Privacy Policy
Legal
What we collect, why, how long we keep it, and the rights you have over it.
DRAFT — NOT LEGALLY REVIEWED. Must be reviewed by qualified privacy counsel before publication. Data-protection statements are legally binding representations; publishing an inaccurate one is itself a regulatory risk.
Effective date: [EFFECTIVE DATE] Controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS] Data protection contact: [DPO OR PRIVACY CONTACT EMAIL] EU representative (GDPR Art. 27): [EU REP] UK representative: [UK REP]
| We collect | Account details, reports you submit, approximate/precise location when you use map features, device and usage data |
| Location precision | Precise while the app is open, only with your permission. We do not track location in the background. |
| We never sell | Your personal data. We do not sell or share it for cross-context behavioural advertising. |
| Retention | Precise location is not stored against your account. Reports are retained while published. Accounts are deleted on request. |
| Your rights | Access, correct, delete, export, object, restrict, withdraw consent |
| Data | Purpose | Lawful basis (GDPR) |
|---|---|---|
| Email address, password (hashed) | Create and secure your account | Contract (Art. 6(1)(b)) |
| Display name (optional) | Attribution of your reports | Contract |
| Home country, language (optional) | Localise content | Legitimate interests |
| Report content, category, severity | Publish safety information | Contract; legitimate interests (Art. 6(1)(f)) |
| Photographs you attach | Evidence supporting a report | Consent (Art. 6(1)(a)) |
| Dispute submissions (including contact email) | Handle a complaint about a report | Legal obligation; legitimate interests |
| Data | Purpose | Lawful basis |
|---|---|---|
| Device location (while app is open) | Show nearby reports and area alerts | Consent (Art. 6(1)(a)) |
| Location attached to a report | Place the report on the map | Contract |
| IP address | Security, abuse prevention, rate limiting | Legitimate interests |
| Device type, OS version, app version | Diagnostics and compatibility | Legitimate interests |
| Crash and error reports | Fix defects | Legitimate interests |
Reports may describe alleged criminal offences. Under GDPR Art. 10, personal data relating to criminal convictions and offences has heightened protection.
Our position: reports must describe conduct and location, not identify private individuals. We prohibit naming individuals in submissions and remove such content in moderation. Where a report names a business, we treat that as commercial information rather than personal data — except where a business is a sole trader identifiable as a natural person, in which case additional care applies and the report may be restricted to an area rather than a named venue.
Counsel note: the Art. 10 analysis for sole traders and small named businesses is the single most important privacy question for this product and needs explicit advice.
between sessions.
against your account**.
report, deliberately imprecise to the street or landmark level rather than an exact point.
continue to work, defaulting to city-level browsing.
reported.
We do not use your data for behavioural advertising, and we do not build advertising profiles.
| Recipient | What | Why |
|---|---|---|
| Hosting and database providers | All service data | Run the service |
| Error and performance monitoring | Diagnostics, IP | Detect and fix failures |
| Email provider | Email address, message content | Send account and dispute emails |
| Map and places providers | Coordinates of a map request | Render maps, look up places |
| Law enforcement | Only what is legally required | Where compelled by valid legal process |
Each processor is bound by a data processing agreement. Current sub-processors are listed at [SUB-PROCESSOR LIST URL].
Aggregated data (for example, "distraction theft reports rose 12% in Barcelona this quarter") contains no personal data and may be published or licensed. We do not re-identify individuals from it.
We are established in [JURISDICTION]; our providers may process data in other countries. Where personal data leaves the EEA or UK we rely on adequacy decisions, or on Standard Contractual Clauses with supplementary measures where required. You can request a copy of the relevant safeguards from [DPO CONTACT].
| Data | Retention |
|---|---|
| Account record | Until you delete your account |
| Published reports | While published; retained in anonymised form afterwards where removal would break the safety record |
| Rejected/removed reports | [90] days, then deleted |
| Dispute records | [6] years, as a record of complaint handling |
| Precise location used for an alert check | Not stored |
| IP address and security logs | [90] days |
| Backups | Purged on the normal backup rotation, up to [35] days after deletion |
When you delete your account, we delete or anonymise your personal data. Reports you submitted may remain published in de-identified form, because removing safety information that other travellers rely on is a separate decision from deleting your account — you can request removal of specific reports as well, and we will consider it.
Depending on where you live, you have rights to:
How: email [DPO CONTACT EMAIL] or use the in-app account controls. We respond within 30 days (or one month under GDPR / 45 days under CCPA), and we do not charge for this.
California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not offer financial incentives for personal information. You may exercise your rights without discrimination.
Complaints: you may lodge a complaint with your local supervisory authority. In the EU this is your national data protection authority; in the UK it is the Information Commissioner's Office.
We protect data with encryption in transit (TLS), hashed passwords (bcrypt), short-lived access tokens with server-side revocation, role-based access control for staff, rate limiting, and least-privilege database access. Staff access to personal data is limited to those who need it for moderation or support.
No system is perfectly secure. If a breach affects your rights, we will notify you and the relevant supervisory authority as required (within 72 hours under GDPR).
The service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has provided us personal data, contact [DPO CONTACT EMAIL] and we will delete it.
We will post material changes with at least [30] days' notice before they take effect.