Legal
Privacy Policy
This policy describes the information Yaato currently processes through its public website, school transport web application, backend services, and direct-distribution Android pilot app.
Effective and last updated: June 18, 2026
1. Scope and roles
This policy applies to Yaato services and the website at yaato.in. A school or platform customer generally decides which authorized users, students, routes, vehicles, and operational records are entered into the service. Depending on the context, Yaato may process information for that organization or for its own website, account, support, and security purposes.
A separate written agreement with a school or other customer may contain additional privacy and data-handling terms. If it conflicts with this public policy, the signed agreement controls for that customer.
2. Information processed
- Account and identity information, such as name, email address, phone number, role, authentication details, school membership, and account status.
- School transport records, such as school details, routes, stops, vehicles, drivers, attendants, students, guardians, assignments, trips, attendance, incidents, announcements, and support records.
- Location information, including school and stop coordinates, student pickup coordinates supplied by authorized users, and driver-published vehicle location, speed, heading, and timestamps during active trips.
- Device and notification information, such as Firebase device tokens and notification permission or delivery information.
- Website and security information, such as IP address and request logs, authentication and CSRF cookies, browser or device information, and optional analytics events when analytics is configured.
- Demo, support, and communication information submitted through forms or email, including school name, role, fleet size, student count, address, message, and contact details.
3. How information is used
Yaato does not use student transport records for targeted advertising. The current service does not provide a feature for selling personal information.
- Provide authenticated school transport administration, trip, attendance, location, notification, reporting, and incident workflows.
- Create and manage accounts, enforce role-based and school-scoped access, protect sessions, investigate misuse, and maintain service security.
- Deliver configured email and mobile communications.
- Respond to walkthrough, pilot, support, and account requests.
- Maintain, test, troubleshoot, and improve the service using operational and diagnostic information.
- Meet applicable contractual, legal, safety, and dispute-resolution obligations.
4. Cookies and analytics
The web application uses a secure authentication cookie to keep signed-in users authenticated and a CSRF cookie to protect state-changing browser requests. These cookies are required for account and security functions.
Google Analytics may be enabled through deployment configuration. When enabled, it can receive page and conversion-event information. Yaato's public pages do not currently provide a preference center, so analytics should remain disabled in deployments where consent or another valid basis has not been established.
5. Service providers and disclosure
Information may be disclosed to authorized users within the relevant school or platform account and to service providers that support the configured product. Current integrations can include Google Maps or Routes services, Firebase Cloud Messaging, Brevo transactional email, hosting and database providers, and optional Google Analytics.
Information may also be disclosed when reasonably necessary to comply with applicable law, protect users or the service, investigate abuse, enforce agreements, or respond to a valid legal process. Yaato does not promise that every listed integration is enabled in every deployment.
6. Student and child information
Yaato is designed for use by schools, authorized staff, drivers, guardians, and platform operators. Schools and other customers are responsible for deciding what student information to enter, establishing the appropriate authority or consent, providing required notices, and limiting accounts to authorized users.
The public website is not intended for children to submit personal information directly. A guardian or school administrator should contact Yaato if child information appears to have been submitted without appropriate authority.
7. Retention and deletion
Yaato does not currently publish one fixed retention period for every data category. Information is retained according to the relevant customer relationship, operational history requirements, security and dispute needs, backup practices, and applicable law.
Some product deletion actions use soft deletion, which hides a record from operational workflows while preserving history. Auditable trip records are retained for authorized review.
Requests for access, correction, account closure, or deletion may be sent to support@yaato.in. Yaato may need to verify the requester and coordinate with the relevant school or account administrator. Some records may be retained where required or permitted by an agreement or applicable law.
8. Security
Yaato uses measures such as authenticated access, role checks, school-scoped data access, password hashing, secure production cookies, CSRF protection, rate limiting for selected endpoints, audit records, and encrypted transport where correctly deployed.
No system can guarantee absolute security, uninterrupted availability, or error-free data. Schools and users must protect account credentials, devices, API keys, and access permissions and must promptly report suspected unauthorized access.
9. International processing
Hosting, maps, messaging, email, analytics, or support providers may process information in locations outside the user's state or country. The locations and protections depend on the providers and deployment selected for a customer.
10. Privacy choices and complaints
Users may decline optional browser or mobile permissions, but location, maps, or notifications may then be unavailable. Account information can generally be corrected through authorized school or platform administrators.
Privacy questions or complaints should first be sent to support@yaato.in with enough information to identify the relevant account and request. Individuals may also use rights and complaint mechanisms available under applicable law.
11. Changes to this policy
Yaato may update this policy as the service, integrations, or legal requirements change. The page will show the revised effective date. Material changes may also be communicated through the service or customer contacts where appropriate.