DevaHop is a small, independent, community-powered bus-tracking tool for the Citadel Shuttle in Deva. This page explains, plainly, what data the app collects and why. DevaHop does not use cookies, does not run ads or third-party trackers, and does not sell or share data with anyone.
The short version
✓No account required
✓No ads, ever
✓No location tracking
✓No data sold or shared — ever
What DevaHop collects
A random device identifier, generated and stored locally in your browser (not a cookie). It is not linked to your name or email. Because an online/device identifier can potentially be considered personal data under applicable privacy law, DevaHop treats it conservatively and uses it only for the functions described here. Creating an account is optional and is not required to use DevaHop. Your device identifier is hashed in your browser before it is sent to our servers; the raw identifier never leaves your device.
Your Scout handle — a randomly generated pair of words plus a number (e.g. “Carpathian Falcon 195”), also stored in your browser. It is designed as a nickname and is not linked to your name, email, phone number, or other directly identifying information.
The reports you submit — which stop, what you reported (e.g. “Bus is Leaving Now”), and when. These are stored to show the live community status to other riders.
Your device’s own trip progress (e.g. “currently heading to the Citadel”) — used only to show or hide the right buttons for you.
A one-way hashed version of your IP address, kept only to prevent spam/abuse (e.g. a script flooding fake reports). Your real IP address is never stored — only a one-way cryptographic hash. Because hashed online identifiers can still potentially be personal data, DevaHop treats this information conservatively. The hash changes every day and these records are automatically deleted after up to 48 hours.
What DevaHop does not collect
No name, email, or phone number for riders using the app
No precise location or GPS tracking
No cookies for riders using the app — the only cookie DevaHop ever sets is a login session for the single admin account, used solely to view the operational debug log described below
No advertising, analytics, or third-party trackers of any kind
Aggregate usage statistics
DevaHop keeps limited aggregate statistics about overall service usage — for example, the number of journeys started, journeys completed, reports submitted, Station Confirmed taps, and XP awarded per day, and which lines are actually used. These are day-level totals, not a record of what any individual rider did. DevaHop does not use these statistics to build individual behavioral profiles.
Journey GPS coordinates are never sent to, or stored by, this statistics system — GPS stays entirely on your device and is used only to advance Journey Mode locally
No individual event history is kept — a report or a journey is counted once, as a total, not logged as “this device did this at this time”
A day-scoped, one-way hashed device identifier — a different hash than the ones described above, and not stored as a name or profile — is used only to avoid counting the same device more than once on the same day; it is discarded within a couple of days
Operational debug log (testing periods only)
During active testing and maintenance periods, DevaHop temporarily records a log of report activity to help diagnose display/timing bugs — for example, confirming that both direction pages show consistent information after a report. This log:
Does not include IP address, in any form — it is not needed for this purpose, so it is not collected here
Stores your device identifier only as a one-way hash (a different hash than the one used for abuse prevention), not the raw value
Includes timestamps and app state (which buttons were available, what the status pages showed) — this is the actual diagnostic data the log exists to capture
Is visible only to the single admin account (Google sign-in, restricted to one specific email address) — there is no public or rider-facing access to this data
Is not run continuously — it is used in short, periodic testing/maintenance windows, not as an ongoing feature
Why this data is collected
Solely to make the app work: showing real-time, community-reported bus status, and preventing spam from breaking that for everyone else. Nothing here is used for advertising, behavioral profiling, or sold to anyone.
How long data is kept
Submitted reports may be kept long-term to provide live status and historical insights about shuttle reliability. Rate-limiting records (the hashed IP data above) are automatically deleted after up to 48 hours. Your device identifier and Scout handle are normally stored only in your browser’s local storage unless you choose to submit reports. If you clear your browser’s site data, your device identifier and Scout handle are gone for good — a future visit starts fresh, as a “new” device.
Security
DevaHop takes reasonable technical and organizational measures to protect the limited data it stores against unauthorized access or misuse.
Children
DevaHop does not require a rider account and does not knowingly collect names, email addresses, phone numbers, or precise location data from riders. The service is intended to be usable by riders of all ages.
Your rights
Because DevaHop uses limited identifiers and reports rather than a conventional personal profile, some rights may need to be handled using the information available to us. If you have a specific concern or request about data tied to your device — for example, asking that reports associated with a particular device identifier be deleted — reach out using the contact below and it will be handled directly. Depending on where you live, you may also have additional rights under applicable privacy laws.
Contact
Questions about this policy or how DevaHop handles data:[email protected].
See also theTerms of Service. DevaHop is an independent, community-powered project and is not affiliated with, endorsed by, or operated on behalf of the Municipality of Deva or the shuttle operator.