Washington residents: in addition to this Privacy Policy, please read our Consumer Health Data Privacy Policy, which governs "consumer health data" under RCW 19.373.
Quick Summary
- What Open Road does: Drive logging app with optional social features (friends, convoys, live presence, marker sharing, voice chat).
- Your drives: Every drive is recorded on your device first (Core Data on iOS; Room database on Android). If you are signed in, drives also sync to our servers by default so you can get them back on a new phone. That upload happens for every drive, not only the ones you share. You can see exactly what is uploaded in Section 2.1.
- Speed along the route: When a drive syncs, we store the route and the speed at each point along it, as part of your drive record. That is what draws your speed chart and your drive history on any phone you sign in on. We keep it until you delete the drive or your account.
- Server data: Social features use Firebase (Firestore, Realtime Database, Cloud Functions, Storage, FCM, App Check). Voice chat uses LiveKit for real-time audio (not recorded).
- Account: Sign in with Apple (iOS), Sign in with Google (iOS and Android), or email/password (Android); stable identifier only received unless you choose to share your email or display name.
- Sign-up location: When you create an account, we look up your approximate city and region from your internet connection and save it with your account, so we can see where drivers come from.
- Public Presence & Waves (see §2.2): Feature (active on iOS and Android) that surfaces nearby drivers within ~10 km and lets you send ephemeral "waves." On Android, onboarding currently defaults to Anonymous, visible without identity. You can switch to Hidden or Open at any time.
- No selling: Personal data is never sold to advertisers, data brokers, insurance companies, or government agencies. No ad tracking or tracking pixels.
- Analytics: Firebase Analytics collects usage data: app launches, screen views, feature usage, and a set of profile-style properties that includes your total drives and total distance. It is tied to your app install and, on the server, to your account, so we do not call it anonymous. It never includes your location, your routes, or any address. You can turn analytics off in the app. Firebase Crashlytics collects crash reports.
- Privacy trimming: Before a drive is shared or used for the heat map, we cut off the beginning and the end of the route, and we remove anything inside a privacy zone you drew. Trimming is on by default. On iOS you can make the trim longer or shorter in Settings, and you can choose to show the start and end on a single drive you post. If you do, that drive is shared with its real start and end.
- Deletion: Delete account in-app to remove all server data from Firestore collections, Cloud Storage, and local data. Permanent and irreversible.
- Contact: openroad2026@gmail.com
1. Who We Are
Controller: OpenRoad LLC, 5941 39th Ave SW, Seattle, WA 98136, USA. Contact: openroad2026@gmail.com.
EU Representative: In accordance with Article 27 of the GDPR, OpenRoad LLC has designated Mikita Shylai as its representative in the European Union (Poland). Individuals in the EU may contact our representative regarding the processing of their personal data at openroad2026@gmail.com.
Contacting us about your data: Users in the EU/EEA, UK, and Switzerland may contact us directly at openroad2026@gmail.com for any data-protection request, and may also lodge a complaint with their local supervisory authority (see Section 13).
2. Data We Collect
2.1 Drive Data
Every drive is recorded on your device (Core Data on iOS; Room database on Android). On iOS it can also sync to your own private iCloud. What a drive contains:
- Location: GPS points recorded while a drive is running. These build the route line, the distance, and the map.
- Speed at each point: the speed reading that goes with each GPS point, plus heading and altitude.
- Motion (if enabled): accelerometer and gyroscope readings, used for acceleration and cornering.
- Drive metadata: start and end times, duration, and any name or note you add.
What we upload when you are signed in
If you are signed in, drive sync is on by default and runs for every drive, not only the ones you share, so your history follows you to a new phone. Two things go to our servers:
- A drive record: the summary numbers (distance, duration, average and top speed, g-force), your account identifier, the vehicle, the time zone, an approximate area, and the route line at two levels of detail. Each route line carries the speed at each point along it. Both are privacy-trimmed before upload.
- A copy of the drive's raw readings, so a new phone can rebuild the drive exactly: one row per GPS reading with time, position, speed, heading, altitude, and the three accelerometer axes. This file is not trimmed, and it is readable only by your own account. It is never shared with other users, and it is not used for the heat map or the feed.
Syncing a drive does not make it visible to anyone else. A synced drive is private to your account until you choose to share it. When you share a drive to the drive feed, to friends, or publicly, a separate post is created that other people can see, holding the trimmed route line, the speed along it, and the summary numbers. Setting a shared drive back to private removes that post. Social features (presence, markers and segments you publish, convoy membership) also send related data to our servers.
