← NotiBus
NotiBus Privacy Policy
Last updated: August 9, 2026
This Privacy Policy explains how NotiBus (“we”, “our”, or “us”), a product in the Noti Family, collects, uses, stores, and shares information when you use the NotiBus mobile application and related services. Our website for this product is https://notifamily.net/notibus/.
NotiBus is separate from the NotiSignal alerts app; NotiSignal has its own privacy policy.
1. Information we collect
Depending on how you use NotiBus, we may process:
- Account information. Email address and authentication data when you sign in with email/password, Google, or Apple. Profile fields such as display name, optional phone number, and preferred language.
- Organization and bus membership. Organizations and buses (groups) you create or join, roles (for example owner, admin, driver, supervisor, rider, parent), and optional organization work-profile fields (name, phone, company email, employee ID, department, notes).
- Rider and guardian information. Rider profiles (including child riders linked to guardians), guardian links, and stop/pickup details you configure (names, coordinates, optional address notes).
- Trip and route data. Routes, stops, schedules, route plans, daily trips, staff assignments, trip snapshots, activity timeline entries, and estimated arrival (ETA) records.
- Attendance and absence. Boarding, drop-off, absence, and correction events, including who recorded them and optional notes or absence reason categories.
- Precise location (drivers). When a driver starts trip tracking, NotiBus collects precise GPS data from that device, including while the app is in the background if permission is granted. See Section 3.
- Device and push data. Platform (iOS/Android), app version, and Expo push tokens when you enable notifications, plus notification preferences.
- Security and operational logs. Append-only domain/security audit events and technical logs needed to operate and secure the service (for example membership changes, account deletion requests).
- On-device data. Session tokens and offline queues stored on your device to keep you signed in and to sync when connectivity returns.
We do not use advertising SDKs, and we do not sell personal information.
2. How we use information
- Provide authentication, membership, routing, trip operations, attendance, and notifications.
- Share live trip status and ETAs with people authorized on the relevant bus/group/organization.
- Calculate routes and traffic-aware travel times using map providers (see Section 5).
- Maintain an auditable operational history for the buses and organizations you participate in.
- Secure the service, prevent abuse, and comply with legal obligations.
3. Location tracking (core feature)
Live bus location is a core NotiBus capability for active trips.
- When collected. Precise location is collected from the driver’s device after the driver starts tracking for a trip, and may continue in the background so tracking keeps working while driving. On Android, we show an in-app disclosure before requesting background location permission.
- Why. To project the bus position for authorized operational use, keep the trip timeline accurate, and compute live arrival estimates to upcoming stops and the destination.
- Who can see it. Live tracking session data is available to the driver and to authorized staff on that bus/group (such as owners, admins, drivers, and supervisors), subject to our access controls. Parents/guardians and riders receive trip status and arrival-oriented information according to their permissions; the product is designed around operations and honest ETAs rather than requiring every parent to watch a continuous map.
- Foreground location for stops. Users may also use foreground location (or map search) when setting pickup/stop locations.
- Retention. Historical driver location points older than 14 days are automatically deleted for tracking sessions that are no longer active. Location points belonging to an active tracking session (preparing, tracking, or paused) are not purged by that job. After a trip ends and the session stops, older points become eligible for the 14-day retention purge.
- Controls. Drivers can stop tracking from the Driver Console. You can revoke location permission in system settings at any time.
We do not use driver location for advertising.
4. Notifications
- If you grant notification permission, we store a push token linked to your account so we can deliver operational alerts (for example trip started, approaching a stop, boarded, delay updates), subject to your in-app preferences.
- Push delivery uses Expo’s push service together with platform services such as Firebase Cloud Messaging (FCM) on Android and Apple Push Notification service (APNs) on iOS.
- When you sign out, NotiBus revokes the current device’s push token registration for your account. Tokens may also be revoked when a push provider reports the device as unregistered.
5. Service providers
We use processors that help us run NotiBus:
- Supabase — authentication, database, realtime updates, and server functions.
- Google — optional Google sign-in; Maps SDK for map display; Routes and Places APIs (via our servers) for directions, traffic-aware duration/distance, and address search. Precise coordinates or search text needed for those features are sent to Google under Google’s terms.
- Apple — optional Apple sign-in where enabled.
- Expo — app platform services and Expo Push for notification delivery.
- Firebase Cloud Messaging (FCM) / Apple Push Notification service (APNs) — platform push delivery used with Expo Push on Android and iOS respectively.
- Device OS geocoding — may convert coordinates to approximate address labels on your device.
These providers process information in accordance with their respective terms and privacy policies and as necessary to provide the services we use.
6. Sharing within your organization
NotiBus is multi-user by design. People you invite or who share a bus/organization with you may see operational information appropriate to their role (for example manifests, attendance, trip status, and—for authorized staff—live tracking). We do not share your data with unrelated buses or organizations.
7. Retention and deletion
- Account deletion. You can delete your account in Settings. Deletion removes your login and personal profile. If you are the primary owner of an organization or the primary supervisor of a bus, you must transfer ownership or permanently delete that organization/bus first—NotiBus will not silently destroy organizations or buses that other people rely on.
- Membership. Leaving a bus or removing membership does not by itself erase historical trip records for that bus.
- Organization/bus deletion. Authorized owners may permanently delete an organization or bus (with confirmation), which removes associated operational data for that entity according to our deletion flows.
- Location history. As described in Section 3, historical driver location points older than 14 days are purged for non-active sessions.
8. Children and school use
NotiBus supports transportation involving children, including child Rider profiles managed by authorized parents, guardians, school staff, or other authorized adults. NotiBus user accounts are intended for adults and are not designed for independent use by children.
A child Rider profile may contain information necessary to provide transportation services, such as the rider’s name, assigned bus, pickup location, attendance or absence status, and trip-related information.
Parents, guardians, schools, transportation providers, and other authorized organizations should only provide or manage information about a child when they have appropriate authority and a lawful basis to do so.
Children are not expected to create accounts, manage transportation groups, or operate NotiBus independently.
NotiBus does not use children’s information for advertising and does not sell children’s personal information.
We may introduce additional child-privacy and organizational controls as NotiBus develops.
9. Your choices and rights
- Update profile and notification preferences in the app.
- Revoke location or notification permissions in system settings.
- Sign out (revokes this device’s push token registration).
- Delete your account in Settings after resolving ownership blockers.
- Contact us with privacy questions or requests (Section 11).
10. Security
We use technical and organizational safeguards designed to protect information, including encrypted network transport, authenticated APIs, and role-based backend access controls. No method of transmission or storage is 100% secure.
11. Contact
For privacy questions about NotiBus, contact support.notifamily@gmail.com or visit https://notifamily.net/.
12. Changes
We may update this Privacy Policy as NotiBus evolves. We will post the updated policy at this URL and revise the “Last updated” date. Material changes may also be communicated in the app or by email when appropriate.