Legal
Privacy Policy
A starter outline for how BusMate handles personal and school transport information.
Draft for legal review. This general starter text is not legal advice and must be reviewed by qualified counsel before launch. Replace all placeholders and confirm jurisdiction-specific requirements.
Information we handle
BusMate may process school, administrator, driver, parent, student, route, attendance, stop, schedule, device, and activity information needed to provide the service. Schools determine the information they provide and remain responsible for having an appropriate basis to do so.
How information is used
Information is used to operate school transport workflows, provide route and status updates, send service notifications, support users, maintain security, and create accountability records.
School and child data
BusMate is designed with school-data responsibilities in mind, including awareness of FERPA and GDPR principles where applicable. The relevant school or district may act as the data controller, while BusMate acts as a service provider or processor under the governing agreement.
Storage and security
Service data is stored using Google Firebase. Administrative safeguards include role-based access and activity audit logs. No online service can promise absolute security, and the final policy should describe verified technical and organisational measures.
Sharing and retention
Information should be shared only with authorised schools, service providers, and parties required by law. Retention periods and deletion procedures must be confirmed in the final policy and applicable school agreement.
Rights and contact
Depending on location, individuals may have rights to access, correct, delete, or restrict use of personal information. Requests involving student data may need to be directed through the relevant school. Replace this section with BusMate’s verified privacy contact details.
Draft date: 18 September 2026 · Effective date: To be confirmed
