Privacy Policy

Last updated: August 24, 2026

This policy explains how ViaNJ handles information when you use the ViaNJ iOS app or visit vianj.app. ViaNJ is an independent app and is not affiliated with or endorsed by NJ Transit.

Information the app handles

ViaNJ handles only the information needed to provide train, ticket, subscription, recovery, security, and support features. Depending on which features you use, this may include:

  • Contact information: your name, email address, and phone number when you sign in to an NJ Transit account, use integrated checkout, or recover a receipt.
  • NJ Transit account information: your NJ Transit account identifier, profile, session information, and credentials when you choose to sign in. Credentials are stored in your iPhone Keychain and sent to NJ Transit for authentication; ViaNJ does not store them on ViaNJ servers.
  • Ticket and purchase information: selected stations, fare type, ticket quantity, price, confirmation and receipt identifiers, ticket status, and subscription status.
  • Installation identifier: a random token stored in your iPhone Keychain. It secures ViaNJ's receipt-routing, recovery, and diagnostic services. It is not an advertising identifier.
  • Product interaction and diagnostics: app version and build, iOS version, a temporary session ID, feature events such as app launch, checkout progress, subscription actions, and ticket recovery outcomes, plus limited technical attributes. ViaNJ also derives a one-way, pseudonymous analytics identifier from the installation credential on its server. Diagnostic events are designed not to contain names, contact information, payment details, ticket barcodes, or full receipt contents.

How ViaNJ uses information

ViaNJ uses information to:

  • show departures, service alerts, fares, and tickets;
  • authenticate with NJ Transit and complete actions you request;
  • route and recover NJ Transit ticket receipts;
  • provide ViaNJ Pro, restore purchases, and determine whether subscription features are available;
  • protect the service, prevent misuse, diagnose failures, and improve reliability; and
  • respond to support and privacy requests.

ViaNJ does not sell personal information, show third-party advertising, use collected information for advertising, or track you across other companies' apps and websites.

Ticket checkout and receipt recovery

When you start ticket checkout, ViaNJ sends your delivery email to a ViaNJ-operated routing service hosted by Cloudflare. The service creates a private purchase address so ViaNJ can receive the NJ Transit receipt, associate it with your installation, and make the ticket available for recovery. The service may process the private purchase address, your delivery email, confirmation number, receipt timing, and installation token for these purposes.

Your phone number, trip, fare, and other checkout details are submitted to NJ Transit as part of the ticket purchase. If you manually import a receipt, the email address and confirmation number you provide are sent to NJ Transit to retrieve it.

Payments and subscriptions

ViaNJ Pro is an optional auto-renewable subscription sold and billed by Apple through StoreKit. Apple processes the purchase and makes subscription status available to the app. ViaNJ does not receive your Apple Account password or full payment-card details from Apple.

NJ Transit fares are separate from ViaNJ Pro. NJ Transit and its payment provider, TrustCommerce, process fare payments. Payment information entered on their secure checkout is governed by their policies. ViaNJ does not store payment-card details on ViaNJ servers.

If you choose to save a ticket payment method in ViaNJ, it is stored locally in your iPhone Keychain. When a linked companion checkout is used, ViaNJ encrypts the payment data to that linked device for the requested transaction. The relay cannot decrypt it, and the companion is designed to use it in memory and clear it after checkout.

Information stored on your device

ViaNJ stores app preferences, saved stations, tickets, activation state, and recovery state on your device. Contact information, optional NJ Transit credentials, optional saved payment information, installation credentials, and linked companion credentials are stored in the iPhone Keychain. Apple Wallet passes are stored and managed by Apple Wallet.

Local notifications may include trip, departure, ticket, and expiration details. Notification permission is optional and controlled in iOS Settings.

Location, maps, and Rail Passport

If you grant When In Use location permission, ViaNJ can show your current location on Rail Radar and an individual train journey map. ViaNJ processes that location on your device. It does not store it on ViaNJ servers, transmit it with diagnostics, use it to estimate a train's location, or use it to add journeys to Rail Passport.

Rail Passport records only journeys you explicitly choose to add. Passport history is stored locally on your device and is not uploaded to ViaNJ servers.

Private iCloud ticket backup

ViaNJ Pro can automatically back up eligible checkout tickets to your private iCloud database using Apple CloudKit. ViaNJ does not operate or have access to a shared server database containing these backups. Apple processes and stores the backup under your iCloud account, subject to Apple's terms and privacy policy. You can control ticket backup in ViaNJ Settings and your device's iCloud settings.