2.2 Social Features Data (Server-Stored)
If you use social features, data processed on our Firebase backend includes, but is not limited to, the categories below. Open Road is an evolving product: we may add, remove, or change social features (and the data they involve) over time, and will update this Policy for material changes.
- Account identifier: Stable identifier from Sign in with Apple / Google (email not received unless user shares).
- Friends list: User identifiers of connected people.
- Convoy membership: Data about convoy groups joined or created.
- Global leaderboard (opt-in): If you join the global leaderboard, your username, profile photo, and aggregate totals are published to a ranking visible to other users: distance driven, number of drives, XP, and an average speed figure worked out from your total distance over your total driving time. Your top speed is never published, and the ranking is by XP, not by speed. You choose whether to join, and you can leave at any time in the app.
- Markers and segments you publish: If you share a marker or segment, its location, route geometry, and your best times on it are stored on our servers and are visible to the people you shared it with.
- Live presence with friends (optional): While you are driving with live presence on, your position is sent to our servers and shown to the people you are sharing with. It is your exact position, because a rounded one would draw you off the road. Each live position is deleted about 90 seconds after it is sent. If you drive into a privacy zone you drew, your live position is removed and you disappear from the map until you leave the zone.
- Public Presence, nearby drivers: Open Road includes a feature that surfaces nearby drivers within approximately 10 km (a radius we may adjust), transported over Firebase Realtime Database. It is active on iOS and Android. It currently offers three tiers, which we may change:
- Hidden: you are not visible to other drivers and you do not see them.
- Anonymous: you appear on other drivers' maps without your identity (no name, no profile photo); you can also see other drivers in the same tier.
- Open: you appear with your username and profile photo to other drivers nearby.
In the Anonymous and Open tiers, the position we broadcast is your exact position, not a rounded or offset one, and it is readable by any signed-in user of the app near you. In the Open tier your speed is broadcast with it. We do not blur it. If you do not want that, use the Hidden tier.
On Android, onboarding currently defaults new users to Anonymous. You can change your tier at any time, including switching to Hidden, in the Public Presence settings inside the app. We may change the default tier, the available tiers, or how this feature works, and will update this Policy for material changes.
- Waves: Where Public Presence is enabled, you can send a lightweight "wave" to a nearby driver. A wave is a brief, ephemeral record (stored in Firebase Realtime Database with an approximately 5-minute time-to-live, then auto-deleted) containing the sender and recipient identifiers and a timestamp. There is no message content.
- Markers and zones: Location data for markers and zones you create (such as community speed traps and zones). Depending on the type, these may be shared with your friends and/or contributed to the broader Open Road community as public community objects visible to other users.
- Push notification tokens: Device tokens stored in Firebase Cloud Messaging (FCM).
- Shared drive routes: When you share a drive, we upload the trimmed route line, the speed along that line, and the summary numbers. Trimming removes the beginning and the end of the route, and it removes any part of the route inside a privacy zone you drew. Trimming is on by default. On iOS you can change how much is trimmed in Settings, and a per-drive control lets you show the start and end on a drive you post. Turning that on for a drive means that drive is shared with its real start and end. If you hide your top speed on a post, the speed readings for that post are dropped too, so nobody can work the top speed back out.
2.3 Photos and Camera
The App may request access to your device camera (for taking a vehicle photo for your garage) and your photo library (for choosing a profile photo). These images are stored locally and, if you use social features, uploaded to Firebase Storage. Photos are deleted when the associated profile or vehicle is deleted, or when the account is deleted.
2.4 Voice Chat
Voice chat is facilitated via LiveKit with authentication tokens issued for calls. Audio streams are transmitted peer-to-peer or via LiveKit servers in real-time. Voice calls are not recorded or stored.
2.5 Markers and Zones
Markers and zones are in-app driving challenges (similar to Forza speed traps). They are not related to law enforcement detection.
- Stored with creator ID for ownership and editing purposes.
- Depending on the type and your choices, markers and zones may be shared privately with your friends and/or published as community objects visible to the broader Open Road community. Community-contributed markers and zones may remain visible to others, in a form that does not identify you by name, after you create them.
- Your own markers and zones are removed from your account when your account is deleted; community objects you contributed may be retained in aggregate or de-identified form to keep the community map functional.
2.6 Now-Playing Music (iOS)
On iOS, the App requests Apple Music access so it can show what you are currently playing and let you skip or pause tracks without leaving the app while driving. Track title and artist are read locally for on-screen display only and are not transmitted to our servers.
2.7 Notification Listener (Android)
On Android, the App offers a now-playing display equivalent to iOS. Android exposes this only through the Notification Listener system permission, which technically grants access to all notifications. Our notification-listener service is bound exclusively to surface currently-playing music; non-music notifications are ignored and never read, stored, or transmitted off-device. You can revoke this access at any time in Android Settings.
2.8 Activity Recognition and Auto-Drive Detection (Android)
On Android, the App uses Activity Recognition to detect when a drive has started and offers to begin logging automatically. The App also requests permission to start in the background after device boot (for resumption of in-progress drives across reboots) and to be exempted from battery optimization (so the foreground location service is not killed mid-drive). Activity-recognition signals are processed on-device and are not transmitted to our servers.
3. Purposes and Legal Bases
| Purpose | Legal Basis (GDPR) |
|---|
| Provide core drive logging functionality | Contract necessity (Art. 6(1)(b)) |
| Sync every drive to our servers so your history survives a lost or replaced phone: route, the speed at each point, motion readings, summary numbers | Contract necessity (Art. 6(1)(b)) |
| Enable social features (friends, convoys, markers) | Contract necessity (Art. 6(1)(b)) |
| Share live presence with friends | Consent (Art. 6(1)(a)) |
| Access microphone for voice chat | Consent (Art. 6(1)(a)) |
| Send push notifications | Consent (Art. 6(1)(a)) |
| Facilitate voice chat connections | Contract necessity (Art. 6(1)(b)) |
| Process in-app purchases | Contract necessity (Art. 6(1)(b)) |
| Product and usage analytics, tied to your app install and your account (Firebase Analytics) | Legitimate interests (Art. 6(1)(f)) |
| Crash reporting (Firebase Crashlytics) | Legitimate interests (Art. 6(1)(f)) |
| Access camera and photo library for profile/vehicle photos | Consent (Art. 6(1)(a)) |
| Detect drive start via Activity Recognition (Android) | Consent (Art. 6(1)(a)) |
| Public Presence: broadcasting your exact live position (and, in the Open tier, your speed) to nearby drivers | Consent (Art. 6(1)(a)) |
| Send and receive Waves with nearby drivers | Consent (Art. 6(1)(a)) |
| Read currently-playing music for in-app display | Consent (Art. 6(1)(a)) |
| Paid-install attribution via SKAdNetwork (iOS) | Legitimate interests (Art. 6(1)(f)) |
| Security monitoring and abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Comply with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Develop, test, and improve features, and create new products and services | Legitimate interests (Art. 6(1)(f)) |
| Any additional purpose disclosed to you at the time of collection or to which you consent | As stated or consent (Art. 6(1)(a)) |
The processing activities and categories described in this Policy reflect how the Service works today and the range of uses we may make of your data. Open Road continues to develop new features; where a new feature involves a materially different use of your personal data, we will update this Policy and, where required, obtain your consent.
4. Recipients and Processors
We rely on third-party service providers (processors) to operate the Service. These currently include, but are not limited to, the following. We may add, remove, or replace service providers as the Service evolves; each acts on our instructions and is bound by contractual confidentiality and data-protection obligations.
- Google / Firebase: Firestore (database), Realtime Database (nearby-driver Public Presence and Waves transport, iOS and Android), Cloud Functions (server logic), Cloud Storage (file storage), Firebase Cloud Messaging (push notifications), Firebase Analytics and Crashlytics (usage analytics and crash reports), Firebase App Check (abuse prevention). Your synced drives, including the route, the speed along it, and the raw-readings file, are held on Google Cloud infrastructure.
- Mapbox: Turn-by-turn routing via the Mapbox Directions API on both iOS and Android. Origin, destination, and intermediate waypoints are sent to Mapbox to compute the route. Mapbox does not receive your full drive history or live driving data.
- Google Maps SDK (Android): Map tile rendering on Android. Tile requests include the visible map area only.
