PickMeUp TERMS AND CONDITIONS

TERMS AND CONDITIONS

Version 1.0 (Draft) · Last updated 2026-10-03 · Cloud Ape AB

Product: PickMeUp (iOS application)
Provider: Cloud Ape AB (Swedish company no. SE559480834601), org. address: Skanevagen 26, Staffanstorp, Sweden
Version: 1.0 (Draft) — Last updated: 2026-10-03

DRAFT — LEGAL REVIEW REQUIRED. This document is a template draft and does not constitute legal advice. Have it reviewed by qualified EU/Swedish counsel before publication, together with the companion Privacy Policy, the Apple App Store privacy disclosures, and a DPIA for continuous location tracking (effectively mandatory under Swedish practice; IMY actively enforces app privacy in Sweden).


1. Who we are and how these Terms apply

1.1 Cloud Ape AB ("PickMeUp", "we", "us", "our") operates the PickMeUp mobile application (the "Service") and related websites, accounts, and cloud infrastructure.

1.2 By creating an account, pressing PickMeUp, or otherwise using the Service, you agree to be bound by these Terms and by our Privacy Policy (linked in the app). The Privacy Policy is incorporated into these Terms by reference.

1.3 If you use the Service on behalf of a company or organization, you represent that you have authority to bind that entity, and "you" includes that entity.

1.4 These Terms may be updated over time as described in Section 14.

2. The Service in one paragraph

PickMeUp is a location-sharing service for families and companies. A Passenger (for example, a child heading to a party or practice) presses PickMeUp from the app. A Driver (for example, a parent) then receives a notification that the passenger wants to be picked up, including the passenger's map location. Users subscribe to the Service on a recurring basis. Roles are selected at the landing screen (Driver / Passenger).

We do not provide navigation, driving instructions, or emergency call services. The Service does not replace 112 / emergency services.

3. Accounts, subscriptions, and billing

3.1 Accounts. You need an account to use the Service. You must provide accurate information and keep it current. You are responsible for the security of your account and for all activity under it.

3.2 Age requirement. You must be at least 13 years old to use the Service. In accordance with the Swedish age of digital consent (13), accounts for users aged 13–16 require the verifiable consent of a parent or legal guardian, which we collect through the parental-consent flow in the app. You may not use the Service if you are below 13.

3.3 Subscriptions. The Service is offered as a recurring subscription. Unless stated otherwise in the app, subscriptions renew automatically at the then-current price until cancelled. You may cancel at any time from within the app or through your App Store subscription settings; cancellation takes effect at the end of the current billing period. Prices are shown in the app before you confirm a purchase; purchases are processed by Apple Inc. or the applicable app store, and refunds are governed by that store's refund policy.

3.4 Family and company plans. You may subscribe on behalf of a family or a company. For company plans, the subscribing company is responsible for ensuring that each employee or member added to the plan has given valid consent to the processing of their location data described in the Privacy Policy, and for complying with applicable employment and data-protection obligations toward them.

3.5 Fair use. You may not resell, redistribute, or provide the Service to third parties as a commercial service without our prior written agreement.

4. Acceptable use

4.1 You agree not to:

  1. use the Service to harass, stalk, threaten, or unlawfully monitor any person;
  2. use the Service to track or share the location of a person who has not given their own valid consent to be tracked (including, in particular, children for whom no valid parental consent has been given where required);
  3. misrepresent your identity or another person's identity;
  4. attempt to access other users' accounts or data other than your own authorized access;
  5. reverse engineer, scrape, or build a competing dataset from the Service;
  6. use the Service for any unlawful purpose, or in violation of applicable location-privacy laws.

4.2 Consent is a core principle. PickMeUp is a consent-based location-sharing service: a person's live location is only revealed to others when that person (or, where legally required, a parent or guardian) chooses to share it. You acknowledge that you will only use the Service with people who consent to it. We may suspend or terminate accounts that we have reasonable grounds to believe are being used for non-consensual tracking.

4.3 We may suspend or terminate access, in whole or in part, where you breach these Terms, where required by law, or where continued use poses a safety or legal risk.

5. Location data: what we collect and why

This section summarizes our key data practices. The Privacy Policy is the authoritative document on personal data; where they differ, the Privacy Policy governs.

