How we handle your data

PRIVACY STATEMENT

What we collect when you report a road hazard, what we publish, what we never publish, and how to get it changed or removed.

Last updated 2 August 2026

1.Who we are

The Garfield Batts Hotspot Solutions Foundation (“GBHSF”, “we”) operates this site, where members of the public report road hazards so they can be mapped, published, and raised with the authorities responsible for fixing them.

We also share hazard data — without reporter contact details — with parish councils and the National Works Agency, so repairs can be located and prioritised.

We are the data controller for everything described here. For any privacy question or request, contact us through privacy@gbhsf.com.

2.The short version

3.What we collect, and why

Hazard reports — no account required

When you submit a report we store the title, the location description you type, the parish or region, the category and severity, your description of the hazard, and the photo or video you attach.

Optionally, and only if you provide them:

Reporter accounts

An account is optional. If you create one we store your name, email address, a one-way cryptographic hash of your password (we cannot read, recover, or tell you your password), whether your email is verified, the date you joined, and the date you last signed in. Short-lived email-verification and password-reset tokens are stored while they are valid.

Contact form

The contact form stores your name, email, phone number if you give one, subject, and message — and, for abuse prevention, your IP address and browser user-agent string.

Anti-spam records

To stop automated signups we record the IP address and email address of each registration attempt, and delete them automatically after 24 hours. We also use Cloudflare Turnstile, a privacy-focused alternative to CAPTCHA, on the signup form. Cloudflare receives your IP address and limited browser signals in order to judge whether you are a person. It does not set tracking cookies or profile you across sites.

Staff activity

Every moderator action — publishing, rejecting, editing, or deleting a report or an account — is recorded in an append-only log with the moderator’s username and IP address. This records our staff’s behaviour, not yours, and exists so moderation decisions can be accounted for.

What we do not collect

No analytics or statistics packages. No advertising or advertising identifiers. No social-media pixels or share-trackers. No profiling, no automated decisions with legal effect, and no sale or rental of personal data to anyone, ever.

4.Our lawful basis

We rely on legitimate interests — the public interest in road safety — for hazard reports and the media attached to them, including for people who appear in a photograph without having submitted it themselves. We chose this rather than consent because a published hazard record has to remain reliable: a pothole outside a school does not stop being a hazard because the person who reported it later changes their mind.

Because that basis is ours rather than yours, it comes with obligations we take seriously and describe in the rest of this statement: minimising what we collect, covering every person before publishing, refusing to publish some images at all, generalising public coordinates, and giving anyone — including someone who never used this site — a way to object. If you think the balance is wrong in your case, write to us and say so.

For account data we rely on legitimate interests in operating the service and on your request for the account itself. For the moderation log we rely on legitimate interests in accountability and security of processing.

5.Photo and video metadata

Phones bury a great deal in the files they produce: GPS coordinates accurate to a few metres, the exact moment of capture, the device’s make, model and sometimes serial number. Published unchanged, that would undo the promise that reporting can be anonymous. All of it is removed in your browser, before the file is uploaded — it never reaches us in the first place.

Photos

  1. We read the GPS coordinates and capture date, and use them to pre-fill the location field and warn you if the photo looks old. You can change or clear anything we pre-fill.
  2. We then re-encode the image, which discards every metadata block — GPS, timestamp, device model and serial included. The visible picture is unchanged.

Videos

Video is rewritten rather than re-encoded, so the picture and sound are bit-for-bit what your camera recorded and nothing is lost to a second round of compression. What is removed are the metadata sections sitting alongside the footage: embedded GPS coordinates, the device make and model, and the capture timestamps — including the ones in the mandatory headers, which are overwritten with zeroes rather than deleted.

We only accept video formats we can clean this way — MP4 and MOV, which covers essentially every phone. A format we cannot clean is refused when you choose it, rather than uploaded with its metadata intact.

Every format we accept is cleaned. We deliberately accept a short list — JPG, PNG and WebP photos, MP4 and MOV video — because those are the ones we can clean in your browser. A file we cannot clean is refused when you choose it, rather than uploaded with its metadata intact. If your file is turned away for its format, that is why.

6.What becomes public

When a moderator publishes a report, the following is visible to anyone:

PublishedNot published
Title, location text, parish or regionYour email address
Description, category, severityYour IP address
Your name, and your account details
The redacted photo or videoThe original, unredacted file
Approximate map coordinatesThe precise coordinates you gave us
Date submittedAnything in a report we did not publish
Contact-form messages

Put plainly: we never publish your name, your email address, the precise coordinates, or the original unredacted file. A published report shows the hazard, where it is to within a stretch of road, and what you wrote about it — not who sent it.

