The short version
SchoolTransit exists to tell the right people — and only the right people — where a school bus and its students are. We collect the minimum needed for that, we never sell data, this website sets no tracking or advertising cookies, and every school's data is isolated from every other school.
What we collect
- Account data — name, email, phone (optional), role, preferred language, and hashed password.
- Student records — entered by the school or by guardians: name, grade, bus/route assignment, stop location, and guardian links.
- Care and health needs — where a school or guardian records them: a child’s medical note, mobility needs (wheelchair, walker, assisted), whether an aide is required, and any named-guardian handover restriction. This is health data. It is collected only so that drivers and attendants can transport a child safely and respond correctly in an incident, and it is never used for anything else. Your school is the data controller and obtains the explicit consent this category requires; we process it only on the school’s instructions. The bus-door scanner receives only the flags it must act on — never the free-text note — and every staff view of the full record is written to the access log your school can inspect.
- Trip and location data — the bus's GPS position while a driver is running a trip, and pickup/drop-off/absence events (including verified bus-card scans). While a trip is running the driver's device also derives driving events from that position and from its motion sensor — speed, harsh braking, sharp turns, route deviation and suspected impacts — which reach school staff as named alerts and form a per-driver safety score.
- Messages — in-app messages, stored encrypted (AES-256-GCM); content never appears in push notifications.
- Fees — invoices and payment records your school creates (amounts and receipt numbers; we never see card or bank details).
- Contact form — the name, email, school, and message you send us.
What we never do
- We never sell or rent personal data, and we never use student data for advertising.
- We do not track parents' or students' phone locations — only the bus, only during a trip, only shared by the driver's device.
- This website sets no analytics, marketing, or third-party cookies. The only browser storage used is your language choice and, in the portal, your own sign-in session — which is why you don't see a cookie-consent banner here: there is nothing to consent to.
Security
All traffic is encrypted in transit with TLS. Message content is encrypted at rest. Access is role-based (admin, staff, driver, parent, student) and every school's records are strictly isolated — cross-school access is refused by the server on every request, enforced in code and continuously tested. Administrative actions are recorded in an audit log.
Retention and deletion
- Live GPS positions are ephemeral — they are held in memory for live maps and are not stored as a movement history.
- Trip records (events, times, delays) are retained for the current school year plus one year, for safety investigations and attendance records, then deleted.
- Accounts and student records are kept while the account or enrolment is active.
- Deletion requests — from a guardian or a school — are completed within 90 days.
Your rights
Under Egypt's Personal Data Protection Law (Law 151/2020) and, where it applies, the EU GDPR, you can request access to, correction of, export of, or deletion of your personal data. Contact your school office (the data controller for school records) or write to us via the contact page — we respond within 24 hours and complete requests within the legal timelines. See our dedicated Egypt PDPL page.
Children
Student profiles are created and controlled by schools and guardians, not by children. Student app logins are created by the school from an existing student record and expose only that student's own bus and trips.
Changes
If this policy changes materially, schools are notified in the portal and the date above is updated.