AUTOPHONE COMPREHENSIVE PRIVACY POLICY
Last Updated: July 31, 2026 Effective Date: July 1, 2026
1. INTRODUCTION AND SCOPE
Welcome to Autophone. This Comprehensive Privacy Policy ("Policy") is designed to inform you about the collection, use, disclosure, transfer, and storage of your personal information when you use the Autophone mobile application, website, and related services (collectively, the "Services").
Autophone is operated by an independent developer ("Company," "we," "us," or "our"). We are committed to protecting your privacy and ensuring that your personal data is handled in a safe, transparent, and legally compliant manner.
This Policy applies to all users of our Services globally and incorporates specific provisions required by the General Data Protection Regulation (GDPR) for the European Economic Area (EEA) and the United Kingdom (UK GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the Personal Data Protection Act of Singapore (PDPA), the Australian Privacy Act, and the Brazilian General Data Protection Law (LGPD), as well as other applicable data protection laws.
By accessing, downloading, installing, or using the Services, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree with this Policy, you must immediately cease using the Services and delete the application from your device.
2. DEFINITIONS
For the purposes of this Policy:
- "Personal Data" or "Personal Information" means any information relating to an identified or identifiable natural person. This includes, but is not limited to, your name, email address, physical location, IP address, and vehicle license plate number.
- "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- "Data Controller" refers to Autophone, the entity that determines the purposes and means of the processing of Personal Data.
- "Data Processor" refers to third-party entities that process Personal Data on behalf of the Data Controller (e.g., Supabase, Expo).
- "User," "you," or "your" refers to the individual accessing or using the Services.
3. CATEGORIES OF DATA WE COLLECT
We collect various types of information to provide and improve our Services. The collection of this data is necessary for the performance of the contract between you and us, and to comply with our legal obligations.
3.1. Information You Provide Directly to Us
When you interact with our Services, you may provide us with the following categories of Personal Data:
- Account Registration Data: When you create an account via third-party OAuth providers (Google or Apple), we collect your email address, an authentication token, and the default profile name provided by the third party.
- Profile Data: You may optionally provide a nickname, a profile picture (avatar), a phone number, and a user status (e.g., "Owner," "Driver," "Other").
- Vehicle and License Plate Data: The core functionality of Autophone involves registering vehicle license plates. We collect the license plate number, country code, region, vehicle brand, and vehicle color.
- User-Generated Content and Media: We collect photographs you upload, including photos of license plates and vehicles. The first photo of a vehicle you upload may automatically be set as a secondary avatar for public display.
- Communications Data: We collect the content of chat messages, including text, images, videos, and documents exchanged between users within the App.
- Customer Support Data: When you contact us for support or submit moderation reports, we collect the content of your communication, including any attached screenshots and reasons for reporting.
3.2. Information We Collect Automatically
When you access or use the Services, we automatically collect certain information about your device and interaction with the App:
- Device Information: We collect information about your mobile device, including the hardware model, operating system and version, unique device identifiers, and mobile network information.
- Log and Usage Data: Our servers automatically record information created by your use of the Services, such as app crash reports, system activity, and the date, time, and referrer URL of your requests. We utilize `expo-insights` to track anonymous "cold start" events to understand app usage across different platforms and versions.
- Push Notification Tokens: We collect Expo Push Tokens to deliver real-time notifications to your device regarding new messages or account activities.
- IP Address: Your Internet Protocol (IP) address is temporarily processed by our cloud infrastructure provider (Supabase) to establish a connection, but we do not actively extract, store, or profile you based on your IP address.
3.3. Information from Third Parties
We do not purchase or acquire Personal Data from data brokers or marketing agencies. The only third-party data we receive is the authentication payload from Google or Apple when you log in.
3.4. Sensitive Personal Data and Biometrics
Autophone does not intentionally collect special categories of Personal Data (such as race, religion, political opinions, or health data). While you may upload photographs (avatars) that depict your face, we do not apply facial recognition technology or biometric processing to uniquely identify you.
3.5. Advertising and Device Identifiers
When advertising is enabled in the App, we and our advertising partners may collect:
- Advertising Identifiers: On iOS, the Identifier for Advertisers (IDFA) is accessed only if you grant permission through Apple's App Tracking Transparency (ATT) prompt. On Android, the Google Advertising ID (AAID) may be used in accordance with your device settings and consent choices.
