Plain summary: Bustro is a free, ad-free public-transit app for Singapore. We use your location on your device to show nearby bus stops; we do not send it to our servers. We generate a random device ID (not linked to your name or Apple ID) so that, if you choose to post in the Commute Feed or subscribe to traffic alerts, we can route notifications and let you delete your own posts. We use Firebase for crash reports, app-usage analytics, push delivery, and storing Commute Feed posts. If you set an Alight Reminder or track a bus arrival, we briefly store a push token together with the stop and bus service involved so our server can update the live countdown on your Lock Screen; that record is deleted when the activity ends. We do not show ads, sell data, or track you across other apps.
This Privacy Policy explains what data Bustro collects, why we collect it, where it goes, how long we keep it, and the rights you have. It applies to the Bustro iOS application, the Bustro Home/Lock Screen widget, and any related online services we provide (collectively, the "App"). The App is operated by the Bustro team ("we", "us", "our"), based in Singapore.
This Policy is read together with the Bustro Terms & Conditions.
Bustro is a Singapore-only utility. Bus stops, bus services, weather data, and traffic alerts are all Singapore-specific, and the App is operated and hosted with Singapore users in mind. We make our best effort to handle data in line with the Singapore Personal Data Protection Act 2012 (PDPA) and Apple's App Store privacy requirements.
Information we collect
1.1Location
| What | Your device's coarse and precise location, while the App or its widget is in use; and, only while an Alight Reminder is active, in the background during your ride. |
|---|---|
| Why | To show bus stops near you, calculate walking distances, select the closest favourite stop for the Home/Lock Screen widget, and, if you set an Alight Reminder, follow your ride so we can alert you before your stop. |
| When | With the When In Use permission, only when you have the App open or the widget on screen. The Alight Reminder feature additionally offers the Always permission: if you grant it, background location runs only while a reminder is active (most intensively during the final approach to your stop) and stops as soon as the ride ends. If you decline Always, Alight Reminder still works with the App kept open. No other feature uses background location. |
| Storage | On your device only. All ride-progress calculation for Alight Reminder happens on-device. We never transmit your location to our servers, to Singapore LTA, to data.gov.sg, to Apple, or to any other third party. |
| Control | iOS Settings → Privacy & Security → Location Services → Bustro. The App remains functional without location, with reduced features. |
1.2Device identifier
| What | A randomly-generated UUID created on your device the first time you open the App. |
|---|---|
| Why | To attribute Commute Feed posts and reactions you submit, to route push notifications to your device (including Live Activity updates for Alight Reminder and arrival tracking, §1.6), and to let you edit or delete your own Commute Feed submissions. |
| Linked to your identity? | No. The UUID is not linked to your name, email, Apple ID, phone number, or any other identifying information. Under Singapore's PDPA it is treated as pseudonymous personal data. |
| Storage | Locally in app preferences (UserDefaults), and on Google's Firebase Firestore servers when accompanying a Commute Feed submission, reaction, or push-notification subscription. |
| Reset | Reinstalling the App generates a new UUID and disconnects you from prior submissions. A future App update will add an in-app Reset Device Identity control. |
1.3App preferences, favourites, and saved journeys
| What | Your favourite bus stops, custom labels, custom colours and icons, sort order, pinned services, and the journeys you save in My Journeys (boarding and alighting stops, bus service, an optional label you give the journey, and when you last used it). |
|---|---|
| Why | To personalise the App and the widget, and to let you re-activate a saved journey in one tap. |
| Storage | Locally on your device, and synced via Apple iCloud / CloudKit to your other Apple devices if you have iCloud enabled. CloudKit data is encrypted by Apple and is never visible to us. The CloudKit container holds only favourites, pinned services, and saved journeys: no Commute Feed content, no analytics, no usage history. |
| Control | iOS Settings → [your name] → iCloud → Bustro. |
1.4Commute Feed posts (user-generated content)
| What | The text of any message you post in the Commute Feed, any URL you include, any reaction you tap, your device identifier (§1.2), a server-side timestamp, and the language detected on-device. |
