Skip to main content
Otranspo
Back to rider information

Public rider information

Privacy and data rights

Otranspo minimizes rider data and does not publish individual journeys or reports.

What the rider service processes

Departure and trip-planning searches are processed to answer the current request. Otranspo does not persist unsuccessful or abandoned searches and does not send exact origins, destinations, coordinates, notes, or itinerary details to analytics.

Saved places, stops, trips, and recent journeys are kept only in the current browser. They are not synchronized to an Otranspo account.

Anyone may submit a private transit report without creating an account. Anonymous evidence is weighted less than account-linked evidence, receives a private receipt, and is reviewed before any sufficiently large aggregate can appear publicly. Signing in afterward never silently links the earlier report.

A precise position used to confirm a nearby crowding observation is not stored with the observation. Only the matched vehicle, reported crowding level, coarse verification evidence, and required audit facts are retained.

Anyone may send a private contact or website-support message. The message and optional reproduction steps are encrypted. An email address is collected only when the sender asks for a reply and gives explicit consent; the message is never treated as evidence of a transit incident or published.

Analytics and cookies

Essential session, language, security, and offline-cache storage support requested features. Optional analytics remains off unless the rider gives explicit consent. Correcting an analytics configuration never enables tracking by itself.

Otranspo counts visits with Cloudflare Web Analytics, which sets no cookie, reads nothing already in the browser, and does not fingerprint or identify the reader. It records the page address without its query string, so trip searches, coordinates, and itinerary details are never part of the count. Because it holds no rider data, it runs for every visit and is the only figure Otranspo publishes as a visitor count.

Optional Google Analytics is different, and it is off. It loads only after a rider turns analytics on in the privacy controls below, never for a browser sending Do Not Track or Global Privacy Control, and it too receives page addresses stripped of their query strings. Turning it off again removes the identifiers it stored. It therefore measures a minority of readers by design, and its numbers are never presented as the size of the audience.

The service does not sell rider data. Infrastructure processors receive only the minimum data needed to operate the service under their configured agreements.

Optional Google Maps mode comparison

Only when a rider explicitly requests the comparison, Otranspo sends the confirmed coordinates and departure intent to Google Maps Routes to calculate driving, walking, and cycling. Place labels, saved-place names, transit itineraries, account details, and reports are not included.

The comparison response is transient and is not stored or placed in browser history by Otranspo. Core transit planning works without this comparison. Google processes the request under its own terms and privacy policy.

Access, export, correction, withdrawal, and deletion

Signed-in riders can use the authenticated privacy endpoints to export or delete account-linked Otranspo records. A deletion request preserves only legally or operationally required audit evidence in de-identified form.

An anonymous report or contact sender receives a private receipt capability. Use that receipt with the authorized privacy contact for an access, correction, withdrawal, or deletion request; it is not a public sharing link.

Do not place sensitive journey or safety information in a general contact message. Use the authorized privacy contact shown on the contact page for a rights request.

Retention

Private submitted reports are retained for up to 365 days unless an active safety review, appeal, or legal hold requires a documented extension. Idempotency and abuse-prevention records expire after 24 hours. Operational feed observations are not rider records.

A private contact case remains open while it is being triaged. Once resolved, closed, marked spam, or marked misdirected, it is scheduled for deletion after 365 days. Account-linked cases are also covered by authenticated account deletion.

Browser-only saved information remains until the rider removes it, clears site data, or the browser evicts it.

Your privacy controls

What works without an account

Reading rider information, changing consent on this device, and asking a privacy question do not require an account.

Access, export, correction, scoped deletion review, appeal, and permanent deletion of account-linked records require the signed-in account owner.

Saved places, recent searches, and unfinished drafts stay on this device. The server cannot export or delete them.

Manage device-only data in Settings

Access or export account-linked records

The download contains only records linked to this Otranspo account. It does not contain browser-only data or records held by the shared identity provider.

Sign in

Request access, correction, deletion review, or an appeal

Choose the smallest useful scope. Do not enter identity documents, passwords, payment details, or unrelated personal information.

Delete account-linked Otranspo data

Type CONFIRM_DELETE_ALL_OTRANSPO_DATA to confirm. This does not delete a shared authentication account.

Deletion review

  • Account-linked reports, requests, votes, crowding submissions, private contact cases, and rider scores in the Otranspo database are deleted where no documented exception applies.
  • Device-only saves and drafts stay on this browser until you clear them in Settings; the server cannot reach them.
  • Notification endpoints and synced saves are removed only when they exist in the account-linked Otranspo systems covered by the verified deletion response.
  • Donation and payment records may have separate legally required financial retention and are not claimed deleted by this control.
  • Public aggregate statistics that no longer identify a person are not reversed.
  • After successful permanent deletion, the deleted account-linked records cannot be restored.
  • The shared authentication account is not deleted by this Otranspo-specific action.

Sign in as the account owner before submitting or changing account-linked records.

Ask a privacy question without an account

Use the private contact form for a general question or to ask for another identity-verification method. Do not send identity documents.

Open the privacy contact form