One could certainly design a least authority system for bike rental. Trusted hardware to compute trip length, psuedonymous account system, untraceable payments. Identity or payment escrow in case of theft.
But really, the straightforward way is culturally. Like if there were a general expectation that a company would only use data for an immediate purpose and then delete it, employees confirmed the company culture and processes, their legal terms supported this, and there was a strong privacy law to backstop any bad actors.
But our culture is not there. We've just generally accepted that Uber will act as an attacker, exploiting their surveillance data on us as much as currently possible, storing it indefinitely to do "better" in the future, and turning it over to other third party attackers for "business purposes".
This article draws our attention because we're pretty sure if the city gets access to this data, they'll do the exact same things for their own ends - probably turning it over to the police to integrate with the ANPR data who will pass it to the feds for their own nefarious games.
It's an environment of zero trust with its corresponding high costs, which are becoming more and more apparent as wider society is hit with the implications. This is the true damage that the Surveillance Valley ethos has done, and it's going to take a hell of a long time to recover.