Privacy Policy
Last Updated: 05/09/2026
1. Introduction
This Privacy Policy explains how Jett Labs ("we," "our," or "us"), located at L0, Ewropa Business Center, Triq Dun Karm, Birkirkara, Malta, collects, uses, shares, and protects personal information across Transport Plus (also referred to as Transport+): our marketing website, operator web application, public trip, shuttle, and payment pages, the Transport Plus customer app (io.transportplus.app), and the Transport Plus Driver app (io.transportplus.driver) (collectively "the Services"). This policy applies to website visitors, operators, drivers, passengers, parents or guardians, and anyone who uses a public share link.
Jett Labs is the data controller for marketing-website visitors, sales and waitlist enquiries, and Transport Plus customer-app accounts that we operate. For operator transport-management data — including drivers, passengers, students, trips, and payments — the Customer (the transport operator) is the data controller and Jett Labs is the data processor, acting on the Customer's documented instructions.
2. Information We Collect
2.1 Website Visitors
- IP addresses and device information
- Browser type and settings
- Date and time of visits
- Pages visited and features used
- Referring websites
- Contact, integration-partner, and waitlist forms: name, company, work email, phone, industry, fleet size or integration type, message, and product interest
- Google reCAPTCHA v3 signals (including IP address and device or interaction data) sent to Google to prevent spam
- An industry-preference cookie named
tp:selected-industry(1 year, SameSite=Lax) and the same value in localStorage - If you book a demo through Calendly, Calendly collects the details you submit to them
2.2 Operator Web Application and TMS Data
The operator (Customer) enters and controls most of this data. We store and process it to provide the Service.
- Account information (name, email, phone number)
- Business details (company name, VAT number, address)
- Login credentials and multi-factor authentication settings
- Driver and passenger records the operator enters, including identity documents (for example national ID, passport, or student ID) and uploaded files, driver payout details such as IBAN, and trip notes
- School-transport records where the operator uses that feature: name, date of birth, gender, guardians, home addresses, and enrollments
- Payment metadata (amount, currency, card brand and last four digits — not the full card number) and cash-reconciliation records
- Usage data, activity logs, preferences, and support communications
- On public trip, shuttle, or payment pages, the browser may share location only to center a "you are here" marker on a shuttle map. Those pages do not create bookings.
2.3 Customer App Users (Transport Plus)
- Name, email, and phone number
- Email one-time login codes (no password and no social login)
- Saved trip links you add by share URL or QR code
- Student and trip records the operator allows you to see
- Push-notification token
- Camera access used only to scan trip QR codes. We read the code; we do not store the camera image
- Map tile requests needed to draw trip maps
The customer app does not collect your device's GPS location. Live maps show the vehicle position published by the operator.
2.4 Driver App Users (Transport Plus Driver)
Driver accounts are created by the operator. There is no in-app sign-up. You sign in with email and password.
- Email, password, and push-notification token
- Precise location while tracking is enabled, including in the background, after you close the app, and after the device restarts, so dispatchers and customers can see your location in real time. Tracking is an opt-in setting (off by default), is not limited to rostered shifts, and cannot be turned off while a trip is in progress
- Motion and activity data to detect whether you are moving or parked
- Device diagnostics (device model, operating system, battery level, network type, and app version)
- Cash amounts you log for reconciliation
- Phone permission used only to open the device dialer with a number already stored on the trip
The driver app does not capture identity-document or profile photos. Any photo or document is stored only if the operator adds it in the web application.
3. How We Use Your Information
3.1 Core Service Functionality
- Managing user accounts and authentication
- Processing and dispatching transportation requests
- Sharing live driver location with the operator and with trip contacts when tracking is enabled
- Facilitating communication between drivers and customers
- Processing payments and managing billing, including driver cash reconciliation
- Sending push notifications about trips and changes
- Rendering maps
- Responding to sales, integration, and waitlist enquiries
- Preventing spam and abuse (including reCAPTCHA)
- Providing customer support
- Maintaining service security and preventing fraud
3.2 Service Improvement
- Analyzing usage patterns and performance metrics
- Improving user experience and interface design
- Developing new features and services
- Conducting research and statistical analysis
- Training and improving our support systems
4. Legal Bases for Processing
We process personal data under the following legal bases:
- Contractual necessity for service provision
- Legal obligations under transport and business regulations
- Legitimate business interests
- Consent (where specifically requested)
- Protection of vital interests of data subjects
5. Data Sharing and Recipients
5.1 Service Providers We Use
- Cloudflare — file storage in Western Europe (R2) and map tiles
- Postmark — transactional email, including login codes and website form delivery
- Google — Firebase Cloud Messaging for push notifications; reCAPTCHA on the website; Maps and Places in the operator web app; fonts
- Mapbox — static map images in emails and customer-app trip previews
- Calendly — demo booking from the website
- Gravatar — optional avatar generated from an email hash
- Sentry — error monitoring, if enabled
- Cloud hosting providers in the EU
5.2 Tools the Customer Enables
The operator may connect the following. We share data with them only as needed to provide that integration on the Customer's instructions.