- Ad Interaction Data: Information about the ads served to you and your interactions with them (e.g., impressions and clicks).
- Approximate Location: Our advertising partner (Google AdMob) may infer an approximate, coarse location (e.g., derived from your IP address) to serve more relevant ads. We do not collect precise GPS location for advertising.
See Section 6.4 for details on personalization, consent, and how to opt out.
3.6. Subscription and Purchase Data
If you purchase the optional AutoPRO subscription, we collect your subscription status, plan, and renewal state so we can unlock premium features. All payment and card details are processed exclusively by the Apple App Store or Google Play Store and by our subscription manager (RevenueCat); we never receive or store your full payment card information.
4. HOW WE USE YOUR PERSONAL DATA
We process your Personal Data for the following specific, explicit, and legitimate purposes:
4.1. Core Service Provision (Performance of Contract)
- To create, manage, and authenticate your user account.
- To maintain the registry of vehicle license plates and associate them with your profile.
- To facilitate real-time messaging, communication, and media sharing between users.
- To display your public profile, avatars, and registered plates to other users within the App's search and directory features.
4.2. Platform Security and Moderation (Legitimate Interest)
- To enforce our Terms of Service and Community Guidelines.
- To process and review moderation reports regarding abusive behavior, illegal content, or disputed plate ownership.
- To maintain a blocklist allowing you to prevent specific users from contacting you.
- To detect, prevent, and address technical issues, fraud, spam, and security breaches.
4.3. Communication and Notifications (Consent / Legitimate Interest)
- To send you push notifications regarding new chat messages, account updates, or administrative notices. You can manage your notification preferences within your device OS settings.
- To respond to your customer support inquiries and data subject access requests.
4.4. Analytics and Improvement (Legitimate Interest)
- To analyze aggregated, anonymized usage trends (via Expo Insights) to improve the App's performance, user interface, and overall user experience.
4.5. Advertising (Consent / Legitimate Interest)
- To display advertising that supports the free version of the App and, where you have given the required consent (via the ATT prompt on iOS and/or the Google consent form in the EEA/UK), to show personalized advertising. Where consent is not given, the ads shown are non-personalized. See Section 6.4.
5. PUBLIC NATURE OF CERTAIN DATA
CRITICAL DISCLOSURE: By the nature of Autophone's social networking features, certain data you provide is inherently public and visible to any authenticated user of the App.
Publicly Visible Data includes:
- Your Nickname (unless "Hide Nickname" is enabled).
- Your Primary Avatar and Secondary Avatar (vehicle photo).
- Your User Status (Owner/Driver).
- The License Plate Numbers, Country Codes, Regions, Car Brands, and Car Colors you have registered.
- The Photos of License Plates and Vehicles you have uploaded.
- Your Phone Number (ONLY if you explicitly choose to provide it in your profile).
Private Data includes:
- Your Email Address (hidden from all users).
- Your Chat Messages and Chat Media (visible only to participants of that specific conversation).
- Your Blocked Users list.
How Search and Contact Work: Other users can find you by searching for a license plate number that you have registered. When your plate matches a search, they can see your registered plate(s), vehicle brand, color, and photos, and your nickname (unless "Hide Nickname" is enabled). Because you register your own plate, you become reachable for in-app messages only after you have voluntarily added that plate to your profile. Plates that have not been registered by their owner cannot be used to contact anyone. If you do not wish to be contacted, you may remove the plate, enable "Hide Nickname," block specific users, or delete your account at any time.
