Effective date: September 2026

Effective date: September 2026

Transit Technologies, LLC, together with its affiliates, subsidiaries, acquired entities, and branded platforms ("Transit Technologies," "we," "us," or "our"), is committed to protecting personal information. This Privacy Policy is the single enterprise privacy policy for Transit Technologies and its operating brands, including Bytecurve, busHive, CTS Software / TripMaster, Ecolane, FASTER Asset Solutions, MJM Innovations, Passio Technologies (including ParaPlan, Passio Navigator, Passio Connect, and Passio GO), TripShot, and Vestige (including Vestige View, Vestige GPS, and Persa Monitoring). References to any of these brands from their websites, applications, or services incorporate this Privacy Policy.
This Privacy Policy applies to Transit Technologies websites, applications, software platforms, communications, services, and related domains that link to or incorporate this Privacy Policy, except where a specific product or service expressly posts and maintains a separate privacy notice. By accessing or using our websites, applications, products, or services that link to this Privacy Policy, you acknowledge the practices described here.
California residents: please also see our California Privacy Rights Annex which supplements this Privacy Policy, and the "Your Privacy Choices / Do Not Sell or Share My Personal Information" link in the footer of applicable websites.
This Privacy Policy applies to personal information collected through:
• public-facing websites
• customer portals and account areas
• mobile applications
• software platforms and in-vehicle or field-deployed technology
• support, sales, and service interactions
• surveys, forms, webinars, demos, contests, and events
• product registration, warranty, and service fulfillment activities
• information processed on behalf of customers using our transportation, fleet, mobility, asset, safety, workforce, and related technology platforms
This Privacy Policy does not apply to:
• third-party services not controlled by Transit Technologies
• customer privacy practices where the customer determines the purposes and means of processing
• products or services that publish a separate privacy notice that does not incorporate this policy
• job applicants and candidates, whose information is described in our Candidate Privacy Notice
Our role depends on the context. For information collected through our own websites, marketing, sales, recruiting, and direct account relationships, Transit Technologies acts as the data controller (or "business" under U.S. state privacy laws). For information processed within customer deployments of our platforms, for example, rider records, trip data, dispatch records, work orders, or archival communications managed by a transit agency, employer, school, broker, healthcare organization, or fleet operator, Transit Technologies generally acts as a data processor (or "service provider") on the customer’s behalf and processes that information only as directed by the customer and as necessary to provide the contracted services.
We may collect personal information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual, household, device, or customer account. The categories below reflect the combined practices of our services; not every category applies to every product, deployment, or user.
• name and contact details (mailing address, email address, phone number)
• company, agency, employer, school, broker, or organization name and job details
• username, password, and account profile information
• demographic details you choose to submit through forms, such as age, date of birth, gender, nationality, or citizenship
• product registration, warranty, and service information
• payment and billing information, which is collected and processed by third-party payment processors (see Section 8)
• support requests, message content, attachments, and communications with us
• survey, contest, and promotion responses, and public comments or reviews
• newsletter and marketing sign-up information
• social media profile information you provide when interacting with us through social platforms
• job application and career-submission materials
• information you provide when requesting a demo, quote, download, support, site or service access, or additional information
When you use our sites, apps, or services, we and our partners may automatically collect, through cookies, web beacons, SDKs, log files, and similar technologies:
• IP address and inferred general location
• device identifiers, device type, hardware and software settings, and operating system
• browser type, connection and mobile network information, and referral URL
• usage and navigation data, including entry and exit pages, pages viewed, actions taken, and visit times
• log, traffic, page-view, and ad-interaction data
• email interaction data (such as opens and clicks)
• search and page interaction data
• app diagnostics, app version, and performance information
• analytics events, which may be logged through third-party analytics providers in anonymized or aggregated form
For services that rely on routing, dispatch, reservations, rider information, trip coordination, field operations, fleet visibility, vehicle safety, or mobile workflows, we may collect precise or approximate location information where you or your organization enable it. This may include GPS-based, IP-based, Wi-Fi-based, or cellular location information; boarding and offboarding events; route, stop, and agency selections; vehicle location, telematics, and safety-system data; and other location-enabled service data. Certain services may sync data from your device to our servers in connection with app use. Some features may not work properly if location access is not enabled.