5.1 Data we collect.

5.2 Why we process it (lawful basis and purposes).

PurposeBasisDetails
Delivering the core Service (sharing your location with the other party when you press PickMeUp, notifications, trip trails, last-known location)Contract (Art. 6(1)(b) GDPR)Necessary for the Service you subscribe to
Safety features (e.g., location history to help reunite a family, geofence alerts)ContractPart of the Service
Service security, fraud prevention, and integrity of the platformLegitimate interest (Art. 6(1)(f) GDPR)Anomaly detection, abuse prevention
Aggregated and de-identified analytics, product development, and researchLegitimate interest (Art. 6(1)(f) GDPR) + de-identificationSee Section 6 — the primary way we improve and expand the Service
Consent-required processing (e.g., marketing, any future processing beyond the purposes above)Explicit consent (Art. 6(1)(a) GDPR)Only with your separate, informed, freely given consent, which you may withdraw at any time

6. De-identified and aggregated data (how we improve and grow the Service)

This section is the heart of our data strategy. Read it carefully.

6.1 De-identification. We may transform personal location data into de-identified data by removing or pseudonymizing direct identifiers and applying techniques such as spatial and temporal generalization, coarsening of resolution, aggregation across many users, and noise addition, so that a person cannot be re-identified by us or by a third party reasonably using the data. De-identified data is no longer personal data under applicable law, and we may use it freely for any lawful business purpose, including:

  1. improving, testing, and developing new features and new products (including products and features that do not yet exist and that we cannot name today, provided they are developed from de-identified data);
  2. aggregated analytics such as demand patterns, trip corridors, wait-time models, and network performance;
  3. safety and reliability research (e.g., accident-prone areas, risky pickup points);
  4. providing aggregated datasets or insights to third parties (e.g., research partners, municipal planners, or commercial customers), only at an aggregated or de-identified level, never at the level of an identifiable individual.

6.2 No re-identification. When we create or receive de-identified or aggregated data, we (and any third party we provide it to) are contractually prohibited from attempting to re-identify individuals from it, and from combining it with other datasets for the purpose of re-identification. We will document and maintain these technical and contractual safeguards.

6.3 Your consent is still asked. Even though de-identified use does not itself require consent, we will ask you for an opt-in consent during onboarding and keep it easy to turn off in Settings for any processing you may reasonably expect to be sensitive — including (a) use of your trip data for product development, and (b) provision of aggregated data to third parties. If you opt out, your data is excluded from the relevant de-identified datasets as far as technically feasible; where full exclusion is not feasible (because your data has already been aggregated and de-identified), we describe this limitation in the Privacy Policy.

6.4 No sale of identifiable location data. We do not sell, rent, or disclose your identifiable personal location data to third parties for their own marketing purposes. Where we ever need to process identifiable data for a new purpose not covered above (for example, a partnership feature), we will ask for a separate, specific consent before doing so, and will not combine it with unrelated processing.

6.5 In-app value-adds. We may use your own location and usage patterns (with the consents described above) to provide you with personalized features, such as commute insights, schedule predictions, or safety tips, as part of the subscription or as a premium feature.

7. Sharing of location between Service users

7.1 When you press PickMeUp, your current location (and, if you have enabled it, a short trail) is shown to the Driver designated for you, and the Driver receives a notification. This is the core function you subscribe to.

7.2 When a Driver accepts a pick-up request, the Driver's live location is shared with you for the duration of the trip, unless you disable this in Settings.

7.3 You control who can receive your location: you may change your Driver list, disable sharing, or stop tracking at any time from within the app.

7.4 Each user is solely responsible for how they use location information shared with them. You must not share, screenshot, or distribute another user's location with anyone outside the Service without that user's explicit permission, and you must not use it for any unlawful purpose (see Section 4).

8. Your license to us

8.1 License. By using the Service, you grant us a worldwide, royalty-free, non-exclusive, transferable, sublicensable license to use, reproduce, process, transmit, display, and analyze the location data, trip data, and usage data you provide or that we collect from your device solely for the purposes described in Sections 5 and 6 (delivery of the Service, security, and — subject to the consents you have given — de-identified/aggregated use), in each case in accordance with applicable data-protection law.

