Plain-language notice
Privacy without surprises
This independent guide has no accounts. It uses Google Analytics only if you accept the cookie banner; decline and no analytics cookies are set. We also process data when you email us or follow a marked affiliate link.
Last updated 29 August 2026
Rhodes Bus
Rhodes Bus Android app privacy
This section applies only to the Rhodes Bus Android app. It explains what leaves your device, why it is processed, how long fixed-retention data is kept, and the choices available to you. Website practices remain described separately below.
Precise location and GO rides
Continuous precise location recording starts only after the first-use explainer and when you explicitly tap Start ride for a GO ride.
The Android foreground service may continue the ride while the screen is locked and stops collecting location when the ride ends. It never runs continuous location collection outside GO.
Each uploaded GO ride has a fresh one-time random code, no account, and no persistent device identifier. Separate rides cannot be linked to one another or to a person.
Supabase stores GO uploads in an EU region for 365 days. The retention process then automatically deletes the raw rows and files.
My Rides keeps the newest 50 tracks on-device only. These tracks are not uploaded. You can delete one ride or clear all local history.
Stop contributions
When you confirm, move, add, or flag a bus stop, the app sends that action, the stop coordinates, and your current rider coordinates at that moment. It also sends a random identifier generated on first launch. This is not a hardware identifier or advertising identifier. Supabase stores stop contributions in the EU.
Problem reports
Report a problem works without a name or email address. The submitted message and any optional name or email you provide go to Sentry in Frankfurt and are retained for 90 days.
Crashes and diagnostics
Sentry automatically receives crash reports, performance data, and Android on-error replay. All text and images in the replay are masked on-device before the data leaves your device. Sentry retains this data in Frankfurt for 90 days.
Product analytics
Rhodes Bus uses PostHog to understand how the app’s features are used. PostHog processes this on its EU Cloud in Frankfurt.
Each event carries an anonymous, device-scoped identifier and an app_id property that scopes the data to Rhodes Bus. Events cannot be linked to a name, email address, or account, and PostHog does not track you across other apps or websites.
Product analytics does not show you ads, and this data is never sold or rented.
In-app purchases
Rhodes Bus offers one-time passes — a 7-day pass, a 30-day pass, and a lifetime pass — on Android, bought through Google Play billing, and on iOS, bought through Apple’s App Store billing.
Purchases are processed by the respective store — Google Play or the App Store — and RevenueCat using an anonymous app user ID; no account or sign-in is required. Rhodes Bus never collects or sees your payment card details — the store handles payment directly.
RevenueCat receives purchase and entitlement events tied to the anonymous app user ID so the app can recognize an active pass. This identifier is separate from the product-analytics identifier above.
Experience Rhodes
Experience Rhodes is optional and its GetYourGuide web-view widget loads only when you open that screen. The widget receives your IP address, device or browser information, and interactions inside the widget under GetYourGuide’s policy. GetYourGuide is an independent controller. Outbound tour links include the SD2 Studio affiliate code.
What the app does not do
These exclusions apply to the Rhodes Bus Android app.
- The app has no accounts, logins, or signups.
- The app does not show ads or use an advertising identifier.
- The app does not sell or rent personal data.
- The app does not collect contacts, photos, files, phone numbers, or payment details.
- The app does not track riders across other apps or websites.
Bases, residency, and privacy rights
SD2 Studio is the developer, operator, and controller for Rhodes Bus. Consent is the basis for GO ride location uploads and stop contributions. SD2 Studio’s legitimate interest in app reliability and security is the basis for crash reporting and diagnostics, and its legitimate interest in understanding feature usage is the basis for product analytics. Performing a purchase you request is the basis for processing in-app purchase data.
Supabase and Sentry app data is stored in the EU, and PostHog processes product-analytics data on its EU Cloud in Frankfurt. GetYourGuide handles its widget data under its own privacy policy. Google Play and RevenueCat process in-app purchase data under their own privacy policies, using an anonymous app user ID rather than an account.
