Effective 1 October 2026 · Version 2026-10-01

SchoolBus privacy notice

How SchoolBus handles child, guardian, school, trip, device, and location information.

Who uses the service

Schools administer transportation records. Guardians see only children linked to their verified school relationship and the minimum current-trip context. Assigned Drivers operate trips. Dispatchers and School Admins manage transport operations. SchoolBus Platform Admins can administer any participating school’s records, including child, trip, and bus-location information, to support and correct them on the school’s behalf; they cannot operate a trip or act as a Guardian.

Information handled

Purposes

SchoolBus uses this information to administer school transport, show an active or last-known bus position, estimate route progress, send the notices described below, diagnose failures, secure accounts, investigate incidents, enforce retention, and maintain an immutable audit trail. It is not used for advertising and is not designed to track a Driver outside an active trip or a Guardian continuously.

Processors and network services

SchoolBus uses Cloudflare for DNS, TLS proxying, edge security, and limited network logs; Railway in its EU West region for the API, website, worker, PostgreSQL/PostGIS, and Redis; Google Firebase Cloud Messaging for push delivery to Android phones and the Apple Push Notification service (APNs) for push delivery to iPhones; Resend for account email, such as password resets and the account-deletion notices sent to the SchoolBus support mailbox (hosted by Google Gmail); and OpenFreeMap for map styles and vector tiles. These providers process only the data needed for those services. A push notice’s title and text pass through the phone platform’s push service and may name a child by first name and the bus or stop, or carry the text of a school announcement. Map and edge requests may expose network metadata and the map area requested by the device. SchoolBus does not use advertising, attribution, or third-party analytics SDKs in the Family and Driver apps.

Sharing and access

School and Guardian access is role- and object-scoped. Guardians deliberately share a saved pickup point with their participating school. During an active trip, assigned school staff use the Driver location and authorized Guardians may see the assigned bus position. The system is not designed to expose another family’s child, another school’s data, raw Driver installation identifiers, or raw replay event payloads. Service providers listed above process data for SchoolBus functionality rather than advertising. Information may be preserved under a narrowly scoped, audited, time-limited incident or legal hold, or disclosed when legally required.

Notifications

SchoolBus sends Guardians push notices about their own children’s trips: when the bus sets off (not sent when all of the family’s children on that trip are marked absent); a nearby alert as the bus approaches the family’s stop or home; when the bus stops there; when a child boards at school for the trip home, arrives at school, or is brought back to school; when a pickup could not be completed or was not recorded, or a child is still on the bus because nobody was at the stop; and about trip problems: a delay, breakdown, cancellation, change of bus or staff, an operational announcement from the school, or live tracking becoming unavailable.

There is no push notice when a child boards or gets off the bus at the family’s own stop, and none when a trip ends. Guardians can switch off the nearby alert in the Family app’s notification settings. The other notices, including the trip-start notice, cannot be switched off inside the app because they concern a child’s status or safety.

Security and limitations

Controls include hashed passwords and one-time tokens, session rotation/revocation, tenant constraints, audit records, encrypted backups, rate limits, and log redaction. No system can promise absolute security, continuous GPS, exact arrival times, or delivery of every notification.

Choices and requests

The school assigns each child’s pickup point as part of the bus roster. The Family app may request the Guardian’s precise location once to help place a proposed pickup pin; the Guardian can refine the pin before sharing it. The Family app does not run continuous location tracking.

Guardians and Drivers can request deletion of their account inside the app: in SchoolBus Family, Settings → Delete account; in SchoolBus Driver, the account (person) icon at the top of the screen → Delete account. SchoolBus records the request, deletes or anonymizes the account and the personal data linked to it within 30 days, and tells the school. Requests for access or correction, and deletion requests from school staff or from anyone who can no longer sign in, go through the school or the email contact described on the deletion page and may require identity and relationship verification. Records under an active, narrowly scoped hold or a legal obligation confirmed for the operating jurisdiction may be kept only for that purpose and period.

Children and emergencies

The mobile apps are for adult Guardians and adult Drivers. Children do not create or operate mobile accounts. The service processes child transportation information under the participating school’s approved process. It is not an emergency-response service and does not replace school supervision, attendance checks, the approved call tree, or local emergency services.

SchoolBus operates the service described in this notice. Contact [email protected] for privacy or data requests. See the deletion instructions and retention statement. Effective date: 1 October 2026.