Skip to main content
MetroSMS™
Zero-PII Data Architecture • Updated September 2026

Privacy Policy & Carrier Terms of Service

MetroSMS™ operates under a strict Zero-PII privacy guarantee. We never sell, broker, or share commuter telephone numbers, and all mobility analytics enforce mathematical k-anonymity.

01. Zero Selling No list brokers or sharing 02. Cryptography Salted HMAC-SHA256 03. Contextual Ads No tracking profiles 04. TCPA / STOP Carrier opt-out rules
1

Strict Anti-Brokerage & Commercial Prohibition Guarantee

MetroSMS LLC (“MetroSMS”, “we”, “our”, or “us”) operates municipal and campus transit telephony gateways. We adhere to an absolute prohibition regarding commuter personal data:

  • We NEVER sell, rent, lease, trade, or transfer telephone numbers, opt-in records, or rider interaction histories to commercial advertisers, data brokers, lead aggregators, or marketing affiliates.
  • Zero Cross-Context Behavioral Advertising: We do not track riders across external websites, physical GPS location beacons, or commercial advertising networks.
  • Carrier Compliance Lock: In strict adherence with CTIA Messaging Principles and The Campaign Registry (TCR) 10DLC regulations, subscriber consent and phone numbers obtained via SMS inquiry lines remain strictly confined to the transit alert service requested.
Legally Binding Guarantee: Under no circumstance will a rider's telephone number be provided to any third party for marketing purposes.
2

Cryptographic Salted Pseudonymization (Zero Plaintext PII on Disk)

To protect commuter privacy while maintaining platform security and rate-limiting against automated abuse:

  • Salted HMAC-SHA256 Pseudonymization: Upon receipt of an inbound inquiry, the telephone number is cryptographically pseudonymized using a server-side cryptographic salt. Only a truncated 16-character cryptographic token (rider_id) is persisted for analytics counting.
  • Masked Display Storage: Activity logs stored on disk display numbers exclusively in masked format (e.g. +1 (505) ***-8007).
  • Operational Separation: Raw telephone numbers are held only in short-lived memory during transit schedule retrieval (20-minute TTL) or inside required regulatory suppression lists (such as the TCPA opt-out registry to permanently prevent messages to unsubscribed riders).
3

First-Party Contextual Sponsorship Model

MetroSMS is funded through public agency partnerships and non-intrusive local business sponsorships displayed within live transit responses (e.g. “[Sponsored by Sandia Area FCU]”).

  • Purely Contextual: Sponsorship taglines are selected based solely on the requested transit line or geographic corridor (e.g. Central Avenue Route 66 vs. UNM South Lot).
  • Zero Advertiser Access to Riders: Advertisers receive only aggregate proof-of-performance metrics (e.g. total monthly corridor impressions and click-through counts). They never receive phone numbers, rider identities, or personal commute patterns.
4

Aggregated Transit Demand Telemetry & k-Anonymity

To help municipalities and transit authorities optimize public bus service, eliminate transit deserts, and evaluate language equity under Title VI of the Civil Rights Act, MetroSMS generates aggregated mobility telemetry.

Mathematical k-Anonymity Rule (k ≥ 5)

No single user or sparse inquiry cluster is ever exposed. All demand telemetry is grouped into high-level corridors, transit routes, or 1-hour temporal bins. Any data bucket containing fewer than k inquiries is automatically suppressed or clustered into “Other” to eliminate re-identification risk.

5

TCPA / CTIA Carrier Terms & Conditions

By sending an SMS message to any MetroSMS telephony number (including 505-448-8007, 505-448-8030, or 505-448-8702), you agree to these program terms:

Opt-Out Instructions: Text STOP, ALTO, CANCEL, or UNSUBSCRIBE at any time to permanently cancel messages. You will receive one final confirmation message. To resubscribe, text START or INICIO.
Customer Support: Text HELP or AYUDA for live instructions, or contact us at support@metrosms.city or phone (505) 555-0100.
Rates & Frequency: Standard message and data rates may apply according to your cellular provider plan. Message frequency varies based on commuter inquiries and proactive departure reminder requests.
Carrier Disclaimer: Mobile carriers (including AT&T, Verizon, T-Mobile, and regional carriers) are not liable for delayed or undelivered messages.
6

University Campus & Student Protections (FERPA)

For university campus shuttle deployments (such as the University of New Mexico PATS Lobo Shuttle line at 505-448-8702):

  • Zero Student Accounts: Students never register, log in, or provide NetIDs, student ID numbers, or educational credentials.
  • FERPA Compliance: Because MetroSMS collects zero educational records and retains zero student PII, the platform introduces zero exposure under the Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g).
7

Data Retention & Scheduled Purge Policy

MetroSMS adheres to a strict data minimization schedule:

  • 90-Day Granular Log Purge: Detailed transactional activity entries are automatically purged after 90 days. High-level monthly counts are archived for trend analysis, with all granular message metadata permanently expunged.
  • Transient Session Purge: In-memory conversation state and recent stop context are cleared after 20 minutes of inactivity.
  • Right to Deletion: Any commuter may request the immediate purging of all historical records matching their pseudonymized hash by emailing privacy@metrosms.city.
8

Legal Entity & Privacy Officer Contact

If you have questions, inquiries, or regulatory compliance verification requests regarding this policy:

Entity: MetroSMS LLC (New Mexico Registered Entity)

Compliance Lead: Data Privacy Officer & Regulatory Compliance

Email: privacy@metrosms.city | support@metrosms.city

Phone: (505) 555-0100

Address: Albuquerque, New Mexico 87106