Certain fleet-safety products deployed by our client may capture video recordings, safety-event data, and related telemetry from in-vehicle systems. Where such products are administered by the customer, the customer is responsible for providing notice to affected individuals and obtaining any required consent. Transit Technologies processes in-vehicle data only on the customer’s behalf and as directed by the customer. For the VestigeView solution, where customer or customer’s organization enables a feature that includes facial geometry, the saved content is considered biometric data.
We may receive personal information from:
• customers and customer administrators
• employers, transit agencies, brokers, healthcare organizations, campuses, schools, fleets, or transportation providers that sponsor or administer your use of a service
• authentication and single sign-on providers, including identity providers used by an employer or organization
• integration partners and third-party applications you choose to connect
• analytics, advertising, and marketing providers
• payment processors and gateway providers
• support providers and vendors
• social media or publicly available sources
• third parties involved in diligence, onboarding, or service delivery
Where our products are used by transit agencies, employers, schools, healthcare organizations, brokers, fleets, or other institutional customers, we may process information on their behalf, including customer account information, uploaded contacts, end-user records, communications or archival information, trip and routing data, support data, and automatically collected service usage information. In those cases, the customer controls the purposes for which the information is used, and we treat customer account information, information about customers’ contacts, archival information, and automatically collected information as the customer’s confidential and proprietary information (see Section 6).
Certain services may involve mobility, eligibility, accommodation, demographic, medical, health-related, or other sensitive information where necessary to provide the requested service — for example, home address, mobility device information, or personal medical information submitted to support paratransit eligibility, reasonable accommodation, or service delivery. Where such information qualifies as protected health information, we handle it as described in Section 7. We collect sensitive information only where reasonably necessary for the requested service, as directed by our customers, or as permitted by law.
Where required by law or operational need, we may collect identity verification information — which may include images of government-issued identification or similar authentication information — to process access, correction, or deletion requests, to authorize site or service access, and to maintain a trusted and secure environment. Certain services may also collect diligence or reputation-related information from users or third parties in connection with job applicants, service providers, and business partners.
We may use personal information to:
• operate, provide, maintain, present, support, secure, administer, and improve our websites, apps, products, and services
• create and manage accounts, and authorize and authenticate access
• personalize user experiences and content
• coordinate routing, dispatch, reservations, transportation, fleet, asset, safety, and workforce workflows
• respond to support and customer service requests and troubleshoot issues
• send administrative and service communications, alerts concerning product upgrades and updated information, push notifications, and text messages where you have enabled them
• communicate about products, services, surveys, campaigns, contests, promotions, special offers, and events
• fulfill transactions, billing, and account management, and process product registration, warranty claims, replacement parts, assembly instructions, refunds, and related service obligations
• analyze performance, usage, product interest, and trends, and conduct analytics and testing
• support integrations and third-party provider relationships you or your organization enable
• conduct threat analysis, detect malicious activity, and detect, investigate, and prevent fraud, misuse, and cybersecurity incidents
• perform due diligence, identity verification, and business administration
• enforce agreements and policies and support legal proceedings and dispute resolution
• comply with legal, regulatory, tax, accounting, contractual, and security obligations
• support mergers, acquisitions, reorganizations, and related corporate activity
• generate aggregated or de-identified data for lawful business use, including de-identified analytics
Where the laws of the European Economic Area, United Kingdom, or Switzerland apply, we process personal information only where we have a lawful basis to do so, such as performance of a contract, our legitimate interests, compliance with legal obligations, or your consent.
We and our partners may use cookies, web beacons, SDKs, pixels, tags, log files, analytics tools, and similar technologies to operate our services, understand usage, improve functionality, analyze trends, remember preferences, measure communications, support security, and in some cases support advertising or remarketing. Certain services use third-party analytics providers to log service interactions, such as agency and route selections, in anonymized form.
