DevaHop is a small, independent, community-powered bus-tracking tool for the Citadel Shuttle in Deva. This page explains, plainly, what data the app collects and why. DevaHop does not use cookies, does not run ads or third-party trackers, and does not sell or share data with anyone.
The short version
✓No account required
✓No ads, ever
✓No location tracking
✓No data sold or shared — ever
What DevaHop collects
A random device identifier, generated and stored locally in your browser (not a cookie). It is not linked to your name or email. Because an online/device identifier can potentially be considered personal data under applicable privacy law, DevaHop treats it conservatively and uses it only for the functions described here. Creating an account is optional and is not required to use DevaHop. Your device identifier is hashed in your browser before it is sent to our servers; the raw identifier never leaves your device.
Your Scout handle — a randomly generated pair of words plus a number (e.g. “Carpathian Falcon 195”), also stored in your browser. It is designed as a nickname and is not linked to your name, email, phone number, or other directly identifying information.
The reports you submit — which stop, what you reported (e.g. “Bus is Leaving Now”), and when. These are stored to show the live community status to other riders.
Your device’s own trip progress (e.g. “currently heading to the Citadel”) — used only to show or hide the right buttons for you.
A one-way hashed version of your IP address, kept only to prevent spam/abuse (e.g. a script flooding fake reports). Your real IP address is never stored — only a one-way cryptographic hash. Because hashed online identifiers can still potentially be personal data, DevaHop treats this information conservatively. The hash changes every day and these records are automatically deleted after up to 48 hours.
What DevaHop does not collect
No name, email, or phone number for riders using the app
No precise location or GPS tracking
No cookies for riders using the app — the only cookie DevaHop ever sets is a login session for the single admin account, used solely to view the operational debug log described below
No advertising, analytics, or third-party trackers of any kind — DevaHop has no optional analytics at all
Operational records and the admin dashboard
DevaHop does not use optional analytics of any kind. Ordinary browsing is not tracked: opening the app, searching for a station, opening a station or a line, checking a schedule, or arriving via the sticker QR code records nothing at all. Records are created only when you use a feature that genuinely needs them to work — Journey Mode, community reporting, XP, or voluntarily signing in. The single admin dashboard shows statistics calculated from those necessary records and nothing else.
People who only consult schedules are not counted as users — nothing is recorded about them, so they cannot appear in any figure anywhere
Journey GPS coordinates are never sent to, or stored by, DevaHop — GPS stays entirely on your device and is used only to advance Journey Mode locally
There is no analytics identifier, analytics cookie, analytics browser-storage key or fingerprinting of any kind. Where the dashboard counts distinct devices, it counts the functional device identifier already present in reporting records — never presented as a guaranteed individual person
Operational debug log (testing periods only)
During active testing and maintenance periods, DevaHop temporarily records a log of report activity to help diagnose display/timing bugs — for example, confirming that both direction pages show consistent information after a report. This log:
Does not include IP address, in any form — it is not needed for this purpose, so it is not collected here
Stores your device identifier only as a one-way hash (a different hash than the one used for abuse prevention), not the raw value
Includes timestamps and app state (which buttons were available, what the status pages showed) — this is the actual diagnostic data the log exists to capture
Is visible only to the single admin account (Google sign-in, restricted to one specific email address) — there is no public or rider-facing access to this data
Is not run continuously — it is used in short, periodic testing/maintenance windows, not as an ongoing feature
Why this data is collected
Solely to make the app work: showing real-time, community-reported bus status, and preventing spam from breaking that for everyone else. Nothing here is used for advertising, behavioral profiling, or sold to anyone.
How long data is kept
Submitted reports may be kept long-term to provide live status and historical insights about shuttle reliability. Rate-limiting records (the hashed IP data above) are automatically deleted after up to 48 hours. Your device identifier and Scout handle are normally stored only in your browser’s local storage unless you choose to submit reports. If you clear your browser’s site data, your device identifier and Scout handle are gone for good — a future visit starts fresh, as a “new” device.
Security
DevaHop takes reasonable technical and organizational measures to protect the limited data it stores against unauthorized access or misuse.
Children
DevaHop does not require a rider account and does not knowingly collect names, email addresses, phone numbers, or precise location data from riders. The service is intended to be usable by riders of all ages.
Your rights
Because DevaHop uses limited identifiers and reports rather than a conventional personal profile, some rights may need to be handled using the information available to us. If you have a specific concern or request about data tied to your device — for example, asking that reports associated with a particular device identifier be deleted — reach out using the contact below and it will be handled directly. Depending on where you live, you may also have additional rights under applicable privacy laws.
See also theTerms of Service. DevaHop is an independent, community-powered project and is not affiliated with, endorsed by, or operated on behalf of the Municipality of Deva or TPLD (Transport Public Local Deva).