Anonymous diagnostics choice

Sharing anonymous diagnostics is enabled by default. You can turn it off at any time in ViaNJ Settings. Turning it off clears queued diagnostic events and stops new events from being uploaded. Diagnostics are used for app analytics, security, and reliability, not advertising or cross-app tracking.

“Anonymous” means that the diagnostic event payload excludes direct rider identifiers and sensitive ticket or payment contents. The upload is authenticated with the same random, persistent installation token that protects receipt recovery. ViaNJ's support database stores a temporary app-launch session ID and does not store that installation token with the event. For aggregate product analytics, ViaNJ's server uses a separate secret to create a one-way pseudonymous installation identifier before sending the same validated, categorical events to PostHog. Person profiles, session replay, and automatic screen or interaction capture are not enabled. These systems do not receive the purchase email, delivery email, name, phone number, confirmation number, ticket ID, barcode, card data, or page contents.

Exact support-diagnostic events in ViaNJ's database are retained for up to 30 days. Pseudonymous product-analytics events in PostHog may be retained for up to seven years so ViaNJ can measure long-term feature adoption and reliability. Disabling diagnostics clears events still queued on your device and prevents new uploads; it does not immediately delete events already accepted by either service. You may contact ViaNJ to request deletion of information controlled by ViaNJ.

Service providers and other recipients

Information may be processed by:

  • Apple: App Store subscriptions, purchase status, Apple Wallet, notifications, and platform services;
  • NJ Transit: schedules, alerts, account authentication, fare quotes, ticket purchases, tickets, and receipt recovery;
  • TrustCommerce: NJ Transit fare payment processing;
  • Cloudflare: hosting and security for ViaNJ's receipt-routing, recovery, and diagnostic services;
  • PostHog: pseudonymous product analytics using only ViaNJ's validated categorical diagnostic events; PostHog is configured to discard IP addresses and does not receive session replays from the app;
  • Supabase: app data services used for train and prediction information; and
  • Vercel: website hosting and privacy-focused Web Analytics for vianj.app.

ViaNJ may also disclose information when required by law, to protect users or the service, or in connection with a merger, acquisition, financing, or sale of the business, subject to applicable law.

Website analytics

vianj.app uses Vercel Web Analytics to measure page views and understand aggregate website usage. Vercel Web Analytics is designed not to use cookies and uses a daily rotating hash rather than a persistent cross-site identifier. It may process page path, referrer, coarse location, browser, device type, operating system, and event time for aggregate reporting.

Retention and security

Exact support-diagnostic events expire after 30 days; pseudonymous product-analytics events processed by PostHog may be retained for up to seven years. Receipt recovery records remain available until the matching ticket is successfully imported and acknowledged. ViaNJ retains the encrypted delivery address and private purchase route while needed to forward and recover receipts for that installation, and retains other server-side information only as reasonably necessary for service delivery, security, support, and legal compliance. Information stored locally remains until you remove it in the app, sign out, clear the applicable setting, or delete the app, subject to iOS, Keychain, Wallet, and iCloud behavior.

ViaNJ uses transport encryption, device Keychain storage, scoped installation credentials, and limited diagnostic fields. No security measure is perfect, but ViaNJ works to limit collection and protect the information it handles.

Your choices and rights

  • Disable anonymous diagnostics in ViaNJ Settings.
  • Manage or cancel ViaNJ Pro in your Apple subscription settings.
  • Remove saved ticket-payment information and linked companion access in ViaNJ Settings.
  • Sign out to clear the local NJ Transit session, or delete the app to remove app data subject to iOS and Keychain behavior.
  • Contact us to request access to, correction of, or deletion of information controlled by ViaNJ. We may need to retain limited information when legally required or necessary for security.

NJ Transit, Apple, TrustCommerce, and other providers control information in their own systems. Requests concerning those systems should be directed to the applicable provider.

Children

ViaNJ is not directed to children under 13, and ViaNJ does not knowingly collect personal information from children under 13. If you believe a child has provided information to ViaNJ, please contact us so we can review and address it.

Changes to this policy

This policy may be updated as ViaNJ changes. The revised policy will be posted here with a new “Last updated” date. Material changes will be communicated when required by law.

Contact

For privacy questions or requests, email hi@njt.app.