Privacy Policy
Last Updated: October 24, 2023
Navigster Privacy Policy
Updated on 21 July 2026 for Navigster-privacy.
1.
Who we are and what this policy covers
Navigster is an institutional transportation platform provided by Workbees Technologies. In this policy, "Navigster" means the product and its services, and "Workbees", "we", "us", and "our" mean the legal operator identified in the contact section.
This policy covers the Navigster User app for parents, guardians, and eligible students; the Navigster Driver app; the institution web dashboard; and the Navigster website. It explains what personal information we handle, why we use it, who can access it, how long we keep it, and how you can make a privacy request.
The information we process depends on your role and the features you use. We do not collect every category described below from every person.
2.
Information provided by you and your institution
Parents and students. Institutions provide student and parent information when setting up transport access. This includes the student's name, student identifier, class or section, parent or guardian name, registered mobile number, institution, and assigned route. An email address may be supplied for communication. We also process activation codes, account status, linked-student details, boarding-point coordinates, and alert preferences.
Your institution creates the transport record. Mobile-number verification and the activation code link your app access to that record. Where a parent is authorised for more than one child, we maintain the links needed to show each child's transport information.
Drivers. We process the driver's name, mobile number, driving licence number, institution, and account status. We record the bus scanned, route-recording sessions, trips operated, and operational actions such as a breakdown report or trip completion. Routine driver registration does not require a licence photograph or a copy of a government identity document.
Institution staff. We process staff names, work contact details, login identifiers, roles, access permissions, and administrative actions. Institution contact information can also identify an individual staff member.
Support enquiries. We process contact details, the issue described, and attachments voluntarily sent to support. Please avoid sharing information about unrelated students or other people.
3.
Location and transport information
Driver location during an active trip. With location permission, the Driver app collects precise coordinates, timestamps, speed, and GPS accuracy. We use these readings to show the bus location, calculate route progress and arrival estimates, deliver approach alerts, and maintain trip history. New trip-location collection ends when the trip is completed, terminated, or ended because of a breakdown.
Separate route recording. A driver can deliberately start a route-mapping session to record the driven route. We collect the route path, start and end points, direction, timestamps, and driver/bus association for institutional review. Recording stops when the driver ends the session. Route mapping can take place without an active passenger trip; it is not continuous monitoring of the driver.
App visibility and background collection. In this version, new device-location collection requires the relevant app to be open and in use. Navigster does not collect new GPS readings while the app is in the background or the phone is locked. If the app moves out of view, GPS is disabled, or connectivity is lost, fresh bus updates may stop. The displayed update time helps users identify an old location. Reopening the app synchronises the session and can resume permitted collection while the trip or recording session remains active.
Boarding points and approach alerts. We store the boarding point selected for the assigned route and the chosen alert radius, between 500 metres and 3 kilometres. Approach alerts compare the bus location with that saved point. Continuous access to the parent's phone location is not needed for those alerts. Device location can help position the map, but a boarding point can also be selected manually.
Optional proximity and boarding status. Where enabled and permitted, the User app sends limited, time-stamped location readings during an active trip while the app is open. We compare those readings with the bus position and movement to support a boarding or drop-status estimate. We also record responses to any status prompt. We do not build a continuous history of the user's movements outside the trip. Raw user-location readings used for this purpose are removed within 24 hours after the trip ends under our normal retention schedule.
A phone's proximity or movement does not prove that a particular child boarded or left the bus. These status updates are transport information, not an attendance register or a substitute for physical supervision. Declining this optional device-location use disables proximity-based status detection, while assigned-bus visibility and saved-point alerts remain available, subject to the user's access and plan.
Offline points and trip history. During a connectivity loss, the Driver app can temporarily store readings collected during an authorised session. It uploads them with their original timestamps after reconnection. These stored readings may be processed after live collection has stopped. They are not presented as new movement. Ending live tracking does not automatically delete previously recorded trip history.
4.
Technical information and device permissions
We process IP addresses, device and operating-system type, app version, session identifiers, notification tokens, error reports, and security or access logs. These help authenticate users, deliver notifications, detect abuse, troubleshoot failures, and understand service reliability. We use service statistics to improve the product without creating advertising profiles.
