> At some level the data needs to be accessible and audit-able, otherwise what am I to do if my driver just drops me off at a different place than where I asked, or doesn't pick me up.
You're seriously arguing that cryptography has no technical means for a driver to send an unrepudiatable attestation of intent to drive from A to B at time C to an anonymous passenger? And that an ombudsman armed with driver GPS data cannot compare the attestation to the GPS data and instead needs identification data on the passenger in order to verify whether the driver went to the correct drop-off?
> You need to know that I was in their vehicle, otherwise how can they charge me if I ruin their car.
By using one of the growing number of datasets to figure out the person's identity after the fact. E.g., same thing you do if you get in a fender-bender or get cut off by a cyclist.
You can even have a multi-hour buffer for an in-vehicle cam which you consult if somebody ruins your car. But the likelihood of someone ruining the driver's car without the driver noticing is so unlikely that there is just no way it justifies collecting and keeping a company-wide database of identity data on every single passenger.
> You need to know they were my driver.
Who is arguing for driver data to be anonymous? I think nobody.
Same for GNU Taler, where the merchant data isn't private but the customer data can be.
In fact, same for E-cash from the 90s. Look up blinded tokens, they are quite fascinating from a technical perspective.