Public rider information
Privacy and data rights
Otranspo minimizes rider data and does not publish individual journeys or reports.
What the rider service processes
Departure and trip-planning searches are processed to answer the current request. Otranspo does not persist unsuccessful or abandoned searches and does not send exact origins, destinations, coordinates, notes, or itinerary details to analytics.
Saved places, stops, trips, and recent journeys are kept only in the current browser. They are not synchronized to an Otranspo account.
Anyone may submit a private transit report without creating an account. Anonymous evidence is weighted less than account-linked evidence, receives a private receipt, and is reviewed before any sufficiently large aggregate can appear publicly. Signing in afterward never silently links the earlier report.
A precise position used to confirm a nearby crowding observation is not stored with the observation. Only the matched vehicle, reported crowding level, coarse verification evidence, and required audit facts are retained.
Anyone may send a private contact or website-support message. The message and optional reproduction steps are encrypted. An email address is collected only when the sender asks for a reply and gives explicit consent; the message is never treated as evidence of a transit incident or published.
Optional Google Maps mode comparison
Only when a rider explicitly requests the comparison, Otranspo sends the confirmed coordinates and departure intent to Google Maps Routes to calculate driving, walking, and cycling. Place labels, saved-place names, transit itineraries, account details, and reports are not included.
The comparison response is transient and is not stored or placed in browser history by Otranspo. Core transit planning works without this comparison. Google processes the request under its own terms and privacy policy.
Access, export, correction, withdrawal, and deletion
Signed-in riders can use the authenticated privacy endpoints to export or delete account-linked Otranspo records. A deletion request preserves only legally or operationally required audit evidence in de-identified form.
An anonymous report or contact sender receives a private receipt capability. Use that receipt with the authorized privacy contact for an access, correction, withdrawal, or deletion request; it is not a public sharing link.
Do not place sensitive journey or safety information in a general contact message. Use the authorized privacy contact shown on the contact page for a rights request.
Retention
Private submitted reports are retained for up to 365 days unless an active safety review, appeal, or legal hold requires a documented extension. Idempotency and abuse-prevention records expire after 24 hours. Operational feed observations are not rider records.
A private contact case remains open while it is being triaged. Once resolved, closed, marked spam, or marked misdirected, it is scheduled for deletion after 365 days. Account-linked cases are also covered by authenticated account deletion.
Browser-only saved information remains until the rider removes it, clears site data, or the browser evicts it.
Your privacy controls
What works without an account
Reading rider information, changing consent on this device, and asking a privacy question do not require an account.
Access, export, correction, scoped deletion review, appeal, and permanent deletion of account-linked records require the signed-in account owner.
Saved places, recent searches, and unfinished drafts stay on this device. The server cannot export or delete them.
Manage device-only data in SettingsOptional analytics consent
Optional analytics is off on this device.
Turning optional analytics off stops future optional collection on this device immediately. The page reloads to apply the new setting everywhere.
Previously aggregated or de-identified measurements cannot be traced back to this device and therefore cannot be reversed.
Access or export account-linked records
The download contains only records linked to this Otranspo account. It does not contain browser-only data or records held by the shared identity provider.
Delete account-linked Otranspo data
Type CONFIRM_DELETE_ALL_OTRANSPO_DATA to confirm. This does not delete a shared authentication account.
Deletion review
- Account-linked reports, requests, votes, crowding submissions, private contact cases, and rider scores in the Otranspo database are deleted where no documented exception applies.
- Device-only saves and drafts stay on this browser until you clear them in Settings; the server cannot reach them.
- Notification endpoints and synced saves are removed only when they exist in the account-linked Otranspo systems covered by the verified deletion response.
- Donation and payment records may have separate legally required financial retention and are not claimed deleted by this control.
- Public aggregate statistics that no longer identify a person are not reversed.
- After successful permanent deletion, the deleted account-linked records cannot be restored.
- The shared authentication account is not deleted by this Otranspo-specific action.
Sign in as the account owner before submitting or changing account-linked records.
Ask a privacy question without an account
Use the private contact form for a general question or to ask for another identity-verification method. Do not send identity documents.
Open the privacy contact form