Skip to main content
HelpFR

Privacy rights

Choose and manage a privacy request

Consent controls work on this device. Account export and deletion require the account owner; questions and appeals use the private request form below.

Your privacy controls

Before you export or delete

Four data scopes, four separate controls

A server download or deletion cannot reach every place where information may exist. Review each scope first so the result says exactly what changed and what still needs a separate action.

Deleting Otranspo records does not clear this browser, delete a shared sign-in identity, or cancel a monthly donation. Each needs its own action below.

  • This browser and device

    Local to this device

    These records stay in browser storage and remain usable without an account.

    Inspect or clear this device’s data
    Details about this data and its limits
    What this includes
    • saved places and recent searches
    • recent or active trips
    • unfinished report and crowding drafts
    • local notification inbox, map choices, language and rider preferences
    Export result
    They are not in the server export because the server cannot read them. Settings shows the local categories that this browser can inspect and clear.
    Deletion result
    Deleting Otranspo service records does not clear this browser. Clear the chosen local category in Settings on each device you used.
  • Otranspo service records

    Controlled by the signed-in owner

    These are records in Otranspo’s database that are linked to the current account.

    Go to the owner-only export
    Details about this data and its limits
    What this includes
    • private reports, contact cases and privacy requests
    • route requests, votes, proposal support and crowding submissions
    • account saves and merge history
    • journey watches, recurring journeys, devices, consents, delivery history and access grants
    Export result
    The owner-only JSON download includes current account-linked records and identifies intentionally excluded secrets such as notification addresses and replaceable encrypted coordinates.
    Deletion result
    Permanent deletion removes each covered category inside one transaction and re-counts every category before claiming success. A short pseudonymous audit and replay-safe receipt remain under their stated limits.
  • Shared sign-in identity

    Separate account-service record

    The account identifier, email, authentication methods and sessions belong to the shared Supabase identity service.

    Ask for shared account removal steps
    Details about this data and its limits
    What this includes
    • account identifier and email
    • password, passkey or configured sign-in method
    • authentication sessions and security events
    Export result
    These records are not included in an Otranspo export. The export names the processor and the boundary instead of silently copying the identity into Otranspo.
    Deletion result
    Otranspo deletion does not delete the sign-in identity. Complete Otranspo deletion first if desired, then use the private privacy intake to request the account-service steps and learn which other service sessions may be affected.
  • Donation and payment records

    Controlled by a private donation receipt

    Stripe holds card or bank details. Otranspo holds only the minimum donation, accounting, refund, dispute and optional contact records described on the funding pages.

    Open donation receipt and management help
    Details about this data and its limits
    What this includes
    • Stripe payment method and processor receipt
    • donation amount, frequency and private Otranspo receipt
    • optional encrypted contact details
    • separate optional public-recognition choice
    Export result
    Donation records are receipt-scoped rather than joined to the Otranspo account export. Otranspo never exports card or bank details because it never receives them.
    Deletion result
    Otranspo account deletion does not cancel a monthly donation or erase records under financial retention. Use the private donation receipt to manage recurrence, erase optional contact details or remove public recognition.

Opening a linked control carries only the page address and the purpose named in the link. Otranspo does not merge browser, account, journey, report, donation, or payment records across services behind the scenes.

Consent register

There is no single accept-all switch. Changing one choice affects only the purpose and records named in that row.

  • Optional analytics

    Manage optional analytics
    Applies to
    This browser
    How state is known
    Shown and changed directly below. Browser privacy signals keep it off.
    What changing it does
    Turning it off stops future optional collection, removes Otranspo-visible Google Analytics identifiers and leaves all rider tools working.
  • Exact journey monitoring and closed-page delivery

    Manage journeys and delivery devices
    Applies to
    One activated journey watch and one delivery device
    How state is known
    Granted during watch activation; browser permission alone is not consent or registration.
    What changing it does
    Ending the watch stops future checks. Revoking the registered device stops future delivery without changing other saved routes or trips.
  • Working location, live sharing and support access

    Review or revoke journey grants
    Applies to
    One active journey, recipient and short purpose
    How state is known
    Separate expiring grants are listed in Journey privacy; a location grant is not a sharing or support grant.
    What changing it does
    Revocation immediately ends that access. The replaceable working point expires within five minutes and does not create a movement trail.
  • Private contribution and any public aggregate use

    Open contribution receipts
    Applies to
    One report, observation or request
    How state is known
    Confirmed during that submission. Public rail evidence requires a second explicit choice and moderation.
    What changing it does
    Withdrawal follows the private receipt and stops future permitted use where policy allows; it does not erase already de-identified public aggregates.
  • Donation receipt or project-update contact

    Manage from a private donation receipt
    Applies to
    One private donation receipt
    How state is known
    Off until a person asks for contact and separately consents to encrypted retention.
    What changing it does
    Erasing contact removes the optional name and email while retaining only records required for accounting, refunds or disputes.
  • Public donor recognition

    Manage public recognition
    Applies to
    One donation receipt and one chosen display name
    How state is known
    Separate from contact consent and off by default. A contact name is never treated as permission to publish it.
    What changing it does
    Turning recognition off removes the name from future supporter-page output without cancelling the donation or receipt contact choice.

What works without an account

Reading rider information, changing consent on this device, and asking a privacy question do not require an account.

Access, export, correction, scoped deletion review, appeal, and permanent deletion of account-linked records require the signed-in account owner.

Saved places, recent searches, and unfinished drafts stay on this device. The server cannot export or delete them.

Manage device-only data in Settings

Access or export account-linked records

The download contains only records linked to this Otranspo account. It does not contain browser-only data or records held by the shared identity provider.

Sign in

Request access, correction, deletion review, or an appeal

Choose the smallest useful scope. Do not enter identity documents, passwords, payment details, or unrelated personal information.

Delete account-linked Otranspo data

Review every item below. This action permanently deletes the account-linked records that Otranspo can verify, while browser data, the shared sign-in identity and payment records keep their separate controls.

Deletion review

  • Account-linked reports, requests, votes, crowding submissions, private contact cases, and rider scores in the Otranspo database are deleted where no documented exception applies.
  • Device-only saves and drafts stay on this browser until you clear them in Settings; the server cannot reach them.
  • Notification endpoints and synced saves are removed only when they exist in the account-linked Otranspo systems covered by the verified deletion response.
  • Donation and payment records may have separate legally required financial retention and are not claimed deleted by this control.
  • Public aggregate statistics that no longer identify a person are not reversed.
  • After successful permanent deletion, the deleted account-linked records cannot be restored.
  • The shared authentication account is not deleted by this Otranspo-specific action.

Sign in as the account owner before submitting or changing account-linked records.

Ask a privacy question without an account

Use the private contact form for a general question or to ask for another identity-verification method. Do not send identity documents.

Open the privacy contact form