Why this page exists. A child's daily pickup location is among the most sensitive data anyone can hold. If you are a transportation company or a school district evaluating us, this page is written for your procurement and privacy review. If you are a parent, the short version is: we cannot see or change your child's record, and we never use it for anything except getting the bus to the stop.
1. Our role
Our customer is usually a transportation company that carries students under contract to one or more school districts. Sometimes it is a district directly. Either way, the school district remains the owner and controller of student records — that does not change because a contractor sits between us.
Where our customer is a transportation contractor, Nice Technologies acts as a school official with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)) only where the district has authorized that designation through its contract with the contractor. We perform an institutional service the district would otherwise perform itself, under the district’s direct control.
We process student data only on documented instructions, which reach us through our customer, as set out in our Data Processing Addendum. If you are a transportation company, that means the commitments below are ones you can pass through to the districts you serve.
2. What we commit to
- We do not sell student data. Not now, not as part of a merger or acquisition without the same protections carrying over, not ever.
- We do not use student data for targeted advertising, and we do not permit anyone else to.
- We do not build behavioral profiles of students for any purpose other than delivering the transportation service that was contracted for.
- We do not use student data to train models for our own or anyone else's benefit. Our right to use aggregated, de-identified data (Terms of Service § 6.1) expressly excludes student, rider and precise location data.
- We collect the minimum the job needs. The rider’s name and pickup address, an assigned stop, an accessibility requirement where relevant, and a contact for notifications. A route cannot be run without knowing who is being collected and from where. We do not ask for grades, discipline records, health records beyond a stated accessibility need, immigration status, or financial information — and we will not accept them if they are sent.
- We delete on request. A district, or the transportation company acting on its instructions, may require deletion at any time, and on termination we delete after the export window and confirm in writing.
- Parents go through the operator or the school. We do not act on a parent's request to change a record. Verifying who is entitled to make that request belongs to the organization that holds the relationship — the transportation company or the district — not to a vendor.
3. Who at Nice can see a student record
Student data sits on systems we run — that is what hosting means, and no vendor can honestly claim otherwise. The question worth asking is not whether we could reach it, but what has to happen before anyone does.
- Nobody has standing access. Accounts start with the narrowest role and are widened deliberately. Reaching customer records is not a permission our staff hold by default.
- A support session needs a reason and your approval. When we need to look at your data to fix something, the session is time-limited, tagged with the reason, approved by the operator, and written to an audit log the operator can read afterwards. You can see every time we were in there and why.
- We never copy it out. Student data is not exported, moved to another system, used for testing, or used to train anything. Our right to use aggregated, de-identified data expressly excludes student, rider and location data.
- Names are stored, and seen only where the job needs them. Operators enter a rider’s legal name and address, because dispatch and the office cannot run a route without them. The driver application can be set to show initials instead of full names — the phone that travels in the vehicle, and gets left on a seat, does not have to carry a roster of children’s full names. Office staff at the operator still see the full record; that is their job, and it is the operator’s access to control, not ours.
If you are a district asking who approves our access to your students’ records: the operator does, acting under the authority you gave it. If you would rather that approval sat with you directly, say so in your agreement with the operator and we will honor it.
4. What the parent application shows, and does not
| A guardian can see | A guardian cannot see |
|---|---|
| That their child boarded this morning | Vehicle location — no map or position is sent to a guardian device |
| That their child was dropped at school, and when | Any other child's name, stop or status |
| That their child boarded for home, and arrived at their stop | Driver personal details or employment records |
| Delay and cancellation notices, and a way to mark an absence or skip a trip up to three hours before pickup | Any operational, routing or fleet screen |
This scoping is enforced at the query layer against the guardian relationship — the application does not fetch a wider dataset and filter it in the client, because that leaks.
Because no continuous student location is sent to a guardian device, there is no guardian-facing student location feed for a district or its transportation contractor to assess, restrict, or have exposed in a breach. Vehicle tracking exists in the operations console, for the staff paid to act on it. Absence and skip submissions travel the other way — from the guardian into the roster — and are retained as an operational record of the trip, not as a location history.
5. Legal framework we operate within
- FERPA — we act as a school official under district control, where the district has designated us as such either directly or through its transportation contractor. We use student records only for the contracted purpose and do not re-disclose except as the district directs or the law requires.
- COPPA — accounts are created by the district, the transportation company or the guardian, never by children. Where any consent is required, the district obtains it as permitted for school-directed services. We do not knowingly allow a child under 13 to create an account directly.
- PPRA — we do not administer surveys, evaluations or analyzes to students.
- State student privacy laws — including California's SOPIPA and equivalents in other states, which restrict sale, targeted advertising and profiling of student data. Our commitments in section 2 are written to meet the strictest of these.
- Section 508 / accessibility — see our Accessibility Statement.
6. Agreements we will sign
We understand that neither a district nor the operator serving it can rely on a vendor's website. We will review and, where we can meet the terms, execute:
- your district's, your customer district's, or your state's standard student data privacy agreement;
- a National Data Privacy Agreement (NDPA) exhibit, including state-specific addenda;
- your own DPA in place of, or alongside, ours; and
- the data security and insurance exhibits your procurement process requires.
Send documents to info@nicetechnologiesinc.com. If there is a term we cannot meet, we will tell you which and why rather than sign and hope.
7. Breach notification
If a security incident affects student data, we will notify our customer, and the district where our agreement requires it, without undue delay and within 72 hours of becoming aware, with what we know and what we are doing. We will support the district in meeting its own notification duties to parents and the state, and we will not notify parents directly unless the district asks us to.
8. Sub-processors
The vendors that support the platform are listed at Sub-processors, with 30 days' notice before any change and a right to object. Each is bound by obligations no less protective than ours.
9. Questions
Transportation operators, district privacy officers, procurement teams and parents can all write to info@nicetechnologiesinc.com. Put "Student privacy" in the subject and it will reach someone who can answer properly.