Bussenmin
    HomeFeaturesAccessibilityHelpContactDriver registration
    HelpPrivacy Policy

    Privacy Policy

    Last updated: 01/09/2026 - Version 3.40


    🛡️ Privacy-First Design

    Your account starts completely anonymous with only your email stored. Random username and avatar are assigned automatically. All additional personalization is entirely optional and under your control.

    Table of contents

    • 1. Data Controller & Contact
    • 2. What Data We Collect
    • 3. How We Use Your Data
    • 4. Third-Party Data Processing
    • 5. Notification System & Data Handling
    • 6. Data Security and Encryption
    • 7. Data Retention and Deletion
    • 8. Your Rights Under GDPR
    • 9. Finding Friends and Social Features
    • 10. Location Data and Vehicle Tracking
    • 11. Route Rating System (Comments and Photos)
    • 12. Cookies and Local Storage
    • 13. Changes to This Privacy Policy
    • 14. Contact Information and Complaints
    • 15. Legal Basis Summary

    1. Data Controller & Contact

    Data Controller: Asadi Dev

    Address: Havnegata 101B, 3040 Drammen, Norway

    Email: info@asadidev.com

    We are committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) and other applicable privacy laws.

    2. What Data We Collect

    2.1 Essential Data (Required)

    Automatically Collected:

    • Email Address: For account authentication and security
    • Random Username: System-generated anonymous identifier
    • Random Avatar: System-generated cartoon image
    • Account Creation Date: For security and audit purposes
    • Encrypted Authentication Tokens: For secure session management

    Legal Basis: Contractual necessity (Article 6(1)(b) GDPR) - required to provide the service

    2.2 Optional Data (Your Choice)

    Only If You Choose to Customize:

    • Custom Username: If you change from the random one
    • Custom Avatar: If you upload your own image
    • Profile Preferences: Visibility settings, notification preferences
    • Social Connections: Friend requests and friendships (if you use social features)
    • Friend Messages: Encrypted message content plus the technical metadata needed to deliver and manage conversations (if you message friends)
    • Driver Colleague Messages: End-to-end encrypted text exchanged with an accepted driver colleague when this rollout is available to both accounts
    • Onboard Location Data: Your location while onboard a vehicle (only with explicit consent and automatically deleted when you get off)

    Legal Basis: Your explicit consent (Article 6(1)(a) GDPR) - you choose what to share

    2.3 Anonymous Service Data

    Anonymous Data Collection:

    • Route Ratings, Comments, and Optional Photos: Submitted without name or email, with a locally generated random feedback token (stored in localStorage) used for anti-spam and abuse prevention
    • Driver Praises: Anonymous positive feedback from passengers to drivers through predefined categories (cannot be traced back to any passenger)
    • Bussenmin App Feedback (Account-Linked, Not Anonymous): App feedback includes title, message, star rating, optional screenshot, and account-linked contact details (email, username, role) so we can follow up when needed
    • Usage Statistics: Aggregated, anonymous data about app usage patterns

    Legal Basis: Legitimate interest (Article 6(1)(f) GDPR) - improving service quality, abuse prevention, and platform safety

    Note: Route-rating submissions are anonymous and are not linked to user accounts. We use a locally generated random feedback token (stored in localStorage) only for cooldowns and abuse prevention.

    2.4 Technical Data

    Automatically Collected for Functionality:

    • Device Information: Device model, app version (for compatibility)
    • Mandatory App-Update Eligibility: To decide whether a required update applies, Bussenmin processes platform, installed app version, app language, country, authentication state and, for signed-in users, account ID and account role; verified-driver status may be checked. Authorized administrators may search by email, username, or account ID to select an account, but a campaign stores only the account ID
    • Location (For Nearby Map and Route Functions): Used in real time for nearby-vehicle calculations, county detection, and establishing the map context for mobility-map requests; it is not stored as persistent user location history
    • DATEX Road-Information Map Bounds: When an enabled Norway DATEX category is available from its minimum zoom level (12, 13, or 14), the geographic bounds of the visible map area are sent to Bussenmin's Supabase backend to return nearby informational road events or measured delay segments
    • Mobility Map Preferences: Your master on/off choice and category choices for scooters, bicycles, and shared cars are stored locally on your device and are not attached to your Bussenmin account
    • Journey Planner Inputs: Selected origin/destination points, search text, and time preference are processed to return route suggestions. These points are not traceable to your user identity
    • Journey Planner Favorites: Saved favorite routes (for example selected origin/destination and route context) are stored locally on your device for quick access and are not used to identify you personally
    • In-App Informational Content Context: Delivery and interaction context for app-related informational cards (for example anonymous device/user identifier, app version, platform, country/region, session/screen/event counters, and optional location-permission/location context when needed for relevance rules)
    • Driver Colleagues (Eligible Verified Drivers): Default activation state, verified name and driver avatar discovery, colleague requests/connections, greeting preferences, and greeting history unless you disable the feature
    • Usage Data: App crashes, performance metrics (platform-level only)
    • Session Data: Login times, feature usage (for security and functionality)
    • Friend-Messaging Metadata: Sender and recipient account IDs, registered device IDs and public keys, timestamps, content length, read/edit state, protocol version, and security/rate-limit events; message text is stored as encrypted content
    • Driver-Colleague-Messaging Metadata: Participant and connection IDs, device IDs and public keys, timestamps, declared content length, read/edit/delete state, protocol version, minimized security outcomes, and generic-push dispatch state; message text is stored only in per-device encrypted envelopes

    Legal Basis: Legitimate interest (Article 6(1)(f) GDPR) - necessary for app functionality and security

    2.5 Driver Verification System (Optional)

    Only if you choose to become a verified driver:

    • Real First Name: Only your actual first name for driver verification (not surname)
    • Verification Photo: Driver photo in driver uniform stored in separate secure storage
    • Consent Date: When you consented to driver verification
    • Display Consent: Explicit consent to display real first name and photo to passengers
    • Driver Communication: Create text and photo announcements visible to all passengers for a selected timed period or, for supported messages, the active driving session
    • Announcement Storage: Messages and photos stored for 90 days then automatically deleted
    • Saved Personal Messages: Titles, message text, and the default validity you choose for reuse are stored privately in your driver account. A saved message is not public until you send it as an announcement.
    • Saved-Message Content: The title, message text, and default validity are saved. Photos, a specific timed duration, vehicle location, and route context are selected or attached when you send and are not stored in the reusable message.
    • Saved-Message Retention: Saved messages remain until you delete them or delete your complete account. Complete account deletion removes them automatically.
    • Vehicle Data: Vehicle location and route info included with announcements

    Public messages and photos you share about route information are not anonymous. They remain visible until timed expiry or, for a driving-session announcement, until deactivation, offboarding, automatic offboarding, or the 12-hour safety limit; inactive announcements are retained under the stated 90-day period.

    Legal Basis:

    Granular Control:

    • Independent storage: Driver data stored separately from regular profile data
    • Consent withdrawal: Withdraw driver consent at any time

    2.6 Driver Registration Application via bussenmin.com Website

    If you submit a driver registration application through our website:

    Data Collected:

    • First Name: Your real first name
    • Last Name: Your real last name
    • Position: Your job position/title
    • Employment Type: Permanent, Temporary, or Substitute
    • Company Name: Your employer's name
    • Department: Your department or division
    • Email Address: For application updates and communication
    • Profile Photo: Photo of you in driver uniform (max 5MB)

    Purpose: Processing your driver verification application to grant verified driver status in the Bussenmin mobile app

    Legal Basis: Your explicit consent (Article 6(1)(a) GDPR) - Given by checking the consent box on the registration form

    Processing:

    • Data sent via email to Bussenmin administrators for review
    • Stored securely in our database for application processing
    • Photo stored in encrypted storage bucket with admin-only access

    Third-Party Processor:

    • Resend (email delivery service) - processes email delivery only
    • Privacy policy: https://resend.com/legal/privacy-policy

    Data Retention:

    • Registration data retained until you delete your account in the Bussenmin app
    • If your application is rejected, data retained until you request deletion via info@bussenmin.com
    • This ensures we maintain proof of your consent for as long as you are a verified driver

    Data Access:

    • Only Bussenmin administrators can view your registration data
    • Your data is never shared with third parties except as required by law

    Your Rights:

    • Request deletion of your application at any time
    • Access your registration data
    • Withdraw consent and request data removal
    • Contact info@bussenmin.com for any data subject requests

    2.7 Driver Praise System (Anonymous Feedback)

    Users can send anonymous positive feedback to drivers through predefined categories when a vehicle has an active driver in the app. Login is not required.

