Last updated: September 10, 2026
TripTrack is an iOS application for recording personal car trips. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to the TripTrack mobile app and any server infrastructure we operate ("Service").
The developer of TripTrack ("we", "us") acts as the data controller for personal data processed through the Service. Contact: privacy@trip-track.app.
TripTrack works in two distinct modes. The data we process depends on which mode you use.
If you do not sign in, TripTrack stores all your data — trips, GPS tracks, photos, vehicle profiles, preferences — exclusively on your device using Apple's CoreData framework. Your trips, tracks, photos and preferences do not leave the device, and we do not create an account for you.
Three things do leave the device even in guest mode, and we would rather name them than claim otherwise:
If you sign in with Apple, your data can be synchronized with our server so it is available on your other devices. Cloud sync is opt-in and can be disabled at any time in the app (Profile → Cloud Sync).
One case does not depend on cloud sync. A trip you choose to publish, and the photos attached to it, are uploaded to our server even when cloud sync is off — that is what publishing means. New trips are private by default, and a private trip is uploaded only when cloud sync is on.
The app sends crash reports, app-hang and watchdog-termination events, session start/stop records and a 10 % sample of performance traces to Sentry (Functional Software, Inc.), acting as our data processor. Events are ingested and stored in Sentry's European region (ingest.de.sentry.io).
Each event carries: your account identifier (a UUID — no name, no email), an installation identifier generated by the SDK, device model, OS version, free memory, battery level, locale, calendar and time-zone name, and a trail of network requests in redacted form — the method, the status code, and the shape of the URL, with query strings, fragments and every identifier inside the path removed before the event leaves the device.
We do not send screenshots, view hierarchies, session replays, performance profiles, request or response bodies, file paths, access tokens, or your home location. The device-and-app hash that the SDK derives from Apple's identifierForVendor is removed before sending as well.
Diagnostics are sent in both modes, including guest mode, and they do not depend on cloud sync; the app has no separate switch for them. Legal basis: legitimate interest (GDPR Art. 6(1)(f)) in keeping the app working. Retention: events are deleted automatically once the retention period configured in our Sentry organisation expires. To object, write to privacy@trip-track.app.
For users in the European Economic Area, the United Kingdom, and jurisdictions with similar rules, we process each data category on the following lawful bases (GDPR Art. 6):
| Data | Purpose | Legal basis |
|---|---|---|
| Apple user ID, account UUID, device UUID | Create and authenticate your account | Contract — Art. 6(1)(b) |
| Email, display name | Account identification, social features, account recovery | Contract — Art. 6(1)(b) |
| GPS trips (uploaded on opt-in) | Deliver the sync service you enabled | Contract — Art. 6(1)(b) |
| Photos (file metadata stripped) | Deliver the sync service | Contract — Art. 6(1)(b) |
| Public profile, follows, reactions, trip shares | Deliver social features you enabled | Contract — Art. 6(1)(b) |
| Crash, performance and session diagnostics (§3.5) | Find and fix defects; keep the app working | Legitimate interests — Art. 6(1)(f) |
| Server access logs, IP addresses, abuse-report records | Security, abuse prevention, accountability | Legitimate interests — Art. 6(1)(f), Recital 49 |
| Account-deletion audit record (timestamp + opaque hash only) | Demonstrate compliance with Art. 17 requests | Legal obligation + legitimate interests — Art. 6(1)(c)+(f) |
We do not rely on consent as a legal basis for the core service. Using a feature (tapping Record, enabling cloud sync, making your profile public) is your affirmative action to use that feature under Art. 6(1)(b). This is intentional — it means there is no ambiguous "consent withdrawal" question for core features; you simply disable the feature and processing stops.
Precise location and special category data. GPS coordinates are not special-category data under GDPR Art. 9 per se. We do not derive, infer, or cluster users by visited-place type (e.g., health, religion, sexuality). We do not run machine-learning inference on trip coordinates. If our practice changes, this policy will be updated in advance.
The following parties process data on our behalf or alongside us. Sentry does so from the first launch, in guest mode too; the others only once you sign in or turn cloud sync on:
We do not sell or share your personal information. There are no advertising or tracking SDKs in the app, no advertising networks, and no cross-app or cross-site tracking. We use exactly one third-party SDK, and it is diagnostic: Sentry (§3.5). It also records session starts and stops, which amounts to a count of app launches — so we no longer claim that we run no analytics at all. We do not share data with advertisers. We do not use your content to train machine-learning models.
Diagnostic events (§3.5) are ingested and stored in Sentry's European region and are not transferred outside it by us; Sentry itself is a US-headquartered company, and our processing is governed by its Data Processing Addendum.
Our primary hosting is in the European Economic Area. Photo storage on Cloudflare R2 uses an EU-jurisdiction bucket; however, as a US-headquartered company, Cloudflare is subject to US law. We rely on Cloudflare's EU-US Data Privacy Framework certification and Standard Contractual Clauses as transfer mechanisms. Sign in with Apple authentication routes through Apple Inc. (United States) under the EU-US DPF. If you are in a jurisdiction with stricter cross-border rules, using cloud sync constitutes your informed consent to this transfer.
Depending on your jurisdiction, you have the following rights:
We respond to verified requests within 30 days.
No system is perfectly secure. If you believe your account has been compromised, contact us immediately.
TripTrack is directed to adults and is not intended for children. The minimum age to use the App is 16 (matching the strictest GDPR Art. 8 threshold across EU member states). We do not knowingly collect personal data from children under 13 in the United States (COPPA), and will delete any account we learn belongs to a user under 13. If you believe a child has provided us with personal data, please contact us for prompt removal.
California (CCPA/CPRA). We do not sell or share your personal information as defined by California law. We do not use personal information for cross-context behavioral advertising. If you are a California resident, you may contact us to exercise rights to know, delete, correct, or access your data. We will verify your identity via the email on file.
Nevada (SB 220). Nevada residents may opt out of any future sale of their covered personal information by emailing privacy@trip-track.app. We currently do not sell personal information.
Washington (My Health My Data Act). Precise location data collected by the App may, in some cases, incidentally reveal visits to health-related facilities (e.g., a medical office, gym). To the extent any such data is classified as "consumer health data" under Washington law: (a) we collect it only when you actively record a trip; (b) we do not sell it; (c) we do not share it with advertisers; (d) we do not geofence health-facility locations; (e) you can delete it at any time by deleting the relevant trip or your account. Before any material change to this practice, we will obtain your separate opt-in consent. To exercise rights under RCW 19.373, email privacy@trip-track.app.
Other US states (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, etc.). Residents of states with comprehensive privacy laws have rights similar to California's under their respective statutes. To exercise any such right, email privacy@trip-track.app.
We may update this Privacy Policy from time to time. Material changes will be announced in the app or by email. The "Last updated" date at the top always reflects the current version.
Questions, complaints, or data subject requests: