VEA Driver Privacy Policy
Vermont Employment Agency
Effective Date: October 12, 2025Last Updated: October 12, 2025
🔒 No Advertising or Cross-App Tracking
VEA Driver does NOT track users for advertising purposes, does NOT share data with advertising networks, and does NOT engage in cross-app tracking. All data collection serves legitimate business purposes only - specifically for shuttle route management, driver coordination, and commuter transportation services.
This Privacy Policy explains how Vermont Employment Agency ("VEA", "we", "us", or "our") collects, uses, and protects your information when you use the VEA Driver mobile application (the "App").
1. Introduction
VEA Driver is a professional shuttle driver management application designed exclusively for Vermont Employment Agency drivers. The app enables drivers to manage their daily routes, check in/out commuters, record route observations, and communicate with supervisors in real-time.
By using the VEA Driver app, you consent to the collection and use of information as described in this policy.
2. Who We Are
VEA Driver is provided by Vermont Employment Agency, a transportation and employment services company based in South Burlington, Vermont. We operate shuttle services connecting employees and commuters to their workplaces and destinations.
3. Scope
This Privacy Policy applies to the VEA Driver mobile application for iOS and Android, and to related webpages we host for support and policy information. Your use of the app is also governed by any employment agreements between you and Vermont Employment Agency.
4. Information We Collect
A. Login and Authentication Information
- Phone Number: Used for secure authentication and driver identification
- Driver ID: Internal identifier linking you to your driver profile
- Employee ID: If you are also an employee with a profile
- Session Tokens: JWT tokens for secure API communication
B. Driver Profile Information
- Full Name: Displayed in the app and visible to supervisors
- Profile Photo/Avatar: If you have an employee profile with a photo
- Gender: Used only for avatar display purposes with appropriate colors
- Vehicle Assignment: Which vehicle you are assigned to drive
C. Location Data
- Real-Time GPS Location: Collected during active driving sessions for route tracking
- Background Location: May be collected if you enable "Always Allow" location permissions for continuous route tracking
- Pickup/Dropoff Locations: Addresses and coordinates of commuter locations
- Usage: Location is used for route coordination, commuter pickup verification, and driver safety monitoring
- Retention: Session-based data, not stored long-term beyond operational needs
D. Route Management Data
- Commuter Information: Names, addresses, phone numbers (for contact), photos/avatars
- Check-In/Check-Out Status: Timestamps and status of commuter pickups and dropoffs
- Route Notes: Observations, issues, unlisted passengers, and other driver-reported information
- Vehicle Information: Vehicle make, model, year, license plate, NHTSA vehicle ID
E. Device and Usage Information
- Device Information: Device model, operating system version, app version
- Network Information: IP address, network connection type (WiFi/cellular)
- Firebase Cloud Messaging Token: For push notifications
- App Usage: Login/logout times, feature usage, error logs for debugging
- Language Preference: Selected language (English, French, Swahili, Haitian Creole, Nepali)
F. Commuter Data (Accessed, Not Owned by Driver)
This information belongs to VEA and is accessed solely for performing driver duties:
- Commuter names, photos, and contact information
- Pickup and dropoff addresses
- Client and department information
- Special instructions and accessibility needs
5. How We Use Information
Primary Purposes:
- Authentication & Access: Verify your identity and authorize app access
- Route Management: Display assigned commuters, pickup/dropoff locations, and route details
- Real-Time Coordination: Enable communication between drivers, supervisors, and dispatch
- Service Delivery: Facilitate shuttle service operations and commuter transportation
- Safety & Monitoring: Track routes for driver and commuter safety
- Record Keeping: Maintain records of check-ins, route notes, and driver observations
- Notifications: Send route updates, schedule changes, and system alerts
- Service Improvement: Analyze usage patterns to improve app features and performance
- Support: Provide technical support and troubleshoot issues
- Compliance: Meet legal, regulatory, and business record-keeping obligations
What We DON'T Do:
- ❌ NO Advertising: We do not use your data for advertising purposes or behavioral targeting
- ❌ NO Data Selling: We never sell your personal information to third parties
- ❌ NO Cross-App Tracking: We do not track you across other apps or websites
6. Information Sharing and Disclosure
6.1 Within VEA
Your information is shared internally with:
- Supervisors: Route notes, check-in status, location during shifts, performance monitoring
- Dispatch: Real-time location for route coordination and emergency response
- Management: Service quality monitoring, compliance, and operational reporting
- HR Department: Driver records, employment information, payroll integration
6.2 Third-Party Service Providers
We use carefully selected service providers who process information only on our behalf:
| Service Provider | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|
| Firebase (Google) | Push notifications, analytics, crash reporting | FCM token, device info, app usage, error logs | Firebase Privacy |
| AWS S3 (Amazon) | Photo and avatar storage | Profile images, commuter photos | AWS Privacy |
| NHTSA (US Gov) | Vehicle images | Vehicle ID only (no personal data) | NHTSA Privacy |
6.3 Legal Requirements
We may disclose your information if required to do so by law or in response to:
- Valid legal process (subpoenas, court orders)
- Government or law enforcement requests
- Protection of our rights, property, or safety
- Protection of drivers, commuters, or the public
- Fraud prevention and security investigations
6.4 What We DON'T Share
- ✅ We do NOT sell your personal information
- ✅ We do NOT share data with advertising networks
- ✅ We do NOT share data for cross-context behavioral advertising
- ✅ We do NOT share location data with unauthorized third parties
7. Data Security
7.1 Security Measures
We implement comprehensive security measures to protect your information:
- Encryption: All data transmitted between the app and our servers uses HTTPS/TLS encryption
- Authentication: JWT token-based secure authentication with automatic expiration
- Storage: Encrypted local storage (AsyncStorage) on your device
- Access Control: Role-based permissions ensure only authorized personnel access your data
- Backend Security: Secure servers with regular security updates, firewalls, and intrusion detection
- API Rate Limiting: Protection against brute force attacks (100 requests/minute limit)
- Session Management: Automatic logout and session expiration for inactive accounts
7.2 Your Security Responsibilities
- Keep your phone number and login credentials secure
- Logout when you finish your shift
- Use strong device security (PIN, biometric authentication)
- Report lost or stolen devices immediately
- Report any unauthorized access to your account
7.3 Data Breach Notification
In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by law.