    Data Collected:

    • Praise Category: Predefined positive category selected by passenger
    • Timestamp: When the praise was sent
    • Vehicle Context: Which vehicle the passenger and driver were on
    • Driver ID: Links praise to receiving driver for their viewing
    • Seen Status: Whether the driver has viewed the praise

    Complete Passenger Anonymity:

    • No Passenger Identification: Praises contain absolutely no link to the sender
    • SHA256 Hash Rate Limiting: One praise per sender per driver per day enforced via cryptographic hash
    • Daily Sender Cap: Maximum three praises per sender per day across all drivers
    • Eligibility Checks in App: Praise is available only when location permission is granted and the selected vehicle is within the configured distance threshold
    • Hash is One-Way: Cannot reveal passenger identity under any circumstances
    • Rate Limit Records Cleaned Daily: No persistent tracking of who praised whom

    What Drivers Can See:

    • Praise Category: Which positive category was selected
    • Timestamp: When the praise was received
    • Aggregate Statistics: Total praises, today, this week, this month, this year
    • Unseen Count: Number of new praises since last viewing

    Drivers CANNOT identify which sender sent any praise.

    Administrator Access:

    Bussenmin administrators have access to praise data for the following purposes:

    • Service Quality Monitoring: Reviewing praise trends and patterns across the service
    • Abuse Prevention: Identifying and addressing potential misuse of the system
    • Category Management: Maintaining and updating predefined praise categories
    • Technical Support: Troubleshooting issues with the praise system

    Administrators CANNOT identify which sender sent which praise. Admin access is logged for audit purposes.

    Data Retention:

    • Account Deletion: All praises linked to the account are automatically deleted as part of complete account deletion (CASCADE DELETE for GDPR compliance)
    • Rate Limit Hashes: Cleaned daily, contain only anonymous cryptographic hashes
    • No Passenger Data Stored: Since no passenger identification exists, no passenger data can be deleted or exported

    Legal Basis: Legitimate interest (Article 6(1)(f) GDPR) - service improvement through anonymous feedback. No consent required from passengers as no personal data is collected.

    Why No Passenger Consent Required: Since praises are completely anonymous and cannot be traced back to any passenger, they do not constitute personal data under GDPR Article 4(1).

    2.8 Driver Colleagues (Default-Enabled Driver Feature)

    Driver Colleagues is enabled by default for eligible verified drivers who use the updated app. Other enabled verified drivers can search for your verified driver name and see your driver avatar. You can disable the feature at any time under Privacy Settings → Driver Settings.

    Activation, Name Search, and Relationships:

    • We store activation status, country code, activation source and time, any disable reason, and the automatic-greetings setting. A prior consent version and timestamp may remain for drivers who used the former join flow.
    • An enabled verified driver can search for all or part of another enabled verified driver's name. A search returns at most ten matches with verified name, driver avatar, and current colleague/request status.
    • Search does not reveal email address, phone number, employer, location, vehicle, or onboard status. Disabled and blocked drivers are excluded, and searches and requests are rate-limited to reduce abuse.
    • For abuse prevention, we store the requester's account ID, outcome category, and timestamp for seven days. The search text and identities of returned drivers are not stored in this security log.
    • Requests, responses, connections, removals, and blocks are processed with the affected account IDs, status, and timestamps. A connection is created only after acceptance.

    Automatic Greetings and What Colleagues See:

    • Automatic greetings are on by default and can be turned off under Privacy Settings → Driver Settings. Greeting notifications are controlled separately under Privacy Settings → Notifications and are also on by default. Both drivers must have automatic greetings on for a greeting to be created.
    • A greeting event stores the two account IDs, detection time, detector version, high-confidence status, a deduplication value, and delivery status/references for each recipient.
    • In the app, colleagues may see the other driver's verified name, avatar, and greeting time, together with their own retained total and counts for today, this week, this month, and the last 12 months.
    • The durable greeting event does not store raw coordinates, road geometry, route, line, or vehicle ID.
    • Request, acceptance, and greeting push notifications may include the other driver's first name. They do not contain the Colleague code, avatar, or encounter/vehicle location.

    Private Messages Between Driver Colleagues:

    • When a separate rollout is available to both accounts, accepted driver colleagues can send private text messages of up to 1,000 characters. The feature does not read onboard status, vehicle, route, movement, or location to permit messages or push notifications.
    • Message content is signed and end-to-end encrypted for each registered device. Bussenmin stores encrypted device envelopes and necessary metadata, but not plaintext. Private keys do not leave secure device storage.
    • A generic OneSignal push says only, ‘You received a new message from a driver colleague.’ It contains no sender name or message content. Push can be disabled separately and is suppressed when the conversation is already open in the foreground.
    • Messages and encrypted envelopes have no automatic age limit. They remain until the sender deletes an individual message for both participants, a colleague is removed in the updated app and the complete conversation is permanently deleted for both, a participant deletes retained history after blocking, an ended connection, or removal in an earlier app version, or an account is deleted. Earlier app versions can end a colleague connection without deleting retained history and may store a per-participant hide timestamp; hiding does not delete message content. Blocking and disabling stop new messages without automatically deleting history.
    • The data export includes readable content when this device's secure key can decrypt it and labels content unavailable when the key is missing. The first version provides blocking and support based on minimized metadata, not content reporting or plaintext access.
    • Do not use messages while driving. Read and write only when you are not driving and it is safe.

    Retention, Control, and Rights:

    • Greeting history is retained for the configured 1-365 day period (default 30 days). Minimized detector diagnostics are retained for 1-30 days (default 7 days), and short-lived encounter state expires within 15 minutes.
    • Name-search security records expire after 7 days. Activation status and historical request/connection records may be retained until account deletion for feature operation, security, and audit. Legacy code records from the former code flow may be retained for security and reuse prevention.
    • When you disable Driver Colleagues, your name and avatar are hidden from colleague search, pending requests are cancelled, short-lived encounter state is deleted, and automatic greetings and new colleague activity stop. Accepted colleagues, the automatic-greetings setting, and greeting history are preserved and become available again if you re-enable the feature.
    • Your data export includes Driver Colleagues data. Complete account deletion removes records linked to your account ID. If driver verification or driver consent is withdrawn, the feature is disabled.

    Legal basis: Our legitimate interest in providing a restricted social colleague network for verified drivers, including default activation, name discovery, relationships, automatic greetings, private messages, security, rate limiting, abuse prevention, reliability, and minimized troubleshooting (Article 6(1)(f) GDPR). You have the right to object to this processing by disabling Driver Colleagues under Privacy Settings → Driver Settings or contacting us.

    2.9 Driver Social Profiles (External Links)

    Eligible verified drivers may voluntarily submit links to their own YouTube, Instagram, TikTok, or Facebook profiles for administrator review. The feature is limited to Norway and may be turned off. It does not create a follow function or social connection in Bussenmin.

    Data We Process:

    • Account ID, platform, profile address, system-assigned display order, submission status, and timestamps.
    • The driver's confirmation that the account is their own, that the profile clearly shows bus-driver context, and that the profile has a recent driver-related post.
    • Administrator check results, status, reason, suspension reason, and review time. Existing verified driver name, employer, and department may appear in the access-restricted moderation queue to identify the correct driver.
    • For each completed submission or resubmission, we create an access-restricted, retryable email event and notify info@bussenmin.com through Resend. The email contains the event type, verified driver name, platform, and submission time. The profile address, account ID, and contact details are not included in the email.
    • On approval, suspension, reinstatement, a request for changes, or rejection, we may create an access-restricted, retryable notification event and send a targeted OneSignal push notification to the driver's external user ID. The notification may contain the platform, event type, and limited event/deep-link identifiers, but not the profile address, internal reason, or complete driver-facing message.

