Skip to content

Privacy policy

How Transport Chief collects, uses and protects personal information.

Effective date: 13 June 2026

1. Introduction

Transport Chief (“we”, “us” or “our”) is committed to protecting the privacy of the individuals and organisations that use our platform. This Privacy Policy explains what personal information we collect, how we use and protect it, and your rights in relation to it.

We are based in New Zealand and handle personal information in accordance with the Privacy Act 2020 and the Information Privacy Principles (IPPs) contained in that Act.

2. Our Role and Your Role

Transport Chief is a software-as-a-service platform used by passenger transport and bus operators. In some cases we collect personal information directly: for example, the contact and account details of the operators and authorised users who sign up to the Service.

In other cases, our operator customers enter information about their own clients, passengers, and drivers into the Service. Where we hold that information, we do so on the operator’s behalf and only to provide the Service to them. The operator is responsible for how that information is collected and used, and for giving its own customers any privacy notices required by law. If your information is held in the Service by an operator, please contact that operator directly to exercise your privacy rights.

If you are an operator, and you enter information about another person into the Service, whether that person is a client, a passenger, a driver or anyone else, you are responsible for meeting the privacy obligations that attach to collecting it and giving it to us. In New Zealand that includes IPP 3A of the Privacy Act 2020, which applies where an agency collects personal information about someone from a source other than that person, and which requires reasonable steps to be taken to make that person aware of the collection and of the matters IPP 3A lists. Our Terms of Service place the same obligation on you contractually.

In data protection terms, we are the controller of the information we collect about operator accounts, our website visitors, and people who contact us. We are a processor for the information an operator enters about its own clients, passengers and drivers, and the operator is the controller of that information. If you are a passenger, a client or a driver and you want to see, correct or delete information held about you in Transport Chief, please contact the operator you travelled with or work for. They decide what is held and for how long. We will help them respond, but we cannot act on their data without their instruction.

3. Information We Collect

Information you provide directly

  • Account registration details (name, email address, phone number, company name).
  • Billing information (processed securely by our payment processor; we do not store full card numbers).
  • Bookings, job details, client and passenger details, driver and vehicle records, and other data you enter into the Service.
  • Support or enquiry correspondence.

Information collected automatically

  • Log data: IP address, browser type, pages visited, and timestamps.
  • Device information: operating system, browser version.
  • Cookies and similar tracking technologies (see Section 8).

4. How We Use Your Information

We use the information we collect to:

  • provide, operate, and improve the Service;
  • process transactions and send related confirmations;
  • respond to your support requests and enquiries;
  • send product updates, security alerts, and administrative messages;
  • monitor and analyse usage to improve user experience and fix issues;
  • detect, investigate, and prevent fraudulent or unauthorised activity; and
  • comply with our legal obligations.

We will not use your personal information for direct marketing without your consent, and you can opt out at any time. Service, security and administrative messages about your account are not marketing, and we send those for as long as you hold an account with us.

5. Sharing Your Information

We do not sell your personal information. We may share it with third parties only in the following circumstances:

  • Service providers: trusted vendors who help us operate the Service (e.g., cloud hosting, payment processing, email delivery) under appropriate confidentiality obligations.
  • Legal requirements: where we are required to disclose information by law, court order, or regulatory authority.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, where the receiving party agrees to honour this Privacy Policy.
  • With your consent: in any other circumstance where you have provided explicit consent.

Providers who act only on our instructions

These providers process information on our behalf, for the purpose we give them, under confidentiality and data-protection obligations. They do not use it for their own purposes.

  • Amazon Web Services: cloud hosting and file storage, in Sydney, Australia.
  • SMTP2GO: delivery of transactional and notification email.
  • HERE: address lookup, geocoding and routing. It receives the addresses entered into the Service.
  • Cloudflare: bot protection on our forms (Turnstile). It receives session-level signals such as your IP address and browser, and does not set a persistent cross-site identifier.
  • Google: sign-in with Google.
  • Microsoft: sign-in with Microsoft.
  • ip-api.com: when you register, we look up your IP address to guess your time zone so the calendar is right on your first login. Your IP address is sent to that service for the lookup.

Where a provider stores or processes information outside New Zealand and Australia, it does so under the contractual protections described in Section 6. We may update this list as our providers change, and each provider only receives what it needs to perform its function.

Independent third parties who also use the information for their own purposes

These are not our processors. They decide for themselves how they use what they collect, and their own privacy terms apply as well as ours.

  • Google (Google Analytics): website analytics on our marketing site and in the application, so we can see which pages are used and where a journey breaks. Google is a data controller in its own right for what it collects. Unlike the others in this list, the tag runs at every level of the cookie banner: if you have not accepted analytics it runs in a cookieless mode and stores nothing on your device, but the request still carries your IP address and browser type to Google. Our Cookie Policy explains the levels and how to stop it entirely.
  • Microsoft (Clarity): product analytics, including session replay and heatmaps, loaded only if you accept analytics cookies. Microsoft is a data controller in its own right for the data Clarity collects, and retains it for 30 days.
  • OpenStreetMap Foundation: when a map is displayed in the application, your browser fetches the map images directly from OpenStreetMap. That request carries your IP address and which part of the map you are looking at. It does not pass through our servers.