Depending on the law that applies to you, you may ask to access, correct, delete, or restrict your data, object to processing, or complain to a supervisory authority.
Deleting your data
This section explains how to ask SD2 Studio to delete data connected with the Rhodes Bus Android app and what can and cannot be located.
Make a deletion request
Email [email protected] and identify the Rhodes Bus Android app and the data you want removed.
Data SD2 Studio can delete on request
- The name, email address, and message in a Report a problem submission.
- Matched stop contributions when you supply the random app-scoped identifier sent with those contributions.
GO ride recordings cannot be located for a rider
GO ride recordings contain no account or persistent device identifier, so SD2 Studio cannot search for a particular rider’s recordings or delete them on request. This is a deliberate privacy property. Raw rows and files remain subject to the 365-day retention process.
Data kept
- Aggregate, non-identifying route results derived from ride recordings, such as typical route-segment travel times, are retained indefinitely. They describe bus routes rather than people.
- My Rides data stays on your device, where you can delete one ride or clear all local history.
Who operates this guide
Rhodes Bus is an independent information website and is not a transport operator, public authority or activity provider.
Privacy questions and rights requests: [email protected].
Website delivery and security
Cloudflare delivers and protects this website. Like most web infrastructure, it processes request information such as IP address, requested URL, traffic-routing data, browser or system information, and security signals. We use this processing only to deliver, cache, secure and diagnose the site.
Website analytics
This guide uses Google Analytics 4 to understand, in aggregate, how visitors find and use the site so we can improve it. Analytics run under Google Consent Mode: they are switched off by default, and the tracking cookies (_ga and _ga_*) are only set after you press Accept on the cookie banner. If you decline, or simply never choose, no analytics cookies are stored and no page-view or session data is sent.
When enabled, Google Analytics measures page views, sessions, approximate location, referrer, and general device and browser information, with IP-address anonymisation turned on. It also records clicks on Google Play buttons, current official timetable links and marked affiliate links, including the placement, page language, route or destination context and outbound URL. We do not use it for advertising, ad personalisation or remarketing — those consent categories stay denied at all times.
You can change or withdraw your choice at any time with Cookie settings in the footer. Withdrawing switches analytics off and removes this site’s Google Analytics cookies.
Email you choose to send us
If you email us, we receive your email address, message, headers and anything you attach. Cloudflare Email Routing forwards the message to a verified support inbox. We use it to answer the request, correct the guide, handle accessibility feedback or meet legal obligations.
Do not send passport, payment-card or health information. Messages are kept only as long as reasonably needed for the conversation, security and legal obligations, then deleted or anonymised.
Affiliate links
Marked GetYourGuide links are affiliate links. Booking through them may support this free guide at no extra cost to you. Affiliate URLs include our partner identifier and a placement label. We do not receive your booking or payment details from this website.
When you select a marked affiliate link, we send one cookie-free affiliate_click event to PostHog EU Cloud so we can understand which placements support this guide. It contains this site’s name, the current page path, the affiliate, placement, and destination host and path. It uses a new random identifier for that single event, creates no visitor profile, and does not track page views or sessions. PostHog also receives ordinary connection data, such as your IP address, to deliver and secure the request.
We use this limited measurement only to assess and improve the guide’s affiliate funding. We keep the events only while they are needed to compare placement performance, then delete or aggregate them.
When you follow a GetYourGuide link, you leave this site and GetYourGuide and the activity provider process information under their own terms.
Read GetYourGuide’s privacy policy .
Kiwitaxi transfer links use a Travelpayouts tracking redirect before opening Kiwitaxi. Travelpayouts and Kiwitaxi process ordinary request and booking information under their own terms.
Your choices and rights
You can choose not to follow an affiliate link. Depending on where you live, you may also have rights to access, correct, delete or restrict personal information, object to some processing, or complain to a data-protection authority. Email us to exercise a right. We may need enough information to verify and complete the request.
Changes to this notice
We update this page when the site’s technology or data practices change. The date above shows the current version.