- Apple: Sign in with Apple (authentication, iOS), App Store (subscription/purchase processing), iCloud/CloudKit (optional drive data sync, iOS), SKAdNetwork (privacy-preserving install attribution for paid ad campaigns, iOS; see §4.1). Payment card details not received from Apple.
- Google: Sign in with Google (authentication, iOS and Android), Google Play Billing (subscription/purchase processing on Android), Google Play In-App Review (optional rating prompt on Android). Payment card details not received from Google.
- LiveKit: Real-time voice transport for voice chat. Receives authentication tokens and routes audio streams; calls not recorded.
4.1 SKAdNetwork (iOS install attribution)
On iOS, Open Road participates in Apple's SKAdNetwork framework so that when you install the App from a paid advertising campaign, Apple can send us a privacy-preserving install-attribution signal, telling us which campaign drove the install in aggregate. SKAdNetwork postbacks do not include your Apple ID, IDFA, email, location, or any other personally identifying signal: only the campaign and conversion identifiers Apple defines.
The list of advertising networks that may receive an SKAdNetwork postback for an Open Road install is declared in the App's Info.plist and visible in our App Store listing under "App Privacy." We do not control which specific ad networks Apple may send postbacks to during any particular campaign.
We do not embed third-party advertising SDKs inside the App. We do not collect IDFA. We do not run cross-app behavioral tracking. Apple's App Tracking Transparency (ATT) prompt is not used because we do not perform tracking that requires it.
Personal data is not sold, rented, licensed, or provided to third parties for commercial purposes, including advertisers, data brokers, insurance companies, or government agencies. No third-party advertising or ad tracking services are used.
5. Who Can See Your Data Inside OpenRoad
We want to be straightforward about what the company can technically see and what we promise not to do with it.
5.1 What we can technically access
Because we operate the server side of Open Road on Google Firebase, authorized OpenRoad LLC personnel can, in principle, view individual user account data through the Firebase console. That includes:
- Your profile, friends, convoy membership, marker and zone ownership, feed entries, and push notification tokens.
- Every drive you synced, not only the ones you shared. That means the trimmed route line, the speed at each point along it, and the summary numbers.
- The raw-readings file for each synced drive, which is untrimmed and holds every GPS point, speed, heading, altitude, and accelerometer reading.
- Files you uploaded (profile photo, vehicle photos).
- Live presence entries while they exist (about 90 seconds).
- Server logs that contain your account identifier.
- Firebase Authentication metadata (sign-in provider, account creation date, last sign-in).
We can see the routes of drives that synced. What we cannot see: drives recorded while you were signed out or with sync turned off, because those never reach us, and voice chat audio, because it is never recorded.
5.2 What we use this access for
- Debugging crashes and reported issues.
- Investigating reports under our Community Guidelines (e.g., harassment, fake drives, abuse).
- Operating and improving the Service.
5.3 What we will not do with this access
- We will not browse user accounts out of curiosity.
- We will not share, sell, license, or otherwise transfer your data to advertisers, data brokers, insurance companies, employers, family members, or any other third party.
- We will not provide your data to law enforcement except as set out in Section 7 (Law Enforcement and Government Requests).
- We will not use your drive data to build anything outside Open Road. It powers your own history and stats, the social features you turn on, and aggregate map features like the Global Heat Map in Section 6, where contributions are trimmed first.
These are commitments about what we do with your data, and they hold. Open Road keeps adding features, so the specific list above will grow; this Policy is updated when it does, and we ask for consent where the law that applies to you requires it.
6. Global Heat Map
Open Road displays a community-wide heat map showing where people drive. To build it, we aggregate contributions from every active user. We disclose this directly so you understand what is being contributed and what is not.
6.1 What is contributed
- The middle portion of drives you have synced or shared. A stretch at the start and a stretch at the end of every drive are cut off before the drive is used, so the heat map cannot show where a trip began or ended. How long that stretch is varies from drive to drive. We do not publish the distances, because that would tell anyone trying to undo the protection how far back to look. On iOS you can see the trim on your own map and make it longer in Settings.
- A second trim is applied on our servers when the heat map is built, on top of the one your phone applied.
- Contributions are aggregated into a coarse grid, and the heat map is served as flat images. An individual drive cannot be pulled back out of the heat map.
6.2 What is not contributed
- Any part of a route inside a privacy zone you drew (for example near home or work).
- The trimmed start and end of every drive.
- Drives that were never synced or shared.
- Your speed. Speed readings are stored with your drive, but they are not used to build the heat map and they do not appear in it.
