1. In General
3. The Connection between Information We Ask For and Our Services
We only ask for, and compile, personal information that is needed to provide you with the service or product that you seek from us. For Electronic Fare Media that provide a high level of functionality, we generally require a greater amount of information, and a broader scope of use for this information. In addition, participation in a Reduced Fare Program requires that you provide us with contact information and other personal information to demonstrate eligibility for the program, and that you allow us broader abilities to use that information in order to run the Reduced Fare Program.
If you are uncomfortable with providing the requested level of information, or with use of the this information for the particular purposes identified, you may simply decline to order that level of service or participate in that particular program. We offer Electronic Fare Media that does not require you to provide us with any personal information, although this Media provides you with no special services on our system, and does not allow you to participate in Reduced Fare Programs.
Please read on to learn more about this relationship between personalized services and your personal information, and about you ability to tailor PATCO services you seek with your wishes regarding the use of your personal information.
4. The Types of Information You May Provide
Information you may provide while visiting our Site or while participating in an Electronic Fare Media Program falls into two broad categories: personally identifiable information, and aggregate information. We use the term "Personally Identifiable
5. Your Choices concerning Personally Identifiable Information
We allow you to decide whether you wish to provide us with personally Identifiable Information. You have the option to buy Electronic Fare Media and elect not to "link" your personal information in our system with the Electronic Fare Media you have purchased. In addition, we have structured our Website so that you may visit us, and review a range of information about transportation services, schedules and updates, without revealing your identity or providing any Personally Identifiable Information. Please note, however, that in order to use certain services offered by PATCO, such as the Autoload and Balance Protection feature for Electronic Fare Media or the Add Value Online service, you must register and provide us with Personally Identifiable Information. For example, if you do not wish to provide us with the Personally Identifiable Information needed to offer these services, you will not be able to obtain the above listed services, and will be unable to use account based features such as recurring autoloads, electronic payments, and loss protection.
We collect Personally Identifiable Information through the following means, and use this information for the following purposes, depending on the level of service and/or program(s) you have selected:
5.1 Order Forms: We collect Personally Identifiable Information in connection with the purchase of transit services online from this Site or purchased by credit card through other means. For credit card purchases, a customer will be asked to provide contact information (such as name, e-mail address, and shipping address) and financial information (such as credit card number and expiration date). We use a reputable company to verify your credit card information before billing your account. This information is used for billing purposes and to fill orders. If we have trouble processing an order, the information may be used to contact you. We will also share your shipping information with the delivery service we use (UPS, U.S Postal Service, or other delivery method selected by PATCO).
5.2 Electronic Fare Media; Managed Accounts: You need not provide any Personally Identifiable Information in order to purchase Electronic Fare Media. If you choose to make a purchase with a credit or debit card, however, we will ask you to provide the Personally Identifiable Information needed for us to process your order, and we will use this information only for billing purposes and to fill your order. In addition, if you choose to register your Freedom Card and obtain a Managed Account, with autoload functionality, electronic payment features, loss protection features, and other available features, you will be asked to provide contact information, and possibly financial information, depending on the level of service you select for your Managed Account. We will use the information you provide to register and service your Managed Account.
5.3 Reduced Fare Program: Senior citizens, persons with disabilities participating in the Reduced Fare Program will be asked to provide Personally Identifiable Information in connection with the purchase and registration of Electronic Fare Media, and our determination of eligibility for the Program. In addition we will electronically store passport size photographs in order to personalize Electronic Fare Media issued under the Reduced Fare Program. We will use this Information to provide the Reduced Fare Program, and ensure compliance with eligibility requirements for the Program.
5.4 Location information: Each time that a patron uses his or her Electronic Fare Media, the PATCO Fare Collection system collects information about the location of use. Except in the case of a Managed Account, this "location of use" information is not "linked" by our system to a particular user. This location information in the AFC system (except in the case of a Managed Account), therefore, does not personally identify you, and constitutes Aggregate Information governed by Section 10.1, below. In the case of a Managed Account, location information is needed by the system to provide autoloads, and other services a user has selected for his or her Managed Account. Therefore, for Managed Accounts, location information is by necessity linked to a particular user and a particular smart card. We use this linked location information only for purposes of providing to you the Managed Account services you have requested from us.
5.5 Email address and other communications: If you send us an e-mail or letter with questions or comments, or if you provide your contact information when ordering PATCO goods or services, PATCO may use your e-mail address and other personal information included in your correspondence in order to respond to you. If you provide us with your e-mail address in order to receive notifications, such as information concerning your Electronic Fare Media account, PATCO will only use your e-mail address to send you the type of information for which you provided your e-mail address, unless you "opt in" and affirmatively agree to receive additional e-mail notifications from time to time.
