Privacy

Last updated 25 August 2026

ProveTrip is software for non-emergency medical transport companies. It records what happened on each trip and checks what the broker paid against what was contracted. This page describes what the software collects and why.

Two kinds of information, treated differently

Records about the people being transported — names, addresses, appointment times, and the trips themselves — belong to the transport company, not to ProveTrip. We hold them on that company’s behalf as a business associate under HIPAA, and what we may do with them is set by the business associate agreement each company accepts before its account opens, not by this page. We do not sell that information, use it for advertising, or use it to train models.

Information about the people using the software — drivers, dispatchers, owners — is described below. That is what a driver installing the app is agreeing to.

What the driver app collects

  • Location, at specific moments only. A position is taken when a driver marks an arrival, a pickup, a drop-off, or a no-show. That fix is the evidence the trip happened where and when it is claimed to have happened, which is the point of the product. The app does not track location in the background and does not follow a vehicle between stops — it holds no background location permission at all, so it cannot.
  • Photographs a driver chooses to take, to document a no-show or an incident. The camera is opened only when a driver taps to use it.
  • A signature captured on the screen where a trip requires one.
  • Sign-in details — the email address the employer registered, and a label for the handset (“Emy’s iPhone”) so an owner revoking a lost phone can tell one device from another.
  • A push notification token, if notifications are allowed, so schedule changes reach the driver.

Trip events are queued on the device when there is no signal and sent when there is. Nothing else is collected: no contacts, no browsing, no advertising identifier, no microphone.

What the web application records

Every time a member’s record is opened, exported, or changed, the software writes an entry naming who did it, when, and from what address. That log exists because HIPAA requires it and because an owner asking “who looked at this?” deserves an answer. It cannot be edited or deleted by the software that writes it.

Sign-in attempts are recorded the same way, including failures, because repeated failures against one account is what a break-in looks like from the inside.

Who else sees it

ProveTrip runs on Amazon Web Services in the United States, under a business associate agreement with AWS. AWS provides the databases, file storage, sign-in, and email delivery the product is built on.

Push notifications are delivered through Expo and the platform notification services operated by Apple and Google. A notification carries a driver’s schedule change, never a member’s name or address.

Nothing is sold. Nothing is shared with advertisers or data brokers. Information is disclosed to anyone else only where the law requires it, or where the transport company that owns the records instructs us to.

How long it is kept

Trip records and their evidence are kept for as long as the transport company holds an account, and afterwards for the period its business associate agreement specifies — claims are disputed and audited long after a trip is over, and a record deleted early is a payment that can no longer be defended.

A driver who leaves has their access switched off. Their name stays on the trips they drove, because removing it would falsify the record of who provided the service.

Your choices

Location and camera permissions can be refused or withdrawn at any time in the phone’s settings. Refusing them does not lock a driver out of the app; it means the trips they complete carry less evidence, which their employer may ask about.

A driver or dispatcher who wants to see or correct what is held about them should ask their employer, who controls the account. Where a request concerns a member rather than an employee, it goes to the transport company, which is the covered entity and the only party that can answer it.

Asking for your data to be deleted

Anyone who uses this software — a driver, a dispatcher, an owner — can ask for the information held about them to be deleted. Ask your employer, who controls the account and can do it directly, or write to vince@lionlensos.com and we will action it with them. No account can be created here in the first place, which is why there is no button for this: your employer made the account, and your employer can remove it.

Two things survive that request, and it is fairer to say so than to discover it later. A driver’s name stays on the trips they drove, because removing it would falsify the record of who provided the service somebody was billed for. And the audit log keeps its entries, because a record of who opened a member’s file is not something the software that wrote it is allowed to edit — that is the property that makes it worth having.

Where the request concerns a member rather than an employee, it goes to the transport company that arranged the ride. They hold those records; we hold them on that company’s behalf and cannot delete them on our own initiative.

Children

The software is used by transport company employees at work and is not directed at children. Members being transported may be of any age; their records are held for the transport company under the agreement described above.

Contact

Questions about this page, or about a specific record, can go to vince@lionlensos.com. A member of the public asking about their own transport records will be directed to the transport company that arranged the ride, because that company holds them and we do not decide what happens to them.

Back to ProveTrip