1. Scope of this policy
This Privacy Policy applies to the websites, web applications, support channels, and programme administration tools operated by DemandTrans Solutions for mobility and transit services delivered through the DemandTrans Mobility platform, including integrations with Uber and authorised programme partners.
It applies when you create an account, sign in, request or manage trips, administer riders, submit documents, contact support, or otherwise interact with our services.
2. Information we collect
Depending on how you use the service, we may collect:
- account and identity data such as name, work or personal email address, phone number, login credentials, user role, and authentication events;
- programme and eligibility data such as rider identifiers, registration details, accessibility information, subsidy or concession status, supporting documents, and consent records;
- trip and transaction data such as booking details, pickup and drop-off information, timestamps, fares, subsidy amounts, receipts, audit history, and exception handling notes;
- device, usage, and security data such as IP address, browser type, operating system, session identifiers, crash logs, diagnostics, and suspected misuse signals; and
- communications data such as support tickets, feedback, training requests, and administrative correspondence.
3. Where the information comes from
We collect personal information directly from you and from authorised sources that support the programme.
- Information you provide in forms, account settings, and support interactions.
- Operational data created when trips are booked, approved, adjusted, or audited.
- Data received from Uber, transport operators, transit agencies, regulators, or referral partners where needed to deliver the programme.
- Security and analytics data gathered automatically through cookies, server logs, and similar technologies.
4. How we use personal information
We use personal information to operate the service in a way that is proportionate to programme needs and current privacy expectations.
- To create and manage accounts, authenticate users, and enforce role-based access.
- To verify eligibility, process registrations, administer subsidies, and reconcile trip activity.
- To provide customer support, training, operational communications, and service notices.
- To monitor uptime, diagnose incidents, prevent fraud, investigate misuse, and protect riders and programme funds.
- To improve accessibility, reporting, and performance using aggregated or de-identified analytics where practical.
- To meet legal, regulatory, tax, records-management, and audit obligations.
5. Legal bases and consent
Where privacy law requires a legal basis, we generally process information because it is necessary to provide the service, administer the mobility programme, protect legitimate security and fraud-prevention interests, comply with law, or because you have given consent.
Where consent is the basis for a specific processing activity, you may withdraw that consent at any time. Withdrawal does not affect processing that was lawful before the withdrawal and may limit the services we can continue to provide.
7. International transfers
Our service providers and platform partners may process information in countries outside the one where you live. When that happens, we use contractual, organisational, and technical safeguards that are designed to meet applicable cross-border transfer requirements.
9. Retention
We retain personal information for as long as needed to operate the programme, honour subsidy and audit requirements, resolve disputes, enforce agreements, and satisfy statutory retention periods.
Retention periods depend on the kind of data involved. When data is no longer required, we delete it, de-identify it, or store it in a form that is securely isolated from routine operational use.
10. Security
We maintain administrative, technical, and physical safeguards designed to protect information against unauthorised access, loss, misuse, and alteration. These include role-based access controls, encrypted transport, monitored infrastructure, authentication controls, logging, and incident-response procedures.
No environment is perfectly secure, so we encourage users to use strong passwords, protect their devices, and report suspicious activity promptly.
11. Your rights and choices
Depending on the law that applies to you, you may have the right to:
- request access to the personal information we hold about you;
- correct inaccurate or incomplete information;
- request deletion or restriction of certain processing;
- object to processing based on legitimate interests;
- request a portable copy of certain information; and
- complain to a regulator or request internal review where available.
To exercise these rights, contact us using the details on this page. We may request reasonable verification before acting on a request.
12. Children and vulnerable users
This service is not directed to children to use independently, and account creation may be limited to adults, carers, guardians, or authorised administrators depending on the programme. When we process information for riders who require assisted access, we expect that an authorised representative or programme administrator is acting within their authority.
13. Changes to this policy
We may update this Privacy Policy to reflect legal, technical, or operational changes. When the changes are material, we will post the revised notice with a new effective date and may also provide in-product or email notice where appropriate.