Back to Home
WANDR Privacy Policy
# WANDR App — Privacy Policy
**Last Updated:** May 30, 2026
---
## Introduction
WANDR ("we", "us", or "our") operates the WANDR mobile application (the "Service"). This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service.
---
## Information We Collect
### Information You Provide
- **Account Information:** Email address, display name, phone number, profile photo.
- **Profile Details:** Blood group, emergency contact information (stored securely in encrypted local storage and private Firestore subcollections).
- **Trip/Plan Data:** Routes, waypoints, start/end points, trip plans created within the app.
- **Group Data:** Group names, member lists, group photos, join codes.
- **Messages:** Text messages, photos, and audio messages shared in group and trip chats.
### Information Collected Automatically
- **Location Data:** GPS coordinates for route tracking, live location sharing with group members during trips, and turn-by-turn navigation. Location is collected in the foreground and, with your explicit consent, in the background during active trips.
- **Device Information:** Device type, operating system version, unique device identifiers.
- **Crash Reports (Firebase Crashlytics):** We use Firebase Crashlytics to collect anonymized crash reports, error logs, device information, and diagnostic data. User identifiers may be associated with crash reports for debugging purposes. This data is shared with Google and retained per Google's data retention policies.
- **Analytics:** Anonymized usage patterns to improve the app experience.
- **Push Notification Tokens:** Firebase Cloud Messaging tokens for delivering notifications about trips and group activity.
---
## Background Location
When you start a trip, WANDR accesses your location in the background to:
- Track your trip progress in real-time
- Share your live location with group members during trips
- Provide turn-by-turn navigation even when the app is in the background
You can disable background location access at any time in your device settings. Without background location, navigation and live tracking features will be limited when the app is not in the foreground.
---
## Audio Recording
WANDR allows you to send audio messages in group and trip chats. Audio is recorded only when you explicitly press and hold the record button. Audio files are stored in Firebase Storage and shared with group members.
---
## Navigation and Route Guidance
WANDR provides turn-by-turn navigation powered by Google Maps Navigation SDK. When you create and save a trip plan within the app:
- **Saved Plans Are Guidance, Not Guarantees:** Your saved trip plans (routes, waypoints, and preferences) serve as suggested guidance for the navigation system. The actual navigation route is computed in real-time by Google Maps Navigation SDK based on current traffic conditions, road closures, and optimal routing algorithms.
- **Route Deviations:** The navigation system may deviate from your saved plan to provide a faster, safer, or more efficient route. The SDK prioritizes real-time optimal routing over strict adherence to pre-planned paths.
- **Waypoint Preferences:** While the app communicates your preferred waypoints to the navigation SDK, the system may adjust the route order or suggest alternative paths based on real-time conditions.
- **No Route Guarantee:** We do not guarantee that the navigation will follow your exact saved plan. The final route is determined by Google's routing algorithms, which prioritize safety, efficiency, and real-time road conditions.
You retain full control to manually adjust your route during navigation or override suggested directions.
---
## How We Use Your Information
- To provide and maintain the Service.
- To enable real-time location sharing with your group members during trips.
- To provide turn-by-turn navigation guidance.
- To send you important notifications about trips and group activities.
- To improve and personalize your experience.
- To monitor and analyze usage for improvements.
- To detect and prevent fraud, abuse, and policy violations.
---
## Data Sharing
We do **not** sell your personal data.
We may share data with:
- **Other Users:** Your display name, profile photo, and real-time location are shared with group members (as enabled by you during trips).
- **Service Providers:**
- Firebase (Google) for authentication, database, storage, crash reporting, and push notifications
- Google Maps for navigation and route computation
- RevenueCat for subscription and payment processing
- SendGrid for transactional email delivery (welcome emails, account notifications)
- **Legal Requirements:** If required by law, regulation, or legal process.
---
## Data Retention
We retain your personal data for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy:
- **Active Account Data:** Retained for the duration of your active account.
- **Trip Location Data:** Retained until you delete the specific trip or your account.
- **Messages and Chat Data:** Retained until you delete them individually or
delete the associated group/trip. If you delete your account, messages and
shared trip or group activity that other users rely on may remain, but your
name, profile photo, and user identifier are replaced with "Deleted user."
- **Saved Plans:** Retained until you delete them or your account.
- **Profile Pictures and Media:** Retained in Firebase Storage until you delete your account.
- **Anonymized Crash Reports:** Retained per Google Firebase Crashlytics policies (typically 90 days for detailed crash data, longer for aggregated analytics).