One thing that is not shared

We look up the country of an IP address using a database file held on our own servers, not an online service. That lookup sends nothing to anyone. Many services do the opposite, so it is worth being explicit.

6. Where Your Data Is Stored (Cross-Border Storage)

Your data is stored on cloud servers located in Australia. Because we are based in New Zealand, this means personal information is stored outside New Zealand. Before personal information is stored outside New Zealand we take reasonable steps to satisfy ourselves that the provider holding it is required to protect it with safeguards comparable to those in the Privacy Act 2020, which is what IPP 12 asks of us. For the Australian hosting we rely on the data protection terms in our agreement with our hosting provider. Section 11 explains what this means if you are in Europe.

We implement industry-standard technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction. These include encrypted data transmission (TLS), access controls, and regular security reviews. No method of transmission or storage is 100% secure; while we strive to protect your information, we cannot guarantee absolute security and encourage you to use a strong, unique password for your account.

If we become aware of a privacy breach that has caused, or is likely to cause, serious harm, we will comply with our obligations under the Privacy Act 2020, including notifying affected individuals and the Office of the Privacy Commissioner where required.

7. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. When data is no longer required, we delete or anonymise it securely.

Where we have a fixed period, it is:

  • Activity and event logs inside the Service: one year.
  • Application server log files: 62 days.
  • Google Analytics data: the retention period configured on our Google Analytics property, after which Google deletes the visitor-level records. Aggregate reporting totals are kept by Google beyond that.
  • Microsoft Clarity analytics data: 30 days, set by Microsoft.
  • Operator account and Operator Data: for as long as the account is active, plus the export period set out in our Terms of Service, after which it is deleted from our production systems.

Where we do not have a fixed period, we keep information only for as long as the purpose it was collected for still applies, or for as long as a legal, accounting or dispute-resolution obligation requires, whichever is longer.

Once deleted, your data may remain in our encrypted backups for a limited period before it is automatically removed as part of our routine backup-retention processes.

8. Cookies

We use cookies and similar technologies to maintain your session, remember your preferences, and understand how the Service is used. You can control cookies through your browser settings, but disabling certain cookies may affect the functionality of the Service. For details of the cookies we use and the choices available to you, see our Cookie Policy.

Analytics are a choice with three levels, and you make it on the cookie banner or through Cookie preferences in the footer of any page:

  • Necessary only: no analytics cookies. Google Analytics still counts the page view but writes nothing to your device.
  • Analytics: Google Analytics runs normally and sets its own cookies.
  • Analytics and session recording: Microsoft Clarity is loaded as well and records how you move around the site.

We use what this produces to understand which pages people actually use and to find journeys that break, and for nothing else. It is not used for advertising, and it is not sold or shared. You can change or withdraw your choice at any time from the same Cookie preferences link, and withdrawing is no harder than accepting. The Cookie Policy sets out exactly what each level loads, what happens when you withdraw, and what we cannot undo without a page reload.

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties and encourage you to review their privacy policies independently.

10. Your Rights

Under the Privacy Act 2020 and the Information Privacy Principles, you have the right to:

  • request access to the personal information we hold about you (IPP 6);
  • request correction of inaccurate or incomplete personal information (IPP 7); and
  • lodge a complaint with the Office of the Privacy Commissioner (OPC) if you believe we have breached the Information Privacy Principles.

The Privacy Act does not give you a general right to have information erased. You can still ask us to delete information we hold about you, or to stop using it for a particular purpose, and we will do that where we are able to. Sometimes we cannot, for example where a tax, accounting or other legal obligation requires us to keep it, or where the information sits in an operator’s records rather than ours. We will tell you which of those applies.

To exercise any of these rights, please contact us using the details in Section 15. (If your information is held in the Service by an operator customer, please see Section 2.)

11. Visitors and Customers in Europe (EU/EEA and UK)

We are a New Zealand business and we host customer data in Australia. We market the Service in New Zealand and Australia. We do not advertise in the European Union, we do not price in euro or pounds, and we do not offer the Service in an EU language. On our reading of the General Data Protection Regulation, that means the GDPR does not apply to us as a controller, because it turns on whether a business targets people in the EU rather than on whether its website can be reached from there.

We are setting out the following anyway. Most of it is simply what a reader is entitled to know, and we would rather say it than rely on a technicality.

Where your information goes, and what protects it

New Zealand is recognised by the European Commission as providing an adequate level of protection for personal data (Decision 2013/65/EU, confirmed by the Commission’s review of January 2024). Personal data may be transferred from the EEA to New Zealand on that basis without further safeguards. The United Kingdom recognises New Zealand in the same way.

Australia, where the servers are, does not have such a decision. Amazon Web Services, which hosts the data, incorporates a data processing addendum into the AWS Service Terms that applies to all of its customers, and that addendum relies on the European Commission’s Standard Contractual Clauses where data goes to a country without an adequacy decision. That is the safeguard for the Australian leg.