- Your name, your username, and your account identifier. None of them survive into the heat map.
6.3 Opt-out
Contributions come from synced and shared drives, trimmed and privacy-zone excluded as described above, and the output is an aggregate image that no individual drive can be pulled back out of. The heat map is a feature of the Service. It is not sold or licensed to third parties. If you would rather your drives were not part of it, email us at openroad2026@gmail.com and we will take them out. Your privacy zones already keep those areas out of it entirely, and a drive you never sync or share is never part of it.
7. Law Enforcement and Government Requests
- We will not voluntarily provide user data to law enforcement, government agencies, or any other authority.
- We do not cooperate with informal requests, voluntary disclosure programs, or non-binding inquiries.
- We will only provide user data if compelled by a legally binding court order. Not a subpoena, not an informal ask.
- Even when legally compelled, we provide the minimum data required and notify the affected user where legally permitted.
- We can only hand over what we hold. Drives recorded while you were signed out, or with sync turned off, never reach us at all. Drives that did sync are on our servers; Section 5.1 says what that includes.
8. Analytics and Crash Reporting
We use Firebase Analytics to understand how the app is used: app launches, screen views, and feature usage. Analytics never includes your location, your routes, or any address. The app blocks that at the point of sending: any event value that looks like a coordinate, a route, a polyline, or an address is dropped before it leaves your phone.
Analytics is not anonymous, and we do not call it that. Events carry an identifier for your app install, and the properties listed below travel with them. A small set of usage figures is also written into your own account record: the date of your first drive, how many drives you have saved, how many friends you have, and how often you said you drive.
- We do not send location, route, or address data to any analytics service.
- Analytics properties we attach: app version and build number, platform, app language, device locale, device region and UTC offset (read from your phone's settings, not from GPS and not from your IP), subscription status and whether a trial is active, the paywall, price and onboarding variants you were shown, how you found the app, your Apple Search Ads attribution token where Apple provides one, the vehicle type in your garage, whether location permission is granted, whether you have added a friend, joined a convoy or shared a drive, your friend count, how often you said you drive, and your running totals: number of drives, total distance, and number of markers and zones you have created. No usernames, no email addresses, no advertising identifier.
- Turning it off: analytics collection only starts after you agree to it, and you can switch it off in the app at any time. Switching it off stops the events, the properties, and the automatic Firebase events together.
- Firebase Remote Config is used for feature flags only.
- Firebase Crashlytics collects crash reports: stack traces, app version, build number, and device model. We do not attach your account identifier to a crash report. No location and no driving data is included in crash reports. Crash reporting is not covered by the analytics opt-out. It runs on legitimate interests, carries no behavioural events, and carries nothing that identifies you.
- We do not embed PostHog, Sentry, Mixpanel, Amplitude, Segment, Facebook SDK, or any third-party behavioral-ad SDK inside the App. We do not collect IDFA. We do not use tracking pixels. Apple's SKAdNetwork is used for paid-campaign install attribution only (see §4.1) and is privacy-preserving by design.
- Firebase derives a coarse location (roughly, a country or region) from the network address your requests arrive from. That happens on Google's side for every internet service, and it is not something our app sends.
9. International Data Transfers
OpenRoad is based in the United States. If you use the Service from outside the U.S., your data is transferred to and processed in the U.S. For EU/EEA, UK, and Swiss data subjects, we rely on:
- The EU-US Data Privacy Framework adequacy decision (Commission Decision (EU) 2023/1795);
- The UK Extension and Swiss-US Data Privacy Framework;
- The EU Standard Contractual Clauses (Commission Decision (EU) 2021/914) and UK International Data Transfer Addendum as fallback where DPF does not apply.
For Brazil, we rely on ANPD-approved Standard Contractual Clauses. Service providers including Google/Firebase, LiveKit, and Mapbox maintain transfer compliance documentation.
10. Data Retention
- Drives on your device: kept until you delete the drive or delete the app.
- Synced drives on our servers: the drive record, the trimmed route, and the speed at each point along it are kept for as long as the drive exists, so that your history is there when you sign in on a new phone. There is no timed expiry. Deleting the drive in the app deletes the record, and deleting your account deletes all of them.
- The raw-readings file for a synced drive: kept in file storage on the same basis, readable only by your own account, and deleted with the drive or the account.