    Visibility and Eligibility:

    • At most two approved and current profile addresses with their platforms may appear to anonymous and signed-in passengers in the driver row. Evidence details, moderation notes, and internal check results are not public.
    • Before approval, an administrator checks that the page shows bus-driver context, contains posts about the driver job, and does not contain inappropriate content. When the account-ownership verification setting is active, ownership is also checked independently for each platform.
    • The profile must have a recent driver-related post. Approved links appear only while the driver remains eligible and an administrator has not suspended or hidden them.
    • A post or screenshot about Bussenmin is not required for social-profile approval.
    • A driver may have at most two active external social profiles, and each platform may appear only once. Pending, approved, suspended, and disabled profiles each use one slot; rejected profiles use no slot. A rejected platform may only be resubmitted through its existing record when a slot is available.

    Access, Audit, and Retention:

    • Only authorized administrators using two-factor authentication can process the moderation queue and change rollout, approval, rejection, suspension, or hiding.
    • Moderation and rollout changes are recorded in an access-restricted, append-only audit log. The log stores a SHA-256 hash instead of the raw profile address and is retained for up to three years. On account deletion, direct account identifiers are removed from retained audit entries.
    • The driver may remove a submission. The link is then hidden immediately and the main record is deleted. Full account deletion removes profile submissions and driver controls linked to the account.
    • The email outbox retains the minimized notification, delivery status, attempt count, any provider reference, and a limited error message for up to 90 days. Email failure does not change the profile submission result; the outbox retries delivery.
    • The push-notification outbox retains the recipient account ID, social-profile ID, platform, event type, revision, delivery status, attempt count, any provider reference, and a limited error message for up to 90 days. Notification failure does not change the moderation result.

    External Platforms: When you open an approved link, you leave Bussenmin and the external platform's terms and privacy rules apply. Bussenmin does not record clicks on these driver links.

    Legal basis: Processing necessary to receive, review, and display a voluntary submission is performed to provide the optional feature requested by the driver (Article 6(1)(b) GDPR). Moderation, security, abuse prevention, audit, and enforcement rely on our legitimate interest in a safe and reliable service (Article 6(1)(f) GDPR).

    2.10 Bussenmin Route Challenge (Game)

    The game is an optional simulated activity that may be opened from a selected bus departure when the feature is available. Game progress is processed independently of the app's real-time and location features.

    Data Stored Locally on the Device:

    • Personal best scores, identifiers for completed routes, tutorial state, and sound, haptic, and reduced-motion preferences are stored in local storage.
    • A temporary game session may contain a route identifier, line name, destination, selected route geometry (LineString), and stops along the selected segment. The session is held in session storage and is removed when the session ends or the web view closes.
    • Local game progress does not contain an account ID, username, email address, phone location, date played, live vehicle location, or analytics events, and scores are not uploaded to Bussenmin.
    • When you choose Drive this route, the app sends the selected service-journey identifier to Entur Journey Planner to retrieve the route shape and stops. Bussenmin does not add an account ID, username, email address, score, or phone location to this request. As with ordinary internet requests, Entur may receive technical network information such as the IP address.
    • You can delete local game progress in the game or in Data & Consent Management, including when the game is later switched off. Server-side account deletion does not automatically remove local game progress on other devices.

    Staged Availability and Administration:

    • The feature may be off, available to selected signed-in accounts, or available to everyone. When available to everyone, it can be used without an account.
    • For a selected-user pilot, we store the selected account's stable internal user ID, who added it, and the time. An access-restricted, append-only administration log stores the mode change, internal reason, administrator ID, time, and user IDs added or removed.
    • Username is used only as a search aid by an authorised administrator with current two-factor authentication. Search text is not stored in the pilot list or audit log, and email addresses are not returned by pilot search.

    Legal Basis and Retention: Processing necessary to provide the voluntarily selected game session is performed as part of the service requested by the user (Article 6(1)(b) GDPR). Administration of a limited pilot, security, abuse prevention, and audit rely on our legitimate interest in a controlled and accountable rollout (Article 6(1)(f) GDPR). Pilot membership is deleted when the account is deleted or an administrator removes the account. The audit log is retained for up to three years; the stable actor ID may remain in the log after account deletion for accountability. You may object to the processing by contacting info@asadidev.com.

    3. How We Use Your Data

    3.1 Core App Functions

    • Authentication: Secure login and account management
    • Route Matching: Calculate distances to nearby vehicles (used in real time and not stored as persistent user location history)
    • Journey Planner: Process selected trip inputs to provide route alternatives and timing estimates, including saving and managing favorite routes locally on device
    • Real-time Updates: Show live vehicle positions and delays
    • In-App Product Information: Show app-related feature updates, guidance, and usage tips (non-commercial)
    • Security: Detect unauthorized access and protect your account
    • Service Improvement: Use route ratings, comments, and optional photos to improve service quality

    Legal Basis: Contractual necessity and legitimate interest

    3.2 Optional Social Features (With Your Consent)

    • Find Friends: Allow others to find you by username or email
    • Messaging: Exchange encrypted text messages with friends and manage delivery, read, edit, block, and deletion state
    • Avatar Social Menu on the Main Map: When you are signed in, your avatar opens Friends and Messages. The avatar may show one combined attention count, while the menu identifies friend-request and unread-message counts separately. The avatar and badge do not show message text or a friend's name on the map
    • Onboard Sharing: Show your journey status to selected users (requires explicit consent for location sharing)
    • Notifications: Alert you about messages and friend requests

    Legal Basis: Legal Basis: Your explicit consent (Article 6(1)(a) GDPR) - you choose what to share

    3.3 Ask Bussenmin Support Agent

    When you use the support assistant, the app sends your question text and limited technical context to Bussenmin's backend so it can answer. If the AI feature is enabled on the backend, this may be processed by the OpenAI API. Do not type sensitive personal information into the assistant.

    • Question text: What you type into the assistant
    • Language and country: Used for the correct language and relevant help
    • Platform and app version: Used for troubleshooting and accurate guidance
    • No live transport decisions: The assistant does not receive live vehicle truth, precise location, or accessibility decisions

    Legal basis: Legitimate interest (Article 6(1)(f) GDPR) - support, troubleshooting, and service improvement.

    4. Third-Party Data Processing

    4.1 Essential Service Providers

    Supabase (Database & Authentication)

    • Purpose: Secure data storage and user authentication
    • Data Processed: Encrypted user data, authentication tokens, encrypted friend-message records and technical messaging metadata, route-rating records (including optional comments/photos), in-app informational-content delivery/interaction state, and Driver Colleagues membership, code, relationship, preference, greeting, and minimized diagnostic records
    • Boarding Signal Installation Delivery State: Account ID, app-installation ID, platform, OneSignal Subscription ID, permission/subscription/identity checks, effective delivery result, reason, and update time; no location, journey, notification text, or Button identifier
    • Location: EU data centers for European users
    • Legal Basis: Contractual necessity for service provision
    • Safeguards: EU-based hosting, encryption at rest, SOC 2 compliance

    OneSignal (Push Notifications)

    Enhanced Privacy Protection:

