logo

Passi Technologies, S.R.L.

SECURITY POLICY

Last updated: September 10, 2026

This Security Policy of Passi Technologies, S.R.L. (doing business as “Passi”, “we”, “us” or “our”) describes the principles and measures we use to protect the Services, user information, and transactions processed through our platform.

This Policy applies to our mobile application, the website https://www.gopassi.com and other systems, functionalities, and channels operated directly by Passi.

Passi is a technological marketplace that connects Clients with independent Hosts and Providers. This Policy refers to the systems and processes under Passi's control. Devices, networks, equipment, or technologies independently operated by Hosts, users, or other third parties are subject to the obligations and practices of those third parties, unless expressly indicated otherwise.

Need to report a security issue? You can write to us at info@gopassi.com.

SUMMARY OF KEY POINTS

  • Layered protection. Passi seeks to use reasonable technical, organizational, and operational controls according to the nature and risk of the Services.
  • Payments. Sensitive card data is captured and tokenized by Azul. Passi designs its flow not to directly store the full PAN or CVV/CVC.
  • Tokenization. Passi may retain tokens, references, masked data, and permitted metadata to manage authorized transactions, refunds, and disputes.
  • Identity verification. Passi may use Stripe Identity to verify identity or driver's license. The tool reduces risk, but does not constitute an absolute guarantee of identity or absence of fraud.
  • Access. Administrative access to information and systems is reasonably limited according to functions, operational need, and available controls.
  • Third parties. Providers such as Azul, Stripe, and infrastructure providers maintain their own obligations and controls. Passi seeks to select and manage providers according to risk.
  • Hosts. Passi does not currently install or operate tracking, telemetry, or camera devices of Hosts. The Host is responsible for their use and legal compliance.
  • No absolute guarantee. No system can guarantee total security. Passi applies reasonable measures and may update them as threats, products, and regulations evolve.

1. PURPOSE AND SCOPE

This Policy describes security measures applicable to the systems and processes that Passi directly controls.

Passi Technologies, S.R.L., RNC 133131021, operates a marketplace for vehicle, boat, yacht, shuttle, and other mobility and leisure service bookings.

The scope of this Policy includes the reasonable protection of accounts, personal information, booking operations, payment integrations, administrative systems, and communications processed by Passi.

This Policy does not constitute an exhaustive description of our architecture, internal configurations, detection mechanisms, or security controls. Passi may keep certain details confidential when their disclosure could increase the risk to the Services or its users.

2. SECURITY PRINCIPLES

Our security strategy is based on reducing exposure, limiting access, and using specialized providers for sensitive functions.

  • Data minimization and access according to operational need.
  • Reasonable separation between critical functions and systems.
  • Use of specialized providers for card processing and identity verification.
  • Protection of information during transmission and, when applicable, during storage.
  • Monitoring and logging of events relevant to operation, fraud, and security.
  • Maintenance and updating of systems according to risks and technical needs.
  • Proportional response to incidents and cooperation with providers or authorities when necessary.

The specific implementation of each principle may vary depending on the system, the level of risk, available technology, and applicable obligations.

3. ACCOUNT SECURITY AND AUTHENTICATION

Passi uses reasonable controls to protect accounts and reduce the risk of unauthorized access.

  • Authentication mechanisms to verify access to accounts and restricted functions.
  • Protection of credentials through appropriate technical practices for the system used.
  • Additional controls or verifications when sensitive changes, unusual activity, or elevated risk are detected, when available.
  • Ability to restrict, suspend, or require additional verification steps upon reasonable signs of fraud or account compromise.

Authentication methods may change over time. Passi does not guarantee that a specific authentication mechanism, including multi-factor authentication, will be available for all accounts, users, or functionalities at all times.

4. SYSTEM AND APPLICATION PROTECTION

Passi seeks to develop, operate, and maintain its systems consistently with reasonable security practices.

  • Review and correction of identified errors and vulnerabilities according to their severity and context.
  • Restriction of interfaces, administrative functions, and sensitive resources to authorized users or systems.
  • Validation and controls in critical flows, including bookings, payments, and account changes.
  • Logical separation of responsibilities between applications, services, and providers when reasonably possible.
  • Protections against automated use, abuse, fraud, and other malicious patterns when detectable.

The existence of these measures does not mean that the software is free from vulnerabilities, errors, or interruptions.

5. PAYMENT SECURITY AND AZUL

Passi uses Azul as a specialized provider for card processing and tokenization.

When a user registers or updates a card, Passi may use a page or WebView operated by Azul, so the capture of sensitive card data occurs in the payment provider's environment.

Azul may tokenize and store payment information through services such as Data Vault. Passi may receive a token or reference, masked data, and permitted transactional metadata to manage bookings, authorized charges, refunds, chargebacks, reconciliation, and support.

