Privacy Policy
Last updated: 11 September 2026
This notice explains how Passenger.ie uses information to provide journey searches and bookings, support customers, and improve the app and website. Optional analytics are a separate choice. Using Passenger or accepting its terms does not mean you consent to analytics.
For privacy requests, contact privacy@passenger.ie.
Information used to provide the service
Journey requests. The words you submit, together with any conversation context, are sent to Passenger's server to understand the journey you requested. This can include origin, destination, dates, times and travel preferences. Our language-model providers may process that request. Please enter journey details only; do not put contact information, payment details, pass numbers or other sensitive information in the search box.
Bookings. Depending on the booking you request, we process your name, email address, phone number, journey details and any travel entitlement information you provide. These are used to arrange your booking and ticket delivery with the transport operator. A Free Travel Pass choice is service information; it is excluded from our new optional analytics.
Purchases and access. Device or app identifiers, purchase and transaction identifiers, receipt-derived values, entitlement status and booking counts may be stored to validate purchases, restore access, provide the free-booking allowance and prevent abuse. These operational records can be linked to a device or purchase and are not anonymous analytics. We do not receive your full payment card number from Apple or Google. Where Stripe payment services are offered, card entry is handled by Stripe; payment status and related booking details may be held by Passenger.
Device features and support. Contact and ticket details you choose to save may remain on your device. Permissions for features such as location are controlled by your operating system. Our optional analytics do not collect GPS coordinates. If you contact support, we process the information you send to answer your request.
Operating the service. Requests pass through our hosting and network providers, which necessarily receive connection information such as IP addresses. Technical, security and booking records may be needed to operate the service, investigate faults and prevent abuse. Turning analytics off does not prevent the processing needed to answer your search or complete your booking.
Optional analytics
Website. Analytics stay off until you enable analytics in Manage preferences or choose Accept all. With permission, our own endpoint receives page names, a broad referring-source category where available, app-store link clicks and selected journey-flow events. A random identifier distinguishes a consenting browser session; it expires after 30 minutes without analytics activity, or when the browser clears its session storage. It counts consenting sessions rather than known people or everyone who visits.
iPhone app. App versions with My Details → Privacy & Analytics offer the Share optional usage analytics setting. It starts off. If enabled, we receive app-open and session events, search insights, and booking-flow events. A random analytics identifier distinguishes consenting app installations and is separate from the identifier used to manage booking access. The installation identifier is reset when you turn analytics off or exclude the device. Older app versions may not have these controls or report the same events.
Understanding searches. We want to learn where searches fail, including the first submitted request in a conversation. With permission, the new analytics records may include:
- Known station or city names selected from a fixed list, the transport mode and single/return choice.
- A broad range for how far ahead the journey is, rather than the exact travel date or time.
- Whether it was the first request, a word-count range, whether a date or time was mentioned, and whether the parser needed clarification or encountered an error. For the first request, a short template may preserve common journey words such as “from”, “to” and “please”, replacing places, dates, times and all other words with placeholders; it does not retain your exact wording.
The new analytics does not store the words you typed, keystrokes, screen recordings, passenger names, emails, phone numbers, payment details, ticket references or Free Travel Pass status. Submitted text is still processed separately to provide your requested search, as explained above.
Booking insights. We measure steps such as starting a booking, opening an operator's booking page, and confirmations or failures reported by the app. Opening an operator's website does not prove that a ticket was purchased. Counts cover reporting clients and consenting users, and can differ from the operator's records or Apple's analytics.
These records use random or pseudonymous identifiers. They are not described as fully anonymous: journey patterns and identifiers can still relate to someone. We use them to improve Passenger, not to serve targeted advertising, sell personal information or build profiles across other companies' apps and websites. The updated website does not load PostHog or session replay.
You can withdraw website consent through , or use the app setting described above. This stops future optional collection and clears the local analytics identifier. It does not automatically erase records already received. Contact us if you would like to request erasure; we may need information to locate records without collecting unnecessary new data.
