πŸ›‘οΈ Privacy Policy

ProtectTrack β€” Family & Business GPS Monitoring

πŸ“… Last Updated: February 2026 πŸ“‹ Version: 1.0 🏒 Efficient AI Algorithms

⚑ Quick Privacy Actions

πŸ“Œ Privacy Summary

In plain terms, here's what you need to know:

Questions? Email us at legal@algoritmos.io

πŸ“Š Data Collection Summary

Category Specific Data Purpose Retention
πŸ“ Location Real-time GPS coordinates, location history, movement speed Display location on map, geofence alerts, route history 30 days
πŸ‘€ Account Email, name, password (hashed), phone (optional) Authentication, communication, account recovery While account is active
πŸ“± Device Model, operating system, browser, IP address, language Service functionality, security, technical support 90 days
βš™οΈ Usage Alert settings, preferences, app interactions Personalization, service improvement 12 months
πŸ’³ Payment Only last 4 digits of card (external processor handles the rest) Billing, payment history Per tax requirements (7 years)

πŸ“ 1. Information We Collect

β–Ό

1.1 Location Information (Sensitive Data)

ProtectTrack collects GPS location data from devices that activate monitoring. This is the core function of our service.

  • GPS Coordinates: Latitude and longitude with 10-50 meter precision.
  • Frequency: Updates every 15 seconds to 5 minutes, based on your settings.
  • History: We store the last 30 days of locations.
  • Speed: We detect movement speed for safety alerts.
ℹ️ Important note about precise location: Under California law (CPRA), GPS location is considered "sensitive personal information" because it can locate you within a 1,850-foot radius (560 meters). You have the right to limit how we use this information.

1.2 Account Information

When you create an account, we collect:

  • Email address
  • Name (or nickname)
  • Password (stored with secure hash, never in plain text)
  • Phone number (optional, for account recovery)
  • Role in family group (admin, member, monitored person)

1.3 Device Information

We automatically collect technical information:

  • Device model and manufacturer
  • Operating system and version
  • Browser used
  • IP address (for security and fraud detection)
  • Language and timezone
  • Battery level (for low battery alerts)

1.4 Usage Information

To improve the service, we record:

  • Geofence and alert settings
  • App usage frequency
  • Errors and technical issues

1.5 Information We DON'T Collect

  • ❌ Text message or call content
  • ❌ Photos, videos, or files from your device
  • ❌ Web browsing history
  • ❌ Your phone contacts
  • ❌ Social media information
  • ❌ Biometric data (fingerprint, face)

βš™οΈ 2. How We Use Your Information

β–Ό

2.1 Primary Purposes

We use your information exclusively to:

  • Provide the service: Display real-time locations on the family map.
  • Safety alerts: Notify you when someone enters or leaves a safe zone (geofence).
  • Route history: Allow you to review the last 30 days of locations.
  • SOS button: Process emergency alerts and notify designated contacts.
  • Communication: Send you important alerts about your account or service.

2.2 Secondary Purposes

  • Security: Detect and prevent unauthorized access to your account.
  • Service improvement: Analyze aggregated usage patterns (never individual) to improve the app.
  • Technical support: Diagnose issues when you contact us.
  • Legal compliance: Respond to valid legal requests.

2.3 What We DON'T Do with Your Data

βœ… Our commitment:
  • We DON'T sell your location to third parties. Ever.
  • We DON'T share data with data brokers.
  • We DON'T use your location for targeted advertising.
  • We DON'T create behavioral profiles for marketing.
  • We DON'T train artificial intelligence with your data.

2.4 Legal Basis for Processing

Under applicable laws, we process your data based on:

  • Explicit consent: You voluntarily activate location monitoring.
  • Contract execution: To provide the service you requested.
  • Legitimate interests: For security and fraud prevention.
  • Legal obligation: When the law requires us to retain certain data.

🀝 3. Who We Share With (and Who We Don't)

β–Ό

3.1 Sharing WITHIN Your Family Group

Your location is visible to family group members you authorize. You control who can see your location.

3.2 Service Providers (Under Strict Contract)

We work with essential providers who only process data according to our instructions:

  • Cloud infrastructure: Secure servers to store encrypted data.
  • Payment processor: To securely handle transactions (we never see your full card).
  • Email service: To send you alerts and notifications.
  • Maps: To display locations (we only send coordinates, not identity).

All our providers sign data processing agreements that prohibit them from using your information for their own purposes.

3.3 Authorities (Only with Valid Legal Process)

We may disclose information if we receive:

  • Valid court order
  • Legal subpoena
  • Emergency request to prevent imminent harm to a person

We will notify the affected user before disclosure unless the law prohibits it or there's a safety risk.

3.4 Who We NEVER Share With

🚫 Absolute prohibition:
  • ❌ Data brokers
  • ❌ Advertisers or ad networks
  • ❌ Social networks
  • ❌ Insurance companies
  • ❌ Employers (without explicit employee consent)
  • ❌ Any third party for marketing purposes

This is a fundamental difference from other family tracking services. We never monetize your location data.

