevant security events.
Passi may log authentication events, errors, API responses, booking and payment status changes, administrative events, technical signals, and other logs necessary to operate, investigate incidents, and improve the Services.
Logs are designed to avoid, to the extent reasonably possible, storing sensitive card data or secrets not necessary for the log's purpose.
Monitoring does not guarantee immediate detection of all attacks, errors, frauds, or unauthorized access.
Passi seeks to identify and address vulnerabilities according to risk.
Passi does not guarantee a fixed correction timeframe for every vulnerability. Priority and response time depend on the nature of the problem and associated risks.
Passi maintains a proportional response approach to the nature and severity of an incident.
Faced with a confirmed or suspected incident, Passi may take measures such as restricting access, revoking or rotating credentials, suspending functions, investigating logs, contacting providers, restoring services, requesting additional verifications, and preserving relevant evidence.
When applicable legislation, contracts, or provider rules require, Passi may notify affected users, providers, acquirers, authorities, or other relevant parties.
The response may involve specialized third parties. The nature and details of the measures taken may be kept confidential when necessary to protect the investigation, system security, or third-party rights.
Passi relies on technological and financial providers operating their own systems and controls.
These providers may include payment processors, identity verification, infrastructure, databases, authentication, analytics, communications, monitoring, and support.
Passi seeks to select providers considering, among other factors, functionality, reliability, security, and reasonable regulatory needs. However, Passi does not fully control the infrastructure, operations, or internal incidents of third parties.
Each provider may maintain its own policies, standards, certifications, and obligations. Using a provider does not represent a guarantee of permanent availability or absence of incidents.
Hosts are responsible for the systems and devices they install or operate independently.
Passi does not currently install, operate, or manage GPS, tracking, telemetry, cameras, or similar devices used independently by Hosts in their vehicles or boats.
The Host is responsible for the legality, safety, maintenance, configuration, and use of those devices, as well as making disclosures or obtaining consent when applicable.
Passi does not provide, certify, monitor, or guarantee such devices. If a Host shares information derived from them with Passi to investigate fraud, damages, accidents, breaches, asset recovery, or a dispute, Passi may use it for those purposes according to its Privacy Policy and applicable legislation.
Passi may use technical signals, verifications, and operational controls to reduce fraud and abuse.
Passi will never request via email, chat, or phone that a user reveal their CVV, full password, or other unnecessary security secrets for support. Users should be suspicious of payment or credential requests outside official channels.
Fraud detection may produce false positives or not detect all cases. Security controls reduce risk but do not eliminate it.
The security of the Services also depends on each user's practices.
The user may be responsible for activity conducted from their account when such activity results from sharing credentials, negligence, breach of Terms, or actions under their control, subject to mandatory limitations and protections under applicable law.
Passi seeks to maintain reasonable availability, but the Services may experience interruptions.
Passi may use backups, redundancy, monitoring, recovery procedures, and other continuity measures when appropriate for the system and risk.
Availability may be affected by maintenance, provider failures, networks, third-party services, security incidents, force majeure events, or other causes beyond Passi's reasonable control.
This Policy does not establish a service level agreement or guarantee uninterrupted availability.
No technical or organizational measure can guarantee total security.
Although Passi seeks to apply reasonable measures to protect the Services and the information under its control, no internet-connected system, external provider, authentication method, verification tool, or fraud prevention mechanism can guarantee absolute protection.
Passi does not guarantee that the Services are completely immune to attacks, errors, vulnerabilities, fraud, unauthorized access, interruptions, or information loss.
Nothing in this Policy limits consumer rights or liabilities that cannot be legally limited. Applicable obligations and limitations are also governed by the Terms and Conditions and corresponding legislation.
We appreciate good-faith reports about possible vulnerabilities or security issues.
If you identify a possible vulnerability, unauthorized access, data exposure, or suspicious conduct related to Passi systems, you can report it to info@gopassi.com.
Include only necessary information to describe the issue. Do not access, download, modify, destroy, or disclose third-party data; do not disrupt Services; do not perform social engineering; and do not use a potential finding for extortion, threats, or undue advantage.
Receiving a report does not create a contractual relationship, reward, bug bounty program, or payment commitment, unless expressly established in writing by Passi.
We may update this Policy as products, risks, providers, or legal requirements change.
The current version will be identified by the date of last update. Material changes may be communicated via the App, website, email, or other reasonable channel when applicable.
Internal security measures may change without each modification requiring this Policy to be updated, provided the public description remains reasonably accurate.
Passi Technologies, S.R.L.
RNC: 133131021
Calle J No. 18, La Castellana
Santo Domingo, Dominican Republic
info@gopassi.com
https://www.gopassi.com