Terms of Service
Last updated: 01/09/2026 - Version 2.48
🛡️ Privacy-First Service
Your account starts completely anonymous with only your email required. Random username and avatar are assigned automatically. Any personal information in your profile is voluntarily provided by you and fully under your control.
Data Sources and Licences: See section 15 for information about Entur Mobility, Norwegian Public Roads Administration DATEX, Kartverket, NLOD 2.0, and CC BY 4.0.
1. Service Overview & Anonymous-by-Default Design
1.1 Anonymous Account Creation:
- Your account starts completely anonymous with random username and cartoon avatar
- Only your email address is required for account functionality
- Any personal information in your profile is voluntarily provided by you
- We cannot determine what information in your profile is real vs. fictional
- You maintain complete control over your level of anonymity
1.2 User Responsibility for Personal Data:
- You control what personal information (if any) to include in your profile
- You can maintain complete anonymity by keeping the random username/avatar
- Any personal data you choose to add is your voluntary decision
- You are responsible for the content you share in messages and profile
- You can change or remove personal information at any time
1.3 Automated Onboard Integrity Controls:
- For safety and service integrity, onboard status may be ended automatically based on technical signals (for example consent withdrawal, trip/session change, stale/missing updates, or when a vehicle is no longer active in live data).
- Manual offboarding remains available at any time in the app.
- After automatic offboarding, the app may show a brief informational message with a simple explanation when you reopen the app.
1.4 In-App Information About App Features:
- We may show in-app content (video, image, or message) to inform you about new features, existing features, and how to use the app.
- This content is not third-party commercial advertising.
- Content may be contextualized (for example app version, platform, language, region, or feature usage) for relevance and frequency control.
- You can close in-app content at any time.
1.5 Journey Planner:
- The Journey Planner is an informational feature that calculates routes based on selected origin/destination points and time preferences.
- We store selected origin and destination points for route planning, but these points are not traceable to your user identity.
- You can save, activate, and remove favorite routes in Journey Planner. Favorites are stored locally on your device for quick access.
- Results may vary based on provider data, real-time changes, and network availability.
- Arrival and departure times shown beside stop names on the map for an activated route, and the compact times in Screen reader mode journey suggestions, are expected journey times based on provider data. The times may change and do not confirm that a vehicle is at the stop.
- For important trips, you should verify departure details before travel.
1.6 Bussenmin Route Challenge (Game Simulation):
- The game is an optional activity that uses the shape and stops of the selected bus departure as the basis for a short, simplified driving route. All bus movement, traffic, events, timing, and scoring in the game are simulated.
- The game is not real-time information, navigation, driver training, or a representation of a real bus's location. The visible simulation notice must be observed throughout play.
- Play only when it is safe. Do not play while driving a real vehicle, crossing a road, boarding or leaving transport, or in another situation that requires your attention.
- The game has no purchases, real money, prizes, public leaderboard, or driver status. Local progress can be deleted on the device.
- Route shape and stops are obtained from Entur Journey Planner, an Open Service under the Norwegian Licence for Open Government Data (NLOD). The game credits Entur as the source and states that Bussenmin modified the data into a game simulation.
- Bussenmin may keep the feature off, make it available to selected signed-in accounts, or open it to everyone, and may change or withdraw access. This does not affect access to transit information. We do not guarantee that a particular departure has suitable route geometry or that the game is always available.
2. Content Guidelines & Profile Standards
2.1 Profile Content Requirements:
While profile customization is optional and anonymous by default, any content you choose to add must comply with our community standards:
2.2 Prohibited Username Content:
- Hate speech, discriminatory language, or slurs
- Sexually explicit, vulgar, or profane language
- Threats, harassment, or intimidating language
- Impersonation of others or false identity claims
- Spam, promotional content, or commercial solicitation
- Content that violates intellectual property rights
- References to illegal activities or substances
2.3 Prohibited Avatar Content:
- Nudity, sexually explicit, or suggestive imagery
- Violent, graphic, or disturbing content
- Hate symbols, discriminatory imagery, or offensive gestures
- Copyrighted material without permission
- Images of other people without their consent
- Misleading or deceptive imagery
- Content promoting illegal activities
- Commercial Product Images and Logos: Images of commercial products, company logos, or images where company logos or product names are visible
- Trademark and Brand Content: Use of registered trademarks, brand names, or brand identity without explicit permission
- Product Advertising: Avatars that serve as advertisements or marketing for commercial products or services
2.4 Driver Verification Requirements:
Users who choose to become verified drivers must comply with additional requirements:
- Authentic First Name: Provide only your actual first name (not surname) for driver verification
- Uniform Photo: Verification photos must show you in driver uniform and be clear, current, and recognizable
- No False Identities: Do not use others' photos or false names for driver verification
- Consent Understanding: Understand that your real first name and uniform photo will be visible to passengers
2.4a Driver Registration Application Process:
- To become a verified driver, you must apply via our registration page at bussenmin.com/driver-registration
- Submitting the registration form constitutes acceptance of these terms and data processing as described in our Privacy Policy (section 2.6)
- We review all applications within 2 working days
- Submitting an application does not guarantee approval - we reserve the right to deny applications at our discretion
- Applications may be denied if information provided is incomplete, inaccurate, or fails to meet our verification standards
2.5 Enforcement Actions:
Violations of content guidelines may result in:
- Warning: First-time minor violations receive a warning notice
- Content Removal: Inappropriate usernames or avatars are reset to default
- Temporary Restriction: Limited access to profile customization features
- Account Suspension: Temporary account suspension for repeated violations
- Account Termination: Permanent account removal for severe or repeated violations
Additional Enforcement for Driver Verification and Announcements:
- Announcement Removal: Inappropriate announcements removed immediately
- Feature Restriction: Temporary loss of announcement creation privileges
- Driver Status Revocation: Loss of driver status for severe announcement violations
- Application Denial: Denial of driver applications for failing to meet requirements
- Verification Revocation: Revocation of driver status for repeated or severe violations
2.6 Appeals Process:
- Users may appeal moderation decisions through our support channels
- Appeals are reviewed by a different administrator than the original decision maker
- Response to appeals provided within 22 business days
- Decisions on appeals are final unless new evidence is provided
2.7 Driver Communication Features:
Feature Description:
As a verified driver, you can share route updates and photos with passengers. These announcements are public and visible to all app users.
