Privacy notice
TransLink uses account, contact, booking, payment-status, support, and trip-location data to provide tickets, operate trips, prevent fraud, answer support requests, and meet legal obligations. We do not store full card numbers; hosted payment providers process card details.
What we collect and why
We collect the minimum details needed for an account and journey, including pickup location. Crew see only the manifest for their assigned bus. Customer-care staff receive exact-match lookup access only when assisting a customer. Managers see approval records; administrators manage accounts and system settings.
AI support
Local support rules answer first. If the administrator enables DeepSeek, email addresses, phone numbers, and booking references are removed before an unanswered question is sent to the provider. Do not type NICs, card details, passwords, or health information into chat.
Retention and rights
Operational records are retained only for the period required for service, dispute handling, accounting, safety, and law. You may request access, correction, deletion where applicable, or object to certain processing by contacting privacy@translink.com.lk. Identity verification may be required.
Security and complaints
We use role-based and trip-level access, encrypted secrets, CSRF protection, protected sessions, audit details for approvals, and payment-provider verification. No online system is risk-free. Report suspected misuse immediately to the hotline or privacy email.
This product notice is a practical implementation draft and should be reviewed by Sri Lankan legal counsel before a public launch.