Plain-language notice
Privacy without surprises
This independent guide has no accounts, analytics cookies, visitor profiles or session tracking. It sends only the anonymous guide, destination, official-source, app-platform interest and affiliate events described below. A non-unique local browser flag prevents repeat platform votes; PostHog receives ordinary connection data. Any email is sent only when you choose to use your own email client.
Last updated 13 August 2026
Crete Bus
Crete Bus mobile app privacy
This section covers the Crete Bus mobile app for iPhone and Android, which is still in development and described here as it is submitted for store review. Website practices are described separately below. The app is free, has no accounts, and carries no advertising.
Location stays on your device during ordinary browsing
For nearby-stop sorting and your position on the map, the app uses foreground location while it is on screen. That ordinary browsing location is processed on the device and is not written to a server.
A GO ride that you deliberately start is different: it records the ride route and can continue while the screen is locked until the ride ends. Verify mode also uses your coordinates when you deliberately submit a stop correction. Both optional paths are described below.
Permission is optional. If you decline it, browsing stops, routes, timetables, and the map keep working; only the “near me” ordering and your own position marker are unavailable.
Schedule data is bundled, not fetched
Timetable, route, and stop data ships inside the app itself and is read from the device. The app performs no update downloads for this data, so no request, device identifier, or update telemetry reaches SD2 Studio while you are planning a journey.
Because the data is bundled, the app does not receive live or real-time departure information, and it keeps working with no signal.
GO ride companion
GO is an optional companion that you start yourself, ride by ride. A GO ride you start uploads an anonymous location trace to Supabase in the EU so SD2 Studio can improve route information. It never starts on its own and is not part of ordinary planning or browsing.
Each upload carries a one-time random code, with no account and no persistent device identifier. Separate rides cannot be linked through that code or tied to your name or email. Under the Play Data safety definition, the precise location is collected, not shared: collection is optional app functionality, and Supabase acts as SD2 Studio’s backend processor rather than an independent recipient.
Crete traces are currently discarded server-side after transmission because Crete is not registered in the ingest backend. That server-side rejection does not prevent the app from sending the trace.
Stop contributions in Verify mode
Verify mode is optional and is switched on by you. When you confirm, move, add, or remove a stop, the app sends the stop change, your coordinates, and an install-scoped device ID to Supabase in the EU. The coordinates help assess how close you were to the stop; the device ID helps protect the contribution process from duplicate or abusive submissions.
For the Play Data safety declaration, precise location and device or other IDs are collected, not shared. Both are optional app functionality. Supabase processes them for SD2 Studio as its backend processor; they are not shared with an independent third party for advertising or another company’s purposes.
The install-scoped device ID is not an advertising identifier and is not used for product analytics, cross-app tracking, or profiling. A Verify contribution is sent only after you choose a stop action; simply opening the map or turning on Verify mode does not submit a contribution.
Tours and activities from GetYourGuide
The app links to activity searches on GetYourGuide and can render a GetYourGuide booking widget inside an in-app web view. SD2 Studio earns a commission on qualifying bookings made through those links and that widget, at no extra cost to you.
Opening a link or the widget loads GetYourGuide, an independent company acting as its own controller. GetYourGuide receives your IP address, device or browser information, and your interactions inside the widget, and it sets its own cookies under its own policy. SD2 Studio does not receive your booking details.
What the app does not do
These exclusions apply to the Crete Bus mobile app.
- It has no accounts, logins, or signups.
- It runs no product analytics and sends no usage or page-view events.
- It sends no crash reports, diagnostics, performance data, or session replay.
- It shows no ads and uses no advertising identifier.
- It contains no purchases or subscriptions and collects no payment details or purchase history.
- It does not collect contacts, photos, files, or phone numbers.
- It does not track riders across other apps or websites.
- It does not sell or rent personal data.
Reaching SD2 Studio
Email is the route for privacy questions, corrections, and requests about the Crete Bus mobile app. There is no in-app messaging or feedback channel, and no support form collects your message inside the app.
Transit data attribution
The planned app will orient journeys against the publications of the responsible operators — KTEL Heraklio–Lasithi, KTEL Chania–Rethymno, Heraklion Urban Buses and Chania Urban Buses — with each claim linked to the operator source it came from. No operator dataset is bundled or redistributed today.
Coverage is limited to scheduled bus services on the island of Crete. Operators remain the final source for routes, times, fares and disruptions.
Bases, residency, and privacy rights
SD2 Studio is the developer, operator, and controller for the Crete Bus mobile app. Your choice to start a GO ride or submit a Verify-mode stop contribution is the basis for that optional processing. Supabase processes those submissions for SD2 Studio in the EU.