Saved Personal Messages:
- When the feature is available for your account, you can privately save a title, message text, and default validity for later reuse.
- A saved message is not a public announcement and is not visible to passengers until you choose to send it.
- The title, message text, and default validity are stored for reuse. A photo is not stored in the reusable message. For a timed default, the specific duration is selected when sending.
- You can edit, rename, or delete your saved messages. They remain until you delete them or delete your complete account.
- When you send a saved message, it is published as a custom driver announcement linked to your driver profile, and all content guidelines in this section apply.
Validity and Deactivation:
- Timed announcements are public until the selected expiry unless the driver deactivates them or goes offboard earlier.
- When the feature is available, the Bussenmin messages “Seatbelt” and “Have a nice trip!” automatically use validity for this driving session. A driver may also choose this default for a personal saved message.
- A driving-session announcement remains public until the driver deactivates it, manually goes offboard, is automatically offboarded, or the 12-hour server safety limit is reached.
- Choosing a default validity does not make a private saved message public. It becomes public only when the driver sends it.
Eligibility:
- Must have active driver consent
- Must be verified driver
- Feature can be revoked for violations
Content Guidelines:
- Must be relevant to current route/journey
- Must be factual and not misleading
- No personal opinions about passengers
- No complaints or grievances
- Professional tone required
Photo Guidelines:
- Photos must relate to route conditions
- No faces of passengers without consent
- No license plates or identifiable vehicles (except your own bus)
- No inappropriate or offensive images
- Photos must be taken while stationary (safety)
Prohibited Announcement Content:
- Personal information about passengers
- Discrimination or harassment
- Profanity or offensive language
- Political statements or advertising
- False or misleading information
- Complaints about employer or working conditions
Your announcements are NOT anonymous. They are linked to your driver profile and visible to everyone. Think carefully about what you share.
Company Rights:
- Right to review and remove announcements
- Right to disable feature for violations
- Right to share content with employer if needed
- No liability for announcement content
Data Retention:
- Active announcements are visible until the selected expiry or, for driving-session announcements, until deactivation, offboarding, automatic offboarding, or the 12-hour safety limit
- Inactive announcements retained for 90 days
- Hard deleted after retention period
2.8 Route Rating (Anonymous, Comments and Photos):
Feature Description:
Passengers can submit route ratings with optional comment and optional photo. Ratings are displayed in aggregated form in the app.
Identity and Anonymity:
- Route-rating submissions do not require name, email, or profile identity in the submission itself
- The system uses a locally generated random feedback token (stored in localStorage) for cooldowns, anti-spam, and abuse prevention
- The token is system-generated, is not a hardware ID (such as IMEI/IDFA/Android ID), and is not linked to a user account
Prohibited Comment and Photo Content:
- Hate speech, racism, discrimination, or harassment
- Threats, violent fantasies, or incitement to violence
- Identifiable personal information about yourself or others
- Photos of people without valid consent
- Defamatory, false, or misleading content
Moderation and Enforcement:
- We may remove comments and photos without prior notice when violations are suspected
- We may restrict or disable access to the route-rating feature in case of abuse
- We may take account-level action for severe or repeated violations
- In cases of serious threats or potentially criminal conduct, information may be shared with authorities as required by law
Important About Content: Comments and photos are user-generated content. The route-rating submission itself is anonymous, but content may contain personal information entered or shown by users.
- Faces in uploaded route-rating photos are automatically blurred before display in staff dashboards
- Comments are automatically screened for hate speech, threats, and other inappropriate language; flagged content may be hidden
- Authorized staff and administrators may review original content for moderation, safety, legal review, and quality follow-up
2.9 Bussenmin App Feedback (Account-Linked, Not Anonymous):
Feature Description:
Logged-in users can submit feedback about the Bussenmin app itself with a title, message, star rating, and optional screenshot.
Identity and Visibility:
- This feedback is not anonymous
- The submission is linked to your user account (including email, username, and role)
- The information is used for follow-up, support, and service improvement
Screenshots and Content:
- Screenshots are optional, but if you upload an image you must not share sensitive information about yourself or others
- We may moderate or remove content that violates law, these terms, or our safety rules
2.10 Driver Praise System:
Feature Description:
Users can send anonymous positive feedback to drivers through predefined categories. This system is designed to recognize and encourage good driver behavior.
Participation & Eligibility:
- Users can send praise when a vehicle has an active driver in the app
- Only verified drivers with active consent can receive praise
- Login is not required to send praise
- Location permission must be granted, and the selected vehicle must be within the app distance threshold for the praise card to appear
Rate Limiting:
- One praise per sender per driver per day
- Maximum three praises total per sender per day
- Rate limiting enforced via cryptographic hash (SHA256) to maintain anonymity
- No direct tracking of which sender sent which praise
Anonymity Guarantees:
- Praise feedback is completely anonymous
- No passenger identification stored with praise records
- Drivers cannot see who sent individual praises
- The system stores the category, timestamp, vehicle context, receiving driver ID, and seen status. It does not store sender identity.
