Privacy Policy
Effective date: June 23, 2026 · Last updated: June 23, 2026
1. Introduction
This Privacy Policy explains how Vaya Technologies Inc. (“VAYA”, “we”, “us”) collects, uses, shares, and protects personal data when you use the VAYA applications and services (the “Platform”). It applies to Parents/Customers, Operators, drivers, attendants, School Administrators, and — through their Parents — student Passengers.
We process personal data in accordance with the Data Privacy Act of 2012 (RA 10173, “DPA”), its Implementing Rules and Regulations (“IRR”), and issuances of the National Privacy Commission (“NPC”). We have appointed a Data Protection Officer, reachable at dpo@vaya.ph.
Where we rely on consent (including a Parent’s consent for a child, and consent for sensitive data), we ask for it at the point of collection and you may withdraw it (Section 11).
2. Our Role, and the Roles of Operators and Schools
- We are a personal information controller for (i) the data we collect to operate the Platform (accounts, app usage, security) and (ii) student Passenger data and other personal data we collect, host, scope, and secure to plan and operate trips — because we determine how that data is processed for those purposes.
- An Operator that receives a Passenger’s data to provide the Transport Services acts as an independent controller for that purpose. A School that accesses scoped data is an independent controller of that data solely for school administration — it does not take on responsibility for the collection, hosting, scoping, security, breach assessment, or NPC notification of data residing in our systems. Each handles the data it controls lawfully under a data-sharing/data-processing agreement with us (Terms §§5.2.f, 5.3.e). For data in our systems, we are responsible for its collection, storage, scoping, security, retention, and breach handling.
Personal data is shared with Operators and Schools who act as independent controllers or processors under appropriate data-sharing or data-processing agreements, for the purpose of providing the transport service. This Policy describes our practices.
3. Personal Data We Collect
(Field names reflect what the Platform actually stores.)
Account & identity — given names, last name, nickname, title, birth date, profile photo, phone number, role(s), guardian relationships.
Contact & location — home address(es); for Operators, garage address; precise coordinates of home/school/garage places; and during an active trip, real-time vehicle GPS and computed estimated times.
Children’s (Passenger) data — a student’s name, school, year level, school status, class schedule, home and school locations, and associated guardian information. See Section 4.
Driver/attendant screening data (sensitive personal information) — for crew undergoing verification, images of a driver’s licence and a government-issued ID, and verification status. These are collected for crew screening, treated as sensitive personal information under the DPA, and protected with heightened security measures including restricted access and early deletion (Section 9).
Operator payment details — an Operator’s own bank/e-wallet provider, account name, and account number — shown to Parents so they can pay the Operator directly, and displayed in masked form (this is the Operator’s own account; it is distinct from “we do not store card numbers” below).
Billing & payment-proof data — billing amounts and status, and proof-of-payment images a Parent uploads, plus data automatically read from them by an AI tool (amount, recipient name/account, reference number, confidence score). See Sections 5 and 8.
Device, usage & diagnostics — app/device information, log data, push-notification tokens, crash/diagnostic reports.
We do not collect or store full payment-card numbers (card PANs), and we do not receive, hold, or move the fare itself — fares are paid by Parents directly to Operators off-Platform.
4. Children’s Personal Data
The Platform arranges transport for children, so we process limited data about student Passengers — treated as warranting heightened protection — only to provide the service:
- A student’s data is provided by, and processed with the consent and authority of, the parent or legal guardian, captured at registration. Students do not hold accounts.
- We minimize children’s data to what is needed to plan trips, identify the student for safe pick-up/drop-off, and communicate with the guardian.
- A child’s live trip information is, by design, visible to that child’s own guardian and the assigned crew — not to other families.
- A guardian may revoke another guardian’s access to a child’s information and live location (Terms Section 5.1.f).
- We do not use children’s data for advertising or unrelated profiling, and raw per-trip location trails are retained only briefly (Section 9).
Parental consent for children’s data is captured in accordance with the DPA and its IRR. If you believe a child’s data was provided without authority, contact us (Section 15) and we will act on it.
Location data — how it is collected, stored, and protected
Because the Platform handles children’s daily routines and live geolocation, we treat location data with heightened care and explain it in detail here. We collect location data in two ways:
1. Place coordinates you set. When you (a Parent, Operator, driver, or attendant) add or edit a home, garage, or school address, you place or adjust a map pin, and we store that address’s precise coordinates as part of that place. We use them to plan routes, match seats, estimate times, and guide safe pick-up and drop-off. We do not read your device’s location to fill the form — you set the pin. These coordinates are visible only to the parties who need them to provide the service (for example, your assigned Operator and crew for your home), are denormalized onto the related booking/route records for that purpose, and are deleted or anonymized when you delete your account (Section 9).