- Live presence data: Expires after about 90 seconds; a server sweep runs every couple of minutes to clear stale entries. Nothing about where you were is kept once the entry expires.
- Waves: Ephemeral; expire approximately 5 minutes after being sent, then auto-deleted.
- Push notification tokens: Retained until notification permissions revoked, notifications disabled in-app, or account deleted.
- Marker/zone objects: Retained until hidden/removed in-app or account deleted. Note: shared items may persist for other users.
- Friends list and convoy data: Retained until relationship removed or account deleted.
- After account deletion: When you delete your account, active server data is removed and your authentication record is revoked. Residual data may persist in encrypted backups, log archives, and provider-side replicas for up to 180 days before being permanently expunged. Moderation reports are redacted (personally identifiable information removed) but not deleted, to maintain platform safety records.
- Drive feed entries: Retained until the user deletes them, changes visibility, or deletes their account.
- Voice chat: No retention; audio transmitted in real-time only.
11. Your Rights
Under GDPR and applicable US privacy laws, you may have the following rights regarding your personal data:
- Access: Request a copy of your personal data.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of data ("right to be forgotten").
- Restriction: Request processing restriction in certain circumstances.
- Portability: Request data in a portable format.
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Withdraw consent where processing is based on consent (live presence, push notifications, microphone access).
How to Exercise Your Rights
- Email: Contact openroad2026@gmail.com with your request. Identity verification may be required.
- In-app deletion: Delete your account directly in the app via Profile → Settings → Delete Account. Removes server data and local data.
Response aim: 30 days or as required by applicable law.
12. Account Deletion
Delete your account anytime from the app:
Profile → Settings → Delete Account
Account deletion removes data from all Firestore collections including:
- Profile, drives, feed entries, friends (both directions), markers/zones, convoys, presence, push tokens, notification settings, and all subcollections.
- Your synced drive records, including the routes and the speed readings along them.
- Stored files: your raw-readings drive files, avatars, vehicle photos, and any other uploads.
- Apple Sign-In tokens are revoked (iOS). Google authentication credentials are removed (Android).
- Local device data is removed. On iOS, iCloud/CloudKit data (if sync was enabled) is also deleted.
- On iOS, deletion is processed server-side via Firebase Cloud Functions. On Android, deletion is performed client-side with cascading Firestore and Storage cleanup followed by Firebase Auth account removal.
Moderation reports are redacted (personally identifiable information removed) but not deleted, to maintain platform safety records.
Deletion is permanent and irreversible.
13. Supervisory Authority (EU/EEA/UK Users)
You have the right to lodge a complaint with your supervisory authority if you believe your data protection rights have been violated:
- EU/EEA: Your local data protection authority
- UK: Information Commissioner's Office (ICO), ico.org.uk
- Switzerland: Swiss Federal Data Protection and Information Commissioner (FDPIC), edoeb.admin.ch
We encourage contacting us first at openroad2026@gmail.com to resolve concerns.
14. California Notice (CCPA/CPRA)
Although OpenRoad is below CCPA/CPRA applicability thresholds, we voluntarily extend these rights to California residents:
- Right to Know: Request a copy of the personal information we collect about you.
- Right to Delete: Request deletion of your personal information.
- Right to Correct: Request correction of inaccurate information.
- Right to Opt Out of Sale/Sharing: There is nothing to opt out of. We do not sell personal information and we do not share it for cross-context behavioral advertising. Open Road is an app, not a website with ad trackers, so a browser signal such as Global Privacy Control has nothing to act on here.
- Right to Limit Sensitive Personal Information: You can limit use of precise geolocation and other sensitive data.
- Right to Non-Discrimination: No discrimination for exercising CCPA/CPRA rights.
- Automatic Renewal Law: The price, the billing period, and the fact that the subscription renews on its own are shown before you buy, and the purchase confirmation and receipt come from Apple or Google. Renewal reminders are sent by Apple and Google under their own rules, not by us. You cancel through the App Store or Google Play at any time.
To exercise rights: Settings → Privacy & Data, or email openroad2026@gmail.com. We respond within 45 days.
15. Other U.S. State Rights
Residents of Virginia, Colorado, Connecticut, Utah, Oregon, Texas, Montana, Delaware, Iowa, Tennessee, Indiana, Kentucky, Rhode Island, New Jersey, New Hampshire, Minnesota, Maryland, Nebraska, and Nevada have similar rights to access, delete, correct, port, and opt out of profiling. We provide these rights on the same basis as California. Nevada and Connecticut residents: our Consumer Health Data Privacy Policy applies to drive data.