6. DATA SHARING AND DISCLOSURE
We do not sell, rent, or trade your Personal Data to third parties for commercial or marketing purposes. We may share your data under the following limited circumstances:
6.1. Third-Party Service Providers (Data Processors)
We engage trusted third-party service providers to perform functions on our behalf. These processors are bound to process your data only on our instructions and in compliance with applicable law. Each processor's own privacy policy governs how it handles data:
- Supabase Inc. (USA): PostgreSQL database, authentication (Supabase Auth), file storage (Supabase Storage), and edge functions. Privacy policy: https://supabase.com/privacy
- Expo / EAS (USA): Mobile framework, over-the-air (OTA) updates, push notification delivery, and anonymous usage analytics (Expo Insights). Privacy policy: https://expo.dev/privacy
- Google / Google AdMob (USA): In-app advertising, ad delivery, and measurement. Privacy policy: https://policies.google.com/privacy ; AdMob data disclosures: https://support.google.com/admob/answer/6128543
- RevenueCat, Inc. (USA): Management and validation of in-app subscriptions and purchases. Privacy policy: https://www.revenuecat.com/privacy
- Apple Inc. and Google LLC: Authentication (Sign in with Apple / Google OAuth) and processing of in-app purchases through the App Store and Google Play.
6.2. Legal Compliance and Law Enforcement
We may disclose your Personal Data if we believe in good faith that such action is necessary to:
- Comply with a valid legal obligation, subpoena, court order, or search warrant.
- Protect and defend the rights, property, or safety of Autophone, our users, or the public.
- Prevent or investigate possible wrongdoing in connection with the Services.
- Protect against legal liability.
6.3. Business Transfers
If Autophone is involved in a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of its assets, your Personal Data may be transferred as part of that transaction. We will notify you via the App or email before your Personal Data is transferred and becomes subject to a different Privacy Policy.
6.4. Advertising, Personalization, and Your Choices
The free version of the App is supported by advertising provided through Google AdMob. Depending on your consent, ads may be personalized (based on advertising identifiers and inferred interests) or non-personalized.
- Apple App Tracking Transparency (iOS): We request your permission through the ATT prompt before accessing your IDFA or tracking you across apps and websites owned by other companies. If you decline, you will still see ads, but they will not be personalized using cross-app tracking.
- Google User Messaging Platform (EEA/UK): In regions governed by the GDPR, we present a Google-certified consent form (UMP) that lets you consent to or refuse personalized ads.
- Managing Your Consent: You can change or withdraw your advertising consent at any time via Settings → "Ad Consent Settings" in the App. You can also opt out of, or reset, your advertising identifier through your device settings (iOS: Settings → Privacy & Security → Tracking / Apple Advertising; Android: Settings → Google → Ads) and manage Google ad personalization at https://adssettings.google.com.
- Cookies, SDKs, and Local Storage: The App is not a website and does not use browser cookies. However, our embedded SDKs (Google AdMob, Expo, RevenueCat) and our authentication layer store identifiers and tokens in your device's local application storage to operate the Services and, where permitted, to deliver and measure advertising.
We do not share your name, email address, chat contents, or registered plate data with advertising networks for their own independent marketing purposes.
7. INTERNATIONAL DATA TRANSFERS
Autophone is operated remotely, and our servers and data processors (e.g., Supabase, Expo) are primarily located in the United States.
By using the Services, you explicitly consent to the transfer, storage, and processing of your Personal Data outside of your country of residence, including to the United States, which may have data protection laws that are different from those in your jurisdiction.
For users in the EEA or UK, we rely on Standard Contractual Clauses (SCCs) and appropriate adequacy decisions to ensure that your data is adequately protected when transferred to our processors in the US.
8. DATA RETENTION AND DELETION
We retain your Personal Data only for as long as is strictly necessary for the purposes set out in this Policy.
8.1. Active Accounts
As long as your account is active, we retain your profile data, plates, messages, and media to provide the Services continuously.
8.2. Account Deletion Process
You have the right to delete your account at any time via the in-app Settings menu. Upon initiating account deletion:
- Your authentication record, profile, registered plates, chat messages, and block lists are immediately and irreversibly deleted from our active database.
- Files uploaded to our cloud storage (avatars, plate photos, chat media) are scheduled for deletion. Due to technical limitations of distributed cloud storage, it may take up to 30 days for these files to be permanently purged from all backup servers.
8.3. Legal Exceptions
We may retain certain data for a longer period if required to do so for legal, tax, or accounting purposes, or to resolve ongoing disputes, enforce our agreements, or prevent fraud.
9. SECURITY OF YOUR DATA
We implement robust technical and organizational security measures to protect your Personal Data from unauthorized access, accidental loss, destruction, or alteration. These measures include:
- Encryption: All data in transit is encrypted using HTTPS/TLS.
