Privacy Policy

Effective date: June 23, 2026 · Last updated: June 23, 2026


1. Introduction

This Privacy Policy explains how Vaya Technologies Inc. (“VAYA”, “we”, “us”) collects, uses, shares, and protects personal data when you use the VAYA applications and services (the “Platform”). It applies to Parents/Customers, Operators, drivers, attendants, School Administrators, and — through their Parents — student Passengers.

We process personal data in accordance with the Data Privacy Act of 2012 (RA 10173, “DPA”), its Implementing Rules and Regulations (“IRR”), and issuances of the National Privacy Commission (“NPC”). We have appointed a Data Protection Officer, reachable at dpo@vaya.ph.

Where we rely on consent (including a Parent’s consent for a child, and consent for sensitive data), we ask for it at the point of collection and you may withdraw it (Section 11).


2. Our Role, and the Roles of Operators and Schools

Personal data is shared with Operators and Schools who act as independent controllers or processors under appropriate data-sharing or data-processing agreements, for the purpose of providing the transport service. This Policy describes our practices.


3. Personal Data We Collect

(Field names reflect what the Platform actually stores.)

Account & identity — given names, last name, nickname, title, birth date, profile photo, phone number, role(s), guardian relationships.

Contact & location — home address(es); for Operators, garage address; precise coordinates of home/school/garage places; and during an active trip, real-time vehicle GPS and computed estimated times.

Children’s (Passenger) data — a student’s name, school, year level, school status, class schedule, home and school locations, and associated guardian information. See Section 4.

Driver/attendant screening data (sensitive personal information) — for crew undergoing verification, images of a driver’s licence and a government-issued ID, and verification status. These are collected for crew screening, treated as sensitive personal information under the DPA, and protected with heightened security measures including restricted access and early deletion (Section 9).

Operator payment details — an Operator’s own bank/e-wallet provider, account name, and account number — shown to Parents so they can pay the Operator directly, and displayed in masked form (this is the Operator’s own account; it is distinct from “we do not store card numbers” below).

Billing & payment-proof data — billing amounts and status, and proof-of-payment images a Parent uploads, plus data automatically read from them by an AI tool (amount, recipient name/account, reference number, confidence score). See Sections 5 and 8.

Device, usage & diagnostics — app/device information, log data, push-notification tokens, crash/diagnostic reports.

We do not collect or store full payment-card numbers (card PANs), and we do not receive, hold, or move the fare itself — fares are paid by Parents directly to Operators off-Platform.


4. Children’s Personal Data

The Platform arranges transport for children, so we process limited data about student Passengers — treated as warranting heightened protection — only to provide the service:

Parental consent for children’s data is captured in accordance with the DPA and its IRR. If you believe a child’s data was provided without authority, contact us (Section 15) and we will act on it.

Location data — how it is collected, stored, and protected

Because the Platform handles children’s daily routines and live geolocation, we treat location data with heightened care and explain it in detail here. We collect location data in two ways:

1. Place coordinates you set. When you (a Parent, Operator, driver, or attendant) add or edit a home, garage, or school address, you place or adjust a map pin, and we store that address’s precise coordinates as part of that place. We use them to plan routes, match seats, estimate times, and guide safe pick-up and drop-off. We do not read your device’s location to fill the form — you set the pin. These coordinates are visible only to the parties who need them to provide the service (for example, your assigned Operator and crew for your home), are denormalized onto the related booking/route records for that purpose, and are deleted or anonymized when you delete your account (Section 9).

2. Live trip location (the bus, during a trip).


5. How We Use Personal Data

We use personal data to: create/manage accounts and verify identity; enable Parents to discover Operators and book; generate and manage trips, routes, schedules, and route/seat matching (automated processing — see below); relay real-time location and estimated times to the relevant guardian and crew; communicate billing and record proof of payment (including assistive AI reading of uploaded proof — Section 8 — noting we do not process the payment itself); support driver/attendant screening for Operators; send service communications and notifications; provide savings/reporting features; secure the Platform and prevent fraud; and comply with law.

Automated processing. Trip generation, route/seat matching, and the AI proof-reading are automated. They are decision-support and record tools that an Operator reviews and can override (Terms Section 3.2); they do not make legally significant decisions about you by solely automated means. You may contact us about any automated processing (Section 11).


