PRIVACY POLICY
Product: PickMeUp (iOS application)
Data controller: Cloud Ape AB, org. no. SE559480834601, Skanevagen 26, SE-24538 Staffanstorp, Sweden
Contact: privacy@cloudape.se (or by post to the address above)
Version: 1.0 (Draft) — Last updated: 2026-10-03
DRAFT — LEGAL REVIEW REQUIRED. Review by qualified EU/Swedish counsel before publication, together with the Terms and Conditions, the App Store privacy labels, and the DPIA for continuous location tracking.
This policy explains, in plain language, what personal data PickMeUp collects, why, how long we keep it, who sees it, and what your rights are. It applies to all PickMeUp services, including the app, the account system, and the cloud services that support them. Our Terms and Conditions (linked in the app) govern the rest of the relationship; where this policy and the Terms differ on personal data, this policy governs.
1. Who is the data controller?
Cloud Ape AB is the controller for the personal data processed through PickMeUp. We determine the purposes and means of that processing. Our contact details are in the header above. You can also reach the Swedish Authority for Privacy Protection (IMY, https://www.imy.se) with a complaint about our processing (Section 9.3).
2. What data we collect
| Category | Specific data | When |
|---|---|---|
| Location (precise) | GPS position, heading, speed, accuracy, timestamps; trip trails; geofence entries/exits; last-known location | When you grant iOS location permission and share in-app (e.g., press PickMeUp, or keep background tracking on) |
| Trips & events | Pick-up requests, notification events, accept/arrive/finish actions | During a trip |
| Account | Name, email address, phone number, profile data, app-store account identifier | At sign-up and while active |
| Device & app | Device model, OS and app version, push token, crash logs, anonymized usage metrics | Ongoing, while the app runs |
| Payment | Subscription and payment data | Processed by Apple (App Store); we see only the subscription status, not payment details |
| Messages | Messages exchanged in-app between users of your account (e.g., Driver ↔ Passenger) | When you use messaging |
| Children's data | For users aged 13–16: the data above plus the parental-consent record (guardian's contact details) | At registration |
We collect no data from people who do not create an account or use the app. We do not knowingly collect personal data from children under 13 (Section 8).
3. Why we process it (purposes and legal bases)
| Purpose | Legal basis | Notes |
|---|---|---|
| Delivering the core Service: sharing a Passenger's location with a designated Driver when PickMeUp is pressed; notifications; trip trails; last-known location; geofence alerts | Contract (Art. 6(1)(b) GDPR) | Necessary for the Service you subscribe to |
| Your in-app sharing choices, Driver lists, alerts, Settings | Contract | Part of the Service |
| Service security, integrity, fraud and abuse prevention (e.g., detecting non-consensual tracking patterns) | Legitimate interest (Art. 6(1)(f) GDPR) | Interest: protecting all users, including children, from misuse |
| Service quality: crash logs, usage metrics, performance | Legitimate interest | Processed pseudonymized where feasible |
| Product development and research on de-identified location data (aggregated patterns, demand, safety research, third-party aggregated datasets — see Section 6) | Legitimate interest plus the de-identification standard in Section 6, plus the opt-in consent you give in onboarding (Section 5) | Double safety: de-identification makes the output non-personal; consent covers any residual personal stage |
| Marketing (email, in-app) | Explicit consent (Art. 6(1)(a) GDPR) | Separate, opt-in; never pre-ticked |
| Compliance with legal obligations (e.g., financial records, safety logs, lawful requests) | Legal obligation (Art. 6(1)(c) GDPR) | Where required |
Consent-based purposes: for everything we mark "consent" above, you give consent in the app during onboarding (and can withdraw it anytime from Settings → Your Data). You may refuse or withdraw consent without any impact on your ability to use the core Service.
4. Who receives your data (recipients and processors)
Other users of the Service. When you press PickMeUp, your location (and trail, if enabled) is shared with the Drivers you designated — that is the core function. When a Driver accepts, their live location is shared with you for the trip duration. Each user is responsible for how they use that information (Terms §4, §7).
