Privacy Policy
- Effective
- July 6, 2026
- Last updated
- August 25, 2026
SchoolSawari ("we," "us," "our") operates a school transport tracking platform: one mobile app used by parents, drivers and attendants, a School Admin dashboard on the web, and the API and infrastructure behind them (together, the "Service").
This policy explains what we collect, why, how long we keep it, and your choices. It covers parents and guardians, drivers and attendants, school administrators, and anyone who submits a school enquiry on our website. Questions: hello@schoolsawari.com.
1Who We Are and Whose Data This Is
SchoolSawari is a business-to-business platform. Our customer is the school (or transport operator) that subscribes. The school decides which students, parents and drivers are enrolled and is responsible for the accuracy of what it submits. For that data we act as the school's processor — we handle it on the school's instructions. We are the controller only for account- and system-level data we need to run and secure the platform (sessions, security logs, support and feedback correspondence, website enquiries).
If you are a parent, driver or attendant asking what your school submitted about you or your child, contact your school first — its admin contact is shown in the app. Your school can escalate to us.
2What We Collect
| Who | What |
|---|---|
| Parents / guardians | Name and phone number and/or email, submitted by the school (either can be the login identity, via one-time passcode). Language and notification preferences. Push notification tokens for each device you sign in on. Login activity (passcode request and verification times, last active). Your children's name, grade, assigned stop and route, entered by the school — including whether a child is on a school tour roster. Absence markings you submit. |
| Drivers / attendants | Name and phone number, submitted by the school. A login PIN, stored only as an irreversible hash. A device fingerprint recorded at first login and checked on later logins to detect a changed or lost phone. Push notification tokens. Roster attendance actions (who boarded and alighted). SOS reports you raise: location, time and message. |
| School administrators | Name, email, optional phone. Password (hashed) and, where two-factor authentication is on, an authenticator secret or emailed one-time codes. Support requests and messages exchanged with our team. An append-only audit log of administrative actions affecting students, routes, drivers and trips, with before/after snapshots. |
| Buses and trips | GPS position, speed, heading, accuracy and battery level from the driver's phone only while a trip is in progress, sent at short intervals (currently about every 10 seconds moving, 60 seconds idle). Trip records: start and end times, route, stops reached and when, status. Derived data: sustained speeding events, stop-arrival statistics used for arrival estimates, and road-following route geometry computed by a routing engine we host ourselves. |
| Everyone signed in | Feedback you submit, with the app version and platform it was sent from, and a record of when the apps last invited you to rate them — never what you rated. The version of the Terms and Privacy Policy you accepted, and when. |
| School enquiries (website) | School name and address, contact name, role, email and phone, estimated student numbers, your message, and the originating IP address, kept to assess the enquiry and prevent abuse. |
| Collected automatically | Request metadata (timestamps, request identifiers, API and app version) for reliability, security and abuse prevention. Email delivery outcomes from our email provider; our own logs record only the recipient's domain, never the full address. |
We do not collect a parent's device location. The app shows the bus, not you.
We deliberately do not collect student photographs, biometrics, or medical or health data; home addresses (only the assigned stop, a public point on the route); or payment card and bank details — school payments are recorded by admins as manual entries (amount, method, date) for cash, bank transfer, eSewa, Khalti, Fonepay or cheque.
We use no advertising trackers or third-party analytics SDKs, and we do not sell personal information.
3Why We Use It
Only to run the Service: to sign you in and keep accounts secure (passcodes, PINs with device binding, passwords and two-factor, attempt limits and lockouts); to show parents the bus and send proximity and arrival alerts; to let schools and drivers run routes, rosters, attendance and trips; to send notifications by push, SMS or email — bus approaching, boarding and alighting, absences, delays, breakdowns, school broadcasts — and operational email to admins such as invitations, password resets, invoice reminders and usage summaries; to detect and respond to SOS and speeding; to keep an audit trail for accountability and disputes; to bill schools for their subscription and metered usage; to answer support requests and feedback; and to compute aggregate, non-identifying statistics such as typical travel time between stops, which is what makes arrival estimates work.