- Revolut — default card payments
- Stripe — card payments, where the operator enables it
- Xero — invoicing and accounting
- WhatsApp via WAAPI — trip and schedule messages
- Fleet GPS vendors the Customer connects (for example Teltonika, HandsOn, Yipii / DazzlePanel)
5.3 People on a Trip
- Driver location is shared with the operator and with customers or passengers on a trip when tracking is on
- Public share links may show live vehicle position and driver contact details according to the operator's settings
6. International Data Transfers
We primarily process data within the European Union (including Cloudflare file storage in Western Europe). Some providers — including Google, Mapbox, WhatsApp, Calendly, Stripe, and Revolut — may process data outside the EU. When data is transferred outside the EU, we ensure:
- Transfers are made to countries with adequate protection levels
- Appropriate safeguards through Standard Contractual Clauses
- Necessary security measures are implemented
- Data transfer impact assessments are conducted
7. Data Retention
- Active account data: retained while the account is active
- Transaction records: minimum 7 years for tax purposes
- Driver records: 3 years after last activity
- Location data: up to 12 months for dispatch and service improvement
- Usage logs: 90 days for security purposes
- Website form emails: kept as business correspondence
- Waitlist entries: until you ask us to remove them
- Customer-app accounts: until you delete the account
- Push-notification tokens: until logout or de-registration
8. Account Deletion
- Transport Plus customer app: open Settings and choose Delete account. This removes your Transport Plus login and the trips you saved. Your school or transport operator still keeps the student and trip records they need to run the service.
- Drivers and operator users: ask the Customer (your operator) or email [email protected]. Driver accounts are created by the operator and cannot be deleted from inside the driver app.
- Website enquiries or waitlist: email [email protected]
9. Your Privacy Rights
Under GDPR, you have the following rights:
- Access your personal data
- Rectify inaccurate data
- Request erasure ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent
- Lodge a complaint with supervisory authorities
Where Jett Labs is the processor, we will pass your request to the Customer so they can respond as controller.
10. Security Measures
We implement appropriate technical and organizational measures including:
- Encryption of data in transit and at rest
- Two-factor authentication
- Access controls and authentication
- Regular security assessments
- Staff training on data protection
- Incident response procedures
- Regular backups and disaster recovery
11. Cookies and On-Device Storage
- Marketing website preference cookie
tp:selected-industry: first-party, 1 year, SameSite=Lax, used only to remember the industry you viewed - Google reCAPTCHA cookies when contact or waitlist forms load
- Operator web-application session cookies for authentication
- The mobile apps use on-device storage (including secure storage) for tokens and settings, not browser cookies
The marketing website does not use analytics cookies. We do not use advertising cookies or advertising identifiers.
12. Children's Privacy
The website and apps are intended for people aged 16 or over. We do not offer accounts to children.
Operators (for example schools) may enter data about younger passengers — such as name, date of birth, guardians, addresses, and trip details — to run school or similar transport. Jett Labs processes that data only as processor for the operator. Parents and guardians use the customer app as adults.
If you believe we hold a child's data as controller, contact [email protected] and we will take steps to correct or delete it where we are able to.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of material changes through:
- Email notifications
- In-app notifications
- Website announcements
- Service dashboard alerts
14. Data Protection Officer
You can contact us for any privacy-related concerns:
- Email: [email protected]
- Address: L0, Ewropa Business Center, Triq Dun Karm, Birkirkara, Malta
15. Contact Information
For any questions about this Privacy Policy or our data practices:
Email: [email protected]
Privacy and data-protection requests: [email protected]
Address: L0, Ewropa Business Center, Triq Dun Karm, Birkirkara, Malta
Registration: C-97468
Supervisory Authority: Malta Data Protection Commissioner