Ebni Privacy Policy
Important location disclosure: Ebni collects and transmits precise location data from an authorized Bus Supervisor's device to enable live school-bus tracking, estimated arrival information, and a safety trail for authorized school staff and guardians linked to children on the trip, even when the app is closed or not in use. Location is not used for advertising.
1. About this policy
This Privacy Policy explains how Perla Tech ("Perla Tech", "we", "us", or "our") handles personal and sensitive information through the Ebni mobile application, school dashboards, tenant portals, and the public website at ebni-app.com (together, the "Service"). Ebni is a school operations and family-communication service supplied to subscribing schools.
For school records, the subscribing school normally decides why and how information is used, and Perla Tech processes that information to provide the contracted Service. Perla Tech is responsible for information it collects for its own website inquiries, account security, service administration, and legal compliance. This policy applies alongside the school's notices, the service agreement, and applicable law.
2. Information we process
Account, identity, and relationship information
- Name, username, email address, telephone number, preferred language, role, school, class or section assignments, and links between guardians and children.
- Authentication, session, device-registration, notification-token, access-control, and security records. Passwords are handled through protected authentication controls and are not intentionally stored or logged in plain text.
Student, learning, and school-operation information
- Enrollment and admissions records; grade, class, attendance, arrival and departure; daily reports; meals; homework and submissions; evaluations; learning portfolios; events; galleries; and required acknowledgements.
- Files and media supplied by authorized users, including photographs, scanned pages, PDFs, Word documents, evidence, and school-approved learning resources.
Safety, care, and sensitive school information
- Authorized-pickup identities, photographs, relationships, validity, QR or PIN verification status, and checkout audit records.
- Health, medication, allergy, consent, incident, safeguarding, hygiene, and care information when the school enables and lawfully uses those features.
- Transportation routes, stops, rosters, boarding and offboarding events, trip changes, and GPS samples described in Section 3.
Communications, support, and financial administration
- In-app messages, announcements, notification preferences, delivery/read status, support cases, notes, attachments, and responses.
- Tuition plans, charges, installments, due dates, payment status, receipts, and transaction references. If a separate payment provider is enabled, its own notice and terms also apply; Ebni does not require users to place payment-card details in ordinary school records.
Device, diagnostic, and website information
- App version, operating system, device or installation identifiers, IP address, timestamps, language, tenant, network and synchronization state, security events, and limited crash and performance diagnostics.
- Camera input when a user scans an authorized QR code, captures homework or admission evidence, or chooses to upload media. Selected files and photographs are processed only when the user initiates those actions.
- Biometric unlocking is performed by the device operating system. Ebni does not receive or store the user's biometric template.
- School demo inquiries and website forms, including the supplied school/contact details, requested services, consent, referral data, and essential security/session information.
3. Precise and background location
Ebni collects location data to enable live school-bus tracking and its safety trail even when the app is closed or not in use.
- Who and when: Location collection is intended for an authorized Bus Supervisor assigned to an active trip. It begins only after the supervisor starts tracking in Ebni, sees the prominent disclosure, and grants the Android permission. Other users do not need to start bus-location sharing to use their permitted non-transport features.
- What: The Service may collect precise or approximate coordinates, timestamp, accuracy, speed, trip identifier, and a protected device identifier. A boarding or offboarding scan may include the current location when available.
- Background operation: During active tracking, samples may be collected periodically, including while Ebni is minimized, the screen is locked, or the app is otherwise not in use. Android displays a persistent foreground-service notification while this operation is active.
- Why: We use the samples to show the bus's current position and historical trail, calculate route progress and estimated arrival, support safe boarding/offboarding and offline synchronization, investigate transport incidents, and provide an operational safety audit.
- Who can see it: Access is limited to authorized personnel of the relevant school and guardians linked to a child assigned to that trip. Perla Tech and contracted infrastructure providers process it only to operate, secure, and support the Service.
- Control and retention: The supervisor can decline the permission or stop tracking. Tracking ends when it is turned off or the trip workflow is closed. Detailed GPS samples are automatically deleted after 30 days. Revoking Android location permission prevents further collection.
We do not sell location information, use it for advertising, build advertising profiles, or expose precise coordinates in push-notification payloads.
4. Why we use information
- Provide authentication, role-based access, school workflows, family communication, educational functions, safety features, transport tracking, reminders, and support.
- Keep records synchronized, deliver requested notifications, provide offline recovery, and maintain service continuity.
