Privacy Policy
RideGT is a free transit companion for Georgia Tech students and visitors. We built it to make getting around campus easier. This policy explains exactly what data we collect, why, and who we share it with. We do not sell your data, we do not run a third-party ad network, and we do not target anything at you. Section 2 describes the campus banner in full, including what is measured when a post is shown to you.
1. Information We Collect
a) Website and app analytics
On the website, we use Vercel Analytics and Vercel Speed Insights for anonymous usage and performance metrics (for example, page views and web vitals). These services do not require an account and are described in Vercel’s analytics privacy policy.
In the RideGT app/backend, we also use PostHog for anonymous product analytics and reliability monitoring. We use this to understand feature usage and improve service quality, not to identify users.
b) Route search (transit routing)
When you search for a route, your starting and destination information is sent to our servers only to compute and return transit options. We do not use your searches for advertising, marketing profiles, or personal identity matching.
c) Route analytics events (PostHog)
We log anonymized route-search events to measure app quality and feature usage. Example event types include:
route searchedroute search no resultsroute search failedapp initialized,nearby stops searched, andstop arrivals viewed
For search analytics, we store limited fields such as:
- Search mode (for example: regular search, set origin, drop pin)
- Search labels (the submitted origin/destination text, bounded in length, to diagnose no-route and failed searches)
- General route context (origin/destination type and coarse location tiles)
- Outcome/performance (results count, success/no-results/error, latency, request status)
- Technical context (app version, OS/platform, and a random per-install ID). The install ID does not contain your name, account, email or any device identifier, and it is not an advertising ID — but it is stable for as long as the app stays installed, so events from one install can be grouped together. Deleting the app deletes it. Location is coarsened to roughly 1 km tiles before it reaches analytics.
For drop-pin destinations, analytics labels may appear as Pinned Location; coordinate details are represented using coarse tiles rather than exact long-term traces.
Important: this telemetry is designed to be non-identifying. We do not intentionally store your name, account identity, advertising ID, or precise long-term location history in analytics.
d) Session recordings (PostHog session replay)
In the RideGT app (not the website), we record a periodic visual capture of the app's own screens while you use it, so we can see where the app is confusing or broken rather than guessing from event counts alone. A recording covers only what is displayed inside RideGT — never other apps, your keyboard, your notifications, or anything outside the app.
- Text you type is masked in the recording, including destination search text.
- Images are masked.
- Recording begins only after you accept these terms on first launch; the acceptance screen itself is not recorded.
- Recordings are tied to the same random, app-scoped install ID as the analytics events above — not to your name or account.
e) Recent locations (on your device)
The website may keep a short list of recent places you searched (for example, up to five), stored only on your device in browser storage, so we can show them as suggestions. You can clear this by clearing site data for RideGT in your browser settings.
f) Device location
When you tap "Use my location," the app requests access to your device's foreground location only (while the app is actively open). Your coordinates are used to:
- Display your position on the map
- Pre-fill the "From" field in route search
- Work out which stops are nearest to you, so a route search returns instantly instead of waiting on a lookup
Two things send your coordinates to our backend server, and both happen only while the app is open on screen:
- When you search a route — your origin is sent so we can compute the trip.
- To keep the nearest-stop list fresh — this happens without you searching. It is rate limited to at most once every 30 seconds and only after you have moved about 60 m, and it refreshes at least once every 5 minutes while the app is open. Only the coordinates are sent; the response is a list of nearby stops.
We do not track your location in the background, and we do not build a location history: each nearest-stop request replaces the last one and is not retained as a trail. Nothing about your location is collected while the app is closed or backgrounded.
g) Feedback submissions
If you choose to submit feedback through the in-app form, we collect:
- Your feedback message (required)
- Your email address (optional — only if you provide it)
Feedback is forwarded to the development team via email and is not stored in any database. We use it only to respond to your feedback and improve the app.
h) Crash reports (Sentry)
RideGT uses Sentry to automatically capture crash reports and errors (when configured). Sentry may collect:
- Stack trace of the error
- Device operating system version and model category
- App version
- Recent API calls that preceded the crash (URLs only — no request bodies)
We have disabled automatic PII collection in Sentry (sendDefaultPii: false).
