The short version.
- While a driver is clocked in for a shift, the Med Ride driver app records their location continuously — including when the app is in the background and the phone is locked. It stops when they clock out.
- That location is visible only to dispatch and management at the driver's own company.
- Passenger information includes health-related details and is handled as protected health information. It is used to arrange and bill rides, and for nothing else.
- We do not sell personal information and we do not use it for advertising.
1. Who this policy covers
“Med Ride Platform”, “we” and “us” mean the operator of the Med Ride Platform software and the Med Ride driver app for Android and iOS, reachable at medrideplatform.com. This policy applies to the website, the driver app, and the public pages such as job applications and the contact form.
There are four kinds of people in the system, and the policy treats them differently:
- Drivers and other staff of a transportation company that uses the platform. They sign in, and the location section below is mainly about them.
- Passengers (also called members or clients) whose rides are scheduled in the platform. Most passengers never sign in; their information is entered by the transportation company or their case manager.
- Case managers and healthcare contacts who request rides on behalf of the passengers they are linked to.
- Job applicants who apply through the public careers pages.
Who is responsible for passenger data. Each transportation company decides what passenger information goes into the platform and who at that company may see it. Under HIPAA, the transportation company is the covered entity or the contractor of one; we operate the software on its behalf as a business associate. If you are a passenger and want your record corrected or deleted, the fastest route is the transportation company that arranges your rides — but you can also write to us at the address in section 12 and we will pass the request on and help carry it out.
2. Location, including background location
This is the part of the platform that collects the most sensitive information about a named individual, so it is set out in full.
2.1 When location is collected
Location is collected from a driver's device only while that driver has an open shift — that is, between clocking in and clocking out. The open time entry is the switch. The server checks it on every single upload: a device that keeps reporting after clock-out has its data rejected and nothing is stored. No shift, no location. Ever.
Location is not collected from passengers, from case managers, or from office staff who are not clocked in as drivers.
2.2 Continuous and background collection
While a shift is open, collection is continuous. On the Android and iOS driver apps it continues when the app is in the background, when the driver is using another app, and when the screen is off or the phone is locked. This is deliberate: a driver reading a trip detail or answering a call is still out driving, and a trail that stops whenever the app is not in front leaves gaps exactly during the hours the record is needed for.
Because it runs in the background, the app tells the driver so, at all times:
- Android shows a permanent notification for the whole shift, which cannot be dismissed while tracking is running.
- iOS keeps the system's blue location indicator visible in the status bar for the whole shift.
- The website, when a driver signs in on a phone browser, shows a “Sharing location” badge on every page while it is reporting.
- The driver app also shows a banner on the trips screen explaining what is being shared and with whom.
Signing out stops location sharing before the session is cleared, so a signed-out driver is never still being tracked.
2.3 What a location record contains
| Field | What it is |
|---|---|
| Latitude and longitude | Where the device was |
| Accuracy | How precise that reading was, in metres |
| Speed and heading | Reported by the device when available |
| Timestamp | When the reading was taken |
| Driver and company | Which driver it belongs to, and which company they work for |
| Shift | The time entry the reading falls inside |
| Channel | Whether it came from the Android app, the iOS app or the website |
We do not collect contacts, photos, messages, call logs, browsing history, or the contents of anything else on the device. We do not record audio or video. We do not use the microphone or the camera for tracking.
2.4 How often, and what is thrown away
- The device sends readings in small batches roughly every 30 seconds while a shift is open.
- A reading taken less than about 12 metres from the previous one is dropped on the device and never sent, so a parked phone does not write a record all day.
- A reading less accurate than 250 metres — typically a cell-tower estimate rather than a real GPS fix — is rejected by the server and not stored at all.
- Readings that cannot be sent because of poor signal are held on the device and sent when it reconnects. The device holds a limited buffer and discards the oldest readings first.
2.5 Vehicle tracking is separate
Some companies fit GPS hardware to their vehicles. That hardware reports the vehicle's position roughly every 30 seconds whenever the vehicle is on, regardless of who is driving it and regardless of whether anyone is signed in. Vehicle tracking belongs to the company that owns the vehicle and is governed by that company's own vehicle policy. It is stored alongside phone location, kept for the same period, and marked so the two can always be told apart.
2.6 Who can see a driver's location
Dispatchers and managers at that driver's own company, on the company's fleet map. Nobody at another company can see it. Passengers cannot see it. It is not published, not shared with advertisers, and not sold.
2.7 How a driver can stop it
Clock out, or sign out of the app. Either one stops collection immediately. Location permission can also be turned off or downgraded in the device's own settings at any time; the app will keep working, but the company will not be able to see where the driver is, which may affect dispatching and any mileage or timekeeping that depends on it. If a company requires location sharing as a condition of driving, that is the company's employment decision, not a technical requirement of the app — raise it with them.
3. What else we collect
| About whom | What |
|---|---|
| Drivers and staff | Name, email, phone, role and company; sign-in times and clocked shifts; trips completed; mileage and odometer readings; fuel and maintenance receipts; vehicle inspection notes and photos; payroll and contractor records; licence, insurance and onboarding documents; signatures captured in the app. |
| Passengers | Name, date of birth, home and destination addresses, phone number, health plan and member identifier, eligibility status, mobility needs and equipment, authorisation numbers, ride history, pickup and drop-off times, and signatures confirming a ride took place. |
| Case managers | Name, work email and phone, organisation, and which passengers they are linked to. |
| Job applicants | Everything on the application form and the documents attached to it. |
| Anyone using the site | IP address, browser type, pages requested and timestamps, held in server and security logs. Session cookies that keep you signed in. |
3.1 Cookies
We use cookies that are necessary for the site to function: one that keeps you signed in, one that protects forms against cross-site request forgery, and one that remembers a support session while it is open. There are no advertising cookies and no third-party analytics trackers.
