🛡️ The one-sentence summary: we keep the minimum needed for the app to work, your alert's position is blurred on the map and your name never appears next to an alert.
Who is the controller
Adriano operates Radar Rider as an individual and is the data controller, based in Ireland. The official contact for any privacy matter — access, correction, erasure or complaints — is contato@radarrider.com, a monitored mailbox.
What data we collect
- Your account: public name, e-mail, phone and your password stored irreversibly as a hash (even we cannot read it).
- Your alerts: category, description, when it happened and the location.
- Your location: only read when you publish an alert, confirm someone else's alert or tap "My location". The app does not track you in the background.
- Confirmations and reports you make about other people's alerts.
- Push notifications: if you enable them, we keep your browser's subscription and the chosen country (Ireland or the United Kingdom), to notify you about alerts in that country. You can disable them whenever you want.
- Technical data: IP address, browser, device and error or security logs may appear in the hosting logs.
- Installation count: when the app is installed on a device, we only record the date and the country — so we know how many installations there were. We do not keep who installed it, nor any device identifier: there is no way to link that number to you.
Today we do not collect profile photos, uploaded images, contact lists, advertising data or analytics. If that changes, this policy and the consent options will be updated in advance.
What happens to your location
This is the most important part of the app, so it is explained in detail. When you publish an alert, we keep two coordinates:
- The public one, rounded to an area of about 100 metres. It is the only one that goes to the map, the app and anyone else.
- The exact one, which is stored and never leaves the site in any response. It exists only so moderation can act when someone uses the app to stalk or intimidate another person, and to respond to a lawful police request. It is deleted 7 days after the alert leaves the map.
The blur is done on our server, not on your phone. This stops someone from tampering with the app to publish an alert pointing at another person's front door.
Why we can use this data
- Performance of contract: your account and your alerts — without them the app cannot work.
- Consent: your location and push notifications. The browser asks first, and you can refuse or withdraw any of them in your device settings at any time. Without location you can read the map, but you cannot publish or confirm.
- Legitimate interest: moderation, abuse prevention and publishing limits — keeping the map trustworthy for the rider community.
Who we share it with
We do not sell your data and we do not run ads. We only use:
- Hostinger — hosting of the site, the database and the sending of our e-mails (account confirmation and password recovery).
- CARTO and OpenStreetMap — the map images. When the map loads, your IP address reaches these services, as happens with any image a website loads.
- Your browser's push service (Google or Mozilla, for example) — only if you enable notifications. It is the one that delivers the message to your device.
We may also disclose data to authorities when we are legally obliged to do so.
Internal access is limited to the operator and authorised moderators, only when needed for support, security, moderation or to comply with a legal obligation. Providers process the data only to provide their service.
International transfers
Some map or infrastructure providers may process data outside the European Economic Area or the United Kingdom. Where applicable, we rely on the transfer safeguards required by the GDPR and the UK GDPR — such as the Standard Contractual Clauses, with the UK addendum where relevant — and we assess the provider before using it.
How long we keep data
- Alerts, confirmations and reports: the alert leaves the map after 1 to 12 hours, the exact location is deleted 7 days later, and the records are removed within 12 months.
- Account: for as long as it exists. On deletion, we immediately remove the direct identifiers — including your phone — and keep only anonymised records for their retention period.
- Buy Me a Coffee: only if you tap "Support". The link opens an external site, subject to its own privacy policy.
- E-mail tokens: up to 30 days after use or expiry.
- Moderation actions: up to 12 months.
Your rights
Under the GDPR (and the UK GDPR, if you are in the United Kingdom) you can request: access to your data, correction, erasure, portability, restriction of processing and objection to processing. When processing is based on consent, you can withdraw it at any time, without affecting what was already done before. Just write to contato@radarrider.com — we usually reply within a month. You can also use the Your GDPR rights page.
If you believe we have processed your data incorrectly, you can complain to the authority in your country: the Data Protection Commission in Ireland, or the Information Commissioner's Office (ICO) in the United Kingdom.
Minimum age
Radar Rider is only for adults aged 18 or over. We do not allow accounts of children or teenagers and we remove any account identified as such.
Automated decisions and the duty to provide data
We do not take decisions with legal effect by algorithm alone. E-mail, public name, phone and password are required to create an account; GPS is optional to view the map, but required to publish or confirm an alert. You can refuse the GPS permission on your device.
Changes to this policy
If we change something relevant, we update the date at the top of this page and let you know inside the app.