The Driver app uses the camera to scan the bus QR code. Camera frames are processed on the device and are not uploaded or kept as photographs. The decoded QR credential is sent to the service to identify and validate the bus.
SMS providers process the registered mobile number and message-delivery information for OTP authentication and institution activation invitations. Navigster does not request general access to your SMS inbox, contacts, call history, microphone, or photo library for its transport features.
Location permission supports the specific functions in section 3. Notification permission allows trip and service alerts. The app explains these uses at the relevant point, and you can change permissions through device settings. Driver GPS permission is necessary to record a route or supply live trip location. Permission withdrawal stops the associated collection but does not erase records already lawfully held.
5.
Why we use information
We use personal information to:
- Verify accounts and link the correct institution, student, route, driver, and bus.
- Provide active-trip visibility, arrival estimates, approach alerts, and enabled status updates.
- Record proposed routes and support their institutional review.
- Maintain transport records and investigate breakdowns or other service issues.
- Deliver OTPs, activation invitations, service notifications, and support responses.
- Protect accounts, prevent misuse, and maintain service reliability.
- Administer optional paid features, verify purchases, and handle billing support.
- Meet applicable legal obligations and respond to valid legal requests.
Where consent is needed, we obtain it through the relevant notice and affirmative action before the processing starts. Reading this policy or accepting general Terms does not by itself provide consent for every use of personal information. Optional promotional communications require a separate choice and include a way to opt out.
We do not sell personal information, use institution transport information for targeted advertising, or share identifiable trip and student records with data brokers.
6.
Who can access information
Your institution. Authorised administrators and transport staff can access the institution's transport records according to their role, including assigned students and routes, driver/bus associations, trips, relevant status updates, and operational events. Raw parent-device location is not shown on the dashboard; the institution sees only the transport information and status outputs it is authorised to receive.
Parents and student users. Users see information for their authorised student and route links, including the relevant bus's location during an active trip. They cannot browse other students' profiles, parent contact details, or personal phone locations.
Drivers. Drivers see their operational account, selected bus and route, trip state, and next-stop information. They are not given a directory of parents or students, individual users' live phone locations, or parent payment information through the Driver app.
Workbees personnel. Personnel with an operational need may access relevant information to provide support, investigate failures, protect the service, and administer the platform. Access is restricted by role and recorded where appropriate.
Service providers. Providers process information needed for the services below. Providers acting on our instructions are subject to contractual confidentiality, security, and purpose restrictions. Where a provider independently processes information, its own privacy terms also apply. We require appropriate protection for information we share.
| Provider or provider category | Purpose and information involved |
|---|---|
| Cloud hosting and database services | Store and process accounts, routes, trips, records, backups, and security logs. |
| Google Maps Platform | Display maps and support routing or arrival estimates using relevant coordinates and technical request information. We do not include student names or parent mobile numbers in routing requests. |
| Google Firebase Cloud Messaging and Apple push delivery services | Deliver app notifications using notification tokens and the limited payload needed for the alert. Push payloads exclude student rosters and precise user-device locations. |
| SMS and OTP delivery providers | Deliver authentication and activation messages using mobile numbers, message content, and delivery metadata. |
| App stores and payment providers used for a purchase | Process checkout and provide transaction references, purchase verification, payment status, refunds, and subscription information. |
| Support and technical monitoring services | Process support communications or diagnostic records needed to resolve issues. Unnecessary student details and location payloads are excluded from diagnostics. |
Google's privacy information is available at https://policies.google.com/privacy and Firebase's at https://firebase.google.com/support/privacy. Apple's is available at https://www.apple.com/legal/privacy/. You can ask our privacy contact for information about other providers relevant to your data.
We may disclose necessary information in response to applicable law, a valid legal process, or a lawful requirement to address security incidents or protect rights. If a business transfer changes responsibility for personal information, we will provide the notice and choices required by applicable law.
7.
Children and parental involvement
For institution transport, the User app is intended for parents or lawful guardians. It still processes information about the linked child. Students aged 18 or older can use institution-authorised student accounts. Any direct use by a student under 18 requires an appropriate parent or guardian process.
