Skip to content

Legal · Privacy

Privacy policy

Draft for owner and legal review — not effective until approved.

This document is a working draft. It does not yet describe confirmed practices and should not be relied upon.

Operator
Avadhya Inc., Santa Clara, California

011. Who we are and what this draft covers

Kidhopper is operated by Avadhya Inc., Santa Clara, California. Contact [email protected] with questions about this draft or the service. This draft describes the public website and the transportation-coordination application; it is not an effective policy until the operator approves it.

The application helps organizations manage riders, staff, vehicles, schedules, attendance and dispatch. Organizations supply and manage operational records. The respective privacy responsibilities of Avadhya Inc. and each organization must be established in the applicable service and data-processing agreements.

022. Information the service can process

Account information can include names, email addresses, organization memberships, roles and sign-in identifiers. For password-based accounts the application stores password hashes. Session records support signed-in access.

Depending on what an organization enters, rider records can include names, student identifiers, date of birth, grade, school, classroom or teacher information, home and pickup/drop-off addresses, schedules, attendance and trip status. Records may also contain special-needs information, medical notes and pickup/drop-off instructions. These can be sensitive records and should only be supplied when necessary and authorized.

Contact records can include parent, guardian, emergency-contact or school-contact names, relationships, email addresses, telephone numbers and communication permissions. Staff and fleet records can include contact details, license and vehicle information, compliance-expiration dates and uploaded documents.

Hosting systems can process technical information such as IP addresses, request details, device/browser information and diagnostic logs. If you email support, the email provider processes your message and the contact details you include. Do not send children's sensitive records or credentials in an initial support email.

033. Why information is processed

The application uses account and organization information to authenticate users and determine access. Operational records support scheduling, assignments, attendance, dispatch, reports and communication features enabled by the organization.

Technical records support operating and troubleshooting the service and investigating misuse. Support correspondence is used to respond to requests. Any additional purposes must be evaluated and disclosed before the final policy is approved.

044. Children's and school-related information

Kidhopper is a tool for authorized transportation organizations, staff and contacts; this website is not an invitation for children to create accounts or submit personal information. Children's records may nevertheless be entered and handled by authorized adults through the operational application.

An organization must determine its authority to supply rider information and obtain any required notices, permissions or consents. Applicable child-privacy and student-record obligations, the parties' responsibilities, and any necessary agreements require review before launch. This draft does not claim COPPA, FERPA or other regulatory compliance.

For questions about a child's records, contact the organization managing the transportation service. You may also contact [email protected] for help identifying the appropriate request process. Please avoid including medical notes, a child's full address or other unnecessary sensitive information in that first message.

055. Access and service providers

Authorized members of an organization can access information according to their roles and permissions. Drivers, coordinators and authorized contacts may receive information through configured operational links or communication features. Recipients should keep those links private.

Operating the service requires providers for hosting, databases, file storage, authentication and, when enabled, communications. The final provider list, processing locations, contractual protections and any international transfers must be confirmed before publication. Do not interpret this draft as a complete subprocessor list.

Any disclosures for legal requests, business transfers or other purposes, and any sale, sharing for advertising, or analytics practices, must be reviewed and accurately stated in the final policy. This draft does not assert an unverified no-sale or no-sharing commitment.

066. Google sign-in

When you choose Google sign-in, the current application requests OpenID, email and profile information to identify you and sign you in. The integration does not request access to your Google Drive, Calendar or Contacts.

Google handles authentication under its own policies. Disconnecting access through your Google account does not itself delete records already held by the organization or Kidhopper. Contact support or the relevant organization about those records.

077. Cookies and this public website

The operational application uses session cookies to maintain signed-in access. Disabling those cookies may prevent sign-in or other account functions.

This public website has no account forms, advertising trackers or optional analytics scripts added by its application code. Its contact links open your email application rather than submitting a website form. Hosting-level logs and any additional provider-injected technologies require a final launch review.

088. Retention and requests

A final retention schedule has not yet been approved for this draft. Before launch, Avadhya Inc. must establish retention periods or criteria for operational records, accounts, files, logs and backups, together with procedures for organization offboarding and deletion requests. No fixed deletion deadline or automatic erasure guarantee is stated here.

You can send access, correction or deletion inquiries to [email protected]. For organization-controlled records, start with the organization that manages them. Requests may require identity and authority verification, and the applicable process depends on the records, governing law and contractual responsibilities. This draft does not claim that all requests can be completed through an automated app feature.

099. Security and policy approval

The application includes authentication and organization/role-based access controls. These measures do not guarantee that incidents cannot occur. Keep accounts and operational links private and report suspected unauthorized access to [email protected].

Before this policy becomes effective, the operator must confirm the actual production configuration, provider inventory, retention/deletion practices, applicable privacy rights and any additional disclosures. The approved policy should carry an effective date and a process for communicating material changes. This draft is general information, not legal advice.

See also: Terms of service (draft) · Contact