Privacy Policy

Updated October 8, 2026

Ride and staff details

The shuttle service uses the name, phone number, service advisor, destination address and passenger count you submit to coordinate your ride. Request and trip records include waiting, boarding, departure, drop-off and return times. Authorized dealership staff can access ride details to arrange transport and contact you.

Staff accounts use a separate shuttle login. Account details and ride records are stored using Supabase; the website is hosted using Sites. Staff sign-in uses session cookies, and hosting services may process connection and security information to operate the service.

Driver location

The driver app shares its phone’s location with permission during a departed shuttle trip and the return to the dealership. This helps estimate travel time and confirm a parked return. Sharing stops after completion or sign-out. The shuttle application keeps the latest trip location rather than a continuous location history and clears that location when the trip completes.

Customers are not asked to share their phone’s GPS location. A destination address is used for the requested drop-off.

Google Maps

When routing is enabled, destination addresses, the shuttle pickup location and the driver’s current coordinates are sent to Google Maps to calculate road travel times. Customer names and phone numbers are not included in these route requests. Google processes information under its Privacy Policy. Google Maps features are subject to the Google Maps/Google Earth Additional Terms of Service.

Abuse prevention

The website uses a necessary, signed browser cookie for up to 24 hours to limit repeated requests. The server keeps hashed identifiers and short-lived counters rather than raw email addresses or network addresses for these limits. Retry identifiers are hashed and kept for up to 24 hours; an hourly cleanup removes expired metadata even when nobody is using the site. These security records do not contain passwords, customer phone numbers, destination addresses or Google route results.

When bot verification is enabled, Cloudflare Turnstile checks the request before a new ride is saved. Cloudflare may process browser and connection information under its Privacy Policy. The shuttle server sends the verification token to Cloudflare, without customer names, phone numbers or destination addresses.

Questions or corrections

Speak with your service advisor or the shuttle administrator to correct ride details, ask about stored records or request their removal. Operational records remain stored until managed by the dealership; completing a trip does not automatically remove the ride record.