Privacy Policy for UW GO

Effective date:

UW GO turns a University of Waterloo or Wilfrid Laurier class schedule into a day-by-day travel plan. This Privacy Policy explains what information the website handles, why it handles it, and the choices available to you.

UW GO is an independent project. It is not affiliated with, endorsed by, or acting on behalf of the University of Waterloo, Wilfrid Laurier University, Google, Supabase, Vercel, or Grand River Transit.

What we collect and why

Account and saved-plan information

To use the signed-in experience, you provide a @uwaterloo.ca email address. Sign-in uses a one-time code sent by Supabase. Supabase maintains your account identifier, email address, session information, and the information necessary to operate its authentication service.

When you choose to save a plan, UW GO stores the parsed details of your schedule and your planning preferences in Supabase. This can include course codes and titles, sections, meeting days and times, rooms, instructor names when they appear in the parsed result, term information, your selected home (including its coordinates and, for a custom home, formatted address), arrival buffer, route, gym, end-of-day, and course-colour preferences, your answers about what to do between classes (for one day or every week), and the way you chose for a trip, such as indoors, walking, or the bus. This lets your plan be available when you return, including on another device. The raw text you paste from Quest is parsed in your browser; UW GO does not upload or store that raw paste.

The saved plan is protected by database access controls intended to allow each signed-in student to read, change, or delete only their own saved plan.

Information kept on your device

Your browser keeps a local copy of your plan and preferences. It may also keep route results, reminder settings, and PAC occupancy samples. These are used to make the app work across reloads and, where possible, without a connection.

Walking-route cache entries are not used after 30 days and transit-route entries are not used after 10 minutes. Expired entries can remain in browser storage until the cache is next pruned or you clear the website’s site data. PAC occupancy samples are kept on the device (up to 2,000 recent samples) until they are replaced or you clear site data.

If you enable leave-time reminders, reminder titles, message text, and timing are stored locally and may be shown through your browser or device notification system. UW GO does not send push notifications from its servers.

Location, compass, maps, and routing

UW GO requests your device’s precise location only after you start a feature that needs it:

  • Where am I requests one location fix to place you on the map.
  • A quick route requests one location fix to route from your current location.
  • Start trip begins a high-accuracy location watch for the active trip. The app uses those fixes to show your position, follow your progress, calculate time and distance remaining, and determine whether you have moved off the planned route. The watch ends when you end the trip or leave that screen.

UW GO does not save GPS fixes to your account or send a continuous location stream to its own servers. A current location can be sent to Google Maps Platform as a route origin when you request a quick route or when UW GO recalculates an off-route walking trip. The embedded map may also process the displayed map area and locations under Google’s privacy practices.

During an active trip, UW GO can use your device’s orientation sensor to orient the map and position marker. Some browsers request separate permission for this, while others make the sensor available once the trip is active. UW GO does not save compass readings to your account or include them in its own server/API requests. Google Maps may process map-display state, including orientation, when the embedded map is in use.

UW GO otherwise uses the building locations in your schedule and the home location you select to calculate routes.

If routing is available, UW GO sends origin and destination coordinates and relevant departure or arrival times to Google Maps Platform through UW GO’s routing service. UW GO does not send your course names, schedule text, or account identity to Google for this purpose. Route results are cached for performance and are not used after 30 days for walking or 10 minutes for transit. A cached route can include the coordinates used to calculate it, including a selected home or current-location coordinate.

If you enter a custom home address, the address is sent once to Google Geocoding API to obtain a location. The resulting formatted address and coordinates are returned to your browser and can be saved with your plan. Opening a route in Google Maps takes you to Google directly; that interaction is governed by Google’s privacy policy.

When you expand the embedded map, Google Maps JavaScript API loads map content in your browser. Google may receive information generated by that interaction, such as your IP address, browser or device information, map viewport, and the relevant map locations, under its own privacy practices.

Live transit and PAC information

For live Grand River Transit predictions, UW GO sends only the route, stop coordinates, scheduled time, and a temporary request key needed to match the planned transit leg. UW GO’s server retrieves the public GRT real-time feed and returns the matching prediction. It does not send your course data to GRT.

If you use the PAC occupancy feature, UW GO retrieves public facility-occupancy information from Waterloo Athletics. The request is made by UW GO’s server; the app keeps occupancy samples on your device to estimate usual busy times.

Route-closure reports

If you report a campus path, tunnel, bridge, or entrance as closed, UW GO stores your account identifier, the identifier of the reported segment, and the time of the report. The report has no free-text field and does not record your device location. Other signed-in users can see only an anonymous count of recent reports for a segment and the time of the most recent report—not the identity of the reporter. You can withdraw your own report in the app.

Website measurement

UW GO uses Vercel Analytics to understand aggregate use of the website. Vercel may process standard web-request and measurement information, such as pages visited, browser or device details, IP-derived approximate location, and performance data, under its own privacy policy. UW GO does not use advertising pixels or sell personal information.

How we use information

We use the information above to authenticate you, save and restore your plan, calculate and display routes, provide optional reminders and live travel or occupancy information, improve route safety through aggregated closure reports, operate and secure the website, and understand aggregate website use.

We do not use your schedule or home information for advertising, and we do not sell it.

Service providers and links

UW GO relies on the following providers to provide its features:

  • Supabase for authentication, account sessions, and saved plans.
  • Google Maps Platform for geocoding, routes, and embedded maps.
  • Vercel for website hosting and analytics.
  • Grand River Transit / Region of Waterloo for public real-time transit predictions.
  • Waterloo Athletics for public PAC occupancy information.

These providers process information under their own terms and privacy policies. UW GO may also link to Google Maps; external websites are responsible for their own privacy practices.

Retention and deletion

Your saved plan remains in Supabase until you delete it. In Settings, choose Delete everything to remove your saved schedule, home, preferences, gap answers, and route choices from UW GO’s user_state record and its primary local plan copy on the device. Local reminder, PAC-sample, and route-cache entries are managed by your browser and may be cleared through your browser’s site-data controls.

Delete everything does not delete your authentication account. Supabase continues to retain the account identifier, Waterloo email address, and authentication/session information needed for the account, as well as the legacy profile record created at sign-up. Signing out clears UW GO’s primary local plan copy but does not delete the account. To request account deletion, use the contact method below.

Route caches expire as described above. Recent closure reports are included in the anonymous consensus for 24 hours; your report remains associated with your account until you withdraw it or your account is deleted.

Security

We use authenticated access and database row-level access controls for saved plans and closure reports. No internet service is completely secure, so please do not treat UW GO as a place to store information you would not want exposed.

Your choices and privacy requests

You can avoid entering a custom address by selecting a residence preset, avoid expanding embedded maps, decline notification permission, use the website without enabling optional live features, edit or delete your saved plan, withdraw a closure report, and clear local data in your browser.

For questions, account deletion requests, or other requests about your UW GO data, email info@uwgo.ca.

Do not send your schedule, address, or other unnecessary personal information in your initial email.

Changes to this policy

We may update this policy when UW GO’s practices change. We will post the revised policy here and update the effective date.

Questions about this Privacy Policy or your UW GO data? Email us at info@uwgo.ca.