Via demo privacy
This prototype stores account credentials as salted password hashes, sessions, demo trips, verification metadata and the latest shared driver position. Do not upload real identity documents or payment details.
Device location requires permission. Pickup coordinates are used for quotes and demo dispatch. Driver location is shared with the assigned passenger while the app is in the foreground. Going offline stops location sharing when no trip is active.
Trip messages are stored by Via and available only to the passenger and assigned driver. Messaging closes when the trip ends. Fresh driver coordinates are shared only during the assigned trip. Location sharing is limited to the foreground app.
Postcodes.io receives pickup and destination coordinates to check BN postcode coverage, and full postcode searches to find their coordinates.
Address searches are sent to Photon (Komoot). Pickup and destination coordinates are sent to the FOSSGIS OSRM routing service. OpenStreetMap street tiles are requested for the visible map area. These providers may log requests. Route results are cached for five minutes and searches for one day to reduce requests. Your Via account identifier is not sent to these providers.
When Google Maps is connected, address searches and journey coordinates are sent to Google for search and routing. Map display also connects to Google. See Google’s Privacy Policy.
Stripe-hosted sandbox checkout handles fictional test card details. Via stores payment references and sends the fare and journey labels to Stripe. Driver payout onboarding sends the driver account email to Stripe. There is no monthly driver fee. Use only fictional test details; do not enter real financial or identity data. Via does not store card numbers.
Via data is hosted through Vercel and Neon. Sign out to revoke your current session. This is a testing service, not a real transport booking service.
Vehicle QR checks store the trip, matched vehicle and check time. Camera QR scanning is processed on your device; no camera images are uploaded. SOS snapshots stay on your device until you choose Share or Copy. If you start live sharing, Via stores your latest device coordinates, accuracy and observation time and makes them and selected trip details available to anyone holding the private link for up to two hours. Recipients can forward the link. Stop sharing or signing out revokes access and clears the stored coordinates. Updating GPS needs Via open in the foreground. Emergency-contact names and phone numbers are stored privately in your account. Contact texts open in your phone for you to send; automatic SMS is not connected. During an assigned ride, tapping Call 999 immediately opens your phone dialler and also attempts a Via demo security request. This does not confirm a call connected or contact police through Via. Requests can be automatically assigned to the security company selected by the owner. Enabled accounts in that company can see the requester’s account email and supplied name/phone, associated journey, driver name/contact and vehicle registration, plus any shared requester device location. Missing or stale location is labelled. Users and assigned security accounts can exchange messages inside Via; messages are stored and access follows the current assignment. Resolved requests hide contact details and device location. Security dispatch is not connected; demo status changes do not send responders. Location and chat updates can pause during a phone call or when the app is in the background.
Driver registration in this demo stores fictional contact, address, licence, vehicle, DBS reference and consent details. Only the driver and Via owner can view a full application. Do not submit real identifiers, DBS findings or identity documents. Digidentity pre-production verification is prepared but unconfigured: no data is sent until Via has provider credentials and the driver starts that flow with consent. The server keeps the verification reference and status, not full identity reports or biometric images. Identity results do not automatically approve right to work or a driver. Ongoing DBS, DVLA and council checks are not connected; monitoring dates are simulated.
The owner-only register searches driver/application records, trip references, booking/dispatch staff records and audit actors within Via. It stores fictional staff joining/leaving dates and dates when the owner records seeing an original Basic DBS certificate; certificate files and criminal-record findings are not collected. Historical staff entries remain preserved until an approved retention policy is implemented. Operator-policy references and HMRC evidence dates are recorded without storing the actual tax-check code. Use fictional entries in this demo.
Back to Via