    • Notification Content: Most notifications are generic; Driver Colleagues request, acceptance, and greeting notifications may include the other verified driver's first name
    • Real-Time Board Reminders: Generic timetable reminder notifications (for example about 10/5/3 minutes before departure)
    • Boarding Signal Readiness: One short functional notification may include the public line code plus opaque signal-event and navigation identifiers; the notification payload contains no passenger or vehicle coordinates
    • Delivery Data: For boarding-signal readiness, Bussenmin targets the OneSignal Subscription ID of the app installation that made the Button decision. OneSignal associates that subscription with its device and external-account identifiers and receives the limited event and deep-link metadata needed to deliver and open the notification
    • Excluded Content: Driver Colleagues notifications do not include the colleague code, avatar, coordinates, road, vehicle, line, route, or message text
    • No Friend-Message Content in Push: Friend-message text and friend names are not included in the push-notification payload
    • IP Protection: IP addresses automatically excluded for EU/UK users
    • EU Compliance: EU-US Data Privacy Framework certified
    • Data Centers: EU-based for European users

    Data Automatically Collected by OneSignal:

    • Device model and app version
    • Cellular carrier (mobile devices)
    • Session duration and usage patterns
    • OneSignal ID and Subscription ID (unique device identifiers)
    • Notification delivery and engagement metrics
    • IP addresses are NOT collected from EU/UK users

    Legal Basis: Legal Basis: Your explicit consent (Article 6(1)(a) GDPR) - you choose what to share

    OneSignal's privacy policy: https://onesignal.com/privacy_policy

    4.2 Platform Analytics

    App-Store Platform Analytics:

    • Google Play Console: App crashes and performance data supplied at platform level (Android)
    • App Store Connect: Usage statistics supplied at platform level (iOS)
    • Platform-level services are controlled by Google/Apple and applicable device or account settings
    • Bussenmin does not operate a separate in-app usage-analytics service

    4.3 International Data Transfers

    Safeguards for Data Transfers:

    • EU-US Data Privacy Framework: OneSignal certification for compliant transfers
    • EU Data Centers: Primary data storage within the EU
    • Standard Contractual Clauses: Additional legal safeguards
    • Technical Measures: Encryption in transit and at rest
    • Organizational Measures: Access controls and audit trails

    5. Notification System & Data Handling

    5.1 Personal Message Notifications

    Maximum Privacy Protection:

    • Mostly Generic Content: Friend-message notifications use short generic text without message text or the friend's name; friend requests also use short generic text
    • Driver Colleagues: Request, acceptance, and greeting notifications may include the other verified driver's first name; the greeting text is localized from the OneSignal subscription language
    • Timetable reminders use generic line/stop timing data only:
    • Boarding Signal Readiness: The short title states that the signal is ready, the body states the public line code, and the action opens a fresh eligibility check; passenger and vehicle coordinates are excluded from the push payload
    • Boarding Signal Diagnostics: Bussenmin stores the passenger account ID, a hashed navigation token, locale, public line code, opaque correlation ID, send attempt and provider result, expiry, and any open result until the short-lived signal event is cleaned up. Separately, the account ID, app-installation ID, platform, OneSignal Subscription ID, permission/subscription/identity checks, effective delivery result, reason, and update time are retained as the current installation delivery state; neither record contains coordinates
    • Boarding Signal Control: The default-on functional preference is shared by the account and works only when general push-notification consent and operating-system permission are also available; it is not a second consent and cannot override a refusal. Technical delivery capability is stored separately for each app installation, and the readiness notification is targeted only to the installation that made the Button decision
    • Automatic vehicle check-off alerts use the same short reason text shown in the app when an onboard session is ended automatically:
    • Driver Colleagues Delivery Data: Recipient external user ID and limited request/event and deep-link metadata are sent to OneSignal
    • Excluded Driver Colleagues Data: Codes, avatars, coordinates, roads, vehicles, lines, routes, and message text are not included in the push payload
    • When a timetable reminder is opened, an in-app overlay may be shown and read aloud using the device's local text-to-speech engine based on app language settings:
    • Voice-over for timetable overlays can be turned on/off in the real-time board and can be muted directly from the overlay:

    5.2 Broadcast Notifications

    Types of Broadcast Notifications:

    • Security Updates: Critical security updates (Legal Basis: Legitimate Interest - cannot be disabled)
    • App Updates: New features, bug fixes (Legal Basis: Legitimate Interest - can be disabled)
    • Service Announcements: Important service changes (Legal Basis: Legitimate Interest - can be disabled)
    • Marketing and Promotions: Feature highlights, tips (Legal Basis: Your Consent - requires opt-in)

    Your Control Over Broadcast Notifications:

    • Granular Settings: Separate controls for each notification type
    • Automatic Vehicle Check-Off Alerts: Enabled by default and can be disabled in notification settings
    • Easy Opt-Out: Disable non-essential notifications at any time
    • Essential Notifications: Security updates cannot be disabled for security reasons
    • Marketing Consent: Explicit opt-in required for promotional content

    6. Data Security and Encryption

    6.1 Friend-Message Encryption

    How Friend Messages Are Protected:

    • Encryption Before Storage: Message content is encrypted by the app before it is stored by the backend
    • New Secure Format: Messages are signed and encrypted separately for each registered device; the backend stores ciphertext and technical metadata
    • Device-Key Storage: Private keys for the new format are kept in Android Keystore-backed storage or the iOS Keychain and are not uploaded to Bussenmin
    • Compatibility Conversations: Older messages use the previously shipped compatibility encryption format
    • Security Claim: The new format is being introduced in stages and is not described as independently verified end-to-end encryption or zero-knowledge encryption
    • Device Loss: Reinstalling the app, changing devices, or losing a device key can make earlier secure-format messages unavailable because key recovery is not currently provided

    6.2 Additional Security Measures

    • Data in Transit: All communication uses TLS 1.3 encryption
    • Access Controls: Row-level security policies restrict data access
    • Authentication: Secure token-based authentication with automatic expiration
    • Audit Logging: All data access and modifications are logged
    • Regular Security Reviews: Ongoing security assessments and updates
    • Route-Rating Data Protection: Route ratings are submitted without direct account identity and use pseudonymous anti-abuse identifiers

    7. Data Retention and Deletion

    7.1 Automatic Data Cleanup

    We Automatically Delete:

    • Device Tokens: Removed after 30 days of inactivity
    • Session Data: Expired tokens automatically purged
    • Location Data (Route Matching): Never stored, only used for real-time calculations
    • Onboard Location Data: Automatically deleted when your onboard session ends (manual offboard or automated technical/safety offboarding)
    • Detailed Bussenmin Button Interaction Telemetry: Automatically deleted after 90 days
    • Boarding Signal Notification Dispatch Records: Deleted with the short-lived boarding-signal event after it expires or ends
    • Boarding Signal Installation Delivery State: Retained until a later synchronization replaces it or the account is deleted
    • Coordinate-Free Driver-Signal Lifecycle Summaries: Automatically deleted after 90 days
    • Audit Logs: Retained for 3 years for legal compliance, then deleted
    • Force-Update Campaign Recipient Data: Explicit inclusion and exclusion account IDs remain while a campaign is draft, active, or paused; they are removed when the campaign is archived or the account is deleted. General audit records store recipient counts, while private rollback snapshots use account-linked UUID rows. Campaign audit and aggregate outcome history are deleted after 3 years. Aggregate outcomes contain date, campaign and revision, platform, installed version, mode, outcome, and count, not account IDs
    • Driver Colleagues Name-Search Security Records: Deleted after 7 days; search text and returned driver identities are not stored in these records
    • Driver Colleagues Encounter State: Short-lived working state expires within 15 minutes
    • Driver Colleagues Diagnostics: Minimized, bucketed diagnostics expire after the configured 1-30 day period (default 7 days)
    • Driver Colleagues Greetings: Greeting events expire after the configured 1-365 day history period (default 30 days)
    • Driver Social Profile Delivery Outboxes: Minimized administrator-email and driver push-delivery records are deleted after 90 days

    7.2 Data You Control

    • Friend Messages: Stored until an individual message is permanently deleted, the friendship is removed (which deletes the conversation), or an account is deleted
    • Secure-Messaging Devices: Device registration and public-key metadata are maintained to deliver secure messages; inactive registrations are deactivated and may be removed through account deletion or service cleanup
    • Saved Driver Messages: Stored privately until you delete them or delete your complete account
    • Profile Data: Retained until you modify it or delete your account
    • Friendships: Maintained until you remove friends or delete your account
    • Privacy Settings: Preserved until you change them or delete your account
    • Driver Colleagues: You can reject or cancel requests, remove or block colleagues, turn automatic greetings and greeting push notifications off, or disable the feature under Privacy Settings
    • Driver Social Profiles: Eligible drivers can update, resubmit, or remove their voluntary external-profile submissions in Profile and account settings

