
The Context: When a Platform Built on Trust Faces a Trust Problem

iToll is a large-scale vehicle services platform in Iran, offering an integrated ecosystem of car ownership services including insurance, technical inspection, maintenance, and legal and administrative tasks, serving over 1 million users across the country.
One of its more operationally complex services was non-presence technical inspection: users could book online, and a verified “CarAgent” agent would collect their vehicle, complete the inspection on their behalf, and return it.
The value proposition was genuinely strong.
But the trust problem was real, and it went straight to the heart of what iToll had built its brand on.
In Iran, a personal vehicle is not simply a transportation asset. In the context of economic volatility and inflation, it often represents one of a household's most significant stores of financial value. Asking users to hand that asset over to a stranger, dispatched by a platform they may have only recently registered on, required a level of trust that no checkbox or confirmation email could manufacture. The checkout flow had not been designed with this reality in mind. The users lived it every day.
1. The Challenge: A Call Center Tells the Truth
The signal came from operations, not analytics. Inbound call center volume was spiking, and a disproportionate share of calls were coming from users who had reached the checkout flow for the inspection service and stopped.
The recurring questions revealed the exact shape of the anxiety:
- How do I know the agent is really from iToll and not someone impersonating them?
- What if they drive off with my car or cause damage during the inspection?
- How will I know where my car is during the process?
- What happens if something goes wrong, who is accountable?
These weren't edge-case concerns. They were the rational, predictable responses of people being asked to do something genuinely high-stakes with no adequate answer from the product.

Business Impact
Because iToll operates as a multi-service vehicle platform, trust breakdown in one high-stakes service carried implications beyond a single funnel. A user who perceived the inspection experience as unsafe or opaque would be less likely to engage with iToll's broader ecosystem, insurance, maintenance, and administrative services.
This made the inspection handover flow strategically important: improving trust here was not only about increasing conversion, but about protecting brand credibility in one of the platform's most sensitive service journeys.
- High abandonment at the inspection checkout step
- Operational strain on the call center
- Downstream revenue risk through weaker cross-sell opportunities for insurance bundles
2. Research Approach: Going Where the Problem Actually Lives
Rather than starting with analytics, I started with people, specifically, the people already trying to articulate their problem in real time.
Call Center Intercepts — the most valuable method
I spent several days embedded in the call center. When users called with inspection-related concerns, calls were routed to me directly for real-time interviews. This was contextual research at its most raw: users were calling mid-decision, often mid-anxiety.
35 users participated across call center intercept sessions during the discovery period.
What this method unlocked was not just pain points, it was the exact language users used to describe their fear. Not UX terminology, but the specific, culturally grounded vocabulary of distrust. That language directly shaped the copy and UI framing in the final solution.
Heatmap Analysis
I reviewed session recordings and heatmap data across the inspection service pages and checkout flow to understand where attention was going, and where it wasn't.
Key observation: Security and agent verification information existed on the page, but sat in low-attention zones: below the fold, in small print, buried in FAQ sections. At the exact moment users needed reassurance, the payment step, the information that could have helped them was not in view.
This was not a content problem. It was a placement and timing problem.
Heuristic Evaluation & Behavioral Audit
I audited the full checkout flow against core UX heuristics, focusing on:
- Visibility of system status
- Error prevention
- Help and documentation at the moment of need
Finding: The flow was designed as if the offline component didn't exist. The digital experience ended at booking confirmation, then the offline reality began, with no bridge. Users were dropped into physical uncertainty with only a confirmation message as guidance.
Literature Review
I reviewed academic and industry research on perceived risk in service handovers and digital trust models, especially work on:
- Trust beliefs vs. trusting intentions
- Visibility and control in high-risk service interactions
- Trust mechanisms in sharing-economy and agent-based service models
Cross-Functional Collaboration
I led the research direction end-to-end: identifying the trust problem through intercepts, structuring the qualitative inquiry, synthesizing behavioral patterns, and translating findings into a trust framework for the service journey.
I partnered closely with marketing on trust messaging and offline artefacts, and with product and operations stakeholders on the feasibility of verification and live-tracking mechanisms. This cross-functional setup was essential because the problem sat at the intersection of interface, field operations, and brand credibility.