Sentry does not receive your name, email, or precise location.
i) Campus banner impressions
When a post is displayed in the banner at the bottom of the map, the app records that it was on screen. Showings are batched and sent to our own server with four fields and nothing else:
- The post's id and how many times it was shown
- Your platform (iOS or Android)
- A random per-install identifier generated on your device
If a post links somewhere and you tap it, the link opens through a counting redirect on our server, which records that a tap happened. The app sends nothing when you tap — the count is a side effect of following the link, and it carries no identifier, no location, and nothing about you.
That identifier is not the IDFA or any advertising ID, it is not shared with anyone, and it exists for one reason: so we can tell “one phone saw this post ten times” apart from “ten phones saw it once.” It is not linked to your searches, your location, or any identity, and deleting the app deletes it. See Section 2 for how the banner works end to end.
j) Ride alerts (push notifications)
Ride alerts are off unless you turn them on. Tapping the bell on a route arms a single alert for that one trip, and only then does the app send us anything. When you arm it we receive:
- A push notification token for your install, issued by Apple or Google via Expo
- A random per-install identifier (the same kind described above — not an advertising ID)
- The vehicle you boarded and the stop ids for that leg, so our server knows which bus to watch and when you are one stop away
- The name of your destination, used only to label the subscription
Our server watches the same public bus feed the app does, and when your stop is next it sends one notification reading “Get off at the next stop.” The alert deliberately carries no destination or address. Delivery goes through Expo’s push service, which relays the message to Apple or Google — see Section 4.
The subscription is tied to one trip and deleted when that trip ends. A push token is meaningless on its own: it addresses a notification to one install of one app and cannot be used to identify you, read anything on your phone, or reach you anywhere else. Turning the bell off, revoking notification permission, or deleting the app all end it. If you never arm an alert, no token is ever sent.
k) What we do NOT collect
- Account credentials (there is no account system)
- Payment information
- Advertising identifiers. We never request the IDFA, we do not show the App Tracking Transparency prompt, and we do not track you across other companies’ apps or websites. There is no third-party ad SDK in the app.
- Push notification tokens — unless you arm a ride alert, which is off by default and described in (j) above. We never send marketing or promotional notifications.
- Background location
- Any data from minors (the app is not directed at children under 13)
2. The Campus Banner (Ad Space)
The strip at the bottom of the map is a free notice board for the Georgia Tech community. This section describes the whole process, because the honest version is short and there is nothing in it we would rather you did not know.
a) It is free, and it is always labelled
Posting costs nothing while RideGT is in beta. Nobody buys placement, and no money changes hands for what appears there. Even so, every post carries an “Ad” label in its corner — including our own announcements — so you can always tell the difference between something RideGT is telling you and something somebody else put there.
b) How a post gets on screen
- A student or student organization submits it at ridegt.com/ads.
- A person reviews every submission before it can run. Nothing is published automatically.
- Approved posts rotate in the banner until the end date the submitter chose, then come down on their own.
- We remove anything that breaks our terms as soon as we learn of it, whether we spot it or you report it.
c) Nothing about you decides what you see
Every rider sees the same rotation. Your location, your searches, your device and your history play no part in picking a post, because there is no targeting system to pick with. No profile is built, no data is sold, and no third-party ad network is involved at any point.
d) What is measured
Two things, both so a student org can find out whether anyone saw their post:
- Impressions — that a post was on screen. See Section 1(h) for the exact fields sent.
- Clicks — if a post links somewhere, the link runs through a counting redirect on our server. The app itself sends nothing when you tap; the redirect simply notes that a tap happened.
Neither carries your name, your identity, your coordinates or your searches, because the app never attaches them.
e) What you can do about a post
Tap the ••• button on the banner. It offers:
- Report — pick a reason, add a note, send. Reports reach a monitored inbox where a person can act on them, and reporting hides that post from you immediately rather than making you look at something you just objected to.
- Close ad — removes the banner for the rest of the session.
- Post here — opens the submission site, if you want to run something yourself.