Our role, if you are a passenger, client or driver

If your information is in the Service because an operator put it there, that operator is the controller and we are only its processor. Your rights run against the operator, not against us. Please contact the operator you travelled with or work for. We will help them respond, but we cannot act on their data without their instruction. Section 2 explains this split.

Why we use your information, and on what basis

  • Creating and running an operator account, providing the Service and billing for it: because it is necessary to perform our contract with you (Article 6(1)(b)).
  • Service, security and administrative emails: to perform that contract, and otherwise because we have a legitimate interest in keeping account holders informed about the service they are using (Article 6(1)(f)).
  • Security, fraud prevention, bot protection and server logs: because we have a legitimate interest in keeping the Service available and secure for everyone using it (Article 6(1)(f)).
  • Analytics: where analytics store or read anything on your device, only with your consent (Article 6(1)(a), and Article 5(3) of the ePrivacy Directive). You can withdraw that consent at any time, and withdrawing it is as easy as giving it. At the lowest level, before you have accepted anything, no analytics cookies are set and nothing is stored on your device, but a request still reaches Google carrying your IP address and browser type; our Cookie Policy says how to prevent that as well.
  • Marketing: only with your consent. We do not send marketing to people who have not asked for it.
  • Meeting our legal and regulatory obligations: because the law requires it (Article 6(1)(c)).
  • Information an operator enters about its clients, passengers and drivers: we act as processor. The operator decides the lawful basis for that information, not us.

Providing your account details is a contractual requirement rather than a statutory one. We cannot create or run an account without them.

We do not use your personal information to make automated decisions that produce legal effects concerning you or that similarly significantly affect you. The Service does automate work for operators, such as calculating a quote from the operator’s own pricing rules or suggesting how vehicles and drivers might be allocated, but those remain the operator’s decisions, made with the operator’s own rules, and a person at the operator stays in control of them.

Your rights, and what we can actually do

We would rather describe what we will really do than list rights we have no process behind, so this section does not restate the GDPR’s list of data subject rights as though we ran a programme built around them. What we offer is what Section 10 offers everyone, wherever they are: ask us for a copy of what we hold about you, ask us to correct it, and ask us to delete it or stop a particular use of it, which we will do where we are able to. Email us and we will tell you what we hold, what we can do about it and when. We will reply as quickly as we can, and in any event within the 20 working days that New Zealand privacy law allows us for a request of this kind. Some information we may have to keep, for example where an accounting or legal obligation requires it, and we will say so if that is the case.

If you are unhappy with how we have handled your information, you can complain to the data protection authority in your country. In the United Kingdom that is the Information Commissioner’s Office. You can also complain to the New Zealand Office of the Privacy Commissioner, which is the authority that actually has jurisdiction over us.

12. Residents of California

The California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to a business that meets at least one of three thresholds: annual gross revenue over roughly USD 26.6 million, buying, selling or sharing the personal information of 100,000 or more California consumers or households in a year, or deriving 50 percent or more of its revenue from selling or sharing personal information. We are well under all three, so the CCPA does not apply to us. We would rather tell you that than imply a compliance programme we do not run.

What follows is therefore a factual statement about what we do, not a claim of statutory compliance.

  • We do not share your personal information for cross-context behavioural advertising. We run no advertising, no remarketing and no advertising pixels, and advertising features are switched off in the analytics tools we use.
  • We do not sell your personal information. Read that alongside Section 5: our analytics provider is an independent controller of what it collects, and we want you to judge that arrangement with the facts in front of you rather than on the strength of one sentence.
  • What we collect and why: identifiers such as your name, email address and phone number, and commercial and internet activity information such as your account activity and how you use the site. We collect it to provide and secure the Service, to bill for it, and with your consent to understand how the site is used. Section 3 and Section 4 set this out in full.

You will not find a “Do Not Sell or Share My Personal Information” link on this site. There would be nothing behind it, and a control that does nothing is worse than no control at all. If you are a California resident and you want to know what we hold about you, or want it corrected or deleted, email us using the details in Section 15 and we will reply within 20 working days.

13. Children

The Service is sold to businesses, and we do not knowingly collect personal information from children through this website or through account signup. If you believe a child has given us personal information directly, please contact us and we will delete it.

That is separate from information an operator enters into the Service. Bus and coach operators run school routes and charter work, so an operator may well record information about passengers who are children. Where that happens the operator is the controller of that information, not us. It is the operator’s responsibility to have a lawful basis for holding it and to obtain any parental consent required, including under Article 8 of the GDPR, which sets a consent age of 16 unless the member state has lowered it, and under the Children’s Online Privacy Protection Act in the United States, which applies under 13.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Where we make material changes we will notify you by email or by a prominent notice within the Service before the changes take effect. Your continued use of the Service after the updated policy is posted constitutes your acceptance of the changes.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact us at:

Transport Chief
Email: info@transportchief.co.nz