- **Anonymized Analytics Data:** May be retained indefinitely for service improvement purposes.
**After Account Deletion:**
- Account profile data, private profile details, push tokens, private feedback,
plans you created, solo trips, live location records, subscription/billing
data, usage statistics, blocked users list, and account-specific storage files
are permanently deleted within 30 days, including residual data in automated
backups.
- Shared group and trip history that would lose context for other users may be
retained with your identity removed. This includes messages, shared trip chat,
voice-note metadata, SOS alert metadata, and moderation reports. These records
display you as "Deleted user" and remove your profile photo and user ID.
- Anonymized or aggregated data that cannot be linked back to you may be
retained for analytics, safety, moderation, and service improvement.
- **Third-Party Services:** Data processed by third-party services may be
retained according to their policies: Firebase Crashlytics (anonymized crash
reports retained up to 90 days), RevenueCat (subscription transaction history
for billing/tax compliance), and SendGrid (email delivery records).
You can delete your account at any time through the app's Profile screen, which triggers permanent deletion of all associated personal data.
---
## Account Deletion
You can delete your account and all associated data at any time:
1. **In-App:** Open the WANDR app → Profile tab → scroll to "Delete Account" → confirm your identity.
2. **Web:** Visit our [account deletion page](https://devdarsshan.github.io/wandr-docs/delete-account.html) for instructions or to request manual deletion.
When you delete your account, the following data is permanently removed:
- Your profile information, phone number, blood group, and emergency contacts
- Your group memberships (you are removed from all groups)
- Plans you created
- Profile pictures and uploaded media
- Push notification tokens
- Solo trips and live trip location data associated with your account
Some shared records are retained only when deleting them would affect other
users' group or trip history. In those cases, WANDR removes your identity and
shows the author or participant as "Deleted user."
---
## Content Moderation
We provide tools to report inappropriate content and block users. Reports are reviewed and actioned per our Terms of Service. We reserve the right to remove content and suspend accounts that violate our policies.
---
## Your Rights
You have the right to:
- Access your personal data (via the "Export Data" feature in your Profile).
- Request correction of inaccurate data.
- Request deletion of your data (via account deletion).
- Withdraw consent for location tracking at any time via device settings.
---
## GDPR Compliance (European Economic Area Users)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):
### Your GDPR Rights
- **Right to Access:** Request copies of your personal data and information about how we process it.
- **Right to Rectification:** Request correction of inaccurate or incomplete personal data.
- **Right to Erasure (Right to be Forgotten):** Request deletion of your personal data when it is no longer necessary for the purposes for which it was collected.
- **Right to Restrict Processing:** Request that we limit the processing of your personal data in certain circumstances.
- **Right to Data Portability:** Receive your personal data in a structured, commonly used, and machine-readable format (available via "Export Data" feature).
- **Right to Object:** Object to processing of your personal data based on legitimate interests.
- **Right to Withdraw Consent:** Withdraw consent for location tracking, analytics, or other consent-based processing at any time without affecting the lawfulness of processing before withdrawal.
- **Right to Lodge a Complaint:** File a complaint with your local data protection authority if you believe your rights have been violated.
### Legal Basis for Processing
We process your personal data under the following legal bases:
- **Consent:** Location tracking (foreground and background), audio recording, analytics, and push notifications.
- **Contract Performance:** Providing the Service you signed up for (account management, trip tracking, group coordination).
- **Legitimate Interests:** Fraud prevention, service improvement, security, and abuse detection.
- **Legal Obligation:** Compliance with applicable laws and regulations.
### Data Retention Periods
- **Active Account Data:** Retained for the duration of your account plus 30 days for backup purging.
- **Trip and Location Data:** Retained until you delete the trip or your account.
- **Messages:** Retained until you delete them or the related group/trip is
deleted. After account deletion, shared messages may be retained in
anonymized form when other users need the conversation history.
- **Crash Reports:** Retained per Google Firebase's data retention policies (typically 90 days for detailed reports, longer for aggregated analytics).
- **Anonymized Analytics:** Retained indefinitely for service improvement.
### Data Transfers
Your personal data may be transferred to and processed in countries outside the EEA, including the United States (Firebase/Google servers). We ensure appropriate safeguards are in place through:
- Google Cloud's Standard Contractual Clauses (SCCs) for GDPR compliance.
- Firebase's adherence to the EU-U.S. Data Privacy Framework.
### Contact for GDPR Requests
To exercise any of your GDPR rights, contact us at:
- **Email:** support.wandr@gmail.com
- **Subject Line:** "GDPR Data Request - [Your Request Type]"
We will respond to your request within 30 days as required by GDPR.
