Privacy Policy for the CoPlay App

Effective date: [EFFECTIVE DATE]

This privacy policy explains how the CoPlay app (bundle identifier de.lukasoberbeck.coplay) processes your personal data. CoPlay is a road-trip companion in which a passenger curates destinations and a driver sees a single destination and a single GO button. We have designed CoPlay to collect as little personal data as possible.

1. Controller


[POSTAL ADDRESS]
Email: [CONTACT EMAIL]

CoPlay is operated by a private individual as a non-commercial, early-stage project (version 0.1).

2. Summary of what we do and do not do

We process only the data described below, which is limited to what is needed to run a shared trip-planning service. We do not use analytics SDKs, advertising, third-party tracking, or crash-reporting SDKs. CoPlay does not access or collect your device's GPS location; destinations are typed, found through Apple MapKit text search, or shared in as links. We do not sell your data.

3. Categories of data we process

a) Account identity (Firebase Authentication)

When you first open the App, an anonymous account is created for you. This is a random user identifier with no personal data attached; you do not need to sign up. You may optionally link your account to Sign in with Apple or Sign in with Google. Only if you do so do we receive an identifier from that provider and, depending on the provider and your own choice, a name and an email address. If you use Sign in with Apple and choose to hide your email, Apple provides a private relay address rather than your real one, as described in the Apple privacy policy (linked in section 6).

b) Public profile

You may set a display name (stored under profiles/{uid}). This display name is visible to the other members of any session you share, so that people can recognise who added a destination.

c) Trip content (Cloud Firestore)

Content you create for a trip is stored in Cloud Firestore. This includes session names and destinations you add, where a destination consists of a title, an optional subtitle, geographic coordinates, an optional address, and an optional source link you shared. Content you add to a session is shared with the other members of that session.

d) Private preferences

Your preferred maps app (Apple Maps, Google Maps, or Waze) is stored under users/{uid}. This preference is private to you.

e) Technical data processed by our infrastructure providers

To deliver the service, our infrastructure providers process standard technical data, such as your IP address in server logs. This is a normal and necessary part of operating an internet service.

4. Purposes and legal bases (Article 6 GDPR)

We process the account identity, public profile, trip content, and private preferences in order to provide the App and its shared-session functionality to you, that is, to perform the contract for use of the App with you (Article 6(1)(b) GDPR). Where you optionally link a sign-in provider, we process the data that provider returns on the basis of your choice to link, which forms part of performing that requested function (Article 6(1)(b) GDPR) and, to the extent required, your consent (Article 6(1)(a) GDPR), which you can withdraw at any time by unlinking or deleting your account.

We process standard technical data (such as IP addresses in server logs) on the basis of our legitimate interest in operating the service securely and reliably and in preventing abuse (Article 6(1)(f) GDPR).

5. Sharing within sessions

CoPlay is a collaborative tool. Your display name and the trip content you add to a shared session are visible to the other members of that session. Anyone who has a session's link or QR code can join that session and see its content. Please treat a session link as sensitive and share it only with people you want to include.

6. Processors and recipients

We use the service providers listed below. We describe here only our own use of them and the data we hand to them. How each provider processes that data as part of its own services is governed by that provider's own terms and privacy policy, which we link to and which are authoritative for their processing. This policy does not restate or guarantee their practices, because those can change; please consult the linked documents for the details that apply.

We do not sell your data and we do not share it for advertising.

7. International transfers

Some of these providers, in particular Google and Apple, may process data on infrastructure located outside the European Union. Any such transfer relies on the safeguards that the provider puts in place, for example the European Commission's standard contractual clauses or an adequacy decision. For the details that apply at any given time, please see the provider's own privacy policy (linked in section 6), which is authoritative.

8. Retention

We keep your account identity, profile, preferences, and the trip content associated with your account for as long as your account exists. When you delete your account (see section 10), the data governed by the App's user-data registry is deleted. Trip content within a shared session may remain visible to other members to the extent it is part of that shared session. Standard technical logs kept by our infrastructure providers are retained only for the limited periods those providers apply for security and operational purposes.

9. In-app data export

The App provides a full export of your data as a JSON file directly in the App. This export is complete by construction: it is generated from the same compile-time registry of user-data categories that governs deletion, so it reflects every category of data the App holds about you. This supports your right to data portability.

10. In-app account and data deletion

The App lets you delete your account and your data directly in the App. Deletion is driven by the same compile-time registry, so it removes the categories of user data the App holds about you. Where deletion requires a recent sign-in for security, the App may ask you to re-authenticate first, so that a failed sign-in cannot leave your data behind.

11. Your rights

Under the GDPR you have the right to:

Where processing is based on consent, you may withdraw that consent at any time with effect for the future. Many of these rights can be exercised directly in the App through the export and deletion features and by editing your profile and content. You can also contact us at [CONTACT EMAIL].

You have the right to lodge a complaint with a supervisory authority, in particular the competent German data protection authority for your place of residence or for the controller's place of establishment.

12. Children

CoPlay is not directed at children and is not intended for use by children under the age required for a valid consent or contract in their country. We do not knowingly process data of such children.

13. Changes to this policy

We may update this privacy policy to reflect changes to the App or to legal requirements. The current version is made available with the App and on our website.