// Legal

PRIVACY POLICY

Last updated: September 7, 2026

01

WHO WE ARE

Rmaps (“Rmaps”, “we”, “us”) is a motorcycle and rider companion app that lets you record rides, navigate, share your live location with friends and crew, and request help in an emergency. This Privacy Policy explains what we collect, why, who we share it with, and the choices you have.

Rmaps is operated by Wildcat Devs. For questions or requests, contact us at team.wildcatdevs@gmail.com.

02

DATA WE COLLECT

We only collect what the app's features need. We do not sell your data, do not use it for advertising, and do not share it with data brokers or use it for cross‑app tracking.

  • Account & contact — Email, name, username, phone number, optional gender and avatar. Used to create and secure your account, show you to friends and crew, and let contacts find you in emergencies.
  • Precise location — GPS coordinates, speed, heading, and altitude — in the foreground and background. Used for ride recording, trip metrics, live group‑ride and friend location sharing, and emergency SOS.
  • Emergency contacts — Names and phone numbers you add, including ones imported from your device address book. Used to notify or contact people you choose in an emergency.
  • Photos — Images you attach — avatar, group gallery, vehicle photos, receipts, SOS evidence — used only for the feature you used them for.
  • Messages & content you create — Group‑ride and live‑ops messages, SOS chat, direct messages, and ride notes. Used to deliver messaging and SOS features.
  • Vehicle, ride & expense data — Vehicles, recorded ride sessions and routes, fuel and service logs and their costs. Used for Garage, ride history, metrics, and cost tracking.
  • Diagnostics — Crash and error logs, performance and hang metrics, a short breadcrumb trail, device model, OS version, app version, and approximate country. Used to keep the app stable and debug problems.
  • Documents you save (Doc Vault) — photos and details of documents you choose to store — registration, licence, IDP, insurance, PUC — including any document number you type. They stay on your device unless you switch on cloud backup, which is off by default; if you do, the document number and any notes are stored encrypted on our servers.
  • Road‑condition observations — after a ride ends, short measurements of the road surface: where you slowed sharply, motion‑sensor impulses while your phone is mounted, and a roughness reading per ~50 m — each with its coordinates, direction, speed, time and vehicle type. Used to warn other riders about speed humps and rough road. On by default; you can turn it off.
  • Network address — your IP address on requests to our servers, and the approximate country, region and city we derive from it. Used for rate limiting, abuse prevention and security, and to understand roughly where the app is used. We store the IP itself alongside diagnostic logs and password‑reset requests; on your account we keep only the derived approximate place.
  • Identifiers — Account ID, a per‑device ID, and push‑notification token. Used to operate the service and send notifications.

We do not record audio, and we do not access photos beyond the images you pick through the system photo picker or capture with the camera.

On road‑condition observations: we upload the derived measurements above, not your recorded track — and only once, after a ride has finished, never live. A hazard that ends up on the map is built from several different riders' observations and is published with no author, so a speed hump on the map is not attributable to you or to anyone else. Rides you record as “Other Transport” (flight, bus, train) contribute nothing.

Data we derive: some of what we hold is inferred rather than collected — a riding profile (typical distances, pace, surface and terrain preferences, and a home region) computed from your recorded rides and used to suggest group rides that suit you; whether you currently appear to be away from your usual country; and whether the country from your GPS and the country from your IP address disagree, which we treat as a rough signal that a VPN is in use. Deleting your account deletes all of it.

03

HOW WE USE YOUR DATA

  • Provide and operate the app's features — recording, navigation, live sharing, SOS, and chat.
  • Authenticate you and keep your account secure.
  • Send notifications you've enabled — ride invites, friend and crew activity, SOS, and alerts.
  • Understand how the app is used in aggregate — how many riders are active, which features get used — so we know what to build and fix.
  • Suggest group rides that match how you ride, using the riding profile described above.
  • Diagnose crashes and improve reliability and performance.
  • Comply with the law and protect users' safety and our rights.

What we never do: We do not sell your data. We do not use your data to serve you third‑party ads. We do not build ad profiles. Ever.

04

LOCATION, INCLUDING BACKGROUND

Some features collect location even when the app is closed or not in use:

  • Ride recording / metrics — while you're recording a trip.
  • Live group‑ride and friend sharing — while you choose to share.
  • Emergency SOS — while an SOS you started or accepted is active.

You control this via Settings → Location sharing (Off / On rides / While tracking). Sharing stops when you turn it off, end the ride, or resolve the SOS. You can revoke location access at any time in your device Settings — the app keeps working without background features. We request background location only after showing an in‑app disclosure and the system permission prompt.

05

HOW WE SHARE DATA

  • With other users you choose — your live location, messages, name, and avatar are shared with the friends, crew, or SOS responders you select. In an SOS, your precise location is shared with a responder only after you confirm them; others see only an approximate (~1 km) area.
  • Service providers — cloud hosting, push‑notification delivery, app delivery and crash tooling (Expo), and Google Maps Platform for maps, directions, and place search. These providers process data on our behalf under contract.
  • Links you create — a ride share link (/r/…), a group invite (/g/…) and an SOS share link (/sos/…) open a public web page that needs no account — anyone holding the link can open it. A live SOS link shows your name and your precise location for as long as that SOS is active, and stops showing the location once it is resolved or cancelled. Send these links only to people you mean to give access to.
  • Legal / safety — when required by law, or to protect the safety, rights, or property of users or the public.
  • Business transfers — as part of a merger, acquisition, or asset sale (with notice).

We do not sell personal data or share it for advertising or cross‑app tracking.

06

THIRD‑PARTY SERVICES

  • Google Maps Platform — maps, directions, and place search. Subject to Google's Privacy Policy and the Google Maps APIs terms.
  • Expo / EAS — app builds, over‑the‑air updates, and push notifications.
  • Hosting & observability — backend infrastructure and diagnostics.
07

DATA RETENTION

We keep account data while your account is active.

  • Live and operational data is short‑lived — live positions and emergency records are pruned on a rolling basis. When you switch location sharing off you stop being visible to friends immediately; your last recorded fix stays on your account until it is overwritten or the account is deleted.
  • Road‑condition observations — individual observations are deleted after 90 days. Only the anonymous, multi‑rider result — a hump or a rough stretch — is kept, and that is retired once riders stop encountering it.
  • Diagnostic logs — crashes, errors, breadcrumbs, and the IP address the report came from are kept while they are useful for debugging and deleted when they are not. We are moving this onto a fixed schedule; today they are removed by periodic purge rather than automatically.
  • Deleting your account — reversible for 7 days if you sign back in. After that your personal data is erased, and the remaining record is deleted within 30 days.

We delete or anonymise data when it is no longer needed, except where we must keep it to meet legal obligations.

08

SECURITY

We use industry‑standard measures — encrypted transport (HTTPS), hashed credentials, JWT authentication, and access controls. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.

09

YOUR CHOICES AND RIGHTS

Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of your data, and to object or withdraw consent. You can:

  • Edit your profile and manage sharing and notification settings in the app.
  • Contribute road conditions — turn this off in Settings to stop sending road‑condition observations. It is on by default; turning it off also clears the road hazards cached on your device. Hazard warnings themselves are unaffected.
  • Cloud backup for Vault — off by default. Documents you save stay on your device unless you switch it on.
  • Revoke camera, location, contacts, and notification permissions in device Settings.
  • Export your data — request a copy of what we hold from the data request page. We respond within 30 days.
  • Delete your account (which deletes associated personal data) from Settings → Account → Delete account, from this page, or by emailing team.wildcatdevs@gmail.com.

To exercise any other right, contact team.wildcatdevs@gmail.com. We will respond as required by applicable law.

10

CHILDREN

Rmaps is not intended for children under 13 or the minimum age in your region. We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

11

INTERNATIONAL TRANSFERS

Your data may be processed in countries other than yours. Where required, we use appropriate safeguards — such as Standard Contractual Clauses — for international transfers.

12

CHANGES TO THIS POLICY

We may update this policy. We'll revise the “Last updated” date and, for material changes, provide notice in the app or by other reasonable means.

13

CONTACT

For any privacy‑related questions or requests, contact us at:

email → team.wildcatdevs@gmail.com
company → Wildcat Devs
© 2026 Rmaps · Wildcat Devs
Terms of ServiceHome