⏱️ 4. Data Retention

β–Ό

4.1 Specific Retention Periods

Data Type Retention Period Reason
Location history 30 days Balance between utility and privacy
Account data While account is active + 30 days Provide the service
Device logs 90 days Security and diagnostics
Aggregated usage data 12 months Service improvement
Billing records 7 years Legal tax requirements
Children's data (post-deletion) Immediate deletion COPPA compliance

4.2 Automatic Deletion

Our systems automatically delete location history after 30 days. No action required from you.

4.3 Deletion Upon Request

You can request deletion of all your data at any time. We'll process your request within:

  • California (CCPA): 45 days
  • European Union (GDPR): 30 days
  • Brazil (LGPD): 15 days

4.4 Inactive Account

If your account remains inactive for 24 months, we'll notify you before deleting your data.

πŸ” 5. Data Security

β–Ό

5.1 Encryption

  • In transit: All communication uses TLS 1.3 (the most secure standard available).
  • At rest: Your location data is stored encrypted with AES-256.
  • Passwords: Hashed with bcrypt, never stored in plain text.

5.2 Access Controls

  • Two-factor authentication (2FA) available for all accounts.
  • Sessions expire automatically after inactivity.
  • Login notifications from new devices.
  • Account lockout after failed attempts.

5.3 Infrastructure

  • Servers in SOC 2 Type II certified data centers.
  • 24/7 security monitoring.
  • Encrypted backups.
  • No data access without documented authorization.

5.4 Breach Notification

In case of a security breach affecting your data:

  • Arizona: Notification within 45 days.
  • California: Notification within 30 days.
  • Florida/Connecticut (if includes location): Notification within 30-60 days.

We'll inform you what data was affected and what steps to take to protect yourself.

ℹ️ Encryption Safe Harbor: Since all location data is encrypted, in most states a breach of encrypted data doesn't require notification if encryption keys remain secure.

βš–οΈ 6. Your Privacy Rights

β–Ό

Depending on your location, you have different rights over your data. We respect the broadest rights for all our users, regardless of location.

6.1 Rights by Jurisdiction

Right πŸ‡ΊπŸ‡Έ CCPA (California) πŸ‡ͺπŸ‡Ί GDPR (Europe) πŸ‡§πŸ‡· LGPD (Brazil)
Know what data we have βœ… Yes βœ… Yes βœ… Yes
Access and download data βœ… Yes βœ… Yes (portability) βœ… Yes
Correct inaccurate data βœ… Yes βœ… Yes βœ… Yes
Delete data βœ… Yes βœ… Yes βœ… Yes
Limit use of sensitive data βœ… Yes (location) βœ… Yes βœ… Yes
Object to processing β€” βœ… Yes βœ… Yes
Non-discrimination for exercising rights βœ… Yes βœ… Yes βœ… Yes
Response time 45 days 30 days 15 days

6.2 Right to Limit Use of Sensitive Information (CPRA)

πŸ”’ Your right under California law: Since GPS location is "sensitive personal information," you have the right to limit its use to only what's necessary to provide the service. To exercise this right, send an email to legal@algoritmos.io with the subject "Limit Use of Sensitive Information."

6.3 Global Privacy Control (GPC)

We respect the Global Privacy Control (GPC) signal from your browser. If your browser sends a GPC signal, we automatically:

  • Won't share your data with third parties for advertising (though we already don't).
  • Treat the signal as an opt-out request under CCPA.

GPC is mandatory in 12+ U.S. states. Learn more at globalprivacycontrol.org.

6.4 How to Exercise Your Rights

You can exercise any privacy right:

  1. From the app: Go to Settings β†’ Privacy β†’ My Data.
  2. By email: Write to legal@algoritmos.io
  3. By mail: Efficient AI Algorithms, Maricopa County, Arizona, USA

We'll verify your identity before processing sensitive requests, using the email associated with your account.

6.5 Authorized Agents

You may designate an authorized agent to exercise rights on your behalf. The agent must provide:

  • Written authorization signed by you, or
  • Valid power of attorney

πŸ‘Ά 7. Children's Privacy (COPPA)

β–Ό

ProtectTrack complies with the U.S. Children's Online Privacy Protection Act (COPPA), including the 2025 amendments effective April 22, 2026.

7.1 Verifiable Parental Consent (VPC)

Before a parent can activate monitoring of a child under 13, we require verifiable parental consent using one of these FTC-approved methods:

  • Credit card verification: A small charge during subscription.
  • Identity verification: Government ID with photo comparison.
  • "Text plus" verification: Text message plus additional confirmatory step.

7.2 Information We Collect from Children

For devices of children under 13, we only collect:

  • GPS location (primary purpose of the service)
  • Name or nickname (assigned by parent)
  • Device identifier

We DO NOT collect email, phone, or other personal data directly from children.