2. Live trip location (the bus, during a trip).
- What we track, and when. We collect a vehicle’s real-time GPS location only while a trip is actively running, and only from the driver’s (bus) device — to relay the ride to the right guardian and crew and to compute estimated times. We do not track the location of a parent’s or child’s device, and there is no background or off-trip tracking.
- Who can see a child’s live location. During a trip it is visible only to that child’s own guardians (the booking customer and the guardians they authorize) and to the assigned crew, the Operator, and — where applicable — administrators of the child’s school and of the platform. No other family can see your child’s location. This is enforced by server-side security rules, not merely by what the app screens show.
- Precision is deliberately limited. To protect children, the bus’s precise position is shown to a family only while the bus is near that child’s own home or stop; at other times the family sees an approximate area (about a 300-metre zone) rather than the exact street position. This obscuring is applied on our servers before the data reaches the family’s app — it is not a cosmetic client-side effect.
- How long we keep it. Live GPS is held only transiently during the trip in our real-time database. The raw per-trip GPS trail is purged on a rolling basis (target: 30 days) and is never kept as a long-term movement history; only a coarse trip-completion record may remain (Section 9).
- How it is protected. Location data is encrypted in transit, access-gated by the server-side rules above, obscured server-side as described, and purged on the schedule in Section 9.
5. How We Use Personal Data
We use personal data to: create/manage accounts and verify identity; enable Parents to discover Operators and book; generate and manage trips, routes, schedules, and route/seat matching (automated processing — see below); relay real-time location and estimated times to the relevant guardian and crew; communicate billing and record proof of payment (including assistive AI reading of uploaded proof — Section 8 — noting we do not process the payment itself); support driver/attendant screening for Operators; send service communications and notifications; provide savings/reporting features; secure the Platform and prevent fraud; and comply with law.
Automated processing. Trip generation, route/seat matching, and the AI proof-reading are automated. They are decision-support and record tools that an Operator reviews and can override (Terms Section 3.2); they do not make legally significant decisions about you by solely automated means. You may contact us about any automated processing (Section 11).
6. Legal Bases
We rely on one or more DPA criteria: consent (including a Parent’s consent for a child, and for AI processing of proof images); performance of a contract / steps at your request; legitimate interests (to secure, operate, and improve the Platform, balanced against your rights); and legal obligation. For sensitive personal information (driver-licence / government-ID images) we rely on DPA §13(a) consent specific to the screening purpose AND §13(b) compliance with LTFRB/DOTr driver-fitness and accreditation requirements (and §13(f) where needed to establish or defend legal claims) — not consent alone.
7. How We Share Personal Data
- With the assigned Operator and its crew — booking, schedule, pick-up/drop-off location, and contacts, so they can provide the Transport Services. Crew see only what their assigned trips require.
- With School Administrators — data scoped to their school, for school-administration purposes.
- Between Parent and Operator for billing — the Operator’s payment details are shown to the relevant Parent; the Parent’s proof and billing status are shown to the Operator.
- With service providers (processors) — Section 8.
- For legal reasons — to comply with law or lawful requests, or to protect the rights, safety, or property of users (including children), us, or the public.
- In a business transfer — subject to this Policy.
We do not sell personal data, and we do not share it for unrelated third-party advertising.
8. Service Providers (Processors) and International Transfers
We use reputable providers, including: cloud hosting, database, authentication, messaging (Google Firebase / Google Cloud); maps and navigation; AI text-extraction (Google Gemini) to read proof-of-payment images; and crash/diagnostics reporting. They process data on our behalf under their terms and may not use it for unrelated purposes. Google Gemini reads a proof image only to extract billing fields (amount, recipient, reference), on a tier that does not train models on the content; we retain the raw image only briefly (Section 9) and, where a proof image incidentally contains another person’s data, we process it only as needed to record the payment and minimize it. A current list of sub-processors is published at https://vaya.ph, and we give 30 days’ advance notice of a new sub-processor handling personal data.
Consent at the point of collection. We obtain consent/notice for precise location when location features are used, and for AI processing of a payment-proof image at the upload screen (a proof image may contain other personal data; do not include information you do not want processed).