3. Key Findings: Four Truths the Product Hadn't Addressed
Finding 1: The Handover, Not the Checkout, Was the True Moment of Risk
Users were not abandoning because of payment friction or unclear pricing. They were abandoning because they were being asked to mentally commit to something the product hadn't explained: handing over a high-value physical asset to a stranger.
The checkout flow was the symptom. The handover was the actual problem.
Finding 2: Users Needed Verifiable Proof, Not Generic Reassurance
Interview data showed that vague trust signals, security badges, generic “our agents are verified” copy, did not meaningfully reduce anxiety. Users wanted something specific and checkable: a name, a photo, a code they could verify.
The distinction between reassurance and proof became the organizing principle for the solution.
Finding 3: Trust Information Existed, but Appeared Too Late and in the Wrong Place
70% of interviewed users expressed anxiety specifically about the handover moment.
Yet the existing security information was positioned in pre-booking contexts or low-visibility sections. At the moment of physical handover, when a stranger arrived at the door, users had no product-provided mechanism to verify legitimacy.
The information architecture had been designed for awareness, not for decision support at the moment of highest stakes.
Finding 4: In a High-Value Asset Context, Visibility and Accountability Outweighed Convenience
A key insight from call center intercepts was that users who received live updates or had direct contact with the agent reported lower anxiety, even when the underlying process was identical.
What reduced risk was not changing the process, but making it visible.
4. The Solution: A Trustworthy Handover Model
Working across research, marketing, and product/operations, I developed the Trustworthy Handover Model, a three-layer trust architecture designed to bridge the digital booking experience with the physical reality of a high-stakes asset handover.
A key part of this work was aligning stakeholders around a reframe: these were not just “support issues” to be handled by the call center, but product trust failures that required design intervention.
Layer 1: Pre-Arrival Assurance
Goal: eliminate uncertainty before the agent arrives.
- Agent identity package sent via SMS/email after booking, including name, photo, employee ID, and a unique verification code
- Step-by-step visual explainer integrated into the booking confirmation
- FAQ module surfaced directly in the checkout step, based on the top questions from call center intercepts
Layer 2: Verification at the Door
Goal: give users a concrete, verifiable signal of legitimacy at the exact moment of handover.
- Custom agent business cards with a unique QR code per booking
- Real-time verification against the booking record
- A simple verbal protocol for agents to guide users through the verification step
The QR-enabled business card was intentionally designed as a physical artefact, not just a digital feature. In a context where trust needed to be felt, tangibility mattered.
Layer 3: Post-Handover Visibility
Goal: remove the black box between handover and return.
- Live GPS tracking of the vehicle during the process
- Status notifications at key milestones
- Direct contact channel to the agent through the app
Validation
Prototype concepts were tested iteratively with users who had either abandoned or hesitated during the inspection booking flow.
Across concept testing rounds, three elements consistently reduced perceived risk:
- Pre-arrival identity confirmation
- QR-based agent verification
- Real-time visibility into vehicle status after handover
Among these, pre-arrival identity confirmation created the strongest immediate confidence signal, while live tracking most effectively reduced post-handover anxiety.
5. Impact
Quantitative Outcomes
- Checkout conversion, inspection flow: +19% vs. prior 3-month baseline
- Call center contacts, inspection-related: −31%
The conversion increase reflected reduced hesitation at the trust-critical step in the checkout flow.
The call center reduction was even more meaningful: it showed that the product was now answering questions that previously required a human to answer.
Qualitative Signal
Post-launch interviews showed a clear shift in user language, from concerns about safety and legitimacy to statements about convenience and reliability.
The experience moved from being a source of anxiety to a source of confidence.
Platform-Level Impact
Improved trust in the inspection flow had downstream value beyond that single service. Users who completed inspection booking showed stronger engagement with related insurance products, creating commercial value from a research-led trust intervention.
6. What This Project Taught Me
The call center is the most honest research lab available.
Intercepting users mid-anxiety produced insights that no scheduled interview session could replicate.
Cultural context is not a footnote, it is an architectural constraint.
The standard UX trust toolkit would not have been enough without understanding the specific cultural and economic weight of vehicle ownership in Iran.
Physical artefacts can carry digital trust.
The business card with QR verification worked not because it was technically complex, but because it was tangible and checkable.
Framing trust failures as product failures, not user problems, unlocks stakeholder action.
Reframing inspection-related calls as unmet information needs aligned product and operations teams around design intervention instead of support escalation.
Visibility is one of the most underrated trust mechanisms in hybrid services.
Users did not need the process to be perfect. They needed to be able to see it.
This case study is based on direct research conducted during my tenure at iToll (Mar 2021 — February 2022). Metrics reflect outcomes observed and documented during my involvement. All user data referenced is anonymized.