Privacy Policy

Your privacy is important to us. Madeira Bus is committed to protecting your privacy while providing bus schedule information for public transportation in Madeira, Portugal. This policy explains what data we collect, how we use it, and your rights.

1. Information We Do Not Collect

Madeira Bus is designed with a privacy-minimising approach. We do not use advertising identifiers, create general-purpose user accounts, access contacts, photos or files, or collect payment-card details. Apple or Google processes payment details. The limited app data we do collect is described below.

  • Advertising identifiers
  • Contacts, photos, or files from your device
  • Payment information (handled entirely by Apple/Google)

As dedicated identity/contact fields, an email address is sent to RevenueCat only if you use the optional supporter-access sign-in, while a name, email address and message can be sent to Sentry only if you include them in crash feedback. Free-text Routes searches are a separate exception described in section 3.

2. Location Data

The app requests location to show your position and nearby stops. That nearby/map use stays on your device. Precise location coordinates can leave your device only in the following user-initiated cases. The derived resident service-area classification described in section 3 can also be sent without coordinates.

  • Stop corrections and data reports: if location permission is already granted and you submit a correction or report, your current precise location may be sent with the submission to Supabase for validation. The submission is linked to an app-scoped install identifier. Reports also include the selected transit item, app and data versions, and any optional note you enter.
  • GO ride: after the explicit first-GO consent, a ride you start follows your location along the route, including while the app is backgrounded or the screen is locked, so the app can alert you at your stop. Tracking stops when the ride ends. The uploaded trace is the span from the first to the last fixes classified as on-route: fixes before and after that span are removed, but interior off-route deviations remain in the upload. Supabase receives it with a random one-time ride code and no persistent device, account or advertising identifier.
  • A completed ride and its full track can be stored locally in My Rides (up to the newest 50) until you delete it. This local history is not uploaded.

You can deny location permission and still use core schedules and planning. Android uses a visible foreground-service notification during a backgrounded GO ride and does not request Android's background-location permission. iOS uses When In Use location with the visible system background indicator during a GO ride.

3. Anonymous Usage Analytics

We use PostHog EU Cloud to understand app use. Events are associated with an app-scoped random identifier generated on first launch and stored on the device. It is not an advertising or hardware identifier, but it lets events from the same installation be linked. It is regenerated when the app is reinstalled.

What We Track

  • Route searches – the exact raw text entered in the Routes search, result count, and the same raw text when a result is opened. PostHog receives it as analytics and Sentry receives it in diagnostic breadcrumbs/logs. Because the field accepts free text, it may contain personal text if you enter it
  • Route views – Which route schedules are viewed
  • Feature interactions – Button taps, direction changes, day type selections
  • App lifecycle – When the app is opened, closed, or backgrounded
  • Device information – Device model, operating system version, app version
  • App-scoped install identifier, language, theme and supporter tier

What We Do NOT Track

  • Your GPS location or coordinates
  • Your name or email as a profile field; however, raw Routes search text is sent as explained above
  • Advertising identifiers
  • Data from other apps on your device

If you claim optional resident access, PostHog receives the postal prefix you entered, store country, a device-timezone match, and a cached last-known GPS-derived service-area classification (such as Madeira, Porto Santo, outside or unknown). RevenueCat receives resident status and claim date, store country, timezone match and the service-area region classification. Neither service receives the precise coordinates for this check, and RevenueCat does not receive the postal code or prefix.

How We Use This Data

  • Understand which routes are most popular
  • Identify which features are most helpful
  • Prioritize improvements and new features
  • Optimize app performance

4. Error Tracking and App Improvement

We use an error tracking service to improve app stability and fix bugs quickly.

Data Collected Automatically

When you use the app, we may collect:

  • Crash reports – Information about app errors and crashes
  • Performance data – App loading times and responsiveness metrics
  • Device information – Device model, operating system version, app version
  • Session replay – on production Android physical devices only, 10% of sessions that encounter an error may be recorded; random-session replay is disabled, and replay is disabled on iOS

Sentry diagnostics are not assigned the app's user or device identity. Replay inputs are masked. A replay can still contain the app screens and interactions needed to diagnose the error.

Data You Choose to Provide

If you use the in-app feedback feature, you may optionally provide:

  • Feedback message – Description of your issue or suggestion
  • Name – Optional, for personalized support
  • Email address – Optional, if you'd like us to follow up

The hidden supporter-access option sends the normalized email address you enter to RevenueCat as its customer identifier and stores a local copy so the app can show and revoke that access. Ordinary store purchases use the app-scoped identifier; RevenueCat receives receipt and entitlement information from Apple or Google.