Depending on the law that applies to you, you may ask to access, correct, delete, or restrict your data, object to processing, or complain to a supervisory authority.
Deleting your data
This section explains how to ask SD2 Studio to delete app data from GO rides, Verify-mode stop contributions, or email correspondence.
Make a deletion request
Email [email protected] and identify the Crete Bus mobile app and the data you want removed.
Data SD2 Studio can delete on request
- GO traces and Verify-mode stop contributions that SD2 Studio can locate from a one-time ride code, install-scoped device ID, or sufficiently specific technical details.
- Email correspondence you have sent, including your address and message.
How anonymous app records can be located
GO traces are not linked to an account, name, email address, or persistent device ID, and Verify contributions are not linked to an account or email address. In your request, describe the ride or stop contribution and provide any one-time ride code or install-scoped device ID available to you. SD2 Studio will explain what can be located and delete matching records. An email address alone cannot identify an anonymous GO trace or Verify contribution.
Data kept
- Data held on your device, such as saved journeys and preferences, stays under your control and is removed when the app is deleted.
- Crete GO traces are currently discarded server-side after transmission because Crete is not registered in the ingest backend. If a trace is accepted in the future, its one-time ride code is not linked to your account, name, email, or persistent device ID.
- Verify-mode contributions may be retained while needed to review and improve stop data or meet legal and security obligations, unless a valid deletion request requires earlier removal.
- Aggregate, non-identifying route or stop results may be retained because they describe the transport network rather than a rider or device.
Who operates this guide
Crete Bus is an independent information website and is not a transport operator, public authority or activity provider.
Privacy questions and rights requests: [email protected].
Website delivery and security
Cloudflare delivers and protects this website. Like most web infrastructure, it processes request information such as IP address, requested URL, traffic-routing data, browser or system information, and security signals. We use this processing only to deliver, cache, secure and diagnose the site.
Anonymous demand signals
On a guide or destination page, and when you select a labelled official-source link, this site sends one cookie-free event to PostHog EU Cloud. It contains the site, page path, guide or destination ID, or the official destination host and path. Each event uses a fresh random identifier, creates no visitor profile and contains no email address, query string, page-view session or persistent identifier.
Anonymous app-interest votes
If you press an iPhone or Android vote, this site sends one cookie-free app_interest_click event to PostHog EU Cloud. It contains only site, platform, placement and page_path. A fresh random identifier is created for that event and no visitor profile is created. PostHog also receives ordinary connection data, such as your IP address, to deliver and secure the request.
After a vote is counted, this site stores the value 1 in localStorage under a key for the site and platform to prevent repeat votes in that browser. The flag contains no unique token and is not a unique visitor identifier. It remains until you clear this site’s stored data.
We use these events only to compare platform demand while deciding whether to build the app, then delete or aggregate them when no longer needed. Voting is optional. You can clear this site’s stored data at any time. The email launch-contact link sends no analytics event.
Email you choose to send us
If you email us, we receive your email address, message, headers and anything you attach. Cloudflare Email Routing forwards the message to a verified support inbox. We use it to answer the request, correct the guide, handle accessibility feedback or meet legal obligations.
Do not send passport, payment-card or health information. Messages are kept only as long as reasonably needed for the conversation, security and legal obligations, then deleted or anonymised.
Affiliate links
Marked GetYourGuide links are affiliate links. If you book after following one, this independent guide may earn a commission at no extra cost to you. Affiliate URLs include our partner identifier and a placement label. We do not receive your booking or payment details from this website.
When you select a marked affiliate link, we send one cookie-free affiliate_click event to PostHog EU Cloud so we can understand which placements support this guide. It contains this site’s name, the current page path, the affiliate, placement, and destination host and path. It uses a new random identifier for that single event, creates no visitor profile, and does not track page views or sessions. PostHog also receives ordinary connection data, such as your IP address, to deliver and secure the request.
We use this limited measurement only to assess and improve the guide’s affiliate funding. We keep the events only while they are needed to compare placement performance, then delete or aggregate them.
When you follow a GetYourGuide link, you leave this site and GetYourGuide and the activity provider process information under their own terms.
Your choices and rights
You can choose not to vote, clear this site’s stored data, or not follow an affiliate link. Depending on where you live, you may also have rights to access, correct, delete or restrict personal information, object to some processing, or complain to a data-protection authority. Email us to exercise a right. We may need enough information to verify and complete the request.
Changes to this notice
We update this page when the site’s technology or data practices change. The date above shows the current version.