Accounts — your display name, email address, authentication records and account timestamps. Supabase Auth processes passwords and stores a hash rather than the plain password. If you choose Google sign-in, Google provides basic account information such as your name, email address and profile image.
Account features — saved stops and reports you submit, including the transport type, route, stop, direction, incident date/time, selected issue, delay and any description or passenger-impact text you provide. Complete reports and written answers are visible only to your account and authorised service administration.
Public-safe report information — report totals and statistics may be shown in aggregate. For selected current-trip issues, such as a full or missing service, the issue category may briefly appear as a service notice to other users. These outputs do not include your name, email address or written answers.
Optional public quotation — if you deliberately enable the switch on a report, edited excerpts from its description or passenger-impact answers may be quoted on Where's My Bus Ireland after review. Account names and email addresses are not displayed, and identifying details should be removed. Because the original report remains linked to your account, this use is based on your consent rather than treating the source report as anonymous. You can withdraw permission from that report's details page.
Device location — only after you grant operating-system permission, and only to centre the map or use “My Location” in search and journey planning. Loading the map checks for an existing permission but does not itself ask for permission; the request appears when you choose the location control or “My Location”. You can decline and type a stop or address instead. The app does not store a history of device locations in the report database.
Searches — address/place text is sent through a Supabase function to LocationIQ to find matches. Stop-name searches use the transport data bundled with the app. Search text is not added to your account or report record, although infrastructure providers may create short-lived technical logs.
Walking directions — when you open a planned journey, the coordinates at the beginning and end of each walking section are sent through a Supabase function to Google Routes to calculate pedestrian distance, time and directions. Results may be cached on your device to reduce repeated requests and are not added to your account or report record.
Device-only information — recent journeys, visual preferences and cookie choices are stored in browser/app storage. Saved stops are also device-only when you use the app without an account. Guest saved stops remain separate from account-synced saved stops.
Technical information — IP address, browser/device type, request details, error messages and timestamps may be recorded by hosting, authentication and infrastructure providers for security, reliability and troubleshooting.