Predefined Categories:
- Praises are limited to predefined positive categories in Norwegian
- This ensures appropriate content and prevents misuse
- Categories are managed by system administrators
Data Handling & GDPR Compliance:
- All praises linked to the account are automatically deleted as part of complete account deletion (CASCADE DELETE)
- Rate limit records are cleaned daily and contain only hashed values
- Drivers can view aggregate statistics but not individual sender information
Driver Rights:
- Drivers can view their praise statistics (total, today, week, month, year)
- Drivers are notified of new praises via badge indicator
- Praises marked as 'seen' when driver views them
Acceptable Use:
- Feature intended for genuine positive feedback only
- Abuse of the system may result in feature restriction
- We reserve the right to modify or remove categories
2.11 Driver Colleagues:
Feature and Eligibility:
- Driver Colleagues is a social feature enabled by default for eligible verified drivers in the updated app. Access may be limited by country, rollout, verification status, and active driver consent.
- You can disable or enable Driver Colleagues at any time under Privacy Settings → Driver Settings. Automatic greetings are on by default and have a separate control there. Greeting notifications are controlled under Privacy Settings → Notifications.
- Enabled verified drivers can search by name and see a name and driver avatar before sending a request. Disabled and blocked drivers are excluded from search results.
Name Search and Requests:
- Name search must be used only to find drivers with whom you have, or reasonably seek, a legitimate colleague connection. You must not use it for monitoring, harassment, profiling, or commercial collection.
- A search result shows verified driver name, driver avatar, and existing colleague/request status. It does not show email, phone number, employer, location, vehicle, or onboard status.
- Search is rate-limited and returns a limited number of matches. You must check the name and avatar before sending a request and respect rejection, blocking, and no response.
- A colleague connection is created only after the recipient accepts the request. Requests can be rejected or cancelled, and connections can be removed or blocked. Blocking ends active connections and pending requests between the pair.
- Search, request, pending-request, and rejected-request cooldown limits may be applied for security and abuse prevention.
Automatic Greetings:
- An automatic digital greeting may be created only between accepted colleagues when both have automatic greetings enabled, both are recorded onboard as drivers of separate vehicles, and the backend service detects with high confidence that they passed in opposite directions on the same road.
- Detection uses active vehicle assignment, fresh public vehicle data from Entur, Entur route geometry as a possible prefilter, and public NVDB road data. It does not use the phone's GPS, Bluetooth, or motion sensors.
- Stale, missing, delayed, or ambiguous provider data may cause a real pass not to create a greeting. Greetings may also be delayed, suppressed by cooldown, or absent. We do not guarantee that every pass is detected.
- A greeting is a social courtesy, not proof that drivers physically met, and must not be used as safety, shift, payroll, employment, route, location, or incident evidence.
Private Messages Between Driver Colleagues:
- Messages is a private social feature, not employer, dispatch, shift, safety, or emergency messaging. Use emergency services and employer-approved channels when the situation requires them.
- Only accepted driver colleagues who are both eligible for the separate rollout can send new messages. Onboard status, vehicle, route, movement, and location do not restrict messages or message notifications.
- You can send text of up to 1,000 characters. Message content is end-to-end encrypted per registered device and is not stored as plaintext by Bussenmin. Loss of secure device keys can make older content unavailable.
- The sender can edit their own message for up to 24 hours and delete it for both participants. Messages have no automatic age limit. Removing a colleague in the updated app permanently deletes the complete conversation for both. Earlier app versions can end the connection without deleting history and can hide a conversation only for that participant; after updating, a participant can permanently delete retained history. Blocking or disabling stops new messages but retains history until a participant permanently deletes it or the account is deleted.
- You must not send unlawful, threatening, harassing, discriminatory, sexually explicit, deceptive, or unwanted content; sensitive personal data; passwords or security codes; or content that infringes others' rights. Do not impersonate others or automate bulk messages.
- Do not use messages while driving. Read and write only when you are not driving and it is safe.
Notifications, History, and Control:
- Request, acceptance, and greeting notifications may include the other verified driver's first name. They do not include the Colleague code, avatar, or encounter/vehicle location. Language is selected from the OneSignal subscription's phone language.
- Greeting push is controlled by Colleague Greeting Notifications under Privacy Settings → Notifications. Request/acceptance notifications have a separate category there. All push also requires the phone's system permission. Turning push off does not delete requests, connections, greeting history, or in-app badges.
- The Greetings view may show the other colleague's verified name, avatar, and time, plus the retained total and counts for today, this week, this month, and the last 12 months. History appears only while retained under the current retention setting.
- When you disable Driver Colleagues in Privacy Settings, you are hidden from name search, pending requests are cancelled, and automatic greetings and new colleague activity stop. Accepted colleagues, preferences, and greeting history are preserved and reappear when you enable the feature again. Complete account deletion and data export are handled as described in the Privacy Policy.
Safe and Acceptable Use:
- Do not interact with the app manually while driving. The digital greeting is automatic and requires no action during the pass. Always follow traffic laws, employer requirements, and safe-driving practices.
- You may not automate, bulk-test, scrape, profile, sell, or publish search results; send harassing or unwanted requests; impersonate another driver; or manipulate onboard status, vehicle data, or detection.
- Misuse may result in restricted or removed feature access, blocked requests, or other enforcement under these Terms.
2.12 Driver Social Profiles:
- The feature is optional, limited to eligible verified drivers in Norway, and may be turned off. It does not create a follow function in Bussenmin.
- You may submit only your own YouTube, Instagram, TikTok, or Facebook profile. The profile must clearly show that you are a bus driver and contain posts about the driver job.
- The profile must contain a recent post about the driver job.
- When Bussenmin requires separate account-ownership verification, ownership must be approved for each submitted platform. A post or screenshot about Bussenmin is not an approval requirement.
- You may have at most two active external social profiles, and you may not have two profiles on the same platform. Pending, approved, suspended, and disabled profiles each use one slot. Rejected profiles use no slot. When two slots are in use, you cannot submit a third platform or resubmit a rejected profile, but you may update a profile that already uses a slot. A slot becomes available when a submission is removed or rejected.
- A rejected platform remains as its existing record and may be resubmitted when a slot is available; it cannot be added as a new duplicate.
