Last updated 22 September 2026
Waypoint is a school bus tracking service. A school's own staff run it for that school's
families. This policy covers the three Android apps — Waypoint Driver
(com.waypoint.driver), Waypoint Parents
(com.waypoint.parents) and Waypoint Admin
(com.waypoint.admin) — and the server behind them at
api.waypoint.best.
The service is not open to the public. You cannot create an account in any of these apps. A school issues a one-time join code to a parent, or a sign-in code to a driver, and without one the apps do nothing.
The three apps are very different in this respect, so they are listed separately rather than covered by one blanket statement.
This is the only app that collects location. While a driver is on a route — strictly between tapping START and tapping STOP — the app records the position of the phone and sends it to the school's server. Each recorded point holds:
This recording continues while the app is closed or the screen is off. It has to: a bus that stops reporting when the driver pockets the phone would freeze on every parent's map. A permanent notification is shown for the whole time tracking is active, and tracking stops when the driver taps STOP or the trip is ended.
Location is not collected before a trip starts or after it ends, and it is never collected outside working hours. The app has no mechanism for doing so: there is no tracking outside an active trip, and no way for a school to turn one on remotely.
The app also stores, on the phone, the driver's sign-in token and any position fixes that have not yet been uploaded. The queue exists so a dead spot on the route does not lose the trip; it is uploaded when the connection returns. Uninstalling the app deletes both.
Before the first trip, the driver is shown a dialog explaining this and must accept it. The date of that acceptance is recorded against the driver's record.
Collects no location. The app requests no location permission of any kind — the only permission it declares is internet access. It shows the position of the bus, which comes from the driver's phone via the school's server; the parent's own phone is never located, and the app cannot locate it.
Collects no location. Like the parent app, its only declared permission is internet access. It is the school office's tool for managing routes, stops, buses, drivers and the student roster.
| About | Held |
|---|---|
| Parents and staff | Name, email address, phone number, a hashed password, the join code issued to them and whether it has been used, and the time they last signed in. |
| Drivers | Name and contact details, licence number and expiry, and the date they accepted location tracking. |
| Students | Name, class, the stop they are assigned to, which guardians are linked to them, and days marked absent. |
| Trips | Start and end time, the last known position, and the full sequence of recorded positions for the trip. |
| Routes and buses | Route paths, stop names and coordinates, bus registration and capacity, and which driver and bus are assigned to which route. |
Passwords are stored only as a hash and cannot be read back. Drivers do not have passwords at all; they sign in with a code issued by the school.
One purpose: so that a parent can see where their child's bus is, and a school can run its buses. Specifically, the recorded positions drive the live map, the arrival estimate for each stop, and the school's own record of how a route actually ran.
The data is not used to monitor drivers outside working hours, to build a profile of anybody, to advertise, or for anything unrelated to the bus service.
A parent sees the bus their own child is assigned to, and their own child's details. They cannot see other families' children or other routes. School staff see their own school's data only.
The data is not sold, and not shared with advertisers, data brokers or analytics companies.
There is no analytics SDK and no crash-reporting SDK in any of the three apps. Nothing is sent to a third party when you open them.
Two third parties are nevertheless involved, and both are worth naming plainly:
Beyond that, data is disclosed only where the law requires it.
Recorded bus positions are currently kept indefinitely. The service does not yet delete old trip position data automatically, so positions recorded since the service began are still held. This is stated plainly because it is the current state of the system rather than the intended one; a retention limit is planned, and this policy will be updated with the period when it is in place.
Account and roster records — parents, drivers, students, routes — are kept while the school is using the service, and removed when the school removes them or stops using it.
Encrypted database backups are kept for 30 days and then deleted.
The school that issued your join code controls your records, so requests go through the school first. There is no self-service delete button in the apps today: school staff delete a parent, a driver or a student from the Admin app, which removes that record from the service.
You may ask, at the address at the top of this policy, for a copy of the data held about you or your child, for a correction, or for deletion. If the school cannot be reached, write to that address directly.
A driver who wants to stop being tracked stops the trip, or declines the tracking consent dialog — in which case the app cannot be used to run a route, because recording the bus position is the whole of what it does.
These apps are for adults: drivers, school staff and parents. They are not designed for or directed at children, and a child is not given an account.
The service does nevertheless hold information about children — name, class, assigned stop, guardians, absences — entered by school staff on the school's own authority as part of running its bus service. It records the position of the bus, from the driver's phone. No child's own device is ever located.
No system is perfectly secure, and this one is small and self-hosted. If you find a vulnerability, please report it to the address above rather than disclosing it publicly.
Material changes will be reflected here with a new date at the top. The retention period in section 5 is the change already expected.