1. Information We Collect
1.1 Location Data
Our primary function is GPS tracking, so we collect:
- Real-time location data: GPS coordinates, altitude, speed, and direction
- Location history: Your movement patterns and routes during activities
- Geofencing data: When you enter or exit designated areas or checkpoints
- Precision data: GPS accuracy measurements and signal strength
1.2 Personal Information
When you register or use our services, we may collect:
- Name, phone number, and email address
- Profile information (age, gender, height, weight) - optional
- Profile photos - optional
- Athletic performance data and statistics
- Device identifiers and push notification tokens
1.3 Technical Data
We automatically collect certain technical information:
- Device type, operating system, and app version
- IP address and network information
- App usage patterns and crash reports
- Battery level and device performance data
1.4 Activity Data
During your activities, we collect:
- Start and end times of activities
- Distance traveled and duration
- Pace, speed, and elevation changes
- Checkpoint and waypoint data
- Pause and resume events
2. How We Use Your Information
2.1 Primary Services
- Provide real-time GPS tracking and navigation
- Enable live monitoring by authorized users (coaches, event organizers)
- Generate activity reports and performance analytics
- Send location-based notifications and alerts
- Facilitate athlete-tracker relationships through QR codes
2.2 Communication
- Send push notifications about activity status
- Provide customer support and technical assistance
- Send important updates about the service
- Respond to your inquiries and feedback
2.3 Improvement and Analytics
- Analyze usage patterns to improve our services
- Optimize GPS accuracy and battery performance
- Debug technical issues and prevent fraud
- Develop new features and functionality
3. Information Sharing and Disclosure
3.1 Authorized Users
Your location data is shared with:
- Users you've authorized through QR code scanning
- Event organizers when you participate in organized activities
- Coaches or support crew members you've granted access to
- Emergency contacts in safety-critical situations
3.2 Service Providers
We may share data with trusted third-party service providers who help us operate our services:
- Cloud hosting and data storage providers
- Push notification services (Firebase Cloud Messaging)
- Analytics and crash reporting services
- Customer support platforms
3.3 Legal Requirements
We may disclose your information if required by law or to:
- Comply with legal processes or government requests
- Protect our rights, property, or safety
- Protect the rights, property, or safety of our users
- Investigate potential violations of our terms of service
4. Data Security
4.1 Security Measures
We implement industry-standard security measures to protect your data:
- Encryption of data in transit and at rest
- Secure server infrastructure with regular security updates
- Access controls and authentication mechanisms
- Regular security audits and vulnerability assessments
- Secure API endpoints with rate limiting
4.2 Data Breach Response
In the event of a data breach, we will:
- Promptly investigate and contain the breach
- Notify affected users within 72 hours when possible
- Report to relevant authorities as required by law
- Take steps to prevent similar incidents
5. Data Retention
We retain your data as follows:
- Location data: Retained for the duration of your account plus 2 years for safety and legal purposes
- Profile information: Retained until you delete your account
- Activity history: Retained for 5 years or until account deletion
- Technical logs: Retained for 1 year for debugging and security purposes
6. Your Rights and Choices
6.1 Access and Control
You have the right to:
- Access your personal data and download your information
- Correct inaccurate or incomplete information
- Delete your account and associated data
- Restrict processing of your data in certain circumstances
- Object to processing based on legitimate interests
6.2 Location Permissions
You can control location access through your device settings:
- Enable/disable location services for the app
- Choose between "Always" and "While Using App" permissions
- View and manage location history
- Revoke access to specific users or events
6.3 Communication Preferences
- Opt out of marketing communications
- Manage push notification settings
- Choose which types of alerts to receive
7. Children's Privacy
For users between 13-18 years old:
- Parental consent may be required in certain jurisdictions
- Additional privacy protections may apply
- Limited data sharing capabilities
8. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place:
- Standard contractual clauses for data transfers
- Adequacy decisions by relevant authorities
- Certification schemes and codes of conduct
9. Third-Party Services
Our app may integrate with third-party services:
- Mapping services: For displaying maps and routes
- Social media: For sharing achievements (if enabled)
- Analytics: For app performance monitoring
- Cloud storage: For data backup and synchronization
Each third-party service has its own privacy policy, which we encourage you to review.
10. Cookies and Tracking Technologies
We use limited tracking technologies:
- Session identifiers: To maintain app functionality
- Device identifiers: For push notifications and support
- Analytics cookies: To understand app usage (can be disabled)
- Crash reporting: To identify and fix technical issues
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do:
- We will notify you through the app or by email
- The updated policy will be posted on our website
- Continued use constitutes acceptance of changes
- Material changes will require explicit consent
12. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
- Email: privacy@maprabbit.app
- Website: https://maprabbit.app
- Data Protection Officer: dpo@maprabbit.app
12.1 Data Subject Requests
To exercise your privacy rights, please include:
- Your full name and registered phone number
- Specific request (access, deletion, correction, etc.)
- Verification of identity for security purposes
- Preferred method of response
13. Jurisdiction-Specific Rights
13.1 European Union (GDPR)
If you are in the EU, you have additional rights under GDPR:
- Right to data portability
- Right to lodge a complaint with supervisory authorities
- Right to withdraw consent at any time
- Right to be forgotten in certain circumstances
13.2 California (CCPA)
California residents have rights under CCPA:
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of sale (we don't sell data)
- Right to non-discrimination for exercising rights