- Each completed submission and resubmission notifies info@bussenmin.com so an administrator can process the review. Email delivery occurs separately and does not affect whether the submission was received.
- You may receive a targeted OneSignal push notification when a profile is approved, suspended, reinstated, needs changes, or is rejected. Delivery failure does not change the moderation result. The platform name may appear in the notification, but the profile address and internal reasons are not included.
- The profile and posts must be appropriate and must not be offensive, hateful, harassing, discriminatory, sexually explicit, illegal, misleading, or otherwise improper. You must follow your employer's rules and the external platform's terms.
- All links are manually reviewed before display. Bussenmin may reject, request changes, suspend, disable, or hide a link or a driver's links, and may turn off the entire feature immediately.
- External profiles and posts are the driver's own content. Approval only means the display requirements were checked; it is not an endorsement of all profile content. When a passenger opens the link, the external platform's terms and privacy rules apply.
- Do not use the app or manage social profiles while driving. You may remove a submission from Settings when the feature is available.
3. Administrative Monitoring & Platform Oversight
3.1 Scope of Administrative Access:
By using our service, you acknowledge and consent that our administrators have the authority to access and monitor:
- Profile Data: Your username, avatar, email, and account information regardless of privacy settings
- Online Activity: Your online/offline status, last seen information, and login patterns
- Platform Usage: Feature usage, friendships, and system interactions
- Message Metadata: Sender and recipient account IDs, device IDs and public keys, timestamps, content length, protocol version, and read/edit state; message text is stored as encrypted content
- Technical Data: Device information and system diagnostics
- Privacy Settings: Your consent choices and preference changes
- Notification Data: Delivery status and engagement metrics
3.2 Purposes of Administrative Monitoring:
- Security: Detecting fraud, unauthorized access, and security threats
- Safety: Preventing harassment, abuse, and harmful behavior
- Content Moderation: Enforcing community guidelines and content standards
- Compliance: Enforcing Terms of Service and community guidelines
- Legal: Responding to legal requests and regulatory requirements
- Technical: System maintenance, troubleshooting, and service improvement
- Support: Providing customer support and resolving user issues
- GDPR Compliance: Processing data subject requests and consent management
3.3 Administrative Actions:
Administrators may take the following actions based on monitoring results:
- Edit or reset usernames that violate guidelines
- Remove or replace inappropriate avatars
- Modify user roles and permissions
- Temporarily or permanently block user accounts
- Delete accounts for serious violations
- Restrict access to specific features
- Process GDPR data subject requests
- Manage consent withdrawals and account deletions
3.4 Limitations and Safeguards:
- The new secure message format is designed so ordinary backend and administrator operations store and process encrypted message content rather than plaintext. This is not an absolute zero-knowledge or independently verified end-to-end guarantee
- Access is limited to authorized personnel with legitimate need
- Monitoring is conducted in accordance with applicable privacy laws
- Users will be notified of administrative actions when appropriate
- Privacy settings are respected except for legitimate administrative purposes
3.5 User Acknowledgment:
You understand that:
- Privacy settings do not restrict administrative access for legitimate purposes
- Administrative monitoring is necessary for platform operation and safety
- Refusing administrative access may result in service limitations or termination
- You can request information about administrative actions on your account
- Administrative access is subject to internal controls and audit procedures
4. Privacy & Data Protection
4.1 Comprehensive Privacy Controls:
- Granular Settings: 15+ individual privacy and notification controls
- Real-time Effect: All privacy changes take effect immediately
- Consolidated Storage: All preferences stored in single, secure location
- Audit Trail: Complete history of all consent and privacy changes
- Self-Service Rights: Exercise GDPR rights directly through the app
4.2 Data Minimization Principles:
- We collect only your email address as required data
- Random username and avatar are system-generated (anonymous)
- All profile customization is optional and user-controlled
- Message content is encrypted before storage; technical messaging metadata is processed for delivery, security, and conversation management
- Your location is not stored as persistent user location history
- Most notification content is generic. Driver Colleagues request, acceptance, and greeting notifications may include the other verified driver's first name, but not the Colleague code, avatar, or encounter/vehicle location
4.3 Your GDPR Rights:
- Right to Access: Export your data instantly via 'My Data'
- Right to Rectification: Edit profile and preferences anytime
- Right to Erasure: Delete your account completely with one click
- Right to Restrict: Disable specific processing activities
- Right to Portability: Download your data in JSON format with full decryption
- Right to Object: Opt out of marketing and non-essential processing
- Right to Withdraw Consent: Change any consent-based setting instantly
4.4 Screen reader mode and Bussenmin Button Assistance:
- Screen reader mode and Bussenmin Button assistance are two separate, optional features. Screen reader mode is a text-based Bussenmin interface designed for VoiceOver and TalkBack. Button assistance uses a physical Bussenmin Button for spoken journey help.
- Screen reader mode may be offered in the Norway Android and iPhone app when the operating system reports that a screen reader is active and the feature is available in the current rollout. It can be used without owning a Bussenmin Button and without signing in for anonymous functions.
- Authentication is a complete process in Screen reader mode and is separate from Settings. When the user is signed out, a separate Log in action provides access to sign-in, account creation, and forgotten-password recovery. Confirmation and recovery links return to the correct step in Screen reader mode. When the user is signed in, a separate Log out action is shown. The same account terms, password rules, email-confirmation requirements, and acceptance of these Terms and the Privacy Policy apply as in the ordinary interface.
- When the operating system locally confirms that VoiceOver or TalkBack is active, the app selects Screen reader mode at launch, after a change while the app is open, and when the app returns to the foreground. Ordinary system dialogs may appear first. When the screen reader is off, the ordinary interface is used.
- Screen reader mode can be used without a physical Bussenmin Button. While the screen reader remains active, Screen reader mode is the accessible passenger interface; a separate speaking version of the ordinary map interface is not offered.