3.2 Remote support
When a user asks for help, a company administrator can be shown the page that user is currently on. With the user's separate, explicit consent the administrator can also see a picture of their screen and, with a further separate consent, click on it for them. A banner and a stop button stay visible for the whole session. Screen images are held in memory only for as long as the support request is open and are never written to disk.
4. Health information
Ride records are health information. Knowing that a named person was taken to a dialysis centre every Tuesday says something about their health whether or not a diagnosis is ever typed in. We treat passenger records — names, addresses, health plan identifiers, eligibility, destinations and ride history — as protected health information under HIPAA, and we handle them under the terms we agree with each transportation company.
Health information is used to arrange rides, to confirm a passenger is eligible for the benefit, and to bill the health plan or state programme that pays for the ride. It is not used for marketing, is not sold, and is not shared with anyone outside the list in section 6.
5. How information is used
- To schedule rides, assign drivers and vehicles, and route them.
- To show dispatch where drivers and vehicles are during a shift.
- To confirm that a ride happened, when, and over what distance.
- To bill health plans and state programmes, and to answer their audits.
- To run payroll, mileage reimbursement and contractor payments.
- To keep vehicles, licences, insurance and inspections current.
- To keep the service secure, investigate incidents and prevent abuse.
- To meet legal, insurance and accreditation obligations.
We do not sell personal information. We do not share it with advertisers. We do not use it to train advertising or profiling systems.
6. Who we share it with
Information leaves the platform in only these circumstances:
- The transportation company whose records they are, and the staff there whose role gives them access.
- Health plans and state programmes such as AHCCCS, and the brokers who administer transportation benefits, for authorisation, billing and audit of the rides they pay for.
- Case managers and healthcare contacts, limited to the passengers they are linked to.
- Service providers that help run the platform, listed below. They may use the data only to provide their service to us.
- When the law requires it — a subpoena, court order, or a legal obligation we cannot refuse — or to protect someone's safety.
6.1 Service providers
| Provider | What it does | What it receives |
|---|---|---|
| SmarterASP.NET | Web and database hosting in the United States | All application data, at rest and in transit through the host |
| Google Maps Platform | Turning addresses into map points, drawing the map, and estimating distance and drive time | Pickup and drop-off addresses and map coordinates. No names and no health information are sent. |
| Twilio | Text-message alerts to company staff | A staff phone number and the text of the alert. |
| Cloudflare Turnstile | Telling a person from a bot on the sign-in, sign-up and contact forms | IP address and browser signals at the moment the form is submitted. |
| SMTP email provider | Password resets, notifications and contact-form mail | Recipient email address and the content of the message. |
This table reflects the integrations currently enabled on this deployment. Individual transportation companies may connect additional services of their own; ask the company that arranges your rides or employs you.
7. How long we keep it
| What | Kept for |
|---|---|
| Driver phone location and vehicle GPS history | 360 days (about 12 months), then deleted automatically by a job that runs every hour |
| Passenger records, ride records and billing records | As long as the transportation company's own retention obligations require — commonly six or seven years under health plan, Medicaid and state rules — and then as that company directs |
| Access and security logs | Retained to support audit and incident investigation |
| Support screen images | In memory only, for the length of the support request; never stored |
| Job applications | As long as the hiring company keeps them |
8. How it is protected
- Traffic to the site is encrypted in transit (HTTPS, with HSTS enabled).
- Particularly sensitive stored fields are encrypted at rest.
- Access is by role. A dispatcher, an accountant and a driver each see a different subset, and each company's data is isolated from every other company's.
- Passwords must be at least 12 characters with mixed case, a digit and a symbol. After 5 failed attempts an account is locked for 15 minutes.
- Signed-in sessions expire after 60 minutes of inactivity.
- Administrative actions are written to an audit log.
- Uploaded documents are served only to signed-in users entitled to see them.
No system is perfectly secure, and we do not claim otherwise. If we discover a breach affecting protected health information, we will notify the affected transportation company without unreasonable delay so that the notifications HIPAA requires can be made.
9. Your choices and rights
- Location. Drivers can stop sharing by clocking out, signing out, or revoking the permission in device settings — see section 2.7.
- See what we hold. Ask the transportation company, or write to us and we will help.
- Correct it. Wrong address, wrong phone, wrong plan identifier — tell the company or tell us.
- Delete it. We will delete what we are not required to keep. Ride and billing records a health plan or state programme requires us to retain cannot be deleted on request until that period ends.
- Complain. To us, to the transportation company, or to the U.S. Department of Health and Human Services Office for Civil Rights. We will not retaliate against anyone for making a complaint.
Arizona residents: the platform is operated in the United States and all data is stored here. If you are outside the United States, you should not use the platform, as it is not designed for transfers of data out of the country.
10. Children
Minors are transported under these benefits, so the platform can hold a minor passenger's name, address and ride details. That information is entered by the transportation company, a parent or guardian, or a case manager — never collected from the child directly. The driver app and the website are for adult employees and contractors, and we do not knowingly create accounts for anyone under 18.
11. Changes to this policy
If we change this policy we will update the date at the top of the page. A change that meaningfully affects what is collected from drivers — especially anything about location — will also be announced in the app before it takes effect, rather than left for people to discover.
This version is effective September 21, 2026.
12. Contact us
Questions about this policy, requests about your information, or a privacy complaint:
If your question is about a specific ride or a specific passenger record, please also name the transportation company involved — they hold the record and we cannot change it without them.