5. Data Security

We take the security of your data seriously:

  • All data is encrypted during transmission (HTTPS/TLS)
  • Sentry, PostHog and Supabase app data is processed in the European Union; RevenueCat processes purchase and supporter-account data in the United States under its safeguards
  • We do not sell your data to third parties
  • We do not use your data for advertising
  • We do not track you across other apps or websites

6. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the following rights:

  • Access your data – Request a copy of data we've collected about you
  • Delete your data – Request deletion of your data
  • Object to processing – Opt-out of data collection where technically feasible
  • Data portability – Receive your data in a portable format

To exercise your rights, contact us at [email protected].

Please note: Since most data is anonymous, we may not be able to identify specific data as belonging to you.

7. Third-Party Services (Processors)

We use the following named processors (GDPR Art. 28):

  • PostHog (EU Cloud, Frankfurt) β€” app product analytics associated with the app-scoped install identifier, including raw Routes search text and resident-access signals; it receives no precise coordinates or dedicated name/email profile fields.
  • Sentry (EU, Frankfurt) β€” app crash reports, performance diagnostics, optional crash feedback and Android on-error replay as described in section 4.
  • Supabase (EU) β€” user-submitted stop corrections and data reports, optional precise location attached at submission, and consented anonymous GO ride traces and derived transit observations.
  • RevenueCat (United States) β€” Apple/Google receipt validation, purchase history, entitlement state, the app-scoped identifier, and an email only when supporter-access sign-in is used.
  • Cloudflare R2 (EU) β€” read-only downloads of schedule and map updates; no user data is uploaded to R2.
  • Google Analytics 4 (Google Ireland Ltd., DPA hosted in the EU under SCCs) β€” aggregate visitor counts and traffic sources on this website. We run GA in Consent Mode v2 with analytics_storage granted by default for audience measurement, while ad_storage, ad_user_data, and ad_personalization stay denied. If you Decline the banner, all four signals are set to denied and GA receives cookieless "consent-denied" pings only.
  • Apple Maps / Google Maps β€” the app provides links to these external services for navigation. Their own privacy policies govern those visits.

Our legal bases are legitimate interests for privacy-minimised analytics, security and diagnostics; performance of the purchase/access service for RevenueCat processing; and your explicit action or consent for optional feedback, submissions, precise location and GO recording. GO consent currently persists for the installation and the app has no withdrawal control. To prevent future GO collection, do not start another GO ride or revoke location permission in your device settings; uninstalling the app resets the stored consent.

You can change or withdraw consent at any time from any page by choosing Cookie Settings in the footer. Choosing Decline leaves GA in the cookieless consent-denied mode described above and clears the website's GA cookies, including any leftover cookies from this website's earlier PostHog integration. You can also clear site data for madeirabus.com in your browser.

8. Data Retention

  • Sentry crash diagnostics, feedback and Android on-error replays are kept under our Sentry project configuration while needed to diagnose and correct app stability problems; we do not publish an unverified fixed period here. Contact us if you want identifiable optional feedback removed.
  • The current app and server configuration specifies a 365-day cutoff for raw anonymous GO trace rows and files. Cleanup depends on the scheduled server retention process. Derived non-identifying transit observations may be kept indefinitely. Because traces carry no user or device identifier, we cannot locate one by identity for deletion.
  • Stop corrections and data reports have no fixed automatic deletion period. They are kept while needed for data-quality review. You may request deletion, but we may be unable to identify a submission if you cannot provide enough details.
  • RevenueCat retains purchase/entitlement records as required to provide and restore access and meet legal obligations.
  • Google Analytics 4 event-level website data follows our current 14-month event-data retention setting. Aggregate reports generated from those events may remain for longer. PostHog app analytics are kept while needed to understand feature use, diagnose product issues and prioritize improvements, subject to the configured project retention; we do not publish an unverified fixed period here.
  • We do not keep personal data indefinitely.

9. Children's Privacy

This app does not knowingly collect data from children under 13. The app is designed for general public transportation use and does not require personal information.

10. Updates

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page. Continued use of the app after changes constitutes acceptance of the updated policy.

Contact Us

If you have questions about this privacy policy or our data practices, contact us at:

Last updated: 9 September 2026

Mobile app

Take Madeira Bus with you

Free offline schedules and multilingual trip planning for iPhone and Android. The offline route map is a premium upgrade.

Scan to get the app