Some of our websites may work with online data or advertising partners that associate site visits or logins with other personal information for marketing communications. You may opt out of these marketing uses as described in Section 10 and where required by law we honor opt-out preference signals such as Global Privacy Control.
To manage your cookie preferences, adjust your browser or device settings. We honor opt-out preference signals such as the Global Privacy Control where required by applicable law. When a cookie preference center is available on a particular website, you may also use it to manage your choices.
To read more about cookies, please see our cookie policy.
We may share personal information with:
• affiliates, subsidiaries, and entities within the Transit Technologies enterprise
• service providers, contractors, vendors, maintenance and support partners, and advisors acting on our behalf under confidentiality obligations
• hosting, support, analytics, payment, communications, infrastructure, and security providers
• customers or organizations that sponsor, administer, or enable your use of the service, including employers, transit agencies, transportation providers, campuses, brokers, schools, and healthcare-related organizations, where necessary to provide the service
• transportation providers and operational personnel where needed to deliver a requested service — for example, if you contact a driver or service provider through a service by phone, your phone number may be visible to that individual
• third-party applications or integrations you or your organization choose to connect, including authentication providers
• commercial providers for business purposes under contract
• advertising and marketing partners as described in Section 4, subject to your opt-out rights
• government authorities, regulators, courts, or law enforcement where required or permitted by law, and where necessary to protect rights, property, or safety or to investigate fraud
• transaction parties in connection with a merger, sale, acquisition, asset transfer, reorganization, or similar corporate event
A current list of the Sub-processors we use to deliver our services is available upon request.
We do not sell personal information for monetary consideration, and we do not sell or rent personal information to third parties for their own marketing purposes. Where information is processed on behalf of a customer, it is shared only as directed by the customer, as necessary to provide contracted services, with our service providers and advisors, in connection with a business transaction, or as required by law.
Where we process information on behalf of a customer, that customer determines how the information is used and is responsible for notices, consents, and requests from its end users. We treat customer account information, information about customers’ contacts, archival information, and automatically collected information processed within customer deployments as the customer’s confidential and proprietary information, and we disclose it only as directed by the customer, as necessary to provide services, to our service providers and advisors, in connection with a business transaction, or as required by law.
Individuals whose information was submitted through a customer deployment — for example, riders, students, employees, or program participants of a transit agency, broker, employer, or school — should generally contact the applicable customer first to access, correct, update, delete, or restrict such information. We will support our customers in responding to such requests as required by law and contract.
For services or deployments involving healthcare, eligibility, mobility, accommodation, or related programs, Transit Technologies may process demographic, health, or health-related information, including information that qualifies as protected health information ("PHI") under the Health Insurance Portability and Accountability Act ("HIPAA"). Where we process PHI on behalf of a covered entity or business associate, we do so only in accordance with HIPAA, applicable Business Associate Agreements, law, contract, and customer obligations, and we require partners handling PHI to provide equivalent protection. Individuals’ rights with respect to PHI are generally governed by the applicable covered entity’s notice of privacy practices, and requests concerning PHI should be directed to that organization.
Where our services support payments, financial transactions are processed through third-party payment gateway providers. Payment card information is collected and processed by those providers and is not stored or processed on Transit Technologies servers. Our payment processors are responsible for safeguarding payment card data in accordance with applicable payment card industry standards, and we maintain our payment integrations consistent with our own compliance obligations.
We retain personal information for as long as reasonably necessary to provide services, maintain customer and business relationships, comply with law and contract, resolve disputes, enforce agreements, and support legitimate business needs. The retention period for a given record depends on the category of information, the purpose for which it was collected, and applicable legal, regulatory, and contractual requirements. Customer-directed retention may also apply in hosted or managed environments, and information processed on behalf of customers is retained and deleted in accordance with our agreements with those customers. When personal information is no longer needed, we delete, de-identify, or securely dispose of it.