3. How We Use Your Information
| Data | Purpose |
|---|---|
| Vercel Analytics & Speed Insights (web) | Anonymous usage and performance metrics |
| PostHog analytics events (app/backend) | Anonymous feature usage, search outcomes, reliability and performance monitoring |
| PostHog session recordings (app only) | Seeing where the app is confusing or broken. Typed text and images are masked; recording starts only after the terms screen is accepted. |
| Route search inputs (sent to our servers) | Computing and returning transit routes; not used for marketing or profiling |
| Recent locations (browser storage) | Showing recent place suggestions on your device |
| Device location coordinates | Map display; route calculation; and refreshing the nearest-stop list while the app is open, which happens without an explicit search. Foreground only; no location history is retained. |
| Feedback message + optional email | Responding to user reports; product improvement |
| Crash reports (Sentry) | Diagnosing and fixing app errors |
| Banner impressions + random per-install id | Counting how many times a post was seen, and by how many devices, so the student org that posted it knows. Not used to target anything. |
| Banner link taps (counting redirect) | Counting how many people followed a post's link, so the student org that posted it knows. Anonymous; no identifier is attached. |
| Ride alert subscription (push token, vehicle, leg stop ids, destination name) | Watching your bus so we can tell you when your stop is next. One trip only, deleted when the trip ends. Never used for marketing. |
We do not use your data for profiling, automated decision-making, or targeted advertising. The campus banner is untargeted: everyone sees the same rotation, and the only advertising-adjacent data we hold is a count of how many times a post appeared. See Section 2.
4. Third-Party Services
| Service | Purpose | Privacy Policy |
|---|---|---|
| Google Maps & Places API | Map rendering, location autocomplete | policies.google.com/privacy |
| Vercel (Analytics & Speed Insights) | Anonymous usage and performance metrics on the website | vercel.com/docs/analytics/privacy-policy |
| Sentry | Crash & error monitoring | sentry.io/privacy |
| PostHog | Anonymous product analytics and observability for app/backend events, and in-app session recordings | posthog.com/privacy |
| Brevo (Sendinblue) | Delivering feedback emails to the development team | brevo.com/legal/privacypolicy |
| RideGT Ads Portal (ridegt.com/ads) | Where students submit banner posts, and where impression counts are sent. Operated by us, not a third-party ad network. | This policy |
| Expo push notification service | Delivering ride alerts. Only used if you arm an alert; receives that trip’s push token and the alert text, and relays it to Apple (APNs) or Google (FCM). | expo.dev/privacy |
| Apple (APNs) / Google (FCM) | The operating system’s own notification delivery. Unavoidable for any push notification on any app. | apple.com/legal/privacy · policies.google.com/privacy |
| Georgia Tech TransLoc API | Real-time bus route & vehicle data | No personal data is sent to this service |
5. Data Retention
- Vercel Analytics / Speed Insights: Retained per Vercel’s policy.
- PostHog analytics events: Retained per project configuration and PostHog policy; used for aggregate reporting, debugging, and product improvement.
- PostHog session recordings: Retained per project configuration and PostHog policy; used only to diagnose usability and reliability problems in the app.
- Feedback emails: Retained in the developer's inbox until manually deleted.
- Crash reports: Retained in Sentry per Sentry’s default policy (typically on the order of ~90 days; see Sentry’s privacy policy).
- Banner impression counts: Retained in aggregate so a student org can see how their post performed. The per-install id is random and app-scoped; deleting the app deletes it.
- Ride alert subscriptions: Held only in our server’s memory — never written to a database or disk. A subscription is deleted the moment its alert fires or you turn the bell off, and any that outlive their trip are evicted automatically after two hours. Restarting the server erases all of them.
- Recent locations (browser): Kept on your device until you clear site data or clear the list by replacing entries over time.
6. Your Rights
You may contact us with questions or requests about your data (including Vercel or Sentry data subject requests, where applicable) using the email below. We will respond within a reasonable time.
To delete your data, see Delete your data. It sets out what uninstalling the app removes on its own, what you have to ask us to remove, and what cannot be removed because it no longer identifies anyone.
If you are located in the European Economic Area (EEA), you have the right to access, rectify, and erase your personal data where applicable. Our lawful basis for processing feedback you provide (optional email) is typically consent or legitimate interest in responding to support; analytics and crash data are processed in our legitimate interest in operating and improving the service.
7. Children's Privacy
RideGT is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
8. Changes to This Policy
We may update this policy as the app evolves. Material changes will be reflected by updating the "Last updated" date at the top of this page. Continued use of the app after changes constitutes acceptance of the revised policy.
9. Contact Us
Questions or requests regarding this privacy policy:
vedantlalitbhatt@gmail.com
RideGT is an independent project and is not affiliated with, endorsed by, or representative of the Georgia Institute of Technology.