Last updated: 11 July 2026
1. Introduction
Welcome to IDMAP.AI ("we," "our," or "us"), a service operated by IDMAP.TECH LLC. We respect your privacy and are committed to
protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use
our app.
Data Controller Details
- Controller Name: IDMAP.AI
- Legal Entity: IDMAP.TECH LLC
- Address: 8930 W Sunset Rd Unit 200, Las Vegas, NV 89148
- Contact: Michael Belsky — michael.belsky@idmap.ai
(We are responsible for collecting and processing your personal data.)
We process personal data in compliance with the General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy
Act (CCPA/CPRA), LGPD, PIPEDA, and other applicable privacy laws.
By using our services, you consent to the practices described in this Privacy Policy. If you do not agree, please refrain from using the
app.
2. Information We Collect
Every 30 minutes — including in the background — when you have granted the corresponding consent, we collect and transmit the following:
- Account & Profile: Firebase user identifier, age and gender (from your profile).
- Precise Location: latitude, longitude, horizontal and vertical accuracy, altitude, heading and speed. Location method (GPS / network /
fused / passive).
- Derived location: a 9-character geohash and the country your device is in (derived on our servers from your GPS coordinates and/or
your IP address).
- Advertising Identifier: your IDFA (iOS) or Google Advertising ID (Android), together with a Limit-Ad-Tracking flag. On iOS this
requires the App Tracking Transparency prompt; if you decline, no advertising identifier is transmitted.
- Network: your public IP address (IPv4/IPv6), captured by our servers from the request, and — where the operating system permits — the
SSID and BSSID of the Wi-Fi network you are connected to.
- Device: model, manufacturer, operating system and version, mobile carrier, timezone, whether the app was in the background at
collection time.
- User agent (synthetic, generated by the app).
- CCPA/CPRA flags: whether you were shown the notice, whether you opted out of "sale," and whether the Limited Service Provider
Agreement (LSPA) applies.
- Vehicle Data: make/model, fuel type, consumption — provided by you when registering a vehicle.
- Trip Data: the routes and classifications produced by the app's trip-tracking feature.
- Consent Records: the choices you make, the version of this Policy in force, and the timestamp.
We do NOT collect contacts, calendar, health data, biometrics, message contents, MAC address, or IMSI. Each of the categories above is
gated by a specific toggle in Profile → Privacy Preferences and can be turned off at any time.
3. How We Use Your Data
- To measure and display your personal carbon footprint.
- To classify trips by transport mode (walk / bike / car / transit / plane).
- To generate personalised insights and reduction suggestions (with your consent).
- To improve reliability, security and performance of the app.
- To comply with legal obligations.
- To communicate with you (support, service updates, and — with your consent — marketing).
4. Legal Bases for Processing (GDPR Compliance)
- Consent — analytics, diagnostics, personalised insights, research participation, marketing communications.
- Performance of Contract — providing you the core trip-tracking service you signed up for.
- Legitimate Interests — security, fraud prevention, protecting the app.
- Legal Obligation — where required by law.
You may withdraw consent at any time from Profile → Privacy Preferences. Withdrawal does not affect the lawfulness of prior processing.
5. Your Rights Under GDPR
If you are a resident of the European Economic Area (EEA), UK, or Switzerland, you have the following rights:
- Right to Access — request a copy of your data.
- Right to Rectification — correct inaccurate data.
- Right to Erasure ("Right to be Forgotten") — request deletion, subject to legal exceptions.
- Right to Restrict Processing — request we limit certain processing.
- Right to Data Portability — receive your data in machine-readable format.
- Right to Object — object to processing based on legitimate interests.
- Right to Lodge a Complaint — with your national Data Protection Authority.
To exercise your rights, use Profile → Privacy → Data requests, or email michael.belsky@idmap.ai.
6. Your Rights Under CCPA / CPRA
If you are a California resident, you have the following additional rights:
- Right to Know what personal information we collect and how it is used.
- Right to Delete personal information collected from you.
- Right to Correct inaccurate information.
- Right to Limit use of sensitive personal information (in this app: precise location).
- Right to Opt-Out of Sale or Sharing — we do NOT sell or share personal information for cross-context behavioural advertising.
- Right to Non-Discrimination — you will not receive different service for exercising your rights.
7. Data Retention
- Trip data: kept while your account is active; deleted on request within 30 days.
- Device/app telemetry: 13 months, then automatically purged by our retention sweeper.
- DSAR export blobs: 30 days.
- Consent ledger and audit logs: 7 years, as required for accountability.
- Backups roll off within 90 days.
8. Data Sharing and Third Parties
We share data with trusted third parties for specific purposes:
- Cloud Service Providers (e.g. Google Firebase) — authentication, database, storage, serverless functions.
- Analytics Providers — anonymised product analytics and diagnostics.
- Data Processor — IDMAP acts as our data processor for identity, device and location processing.
- Security & Fraud Prevention Services — monitoring, abuse prevention.
- Regulatory Authorities & Law Enforcement — only where legally required.
- Third-party marketing and analytics, programmatic targeting, market research — only if you enable "Share with Third-Party Partners."
CCPA/CPRA classifies this as a "sale" or "sharing"; you can toggle it off at any time in Profile → Privacy Preferences.
If you do NOT enable that toggle, your data stays with us and our processors and is not disclosed to commercial partners. California
residents have an explicit "Do Not Sell/Share" right that is honored by this same toggle.
Government or law-enforcement disclosure only on valid legal process; we notify users where legally permitted.
9. Security Measures
- Encryption in transit (TLS 1.3) and at rest (Firebase-managed encryption).
- Least-privilege Firestore/Storage security rules — users can only read their own data.
- Server-side ingest via Cloud Functions with authenticated callers and validated payloads.
- Cloud Functions IAM restricts admin capabilities.
- Continuous monitoring, dependency scanning, and periodic penetration tests.
10. Children's Data Protection
The app is not directed to children under 16 (or the applicable age of digital consent in your country — 13 in the US under COPPA). We
do not knowingly collect personal data from children. If you believe a child has provided data, contact michael.belsky@idmap.ai and we
will delete it.
11. Changes to This Privacy Policy
We may update this policy periodically. Significant changes will be notified in-app and, where required, by email. You will be asked to
re-consent when the policy version changes.
12. Contact Us
For privacy-related inquiries, contact us at:
- Controller: IDMAP.AI (IDMAP.TECH LLC)
- Address: 8930 W Sunset Rd Unit 200, Las Vegas, NV 89148
- Contact: Michael Belsky — michael.belsky@idmap.ai