8.2 Withdrawal and termination. You may withdraw consents (including the opt-ins in 6.3) at any time from Settings. Withdrawal does not affect our right to process data collected under valid consent prior to withdrawal, where we have a documented legitimate purpose. You may request deletion of your account and personal data as described in the Privacy Policy (Sections 7 and 9 of the Privacy Policy); we retain only what we must keep to comply with law.

8.3 Your content. Any content you submit (profile name, photos, messages) may be displayed within the Service to other users of your account. You retain ownership of your content; you grant us the license needed to host, display, and transmit it within the Service.

9. Business (B2B) terms

9.1 Where a company subscribes, the company grants its members the right to use the Service within the scope of the plan, and remains the point of contact for plan administration. Member-level personal data is processed by us on the basis of the member's own consent and the company's instruction; the company must not instruct us to process member data in a manner inconsistent with applicable data-protection law or this Section.

9.2 We may offer the company aggregated, de-identified analytics about its members' usage (e.g., trip completion rates) under the same safeguards in Section 6.

9.3 In the event of a dispute between a company customer and us, the B2B terms in Section 16 (governing law and jurisdiction) apply to the commercial relationship.

10. Intellectual property

10.1 The Service, our software, and our marks are owned by Cloud Ape AB and protected by applicable law. You do not acquire any ownership right in the Service by using it.

10.2 You are solely responsible for content you provide and for ensuring it does not infringe the rights of others.

10.3 We welcome feedback; if you give it, you grant us a free, irrevocable license to use it without obligation.

11. Third-party services and maps

11.1 The Service uses third-party services (Apple App Store, Apple ID, Apple push notifications, mapping and tile services, cloud hosting). Where we are the controller, we have entered into data-processing agreements with providers that act as processors. Where a provider processes data in its own right (e.g., your Apple account with Apple), their own terms and privacy policy apply.

11.2 Our cloud infrastructure (all services and the database) is hosted in the EU (Finland). Transfers outside the EU, if any, rely on appropriate safeguards (e.g., EU Standard Contractual Clauses) as described in the Privacy Policy.

12. Disclaimers

12.1 The Service is provided "as is". To the maximum extent permitted by law, we disclaim all implied warranties, including merchantability, fitness for a particular purpose, accuracy, availability, and non-infringement.

12.2 Location accuracy. GPS position is inherently approximate and can be affected by buildings, weather, device battery settings, and network conditions. The location shown in the Service may lag, drift, or be temporarily unavailable. Do not rely on the Service as your sole source of a person's position in any safety-critical situation. For emergencies, always call emergency services (112).

12.3 We do not warrant that the Service will be uninterrupted, error-free, or secure against all attacks, although we implement appropriate technical and organizational safeguards.

13. Limitation of liability

13.1 To the maximum extent permitted by law, and excluding liability that cannot be excluded under applicable law (including consumer protections and liability for death or personal injury caused by negligence):

  1. we are not liable for any indirect, incidental, special, consequential, or punitive damages, or for loss of profits, revenues, data, or goodwill;
  2. our total aggregate liability arising out of or relating to the Service in any 12-month period is limited to the fees you paid (or were charged) for the Service in the 12 months preceding the claim, or EUR 100, whichever is greater.

13.2 Nothing in these Terms limits liability that cannot be limited under mandatory EU or Swedish law, or excludes our liability for fraud or gross negligence.

14. Changes to the Service and the Terms

14.1 We may add, modify, or discontinue features at any time. Material changes that affect the Service you subscribe to will be notified in the app or by email.

14.2 Changes to these Terms. We may update these Terms from time to time. For material changes (including any new processing purpose for personal data), we will notify you in the app or by email at least 14 days before the change takes effect. For processing based on consent, a new or expanded purpose requires a fresh, specific consent — silence is never consent. If you do not agree to a material change, you may terminate your subscription before it takes effect and receive a pro-rata refund for the unused portion where applicable.

15. Termination

15.1 You may cancel your subscription and/or delete your account at any time from within the app (Settings → Account) or through your app store settings. Upon account deletion, we delete or de-identify your personal data in accordance with the Privacy Policy, subject to statutory retention (e.g., financial records, safety logs, legal holds).