We may process, store, and transfer information in the United States and in other jurisdictions where Transit Technologies or its service providers operate. These jurisdictions may have data protection laws that differ from those of your home jurisdiction. Where required, we use appropriate safeguards for cross-border transfers, such as standard contractual clauses or other lawful transfer mechanisms. Certain government or regulated deployments may be subject to contractual data residency commitments, which are addressed in the applicable customer agreement.
Where applicable international data protection law applies, we process personal information in compliance with applicable requirements, including providing appropriate safeguards for cross-border transfers.
11. Your Rights and Choices
Depending on applicable law and your place of residence, you may have rights to:
• access personal information and receive information about our processing
• correct inaccurate information
• request deletion
• restrict or object to certain processing
• withdraw consent where processing is based on consent
• request portability of personal information
• opt out of promotional communications and of targeted advertising or "sharing" of personal information as defined by applicable state law
• exercise rights free from discrimination
• appeal a decision regarding your request where permitted, and lodge a complaint with a supervisory authority or regulator
To exercise these rights, contact us as described in Section 16 or use any request mechanism provided within the applicable service. We may verify your identity before fulfilling a request, which may include requesting information sufficient to confirm your identity or, where permitted, images of government-issued identification for high-risk requests. Where permitted by law, you may use an authorized agent to submit a request on your behalf; we may require proof of the agent’s authority and verification of your identity. We will respond within the timeframes required by applicable law. If we decline a request, we will explain the basis for our decision and, where required, how to appeal.
We will respond to verifiable privacy requests within the timeframes required by applicable law. Where we need additional time, we will notify you as required.
Residents of California, Colorado, Connecticut, Texas, Virginia, and other U.S. states with comprehensive privacy laws, and individuals in the European Economic Area, United Kingdom, and Switzerland, may have some or all of the rights above under their applicable laws. Requests concerning information we process on behalf of a customer should be directed to that customer as described in Section 6.
California residents: see the California Privacy Rights Annex for the CCPA category disclosures, sale/sharing opt-out, sensitive personal information statement, and request metrics applicable to California.
You may opt out of promotional emails by using the unsubscribe link included in the message or by contacting us. We may still send administrative or service-related communications, such as account, transaction, security, and service alerts. You may control push notifications and text messages through your device settings or by following the opt-out instructions provided in the message.
Where account-based services are offered, you may update account and profile information through your account or profile settings. You may request deletion of an account through in-service settings where available, through the designated support channel for the applicable service, or by contacting us as described in Section 16. To help us locate your account, include the service or application name and the username or email address associated with the account.
We maintain administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, use, disclosure, alteration, or destruction. These safeguards include encryption of information in transit (such as HTTPS/TLS), access controls and restricted-access systems, servers located in controlled facilities, and related security controls, and they are maintained as part of the Transit Technologies information security and privacy program, which is assessed against recognized industry frameworks. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
Information about our certifications and attestations are available by request.
If a breach of security involving personal information occurs, we will notify affected individuals, customers, and regulators as required by applicable law and contract.
Our websites and direct services are not directed to children under 13, and we do not knowingly collect personal information from children under 13 through them. Certain customer-controlled deployments, for example, school or student transportation programs, may involve minors; in those cases, the customer is responsible for any required notices and consents, and we process the information only on the customer’s behalf. If you believe a child has provided personal information to us without appropriate authorization, contact us and we will address it promptly.
Our websites and services may link to or integrate with third-party websites, products, applications, or services. We are not responsible for the privacy practices of those third parties, and users should review their privacy policies directly.
We may update this Privacy Policy from time to time. Changes will be posted to this page with an updated "Last Updated" date, and where required by law or where changes are material, we may provide enhanced notice. Your continued use of our websites, applications, or services after posted changes indicates your acknowledgment of the revised policy.
For questions, requests, or privacy-related concerns, or to exercise your rights, contact:
Transit Technologies, LLC
Attn: Data Privacy Officer
2459 Wilkinson Blvd, Suite 200
Charlotte, NC 28208
Email: [email protected]
Toll-free: +1 855 313 4622