Legal information
Privacy Policy
This policy explains what data RideArrow processes, why it is processed, who may receive it, and the rights available to you.
Effective 22 July 2026 · Last updated 5 September 2026
1. Data controller
The controller of personal data processed through the RideArrow application is:
2. Scope
This policy applies to the RideArrow application for iOS and Android, its cloud features, RideArrow accounts, and the related data-management portal. It does not govern third-party services used separately outside RideArrow.
3. Data we process
Account and authentication
- Firebase user identifier and whether the account is anonymous, linked to Apple or Google, or uses email sign-in,
- for Apple or Google sign-in, the name and email address made available by the provider and authentication data needed to verify the login,
- for an email account, the email address, verification state, and security data managed by Firebase Authentication,
- Free, Lite, or Full access tier.
RideArrow never receives your Apple or Google password. Email-account passwords are processed by Firebase Authentication in securely hashed form; neither the operator nor the app can read the original password.
Location, search, and navigation
- precise or approximate location, bearing, speed, altitude, and GPS accuracy,
- origin, destination, intermediate stops, search terms, and calculated route,
- navigation progress, maneuvers, off-route status, and arrival.
Location is processed during an active ride or navigation session. If a ride or navigation remains active while the screen is locked or another app is visible, RideArrow uses the operating system’s background-location mechanism. Android displays a persistent foreground-service notification; iOS displays its system location-use indicator.
Place search is presented through the official Google Places UI Kit. Google displays the place name, address, and required Google Maps attribution inside that component. After you select a result, RideArrow uses its place ID and coordinates to place a point on the RideArrow map. RideArrow stores your own search text as its label instead of copying the Google place name or address.
Selected destinations may be kept only in a recent-destinations list on that device. Search history is never included in RideArrow cloud backup. Each complete history entry—including the search text, place ID, and coordinates—is automatically removed 30 days after its last use, or earlier when you clear the list.
Shared destinations and routes
When you deliberately share a destination or planned route, RideArrow sends its title, points and geometry, and the preferences needed to recalculate it to Firebase and Google Cloud. RideArrow creates a random link that can be opened by anyone you give it to while it remains valid. The link does not contain your name or email address, but the route itself may reveal places you visited or plan to visit. Do not publish the link if you do not want those details available to others.
Ride Log and ride telemetry
When you save a ride, RideArrow may record timestamps, GPS track, distance, duration, speed, acceleration and g-force, lean angle, altitude, bearing, GPS accuracy and satellite count, battery status and device temperature, mobile network type and signal strength, and navigation state. We do not access call content, contacts, messages, your phone number, or call history.
Settings and layouts
We process your selected language, measurement system, appearance, voice preferences, widget configuration, saved layouts, and cloud-backup and diagnostics preferences.
Subscriptions
We process the product ID, transaction or purchase token, subscription state and expiry, and a pseudonymized account identifier. We do not receive card details or full payment information; Apple processes App Store payments and Google processes Google Play payments.
Diagnostics and performance
If you enable “Share diagnostics” in Profile, Firebase may process app interactions, aggregate ride measurements, performance, crashes, error details, app version, device model, operating-system version, network information, and installation identifiers. Our diagnostic events never include coordinates, destination names, search text, or route geometry. This setting is disabled by default.
Advertising and consent
Anonymous and Free tiers may display Google AdMob banners. Depending on your consent, Google may process advertising identifiers, IP address, network-derived approximate location, ad interactions, and diagnostics to serve, measure, and possibly personalize ads. RideArrow does not send precise GPS tracks, destinations, or Ride Log data to AdMob. Where required in your region, advertising choices can be changed in Profile. Lite and Full do not display ads.
Application security
Firebase App Check, Apple App Attest, and Google Play Integrity may process technical information and integrity tokens to confirm that requests come from a genuine application, protect APIs, and prevent abuse.
4. Purposes and legal bases
- Providing the service and performing a contract: account, dashboard, ride recording, route calculation, navigation, synchronization, and subscriptions.
- Your consent: location permission, optional diagnostics, cloud backup, and personalized advertising where consent is required. Consent can be withdrawn in the app or the iOS or Android settings.
- Legitimate interests: service security, fraud prevention, troubleshooting, and protection of our systems where your rights do not override those interests.
- Legal obligations: information we must retain under accounting, tax, or other applicable laws.
5. Local and cloud storage
Ride records, preferences, and search history are first stored on the device. Search history remains device-local, is excluded from RideArrow cloud backup, and expires after 30 days. Android system backup for RideArrow is disabled; on iOS, local app data may be included in the user’s encrypted device backup according to their Apple settings. Signed-in users can disable RideArrow cloud backup in Profile. Signed-in accounts synchronize settings and layouts; Lite and Full may also synchronize saved rides, GPS tracks, and detailed telemetry. RideArrow cloud backup runs at most once per day.
Cloud backups, subscription records, and shared routes use Firebase and Google Cloud, including an SQL database in europe-central2. Some supporting Google services may process data outside the European Economic Area subject to applicable transfer safeguards.
6. Recipients
We do not sell personal data. The following providers may process data where necessary:
- Google Firebase and Google Cloud — authentication, cloud functions, SQL backup, optional diagnostics, and security,
- Google Maps Platform — place search through the official Places UI Kit; use of Google Maps Platform is subject to the Google Maps Platform Terms and Google Privacy Policy,
- OpenStreetMap contributors, Protomaps, MapLibre, Valhalla, and Cloudflare R2 — RideArrow map rendering, map-data delivery, and route calculation,
- Google AdMob and User Messaging Platform — ads and consent management for Anonymous and Free tiers,
- Apple — App Store distribution and subscriptions, Sign in with Apple, and App Attest integrity verification on iOS,
- Google Play — Android distribution, subscriptions, and integrity verification.
We may disclose information to public authorities where legally required or where necessary to protect users, our rights, and our systems.
7. Retention
- local data remains on the device until you delete it, clear app storage, or uninstall RideArrow,
- cloud settings, layouts, and rides are retained while the account exists or until deleted; search history is not sent to this cloud storage,
- every local search-history entry is automatically removed 30 days after its last use,
- a shared route remains available through its link for no longer than 30 days and expired records are removed regularly; deleting an account also removes its active shared routes,
- technical deletion markers without ride content may be kept temporarily to synchronize deletions,
- diagnostic and advertising data follows your settings and the applicable Google service retention rules,
- minimum purchase or security records may be retained for legally required periods or as necessary to prevent fraud and resolve disputes.
8. Your rights and account deletion
Subject to applicable law, you may request access, correction, portability, restriction, objection, or deletion and may withdraw consent. You may also lodge a complaint with the Slovak Data Protection Authority or your local supervisory authority.
You can delete your RideArrow account and associated cloud data through the app or the secure portal. Account deletion does not automatically cancel an App Store or Google Play subscription; cancel automatic renewal in the applicable store before deleting the account.
You can also email info@jsoft.sk. We may request reasonable identity verification to protect the account.
9. Security
We use HTTPS encryption in transit, Firebase Authentication, App Check, Apple App Attest, Google Play Integrity, account-scoped authorization, and server-side storage for secret API keys. Cleartext traffic is disabled. No system can nevertheless be guaranteed entirely risk-free.
10. Children
RideArrow is not directed to children, and we do not knowingly collect data from children below the age at which they can independently consent under the laws of their country.
11. Changes and contact
We may update this policy when features or legal requirements change. The current version and date will remain available here. Contact JSoft s.r.o. at info@jsoft.sk with privacy questions.