- Automatic selection of Screen reader mode does not enable Bussenmin Button assistance, grant Button access, pair a Button, or constitute consent to background location. In Screen reader mode, Button assistance is controlled separately by choosing Bussenmin Button from the main options.
- Bussenmin Button assistance requires sign-in, active Button access for the account, a paired Button, and the necessary Bluetooth and location permissions. Screen reader mode alone does not grant Button access, pair a Button, or constitute consent to Button background location.
- A user who meets the requirements may explicitly select one exact departure from Timetable or one reviewed journey from the journey planner for Bussenmin Button. The selection temporarily changes the meaning of Button gestures. The user can end the selection on screen or by holding the Button; this ends the selection but does not turn Button assistance off. A new selection may require confirmation that it should replace the old one.
- A selected departure and selected journey are time-limited information contexts. They may expire, become invalid, be replaced, or require replanning if the departure, service journey, platform, or next leg can no longer be confirmed reliably. Bussenmin does not guarantee that a connection will be held or that a transfer can be completed.
- When the Norway rollout makes the feature available and an eligible signed-in user has enabled Bussenmin Button assistance, boarding and alighting signals are on by default for a selected departure or journey. They can be turned off under Bussenmin Button in Screen reader mode. A boarding signal may become ready when a fresh, accurate location shows that the user is no more than 300 metres from the exact source platform and one exact live vehicle is before the same stop occurrence and either no more than 1,000 metres away along reliable remaining route distance or no more than 300 metres away under the restricted straight-line fallback. Identity and stop occurrence must match; “vehicle at stop” is not required. Multiple candidates are evaluated without automatic rejection, but the app does not guess when the leading safe matches remain tied. Passenger readiness does not require a participating Bussenmin driver. In this app version, the boarding-signal readiness notification is turned off, so no system notification is sent and the related notification controls are not shown. When the app is visible in the foreground in Screen reader mode or the ordinary interface, the signal is displayed automatically from the active readiness event. During an early onboard offer, Bussenmin states that the signal is ready in the app only after confirming the active signal event; otherwise only that sentence is omitted. If background notification delivery is made available later, opening from it requires a new native location and successful validation of the active signal, distance, and fresh vehicle progress. The existing distance and time rules for alighting signals are unchanged.
- A green boarding signal or blue alighting signal may appear to a Bussenmin user who is registered onboard as the driver of the exact selected vehicle, has the app visible in the foreground, and has not turned the signals off. The map does not need to be open. The signal appears as a priority layer above the current app content, including an open vehicle dialog, page, or other app dialog. The signal does not close or block the app dialog underneath; controls outside the signal remain usable, while controls physically covered by the signal cannot be activated through it. An active passenger-readiness event for the same exact vehicle can create the driver signal without waiting for a later passenger-onboard row or separate stop-count gate. A new signal is never created from a vehicle sample beyond the target stop. Fresh, unambiguous Entur route progress for the exact vehicle, not the driver phone's position, determines passage. A blind-person-with-cane icon and two-row text identify boarding or alighting and the target stop. The first row shows the icon and action; the second row shows the complete stop name with the same text formatting. The signal retains the narrow control width when the text fits, but may expand when needed, never beyond the vehicle dialog width. Long stop names wrap instead of being shortened. The line is not shown. On the map, the signal covers the county/line selectors and bus-number search. It remains while the vehicle waits at the stop. A boarding signal ends automatically after two consecutive fresh, ordered, unambiguous post-passage samples. An alighting signal for a planned leg ends immediately when one fresh, ordered, unambiguous vehicle sample places the exact vehicle's monitored stop occurrence after the selected destination. Otherwise, the 15-minute safety expiry applies at the latest. Missing, stale, or ambiguous vehicle information and “vehicle at stop” are not used to determine passage. When safe, the driver can activate the signal to dismiss it manually; otherwise no action is required. The signal is not sent by SMS; a recorded event at the preceding stop is not required.
- Bussenmin gives the passenger no read, delivery, or attention receipt. The passenger signal does not replace ordinary signalling at the stop, operator procedures, the driver's road-safety judgment, or public-transport rules; it creates no special duty for the driver or operator and does not guarantee that the vehicle will stop or that boarding or alighting will succeed.
- For a selected departure or the current transit leg, Bussenmin may offer onboard guidance before the vehicle reaches the platform when fresh data matches the exact service journey, operating date, physical vehicle, source platform, and stop occurrence; the passenger is no more than 300 metres from the platform; the vehicle's reliable remaining distance along the locked route is no more than 1,000 metres; and there is no positive evidence that the vehicle has passed. Straight-line distance of no more than 300 metres may be used as a limited fallback when route geometry is unavailable, identity is exact, and the stop sequence still shows that the vehicle has not passed. Vehicle at stop is neither required nor used for ranking. The offer requires an explicit Button action, and one click confirms intended boarding and starts onboard guidance. Onboard guidance never starts automatically.
- When onboard guidance starts early, the exact source platform and stop occurrence are retained until fresh, positive route progress shows passage. Before passage, Bussenmin may continue to state that guidance started early, the vehicle's remaining route distance, the number of stops before the platform, and the reported current position and next stop. Shared onboard status and the map marker are published only when the existing check confirms a fresh phone location, the exact live vehicle, and proximity between them. A timeout, missing update, or changed Vehicle at stop value is not by itself evidence of passage.
- When the passenger already accepted the early offer, that action is the routine boarding confirmation. When fresh, unambiguous route progress later confirms that the exact vehicle passed the source platform, the early phase ends without another boarding question and onboard guidance continues. If the early offer was not accepted, the existing safeguard may still ask after passage whether the passenger boarded and may offer the next confirmed departure or a replacement journey after a negative answer.