8. Data Retention
We retain your information for as long as necessary to provide services and meet legal obligations:
- Active Session Data: Duration of your driving shift
- Check-In/Check-Out Records: Retained for payroll, billing, and audit purposes (typically 7 years)
- Route Notes: Retained per business operational needs and legal requirements
- Location Data: Session-based, retained briefly for operational purposes
- Driver Profile: Duration of employment plus retention period as required by law
- Deleted Accounts: Personal data removed within 30 days of account deletion, except where retention is required
9. Your Privacy Rights
9.1 Access and Control
You have the following rights regarding your personal information:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request removal of your data (subject to legal obligations)
- Portability: Receive your data in a structured, machine-readable format
- Opt-Out: Disable location services or push notifications in app settings
9.2 California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights:
- Right to know what personal information is collected, used, shared, or sold
- Right to deletion of your personal information
- Right to opt-out of sale or sharing (we don't sell or share)
- Right to correct inaccurate personal information
- Right to limit use of sensitive personal information
- Right to non-discrimination for exercising your rights
9.3 GDPR Rights (European Users)
If you are in the European Economic Area, you have rights under GDPR:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
9.4 How to Exercise Your Rights
To exercise any of these rights:
- Email: privacy@veatimeclock.com
- Phone: (802) 448-3957
- Mail: Vermont Employment Agency, ATTN: Privacy Officer, 1944 Williston Road, South Burlington, VT 05403
We may need to verify your identity and, if applicable, work with VEA management to fulfill requests.
10. Location Services
10.1 Location Permission Types
- When In Use: Location accessed only while the app is open and active
- Always / Allow All the Time: Background location for continuous route tracking (optional)
10.2 How We Use Location
- Real-time route tracking during your shift
- Verify commuter pickup and dropoff locations
- Driver safety and emergency response
- Route optimization and navigation assistance
10.3 Managing Location Permissions
iOS: Settings → Privacy & Security → Location Services → VEA Driver
Android: Settings → Apps → VEA Driver → Permissions → Location
Note: Disabling location services may limit app functionality, particularly route tracking features.
11. Push Notifications
11.1 Notification Types
- Route updates and schedule changes
- New commuter assignments
- System alerts and important messages
- Emergency notifications
11.2 Managing Notifications
In-App: Settings → Push Notifications
iOS: Settings → Notifications → VEA Driver
Android: Settings → Apps → VEA Driver → Notifications
12. International Data Transfers
Your information may be processed in the United States and other locations where we or our service providers operate. We take steps to protect information in accordance with this Policy and applicable law, including:
- Standard contractual clauses
- Data protection agreements with service providers
- Encryption during transmission and storage
- Compliance with international privacy frameworks
13. Children's Privacy
VEA Driver is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will take appropriate steps to delete it.
If you believe a child has provided information to us, please contact us immediately at privacy@veatimeclock.com.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you via push notification in the app
- Post the updated policy on our website
- Provide at least 30 days notice for material changes (where feasible)
Your continued use of the app after changes are posted constitutes acceptance of the updated policy.
15. Contact Us
For questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us:
Vermont Employment Agency
Privacy Officer / Data Protection
📍 Address:
1944 Williston Road
South Burlington, VT 05403
United States
📞 Phone: (802) 448-3957
✉️ Email: info@veatimeclock.com
🔐 Privacy: privacy@veatimeclock.com
🌐 Website: portal.veatimeclock.com
16. App Store Privacy Summary
✅ Apple App Store & Google Play Store Compliance
Data Used to Track You: NONE - VEA Driver does not track users across apps or websites for advertising purposes. All data collection is for legitimate business functionality only.
Data Collection Summary
| Data Category | Examples | Purpose | Linked to User | Used for Tracking |
|---|---|---|---|---|
| Contact Info | Phone number, name | Authentication, driver identification, in-app display | ✅ Yes | ❌ No |
| Location | Precise GPS location | Route tracking, commuter pickup coordination, driver safety | ✅ Yes | ❌ No |
| User Content | Route notes, observations | Communication with supervisors, service documentation | ✅ Yes | ❌ No |
| Identifiers | Driver ID, employee ID, device token | Account management, push notifications, security | ✅ Yes | ❌ No |
| Usage Data | App interactions, feature usage, error logs | App functionality, diagnostics, service improvement | ⚠️ May be | ❌ No |
| Diagnostics | Crash data, performance logs | Bug fixes, performance optimization | ⚠️ May be | ❌ No |
Third-Party Data Access
- Firebase (Google): Push notifications, crash reporting, analytics
- AWS S3 (Amazon): Photo storage only
- NHTSA: Vehicle images (no personal data shared)
Key Privacy Commitments
✅ We DO:
- Collect only necessary data for shuttle operations
- Use encryption for all data transmission
- Provide transparent privacy practices
- Honor your privacy rights and choices
- Limit data access to authorized personnel
- Comply with privacy laws and regulations
❌ We DON'T:
- Sell your personal information
- Use data for advertising or marketing
- Track you across other apps or websites
- Share data with advertising networks
- Collect data from children under 18
- Share location with unauthorized parties