Privacy Policy
Campus Ride is operated by Choudhary Tours & Travels Pvt. Ltd., which is the data controller for the information described below. This page explains how the Campus Ride student shuttle app collects, uses and deletes your data.
1. What we collect
- Account details — name, email, mobile number and (optionally) a profile photo.
- Travel data — chosen pickup stop, campus, bookings, boarding passes and monthly pass usage.
- Location — rider location is read only while you have the tracking screen open, to show your position and distance to the shuttle. Driver location is broadcast continuously while a trip is running.
- Support content — messages and attachments you send to the ops team.
- Diagnostics — anonymous crash and error reports (no message contents, no precise location).
2. Why we use it
To reserve seats, run the shuttle service, show live vehicle tracking and ETAs, verify boarding, process pass payments, respond to support requests, and keep riders safe during a trip.
3. Location in detail
Riders: location is requested when you open live tracking, when you share your ride with a family member, or when you use SOS. Ordinary map tracking is read only while the tracking screen is open. If you start a family share or an SOS alert, that specific share keeps reading your location until it finishes or you stop it — including if you navigate away or the screen locks — so the people you shared with keep seeing you move; it never runs longer than the window described in section 4 below. Drivers: background location runs only while you are on duty with an active trip, so riders can see the shuttle when the phone is locked. Location is never sold, never used for advertising, and driver coordinates stop being published the moment a trip ends. Incident reports and ride-rating comments (which may include health or third-party details you choose to describe) are collected as support content and kept only as long as needed to resolve the matter, then deleted or anonymised.
4. Sharing
We share data with the parties needed to run the service: our cloud/database host, our payments partner (Razorpay) for pass purchases, mapping and routing providers, Google Firebase Cloud Messaging (to deliver push notifications to your device), our email delivery infrastructure (to send verification codes and alerts), Google Fonts (to load the app's typefaces), and an error monitoring service (Sentry) that receives crash reports containing your account ID (never your location or contact details). Map tiles are normally served from our own servers; if those are unreachable the app falls back to public map hosts (OpenFreeMap, CARTO, MapTiler, and — only if we have separately enabled it — Stadia Maps), and map fonts and, occasionally, road-routing requests may be served by further public infrastructure (GitHub Pages, and a public OSRM routing server) operated by those same mapping partners. Each of these sees your IP address and the area of the map or the route you are viewing, never your name or contact details.
If you use the trip-share feature, the people you pick receive a temporary tracking link. That link carries a hard expiry (at most 12 hours) enforced on our servers, is stopped when the trip ends, and its location history is deleted after 30 days. The SOS alert works differently: the message we send your emergency contacts includes a plain link to your last known coordinates on Google Maps rather than a revocable Campus Ride link, so — unlike trip-share — it has no expiry and cannot be revoked once sent. Use trip-share, not SOS, if you need a link you can switch off later.
5. Payments
Campus Ride sells seats on a physical shuttle service, so pass payments are handled by our payment processor (Razorpay) rather than in-app purchase. We never see or store your full card, UPI or bank credentials — only a payment reference, amount and status.
6. Phone permissions
The Android app asks for: location (live tracking, ride sharing, SOS, and driver on-duty tracking, including background location for drivers only), notifications (trip alerts), and foreground service (keeping driver tracking alive while the screen is off). Location is always requested at the moment you use a location-based feature. The notification prompt may appear shortly after you sign in, rather than only when a specific alert is about to be sent, so that you don't miss trip updates that start immediately. Declining any prompt only disables that feature — everything else keeps working.
7. Security
All traffic is encrypted in transit (HTTPS/TLS). Rider data is protected by row-level database rules so one account can never read another account's bookings, passes or location. Staff access is role-gated and audit-logged.
8. Advertising & tracking
Campus Ride contains no advertising SDKs, we do not build marketing profiles, and we do not track you across other apps or websites. The only third-party telemetry is the crash and error monitoring described in section 4. Your data is never sold.
9. Children
The service is intended for college students and staff aged 13 and above. We do not knowingly collect data from children under 13; if we learn we have, we delete it.
10. Retention & deletion
Location data is kept for 30 days. Raw GPS coordinates — shuttle tracking points, coordinates attached to boarding check-ins, and expired live location shares — are permanently deleted by an automated nightly job once they are older than 30 days. We keep the trip record itself (route, timings, seat, payment status) so your ride history and our operational statistics still work, but the precise coordinates behind it are gone. The copy of your recent share links kept on your phone is cleared automatically after 30 days, and immediately when you sign out or delete your account. Coordinates you save yourself — a home or work address, or a new stop you propose to ops — are kept until you remove them, because they are settings rather than tracking history.
Trip and payment records are retained while your account is active, and afterwards only as long as required for accounting (up to 8 years, in de-identified form). You can request deletion of your account from Settings → Delete account, subject to two exceptions: deletion is blocked while you hold a positive wallet balance, and staff accounts (driver, operator, admin) must be off-boarded by ops first. Deletion removes your profile, bookings, passes and remaining travel days, and releases any upcoming seats. It cannot be undone. Full details, including how to request deletion without the app, are on the account deletion page.
11. Your choices
- Revoke location or notification permission any time in your phone settings.
- Edit or clear your profile details in the app.
- Request a copy of your data from Help & Support.
12. Contact
Privacy questions, data-access requests and grievances: email support-no-response@shuttlz.in (Choudhary Tours & Travels Pvt. Ltd.) or use the in-app Help & Support screen.
Last updated: August 2026. Terms & Refunds · Back to home