We do not use parent, student or driver data for advertising, and we build no behavioral profiles beyond what running the Service requires.
4Who We Share It With
- Your school — administrators see data for their own students, drivers and routes. Every query is scoped to a single school; one school can never see another's data.
- Service providers, under contract, only for the purpose we specify: Firebase Cloud Messaging (push notifications), Sparrow SMS (an NTA-licensed Nepali aggregator, for passcodes and SMS fallback), Resend (transactional email and delivery status), Google Cloud Storage (encrypted backups and end-of-year archives), Google Cloud Translation (only when an admin asks us to translate a broadcast; message text only, never personal data), and our hosting and database providers, who store data on our behalf and do not use it for their own purposes.
- Legal and safety — where required by Nepali law or valid legal process, or to protect the safety of a student, driver or the public, such as an active SOS.
- A successor — if the business is merged, acquired or reorganized, subject to this policy.
We do not sell personal information or share it with advertisers.
5How Long We Keep It
Retention is set per school within platform limits. Current defaults — the settings in your school's dashboard are what actually apply:
| Data | Default |
|---|---|
| Live "where is the bus now" position | Minutes; a short-lived cache, never a permanent store |
| GPS trails | Full resolution for about 2 days after a trip ends, then thinned to a coarse trail; deleted at 90 days |
| Notifications | 90 days |
| Administrative audit log | 12 months |
| Passcodes and expired login tokens | Deleted shortly after they expire |
| Trip and stop-arrival history (no raw location trail) | Kept as the school's trip history |
| Support requests and feedback | While the school's account is active |
End of academic year. A school's operational records — trips, attendance, notifications, incidents and related history — can be exported to a secure, integrity-checked archive. After a grace period the school configures, the archived records are permanently deleted from our live systems. Export what you need before the grace period ends.
End of subscription. We keep data only as long as needed to complete offboarding, let the school export its records, and meet legal obligations, after which it is deleted or anonymized.
We also keep encrypted backups for disaster recovery; these are overwritten on a rolling schedule, so deletions from live systems reach backups on that cycle rather than immediately.
6Children's Data
The Service records students, who are minors. We hold the minimum needed to put a child on a bus: name, grade, assigned stop and route. No photographs, biometrics, health data or home addresses. There is no student login and no student-facing account. Student records are entered and controlled by the school, and requests about a child go to the school.
7Your Choices and Rights
- Parents — set language and notification preferences in the app, and download a copy of your own data (profile, children, attendance, absences, notifications and registered devices) from the app at any time. To correct or remove information about you or your child, contact your school admin; deactivating a record stops future notifications and hides it from live views while preserving the trip history the school is required to keep.
- Drivers / attendants — ask your school admin to correct your profile or reset your device binding when you change phones.
- School admins — export or delete records within the retention rules above, and configure your school's retention settings.
- Notifications — preference-based alerts can be turned down in the app; safety-critical ones such as SOS cannot be disabled.
- Requests we cannot action ourselves — because the data belongs to a school — are passed to that school.
8Security
We hash PINs and passwords and never store them in plain text; scope session tokens by role and school; bind driver sessions to a device; rate-limit passcode and PIN attempts with automatic lockout; encrypt connections in transit; isolate every query to a single school; encrypt backups; and log administrative actions to an append-only trail. No system is completely secure. Keep your login credentials — your phone number, driver PIN or admin password — confidential, and tell us or your school promptly if you suspect misuse.
9Hosting, Changes and Contact
Our infrastructure may be hosted outside Nepal. Where data is processed abroad, we require providers to protect it consistently with this policy.
We may update this policy as the Service changes. We will update the "Last updated" date and, for material changes to how we use data already collected, give notice in the app or by email to school admins.
Contact: hello@schoolsawari.com
Parents, drivers and attendants may also raise data questions with their school administrator, who can escalate to us.