|---|---|
| Why | To display your message to other users after admin review and approval, and to let you edit or delete it. |
| Storage | Google Firebase Firestore. Messages enter a pending state and are reviewed by a member of the Bustro team before becoming visible to anyone else. |
| Retention | User-submitted messages are deleted automatically 7 days after submission. Reactions are deleted with the message. Official advisories from the Bustro team and automated LTA service alerts are retained indefinitely. |
| Visibility | After admin approval, your message is visible to all users of the App. Do not include personal information you would not want to be public. |
| On-device checks before upload | Length limits, rate limiting, transport-topic keyword check, and language detection (Apple's on-device NLLanguageRecognizer) all run on your device. Drafts that fail these checks are never uploaded. |
| Link previews | If your message contains a URL, your device fetches a preview using Apple's LinkPresentation framework. This contacts the URL's origin server directly from your device, and that server may log your IP address. We do not see or store the contents of those preview requests. |
| Removal | Delete your own messages from within the App, or email hi@bustro.app referencing the device on which you submitted. |
1.5Push-notification token and subscriptions
| What | Your Apple Push Notification (APNs) device token, the Firebase Cloud Messaging (FCM) token derived from it, and the list of traffic-incident categories you have subscribed to (e.g. accident, road closure, weather disruption). |
|---|---|
| Why | To deliver the traffic alerts and Commute Feed notifications you have opted in to. |
| Storage | In Firebase Firestore, keyed to your device identifier. |
| Control | iOS Settings → Notifications → Bustro to revoke permission entirely. In-app subscription preferences to change which categories you receive. Uninstalling the App removes your token from active rotation. |
1.6Live Activities: Alight Reminder and Track Arrival
| What | When you start an Alight Reminder or track a bus arrival on the Lock Screen, we store an Apple Live Activity push token, your device identifier (§1.2), the bus stop code involved (plus the stop's display name for arrival tracking), the bus service number, and the activity's state. |
|---|---|
| Why | Our server uses this record to fetch live arrival data from LTA and push countdown updates and alerts to the Live Activity on your Lock Screen and Dynamic Island, even while the App is not running. |
| What is not sent | Your location, your position along the route, and your journey's stop list never leave your device. During an Alight Reminder, ride progress is computed on-device (§1.1); the server knows only the stop and service you selected. |
| Storage | Google Firebase Firestore, in the asia-southeast1 (Singapore) region. |
| Retention | Deleted as soon as the reminder or tracker ends (whether you stop it or it completes). As a safety net, records also expire automatically, after at most 4 hours for an Alight Reminder and 2 hours for arrival tracking. |
1.7Crash and error reports
| What | Stack traces, error messages, the iOS version, device model, App version, and the Firebase App Instance ID. We do not set a custom user ID in Crashlytics. |
|---|---|
| Why | To identify and fix bugs and crashes. |
| Service | Firebase Crashlytics (Google LLC). |
1.8Usage analytics
| What | Pseudonymous, event-level data: which screens you open (e.g. weather, traffic dashboard, favourites), interaction events such as community-message-submitted (with the detected language only, never the message content), reaction-tapped (with the reaction type only), App Store rating prompt shown, and engagement events. The Firebase App Instance ID and Apple's IDFV are automatically collected by the Firebase SDK. |
|---|---|
| Why | To understand which features are used and where the App needs improvement. |
| What is not collected | Your name, email, phone, location, search queries, message content, or stop codes you view. |
| Service | Firebase Analytics (Google LLC). |
| Retention | 14 months (the maximum we configure in the Firebase console). |
1.9What we do not collect
- Your name, email address, phone number, photos, contacts, microphone, or health data. (The bus stop scanner uses the camera live on your device without capturing or storing anything; see §1.11.)
- Your location while the App and widget are not in use (the only exception is during an active Alight Reminder, and even then your location stays on your device; see §1.1).
- Your search queries by name, code, or service number. These are processed locally on your device against bus-stop and bus-service data already on the device. (A postal-code search is the one exception; see §1.10.)
