Pick Me Up

Privacy Policy

Last updated 22 September 2026

Pick Me Up (“PMU”, “we”, “us”) helps tour operators get their customers onto the right bus. We turn a booking into a ticket in Apple Wallet or Google Wallet, and the ticket carries a link that lets the traveler check in at the pickup point.

This policy explains, in plain language, what personal information we handle to do that, why we handle it, who we share it with and what choices you have. It applies to https://www.pmu.is, our wallet tickets and emails, and our check-in service at api.pmu.is.

1. Who is responsible for your data

If you are a traveler, you booked a tour with a tour operator (for example a diving or glacier company). That operator decides to use PMU for its tickets and pickups, so the operator is the data controller for your booking, and we process your booking information on its behalf as a data processor. The operator’s own privacy policy applies to the booking itself (price, payment, cancellation and so on).

We are the data controller for the things we decide ourselves: how this website runs, the anonymous measurements we take to keep the check-in flow working, the accounts of tour operator staff, and the technical logs of our systems.

Wherever this policy says “your tour operator” it means the company named on your ticket and in the email that delivered it.

2. Information we receive from your tour operator

When you book a tour, the operator’s booking system sends us a notification. From it we receive and keep:

  • Your name, email address and phone number.
  • The booking reference, confirmation code and ticket code (the ticket code becomes the QR code on your pass).
  • The tour name, date and start time, and how many people are on the booking.
  • Your pickup place (name, address and map coordinates) and pickup time.
  • The booking status (confirmed, updated or cancelled), the operator's details and, if the tour was resold, the seller's business details.

We keep a copy of each notification so we can process it reliably, retry it if something goes wrong, and investigate problems the operator reports. During an operator’s setup period we may generate tickets for real bookings for the operator to review without emailing anyone; those tickets contain the same information.

3. Information involved in your wallet ticket

Your ticket shows your name, the tour, the start time, the pickup place and time, a QR code and a check-in link. The link contains a signed token that identifies your booking and operator; it works only for your ticket.

Email. Once your operator is live, we send one “Add to Wallet” email per booking to the address on the booking, from the operator’s sender address or from noreply@pmu.is. We record when it was sent so we never send it twice.

Apple Wallet. When you add the pass, your iPhone registers with our server using a random device identifier and a push token. We store those so we can send an updated pass when, for example, the pickup time changes. Apple Wallet may also send our server technical error reports about the pass; these are device-generated messages that we log and may email to our staff so we can fix the problem. Pass files are stored in private storage and downloaded through links that expire after a few minutes.

Google Wallet. The pass is created under our issuer account with Google. Google notifies us when you save or remove the pass, and we record the time so your operator can see whether the ticket reached your wallet.

4. Information collected when you check in

Your location. When you open the check-in link, your browser asks whether you want to share your location. If you agree, we use it to measure how far you are from the pickup point, to show you directions on a map, and to confirm the check-in once you are at the stop. You can say no: online check-in then does not work, but your ticket is still valid when you show it to the driver. You can withdraw this permission at any time in your browser or phone settings.

When your check-in succeeds we store the booking reference, your name, the tour, its start time, the number of people, the confirmation code, the bus stop and the time. We do not store your coordinates with a successful check-in. If you are too far from the stop, we may record your position, its reported accuracy and the distance to the stop so the operator’s staff can see who tried to check in and help.

Live bus position. The check-in page may show where the bus is. That is the vehicle’s position from the operator’s fleet tracking, not yours.

How the check-in flow is used. To find out where travelers get stuck, the check-in page reports which step you reached (page opened, location allowed or denied, too far from the stop, check-in succeeded or failed), together with the distance and GPS accuracy in metres, the operator and the time. Your check-in token is stored only as a one-way hash so the events for one booking can be grouped without keeping the token itself. Only PMU staff can see these measurements.

Phone check-in (older method). Some operators still offer check-in by phone number. There we collect your phone number, send a six-digit code by SMS (the code expires after five minutes) and record the check-in with your phone number and bus stop.

5. Information about tour operator staff

Operator staff sign in to the PMU dashboard through our sign-in provider, Clerk. We receive your name, email address, sign-in method and the organisation you belong to; Clerk also keeps standard security information about sign-ins such as IP address and device type. We store which company your account belongs to so you only see that company’s check-ins, tickets and pickup places.

When an operator is set up we store the company name, logo, phone number, email address, website and the details needed to connect to its booking system. Booking-system keys are kept as protected configuration, not in the dashboard.

