Driver Tracker Privacy Policy
Last updated: September 4, 2026
This policy explains how Result Hosting supports the Driver Tracker application for schools and their authorized transport staff.
Information the app handles
- Driver sign-in identifier, driver name, role, registered mobile number, and device identifier/model.
- Live precise location, timestamp, vehicle identifier, and route activity while vehicle tracking is enabled.
- Assigned operational roster data: student name, student photo, class, section, parent name, route, and transport assignment identifiers.
- Vehicle and schedule information supplied by the school.
- Face template/embedding and face-attendance verification records when the driver separately enables face attendance.
The app does not contain advertising, sell personal information, or use student or driver information for targeted advertising.
Location disclosure
Driver Tracker requests precise location because route monitoring and GPS-fenced attendance require an accurate position. Location is used to provide the authorized school service, maintain route history, and protect the integrity of transport operations. The driver must grant precise Allow all the time location access, keep device Location services enabled, and may stop only a manually started tracking run. A server-assigned automatic schedule cannot be stopped or logged out from the driver controls until its server window ends. Approximate-only or foreground-only location is not sufficient for this core transport function. Android does not permit an app to silently switch Location services on; if services are off, Driver Tracker opens the system Location settings and waits for the driver to enable them. The app never sends location, device telemetry, roster data, or face data before a successful vehicle-proof login and the required consent.
Face registration and attendance
With the driver's separate, explicit consent, the app can use the camera to register and verify the driver's face for school attendance. Face registration is permitted only inside an active school GPS-fenced area. The camera image is processed on the device to create a mathematical face template (face embedding); the raw camera image is not uploaded or retained by Driver Tracker. The template is encrypted in transit and stored for the driver's attendance identity, not for advertising, profiling, or identification outside the school service.
For a daily face-scan attendance event, the server receives the face verification result, precise latitude and longitude, location accuracy, date and time, school-area identifier, device/app information, and attendance direction (IN or OUT). These records are shared with the authorized school transport and attendance administrators and are synchronized with the school's ERP attendance record. Face attendance cannot be used unless the driver accepts the face, precise-location, and device-information disclosures; the driver may ask the school to reset or delete the registered face template, subject to records the school must retain for safety, attendance, financial, or legal reasons.
Face registration is optional only where the school provides another approved attendance process. If the school has made face attendance the assigned process, declining it means the driver must contact the school administrator for an approved alternative before operating the service.
How information is used and shared
Result Hosting processes information on the school's behalf to authenticate the driver, enforce vehicle assignment, provide live transport tracking, display the assigned roster, and support troubleshooting. Authorized school administrators may access transport records. Information may be disclosed where required by law or to protect users and the service.
Before sign-in, the driver must consent to precise location sharing and to sending device model, Android version, app version, and the app-scoped device identifier. The public update check sends only the installed app version name/code; it does not send location, device identity, face data, roster data, or driver credentials. The login handshake sends the credentials and consented device metadata required to authenticate and bind the assigned vehicle. The driver consent and vehicle manifest screens show the operational assignment and safety information supplied by the school.
Student roster information is limited to the vehicle assigned to the signed-in driver. The app does not provide a general student directory. A vehicle login is confirmed with the vehicle number, the assigned driver's registered mobile number, and the last four chassis characters; the server binds that assignment to the current device.
Security and retention
Network requests use HTTPS. The app stores its operational session and cached school data in encrypted local storage, and the server enforces school tenant, active-driver, active-vehicle, and driver-assignment checks on each protected request. The app asks the driver to disable Android battery optimization and allow unrestricted battery use because battery restrictions can stop or delay the core live-tracking updates; this setting is used only for Driver Tracker's transport service. The school deployment also requests Android's special Display over other apps access for its persistent driver controls; Driver Tracker does not read or collect content from other apps.
For server-assigned tracking schedules, Driver Tracker requests Android's Alarms & reminders exact-alarm access so a scheduled boundary can start or stop the visible location foreground service while the app is not open. The app cannot silently grant this access, and it cannot silently turn on Location services; the driver must complete the Android settings screens. A persistent tracking notification is shown while the location service is running.
Only one current Driver Tracker device binding is permitted for a driver and assigned vehicle. A newer valid login revokes the previous binding. When the old device next connects, the service rejects it, stops tracking, and clears its encrypted local driver, vehicle, roster, schedule, and session cache. A phone that is powered off or offline cannot receive a remote command until it connects again.
Vehicle path points, ended tracking sessions, and stale live-location markers are automatically and permanently deleted after 30 days for the relevant school/vendor/vehicle scope. Device registry and login-binding rows are retained as security/audit records. Face templates, face-scan attendance, driver consent, and ERP attendance records follow the school's attendance, safety, security, financial, and legal retention requirements and may remain after tracking history is purged.
Your choices and requests
Drivers can stop location tracking and manage location and notification permissions in Android settings. A school may deactivate the driver account or block the registered device. For access, correction, deletion, or privacy questions, contact the school first or email resulthostingnet@gmail.com. Requests may require identity and school authorization verification, and records that must be retained may not be immediately removable.
Driver accounts are provisioned by the school; the app does not offer public account creation.