    7.3 Anonymous Data Retention

    Route-Rating and Related Service Data:

    • Route Rating Records: May be retained long-term for quality improvement, fraud/abuse analysis, moderation, and safety investigations
    • Route Rating Photos: Stored in secure object storage and may be deleted by moderation, operational cleanup, or legal compliance workflows
    • Random Feedback Token: Stored only for cooldown, anti-spam, and abuse-prevention functions
    • Aggregated Statistics: Anonymous usage patterns retained for service optimization
    • No Direct Account Identity Required: Route ratings are not required to contain your name, email, or profile identity

    7.4 Account Deletion

    Complete Data Removal:

    • Immediate Effect: Account access disabled instantly
    • Permanently: All personal data permanently deleted immediately
    • Backup Removal: Data removed from all backups and archives
    • Route-Rating Data May Remain: Certain route-rating records may remain for quality, safety, anti-abuse, or legal-compliance reasons
    • Driver Colleagues Data: Complete account deletion removes membership, codes, requests, connections, greetings, and other records linked by your account ID
    • Driver Social Profiles: Complete account deletion removes main submissions and pending delivery events linked to your account; direct identifiers are removed from audit entries retained for their lawful retention period
    • Irreversible: Deletion cannot be undone

    8. Your Rights Under GDPR

    8.1 Data Subject Rights

    Your Rights and How to Exercise Them:

    • Right of Access: Export your data anytime via Privacy Settings → "Request My Data"
    • Right to Rectification: Edit your profile, username, and settings in app settings
    • Right to Erasure: Delete your account completely via Privacy Settings
    • Right to Restriction of Processing: Disable specific features via granular privacy controls
    • Right to Data Portability: Export available account data in JSON format; encrypted message content that is unavailable on the current device may not be recoverable or decryptable
    • Right to Object: Opt out of marketing and non-essential processing
    • Right to Withdraw Consent: Change any consent-based setting instantly
    • Driver Colleagues Export and Objection: Your data export includes your Colleagues records; disabling hides you from name search, cancels pending requests, stops automatic greetings and new Colleagues activity, and preserves accepted colleagues and greeting history for restoration if you re-enable

    Note on Route-Rating Data:

    Route-rating submissions are designed to minimize direct identity collection, but comments/photos may still contain personal information entered by users. Authorized staff and administrators may review such content for moderation, safety, abuse prevention, and quality follow-up.

    8.2 How to Exercise Your Rights

    Self-Service Options (Instantaneous):

    • Privacy Settings Page: Access all privacy controls and data export
    • Profile Settings: Update personal information and preferences
    • Notification Settings: Granular control over all notification types
    • Account Deletion: Fully self-service account removal

    Contact Us For:

    • Complex data requests requiring manual processing
    • Inquiries about our privacy practices
    • Complaints about data processing
    • Technical issues with self-service options

    8.3 Response Times

    • Self-Service Actions: Instantaneous effect (data export, privacy settings, account deletion)
    • Email Requests: Response within 72 hours, completion within 30 days
    • Complex Requests: May require up to 30 days, with progress updates
    • Urgent Security Issues: Immediate response during business hours

    9. Finding Friends and Social Features

    9.1 How Finding Friends Works

    What Others Can See When Searching:

    • Your Username: Can be a pseudonym for privacy
    • Your Avatar: Can be the anonymous cartoon image
    • Your Email: Only if they search specifically by email address
    • Your Online Status: Only if you have opted in
    • No Other Information: No profile details, location, or activity data

    Your Privacy Controls:

    • Profile Visibility: Set to Public, Friends Only, or Private
    • Username Choice: Use any name you like, including pseudonyms
    • Avatar Control: Keep the random avatar or upload your own
    • No Public Directory: You only appear when specifically searched for and if you have opted in

    Legal Basis: Legitimate interest in providing friend-finding functionality (Article 6(1)(f) GDPR)

    9.2 Onboard Status Sharing

    Granular Visibility Controls:

    • Consent Required: Must explicitly enable onboard visibility
    • Visibility Options: Public, Friends Only, Only Me, or Disabled
    • Real-time Control: Change settings anytime with immediate effect
    • Auto-Offboard: Automatically removed from vehicle based on safety and technical integrity signals (for example consent withdrawal, trip/session change, stale/missing location updates, or when the vehicle is no longer active in live data)
    • Auto-Offboard Notice: A brief informational reason may be shown in the app after reopen, then cleared

    Legal Basis: Legal Basis: Your explicit consent (Article 6(1)(a) GDPR) - you choose what to share

    9.3 Driver Colleagues Discovery

    • Enabled verified drivers can search for all or part of the verified name of other enabled verified drivers. Each search returns at most ten matches and is rate-limited.
    • A search result shows verified driver name, driver avatar, and existing colleague/request status so the searching driver can confirm the recipient before sending a request.
    • This is separate from the profile visibility setting used for passenger activity. Search does not show email, phone number, employer, location, vehicle, or onboard status. Disabled and blocked drivers are not shown.

    Legal basis: Our legitimate interest (Article 6(1)(f) GDPR). You can object by disabling Driver Colleagues under Privacy Settings → Driver Settings.

    10. Location Data and Vehicle Tracking

    10.1 Location Usage for Nearby Map and Route Functions

    Privacy-First Location Handling:

    • Not Persistent User Tracking: Your location is not stored as persistent user location history
    • Real-time Functions: Used for distance calculations to nearby vehicles, determining the current county, and centring or updating the map
    • Mobility Map Requests: When Mobility is on from zoom level 15, Entur Mobility receives the geographic bounds of the visible map area and the enabled categories (scooters, bicycles, and shared cars) so it can return nearby shared-mobility options; Bussenmin does not send your account ID or email in this request
    • Network Metadata: As with ordinary internet requests, Entur may receive technical network information such as the IP address
    • Provider Links: If you choose an operator button, Bussenmin hands an Entur-reported or verified fallback link to the device so it can open the operator's app or HTTPS website. Bussenmin does not add your account ID or email to the link. The operator may receive ordinary technical or network information when the destination opens, and the operator's privacy policy applies
    • Temporary Processing: Location and map bounds used by this feature are not stored by Bussenmin as location history
    • DATEX Map Requests: The visible map bounds are sent to Bussenmin's Supabase backend, which returns enabled nearby current closures, serious incidents, planned closures, major roadworks, temporary traffic controls, or measured general-road delay segments; the bounds are not stored as user location history
    • DATEX Source Separation: The Norwegian Public Roads Administration receives requests from Bussenmin's backend, not the end user's account ID, email address, or device IP address
    • DATEX Rollout: During a signed-in allowlist pilot, the Supabase Auth user ID may be compared inside Bussenmin's backend to decide access, but it is not sent to the Norwegian Public Roads Administration
    • Device Control: You control location permission through device settings and can instead select a Norwegian county manually

    Legal Basis: Legitimate interest (Article 6(1)(f) GDPR) in providing map, nearby-area, and mobility functions. You control location access through device settings.