5.6 Surveys: From time to time, PATCO may conduct online and other surveys that customers may complete on a voluntary basis. Information collected through the surveys will be used for the purpose of marketing or planning PATCO services only, unless you expressly agree otherwise.
6. No Unrelated Third Party Is Given Access To Your Personally Identifiable Information
7. How to Obtain Access to Information You have Provided, and How to Remove Your Information from Our Database
To allow you appropriate control over your Personally Identifiable Information, you can request access to review, change or update personally Identifiable Information that you have previously submitted. In all cases, we will take reasonable steps to verify your identity before granting access to your Personally Identifiable Information. Except as provided in Section 12, only a Data Subject is entitled to access Personally Identifiable Information concerning that Data Subject. We will not accept or respond to requests for Aggregate Information or ridership information (if available).
If you request, we will remove your name and other Personally Identifiable Information from our databases. Please understand, however, that it may be impossible to remove this information completely, due to system backups. In addition, please understand that, if you request deletion of your information, you will be unable to utilize associated features of the Website and any services offered through our electronic Fare Media Programs, such as Managed Account features. Please contact us if you wish to remove your name and other Personally Identifiable Information.
8. Opt-In Right Concerning Certain Information
You have the ability to decline to receive bulletins, updates, other communications from us, if you wish. We will contact you to request permission before sending you such information. Please understand that you may not be allowed to decline to receive certain formal notices concerning operation of this Site, notices concerning operations of the Electronic Fare Media Programs, and legal and other related notices concerning your relationship to the Site and your participation in Electronic Fare Media programs.
9. Information That Does Not Identify You: Aggregate Information
General information that describes our customers' activities, but that does not identify any particular customer, is Aggregate Information. For example, if site visitors spend the majority of their time browsing information about "train schedules", this suggests that train schedules are important to our customers generally.
This information does not identify a particular user, but that does provide potentially useful data concerning our customers' preferences and the efficacy and interest of our Site's and Electronic Media Program's features. PATCO uses Aggregate Information to analyze the effectiveness of our Site and our Electronic Fare Media programs, and to improve our services. From time to time, we may undertake or commission statistical and other summary analysis of the general behavior and characteristics of customers participating in any of the Electronic Fare Media Programs and the characteristics of visitors at our site and may share Aggregate Information with third parties. Rest assured, though, that Aggregate Information provided to third parties will not allow anyone to identify you, or determine anything personal about you. We collect Aggregate Information through the following means:
9.1 Ridership Information: Our AFC system collects Aggregate Information through the use of Electronic Fare Media. "Ridership Information" such as the travel patterns of our customers, the number of people using certain PATCO locations, and peak travel times, will be collected to analyze and improve the operations of Electronic Fare Media Programs and applicable PATCO services. Ridership information will not include your name or other Personally Identifiable Information and will be protected as detailed in Section 11 below.
9.3 Fraud Detection: To allow us to detect fraud and system errors, we may compare Ridership information to Electronic Fare Media information. If for example, the system shows that anonymous smart card no. 1234 was used to enter the Ferry Ave. station, and anonymous smart card no. 1234 was also used simultaneously to enter the Woodcrest Ave station, we can assume either (i) that there is a system malfunction, or (ii) that fraudulent activity has taken place. If in the course of inspecting for fraudulent activity or system errors, Ridership Information is combined or linked with any Personally Identifiable Information, the combined information will be treated as Personally Identifiable Information and will be protected as detailed in Section 11, below.
9.4 IP Addresses: An Internet Protocol (IP) address is associated with your computer's connections to the Internet. We use your computer's IP address to maintain contact with you as you navigate through our Site. We may also use your computer's IP address to provide you with personalized content. Your computer's IP address by itself does not identify you personally and thus we treat IP addresses, as Aggregate Information. If your IP address is combined with any Personally Identifiable Information, the combined information will be treated as Personally Identifiable Information and will be protected as outlined in Section 9, above.
10. Any Information Linked With Your Personally Identifiable Information Is Protected As "Personally Identifiable Information"
To enable us to better understand the characteristics of our Customers and/or to provide services tailored to your needs, we may link (a) Personally Identifiable Information you have provided; with (b) Aggregate Information. Linking, for example, is necessary for Managed Accounts, in order to ensure that transactions you complete using the PATCO system are credited to your personal account.