- For a planned journey, Bussenmin states the target stop when onboard guidance starts. When the stop before the target becomes the next stop, it states that the following stop is where the passenger should get off; when the target is next, it says so directly. After two consecutive fresh, ordered samples show that the exact vehicle passed the target stop, Bussenmin asks whether the passenger got off. One click confirms exit and ends or advances to the next leg; a double click or no answer keeps onboard guidance running. Passenger distance and Vehicle at stop are not used as passage confirmation. On the final transit leg, a double click combines the exit stop and updated expected or actual time in one item instead of repeating the same destination as both planned exit and planned arrival. Separate transfer information remains when available.
- If the user does not move with a departure that is confirmed with sufficient confidence as missed, Bussenmin may offer the next matching departure. For a selected journey, Bussenmin may propose a replacement journey from the user's fresh position to the stored destination, including after a missed connection. A replacement proposal requires the user's confirmation before it is activated. Later missed departures may be handled in the same way until the user ends the selection or no valid departure or journey is available.
- Vehicle distance stated for a selected departure is calculated along the confirmed line geometry when it can be matched unambiguously. If the line geometry or vehicle match is ambiguous, Bussenmin must omit the distance or clearly use estimated information instead of claiming that the vehicle is at the stop.
- A stated walking distance is an approximate routed calculation to the exact platform. If it cannot be calculated, the app may state straight-line distance. Neither is step-by-step navigation, identifies a safe crossing place, or guarantees that the walking route is accessible, free of temporary obstacles, or safe to follow.
- Before Button assistance is enabled for the first time, the user must continue after the prominent location disclosure and grant the necessary system permissions. If the user chooses “Not now” or a required permission is missing, Button assistance is not enabled.
- The user may withdraw consent to Button location processing by turning off Button assistance in the app or by long-pressing the physical Button when no selected departure, selected journey, or active onboard action has priority. When such a context has priority, holding the Button ends the context instead of turning assistance off.
- Screen reader mode follows the locally confirmed screen-reader state. Button assistance remains off when it has been turned off even if VoiceOver or TalkBack is active, and must be enabled separately by the user.
- On Android, Button assistance may use background location for user-initiated Button presses and active travel assistance when the user has granted “Allow all the time.” It may continue when the app is not open.
- On iPhone, Button assistance may work while the app is running in the foreground or background. If the app is swipe-killed, iOS may stop background operation until the app is opened again.
- When Button assistance is on, the app may refresh location periodically in the background, typically around every 10 seconds and configurable, and use fresh location and real-time data for spoken stop and journey guidance. The refresh stops when Button assistance is turned off.
- When BIT-1 collection is active for an otherwise eligible Bussenmin Button user, the service may store pseudonymous interaction events for operations, support, and troubleshooting about physical, automatic, and in-app actions; foreground/background context; normal use, a selected departure, a selected journey, confirmation or onboard mode; the function performed; outcome; speech-delivery status; information basis; response time; arrival basis; and observable notification/signal lifecycles. Unchanged automatic monitoring may be limited to a configurable coordinate-free heartbeat, while actions, errors, and important transitions remain. Minimized coordinate-free readiness and driver-signal lifecycle summaries may survive the short-lived detailed rows. Detailed events and the summaries are automatically deleted after no more than 90 days. Telemetry does not include precise or rounded user coordinates, vehicle coordinates, full spoken text, notification text, provider tokens, driver-announcement content, the raw Button ID, access tokens, or screen-reader status.
- Screen reader mode and Button assistance are assistive tools and are not a guarantee of physical vehicle presence, the correct bus, boarding, a safe travel decision, an accessible route, a safe crossing place, or navigation accuracy. Check critical journey information against the operator's or transport authority's official sources and use your own orientation skills and ordinary safety measures.
- When spoken output starts with “Estimated,” information is based on expected departure times (ETA) and not confirmed vehicle position.
- Planned arrival and updated expected or actual arrival are stated separately. An updated time is used only when a fresh, reliable Entur response matches the exact service journey, operating date, stop, and stop occurrence. Otherwise, Bussenmin states that an updated expected arrival is unavailable.
- Screen reader mode is designed for screen readers, but it is not a guarantee that every feature, all third-party content, or every combination of device, operating system, and screen-reader version meets every accessibility standard or works identically.
- Availability and behavior may vary across platforms (Android/iOS), OS versions, permissions, device settings, provider data, and network conditions.
- The user is responsible for keeping device, app, and permissions correctly configured for intended functionality.
5. Notification Services & Third-Party Processing
5.1 Enhanced Privacy Notification System:
Our notification system operates with maximum privacy protection through two complementary components:
5.2 Personal Message Notifications:
- Messages and friend requests are delivered via OneSignal with short generic content ('New message' or 'Friend request')
- On the main map, signed-in users use the avatar menu to open Friends and Messages. The avatar may show one combined badge for pending friend requests and unread messages; the menu shows the two counts separately. This badge is an account-linked in-app status, not a push notification, and it does not show message text or a friend's name on the map.