Processors (service providers acting on our instructions), all bound by data processing agreements with EU Standard Contractual Clauses where applicable:
| Processor | What they process | Where |
|---|---|---|
| Google Cloud (Cloud Run, Pub/Sub, Secret Manager, Cloud SQL PostgreSQL + PostGIS) | Location streams, trip data, account data — storage and application infrastructure | EU: europe-north1 (Hamina, Finland) — all services and the database. See Section 5 |
| Apple Inc. (App Store, Apple ID / Sign in with Apple, push notifications) | Account ID, subscription status, push token | Apple's regions; governed by Apple's DPA and our user terms |
| Map-tile / mapping provider (MapTiler / Mapbox, per current configuration) | The location coordinates needed to render a map around a user's position | Provider's EU infrastructure; see Section 5 |
| Crash and performance analytics vendor (if adopted: e.g., ____________) | Crash logs, device metrics, no precise location | EU, or under SCCs |
Authorities. We disclose to competent authorities (e.g., law enforcement, IMY) only where legally required.
5. Where your data is stored and transferred
Your personal data is stored in the EU: all application services and the database in Hamina, Finland.
- Transfers outside the EU. To the extent a processor (e.g., Google, Apple, or the mapping provider) operates support functions or backup subprocessors outside the EU, transfers are governed by the processor's standard contractual clauses and their transparency documentation; where no adequate safeguard exists for a planned transfer, we will add one before the transfer or will not make it. We do not knowingly transfer identifiable location data outside the EU for processing purposes.
- The de-identified and aggregated datasets described in Section 6 are no longer personal data; their handling is not subject to GDPR transfer rules.
6. De-identified and aggregated location data
We may create de-identified datasets from trip and location data by:
- removing direct identifiers (account IDs, names, device IDs, tokens);
- spatial generalization (coarsening coordinates to a grid of at least ____________ metres);
- temporal generalization (aggregating over windows of at least ____________);
- aggregation across many users, and where applicable, addition of noise (differential-privacy parameters: ε = ____________).
Once de-identified to this standard, the data may be used by us for any lawful purpose (product development, research, aggregated analytics, provision of aggregated datasets to third parties), and recipients are contractually prohibited from attempting to re-identify individuals or from combining the data for re-identification.
Opt-in consent. Onboarding includes a separate, unchecked-by-default toggle: "Use my de-identified trip data to help improve PickMeUp and for aggregated research". You can turn it off anytime in Settings → Your Data. New data is excluded immediately; already-aggregated data may retain your contribution (where technically inseparable), which we state honestly in the onboarding screen.
We will never sell, rent, or disclose identifiable personal location data to third parties for their marketing purposes.
7. How long we keep your data
| Data | Retention |
|---|---|
| Live location while a trip is active | For the trip; trip trail deleted after ____________ unless you enable history |
| Trip history / last-known location | As configured by you; default ____________, then deleted |
| Account and profile | Until account deletion, then deleted within ____________ days |
| De-identified/aggregated datasets | Indefinite (no longer personal data) |
| Crash logs and telemetry | ____________ |
| Financial/subscription records | As required by Swedish bookkeeping law (generally 7 years) |
| Parental-consent records (13–16) | Until the user turns 18, then deleted unless law requires longer |
On account deletion we hard-delete or irreversibly de-identify your personal data within the documented deadline, except where we must retain specific records by law (e.g., financial records, unresolved safety incidents), and we mark retained items so no further processing occurs.
8. Children (13–16) and parental consent
- PickMeUp requires you to be at least 13 years old.
- Users aged 13–16 need a verifiable parental consent: at registration we send a verification code to the guardian's phone or email; the account and any location sharing are limited until the guardian completes it. (This reflects the Swedish age of digital consent of 13; the GDPR's Art. 8 threshold is set by Member State law.)
- We do not knowingly collect data from under-13s. If we discover an under-13 account, we suspend location sharing and delete the account.
