Privacy
Privacy policy
1. Who is responsible
The controller is Vegvísir Hugbúnaðarlausnir ehf., registration number 490626-2040, Akrakór 7, 203 Kópavogur, Iceland. Telephone: +354 778 9654. For privacy questions or requests, email privacy@taptraffic.app.
2. What Vegvísir does
Vegvísir helps you plan regular drives and gives departure and route advice. With your optional consent, it can learn regular drives from precise location and motion data, including data collected while the app is closed or not in use. The beta is for known adults invited by us; it is not a public launch or official city pilot.
3. Information we process
Account and security data
- Guest accounts: a pseudonymous account identifier, a hash of the secret held on your device, language, timezone and security/session metadata. We cannot identify a guest by email unless they later add one.
- Email accounts: your normalized email address, single-use login-code records and the same account/session metadata.
- Access and rotating refresh sessions, device/installation identifiers, user agent, coarse account activity timestamps, IP-derived rate-limit records and request-security metadata.
Access tokens last 60 minutes. Refresh sessions roll for up to 90 days and rotate when used.
Information you provide
- Saved places, including home, work and other labels, addresses and coordinates.
- Declared trips, origins, destinations, schedule, arrival windows and flexibility.
- Language, timezone, notification preferences, consent and onboarding settings.
Optional precise trip-data collection
When Trip data collection is enabled, the app may collect precise GPS position, timestamp, accuracy, speed, heading and altitude; motion/activity signals; visit transitions; battery and device/app metadata; detected trip sessions; and recorded route traces. Collection can continue while the app is closed or not in use so regular drives can be detected. Samples may be held temporarily in the device sandbox before authenticated upload.
Information generated by the service
Vegvísir may derive visits, detected and inferred trips, map-matched paths, frequent places, learned travel patterns, typical times and durations, predicted trips, recommendations, suggestion feedback and recommendation outcomes.
Notifications, usage and diagnostics
We process push tokens, notification preferences, notification/inbox and delivery history. We accept a small fixed set of beta usage events, such as opening the app or a notification, viewing advice, starting tracking or accepting a suggestion. Sentry receives scrubbed crash diagnostics such as stack traces and device/app details. Our filters are designed to remove precise coordinates, addresses, credentials, tokens, provider paths and raw error text before diagnostics leave the app or API.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Create and operate your guest or email account, save your declared plan, provide routes and departure advice, and deliver settings you request. | Contract — GDPR Article 6(1)(b). |
| Collect precise background location and motion and learn visits, trips, frequent places and patterns from it. | Your consent — Article 6(1)(a). Consent is optional and withdrawable in the app. |
| Prevent abuse, secure sessions, diagnose failures and keep the beta reliable. | Our legitimate interests — Article 6(1)(f), balanced against tester privacy and limited through minimisation and scrubbing. |
| Measure minimal beta usage so we can determine whether core functions work. | Our legitimate interests — Article 6(1)(f). We do not use advertising analytics. |
We do not sell personal data, use it for advertising, actively share it with employers, or publish cross-user optimiser results. If those product boundaries change, we will update the policy and establish the necessary basis and safeguards first.
5. Providers
| Provider | Purpose and data |
|---|---|
| Render | Frankfurt API, worker, PostgreSQL database, service logs, backups and logical recovery exports. |
| Google Maps Platform | Place search, geocoding and place details; queries, place identifiers and relevant coordinates. |
| TomTom | Routing, traffic estimates and map matching; route endpoints, timing and route/trace coordinates when required. |
| Apple MapKit | Map presentation and opening directions on supported Apple devices where applicable. |
| Expo, APNs and FCM | Push registration and delivery; push token, platform and notification content. |
| Sentry | Scrubbed mobile and API crash/error diagnostics. |
| Resend | Email sign-in codes, privacy-request delivery and inbound privacy email. |
| Vercel | This public website and its privacy-request functions. |
| Healthchecks | Content-free scheduled-worker heartbeat identifiers and timestamps. |
6. International transfers
The main beta API and database are intended to run in Frankfurt, Germany. Some providers are headquartered or may provide support outside the EEA. Where personal data is transferred outside the EEA, we use the provider agreement and an applicable transfer mechanism, such as an adequacy decision, the EU–US Data Privacy Framework where valid for that provider, or European Commission Standard Contractual Clauses, together with appropriate supplementary safeguards. We maintain an internal provider and transfer register.
7. Retention
| Information | Retention |
|---|---|
| Raw location and motion | 90 days. |
| Visits, detected-trip sessions, recorded traces, frequent places and learned travel patterns | Until Delete My Data or account deletion. |
| Saved places, declared trips and account settings | Until you remove them or delete the account. |
| Inactive guest account and everything associated with it | Deleted after 180 days without successful authentication, unless an unexpired non-revoked refresh session remains. |
| Minimal usage, notification/dispatch and route-sampling history | Generally 90 days; internal optimiser run rows are 30 days. Cross-user publishing remains disabled. |
| Expired/consumed login codes and expired/revoked session artifacts | Removed after a seven-day cleanup window. |
| Render service logs | Seven days on the selected beta service plan. |
| Render PostgreSQL point-in-time recovery | Three days. |
| Render logical exports | Seven days after creation. |
| Resend email data | 30 days. |
| Sentry diagnostics | No longer than 90 days; the exact active project setting is recorded and checked before tester access. |
Deletion takes effect in the live application database immediately when completed. Encrypted recovery copies may retain deleted data until the applicable three- or seven-day recovery period expires; they are not restored as ordinary live data. A restore procedure requires deletion requests completed after the restored point to be replayed before service resumes.
8. Your controls and rights
Withdraw consent
Turn off Trip data collection in Account. This stops further collection but does not erase existing data.
Delete My Data
This deletes collected trip data and learned information while keeping your account, saved places, declared trips, preferences and session. Account/security metadata such as the last successful authentication remains until account deletion.
Delete Account
This removes the account and all directly and indirectly associated application data. In-app deletion is immediate and preferred. Email-account users can also use our web request page.
You may request access, correction, erasure, restriction, portability or object to legitimate-interest processing. Email us or use the request form. We verify ownership through the claimed account email and normally respond within one month. Do not send identity documents, passwords, guest secrets or tokens.
9. Guests
A guest is known only by the secret held on their device. We cannot locate a guest account from an email address. Guests should use in-app deletion while they retain the device. A lost inactive guest and all associated data are deleted after 180 days. Using an old guest secret after expiry may create a new empty account; deleted data is never recovered.
10. Profiling and decisions
Vegvísir profiles travel patterns to make optional recommendations. You can ignore them. The beta does not make decisions with legal or similarly significant effects and does not use Article 22 automated decision-making.
11. Adults only
The invitation beta is intended only for adults whom we know and invite. It is not directed at children, and there is no public self-service enrollment or in-app age gate during this controlled beta.
12. Complaints and contact
Contact privacy@taptraffic.app. You also have the right to complain to Persónuvernd, the Icelandic data protection authority.