TransportHQ Privacy Policy

Last updated: [DATE — set this to the day you publish]

This Privacy Policy explains how personal data is handled in connection with TransportHQ, a school transport management web application available at transporthq.co.uk.

Please read the section “Our two roles” below — it explains an important distinction about whose data we control versus data we merely store on behalf of our customers.

Who we are

TransportHQ is operated by Michelle Sharpe, trading as TransportHQ (a sole trader).

If you have any question about this policy or how your data is handled, email us at the address above.

Our two roles (“controller” vs “processor”)

Data protection law distinguishes between the organisation that decides how and why personal data is used (the controller) and an organisation that only processes data on the controller's instructions (the processor).

TransportHQ acts in two roles:

  1. As a controller — for the limited personal data we hold about the people who directly deal with us: the account holders at transport companies who register and log in to the app, and anyone who contacts us by email. We decide how that data is used, so this policy governs it.
  2. As a processor — for the passenger, driver and passenger-assistant records that our transport-company customers enter into the app. In that case, the transport company is the controller — they decide what to collect and why. We simply store and process that data securely on their instructions. How that data is explained to parents, passengers, drivers and assistants is primarily the transport company's responsibility as controller, though this policy describes how the app treats it.

The personal data we handle

Data we control (account holders and enquirers)

Data we process on behalf of customers (controlled by the transport company)

Entered into the app by our transport-company customers:

We do not collect passenger dates of birth, passenger profile photographs, emergency contacts, or detailed medical/SEN information. We do not store telephone numbers for client or council contacts, separate school contact details, driver home addresses, DBS numbers or licence information.

A note on sensitive (“special category”) data

The wheelchair-access and passenger-assistant flags may indicate that a passenger has a disability or health-related need. Data about health or disability is treated as special category data under UK GDPR and given extra protection. Where the app holds this data, we process it only on the instructions of our transport-company customer, who is responsible for having a valid lawful basis and appropriate condition for holding it. We apply appropriate security to all such data.

Why we use this data and our lawful basis

For data we control:

For data we process on behalf of customers: we act only on the documented instructions of the transport company (the controller), to enable them to manage their school transport operations. The lawful basis for that processing rests with the transport company.

We do not use any data for marketing. TransportHQ has no mailing list or marketing feature. Any outreach to prospective customers is done manually by us, outside the app.

Who we share data with

We do not sell personal data and we do not share it with third parties for their own purposes.

The app includes a feature that lets our customers share certain information — such as the passengers, runs, cancellations and notes relevant to a particular client or council — with those clients or councils, by giving them access to log in and view it and by sending them email notifications. This sharing is set up and controlled by the customer (the transport company), not by us. Where a client or council receives this information, they may be responsible for it as a separate controller in their own right.

The app is built entirely on Google Firebase (Firebase Authentication and Firestore). Google acts as our sub-processor / data processor, hosting the data and providing the authentication and database services that make the app work. Google is contractually bound to protect the data and process it only as needed to provide those services.

We may also disclose data if required to do so by law.

Where your data is stored and international transfers

Your operational data stays in the UK. All personal data entered into the app — passenger, driver, passenger-assistant and client/council records, notes, and cancellation photos — is stored in Google's Firestore database in the europe-west2 (London, United Kingdom) region. Cancellation photos are compressed and stored inside the database record in London, not in a separate storage location.

Login email addresses are processed in the United States. Logins are handled by Firebase Authentication, which Google runs only from data centres in the United States. This means the email addresses used to log in (for managers, drivers, passenger assistants and client/council contacts) are processed in the US. Google applies recognised legal safeguards for this transfer, namely Standard Contractual Clauses together with the UK Addendum. Passenger information is not part of the login system and remains in the UK.

Website and app code is served globally. The app (app.transporthq.co.uk) is served through GitHub Pages, and our marketing landing page (transporthq.co.uk) through Firebase Hosting. Both deliver standard website files — the same code for every user — through global content-delivery networks that may cache these files outside the UK. These files contain the application itself, not anyone's personal data.

How long we keep data

We keep personal data only as long as necessary:

Full details are set out in our Data Retention Policy, available on request.

Your rights

Under UK GDPR you have the right to:

How to make a request, including deletion: email hello@transporthq.co.uk with your request. We will respond within one month.

Please note: for passenger, driver and passenger-assistant records (where we act as processor), we may need to direct your request to the relevant transport company, as they are the controller of that data. We will help make sure your request reaches the right place.

Cookies and local storage

The app uses only the essential storage needed to keep you securely logged in (authentication tokens managed by Firebase Authentication). We do not use analytics, advertising, or third-party tracking cookies.

Complaints

If you have a concern about how your data is handled, please contact us first at hello@transporthq.co.uk so we can try to resolve it.

You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk or by calling their helpline.

Changes to this policy

We may update this policy from time to time. When we do, we will change the “Last updated” date at the top. Significant changes will be communicated to account holders where appropriate.