- Browsing or usage data from other apps. We do not use the App Tracking Transparency (ATT) tracking permission.
- Any payment information. Bustro is free and contains no in-app purchases or advertising.
We do not send marketing or commercial electronic messages. Push notifications carry only the operational alerts and Commute Feed updates you have opted in to, and Bustro does not engage in any activity subject to the Spam Control Act 2007.
1.10Postal code search and search history
| What | When you search by postal code, the 6-digit code you type is sent to Apple's CLGeocoder to resolve it to a location. This is the one search input that leaves your device. Separately, the bus stops and services you select from Search (including postal-code results) are kept in a local history, with the time of each selection. |
|---|---|
| Why | Postal-code lookup: to find the bus stops nearest that address. Search history: to show your recent selections and favourites at the top of Search, so you can find them again in one tap. |
| Storage | Postal-code lookups are not stored by us. Apple's geocoding privacy practices apply to that request. Search history is stored locally on your device only (UserDefaults), capped at 10 entries, not synced via iCloud, and never sent to our servers. |
| Control | Swipe to remove a single history entry, or use "Clear All" in Search to erase your history. Uninstalling the App also clears it. |
1.11Camera (bus stop scanner)
| What | A live camera preview, shown only while the bus stop scanner is open. Bustro reads the QR code or the printed 5-digit stop number that appears inside the on-screen frame. |
|---|---|
| Why | To open a bus stop from the code on its pole, without typing it. |
| When | Only while you have the scanner screen open. Closing the scanner ends camera access. No other feature uses the camera. |
| Storage | None. Recognition runs on your device through Apple's VisionKit, and only on the part of the picture inside the frame. No photo or video is captured, saved, or transmitted, neither to us nor to any third party. The only thing the scanner produces is a 5-digit stop code, which is looked up against the bus-stop data already stored on your device. |
| Control | iOS Settings → Privacy & Security → Camera → Bustro. Declining camera access disables only the scanner; every other way of finding a stop continues to work. |
On-device intelligence (Foundation Models)
Bustro uses Apple's on-device Foundation Models (iOS 26+) to generate the short transit-mood headline shown above the bus-stop list. Generation runs entirely on your device. Weather context used to seed the prompt is never sent to Apple, to us, or to any third party. If on-device generation fails for any reason, a deterministic scripted fallback runs locally instead.
How we use your information
We use the data described in §1 only to:
- Show bus stops near you, calculate walking distances, and power the widget;
- Read a bus stop's QR code or printed stop number through the camera, on your device, to open that stop (§1.11);
- Run the Alight Reminders and arrival trackers you start, including pushing live countdown updates and alerts to your Lock Screen (§1.6);
- Save your favourites and journeys and sync them across your Apple devices via iCloud;
- Display, moderate, edit, and delete Commute Feed content you submit;
- Deliver traffic-alert and Commute Feed notification pushes you have opted in to;
- Generate crash reports and usage analytics to fix bugs and improve features;
- Decide which version of the App to recommend (Firebase Remote Config gates an in-app "update available" prompt; it does not personalise content);
- Comply with applicable law and respond to lawful requests from authorities.
We take reasonable steps to keep the personal data we hold about you accurate and complete (PDPA §23), and you may request correction of any inaccurate data at any time (§6).
Third parties and cross-border transfers
We use the following third-party services. Each has its own privacy practices.
