My Role
Lead Product Designer
Type
Product concept
Period
4 weeks
A privacy-first, encrypted handshake for instant multi-stop navigation transfers between passengers and drivers.
19 commuters tested the concept and every one said they'd use it. The QR handshake is designed to complete in under five seconds.
"Treating privacy as a core feature instead of an afterthought is what makes this work for commuters anywhere."
The Friction Gap Nobody Talks About
Google Maps lets you plan a perfect multi-stop route in under a minute. Then you get in a taxi and that plan stays trapped on your phone, invisible to the person actually driving.
So you're left with two bad options: shouting directions across a language barrier, or handing over your number on WhatsApp. Neither is fine. And for billions of daily taxi trips, those are the only choices.
"I usually just take the driver's phone and type the location myself. It feels invasive, but it's the only way to be sure he gets the right pin." — Commuter, London
The Research
I ran a two-phase study: a survey of 19 Dubai commuters (Google Forms, January 2026), then guerrilla interviews with both passengers and drivers about what actually goes wrong.
- 74% rated their comfort sharing a number with a driver at 1 or 2 out of 5
- 63% rely only on verbal directions to share where they're going
- 53% have avoided a multi-stop route because it was too hard to explain
- 42% worried most that the driver wouldn't know how to scan
- 100% said they'd use Route Pass ("definitely" or "if it's fast")
What the Data Told Me
Privacy is the real blocker. People weren't using risky workarounds because they wanted to. They did it because nothing safer existed. So the design starts from zero data exchange: no account syncing, no contact sharing, nothing personal crossing between devices.
The friction changes behaviour. When half your users avoid multi-stop routes because they're too hard to explain, that isn't just annoying, it's reshaping trips. Passengers become human GPS units, tense and watching every turn. The fix: load the whole itinerary at once so the driver never has to ask "where to next?"
Speed decides adoption. If it's slower than saying an address out loud, nobody uses it. The QR screen jumps to full brightness on its own and has to scan in under two seconds. Plus Codes cover the dead-signal areas.
I built the flow around two people. Maya is a privacy-conscious commuter who doesn't want to hand over her phone or her number. Samuel is a driver who'll adopt anything faster than typing in traffic, as long as it works the first time, every time.
Why QR Won
The handshake could have used NFC or Bluetooth. I ruled both out:
- QR code works with any camera, broadcasts one way, and reads from the back seat. ✓
- NFC isn't on every device, needs physical contact, and exposes data both ways. ✗
- Bluetooth is widely supported, but it's a two-way link that can leak device IDs. ✗
A QR code only sends the route the passenger chooses to share. It can't expose a device ID or anything personal. The one catch: long URLs make dense codes that fail in low light, so Route Pass compresses each route into a short link that scans cleanly even in a dark cab.
The tools people already reach for all fall short. AirDrop is Apple-only. WhatsApp means sharing your number. Uber and Careem only work inside their own apps. Google Maps is the one that runs everywhere and can put privacy first by default.
The Solution: Route Pass
How It Works in 4 Steps
1. Plan. The passenger builds their multi-stop route in Google Maps as usual.
2. Generate. They tap "Route Pass" in the share menu, and Maps packs the whole itinerary into a temporary, encrypted QR code.
3. Handshake. The passenger holds up their screen and the driver scans it from the dashboard mount. Nothing to install, nothing to pair, no personal data shared.
4. Navigate. The driver's phone reads "3 stops detected. 45 mins. Start?" and navigation begins with every stop preloaded.
The whole thing takes under five seconds.
Privacy Controls
- Mask home address. Hides the exact final stop until the driver is within 500m.
- One-time use. The link expires the moment the trip is marked complete.
- Session expiry. Route data is wiped from the driver's device 30 minutes after arrival.
Key Design Decisions
Luminance override. Opening the screen forces the phone to 100% brightness, so the driver's camera can read it through tinted glass or direct sun.
A driver screen with one job. One big confirmation, one button, large high-contrast text, no decisions to make in traffic.
Offline by default. The QR carries Plus Codes for every waypoint, so turn-by-turn still works with no signal. If the driver has Google Maps it opens right in it; a partner app or built-in meter gets the coordinates through an API.
Reflection
The biggest surprise wasn't the navigation frustration. It was the emotional weight of handing over a phone. People didn't call it inconvenient. They called it invasive, and anxious. That one insight moved my whole priority from speed to trust. Privacy wasn't a feature to bolt on at the end. It was the product.
Honest limitations. 19 respondents gives direction, not statistical confidence. A study of 100+ across several cities would put this on firmer ground. And the scan flow and driver screen stay hypotheses until they're tested with real drivers, in moving cars, in different light, on different phones.
Treat privacy as the core feature instead of an afterthought, and Route Pass works for commuters everywhere. Any device, any city, any language.