International transfers. Some providers may store or process data on servers outside the Philippines, so personal data may be transferred across borders; where that happens we take steps to ensure comparable protection as the DPA requires.
9. Data Retention
We keep personal data only as long as needed for the purposes here, to provide the Platform, to meet legal/tax obligations, to resolve disputes, and to enforce our agreements; then we delete or anonymize it. In particular:
- Raw per-trip GPS trails of a trip’s live location are retained only briefly (target: 30 days) and then purged or reduced to a coarse completion record — a child’s day-to-day movement history is not kept as a detailed trail.
- Driver-licence / government-ID images are retained only as long as needed for screening plus any legally required period (target: 6 months after offboarding), then deleted.
- Children’s data is deleted or anonymized when the booking relationship ends, subject to legal retention.
- Deactivated (deleted) accounts. When you delete your account we revoke access and deactivate it immediately, then retain your personal data for a limited period (target: 6 months after account deletion) where the law permits — to resolve disputes, establish or defend legal claims, support the safety of users (including children), and respond to lawful requests — after which we delete or anonymize it. Business-entity records (such as an Operator’s business details and billing history required for tax) are retained as required.
10. How We Protect Personal Data
We apply technical and organizational measures appropriate to the data, including:
- Authenticated access and role-based access control, so users reach only the data their role permits;
- Data scoping that limits exposure — a Parent’s app accesses only their own child’s trip information, never another family’s; School access is scoped to the school; crew access is scoped to assigned trips; driver-licence/ID images are restricted to the relevant Operator/administrator;
- Masking of sensitive identifiers in the interface (for example, showing only part of an account number) on every Parent-facing surface;
- Encryption in transit and at rest using our cloud provider’s infrastructure; and
- Least-privilege design with server-side enforcement of write/validation rules.
No system is perfectly secure, and we cannot guarantee absolute security.
11. Your Rights
Subject to the DPA, you have the right to: be informed; access your data and obtain a copy; correct inaccurate data (much of which you can edit in-app); object to or restrict certain processing and withdraw consent (which may stop our ability to provide the service); request erasure or blocking where the DPA allows; data portability for data processed electronically; and complain to the NPC and be indemnified for damage from unlawful processing.
To exercise these rights, contact us or our DPO (Section 15); we may verify your identity and will respond within 30 days. For a child’s data, the parent/guardian may exercise these rights. Where an Operator or School also holds data as an independent controller, you may contact them too — but for data held in our systems, we will operationalize your request (including erasure/access) so you are not bounced between parties.
You can export your data and delete your account from within the app (Settings → Account; for administrators, the account menu). Deleting your account immediately revokes your access and deactivates the account; we then retain certain personal data for a limited period where the law allows (Section 9) before deleting or anonymizing it. We act on a verified request within 30 days; full deletion or anonymization follows the retention period in Section 9. For data held in our systems, we operationalize your request so you are not bounced between parties.
12. Cookies, Analytics, and Diagnostics
Our mobile applications use device identifiers, analytics, and crash-reporting tools to operate the service, understand usage, and fix problems. Our website (https://vaya.ph) is a static marketing site that does not use advertising or cross-site tracking cookies; only strictly-necessary technical cookies, if any, are used.
13. Data Breach
If a personal-data breach meeting the notification thresholds occurs, we will notify the NPC and affected data subjects within seventy-two (72) hours of knowledge, as the NPC rules require, and we maintain a breach register. A breach originating in our systems is our responsibility to assess, notify, and remediate. Allocation of roles for a breach involving an Operator’s or School’s own systems is set in their data-sharing/processing agreement (which also sets a short inter-party notice window so each controller can meet its own 72-hour clock).
14. Changes to this Policy
We may update this Policy. For a material change we will give reasonable notice (in-app) and update the “Last updated” date. A material change that expands processing of children’s data or live-location sharing requires fresh affirmative consent (Terms Section 16.2); other continued use means acknowledgement.
15. Contact Us and Our Data Protection Officer
Vaya Technologies Inc. · 213-A Maclang Street, Santa Lucia, City of San Juan, Second District, National Capital Region (NCR), 1500, Philippines Data Protection Officer: dpo@vaya.ph General contact / support: support@vaya.ph Legal notices: legal@vaya.ph
You may also contact the National Privacy Commission (https://www.privacy.gov.ph/) if you believe your DPA rights were violated.
Privacy Policy — Vaya Technologies Inc. Effective June 23, 2026.