6. Information collected automatically on this website

  • Page-view analytics. We use Vercel Web Analytics to count visits and page views. It does not use cookies and does not identify you personally.
  • Maps. The map tiles on our pages are loaded from Mapbox. Your browser sends Mapbox your IP address and the map area you are looking at; Mapbox’s privacy policy applies to that request.
  • Server logs. Our hosting providers keep standard request logs (IP address, browser type, time, the page or endpoint requested and any error) for security and troubleshooting, for a limited period.
  • Cookies and local storage. We do not use advertising or tracking cookies. Clerk sets cookies only to keep operator staff signed in. The operator dashboard remembers your preferences (the selected company and the sidebar state) in your browser’s local storage. The public check-in pages set no cookies of ours.

7. Why we use your information

We use the information described above to:

  • Create your wallet ticket, keep it up to date and deliver it by email, on your operator's instructions and under its contract with you.
  • Confirm that you are at the pickup point and record the check-in, based on your consent to share your location and the operator's need to run its pickups.
  • Show operator staff who has checked in, who tried to and who has added the ticket to a wallet, based on the operator's legitimate interest in getting everyone on the bus.
  • Keep the service reliable and secure, prevent misuse and fix errors, based on our legitimate interest in running a working service.
  • Understand where the check-in flow loses people so we can improve it, based on our legitimate interest and using the minimum data needed.
  • Meet legal obligations, for example responding to lawful requests from authorities.

We do not sell personal information, we do not use it for advertising, and we do not make automated decisions about you that have legal or similarly significant effects.

8. Who we share information with

We share personal information only with your tour operator and with the service providers we need to run PMU. Each provider may use the information only to provide its service to us.

ProviderWhat they do for usWhere
Your tour operatorSends us your booking, receives your check-in and sees your ticket status. The operator is the source of your data, not one of our providers.Usually Iceland
Bokun (the operator's booking system)Notifies us when a booking is created, updated or cancelled, and lists the operator's pickup places.EU
VercelHosts this website and provides cookie-free page-view analytics.EU and US (global network)
RenderHosts the check-in and wallet-ticket service (api.pmu.is).Frankfurt, Germany (EU)
SupabaseRuns our database and the private storage for Apple Wallet pass files.Ireland (EU)
ClerkSign-in and accounts for tour operator staff.US
Twilio SendGridSends the “Add to Wallet” email. Twilio also sends the SMS code in the older phone check-in flow.US
AppleStores your pass in Apple Wallet and delivers pass updates to your iPhone.US and global
GoogleStores your pass in Google Wallet and tells us when it is saved or removed.US and global
MapboxServes the map tiles behind the pickup map.US

We may also share information with professional advisers, with authorities when the law requires it, and with a buyer or successor if PMU is sold or merged, in which case this policy continues to apply.

9. Where your information is stored

Our database and pass storage are in the European Union (Ireland) and our check-in service runs in Frankfurt, Germany. Some of the providers listed above are based in the United States or operate globally. When information leaves the European Economic Area we rely on the provider’s certification under the EU-US Data Privacy Framework or on the European Commission’s standard contractual clauses.

10. How long we keep information

  • Booking, ticket and check-in records are kept for as long as your tour operator uses PMU and needs them for running pickups and reporting. When an operator leaves, or asks us to delete a customer’s data, we delete or anonymise the records.
  • Booking notifications are kept so we can reprocess them if something goes wrong, and are deleted when they are no longer needed for that.
  • Apple Wallet device registrations are removed when you delete the pass from your iPhone.
  • SMS verification codes expire after five minutes.
  • Check-in flow measurements are kept while we need them to understand and improve the flow, and are reviewed in 90-day windows.
  • Server logs are kept for the short period our hosting providers retain them.

11. How we protect information

All traffic to our website and service is encrypted (HTTPS). Check-in links carry signed tokens that work only for one booking and operator, and pass downloads use links that expire after a few minutes. Database and file storage are private, secrets are kept in protected configuration, and access is limited to PMU staff and, for each operator, its own staff. No system is completely secure, so please contact us if you believe your ticket or account has been misused.

12. Your rights

Under the General Data Protection Regulation and Icelandic data protection law you can ask to access the personal information we hold about you, to correct it, to delete it, to restrict or object to how we use it, and to receive a copy in a portable format. You can withdraw consent to location sharing at any time through your browser or phone settings.

For anything about your booking or ticket, the quickest route is your tour operator, because it holds the booking and instructs us. You can also email us at brekigudm@gmail.com and we will help or pass the request on. We may ask you to confirm your identity first.

If you are unhappy with how we handle your information you can complain to Persónuvernd (the Icelandic Data Protection Authority) or to the data protection authority where you live.

13. Children

Our service is not directed at children. Bookings are made by adults, and if a booking includes a child the operator or the person booking provides that information. We do not knowingly collect information directly from anyone under 16.

14. Changes to this policy

We update this policy when our service or the law changes. The date at the top shows the latest version. If a change materially affects how we use your information we will make that clear on this page, and operators will be told directly.

15. Contact

Pick Me Up, Iceland. Email brekigudm@gmail.com for anything about this policy or your information. Our Terms of Service describe the rules for using the service.