- Protect accounts and children, prevent fraud or unauthorized access, investigate incidents, maintain audit records, and comply with legal obligations.
- Diagnose faults and improve reliability. Release builds use Firebase Crashlytics for limited crash information such as error type, stack trace, random client error ID, and device/app diagnostics. Our application is designed not to attach names, messages, credentials, request content, tokens, coordinates, or student identifiers to crash reports.
- Respond to inquiries, manage contracts, provide training, and communicate material service or policy changes.
5. Legal grounds
Depending on the applicable jurisdiction and context, processing is based on the school's service agreement and instructions, performance of a contract, legitimate interests in operating and securing the Service, consent or guardian authorization where required, protection of vital or safety interests, and compliance with legal obligations. Schools are responsible for establishing the appropriate basis for the student and staff records they instruct us to process.
6. When information is disclosed
We disclose information only as needed for the purposes described above:
- The subscribing school and authorized users: administrators, teachers, transport or health personnel, and linked guardians receive only the records permitted by their role, child, section, trip, and time-based access.
- Service providers: contracted hosting, storage, backup, content delivery, security, email/support, and media providers; Google Firebase for push notifications and limited crash diagnostics; and MapTiler/OpenStreetMap services for map presentation. Map requests may include IP address, technical request information, and the area of the map being displayed. We do not intentionally send student names or school-record content to the map provider.
- Payment or integration providers: only when enabled by the school and necessary to perform the requested integration.
- Legal and safety disclosures: when required by law, valid legal process, protection of rights or safety, investigation of abuse, or prevention of serious harm.
- Business reorganization: under appropriate confidentiality and data-protection safeguards if the Service or relevant business is reorganized, financed, acquired, or transferred.
We do not sell or rent personal information. We do not use student data, health data, private messages, files, or location for behavioral advertising or data-broker activity.
7. Permissions and user choices
- Location: used for the active transport functions described in Section 3. Permission may be declined or revoked in Android settings, but live trip sharing will not work.
- Camera and files/photos: used for QR verification, document scanning, evidence, homework, gallery, and authorized uploads. Users choose when to capture or select content.
- Notifications: used for school communications, safety alerts, messages, reminders, and workflow updates. Device permission and in-app preferences can be changed, although critical in-app records remain visible.
- Biometrics: optional local device authentication. Biometric data remains under the operating system's control.
8. Retention and deletion
We keep information only for the period needed to provide the Service, meet the school's documented retention requirements, protect users, resolve disputes, maintain required educational or safety records, and comply with law. Detailed GPS samples are deleted after 30 days. Expired authentication/session records are cleaned periodically. Crash information is retained according to the configured Firebase retention controls. Backups expire through protected rotation and are not used as an active source after deletion.
School accounts are created and managed by the subscribing school; Ebni does not offer unrestricted public self-registration. An authorized user may request access, correction, export, account closure, or deletion through the school or at support@ebni-app.com. We verify identity and authority before acting. When an account is deleted, associated personal data is deleted or de-identified unless the school or applicable law requires specified educational, financial, security, safeguarding, or audit records to be retained. We will explain any required retention. Uninstalling the app does not itself delete server records.
9. Security
Ebni uses encrypted network transport, protected sessions and credentials, tenant-isolated school databases, role and relationship access controls, audit records, restricted media access, backups, monitoring, and session revocation. Access is limited to personnel and providers who need it for their duties and are subject to confidentiality obligations. No system is completely secure; users should protect their credentials and promptly report suspected misuse.
10. Children's and student information
Ebni is designed primarily for schools, staff, transport teams, and guardians, not for unsupervised consumer use by children. Student information is processed to provide educational, care, administrative, and safety services on the school's instructions and with guardian authorization where required. We do not use student information for advertising or profiling unrelated to education and safety.
11. International processing
The Service and its contracted providers may process information in countries where infrastructure or support teams operate. Where required, Perla Tech and the school apply contractual, organizational, and technical safeguards appropriate to the information and applicable law.
12. Updates to this policy
We may update this policy when the Service, providers, legal requirements, or processing practices change. The current version and effective date appear on this page. We will provide additional notice through the Service or the school when a material change requires it.
13. Contact and privacy requests
Perla Tech — Ebni Privacy
Damascus, Syrian Arab Republic
Email: support@ebni-app.com
Website: https://ebni-app.com
Please identify your school and account relationship without sending passwords, pickup PINs, health documents, or other sensitive attachments in the first email.