We rely on one or more DPA criteria: consent (including a Parent’s consent for a child, and for AI processing of proof images); performance of a contract / steps at your request; legitimate interests (to secure, operate, and improve the Platform, balanced against your rights); and legal obligation. For sensitive personal information (driver-licence / government-ID images) we rely on DPA §13(a) consent specific to the screening purpose AND §13(b) compliance with LTFRB/DOTr driver-fitness and accreditation requirements (and §13(f) where needed to establish or defend legal claims) — not consent alone.


7. How We Share Personal Data

We do not sell personal data, and we do not share it for unrelated third-party advertising.


8. Service Providers (Processors) and International Transfers

We use reputable providers, including: cloud hosting, database, authentication, messaging (Google Firebase / Google Cloud); maps and navigation; AI text-extraction (Google Gemini) to read proof-of-payment images; and crash/diagnostics reporting. They process data on our behalf under their terms and may not use it for unrelated purposes. Google Gemini reads a proof image only to extract billing fields (amount, recipient, reference), on a tier that does not train models on the content; we retain the raw image only briefly (Section 9) and, where a proof image incidentally contains another person’s data, we process it only as needed to record the payment and minimize it. A current list of sub-processors is published at https://vaya.ph, and we give 30 days’ advance notice of a new sub-processor handling personal data.

Consent at the point of collection. We obtain consent/notice for precise location when location features are used, and for AI processing of a payment-proof image at the upload screen (a proof image may contain other personal data; do not include information you do not want processed).

International transfers. Some providers may store or process data on servers outside the Philippines, so personal data may be transferred across borders; where that happens we take steps to ensure comparable protection as the DPA requires.


9. Data Retention

We keep personal data only as long as needed for the purposes here, to provide the Platform, to meet legal/tax obligations, to resolve disputes, and to enforce our agreements; then we delete or anonymize it. In particular:


10. How We Protect Personal Data

We apply technical and organizational measures appropriate to the data, including:

No system is perfectly secure, and we cannot guarantee absolute security.


11. Your Rights

Subject to the DPA, you have the right to: be informed; access your data and obtain a copy; correct inaccurate data (much of which you can edit in-app); object to or restrict certain processing and withdraw consent (which may stop our ability to provide the service); request erasure or blocking where the DPA allows; data portability for data processed electronically; and complain to the NPC and be indemnified for damage from unlawful processing.

To exercise these rights, contact us or our DPO (Section 15); we may verify your identity and will respond within 30 days. For a child’s data, the parent/guardian may exercise these rights. Where an Operator or School also holds data as an independent controller, you may contact them too — but for data held in our systems, we will operationalize your request (including erasure/access) so you are not bounced between parties.

You can export your data and delete your account from within the app (Settings → Account; for administrators, the account menu). Deleting your account immediately revokes your access and deactivates the account; we then retain certain personal data for a limited period where the law allows (Section 9) before deleting or anonymizing it. We act on a verified request within 30 days; full deletion or anonymization follows the retention period in Section 9. For data held in our systems, we operationalize your request so you are not bounced between parties.


12. Cookies, Analytics, and Diagnostics

Our mobile applications use device identifiers, analytics, and crash-reporting tools to operate the service, understand usage, and fix problems. Our website (https://vaya.ph) is a static marketing site that does not use advertising or cross-site tracking cookies; only strictly-necessary technical cookies, if any, are used.


13. Data Breach

If a personal-data breach meeting the notification thresholds occurs, we will notify the NPC and affected data subjects within seventy-two (72) hours of knowledge, as the NPC rules require, and we maintain a breach register. A breach originating in our systems is our responsibility to assess, notify, and remediate. Allocation of roles for a breach involving an Operator’s or School’s own systems is set in their data-sharing/processing agreement (which also sets a short inter-party notice window so each controller can meet its own 72-hour clock).


14. Changes to this Policy

We may update this Policy. For a material change we will give reasonable notice (in-app) and update the “Last updated” date. A material change that expands processing of children’s data or live-location sharing requires fresh affirmative consent (Terms Section 16.2); other continued use means acknowledgement.


15. Contact Us and Our Data Protection Officer

Vaya Technologies Inc. · 213-A Maclang Street, Santa Lucia, City of San Juan, Second District, National Capital Region (NCR), 1500, Philippines Data Protection Officer: dpo@vaya.ph General contact / support: support@vaya.ph Legal notices: legal@vaya.ph

You may also contact the National Privacy Commission (https://www.privacy.gov.ph/) if you believe your DPA rights were violated.


Privacy Policy — Vaya Technologies Inc. Effective June 23, 2026.