| Service | Operator | Data shared | Purpose | Region |
|---|---|---|---|---|
| Firebase Analytics | Google LLC | App Instance ID, event names, device model, OS version | Usage analytics | US / EU |
| Firebase Crashlytics | Google LLC | App Instance ID, crash logs, device model, OS version | Diagnostics | US / EU |
| Firebase Cloud Messaging | Google LLC | APNs token, FCM token, device identifier, subscription list | Push delivery | US / EU |
| Firebase Firestore | Google LLC | Commute Feed post text, URLs, reactions, device identifier, FCM token, subscriptions, Live Activity push tokens with the tracked stop and service (§1.6) | UGC storage, push routing, Live Activity updates | Singapore (asia-southeast1) |
| Firebase Remote Config | Google LLC | App version, App Instance ID | Gate in-app "update available" prompt | US / EU |
| Google Forms | Google LLC | Only if you choose Report a Bug or Request a Feature: the form is pre-filled with your app version, iOS version, and device model, plus whatever you type | Bug reports and feature requests | US / EU |
| Apple Push Notification service | Apple Inc. | Device push token | Push delivery | Apple infrastructure |
| Apple iCloud / CloudKit | Apple Inc. | Favourites and pinned services | Sync across your Apple devices | Apple infrastructure |
Apple LinkPresentation | Apple Inc. (your device contacts the linked site) | URL, your IP | Render link previews in Commute Feed posts | Direct from your device to the linked site |
| Singapore LTA DataMall | Land Transport Authority of Singapore | Only an API key (no user data) | Real-time bus arrivals, stops, services, routes | Singapore |
| BusRouter SG | data.busrouter.sg | Only an API key (no user data) | Bus route geometry | Singapore |
| Singapore Government data.gov.sg | Government Technology Agency of Singapore | Only an API key (no user data) | Weather, rainfall, lightning, air quality, temperature. Fetched in bulk for all of Singapore; the relevant zone for your location is selected on your device | Singapore |
| Apple Maps / Google Maps | Apple Inc. / Google LLC | Stop coordinates when you tap "Get Directions" | External directions | Per provider |
Apple CLGeocoder | Apple Inc. | The postal code you type in Search | Resolve a postal code to a location for bus stop search | Apple infrastructure |
Cross-border data transfers (PDPA §26). Firestore records (Commute Feed content, push-routing records, and Live Activity tokens) are stored in Google's asia-southeast1 (Singapore) region. Firebase Analytics, Crashlytics, Cloud Messaging, and Remote Config are processed by Google LLC on infrastructure that may be in the United States or European Union. Google's data-protection terms (https://firebase.google.com/support/privacy) bind Google to provide a standard of protection comparable to what the PDPA requires; we rely on those terms for compliance with PDPA Section 26.
We do not sell, rent, or trade your information. We do not share data with advertisers, data brokers, or analytics providers other than those listed above.
We may disclose information when required to do so by Singapore law, by a valid order of a Singapore court, or by a Singapore regulator or law-enforcement authority acting within its statutory powers (including the Personal Data Protection Commission, the Infocomm Media Development Authority, and the Singapore Police Force under the Criminal Procedure Code), or to protect the rights, property, or safety of users, the public, or us. Where the law permits, we will notify the affected user before disclosing their information.
Retention
| Data | Retention |
|---|---|
| Location | Not retained; processed in memory on your device only |
| Device identifier | Until you reinstall the App, reset device identity (planned), or request deletion |
| Favourites, pinned services & saved journeys | Until you delete them, sign out of iCloud, or delete the App |
| Alight Reminder Live Activity token | Deleted when the reminder ends; expires automatically after at most 4 hours |
| Track Arrival Live Activity token | Deleted when tracking stops; expires automatically after at most 2 hours |
| User-submitted Commute Feed posts | 7 days, then automatic deletion |
| Official advisories and LTA alerts | Indefinite (no personal data) |
| Reactions | Deleted with the message |
| FCM token + subscriptions | Until you uninstall, revoke notifications, or change subscriptions |
| Firebase Analytics events | 14 months |
| Crashlytics records | 90 days (Google default) |
| Email correspondence with us | Up to 24 months for support and dispute-resolution purposes |
| Search history | Until you clear it, remove an entry, or delete the App; capped at 10 entries |
Your rights
Under the PDPA you have the right to:
- Access: request a copy of personal data we hold about you (Commute Feed posts tied to your device, your push token, your subscription list). PDPA §21.
- Correction: request that inaccurate data be corrected. PDPA §22.
- Withdraw consent at any time, which (subject to legal retention obligations) will result in deletion of your data. PDPA §16. See §7 below for the practical ways to do this.
