Privacy rights
Choose and manage a privacy request
Consent controls work on this device. Account export and deletion require the account owner; questions and appeals use the private request form below.
Your privacy controls
Before you export or delete
Four data scopes, four separate controls
A server download or deletion cannot reach every place where information may exist. Review each scope first so the result says exactly what changed and what still needs a separate action.
Deleting Otranspo records does not clear this browser, delete a shared sign-in identity, or cancel a monthly donation. Each needs its own action below.
This browser and device
Local to this deviceThese records stay in browser storage and remain usable without an account.
Inspect or clear this device’s dataDetails about this data and its limits
What this includes
- saved places and recent searches
- recent or active trips
- unfinished report and crowding drafts
- local notification inbox, map choices, language and rider preferences
- Export result
- They are not in the server export because the server cannot read them. Settings shows the local categories that this browser can inspect and clear.
- Deletion result
- Deleting Otranspo service records does not clear this browser. Clear the chosen local category in Settings on each device you used.
Otranspo service records
Controlled by the signed-in ownerThese are records in Otranspo’s database that are linked to the current account.
Go to the owner-only exportDetails about this data and its limits
What this includes
- private reports, contact cases and privacy requests
- route requests, votes, proposal support and crowding submissions
- account saves and merge history
- journey watches, recurring journeys, devices, consents, delivery history and access grants
- Export result
- The owner-only JSON download includes current account-linked records and identifies intentionally excluded secrets such as notification addresses and replaceable encrypted coordinates.
- Deletion result
- Permanent deletion removes each covered category inside one transaction and re-counts every category before claiming success. A short pseudonymous audit and replay-safe receipt remain under their stated limits.
Shared sign-in identity
Separate account-service recordThe account identifier, email, authentication methods and sessions belong to the shared Supabase identity service.
Ask for shared account removal stepsDetails about this data and its limits
What this includes
- account identifier and email
- password, passkey or configured sign-in method
- authentication sessions and security events
- Export result
- These records are not included in an Otranspo export. The export names the processor and the boundary instead of silently copying the identity into Otranspo.
- Deletion result
- Otranspo deletion does not delete the sign-in identity. Complete Otranspo deletion first if desired, then use the private privacy intake to request the account-service steps and learn which other service sessions may be affected.
Donation and payment records
Controlled by a private donation receiptStripe holds card or bank details. Otranspo holds only the minimum donation, accounting, refund, dispute and optional contact records described on the funding pages.
Open donation receipt and management helpDetails about this data and its limits
What this includes
- Stripe payment method and processor receipt
- donation amount, frequency and private Otranspo receipt
- optional encrypted contact details
- separate optional public-recognition choice
- Export result
- Donation records are receipt-scoped rather than joined to the Otranspo account export. Otranspo never exports card or bank details because it never receives them.
- Deletion result
- Otranspo account deletion does not cancel a monthly donation or erase records under financial retention. Use the private donation receipt to manage recurrence, erase optional contact details or remove public recognition.
Opening a linked control carries only the page address and the purpose named in the link. Otranspo does not merge browser, account, journey, report, donation, or payment records across services behind the scenes.
Consent register
Each optional use has its own decision
There is no single accept-all switch. Changing one choice affects only the purpose and records named in that row.
Optional analytics
Manage optional analytics- Applies to
- This browser
- How state is known
- Shown and changed directly below. Browser privacy signals keep it off.
- What changing it does
- Turning it off stops future optional collection, removes Otranspo-visible Google Analytics identifiers and leaves all rider tools working.
Exact journey monitoring and closed-page delivery
Manage journeys and delivery devices- Applies to
- One activated journey watch and one delivery device
- How state is known
- Granted during watch activation; browser permission alone is not consent or registration.
- What changing it does
- Ending the watch stops future checks. Revoking the registered device stops future delivery without changing other saved routes or trips.
Working location, live sharing and support access
Review or revoke journey grants- Applies to
- One active journey, recipient and short purpose
- How state is known
- Separate expiring grants are listed in Journey privacy; a location grant is not a sharing or support grant.
- What changing it does
- Revocation immediately ends that access. The replaceable working point expires within five minutes and does not create a movement trail.
Private contribution and any public aggregate use
Open contribution receipts- Applies to
- One report, observation or request
- How state is known
- Confirmed during that submission. Public rail evidence requires a second explicit choice and moderation.
- What changing it does
- Withdrawal follows the private receipt and stops future permitted use where policy allows; it does not erase already de-identified public aggregates.
Donation receipt or project-update contact
Manage from a private donation receipt- Applies to
- One private donation receipt
- How state is known
- Off until a person asks for contact and separately consents to encrypted retention.
- What changing it does
- Erasing contact removes the optional name and email while retaining only records required for accounting, refunds or disputes.
Public donor recognition
Manage public recognition- Applies to
- One donation receipt and one chosen display name
- How state is known
- Separate from contact consent and off by default. A contact name is never treated as permission to publish it.
- What changing it does
- Turning recognition off removes the name from future supporter-page output without cancelling the donation or receipt contact choice.
What works without an account
Reading rider information, changing consent on this device, and asking a privacy question do not require an account.
Access, export, correction, scoped deletion review, appeal, and permanent deletion of account-linked records require the signed-in account owner.
Saved places, recent searches, and unfinished drafts stay on this device. The server cannot export or delete them.
Manage device-only data in SettingsOptional analytics consent
Optional analytics is off on this device.
Turning optional analytics off stops future optional collection on this device immediately. The page reloads to apply the new setting everywhere.
Previously aggregated or de-identified measurements cannot be traced back to this device and therefore cannot be reversed.
Access or export account-linked records
The download contains only records linked to this Otranspo account. It does not contain browser-only data or records held by the shared identity provider.
Delete account-linked Otranspo data
Review every item below. This action permanently deletes the account-linked records that Otranspo can verify, while browser data, the shared sign-in identity and payment records keep their separate controls.
Deletion review
- Account-linked reports, requests, votes, crowding submissions, private contact cases, and rider scores in the Otranspo database are deleted where no documented exception applies.
- Device-only saves and drafts stay on this browser until you clear them in Settings; the server cannot reach them.
- Notification endpoints and synced saves are removed only when they exist in the account-linked Otranspo systems covered by the verified deletion response.
- Donation and payment records may have separate legally required financial retention and are not claimed deleted by this control.
- Public aggregate statistics that no longer identify a person are not reversed.
- After successful permanent deletion, the deleted account-linked records cannot be restored.
- The shared authentication account is not deleted by this Otranspo-specific action.
Sign in as the account owner before submitting or changing account-linked records.
Ask a privacy question without an account
Use the private contact form for a general question or to ask for another identity-verification method. Do not send identity documents.
Open the privacy contact form