Privacy Policy & Carrier Terms of Service
MetroSMS™ operates under a strict Zero-PII privacy guarantee. We never sell, broker, or share commuter telephone numbers, and all mobility analytics enforce mathematical k-anonymity.
Strict Anti-Brokerage & Commercial Prohibition Guarantee
MetroSMS LLC (“MetroSMS”, “we”, “our”, or “us”) operates municipal and campus transit telephony gateways. We adhere to an absolute prohibition regarding commuter personal data:
- We NEVER sell, rent, lease, trade, or transfer telephone numbers, opt-in records, or rider interaction histories to commercial advertisers, data brokers, lead aggregators, or marketing affiliates.
- Zero Cross-Context Behavioral Advertising: We do not track riders across external websites, physical GPS location beacons, or commercial advertising networks.
- Carrier Compliance Lock: In strict adherence with CTIA Messaging Principles and The Campaign Registry (TCR) 10DLC regulations, subscriber consent and phone numbers obtained via SMS inquiry lines remain strictly confined to the transit alert service requested.
Cryptographic Salted Pseudonymization (Zero Plaintext PII on Disk)
To protect commuter privacy while maintaining platform security and rate-limiting against automated abuse:
- Salted HMAC-SHA256 Pseudonymization: Upon receipt of an inbound inquiry, the telephone number is cryptographically pseudonymized using a server-side cryptographic salt. Only a truncated 16-character cryptographic token (
rider_id) is persisted for analytics counting. - Masked Display Storage: Activity logs stored on disk display numbers exclusively in masked format (e.g.
+1 (505) ***-8007). - Operational Separation: Raw telephone numbers are held only in short-lived memory during transit schedule retrieval (20-minute TTL) or inside required regulatory suppression lists (such as the TCPA opt-out registry to permanently prevent messages to unsubscribed riders).
First-Party Contextual Sponsorship Model
MetroSMS is funded through public agency partnerships and non-intrusive local business sponsorships displayed within live transit responses (e.g. “[Sponsored by Sandia Area FCU]”).
- Purely Contextual: Sponsorship taglines are selected based solely on the requested transit line or geographic corridor (e.g. Central Avenue Route 66 vs. UNM South Lot).
- Zero Advertiser Access to Riders: Advertisers receive only aggregate proof-of-performance metrics (e.g. total monthly corridor impressions and click-through counts). They never receive phone numbers, rider identities, or personal commute patterns.
Aggregated Transit Demand Telemetry & k-Anonymity
To help municipalities and transit authorities optimize public bus service, eliminate transit deserts, and evaluate language equity under Title VI of the Civil Rights Act, MetroSMS generates aggregated mobility telemetry.
Mathematical k-Anonymity Rule (k ≥ 5)
No single user or sparse inquiry cluster is ever exposed. All demand telemetry is grouped into high-level corridors, transit routes, or 1-hour temporal bins. Any data bucket containing fewer than k inquiries is automatically suppressed or clustered into “Other” to eliminate re-identification risk.
TCPA / CTIA Carrier Terms & Conditions
By sending an SMS message to any MetroSMS telephony number (including 505-448-8007, 505-448-8030, or 505-448-8702), you agree to these program terms:
University Campus & Student Protections (FERPA)
For university campus shuttle deployments (such as the University of New Mexico PATS Lobo Shuttle line at 505-448-8702):
- Zero Student Accounts: Students never register, log in, or provide NetIDs, student ID numbers, or educational credentials.
- FERPA Compliance: Because MetroSMS collects zero educational records and retains zero student PII, the platform introduces zero exposure under the Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g).
Data Retention & Scheduled Purge Policy
MetroSMS adheres to a strict data minimization schedule:
- 90-Day Granular Log Purge: Detailed transactional activity entries are automatically purged after 90 days. High-level monthly counts are archived for trend analysis, with all granular message metadata permanently expunged.
- Transient Session Purge: In-memory conversation state and recent stop context are cleared after 20 minutes of inactivity.
- Right to Deletion: Any commuter may request the immediate purging of all historical records matching their pseudonymized hash by emailing privacy@metrosms.city.
Legal Entity & Privacy Officer Contact
If you have questions, inquiries, or regulatory compliance verification requests regarding this policy:
Entity: MetroSMS LLC (New Mexico Registered Entity)
Compliance Lead: Data Privacy Officer & Regulatory Compliance
Email: privacy@metrosms.city | support@metrosms.city
Phone: (505) 555-0100
Address: Albuquerque, New Mexico 87106