Subsequent transactions may be initiated from Passi's systems using the corresponding token when there is a contractual basis or valid authorization. Passi seeks to ensure that the transaction amount is determined and validated from its systems and that the provider's responses are verified before modifying a booking's status.

The availability of cardholder authentication, 3D Secure, DCC, or other controls depends on Azul, issuers, card networks, integration configuration, and transaction characteristics.

Visa SecureMastercard ID Check

6. CARD DATA, TOKENIZATION AND PCI DSS

Passi designs its flow to minimize direct exposure to sensitive card data.

Passi does not intend to directly store the full card number (PAN) or the security code (CVV/CVC). Sensitive card data is handled by Azul and other payment ecosystem participants according to their own standards and obligations.

Passi may store limited permitted data, such as tokens, references, card brand, last digits, expiration date when available, transaction identifiers, statuses, response codes, and other metadata necessary to operate the service.

Azul establishes security requirements associated with PCI DSS for affiliates and e-commerce integrations. Passi seeks to comply with the requirements corresponding to its architecture and final integration. This Policy does not constitute a representation that Passi possesses a specific PCI DSS certification, nor does it replace questionnaires, attestations, validations, or certifications that Azul or card brands may require.

7. IDENTITY VERIFICATION WITH STRIPE IDENTITY

Passi may use Stripe Identity as an external tool to verify identity or driver's license.

In certain flows, Stripe Identity may directly collect documents, images, information extracted from such documents, and technical data necessary to perform the verification.

Passi may receive the verification result and certain information reasonably necessary to manage the account, prevent fraud, verify eligibility, or handle incidents.

The result of an automated or assisted verification does not constitute an absolute guarantee of identity, documentary authenticity, driving ability, future conduct, or absence of fraud. Stripe maintains its own controls and obligations regarding the processing it performs.

8. ACCESS CONTROL AND AUTHORIZED PERSONNEL

Access to systems and information is reasonably limited according to functions and need.

  • Administrative access limited to individuals or services needing it for authorized functions.
  • Review and adjustment of permissions when responsibilities change or operational need ceases to exist.
  • Reasonable separation between personal accounts, administrative accounts, and technical credentials when applicable.
  • Additional restrictions for information or functions considered more sensitive.

Details of roles, access matrices, and internal configurations are considered operational security information and are not published in this Policy.

9. ENCRYPTION AND INFORMATION TRANSMISSION

Passi seeks to protect information transmitted across public networks using appropriate encryption protocols.

Connections to web services, APIs, sites, and external providers handling sensitive or transactional information are designed to use encrypted connections when applicable.

Azul documents the use of HTTPS/TLS and other authentication and security mechanisms in its integrations. The final configuration of Passi's integration will be implemented according to the provider's technical specifications and applicable validations.

No internet transmission method is completely infallible. Users should avoid compromised networks or devices and verify they are using official Passi channels.

10. CREDENTIALS, SECRETS AND ADMINISTRATIVE ACCESS

Passi seeks to protect technical credentials, keys, secrets, and privileged access.

  • Avoid, when reasonably possible, incorporating sensitive secrets directly in user-distributed code.
  • Restrict production credentials to the systems and persons requiring access.
  • Rotate or replace credentials when there is a security reason or suspected compromise.
  • Reasonably separate test and production environments and credentials when the architecture allows.

Passi may modify these practices as its infrastructure evolves or adopts new tools.

11. MONITORING, LOGS AND INCIDENT DETECTION

We use logs and observability tools to detect technical issues, fraud, and relevant security events.

Passi may log authentication events, errors, API responses, booking and payment status changes, administrative events, technical signals, and other logs necessary to operate, investigate incidents, and improve the Services.

Logs are designed to avoid, to the extent reasonably possible, storing sensitive card data or secrets not necessary for the log's purpose.

Monitoring does not guarantee immediate detection of all attacks, errors, frauds, or unauthorized access.

12. VULNERABILITIES, UPDATES AND CHANGES

Passi seeks to identify and address vulnerabilities according to risk.

  • Apply relevant security updates to applications, libraries, systems, or services when applicable.
  • Evaluate errors or findings reported by users, technical team, providers, or monitoring tools.
  • Prioritize corrections considering severity, exposure, exploitability, and impact on users.
  • Perform reasonable testing and validations before deploying sensitive changes when circumstances permit.

Passi does not guarantee a fixed correction timeframe for every vulnerability. Priority and response time depend on the nature of the problem and associated risks.

13. SECURITY INCIDENT RESPONSE

Passi maintains a proportional response approach to the nature and severity of an incident.

Faced with a confirmed or suspected incident, Passi may take measures such as restricting access, revoking or rotating credentials, suspending functions, investigating logs, contacting providers, restoring services, requesting additional verifications, and preserving relevant evidence.

When applicable legislation, contracts, or provider rules require, Passi may notify affected users, providers, acquirers, authorities, or other relevant parties.