Before student information is provided, the institution must establish its authority to use it for Navigster transport services and deliver the relevant notice. Where parental consent is required, the institution and Workbees coordinate a record of the parent's informed choice and verification of adult identity and the relationship to the student. Institution-held reliable records may support that process; a phone OTP alone is not treated as proof of parental status or adulthood.
We restrict children's information to transport-related functions and associated support, security, and legal needs. We do not use it for advertising or unrelated profiling. Permission to show a bus route does not authorise continuous tracking of a child's or parent's phone.
A parent or guardian can contact our privacy contact to request correction, raise an unauthorised-link concern, or withdraw consent where applicable. We will coordinate with the institution and explain the effect on transport visibility. We do not treat an institution's upload as a substitute for a consent process where one is required.
8.
How we work with institutions
Institutions decide transport arrangements, enrolment, routes, and authorised staff access. Workbees processes institution-supplied transport records to provide the agreed service under the institution's documented instructions. Workbees also determines the necessary handling of its own account security, direct support, and any direct user billing.
An institution remains responsible for the accuracy and lawful provision of records it supplies and for its independent use of those records. Workbees remains responsible for its own processing and service providers. You can contact us directly about Navigster's handling of your data; we will coordinate with the institution rather than require you to resolve that division of responsibilities yourself.
9.
Storage and security
Our primary application database and routine backups are hosted in India. Providers supporting maps, notifications, payments, and other technical functions may process limited information in other countries. We apply contractual and technical safeguards and comply with applicable restrictions on international processing. Primary hosting in India does not mean every provider processes all information only in India.
We use encrypted network connections, role-based access, separation between institutions, restricted administration, security logging, and protected backups. Staff and providers receive access only as needed for their functions. No online system is completely risk-free. We assess personal-data incidents and notify affected people and authorities where applicable law requires it.
10.
Retention and deletion periods
The periods below are our normal operating limits. An eligible deletion request can result in earlier removal of account-linked information. Specific legal retention duties override these operating limits only for the records and period that the law requires. We restrict any retained exception records to that purpose and explain the applicable category, reason, and period when responding to a request, unless the law prevents disclosure.
| Information | Normal retention limit |
|---|---|
| Profiles, institution links, boarding points, and preferences | While needed for the active service relationship; removed within 30 calendar days after a verified deletion request or confirmed permanent service closure. Dormant records are reviewed annually. |
| Raw driver GPS and location history | Up to 90 days after the trip ends. |
| Raw user-device proximity readings | Up to 24 hours after the trip ends; saved boarding points and resulting status events follow their separate schedules. |
| Trip summaries and boarding or drop-status events | Up to 12 months after the trip ends, unless an earlier eligible deletion request applies. |
| Approved routes and route versions | While operationally needed; up to 12 months after retirement for trip-record continuity. Driver identifiers follow account-deletion rules. |
| Pending or rejected route recordings | Up to 90 days after submission or rejection if not approved for use. |
| Offline GPS stored on the driver's device | Removed within 24 hours of confirmed upload, or within 72 hours of collection if upload remains unsuccessful. |
| Security logs and administrative audit records | Up to 12 months from the event for security and accountability, subject to any specific legal retention or investigation hold. |
| Technical error and crash diagnostics | Up to 90 days after collection. |
| Support cases | Up to 12 months after closure, subject to earlier deletion where applicable. |
| Minimal consent and completed privacy-request records | Up to 12 months after withdrawal or request completion where necessary for accountability or a legal requirement; access is restricted. |
| Billing and tax records | Only necessary transaction and invoice information, for the statutory accounting or tax period applicable to the record. This does not include trip GPS or student movement history. |
| Routine backups | Rolling expiry within 90 days. Deleted data may persist in restricted backups until expiry, for no more than 90 additional days after deletion from live systems. |
Expiry means deletion or irreversible anonymisation where appropriate. Replacing a name with an identifier alone is not irreversible anonymisation. We do not retain identifiable history indefinitely merely because operational records cannot be edited through the dashboard.
