Bridge Privacy Policy

Last updated: August 17, 2026 (first production draft — see the founder/legal review note at the bottom before this is treated as final).

Bridge by Shepherd ("Bridge," "we," "us") is a church/ministry transportation coordination app owned and operated by REMNANT Technologies LLC. Bridge is used by member churches and ministries ("organizations") to coordinate rides between riders who need transportation and volunteer/staff drivers within that organization. This policy explains what information Bridge collects, why, and how it's handled. It describes what the app actually does today, based on its current technical implementation — not aspirational or marketing language.

1. Information you provide

When you create a Bridge account (through your organization), we collect:

  • Your name, email address, and phone number.
  • If you request rides: pickup address, contact name/phone/email for that pickup (which may be your own, or a different contact for that specific ride), and, optionally, saved locations you choose to store for reuse.
  • If you drive: vehicle information (make, model, color, seating capacity) and, if your organization enables Driver Readiness tracking, the expiration dates of your license, insurance, and vehicle registration. We store only the dates — we do not collect or store license numbers, policy numbers, or plate numbers.

2. Information created by using Bridge

  • Ride requests and their status history (requested, assigned, in progress, completed, cancelled).
  • Which organization(s) you belong to and your role(s) within them.
  • A push-notification delivery token for your device, if you enable notifications. Each notification we send (for example, a ride-assignment or status update) includes a short title, a body message, and identifiers for the relevant ride so the app can route you to it when tapped.

3. What we do not collect

Bridge does not collect payment or financial information, background/precise device location (Bridge never requests your device's location permission — map links open your phone's own maps app instead), photos, camera access, your contacts, government ID numbers, or the underlying numbers behind your license/insurance/registration (only their expiration dates, where your organization has enabled that feature).

4. How we use information

  • To operate the core function of the app: connecting riders who need a ride with an available, approved driver in the same organization.
  • To send notifications about ride status (for example, that a driver has been assigned) when you've enabled notifications.
  • To let your organization's transportation administrators review driver eligibility (approval status, and, where enabled, whether required documents are current).
  • To keep a record of completed rides as part of the organization's own ministry operations.

We do not use your information for advertising, and we do not sell your information.

5. Who can see your information

  • Staff/admins of your own organization who hold the relevant permission can see rider and driver information needed to coordinate transportation. Bridge is multi-tenant: staff at a different organization cannot see your organization's data.
  • An assigned driver can see a rider's pickup address and contact information for the ride they're driving. A rider can see their assigned driver's name and vehicle information.
  • We use one third-party service provider, PostHog, for product analytics — see section 6 below for exactly what it receives. We do not sell your information, and we do not share it with advertisers, data brokers, or any other third-party company. Push notifications are delivered through Expo's push notification service and, downstream of that, Apple's and Google's own push infrastructure — this is standard for any app built on the Expo/React Native platform, not a Bridge-specific data-sharing arrangement. The notification's title, body text, and ride identifier pass through these services as part of delivering it to your device — they do not pass through any other third party, and are used only to deliver that one notification.

6. Analytics

We use PostHog, a product-analytics service, to understand how Bridge is used so we can improve it — for example, how many drivers open their route, or where someone gets stuck requesting a ride. This section describes exactly what it does and does not receive, because a vague answer here is not good enough for a congregation's data.

What we send: a fixed, reviewed list of events — such as "a ride was requested," "a route was viewed," "availability was set" — along with counts and internal identifiers, plus your app version and device model. If you are signed in, these are associated with your account's internal ID number.

What we never send: names, pickup or drop-off addresses, phone numbers, email addresses, map coordinates, or anything you typed. Automatic capture is switched off, so nothing is collected except the specific events listed above. Session recording — which would film your screen — is switched off entirely. We also tell PostHog to discard IP addresses, so your approximate location is not derived or stored.

Not advertising. Bridge contains no advertising and no ad networks. Nothing we collect is used to track you across other companies' apps or websites, and nothing is sold or given to a data broker.

7. Retention

We keep account and ride information for as long as your account is active. Ride history is a shared record between the rider and driver involved (and the organization coordinating the ride), so it isn't deleted unilaterally just because one participant requests it — see the Account Deletion page for how this is actually handled. The exact length of time we retain identifying personal information after an account deletion request is still being finalized — see that page for details.

8. Account deletion

You can request that your account be deactivated, and separately request that your personal information be erased. See our Account Deletion page for exactly what each step does and doesn't remove.

9. Children's information

Bridge is intended for use by adult riders and drivers coordinating transportation through their organization. We are not aware of Bridge being used to knowingly collect information directly from children. [FOUNDER/LEGAL REVIEW: confirm whether any organization-side use involves minors — e.g. a parent/guardian requesting a ride on a minor's behalf — and whether additional language is required here.]

10. Your rights

You can review and update your profile information within the app. You can request account deletion as described above. If you have questions about your information, contact us at hello@buildwithremnant.com.

11. Security

Bridge data is stored using row-level access controls that restrict each organization's data to that organization's own authorized staff. Access to administrative functions (like approving a driver) requires a specific permission, not just organization membership.

12. Changes to this policy

We'll update this page if how Bridge handles information changes, and update the date at the top.

13. Contact

REMNANT Technologies LLC
[BUSINESS ADDRESS]
hello@buildwithremnant.com

FOUNDER/LEGAL REVIEW REQUIRED before this is treated as final or submitted to Apple/Google: fill in the bracketed legal entity/address/contact fields, confirm section 8, and confirm the retention-window language once that decision is made (see docs/bm5-account-deletion-recommendation.md in the engineering repo).