    10.2 Onboard Location Data (With Your Consent)

    When You Choose to Onboard a Vehicle:

    • Explicit Consent Required: You must click "Get On" to consent to location sharing
    • Vehicle Location Stored: Your location becomes the vehicle's location while you are onboard
    • Temporary Storage: Location data stored only while you remain onboard
    • Automatic Deletion: Location data automatically deleted when
    • - You click "Offboard" to leave the vehicle
    • - The system ends your onboard session based on technical/safety integrity checks
    • Consent Withdrawal: You can withdraw consent and offboard at any time

    Your Control Over Onboard Location:

    • Visibility Settings: Choose who can see your onboard status (Public, Friends Only, Only Me, or Disabled)
    • Real-time Control: Change visibility settings while onboard with immediate effect
    • Instant Removal: Offboard at any time to instantly delete your location data
    • No Historical Data: We never store where you've been, only where you are currently (if onboard)

    Legal Basis: Legal Basis: Your explicit consent (Article 6(1)(a) GDPR) - you choose what to share

    10.3 Vehicle Data (Anonymous)

    Anonymous Vehicle Analysis:

    • Vehicle Positions: Stored for real-time tracking and route information
    • Untraceable: Cannot be linked back to individual users
    • Aggregated Data: Can be used for anonymous route analysis and service improvement
    • No Personal Connection: Vehicle data is completely separate from user profiles

    Legal Basis: Legitimate interest in providing real-time vehicle information (Article 6(1)(f) GDPR)

    10.4 Screen reader mode and Bussenmin Button Assistance

    Two separate accessibility features with different on-device and background processing.