- OneSignal never receives or stores your actual message content
- Driver Colleagues request, acceptance, and greeting notifications may include the other verified driver's first name. OneSignal receives the recipient's external user ID and limited event/deep-link metadata for delivery
- Real-time board reminders may be sent as generic notifications (e.g., approx. 10/5/3 minutes before departure) without personal identifiers
- When a boarding signal becomes ready, OneSignal may deliver one short functional notification titled “Boarding signal ready,” with the public line code and a “Show signal” action. The payload may contain the recipient's external user ID plus opaque event and navigation identifiers, locale, and expiry, but no passenger or vehicle coordinates, route geometry, stop history, complete journey, or spoken text
- When Show signal is used, the native part of the app obtains a new location and revalidates the signal. An expired or no-longer-eligible signal is not shown. The location is not stored in the notification dispatch record or sent to OneSignal
- When such a reminder is opened, the app may show a detailed in-app overlay and use local text-to-speech based on app language; voice availability depends on the device TTS engine and installed voice packs
- Users can turn voice on/off in the real-time board and mute speech directly from the in-app overlay
- OneSignal automatically collects device data (device model, app version, cellular carrier, session data, unique identifiers) from each user's device
- IP addresses are automatically excluded for EU/UK users (including Norway)
5.3 Broadcast Notifications:
We send broadcast notifications to all users for various legitimate business purposes:
- Security Updates: Critical security patches and safety notices (cannot be disabled for user safety)
- App Updates: New features, bug fixes, and system maintenance notices (can be disabled)
- Service Announcements: Important service changes and policy updates (can be disabled)
- Marketing & Promotions: Feature highlights, tips, and promotional content (requires explicit consent)
5.4 Broadcast Notification Content Standards:
All broadcast notifications must comply with the following standards:
- Professional and appropriate language
- Relevant to app functionality or user safety
- No misleading or deceptive content
- Respect for user preferences and opt-out choices
- Compliance with applicable advertising and marketing laws
5.5 OneSignal Data Processing:
- Company: OneSignal is a US-based company certified under the EU-US Data Privacy Framework
- Data Centers: Located in the EU for European users
- Compliance: Automatic compliance measures for EU/UK users (IP address exclusion)
- Device Identifiers: Each user device receives unique OneSignal ID and Subscription ID for notification delivery
- Recipient Routing: For targeted notifications, OneSignal receives the recipient account's external user ID and limited request/event and deep-link metadata
- Privacy Protection: Coordinates, route geometry, stop history, and spoken text are not transmitted in push content. Driver Colleagues notifications may include the other verified driver's first name, and a boarding-signal readiness notification may include the public line code and opaque event/navigation identifiers
- Data Retention: Dashboard messages stored indefinitely, API messages deleted after ~30 days, device data cleaned after ~30 days of inactivity
5.6 User Control and Consent:
- Granular Control: Separate settings for each type of notification in Privacy Settings
- Marketing Consent: Explicit opt-in required for promotional notifications
- Easy Opt-Out: One-click unsubscribe from non-essential notifications
- Preference Persistence: Your choices are remembered and respected
- Immediate Effect: All notification preference changes take effect instantly
- Driver Colleagues: Request/acceptance notifications and greeting notifications have separate default-on controls under Privacy Settings → Notifications. Automatic greetings are controlled separately under Privacy Settings → Driver Settings
- Boarding signal notifications: This default-on functional preference is under Settings → Notifications when the feature is available. It works only while general push-notification consent, operating-system permission, and the OneSignal recipient are also available, and cannot override a refusal
5.7 Data Retention Policy:
- OneSignal API/Automated Messages: Automatically deleted after approximately 30 days
- OneSignal Device Data: Cleaned up after approximately 30 days of inactivity
- User Preferences: Notification settings retained until account deletion
5.8 User Responsibilities:
- Understand that most notifications are generic, while Driver Colleagues notifications may include the other verified driver's first name
- Report any inappropriate notification content through our support channels
- Manage your notification preferences through the Privacy Settings page
- Understand that OneSignal automatically collects certain device data for functionality
- Acknowledge that withdrawing notification consent will disable all push notifications
- Understand that the network, OneSignal, operating-system scheduling, Focus mode, volume, and screen-reader notification settings may delay or prevent a notification or its announcement. No custom vibration is used. A readiness notification or displayed passenger signal is not a driver delivery, read, or attention receipt and does not guarantee that the vehicle will stop
6. Friend-Message Encryption & Security
6.1 Message Encryption:
- Message content is encrypted by the app before it is stored by the backend
- In the new secure format, content is signed and encrypted separately for each registered device; the backend stores encrypted content and technical metadata
- Private keys for the new format are created on the device and kept in Android Keystore-backed storage or the iOS Keychain; public keys and device metadata are registered with the service
- Older conversations use the previously shipped compatibility encryption format
- The new format is being introduced in stages and is not described as independently verified end-to-end encryption or zero-knowledge encryption
- Friend-message text and the friend's name are not included in the push-notification payload
- Reinstalling, changing devices, or losing a device key can make earlier secure-format messages unavailable; the service does not currently provide message-key recovery
6.2 User Responsibilities for Messages:
- You are responsible for the content of your messages
- Do not share illegal, harmful, or inappropriate content
- Respect other users' privacy and consent
- Report harassment or abuse through our support channels
- Understand that deleted messages cannot be recovered
7. Account Management & User Responsibilities
7.1 Account Security:
- You are responsible for maintaining the security of your account
- Use a strong, unique password for your account
- Do not share your login credentials with others
- Report suspected unauthorized access immediately
- Keep your email address current for security notifications
7.2 Acceptable Use:
- Use the service only for its intended purpose
- Do not attempt to circumvent security measures
- Do not interfere with other users' use of the service
- Do not use the service for illegal activities
- Respect intellectual property rights
7.3 Account Termination:
- You may delete your account at any time through Privacy Settings
- We may terminate accounts for violations of these terms
- Account deletion is permanent and cannot be undone
- All data is permanently deleted after account termination
8. Service Availability & Technical Requirements
8.1 Service Availability:
- We strive to maintain high service availability but cannot guarantee 100% uptime
- Scheduled maintenance will be announced in advance when possible
- Emergency maintenance may occur without notice
- Service interruptions may occur due to technical issues or external factors
