Privacy

Privacy policy

Version 1.0-betaEffective 6 August 2026
This policy covers the invitation-only Vegvísir beta. Cross-user coordination, employer features and publishing from the citywide optimiser are not active for beta users.

1. Who is responsible

The controller is Vegvísir Hugbúnaðarlausnir ehf., registration number 490626-2040, Akrakór 7, 203 Kópavogur, Iceland. Telephone: +354 778 9654. For privacy questions or requests, email privacy@taptraffic.app.

2. What Vegvísir does

Vegvísir helps you plan regular drives and gives departure and route advice. With your optional consent, it can learn regular drives from precise location and motion data, including data collected while the app is closed or not in use. The beta is for known adults invited by us; it is not a public launch or official city pilot.

3. Information we process

Account and security data

Access tokens last 60 minutes. Refresh sessions roll for up to 90 days and rotate when used.

Information you provide

Optional precise trip-data collection

When Trip data collection is enabled, the app may collect precise GPS position, timestamp, accuracy, speed, heading and altitude; motion/activity signals; visit transitions; battery and device/app metadata; detected trip sessions; and recorded route traces. Collection can continue while the app is closed or not in use so regular drives can be detected. Samples may be held temporarily in the device sandbox before authenticated upload.

Information generated by the service

Vegvísir may derive visits, detected and inferred trips, map-matched paths, frequent places, learned travel patterns, typical times and durations, predicted trips, recommendations, suggestion feedback and recommendation outcomes.

Notifications, usage and diagnostics

We process push tokens, notification preferences, notification/inbox and delivery history. We accept a small fixed set of beta usage events, such as opening the app or a notification, viewing advice, starting tracking or accepting a suggestion. Sentry receives scrubbed crash diagnostics such as stack traces and device/app details. Our filters are designed to remove precise coordinates, addresses, credentials, tokens, provider paths and raw error text before diagnostics leave the app or API.

4. Purposes and legal bases

PurposeLegal basis
Create and operate your guest or email account, save your declared plan, provide routes and departure advice, and deliver settings you request.Contract — GDPR Article 6(1)(b).
Collect precise background location and motion and learn visits, trips, frequent places and patterns from it.Your consent — Article 6(1)(a). Consent is optional and withdrawable in the app.
Prevent abuse, secure sessions, diagnose failures and keep the beta reliable.Our legitimate interests — Article 6(1)(f), balanced against tester privacy and limited through minimisation and scrubbing.
Measure minimal beta usage so we can determine whether core functions work.Our legitimate interests — Article 6(1)(f). We do not use advertising analytics.

We do not sell personal data, use it for advertising, actively share it with employers, or publish cross-user optimiser results. If those product boundaries change, we will update the policy and establish the necessary basis and safeguards first.

5. Providers

ProviderPurpose and data
RenderFrankfurt API, worker, PostgreSQL database, service logs, backups and logical recovery exports.
Google Maps PlatformPlace search, geocoding and place details; queries, place identifiers and relevant coordinates.
TomTomRouting, traffic estimates and map matching; route endpoints, timing and route/trace coordinates when required.
Apple MapKitMap presentation and opening directions on supported Apple devices where applicable.
Expo, APNs and FCMPush registration and delivery; push token, platform and notification content.
SentryScrubbed mobile and API crash/error diagnostics.
ResendEmail sign-in codes, privacy-request delivery and inbound privacy email.
VercelThis public website and its privacy-request functions.
HealthchecksContent-free scheduled-worker heartbeat identifiers and timestamps.

6. International transfers

The main beta API and database are intended to run in Frankfurt, Germany. Some providers are headquartered or may provide support outside the EEA. Where personal data is transferred outside the EEA, we use the provider agreement and an applicable transfer mechanism, such as an adequacy decision, the EU–US Data Privacy Framework where valid for that provider, or European Commission Standard Contractual Clauses, together with appropriate supplementary safeguards. We maintain an internal provider and transfer register.

7. Retention

InformationRetention
Raw location and motion90 days.
Visits, detected-trip sessions, recorded traces, frequent places and learned travel patternsUntil Delete My Data or account deletion.
Saved places, declared trips and account settingsUntil you remove them or delete the account.
Inactive guest account and everything associated with itDeleted after 180 days without successful authentication, unless an unexpired non-revoked refresh session remains.
Minimal usage, notification/dispatch and route-sampling historyGenerally 90 days; internal optimiser run rows are 30 days. Cross-user publishing remains disabled.
Expired/consumed login codes and expired/revoked session artifactsRemoved after a seven-day cleanup window.
Render service logsSeven days on the selected beta service plan.
Render PostgreSQL point-in-time recoveryThree days.
Render logical exportsSeven days after creation.
Resend email data30 days.
Sentry diagnosticsNo longer than 90 days; the exact active project setting is recorded and checked before tester access.

Deletion takes effect in the live application database immediately when completed. Encrypted recovery copies may retain deleted data until the applicable three- or seven-day recovery period expires; they are not restored as ordinary live data. A restore procedure requires deletion requests completed after the restored point to be replayed before service resumes.

8. Your controls and rights

Withdraw consent

Turn off Trip data collection in Account. This stops further collection but does not erase existing data.

Delete My Data

This deletes collected trip data and learned information while keeping your account, saved places, declared trips, preferences and session. Account/security metadata such as the last successful authentication remains until account deletion.

Delete Account

This removes the account and all directly and indirectly associated application data. In-app deletion is immediate and preferred. Email-account users can also use our web request page.

You may request access, correction, erasure, restriction, portability or object to legitimate-interest processing. Email us or use the request form. We verify ownership through the claimed account email and normally respond within one month. Do not send identity documents, passwords, guest secrets or tokens.

9. Guests

A guest is known only by the secret held on their device. We cannot locate a guest account from an email address. Guests should use in-app deletion while they retain the device. A lost inactive guest and all associated data are deleted after 180 days. Using an old guest secret after expiry may create a new empty account; deleted data is never recovered.

10. Profiling and decisions

Vegvísir profiles travel patterns to make optional recommendations. You can ignore them. The beta does not make decisions with legal or similarly significant effects and does not use Article 22 automated decision-making.

11. Adults only

The invitation beta is intended only for adults whom we know and invite. It is not directed at children, and there is no public self-service enrollment or in-app age gate during this controlled beta.

12. Complaints and contact

Contact privacy@taptraffic.app. You also have the right to complain to Persónuvernd, the Icelandic data protection authority.