Version 1.0

Privacy Policy & User Agreement

Please read this notice carefully. It explains how the School Service Monitoring System handles registration data, transport activity, live tracking, notifications, and user responsibilities.

Privacy Policy, Operator, and Scope

This Privacy Policy explains how School Service Monitoring (the "Service"), operated by the School Service Monitoring Team, accesses, collects, uses, stores, and discloses information through the School Service Monitoring website and Android application.

The Android application is a login-only application for approved School Service Monitoring accounts. Student and Parent/Guardian registration may be available separately through the public website. Questions about this policy or personal information may be sent to schoolservicemonitoringapp@gmail.com. This policy was last updated on August 21, 2026.

1

Personal Information We Collect

Depending on a user's role and use of the Service, we may process names, email addresses, passwords, contact numbers, account and user identifiers, roles, barangay assignments, approval and account status, Student ID numbers, course and year level, Parent/Guardian relationship details, Driver license and bus-assignment information, registration rejection reasons, and records showing acceptance of the current Privacy Policy and User Agreement. Passwords are used for authentication and are stored by the Service in hashed form rather than as readable passwords.

2

Student School Proof and Parent Proof Uploads

A Student ID image or a cropped COR Student General Information/header section showing the student's full name and Student ID number, including the same minimal student school proof submitted with a Parent/Guardian registration, are used only to verify registration requests and the linked student. Users should crop or cover grades, subjects, units, schedules, payment details, and other information not needed for verification. Sensitive uploads are stored in private Laravel storage and are accessible only to authorized users for review and verification.

3

Live Bus and Driver Location Tracking

When an authorized Driver starts an active trip and enables live tracking, the Android app may continuously process precise or approximate location, speed, location accuracy, trip, bus, route, Driver, timestamp, arrival, and operational-status information. Tracking may continue while the app is not visible through an Android foreground location service, and an ongoing notification informs the Driver that tracking is active. This information supports authorized Student and Parent/Guardian visibility, barangay monitoring, pickup-arrival detection, delay checks, overspeed monitoring, trip operations, and safety records. It is not used for advertising, turn-by-turn navigation, or geofencing.

4

QR Boarding, Wait Request, and I'm Here Actions

Trip starts and ends, route direction, boarding status, pickup point, timestamps, QR validation results, Wait Request and I'm Here actions, predefined Driver responses, completion status, and related audit information are recorded to support safe boarding, pickup coordination, authorized status updates, incident review, and official operations. The Android camera is used to scan QR codes for boarding validation; the app does not use this feature to upload photographs or videos.

5

Notifications, Announcements, Feedback, and Reports

The system may send account, registration, transport, boarding, waiting-state, trip, announcement, feedback, and safety notifications and may record delivery, failure, and dismissal information. A Firebase Cloud Messaging registration token and device type may be processed to deliver notifications. Student feedback categories, subjects, and messages may be reviewed by authorized barangay personnel for service improvement, follow-up, and issue handling.

6

Admin and Super Admin Access

Barangay admins and super admins may access relevant records based on their role and barangay permissions. Access is intended only for account approval, transport operations, safety monitoring, support, reporting, and system administration.

7

User Responsibilities

  • Provide true and updated registration information.
  • Use QR, waiting-state, feedback, and tracking features only for legitimate school service use.
  • Keep account credentials private and do not share access with others.
  • Respect student, parent, driver, and barangay data shown inside the system.
  • Report incorrect information, suspicious access, or transport safety concerns promptly.
8

Data Protection Statement

MySQL is the source of truth for official records. Laravel handles validation, authorization, writes, approvals, logs, and business rules. Cloud Firestore is used for selected live operational tracking data, and official business records are not written directly to Firestore by client apps. Safeguards include HTTPS transport for the production service, hashed passwords, role and barangay restrictions, authenticated API tokens, private document storage, secure mobile token storage, and Firebase Authentication and Firestore Security Rules. No system can guarantee absolute security.

9

Android App and Local Device Information

The Android app transmits login credentials to the Laravel service for authentication and uses an authentication token to maintain the signed-in session. The token is stored using secure device storage. The app may also store a notification-permission state, Firebase notification token, selected bus preference, and locally dismissed notice identifiers to support app functionality. Android app backup is disabled.

10

Service Providers and External Services

The Service uses hosting and database infrastructure, email delivery, Google Firebase Authentication, Cloud Firestore, Firebase Cloud Messaging, Google Maps, Google Routes, and Google Play services for authentication, hosting, live operations, notifications, maps, route information, and distribution. These providers may process network or IP address, device and request metadata, service-specific identifiers, map interactions, diagnostics, or data needed to provide their services. Their processing is also governed by their applicable terms and privacy practices.

11

How Information Is Used and Disclosed

Information is used to authenticate users, maintain accounts, review registrations, operate trips, provide role-appropriate dashboards, coordinate boarding and pickups, deliver notifications, respond to feedback and support requests, maintain audit history, investigate incidents, prevent abuse, troubleshoot failures, and comply with applicable legal, security, and institutional requirements.

Approved Students and Parents/Guardians may view authorized live bus and transport information. Drivers may view information needed for assigned operations. Barangay Admins are limited to their authorized barangay, while Super Admins may access broader system information for administration and support. Information may also be disclosed when required by law or necessary to protect users and the Service. We do not sell personal information or use it for third-party advertising.

12

Data Retention

We retain personal information only for as long as reasonably necessary for account administration, registration verification, school service operations, safety, security, support, dispute resolution, and applicable legal or institutional requirements. Retention periods may vary according to the type and purpose of the record.

Account and profile information may be retained while an account is active and afterward when needed for operational, security, approval, or support records. Verification documents may be retained while needed to review and maintain registration records. Trip, boarding, waiting-state, audit, overspeed, incident, and related safety records may be retained after deactivation to preserve official history, investigate concerns, resolve disputes, or protect users.

Driver location is processed during active trips. When a trip ends, current coordinates are removed from active live-tracking fields, although related timestamps, operational history, and safety or overspeed records may remain where necessary. Notification tokens may be removed when a device is unregistered, logout cleanup succeeds, a token becomes invalid, or applicable account-status cleanup occurs. Backup copies may remain for an additional period as part of normal security and disaster recovery before being overwritten under the applicable backup cycle.

13

User Requests, Account Status, and Deletion

Users may contact schoolservicemonitoringapp@gmail.com to request access to or correction of their information, ask about data handling, or request account-status assistance. Requests may require identity verification and may be subject to legitimate operational, safety, security, legal, and recordkeeping requirements. Account deactivation prevents continued access but is not permanent account deletion. The Service does not currently provide a user-facing permanent account-deletion feature.

14

Student Information

Student information is processed only for registration, approved school service operations, transport coordination, safety, and related administration. Access is limited according to role, approval, relationship, ownership, and barangay scope. Parents or Guardians should guide younger users and contact the Team if they believe Student information is inaccurate or used without proper authorization.

15

Policy Changes and Contact

We may update this Privacy Policy when the Service, legal requirements, or data-handling practices change. The current policy will be posted on this page with its version and latest update date. Where required by the Service, users may be asked to review and accept an updated version before continuing.

For privacy questions, data requests, or concerns, contact the School Service Monitoring Team at schoolservicemonitoringapp@gmail.com. This policy was last updated on August 21, 2026.