    • Two separate systems: Screen reader mode is a text-based Bussenmin interface designed for VoiceOver and TalkBack. Bussenmin Button assistance is a separate service for a paired physical Button and spoken journey help.
    • Access: Screen reader mode can be used without owning a Bussenmin Button and without signing in for anonymous functions. Sign-in, active Button access, and pairing are required for Bussenmin Button assistance.
    • Authentication in Screen reader mode: Sign-in status, sign-in, account creation, email confirmation, forgotten, reset or changed passwords, and sign-out use the same email address, account data, authentication tokens, Supabase service, and local consent and storage choices described elsewhere in this policy. Screen-reader status is not added to the account or authentication requests and does not create new personal data about disability.
    • Local screen-reader check: On Android and iPhone, the app locally asks the operating system whether a screen reader is active so the accessibility control can use the correct behavior. The result is not sent to Bussenmin, is not included in Button telemetry, and is not used to create a disability profile.
    • Automatic interface selection: When the operating system locally confirms that VoiceOver or TalkBack is active, the app selects Screen reader mode at launch, after a change while the app is open, and when the app returns to the foreground. When the screen reader is off, the ordinary interface is used. This local decision is not sent to Bussenmin and does not create a disability profile.
    • Button assistance remains separate: Automatic selection of Screen reader mode does not enable Bussenmin Button assistance, grant Button access, pair a Button, or start background location. Button assistance must be enabled separately after the prominent location disclosure and necessary system permissions.
    • Location in Screen reader mode: Screen reader mode may use the current device location in the foreground for stops, departures, and journey planning when the user has granted location permission. This follows the general location description in section 10.1 and does not start Button background location by itself.
    • Boarding and alighting signals: When the feature is available in Norway and an eligible signed-in user has enabled Bussenmin Button assistance, boarding and alighting signals are on by default. The setting can be turned off under Bussenmin Button in Screen reader mode. For a selected departure or journey, the app uses a fresh, accurate device location and fresh Entur data to decide whether a static STOP signal may appear on the user's phone. The passenger must be no more than 300 metres from the exact source platform. One exact vehicle must be before the same stop occurrence and either no more than 1,000 metres away by reliable remaining route distance or no more than 300 metres away under the restricted straight-line fallback. Service journey, operating date, vehicle, platform, and stop occurrence are checked; “vehicle at stop” is not required. Passenger readiness does not require a participating Bussenmin driver. Multiple candidates are evaluated, and an unresolved tie between the leading safe matches causes the app to wait instead of guessing. Alighting rules are unchanged. The signal switch is a functional setting and does not control consent to Button-assistance location use; that consent is withdrawn by turning Button assistance off.
    • Boarding-signal readiness notification: In this app version, the boarding-signal readiness notification rollout is turned off. Bussenmin therefore does not send this OneSignal notification, and the related notification and test controls are not shown. If notification delivery is made available later, Bussenmin may send one short functional notification through OneSignal. Its title and action will state that the boarding signal is ready and can be shown; its body will contain the public line code. Bussenmin targets the OneSignal Subscription ID of the app installation that made the Button decision. OneSignal associates the subscription with its device and external-account identifiers and receives the locale, opaque event and navigation identifiers, and expiry metadata. The push payload contains no passenger or vehicle coordinates, route geometry, stop history, complete journey, or spoken text.
    • Foreground presentation, opening, and control: When the app is visible in the foreground, the active authoritative readiness event can display the passenger signal automatically, independently of system notification delivery. A background or locked-screen boarding-signal readiness notification is not available in this app version. If this notification is enabled later and the user chooses Show signal, the native part of the app obtains a new location and sends it to Bussenmin's validation service to check distance, the active signal event, and fresh vehicle progress. The location is processed in real time and is not stored in the notification dispatch record or sent to OneSignal. The dispatch record may contain account ID, hashed navigation token, public line, locale, opaque correlation ID, attempt count, provider ID and result, error, send, expiry and open times, and a coarse open result. It is deleted with the short-lived signal event.
    • Notification preference and consent: Boarding-signal readiness notifications and their related test and delivery controls are not available in this app version because the rollout is turned off. This does not change the user's general push-notification consent or the operating system's notification permission. If the feature is made available later, its notification preference is account-wide and works only together with existing general push-notification consent, operating-system notification permission, and an active OneSignal recipient. It does not create new consent and cannot override a refusal. Technical delivery state is stored separately per app installation with account ID, app-installation ID, platform, OneSignal Subscription ID, permission, subscription and identity checks, delivery result, reason, and update time. Notification state on another signed-in device cannot overwrite the installation that made the Button decision. The preference and delivery state are retained until replaced or the account is deleted.
    • Driver recipient and live vehicle location: A driver signal may be made available only to a Bussenmin user who is registered onboard as the driver of the exact selected vehicle. An active passenger-readiness event for the same exact vehicle can trigger the driver signal without a later passenger-onboard row or separate stop-count gate. A signal is not created from a vehicle sample beyond the target stop. After creation, fresh, unambiguous Entur live location and route progress for that same exact vehicle are used to check passage; a boarding signal requires two consecutive fresh, ordered post-passage samples. An alighting signal for a planned leg ends immediately when one fresh, ordered, unambiguous sample places the exact vehicle's monitored stop occurrence after the selected destination. The driver phone's position is not used for this signal decision. This does not change other enabled onboard-location processing. Missing, stale, identity-mismatched, or ambiguous vehicle information and “vehicle at stop” are not used as passage confirmation. The signal is shown only while the app is visible in the foreground; the map does not need to be open. The priority layer may appear above an open vehicle dialog, page, or other app dialog, but it does not close the dialog or block controls outside the signal itself. Controls physically covered by the signal cannot be activated through it. The driver can end the signal manually by activating it. The driver setting is on by default when the feature is available and can be turned off in Privacy settings.
    • Minimized signal content: A short-lived readiness event on the passenger's phone may contain the passenger account ID, a hashed context reference, service journey and operating date, vehicle, source platform and stop order, public line code, route- or straight-line distance basis, rounded distances, location accuracy without coordinates, vehicle-sample time, candidate counts and outcome, lifecycle status, end reason, passage-observation count, and timestamps for activation, presentation, focus, dismissal, passage sample, and ending. It contains no passenger or vehicle coordinates, route geometry, name, email address, phone number, free text, spoken text, or raw Button ID. The separate driver signal may contain the recipient driver account ID, vehicle, journey, date and stop identifiers, line and direction, target and vehicle route offsets, Entur sample time, end reason, lifecycle times, and count/outcome for received render acknowledgements, but no raw driver, passenger, or vehicle coordinates. No SMS is sent.
    • Retention and automatic cleanup: A current signal event remains active for no more than 15 minutes. A driver boarding signal stays full-size until two consecutive fresh, ordered, unambiguous post-passage vehicle samples confirm that the target stop was passed. A driver alighting signal for a planned leg ends immediately when one fresh, ordered, unambiguous vehicle sample places the exact vehicle's monitored stop occurrence after the selected destination. Both can be ended manually by the driver and otherwise remain subject to the safety limit. Passenger readiness ends under the same two-fresh-ordered-positive-passage-sample requirement, on manual dismissal, or at the safety limit. A version 2 readiness event and its dispatch record are normally removed within about five minutes after hard expiry. Before the detailed rows are removed, a minimized, coordinate-free lifecycle summary is retained for no more than 90 days with status categories, candidate outcome, notification/signal stages, platform, and timestamps, but without journey, vehicle, or stop identifiers, notification text, or provider token. A separate coordinate-free driver-signal summary is retained for no more than 90 days with an opaque event ID, hashed context reference, signal and context type, lifecycle version, activation/render/end timestamps, and end reason. This summary contains no account, vehicle, journey, date, line, platform, or stop identifiers, coordinates, geometry, or text. Older compatibility events follow their existing short-lived rules. Other service pseudonymous deduplication controls are retained for no more than 24 hours. Passenger and driver preferences are retained until changed or the account is deleted.
    • Purpose of Button assistance: Provide spoken platform, departure, and journey information when an eligible user presses the Bussenmin Button or has active travel assistance.
    • Selected departure and selected journey: When a signed-in user explicitly selects a departure or journey for Bussenmin Button, the native part of the app stores a time-limited, account-bound context on the device. It may contain a context ID, activation and expiry times, line, destination, scheduled and expected times, Entur identifiers, names and coordinates for exact platforms, and for a planned journey also the origin, destination, and an ordered list of transit and walking legs. The context is replaced, ended, or removed on expiry, invalid state, sign-out, or when the user ends it.
    • Processing when the Button is pressed: When the Button is pressed, the active context and a fresh device position are sent to Bussenmin's decision service to check the exact departure or current leg against fresh Entur data. If a fresh position is unavailable, a stored position is not used as a substitute.
    • Exact-departure progress: For a selected departure or the current transit leg, the decision service compares consecutive fresh position observations for the passenger and the exactly matched vehicle with the line geometry and ordered stops. This is used to reject ambiguous matches, including vehicles on parallel roads, and to determine whether the vehicle served and left the selected stop. When the user accepts an early offer, the native part of the app stores the confirmation and retains the source platform locally while onboard guidance runs. The ordinary shared onboard status is published only after the existing check confirms a fresh phone location, the exact live vehicle, and proximity between them. Confirmed source passage then ends the early phase without another boarding question. If the early offer was not accepted, the existing safeguard may still ask after passage whether the passenger boarded. For a planned journey, the native part also stores locally the latest Entur sample time and a limited count of positive ordered-stop samples to ask about exit after two fresh samples beyond the target stop. These local control values are deleted when onboard guidance ends or is reset, when new guidance starts, or when the account changes. This does not change the ordinary onboard status's on/off or automatic offboarding processing. The private progress evidence in the decision service is available only to the service, expires with the selected context, and is removed by a daily cleanup.
    • Recovery after a missed departure: When the evidence shows with sufficient confidence that a selected departure was missed, the service may find the next matching departure. For a selected journey, it may send a fresh device position and the journey's already stored destination to the journey planner to propose a replacement journey. The proposal is not activated until the user confirms it.
    • Walking-distance calculation: When walking distance is enabled and can be calculated, Bussenmin's backend sends the origin coordinate and the exact platform coordinate to Entur's journey planner for a walking route. Account ID and email are not sent to Entur in this request. If the calculation fails, Bussenmin may use straight-line distance. Route geometry and step-by-step walking instructions are not stored in the selected departure or journey.
    • Prominent location disclosure and permissions: Before Button assistance is enabled for the first time, the app shows information about location use and requests the necessary system permissions. If the user does not continue or a required permission is missing, Button assistance is not enabled.
    • Background location (Android): When Button assistance is on and the user has granted “Allow all the time,” Android may use location in the background for user-initiated Button presses and active travel assistance even when the app is not open.
    • Background on iPhone: On iPhone, Button assistance may use location while the app is running in the foreground or background. If the user swipe-kills the app, iOS may stop background operation until the app is opened again.
    • Background refresh: When Button assistance is on, the app may refresh device location periodically in the background, typically around every 10 seconds and configurable, and when needed use shorter continuous updates to keep location fresh enough.
    • Stopping background refresh: When Button assistance is turned off, the periodic background refresh for Button assistance is stopped.
    • Consent and withdrawal: The user consents to the described location processing by continuing after the location disclosure and turning on Button assistance. Consent can be withdrawn by turning off Button assistance in the app or by long-pressing the physical Button when no selected departure, selected journey, or active onboard action has priority. A selected departure or journey can be ended separately without turning Button assistance off.
    • Data minimization: Button assistance uses only data necessary for spoken assistance and journey help. Location is not used for advertising, profiling, or selling data.
    • Button telemetry: When BIT-1 collection is active for an otherwise eligible Bussenmin Button user, we may record pseudonymous Button events for operations, troubleshooting, and support. These may include single, double, and long presses, automatic and in-app actions, whether processing occurred in the foreground, background, or on Android after the app task was closed, normal use, a selected departure, a selected journey, boarding confirmation, active onboard guidance or offboarding confirmation, the function performed, outcome, speech-delivery status, information basis, technical response time, and observable receipt, presentation, activation, or dismissal stages for a boarding notification. The source may be the backend, native Android, native iPhone, or a permitted foreground client. When needed to investigate a specific event, the line code, destination, and Entur identifiers for the stop place, platform, and service journey may be included. Collection does not change the Button decision or speech. Unchanged automatic monitoring may be sampled to one coordinate-free state per context and configurable interval; physical actions, errors, and important state changes are not sampled away.
    • Button telemetry data minimization: Button telemetry does not include precise or rounded user coordinates, vehicle coordinates, the full spoken text, driver-announcement content, the raw Button ID, access tokens, or whether a screen reader is active.
    • Assignment and access control: To manage Bussenmin Button hardware, Button identity may be associated with a user and device, for example with a hashed Button ID and app-generated installation ID. Cross-user access is limited to authorized administrators with a legitimate operational need and two-factor authentication.
    • Secure background submission: For background submission, the device may store a revocable, installation-scoped credential in the operating system's secure storage. The server stores only a one-way hash of the credential and continues to verify active access, pairing, and Button assignment when data is submitted.
    • Interaction telemetry retention: Detailed interaction events are automatically deleted after 90 days. Aggregated statistics without the detailed events may be retained for engineering analysis.
    • Estimated speech: When reliable real-time vehicle position is unavailable, spoken output starts with “Estimated” and uses expected departure times, not confirmed vehicle position.
    • Planned and updated arrival: For additional planned-journey information, Bussenmin may retrieve the arrival call for the exact service journey, operating date, stop, and stop occurrence from Entur. Planned time remains separate. Only a fresh matching realtime response not marked unreliable is described as updated expected or actual arrival; otherwise the app states that an updated expected arrival is unavailable. Telemetry may retain the basis category, reason, time offsets, and delay, but not spoken text.
    • Previous submissions: Contact and delivery details, agreement and consent records, feedback, and technical diagnostics previously submitted voluntarily through Bussenmin accessibility or support forms may be retained for documentation, support, troubleshooting, and follow-up according to the purpose and retention period that applied when submitted. Delivery details are kept only as long as needed for dispatch and follow-up. Other structured submissions may be kept for up to 12 months after the relevant purpose ends. Raw personal feedback is deleted on request. You can request access or deletion by contacting info@bussenmin.com; the request is verified by email. The legal bases are consent (Article 6(1)(a)), contractual necessity where a service agreement was entered into (Article 6(1)(b)), and legitimate interest in security, abuse prevention, troubleshooting, documentation, and aggregated engineering analysis (Article 6(1)(f)).