11. How We Safeguard Information We Collect
We have put in place security systems designed to prevent unauthorized disclosure of information you provide to us and to deter and prevent hackers and others from accessing this information. For example, we have taken steps to safeguard the integrity of our telecommunications and computing infrastructure, including but not limited to authentication, and encryption. In addition, customer orders are processed through a secure server using advanced forms of encryption software. This means that all of your Personally Identifiable Information provided online, including your financial information, will be encrypted during transmission to maximize security protection.
Because this site does not encrypt incoming e-mail, you should not send emails containing information that you consider highly sensitive through this Website. We use standard security measures to minimize the threat that your Personally Identifiable Information will be lost, misused, altered, or unintentionally destroyed.
The information contained in this policy should not be construed in any way as giving business, legal, or other advice, or warranting as fail proof, the security of information provided by or submitted to the PATCO Site and of information submitted through customer participation in the Electronic Fare Media Programs. Due to the nature of Internet communications and evolving technologies, we cannot provide, and hereby disclaim, assurance that the information you provide to us will remain free from loss, misuse, or alteration by third parties, who, despite our efforts, obtain unauthorized access.
If we detect an intrusion or other unauthorized access to or use of Personally Identifiable Information (an "Intrusion"), we will notify effected Data Subjects of the Intrusion, and will (i) deliver this notice by the means we deem most efficient under the circumstances (such as, for example, first class mail or email); (ii) use contact information for each effected Data Subject that is current in our files; and (iii) use commercially reasonable efforts to provide this notice in a timely manner.
Persons who receive information in proper accordance with the procedures set out in this Section ("Proper Recipients") may be able to combine (i) information they properly obtain from us under this Section with (ii) other information they independently possess concerning you. We will not be responsible for Proper Recipients' use of this information.
13. Retention Period
We retain records from our Electronic Fare Media Programs on our active database systems, and on our archive systems. These records contain Personally Identifiable Information, and Aggregate Information. We retain on our active systems Electronic Fare Media Program records that contain Personally Identifiable Information for not more than eighteen (18) months. At that point, we archive such records, and retain the archived records for the retention period of four (4) years. Our backup systems do not materially change the retention period of Electronic Fare Media Program records that contain Personally Identifiable Information. We retain Aggregate Information indefinitely.
PATCO will appoint a Privacy and Security Administrator (the "Administrator") to be responsible for administering and ensuring compliance with this Policy. He or she shall ensure timely response requests for access to records; shall provide notice (where allowed) when records are obtained pursuant to compulsory legal process under Section 12; and shall be responsible for the implementation of this Policy in each PATCO office/department.
14. Scope Of Policy
Automated Fare Collection (AFC) means the platform of systems, equipment (fare vending machines, fareboxes, fare gates), back office hardware, and software for PATCO's fare collection activities. This system includes Electronic Fare Media, electronic ticketing, electronic fare collection, and customer service activities.
Data Subject means the individual identified by the personally Identifiable Information at issue.
Electronic Fare media means a smart card or magnetic strip ticket designed to be used by Customers to obtain PATCO transportation services.
Managed Account means an account for Electronic Fare Media that includes advanced service features such as recurring autoloads, electronic payments, and loss protection.
Electronic Fare Media Programs means PATCO administered programs dealing with customer purchase, registration, or use of Electronic Fare Media.
Reduced Fare Programs mean Electronic Fare Media Programs at reduced rates provided to senior citizens, persons with disabilities, and blind persons.
Registered User means an individual or entity that has registered a Smart Card with PATCO.
"You" and "your" refer to any person (i) who accesses this Site or participates in an Electronic Fare Media Program, and (ii) whose personally Identifiable Information is Provided to PATCO.
"We", "us" and "our" mean PATCO.
16. Additional General Provisions
16.1 Privacy Protection for Children: Our Site is not directed at children, and we will not accept or request personal information from individuals we know to be under 13. In accordance with the Children's Online Privacy Protection Act of 1998, if we learn that a child under 13 has provided us with Personally Identifiable Information, we will delete this information from our databases.
16.4 Site Privileges: You agree to refrain from activity that imposes an unreasonable burden on the Site. We reserve the right to limit the order quantity on any item and/or to refuse service to any customer who violates these provisions.
16.5 Choice of Law and Jurisdiction: We will comply with all laws applicable to the DRPA and PATCO.
16.6 Fees for Disclosed Records: We reserve the right to impose reasonable charges for responding to access requests under Section 7. Fees for copies of records which are disclosed shall be assessed in accordance with the Federal Department of Transportation regulations regarding the assessment of fees under the Privacy Act (49 CFR 10.75).
16.8 Contact Us: We welcome your feedback or suggestions, please contact us at 1-877-FRDM-777 (1-877-373-6777) or www.ridepatco.org
Effective: August 9, 2006