About the map pin

Coordinates are stored precisely, because a repair crew has to find the hazard. What we publish is rounded to roughly an 11-metre grid, so a pin marks the stretch of road rather than a particular doorstep. Parish councils and the National Works Agency receive the precise figure, because they are the ones doing the repair.

One thing rounding cannot fix: the location you type is published word for word.If you write “outside 12 Hope Road”, that is public no matter how approximate the pin is. Describe the place rather than the address, if that matters to you.

About people in photographs

This is a record of hazards, not of people. You chose to take part; nobody else in the frame did. So before anything is published:

If covering everyone would hide the hazard itself, we do not publish the report and will ask for another photo. Reports we do not publish are never public, and their photos and videos are destroyed after 30 days.

Two further safeguards

Published reports are indexed by search engines and may be quoted by media or road authorities. Once something is public we cannot fully recall it.

7.How long we keep things

DataRetention
Media on reports we did not publishDestroyed after 30 days
The private original of a resolved reportDestroyed after 90 days; the published redacted copy remains
Signup-attempt and anti-spam records24 hours
The IP address and browser details on a contact messageErased after 90 days
The contact message itselfDeleted after 24 months
Email verification and password-reset tokensUntil used or expired
Published reportsKept as a public safety record
AccountsUntil you ask us to delete yours
Moderation logKept as an accountability record

The first five are enforced by automated jobs that run every day — not by somebody remembering to do it.

Contact messages get two clocks rather than one, because the message and the technical details are collected for different reasons. Your name, email and message are the correspondence. The IP address and browser details are there to catch abuse of the form, and stop being useful for that within weeks — so they are erased long before the message is, rather than being kept longest simply because nobody separated them.

8.Who else processes your data

We use these providers. None of them is permitted to use your data for their own purposes.

ProviderWhat it handles
VercelWebsite hosting and delivery
NeonThe database — reports, accounts, messages
Vercel BlobPhoto and video storage and delivery
ResendSending our email
CloudflareThe bot check on the signup form
OpenStreetMap FoundationMap background tiles

A note on the map.Map imagery is loaded directly from OpenStreetMap’s servers by your browser, so viewing the map reveals your IP address and the area you are looking at to the OpenStreetMap Foundation. This is normal for web maps and applies to almost every site with one, but you should know it happens.

These providers operate internationally, so your data may be processed outside Jamaica, including in the United States and Europe.

9.Cookies

We use no advertising, analytics, or tracking cookies, and therefore show no cookie banner. The only cookies we set are the ones without which the site cannot function: a session cookie if you sign in, so you stay signed in, and a separate administrator session cookie for moderators. Both are httpOnly, meaning scripts on the page cannot read them.

The site also installs a service worker that caches pages and images so it keeps working on a poor connection or after a storm. That cache lives on your own device, is never sent to us, and deliberately never stores anything from a signed-in or administrative area.

10.How we protect your data

Passwords are stored only as one-way hashes. Moderator accounts support two-factor authentication, and their sessions are signed and expire after eight hours. Original media is never publicly addressable. All traffic is encrypted in transit. Moderation actions are logged.

No system is perfectly secure, and we do not claim otherwise.

11.Your rights

You may ask us to:

This includes people who never used this site. If you appear in a published photograph, or believe you do, write to us and we will look at it — you do not need an account and you do not need to explain yourself.

Write to privacy@gbhsf.com or use our contact form. We will respond within 30 days.

One important limit. We will always delete your account, your email address, and your name. We may decline to delete the hazard report itself where it has been published and forms part of a public safety record — a pothole outside a school does not stop being a hazard because the person who reported it has withdrawn. In that case we anonymise the report rather than erasing it: your name and contact details are deleted from our records, and what remains is the hazard itself — which never carried your name in the first place. Tell us if that is a problem for you and we will discuss it.

If you are unhappy with how we have handled your data, you can complain to the Office of the Information Commissioner (Jamaica), or to your local data protection authority if you are elsewhere.

12.Children

This site is not directed at children under 13, and we do not knowingly collect their personal data. Anyone can report a hazard anonymously without giving us anything about themselves. We do not publish photographs showing children. If you believe a child has given us personal details, contact us and we will remove them.

13.Automated decisions

We make none. Every report is reviewed by a person before it is published or turned down. The bot check on the signup form may prevent an automated submission, but never makes a decision about you as an individual.

14.Changes to this statement

If we change how we handle your data we will update this page and change the date at the top. If the change is significant we will say so on the site.