Cookies and device storage
The website uses browser storage to remember your analytics choice for up to 180 days and, where used, accessibility preferences and temporary booking state. Optional analytics session storage is created only after acceptance. A previous notice dismissal is not treated as consent.
Choose Reject all to keep Passenger’s optional analytics off, or change the analytics choice in Manage preferences. You can use the website either way. You can also close the banner without changing your choice. Clearing your browser's storage removes the saved choice and we will ask again. If storage is blocked, a choice may last only for the current page.
See the Cookie and storage notice for the storage names, purposes and durations. Protected administrator pages use a separate login session for security.
Service providers and sharing
We use providers to deliver the functions you request:
- Transport operators: booking and journey information needed for the search, reservation and ticket delivery. Their own terms and privacy notices apply to their services.
- OpenAI and, where configured, Google Gemini: submitted journey text and context to interpret a search request.
- Fly.io and Turso: application hosting and database services for Passenger's service and first-party analytics.
- Upstash: operational session and rate-limit storage to protect the service and administrator access.
- HERE: place and journey information needed to resolve and provide supported journey searches.
- Apple, Google and, where offered, Stripe: purchases, payment processing and purchase validation.
Providers may process information outside Ireland or the European Economic Area. The country, retention and transfer arrangements depend on the provider and service configuration. Contact privacy@passenger.ie for details about the arrangements applying to your information.
Apple's App Store analytics are separate from Passenger's optional analytics and are subject to Apple's settings and notices. The landing page directly embeds a YouTube video using YouTube's privacy-enhanced player. The player can load as you browse to it; playback starts when you press its play control. Loading it connects to Google, which may process your IP address, device and viewing information and use its own storage under its privacy notice. Passenger's analytics choice does not control YouTube's player or Google's processing. Following a link to an app store or a transport operator opens that provider's service, where its own privacy practices apply. We may also disclose information where required by law, or where necessary to establish or defend legal claims.
Why we use information
- Providing the service you request: to understand a journey, make a booking, manage purchased access and respond to related support requests.
- Consent: for the optional analytics described here. Consent can be withdrawn without affecting your ability to use the service or the lawfulness of earlier processing.
- Legitimate interests: to secure the service, prevent abuse, diagnose operational problems and handle disputes, taking account of your rights and interests.
- Legal obligations: where records or disclosures are required by applicable law.
How long information is kept
- New optional analytics: individual events are scheduled for removal after 90 days. Daily aggregate event totals are scheduled for removal after 13 months. Cleanup runs during service operation; a stopped service may retain records until it resumes.
- Older analytics: historical records created before this update are kept separately from the new measurements. They may contain device identifiers or more detailed journey information and are not represented as new, consented or fully anonymous data.
- Bookings, purchases and support: retained while needed to provide and restore purchased access, resolve booking or payment queries, prevent abuse and satisfy applicable record-keeping or legal requirements. The period depends on the record and its purpose; the 90-day analytics limit does not apply to all service records.
- Device storage: retained for the periods in our storage notice or until you clear it. Uninstalling the app does not itself delete records already held by Passenger, a transport operator or a payment provider.
Contact us to ask about a particular record or request deletion. Some records may need to be retained where another lawful reason applies.
Your choices and rights
Depending on the information and legal basis involved, you may request access, correction, erasure, restriction or portability of your personal data, object to processing based on legitimate interests, and withdraw consent. Email privacy@passenger.ie. We may ask for proportionate information to verify a request and locate the relevant records.
You can complain to Ireland's Data Protection Commission, or your local supervisory authority. Our service is intended for adults. If you believe a child has provided personal information, please contact us.
We use access controls and encrypted connections to protect information, but no service can guarantee absolute security. We will update this notice when our practices change and seek a new choice when an optional analytics purpose changes. A policy update does not silently turn analytics on.