Privacy policy
Version 0.1, 9 October 2026
Wayzi is a school transport service: it lets transport companies organise their buses, guides the nanny on board, tells parents when the bus is coming and keeps a record of each pick-up and drop-off. Because it handles information about children and the position of buses in real time, we collect only what the service needs and show each person only what concerns them.
This policy explains what personal data is processed through the Wayzi mobile app, the Wayzi web application and this website, why, where, for how long, and how you can exercise your rights.
1. Who is responsible
The Wayzi service is published by H2S Technology FZE, Block B - B31-200, Sharjah, United Arab Emirates (“Wayzi”, “we”).
Two situations must be distinguished:
- Data entered by a transport company or a school to organise transport (children, addresses and stops, routes, trip records, staff accounts): the transport company decides why and how this data is used and is responsible for it. Wayzi processes it on its behalf and on its instructions, under a data processing agreement.
- Parent accounts and subscriptions, and this website: Wayzi is responsible for this data.
If your question concerns the transport of your child (a route, a stop, a pick-up time), the transport company is usually the right contact. In every case you may write to us at contact@h2stechnology.com: we will answer or pass your request to the transport company concerned.
2. The data we process
Parents
- Identity and contact: name, mobile phone number, preferred language. Parents sign in with their phone number and a one-time code (activation code or text message); they have no password.
- Family information entered by the parent: absences, persons authorised to collect the child (name, phone number, relationship), a substitute for one day (name), notification preferences.
- Signed consents and authorisations (for example an autonomous drop-off authorisation): the version of the document, the typed name of the signer, date and time, IP address and device information, kept as proof.
- Technical data: push notification token of the phone, sign-in sessions, security logs (IP address, date and time).
- Subscription: plan and its status. Paid plans are not available yet; when they open, payments will be handled by a payment provider and Wayzi will not store card numbers. This policy will be updated before then.
Children
- Name, school, the bus and route serving the child, the pick-up and drop-off stop (address and position on the map), notes useful for the trip (for example an allergy or a car seat), entered by the transport company or the school.
- Trip records: on board, arrived at school, dropped off, absent, not present at the stop — each with the time, the location of the bus at that moment and the person who recorded it.
- If the school uses them, a QR badge used by the nanny to check the child on and off the bus.
Children do not use Wayzi and we never collect data directly from them.
Nannies and staff of companies and schools
- Name, work email address, phone number (nannies), role and assignments (bus, school).
- Sign-in data: password (stored only as a secure hash), two-step verification settings, sessions.
- Actions in the service, recorded in an audit log (for example who changed a route or confirmed a drop-off).
Location
Wayzi never locates children, nor the parents’ phones. The only position tracked is that of the bus, sent by the phone of the nanny on board only during trips (including when the screen is off). It is used to show the bus to the parents and the school, estimate arrival times, detect arrival at a stop and keep the trip record. A child’s pick-up and drop-off are recorded with the time and the location of the bus at that moment.
This website
This website sets no cookies, uses no analytics and loads no third-party resources (its fonts are served from our own address). Like any web server, the hosting provider receives your IP address and the requested page in order to deliver it. The activation page reads the code in its address only inside your browser and sends it nowhere.
3. Why we use this data
- To provide the service: organise routes, guide the nanny, show the bus and send alerts to parents and schools (performance of the contract with the transport company and of our terms of use with parents).
- To protect children and keep proof: the record of each pick-up, hand-over and drop-off, with its time, the location of the bus and its author (legitimate interest of the transport company and of families, and legal obligations of the transport company).
- To apply the choices and authorisations given by parents (autonomous drop-off, authorised persons, substitutes), based on their signed consent, which they may withdraw at any time in the app.
- To secure the service: sign-in, two-step verification for staff, detection of abuse, audit logs.
- To manage subscriptions and invoices, once paid plans exist (contract and legal obligations).
We do not sell personal data, we do not use it for advertising and we do not build profiles of children.
4. Children’s data
Children’s data is provided by the transport company, the school or the parents, never by the children themselves. The parent gives their consent when activating their account and can see, in the app, the information about their own children.
Strict rules limit who sees it:
- A parent sees only their own children. They never receive the name, address or identifiers of another child, even hidden on screen. Other stops are shown as anonymous stops (“Stop 3”); on the live map of the Premium plan they may appear at an approximate position, rounded to about 100 metres.
- A nanny sees the children of her bus for the day, with their stop and notes, during her trips.