- Driver Colleagues greetings depend on fresh Entur data, NVDB availability, backend processing, and current safety thresholds. A pass may therefore be missed, delayed, or not produce a push notification
8.2 Technical Requirements:
- Compatible device with supported operating system
- Stable internet connection for real-time features
- Location services enabled for route matching functionality
- Push notification permissions for message alerts
- Driver Colleagues encounter detection runs in the backend and does not require the app or map to be open, but push delivery may be affected by network conditions, OneSignal, operating-system background rules, Android force-stop, or swiping the app away on iOS
- Sufficient device storage for app operation
9. Intellectual Property & Content Rights
9.1 Our Intellectual Property:
- The app, its design, and functionality are our intellectual property
- You may not copy, modify, or distribute our software
- Our trademarks and logos are protected intellectual property
9.2 Your Content Rights:
- You retain ownership of content you create (messages, profile information)
- You grant us necessary rights to provide the service
- You are responsible for ensuring you have rights to content you share
- We do not claim ownership of your personal content
10. Limitation of Liability & Disclaimers
10.1 Service Disclaimers:
- The service is provided 'as is' without warranties
- We do not guarantee accuracy of real-time vehicle information
- We do not guarantee that Driver Colleagues detects every pass or that a notification is delivered. A greeting is not safety, location, employment, or incident evidence
- We are not responsible for user-generated content or driver announcements
- Driver announcements are opinions, not official information - verify with official sources
- We are not responsible for accuracy of photos or content shared by drivers
- We do not guarantee compatibility with all devices
10.2 Limitation of Liability:
- Our liability is limited to the maximum extent permitted by law
- We are not liable for indirect, incidental, or consequential damages
- Our total liability shall not exceed the amount paid for the service
- These limitations do not apply to gross negligence or willful misconduct
11. Governing Law & Dispute Resolution
11.1 Applicable Law:
- These terms are governed by Norwegian law
- GDPR applies to all EU/EEA users regardless of governing law
- Local consumer protection laws may also apply
11.2 Dispute Resolution:
- We encourage resolving disputes through direct communication
- Mediation may be used for unresolved disputes
- Legal action may be pursued in appropriate courts
- EU users may use the European Commission's Online Dispute Resolution platform
12. Changes to Terms & Service Updates
12.1 Terms Updates:
- We may update these terms to reflect service changes or legal requirements
- Continued use constitutes acceptance of updated terms
- You may terminate your account if you disagree with changes
12.2 Service Updates:
- We regularly update the app to improve functionality and security
- Some updates may be required for continued service access
- New features may be added with appropriate user consent
13. Contact Information & Support
13.1 Contact Details:
- Email: info@asadidev.com
13.2 Response Times:
- General inquiries: Response within 3 business days
- Privacy/GDPR requests: Response within 72 hours
- Security issues: Response within 48 hours
- Legal matters: Response within 5 business days
14. Severability & Entire Agreement
14.1 Severability:
If any provision of these terms is found to be unenforceable, the remaining provisions will continue in full force and effect.
14.2 Entire Agreement:
These terms, together with our Privacy Policy, constitute the entire agreement between you and us regarding the service.
14.3 Acknowledgment:
By using our service, you acknowledge that you have read, understood, and agree to be bound by these Terms of Service and our Privacy Policy.
15. Data Sources and Licences
15.1 Entur Open Services Data:

Data made available by Entur
Route shapes, service journeys, and stops used by Bussenmin Route Challenge are obtained from Entur Journey Planner. Shared-mobility data in Bussenmin, including scooters, bicycles, and shared cars, is obtained from the Entur Mobility API. These Entur Open Services are used under the Norwegian Licence for Open Government Data (NLOD) 2.0.
15.2 Bussenmin Processing:
Bussenmin selects reported available standing and seated scooters, bicycles and cargo bicycles, and shared cars. For bicycles and cars, Bussenmin may also select stations with reported available vehicles. The data is limited to the visible map area and the categories enabled by the user, then grouped and formatted for map display. This is Bussenmin's processing of the source data.
For Bussenmin Route Challenge, Bussenmin selects and validates the route shape and ordered stop sequence for the service journey chosen by the user, extracts a short segment with three to five stops, and transforms the coordinates into a local game simulation. All bus movement, traffic, timing, and scoring are added by Bussenmin and are not Entur data. The game clearly states that the data has been modified, that driving is simulated, and that it is not real-time information.
15.3 Data Quality and External Services:
Location, vehicle and station status, numbers of available vehicles or docks, range, battery or fuel level, operator, prices, and links are information reported by the data providers and may be delayed, incomplete, or incorrect. Always check availability, price, and terms with the operator before reserving, renting, or using an option. Bussenmin does not provide the rental or reservation service, is not a party to the agreement between you and the operator, and does not rent, reserve, unlock, or operate the vehicles.
When an operator button is shown, it attempts to open the operator's app or website using a link reported through Entur or a verified fallback link maintained by Bussenmin. External apps and websites may be unavailable or change without notice. When you open the link, you leave Bussenmin, and the operator's own terms and privacy policy apply. Operator names and colours are used only to identify the data source and do not imply that Entur or the operator supports, recommends, or markets Bussenmin.
15.4 Norwegian Public Roads Administration DATEX – Road Information:
Road information in Bussenmin is obtained from the Norwegian Public Roads Administration's DATEX service and used under the Norwegian Licence for Open Government Data (NLOD) 2.0. The content may include current road closures, serious road incidents, planned road closures, major roadworks and temporary traffic controls, and measured general-road delays.
Bussenmin uses structured DATEX fields for category, confirmation, severity, impact, and validity. Planned closures are limited to the next start within 24 hours. Measured travel times are joined to the Norwegian Public Roads Administration's named road segments by official identifier, and a delay is shown only when it is at least 60 seconds and 10 percent above the reported free-flow travel time. Results are limited to the visible map area and formatted for the map and details dialog. This is Bussenmin's processing of the source data.
DATEX content is standalone, informational-only map information. It is not used to change journey planning, routing, departure times, estimated arrival, or vehicle information. Text from the DATEX source is shown in Norwegian without translation. The information may be delayed, incomplete, or incorrect. Always follow signs and instructions at the location.
15.5 Kartverket – County Boundaries:
Bussenmin uses a simplified, local copy of Kartverket's administrative county-boundary data to limit which supplementary live vehicles may be shown when a Norwegian county is selected. The boundary data was retrieved on 04/08/2026 and processed for use in the app. © Kartverket.
Last Updated: 01/09/2026 - Version 2.48
Effective Date: These terms are effective immediately upon posting.