15.2 We may suspend or terminate access as described in Section 4.3. Upon termination for breach, we are not obliged to refund accrued fees except where required by law.

15.3 Sections that by their nature survive termination (including Sections 6, 8, 10, 12, 13, 16, and 17) survive.

16. Governing law and jurisdiction

16.1 These Terms are governed by the laws of Sweden, together with directly applicable EU law (including the GDPR).

16.2 Disputes between you (acting as a consumer) and us shall be resolved by the competent court in Stockholm, Sweden, unless mandatory consumer-protection rules give you the right to sue in your habitual residence under the EU Regulation on jurisdiction (Brussels I Recast / Lugano). Consumer disputes may also be submitted to the Swedish Consumer Ombudsman (Konsumentombudsmannen) or the national Alternative Dispute Resolution body.

16.3 For B2B disputes, the parties agree to the exclusive jurisdiction of the District Court of Stockholm (Stockholms tingsrätt), with the Svea Court of Appeal (Svea hovrätt) as the second instance.

17. Complaints and contact

17.1 Questions, complaints, data-subject requests (access, rectification, erasure, portability, objection, withdrawal of consent): privacy@cloudape.se / support@cloudape.se
17.2 Postal address: Cloud Ape AB, Skanevagen 26, SE-24538 Staffanstorp, Sweden.
17.3 Supervisory authority: You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY, https://www.imy.se) or with another competent EU supervisory authority.


Appendix A — Location data processing summary (transparency schedule)

DataSourcePurposeBasisRetention (indicative)
Precise location (live)Device GPS (with iOS permission + your in-app choice)Core Service (pick-up sharing)Contract + consent for background modeDeleted shortly after trip end, unless you keep history
Trip trail / last-known locationDevice GPSCore Service, safety (last-known)ContractConfigurable by user; default deleted after __ months
Geofences, alertsUser configurationCore ServiceContractWith account
Device / app telemetryAppService quality, debugging, fraudLegitimate interest days to months
De-identified aggregated location dataDerived from the aboveProduct development, research, aggregated third-party datasetsLegitimate interest + de-identification (opt-in consent asked)Indefinite (no longer personal data)
Marketing communications (if any)AccountMarketingExplicit consent (separate)Until withdrawal

Retention periods to be finalized by counsel and set consistently with the Privacy Policy and the DPIA.


Appendix B — Implementation checklist (for the product and legal team)

Before publication, these must be true in the product itself:

  1. Onboarding consent screens matching Section 5.2 and 6.3: (a) location permission (iOS system prompt + in-app explanation of what and why); (b) opt-in toggle for de-identified/aggregated use; (c) opt-in toggle for any third-party aggregated data provision; (d) separate marketing consent. Every toggle defaulting to off, none pre-ticked.
  2. Parental-consent flow for 13–16 (verifiable — e.g., code sent to guardian's phone/email), and a hard age gate below 13.
  3. In-app "Your Data" screen: view, export, and delete your data; list who currently has access to your location; one-tap "stop sharing now".
  4. DPIA for continuous location tracking (mandatory under Swedish practice for this category of processing), updated whenever a new feature changes the processing.
  5. Privacy Policy as a separate, linked document with the full Art. 13/14 disclosures; App Store privacy-nutrition labels matching it exactly.
  6. Processor agreements (DPA + SCCs where relevant) with every sub-processor; data located in the EU (Finland — as per the architecture decision).
  7. De-identification standard documented (spatial/temporal coarsening thresholds, k-anonymity or differential-privacy parameters, re-identification contract clauses for any third-party recipient) — this is what makes Section 6 defensible.
  8. Deletion pipeline: account deletion → hard-delete or irreversible de-identification within a documented deadline; log it for IMY.
  9. Swedish translation of both the Terms and the Privacy Policy, available in the app (recommended; English alone is workable but Swedish is expected for a Swedish consumer product).
  10. Counsel review sign-off on: Section 13 (liability), 16 (jurisdiction), 6.3 (feasibility of exclusion from already-aggregated datasets), and the Appendix A retention figures.