- Access Controls: We employ strict Row Level Security (RLS) policies in our Supabase database to ensure users can only access their own private data and messages belonging to their conversations.
- Authentication: Secure OAuth 2.0 flows mean we never touch or store your passwords.
- Storage: Session tokens are stored securely in encrypted local storage on your mobile device.
Despite our best efforts, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security. In the event of a severe data breach, we will notify you and relevant regulatory authorities in accordance with applicable laws.
10. AGE RESTRICTION AND MINORS' PRIVACY
The Services are strictly intended for adults who are 18 years of age or older. The Services are not directed to, and we do not knowingly collect Personal Data from, anyone under the age of 18.
If you are a parent or guardian and you become aware that a person under the age of 18 has provided us with Personal Data, please contact us immediately. If we become aware that we have collected Personal Data from a person under the age of 18, we will take immediate steps to delete that information from our servers and terminate the associated account.
11. YOUR PRIVACY RIGHTS (GLOBAL)
Depending on your jurisdiction, you may have specific rights regarding your Personal Data. We extend these core rights to all our users, regardless of location:
- The Right to Access: You have the right to request a copy of the Personal Data we hold about you.
- The Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- The Right to Erasure ("Right to be Forgotten"): You have the right to request that we erase your Personal Data via the in-app deletion tool.
- The Right to Restrict Processing: You have the right to request that we restrict the processing of your Personal Data under certain conditions.
- The Right to Object to Processing: You have the right to object to our processing of your Personal Data based on legitimate interests, including profiling for personalized advertising. You can exercise this in-app via Settings → "Ad Consent Settings" or through your device's tracking controls.
- The Right to Data Portability: You have the right to request that we transfer the data that we have collected to another organization, or directly to you, in a structured, commonly used, and machine-readable format.
To exercise any of these rights, please submit a Data Subject Access Request (DSAR) by emailing autophonedev@gmail.com. We have 30 days to respond to your request.
12. JURISDICTION-SPECIFIC NOTICES
12.1. California Residents (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, provides you with specific rights.
- No Sale for Money: We do not sell your Personal Information for monetary consideration.
- "Sharing" for Personalized Ads: When you consent to personalized advertising, the use of advertising identifiers by our advertising partner (Google) may qualify as "sharing" for "cross-context behavioral advertising" under the CPRA. You have the right to opt out of this sharing at any time via Settings → "Ad Consent Settings" in the App, by declining the App Tracking Transparency prompt on iOS, or through your device advertising controls. Because the Services are restricted to adults, we do not knowingly share or sell the Personal Information of any consumer under 18 years of age.
- Categories Collected: Identifiers (including device and advertising identifiers), Personal information categories listed in the California Customer Records statute, commercial information (subscription status), Internet or other similar network activity, and approximate geolocation used for advertising.
- Right to Know, Delete, and Correct: You have the right to request the specific pieces of Personal Information we have collected about you, and to request their correction or deletion.
- Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.
12.2. European Economic Area and UK Residents (GDPR)
Our legal bases for processing your data are outlined in Section 4. If you believe our processing of your Personal Data infringes data protection laws, you have a legal right to lodge a complaint with a supervisory authority responsible for data protection in your country of habitual residence, place of work, or place of the alleged infringement.
12.3. Brazil Residents (LGPD)
In accordance with the Lei Geral de Proteção de Dados (LGPD), you have the right to confirmation of the existence of processing, access to data, correction of incomplete/inaccurate data, anonymization/blocking/deletion of unnecessary data, portability, and revocation of consent.
13. CHANGES TO THIS PRIVACY POLICY
We may update this Comprehensive Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or regulatory guidance. We will notify you of any material changes by posting the new Privacy Policy within the App and updating the "Last Updated" date at the top of this document. We may also provide notice via push notification.
You are advised to review this Privacy Policy periodically for any changes. Your continued use of the Services after the posting of changes constitutes your binding acceptance of such changes.
14. CONTACT US
If you have any questions, concerns, or complaints about this Privacy Policy, our data collection practices, or if you wish to exercise your legal rights, please contact us at:
Autophone Support & Privacy Team Email: autophonedev@gmail.com