---
## CCPA Compliance (California Residents)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
### Your CCPA Rights
- **Right to Know:** Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of that information, the purposes for collection, and the categories of third parties with whom we share it.
- **Right to Delete:** Request deletion of your personal information, subject to certain exceptions.
- **Right to Opt-Out of Sale:** We **do not sell** your personal information to third parties. We do not share your data for monetary consideration.
- **Right to Non-Discrimination:** We will not discriminate against you for exercising your CCPA rights (e.g., denying service, charging different prices, or providing a different level of service).
- **Right to Limit Use of Sensitive Personal Information:** You can limit our use of sensitive personal information (such as precise location data) by disabling location permissions in your device settings.
### Categories of Personal Information We Collect
Under CCPA, we collect the following categories of personal information:
- **Identifiers:** Email address, display name, unique device identifiers, Firebase user ID.
- **Personal Information (Cal. Civ. Code § 1798.80(e)):** Name, phone number, blood group, emergency contact information.
- **Internet or Network Activity:** App usage patterns, crash reports, analytics data.
- **Geolocation Data:** Precise GPS coordinates during trips (with your consent).
- **Audio Information:** Audio messages you record and send in chats (with your explicit action).
- **Inferences:** Preferences and behaviors derived from your usage patterns.
### How We Use Personal Information
We use your personal information for the following business purposes:
- Providing and maintaining the Service
- Personalizing your experience
- Communicating with you about trips and group activities
- Improving service quality and security
- Detecting and preventing fraud and abuse
- Complying with legal obligations
### Third Parties We Share With
We share personal information with the following categories of third parties:
- **Service Providers:**
- Google (Firebase, Google Maps) for authentication, database, storage, navigation, crash reporting, and analytics
- RevenueCat for subscription and payment processing
- SendGrid for transactional email delivery
- **Group Members:** Your display name, profile photo, and real-time location are shared with members of groups you join (as consented by you).
We **do not sell** your personal information and have not sold personal information in the past 12 months.
### Exercising Your CCPA Rights
To exercise your CCPA rights, contact us at:
- **Email:** support.wandr@gmail.com
- **Subject Line:** "CCPA Privacy Request - [Your Request Type]"
- **Verification:** We may request additional information to verify your identity before processing requests.
We will respond to verifiable consumer requests within 45 days. You may exercise these rights twice per 12-month period free of charge.
---
## International Users
WANDR is operated from India (Tamil Nadu). If you access the Service from outside India, your information will be transferred to, stored, and processed in India and other countries where our service providers operate (including the United States for Firebase/Google services). These countries may have data protection laws that differ from your jurisdiction.
By using the Service, you consent to the transfer of your information to these countries. We take appropriate measures to ensure your data is protected in accordance with this Privacy Policy and applicable laws.
---
## Security
We implement industry-standard measures to protect your data:
- All data in transit is encrypted via TLS/HTTPS.
- Sensitive personal information (phone number, blood group, emergency contacts) is stored in private Firestore subcollections accessible only to the account owner.
- PII is additionally encrypted in local secure storage (expo-secure-store).
- Firebase Security Rules enforce per-user data access controls.
- Firebase App Check protects backend APIs from abuse.
However, no method of electronic transmission or storage is 100% secure.
---
## Children's Privacy
Our Service is not directed to individuals under 13. We do not knowingly collect personal data from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete it.
---
## Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or via email. Your continued use of the Service after changes constitutes acceptance of the updated policy.
---
## Third-Party Privacy Policies
For more information about how our service providers handle your data:
- **Firebase/Google Cloud:** [Google Privacy Policy](https://policies.google.com/privacy) | [Firebase Data Processing Terms](https://firebase.google.com/terms/data-processing-terms)
- **Google Maps:** [Google Maps Privacy Policy](https://policies.google.com/privacy)
- **RevenueCat:** [RevenueCat Privacy Policy](https://www.revenuecat.com/privacy) | [WANDR's RevenueCat Data Deletion Guide](https://devdarsshan.github.io/wandr-docs/revenuecat-data-deletion.html)
- **SendGrid:** [SendGrid Privacy Policy](https://www.twilio.com/legal/privacy)
- **Firebase Crashlytics:** [Crashlytics Data Collection](https://firebase.google.com/support/privacy)
---
## Contact Us
For questions about this Privacy Policy or to exercise your data rights, contact us at:
- **Email:** support.wandr@gmail.com
---
## Jurisdiction
This Privacy Policy is governed by the laws of Tamil Nadu, India.