The response may involve specialized third parties. The nature and details of the measures taken may be kept confidential when necessary to protect the investigation, system security, or third-party rights.

14. PROVIDERS AND THIRD PARTIES

Passi relies on technological and financial providers operating their own systems and controls.

These providers may include payment processors, identity verification, infrastructure, databases, authentication, analytics, communications, monitoring, and support.

Passi seeks to select providers considering, among other factors, functionality, reliability, security, and reasonable regulatory needs. However, Passi does not fully control the infrastructure, operations, or internal incidents of third parties.

Each provider may maintain its own policies, standards, certifications, and obligations. Using a provider does not represent a guarantee of permanent availability or absence of incidents.

15. HOSTS, DEVICES AND INDEPENDENT SYSTEMS

Hosts are responsible for the systems and devices they install or operate independently.

Passi does not currently install, operate, or manage GPS, tracking, telemetry, cameras, or similar devices used independently by Hosts in their vehicles or boats.

The Host is responsible for the legality, safety, maintenance, configuration, and use of those devices, as well as making disclosures or obtaining consent when applicable.

Passi does not provide, certify, monitor, or guarantee such devices. If a Host shares information derived from them with Passi to investigate fraud, damages, accidents, breaches, asset recovery, or a dispute, Passi may use it for those purposes according to its Privacy Policy and applicable legislation.

16. FRAUD, PHISHING AND ABUSE PREVENTION

Passi may use technical signals, verifications, and operational controls to reduce fraud and abuse.

  • Review of unusual activity or potentially fraudulent booking patterns.
  • Additional identity, license, or account information verification when there is a legitimate reason.
  • Blocking, suspension, or review of accounts, payments, or bookings when there are reasonable signs of risk.
  • Cooperation with Hosts, payment processors, identity providers, banks, card networks, or authorities when applicable.

Passi will never request via email, chat, or phone that a user reveal their CVV, full password, or other unnecessary security secrets for support. Users should be suspicious of payment or credential requests outside official channels.

Fraud detection may produce false positives or not detect all cases. Security controls reduce risk but do not eliminate it.

17. USER RESPONSIBILITIES

The security of the Services also depends on each user's practices.

  • Keep credentials confidential and do not share them with third parties.
  • Use reasonably secure and updated devices, software, and networks.
  • Carefully review links, messages, and payment requests before interacting with them.
  • Promptly notify Passi if you suspect unauthorized access, fraud, lost device, or strange activity.
  • Do not attempt to bypass, disable, probe without authorization, or interfere with Passi's or its providers' security controls.

The user may be responsible for activity conducted from their account when such activity results from sharing credentials, negligence, breach of Terms, or actions under their control, subject to mandatory limitations and protections under applicable law.

18. CONTINUITY AND AVAILABILITY

Passi seeks to maintain reasonable availability, but the Services may experience interruptions.

Passi may use backups, redundancy, monitoring, recovery procedures, and other continuity measures when appropriate for the system and risk.

Availability may be affected by maintenance, provider failures, networks, third-party services, security incidents, force majeure events, or other causes beyond Passi's reasonable control.

This Policy does not establish a service level agreement or guarantee uninterrupted availability.

19. LIMITATIONS AND ABSENCE OF ABSOLUTE GUARANTEE

No technical or organizational measure can guarantee total security.

Although Passi seeks to apply reasonable measures to protect the Services and the information under its control, no internet-connected system, external provider, authentication method, verification tool, or fraud prevention mechanism can guarantee absolute protection.

Passi does not guarantee that the Services are completely immune to attacks, errors, vulnerabilities, fraud, unauthorized access, interruptions, or information loss.

Nothing in this Policy limits consumer rights or liabilities that cannot be legally limited. Applicable obligations and limitations are also governed by the Terms and Conditions and corresponding legislation.

20. RESPONSIBLE REPORTING OF SECURITY ISSUES

We appreciate good-faith reports about possible vulnerabilities or security issues.

If you identify a possible vulnerability, unauthorized access, data exposure, or suspicious conduct related to Passi systems, you can report it to info@gopassi.com.

Include only necessary information to describe the issue. Do not access, download, modify, destroy, or disclose third-party data; do not disrupt Services; do not perform social engineering; and do not use a potential finding for extortion, threats, or undue advantage.

Receiving a report does not create a contractual relationship, reward, bug bounty program, or payment commitment, unless expressly established in writing by Passi.

21. UPDATES TO THIS POLICY

We may update this Policy as products, risks, providers, or legal requirements change.

The current version will be identified by the date of last update. Material changes may be communicated via the App, website, email, or other reasonable channel when applicable.

Internal security measures may change without each modification requiring this Policy to be updated, provided the public description remains reasonably accurate.

22. CONTACT

Passi Technologies, S.R.L.
RNC: 133131021
Calle J No. 18, La Castellana
Santo Domingo, Dominican Republic
info@gopassi.com
https://www.gopassi.com