- Lodge a complaint with the Personal Data Protection Commission of Singapore at https://www.pdpc.gov.sg.
To exercise any right, email hi@bustro.app. You will need to provide the device identifier on which you used the App so we can locate the relevant data. We cannot honour requests we cannot tie to a record. We aim to respond within 30 days.
If you are a resident of a jurisdiction with its own data-protection regime and would like to exercise rights granted by your local law, email us at the same address. We will assess such requests in good faith, even where the local regime does not formally apply to us.
Withdrawing consent
You can withdraw consent at any time by:
- Revoking Location permission in iOS Settings;
- Revoking Notifications permission in iOS Settings;
- Revoking Camera permission in iOS Settings, which disables the bus stop scanner;
- Disabling iCloud sync for Bustro;
- Deleting your Commute Feed posts from within the App;
- Stopping an active Alight Reminder or arrival tracker, which deletes its push-token record;
- Deleting the App, which removes the device identifier and ends push delivery;
- Emailing hi@bustro.app to request server-side deletion of any remaining data.
Security
We protect your data using:
- iOS sandboxing and Keychain protection on your device;
- HTTPS/TLS for all network communication;
- Firebase's encryption at rest and in transit;
- Server-side admin review on Commute Feed submissions before publication;
- The principle of least data: we do not collect data we do not need.
No system is perfectly secure. If we become aware of a data breach affecting your personal data, we will notify the Personal Data Protection Commission of Singapore as soon as practicable, and in any case no later than 3 calendar days after we determine that the breach (a) is of a significant scale (affecting 500 or more individuals) or (b) results in, or is likely to result in, significant harm to an affected individual, in accordance with PDPA Part VIA (Data Breach Notification). Where a breach is likely to result in significant harm to you, we will also notify you in a reasonable manner.
Children and minors
Bustro is a general-audience public-transit utility, rated 4+ on the App Store. It is designed to be useful to Singapore students and young commuters who rely on buses to get to and from school, and there is no minimum age for using it for its primary purpose: checking bus arrival times, viewing stops, services, and routes, saving favourites, using the widget, viewing weather and traffic information, or viewing the Commute Feed.
For posting in the Commute Feed, you must be at least 13 years old. Every Commute Feed submission is reviewed and approved by a member of the Bustro team before it becomes visible to other users. This human review is part of our child-safety and content-quality controls, so that no harmful, identifying, or otherwise inappropriate content (whether about a young person or by one) is published. We may decline submissions and disable posting from a device if we have reason to believe the submitter is under 13.
If you are a parent or guardian and believe a child under 13 has submitted content, email hi@bustro.app and we will remove it.
Singapore Open Data Licence attribution
In accordance with the Singapore Open Data Licence v1.0:
Contains information from the Singapore Government data.gov.sg APIs, made available under the Singapore Open Data Licence version 1.0.
We also acknowledge Singapore LTA DataMall as the source of bus arrival, bus stop, and bus service information.
Changes to this Policy
We may update this Policy. The "Last updated" date at the top reflects the most recent revision. Material changes will be highlighted in-app or via push notification at least 14 days before they take effect, except where an immediate change is required by law or to address a security issue. Continued use of the App after the effective date constitutes acceptance.
Contact us
- General enquiries: hi@bustro.app
- Data Protection Officer: hi@bustro.app (mark "DPO" in the subject line)
- Privacy or content reports: hi@bustro.app
We aim to acknowledge most enquiries within 7 days, and to formally respond to data-rights requests within 30 days.
Compliance
This Policy is designed to comply with:
- Singapore Personal Data Protection Act 2012 (PDPA), including the Data Protection Provisions, Section 26 (transfer limitation), and Part VIA (data-breach notification);
- Apple App Store Review Guidelines, including 5.1 (Data Collection and Storage) and 1.2 (User-Generated Content);
- Apple App Privacy Nutrition Label disclosure requirements.
Bustro is built with privacy in mind: no ads, no trackers across other apps, no sale of data, and as little personal data on our servers as possible.