If a backup is restored, deletion instructions are reapplied before the restored personal information is returned to normal service. Provider deletion follows our instructions and applicable retention duties. Specific investigation or legal holds are reviewed and removed when their purpose ends.
11.
Your choices and account deletion
You can ask us for access to information about you, correction of inaccurate information, deletion, withdrawal of consent where relevant, or review of a privacy concern. Additional rights available under applicable law remain available through our privacy contact. We use proportionate verification, normally through your registered account or mobile number, before disclosing or deleting information.
From either app: open Menu, select Account, and choose Delete account. Review the effect, complete verification if requested, and confirm. This starts deletion of the account and associated personal information, not merely logout or suspension.
Without the app: use https://navigster.com/delete-account. You can verify the registered mobile number and submit a request without reinstalling the app. If you cannot access that number, our privacy contact provides an alternative verification route. Dashboard users can also use that page or the privacy contact. An authorised institution representative can request service closure; an individual staff request does not automatically close the whole institution.
We aim to acknowledge privacy requests within 3 business days and respond within 30 calendar days. Verified account-deletion requests are completed in live systems within 30 calendar days, subject to the specific retention exceptions and backup expiry explained above. We confirm completion and identify any retained exceptions. Any shorter legally required deadline takes priority. We explain additional time if permitted and needed for another type of request.
Deleting a parent account removes its app access and student links. It does not automatically delete another guardian's account or records held independently by the institution. Shared operational records are assessed for removal, irreversible anonymisation, or a justified retention exception; their association with an institution is not by itself a reason to keep your personal data forever.
Subscriptions. Deleting an account does not automatically cancel an app-store-managed subscription. The deletion flow explains how to manage any active subscription through the original store or payment provider. You can request deletion without waiting for a paid period to expire. Refund and cancellation handling is described separately at https://navigster.com/subscription-terms.
Disabling notifications, revoking a permission, or uninstalling the app does not delete the account. Withdrawing consent stops the relevant future processing unless another lawful basis applies; it does not automatically remove information that must be kept for a valid legal reason.
12.
Website cookies and similar technologies
The website and dashboard use essential session, authentication, security, and preference storage. Session data normally expires on logout or session expiry; preferences remain until changed, cleared, or no longer required. These technologies are not used for advertising profiles.
The launch configuration does not use advertising cookies or optional third-party website analytics. If optional analytics or marketing technologies are introduced, we will describe them, identify their purposes and providers, and provide any required consent controls before they operate. Browser controls can remove stored website data, but doing so may sign you out or reset preferences.
13.
Policy updates
The current version of this policy is available at https://navigster.com/privacy. We update the displayed effective date when a revised version takes effect. Material changes are communicated through the app, dashboard, website, or registered contact channel as appropriate. If a new use requires consent, we obtain that consent before starting it.
14.
Privacy contact
For privacy requests or complaints, include your registered mobile number, institution, and a brief description of the request. Do not send passwords, OTPs, full payment-card details, or unnecessary identity documents.
Product: Navigster
Business name: Workbees Technologies
Legal operator and business type: Workbees Technologies opc private limited
Business address: Registered Office: 3rd Floor, Pranava Business Park, ODCWL, Kothaguda Village, Building No./Flat No. 2-40/37TO39P,44P/3F/U-11, Road No. 5, Beside Harsh Toyota Showroom, Kothaguda, Kondapur, Hyderabad, Rangareddy, Telangana – 500084, India
Privacy and grievance email: support@navigster.com
Customer care and grievance phone: +91 90103 00299
Grievance officer: Mr. Samudra Varma Palepu — Founder & Chief Executive Officer (CEO), Grievance Officer
General support email: support@navigster.com
Support page: https://navigster.com/support
Navigster Privacy Office
Privacy and grievance email: support@navigster.com
General support email: support@navigster.com
Customer care and grievance phone: +91 90103 00299
Address: Registered Office: 3rd Floor, Pranava Business Park, ODCWL, Kothaguda Village, Building No./Flat No. 2-40/37TO39P,44P/3F/U-11, Road No. 5, Beside Harsh Toyota Showroom, Kothaguda, Kondapur, Hyderabad, Rangareddy, Telangana - 500084, India