- Location data of minors is treated as sensitive in practice: we run additional safeguards (e.g., sharing is always limited to designated adults in the minor's own account, alerts to guardians, no advertising) and the DPIA covers this specifically.
- Guardians can withdraw consent, view the minor's data, or request deletion by contacting privacy@cloudape.se.
9. Your rights
You have the following rights under the GDPR, which you can exercise for free by emailing privacy@cloudape.se (or via Settings → Your Data where implemented):
- Access — a copy of the personal data we hold about you, in a readable format.
- Rectification — correction of inaccurate or incomplete data.
- Erasure — deletion ("right to be forgotten"), subject to Section 7 retention.
- Restriction of processing.
- Data portability — your data in a structured, commonly used, machine-readable format (e.g., JSON/GPX for location history).
- Objection — to processing based on legitimate interest (Sections 3, 6); we stop the relevant processing unless we demonstrate compelling legitimate grounds.
- Withdrawal of consent — at any time, without effect on the lawfulness of processing before withdrawal (Settings → Your Data).
- Not to be subject to automated decision-making producing legal or similarly significant effects (Art. 22): we do not make such decisions about you. Some safety features (e.g., anomaly alerts) involve profiling; you are always notified and may opt out.
- Complaint — you may lodge a complaint with IMY (https://www.imy.se) or another EU supervisory authority. This does not require you to contact us first.
We respond to rights requests within one month (extendable by two further months for complex requests, with notice). To prevent fraud, we may verify your identity before fulfilling a request, especially for data relating to minors.
10. Security
We apply appropriate technical and organizational measures (Art. 32 GDPR), including:
- encryption in transit (TLS) and at rest (AES-256) for location and account data;
- fine-grained Google Cloud IAM; location data access limited to the pipelines that need it; secrets in Secret Manager;
- per-user access control — a Driver sees only locations you chose to share;
- audit logging of data access by staff (least-privilege, logged, reviewed);
- breach response procedure with 72-hour supervisory-authority notification where required;
- vendor due diligence and DPAs for every processor (Section 4).
No method is 100% secure. If a breach affecting your data occurs, we will notify you and, where required, IMY.
11. Automated processing and profiling (plain language)
PickMeUp uses some automated processing: matching a pick-up press to your designated Driver, geofence entry/exit detection, and anomaly detection to flag possible misuse (e.g., tracking patterns inconsistent with the consented use). We do not build advertising profiles of you, sell profiles, or make automated decisions with legal effect. You can review and disable each feature in Settings.
12. Children's data in automated processing
Minors' data is excluded from advertising, profiling, and any sale-like use by design (there is none). The anomaly-detection in Section 11 applies to minors' accounts for safety (protecting them from non-consensual tracking) and is described in the DPIA.
13. Changes to this policy
We will notify you of material changes in the app (and by email where feasible) at least 14 days before they take effect. Where a change adds a new purpose for consent-based processing, we will ask for a fresh, specific consent — continued use of the Service is never treated as consent to new processing. The version date at the top of each copy shows which version applies to you.
14. International picture (short version)
- Data controller: Sweden (Cloud Ape AB).
- Storage: EU only (Hamina, Finland).
- Law: GDPR + Swedish Data Protection Act (dataskyddslagen, 2018:218).
- Supervisory authority: IMY.
Appendix — Data flow (matches architecture)
iOS app (CoreLocation)
│ TLS
▼
Cloud Run API (europe-north1, Hamina)
│
├─► Pub/Sub ingestion (europe-north1)
│ │
│ ▼
└────► Cloud SQL PostgreSQL + PostGIS (europe-north1, Hamina)
▲ (trip trails, geofences, last-known location)
│
App queries (trip history, alerts)
Map rendering: app requests tiles from the map provider (MapTiler/Mapbox)
with the user's current coordinates — see Section 4.
All storage in the EU. De-identification and aggregation pipelines run inside the EU as well.