Minimal data, clear controls.
UTA Tracker is built to work without accounts, with optional sign-in for synced commute features. The policy below explains the limited operational data involved in running the service and the choices available to you.
01
Information we collect
UTA Tracker is a free transit tracking tool that works without sign-in. We use Google Analytics to understand aggregate usage patterns such as pages visited, session duration, approximate region, device type, browser, operating system, and referrer URL. We also serve display ads through Google AdSense to help keep the site free.
When you first visit, a consent banner appears so you can choose which categories of data to allow. You can accept all, reject all, or customize preferences for analytics, advertising, and functional cookies. Your choices are stored in your browser and you can change them anytime by clicking the Privacy button at the bottom-left of any page.
The consent banner also offers Incognito mode. Incognito mode turns off Google Analytics, advertising personalization, visitor context, referrer capture, and session-duration tracking. UTA Tracker still keeps first-party page-view counts so we can tell which pages need capacity, fixes, or clearer transit information.
The interactive map stores your last viewed map position, selected filters, dashboard preferences, and signed-out saved commutes in browser localStorage. That preference data stays on your device and can be cleared through your browser site data settings.
If you sign in (magic-link email or Google OAuth) we use Supabase Auth, which stores your email address, any Google OAuth profile fields, session tokens, and your assistant data-consent record. If you save commutes to your account we also store the commute name, selected routes and stops, scheduled times, selected days, and any custom commute places you add so the commute can sync across devices.
If you subscribe to the newsletter we store your email address, subscription timestamp, confirmation status, and a per-subscriber salt used to sign your one-click unsubscribe link. Newsletter emails carry our physical postal address and an unsubscribe link in every send, as required by CAN-SPAM.
If you submit feedback or a rider report we store the message body, your rating, your browser user-agent, and a short-lived session ID for debugging. These are visible only to the operator.
Hosting infrastructure may keep standard access logs such as IP address, request path, timestamp, and HTTP status for up to 14 days for security and operational purposes.
02
Information we do not collect
- No payment information
- No precise GPS location access unless you explicitly use location-based features
- No contact information unless you email us directly
- No advertising resale or commercial data sharing — ads are served by Google AdSense, not by selling your data
- No selling saved commute data
03
Transit and map data
Real-time vehicle positions, arrivals, and service alerts are sourced from UTA public GTFS-Realtime feeds and relayed to the browser. We do not store individual route, stop, or vehicle lookups as rider profiles.
Map tiles are served by OpenFreeMap. Your browser may make direct requests to OpenFreeMap tile servers when viewing the interactive map.
04
ChatGPT app integration
UTA Tracker can be used through ChatGPT via the Model Context Protocol. Tool requests are routed through the UTA Tracker MCP server, and we do not log the content of individual tool calls.
05
In-app AI assistant
The in-app assistant (the 'Stuck?' button) is gated behind sign-in and a two-part opt-in. The first opt-in lets us forward your typed message to OpenAI's gpt-5.4-nano model so it can write the reply. We send each request with the lowest-retention setting OpenAI exposes (store: false), so OpenAI does not retain your prompts for training. The second opt-in lets us store your prompt and the assistant's reply in our developer analytics so we can see what riders are asking about and improve the assistant. Both opt-ins default to off and are required before the assistant will respond.
Before forwarding text to OpenAI we redact common PII patterns (emails, phone numbers, long digit runs). The assistant is AI-generated and may be inaccurate — always confirm critical schedule information against the official UTA app or rideuta.com.
You can revoke either opt-in at any time by emailing hello@utatracker.com; we will clear the consent flags on your account and delete any stored prompt logs tied to your user ID.
06
Your choices and data rights
- Use the Privacy button at the bottom-left of any page to change your cookie and ad preferences at any time.
- Choose Incognito mode if you want UTA Tracker to keep only page-view counts and stop all other analytics signals that the app controls.
- Use the Google Analytics opt-out browser add-on to limit Google Analytics measurement.
- Clear localStorage or site data in your browser settings at any time.
- Save commutes locally without signing in, or sign in only if you want cross-device sync.
- Use browser Do Not Track settings where technically feasible.
- To request a copy or deletion of your account, saved commutes, assistant conversation logs, newsletter subscription, or submitted feedback, email hello@utatracker.com from the address on file. We will respond within 30 days. EU/UK (GDPR), California (CCPA), and Utah (UCPA) residents may exercise the data-subject rights granted by their local law through the same address.
- Unsubscribe from the newsletter at any time using the one-click unsubscribe link in any issue.
07
Policy changes
We may update this Privacy Policy from time to time. The last updated date reflects the most recent revision, and continued use of the service after changes are posted constitutes acceptance of the revised policy.
Privacy links and sources
Use these links to verify transit, map, analytics, and official agency references.
hello@utatracker.com