- A school sees its own pupils on board, never the parents’ contact details.
- A transport company sees only its own buses, families and trips; two companies never see each other’s data. It never sees the parents’ payments.
5. Service providers and where data is located
We use a small number of providers, each for a precise task and only with the data that task needs:
| Provider | Task | Data | Location |
|---|---|---|---|
| Microsoft Azure | Hosting of the database, its backups, the server and its logs | All the service data | United Arab Emirates (UAE North, Dubai) |
| Microsoft Azure Static Web Apps | Delivery of this website and of the web application’s code | No service data; technical request data (IP address) | Global content delivery network |
| Google (Routes API) | Calculation of arrival times | Positions of the bus and of the stops, without names | Google servers, possibly outside the UAE |
| Google (Geocoding API) | Address search when a company places a stop on the map | The searched address, without names | Google servers, possibly outside the UAE |
| Google (Firebase Cloud Messaging), and Apple for iPhones | Delivery of push notifications | The phone’s notification token and the text of the notification | Google and Apple servers, possibly outside the UAE |
| Amazon Web Services (Amazon SES), when enabled | Sending emails (invitations, sign-in codes, password resets) | Email address and content of the email | United Arab Emirates (me-central-1) |
| Text-message providers (Infobip, e&, and Twilio as a backup), when enabled | Sending sign-in codes and backup alerts by text message | Phone number and text of the message | Depending on the provider and the destination network |
Each provider acts on our instructions and is bound by its data processing terms. We will update this list before adding or changing a provider.
6. Transfers outside the country
The database and its backups stay in the United Arab Emirates. Some functions need a provider whose servers may be located abroad: arrival-time calculation and address search (Google) and push notifications (Google, Apple). For these, we send only what is strictly necessary — positions without names, a notification token, the text of a notification — under the providers’ contractual safeguards.
For Morocco, transfers of personal data abroad are subject to the rules of Law No. 09-08 and to the authorisation of the CNDP where required. These steps will be completed before the service opens in Morocco.
7. How long we keep data
| Data | Retention |
|---|---|
| Raw positions of the buses (GPS) | 30 days |
| Trip records (statuses, times, positions, authors) | 12 months |
| Notifications sent (app, push, SMS, email) | 12 months |
| Operational alerts (delays, absences, emergencies) | 12 months |
| Audit log (sign-ins, rights, child records viewed by schools) | 24 months |
| Ended sessions (signed out, revoked or expired) | Deleted 30 days after they end |
| Invoices and receipts | 5 years (accounting obligations) |
| Accounts | Deleted 30 days after the end of the subscription or of the service with the transport company, or after a deletion request |
| One-time sign-in codes | Deleted 1 day after they expire (they are valid 5 minutes) |
| Single-use links (invitation, password reset) | Deleted 7 days after they expire |
| Server logs | 30 days |
| Database backups | Rolling, 7 to 14 days |
Deletion is automatic: a daily job removes what has passed its retention period.
8. Security
- Encrypted connections (HTTPS) between the apps and the server; data encrypted at rest by the hosting provider.
- The database is not reachable from the internet; each company’s data is isolated at the database level.
- Staff accounts are protected by a password and a mandatory second step (authenticator app or email code).
- One-time codes are stored only in a protected (hashed) form; access to children’s records is logged.
No system is perfectly secure. If a breach affecting your data occurs, we will inform the transport companies concerned, the competent authorities and, where required, the people affected.
9. Your rights
Depending on the law that applies to you, you may:
- access your data and receive a copy of it;
- have inaccurate data corrected;
- have your data deleted (Delete an account);
- object to or restrict some processing;
- withdraw a consent at any time, without affecting what was done before;
- receive your data in a structured format, where applicable;
- lodge a complaint with the data protection authority: in the United Arab Emirates, the UAE Data Office; in Morocco, the CNDP.
Write to us at contact@h2stechnology.com. We may ask you to confirm your identity, for example from the phone number linked to your account. We aim to answer within 30 days. When the data is held on behalf of a transport company, we pass your request to that company and help it answer.
10. Applicable laws
Wayzi starts in the United Arab Emirates. This policy has been written with the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data in mind, and, for Morocco, Law No. 09-08 on the protection of individuals with regard to the processing of personal data. It will be adapted to the rules of each new country before the service opens there.
11. Changes and contact
We will publish any change on this page, with a new version number and date. If a change significantly affects how your data is used, we will inform you in the app beforehand.
Questions about this policy or your data: contact@h2stechnology.com.