    Legal basis: For Bussenmin Button assistance and associated passenger location: your explicit consent (Article 6(1)(a) GDPR). For creating and delivering minimized boarding and alighting signals and functional boarding-signal readiness notifications within enabled Button assistance, recipient selection, the exact vehicle's fresh Entur live location and route-progress processing, data minimization, abuse prevention, and technical operation: our legitimate interest in providing and securing accessible journey assistance (Article 6(1)(f) GDPR). General push-notification delivery also relies on your existing notification consent. The passenger can object by turning the signals off under Bussenmin Button. If the readiness notification is made available later, it can be turned off under Settings → Notifications. The driver can turn signals off in Privacy settings. The local screen-reader status check and automatic interface selection are not sent to Bussenmin.

    10.5 Driver Colleagues Encounter Detection (No Phone Location)

    • Source: The backend service uses each driver's active onboard vehicle assignment and fresh public vehicle data from Entur, including vehicle ID, service-journey/line context, position, movement, and bearing.
    • Same road: Entur route geometry may be used as a prefilter, and public road data from the Norwegian Public Roads Administration's NVDB is used to check that vehicles pass in opposite directions on the same road. No account ID, name, or Colleague code is sent to NVDB.
    • No device location: The feature does not use the phone's GPS location, Bluetooth, or device motion data to detect the encounter, and it does not depend on the map or app being open.
    • Data minimization: Short-lived working state contains distances, sample counts, and a hashed road identity. Diagnostics use bucketed distance/bearing, source-data age, and outcome codes; raw coordinates are not stored in the greeting event or detector diagnostics.
    • Conservative processing: If vehicle data is stale, incomplete, or ambiguous, or the same road cannot be confirmed with high confidence, no greeting is created.

    Legal basis: Our legitimate interest in providing reliable automatic greetings with accuracy, security, abuse prevention, and minimized troubleshooting (Article 6(1)(f) GDPR). You can object by turning Automatic Greetings off or disabling Driver Colleagues under Privacy Settings → Driver Settings.

    11. Route Rating System (Comments and Photos)

    11.1 Anonymous Route Ratings

    Identity-Minimizing Design with Abuse Protection:

    • No Name/Email Requirement: Route ratings are submitted without requiring your name, email, or profile identity
    • Not Linked to User Accounts: Even when login is required to access the feature, submitted ratings are not linked to account identity
    • Optional Content: Rating value, comment text, route context, and optional photo may be stored
    • Anonymous Feedback Token: A locally generated random feedback token (stored in localStorage) is used for cooldown, anti-spam, and abuse prevention
    • Not a Hardware Device ID: The token is system-generated and is not IMEI/IDFA/Android ID
    • No Direct Identity Mapping: The token cannot directly identify a person from feedback records alone
    • Content Risk Reminder: Comments/photos are user-generated and may contain personal information

    11.2 How Route Ratings Work

    Rating Process:

    • Optional Participation: You can choose whether or not to rate routes
    • Identity-Minimized Submission: Ratings are submitted without requiring account identity
    • Optional Photo Upload: If you attach a photo, it is stored securely and linked to your rating record
    • Face Blur Before Dashboard Display: Uploaded feedback photos are automatically blurred before display in staff dashboards
    • Comment Screening: Feedback comments are screened for hate speech, threats, and abusive language; flagged content may be hidden in dashboard views
    • Service Improvement: Used to enhance route quality and service delivery
    • Aggregated Display: Only average ratings and statistics are shown to users
    • Moderation and Safety Review: Authorized staff and administrators may review original content for abuse, safety, legal review, and policy enforcement

    Legal Basis: Legal Basis: Legitimate interest (Article 6(1)(f) GDPR) - improving service quality, abuse prevention, and platform safety

    Route ratings are processed under legitimate interest (Article 6(1)(f) GDPR) for service improvement, moderation, abuse prevention, and safety. Ratings are anonymous and not linked to user accounts, while user-generated comments/photos may still contain personal information.

    12. Cookies and Local Storage

    12.1 Essential Cookies (Required)

    Necessary for App Functionality:

    • Authentication Tokens: Keep you securely logged in
    • Session Management: Maintain your app state
    • Security Tokens: Prevent unauthorized access
    • User Preferences: Remember your settings

    Legal Basis: Strictly necessary for service provision (no consent required under GDPR)

    12.2 Optional Local Storage

    With Your Consent:

    • Login Credentials: Store email for faster login (optional)
    • App Settings: Theme, language, and display preferences
    • Privacy Settings: Your consent choices and preferences

    Your Control: Disable in Privacy Settings (will log you out and clear all data)

    13. Changes to This Privacy Policy

    How We Handle Updates:

    • Notification Methods: Email, in-app notification, and website posting

    14. Contact Information and Complaints

    14.1 Contact Details

    • General Privacy Inquiries: info@asadidev.com

    14.2 Supervisory Authority

    You have the right to lodge a complaint with your local data protection authority if you believe we have not handled your personal data in accordance with the law.

    EU/EEA Residents:

    Contact your national data protection authority. A list is available at: https://edpb.europa.eu/about-edpb/board/members_en

    15. Legal Basis Summary

    Processing Activities and Legal Basis:

    • Account Management: Contractual necessity (Article 6(1)(b))
    • Security and Fraud Prevention: Legitimate interest (Article 6(1)(f))
    • Mandatory App-Update Eligibility and Administration: Legitimate interest (Article 6(1)(f)) - compatibility, security, staged-release safety, account selection, rollback, and minimized aggregate diagnostics
    • Route Matching (Location): Legitimate interest (Article 6(1)(f)) - temporary processing only
    • Boarding and Alighting Signals for Bussenmin Button: Legitimate interest (Article 6(1)(f)) - accessible journey assistance with minimized, short-lived signals; you can object by disabling the feature under Bussenmin Button
    • Journey Planner Inputs: Legitimate interest (Article 6(1)(f)) - route suggestions and service reliability
    • Journey Planner Favorites (Local Storage): Legitimate interest (Article 6(1)(f)) - user convenience and faster route access
    • In-App Product Information (Non-Commercial): Legitimate interest (Article 6(1)(f)) - feature updates, guidance, relevance, and frequency control
    • Onboard Location Storage: Your explicit consent (Article 6(1)(a)) - when you click "Get On"
    • Route Ratings, Comments, and Photos (Anonymous): Legitimate interest (Article 6(1)(f)) - service improvement, moderation, anti-spam, and abuse prevention
    • Bussenmin App Feedback (Account-Linked, Not Anonymous): Legitimate interest (Article 6(1)(f)) - app improvement, support follow-up, and service quality
    • Ask Bussenmin Support Agent: Legitimate interest (Article 6(1)(f)) - answering support questions and improving help access. Only the question text, language, country, platform, and app version are sent when the assistant is used
    • Driver Praises (Anonymous): Legitimate interest (Article 6(1)(f)) - no passenger personal data collected
    • Driver Colleagues Default Activation, Name Discovery, Relationships, Automatic Greetings, Security, Rate Limiting, Reliability, and Minimized Diagnostics: Legitimate interest (Article 6(1)(f)); you can object by disabling the feature in Privacy Settings
    • Voluntary Driver Social Profiles: Contractual necessity (Article 6(1)(b)) for submission, review, and display; legitimate interest (Article 6(1)(f)) for moderation, security, abuse prevention, audit, and enforcement
    • Finding Friends: Your consent (Article 6(1)(a))
    • Social Features: Your consent (Article 6(1)(a))
    • Push Notifications: Your consent (Article 6(1)(a))
    • Marketing (Future): Your consent (Article 6(1)(a))
    • Legal Compliance: Legal obligation (Article 6(1)(c))

    Last updated: 01/09/2026 - Version 3.40

    Effective Date: Effective Date: This privacy policy is effective immediately upon posting.

    Related documentation

    Terms of ServiceHelp
    Bussenmin

    Realtime information and practical tools for passengers, Bussenmin Accessibility and approved drivers.

    info@bussenmin.com

    Norway

    Product

    • All features
    • How it works
    • Personal and social

    Help and accessibility

    • Accessibility
    • Help
    • Driver registration

    Legal and contact

    • Privacy Policy
    • Terms of Service
    • Contact
    © 2026 Bussenmin. All rights reserved.