16. EU/EEA, UK, and Swiss Rights (GDPR / UK GDPR)
You have the following rights under GDPR / UK GDPR:
- Access (Art. 15): Obtain a copy of your personal data.
- Rectification (Art. 16): Correct inaccurate data.
- Erasure (Art. 17): Request deletion ("right to be forgotten").
- Restriction (Art. 18): Restrict processing in certain circumstances.
- Portability (Art. 20): Receive data in a portable format.
- Objection (Art. 21): Object to processing based on legitimate interests.
- Not to be subject to automated decision-making (Art. 22): Receive human review for decisions with legal or similarly significant effects.
- Withdraw consent (Art. 7(3)): Withdraw consent at any time without affecting prior lawfulness.
Exercise rights in-app (Settings → Privacy & Data) or email openroad2026@gmail.com. Response time: 30 days.
17. Other Jurisdictions
Canada (PIPEDA / Quebec Law 25): Right to access, correct, withdraw consent, and complain to the Office of the Privacy Commissioner (priv.gc.ca) or your provincial authority.
Brazil (LGPD): Rights include confirmation, access, correction, deletion, portability, and withdrawal of consent. Contact us at openroad2026@gmail.com with subject "LGPD". Complaints: ANPD at gov.br/anpd. We are below the LGPD threshold that requires appointing a Data Protection Officer; if that changes we will update this policy.
Japan (APPI): Request disclosure, correction, suspension of use, and suspension of third-party provision. Contact openroad2026@gmail.com (subject: "APPI").
18. Security Measures
Technical and organizational measures implemented to protect personal data:
- Encryption of data in transit (TLS/HTTPS).
- Encryption at rest applied by service providers (Firebase, iCloud) as part of standard infrastructure.
- Authentication via Sign in with Apple / Google with secure token handling.
- Firebase Security Rules restricting data access.
- Regular access control and security practice review.
- Location, route, and address data are blocked from analytics events at the point of sending, not merely left out by convention.
- Privacy zones. The circle we store and draw is deliberately not centred on the place you picked. The centre is shifted a random distance in a random direction, capped so the real place stays well inside the circle rather than near its edge. Any part of a route inside a zone is removed before sharing or heat-map use, and your live presence disappears while you are inside one.
- Route trimming. Before a drive is shared, used for the heat map, or drawn on a share card, a stretch at the start and the end of the route is removed. The distance varies per drive and is not predictable across drives or across phones, while staying stable for the same drive so the line does not move between views. We do not publish the distances or the method that varies them. On iOS you can make the trim longer in Settings.
- Live position is not trimmed or rounded. Convoy members, friends you share with, and (in the Anonymous or Open tier) nearby drivers see your exact position, because a rounded live position would put you off the road. Privacy zones still apply, and each live position is deleted after about 90 seconds. The controls are the Hidden tier and turning friends' live presence off.
- The raw-readings file for each synced drive is untrimmed, and Storage rules restrict it to your own signed-in account.
19. Children and Minors
Open Road is not directed to children and is not intended for anyone under 16. Our Terms of Service require you to be at least 16 (or the age of digital consent where you live, if that is higher), and agreeing to the Terms is a condition of using the app. We do not knowingly collect personal data from anyone under 16, and if we learn that we have, we delete it. If a child under 16 has created an account, contact openroad2026@gmail.com and the account and associated data will be deleted as soon as reasonably practicable. Open Road is a general-audience driving app; it is not aimed at children, has no child-directed content, and collects nothing from anyone we know to be under 16.
20. Purchases
Subscriptions and in-app purchases are processed by Apple via the App Store (iOS) or Google via Google Play (Android). Payment card details are not received or stored by Open Road. Purchase history is managed by Apple / Google under their respective privacy policies.
21. Changes to This Policy
We may update this Policy at any time as the Service changes. The current version is always the one posted here, and the "Last updated" date at the top tells you when it changed. Changes take effect when they are posted, and continued use of the Service after that constitutes acceptance. Where a change requires your consent under the law that applies to you, we will ask for it.
22. Contact
For questions, requests, or concerns about this Privacy Policy or your personal data:
openroad2026@gmail.com
See also our Community Guidelines.