7.3 Parental Rights

Parents can at any time:

  • βœ… Review their child's location data
  • βœ… Delete their child's data
  • βœ… Revoke consent and deactivate monitoring
  • βœ… Refuse to allow future collection

7.4 We Don't Share Children's Data with Third Parties

🚫 Absolute prohibition: We never share data of children under 13 with third parties for advertising, monetization, or AI training. This is prohibited by COPPA and contrary to our values.

7.5 Retention and Deletion

Children's data is deleted:

  • Automatically after 30 days (location history)
  • Immediately if parent revokes consent
  • When the child turns 13 (parent decides whether to continue)

7.6 Teenagers (13-17 years)

For teenagers between 13 and 17 years old:

  • 13-15 years: Parents maintain control, but the teenager receives visible notification that they're being monitored.
  • 16-17 years: The teenager can request to limit certain features, with notification to parent.

πŸ‘₯ 8. Monitored Individuals

β–Ό

ProtectTrack serves different groups of monitored individuals, each with special considerations.

8.1 Elderly Adults with Alzheimer's or Dementia

Monitoring people with cognitive conditions requires special ethical considerations:

  • Advance consent: We recommend the monitoring decision be made while the person still has decision-making capacity.
  • Legal representative: If the person cannot consent, we require documentation of:
    • Court-appointed guardianship, or
    • Power of attorney for healthcare decisions
  • Dignity: Monitoring should be as minimally invasive as possible while fulfilling its safety purpose.

8.2 Employees (Business Use)

For fleet and field team monitoring:

  • Required notification: Employees must be informed in writing before activating monitoring.
  • Consent: We require explicit consent for employee personal devices.
  • Work hours: We recommend monitoring be automatically suspended outside work hours.
  • Company vehicles: Monitoring company vehicles is generally legal with proper notification.
⚠️ Important note for employers: California makes it a criminal offense to track a vehicle without consent from both the owner and driver. Make sure to comply with labor laws in your jurisdiction.

8.3 Rights of All Monitored Individuals

Every monitored adult has the right to:

  • Know they're being monitored (visible indicator required)
  • Access their own location data
  • Request a copy of their data
  • Request deletion of their data

πŸ›‘οΈ 10. Abuse Protection

β–Ό

We recognize that family tracking apps can be misused for unwanted surveillance or domestic violence. We take this very seriously.

10.1 Visible Tracking Indicator

Every monitored device displays a permanent, non-hideable indicator that tracking is active. This is mandatory and cannot be disabled by the administrator.

10.2 Independent Exit for Adults

Any monitored adult can:

  • Pause their own monitoring at any time
  • Leave a family group without administrator approval
  • Delete their data independently

The administrator will receive a notification, but cannot prevent these actions.

10.3 Help Resources

πŸ†˜ If you're in an abusive situation:

If someone is using this or another app to control you without your consent, get help:

  • National Domestic Violence Hotline (USA): 1-800-799-7233
  • Online chat: thehotline.org
  • UK: 0808 2000 247 (National Domestic Abuse Helpline)
  • Canada: 1-800-363-9010

These hotlines won't appear in your call history if you call from a landline.

10.4 Report Abuse

If you suspect ProtectTrack is being used to harass or control someone:

  • Confidential email: legal@algoritmos.io
  • We'll investigate and may suspend accounts that violate our policies
  • We cooperate with authorities when there's evidence of crime

10.5 Proactive Detection

We monitor for patterns that could indicate abusive use, such as:

  • Attempts to hide that tracking is active
  • Monitoring adults without their apparent knowledge
  • Coercive control patterns

🌍 11. International Transfers

β–Ό

11.1 Server Location

Our primary servers are located in the United States. If you access ProtectTrack from outside the U.S., your data will be transferred to the U.S.

11.2 Safeguards for EU Users

For users in the European Economic Area (EEA), United Kingdom, and Switzerland:

  • We use Standard Contractual Clauses (SCCs) approved by the European Commission.
  • We implement supplementary technical measures, including end-to-end encryption.
  • Your GDPR rights are respected regardless of where data is processed.

11.3 Safeguards for Brazilian Users

For Brazilian users protected by LGPD:

  • Transfers based on explicit consent or standard contractual clauses.
  • You have the right to request information about who we share your data with internationally.

11.4 Equivalent Privacy

Regardless of where you live, we grant you the same privacy rights that the most protective laws (GDPR and LGPD) guarantee their citizens.

πŸ“ 12. Changes to This Policy

β–Ό

12.1 How We'll Notify You

If we make material changes to this policy:

  • We'll send you an email at least 30 days in advance
  • We'll display a prominent notice in the app
  • We'll update the "last updated" date at the top

12.2 Material Changes

We consider "material changes" to be:

  • New categories of data we collect
  • New purposes for using your data
  • Changes in who we share data with
  • Changes to your privacy rights
  • Changes in retention periods

12.3 Your Consent for Changes

If changes affect how we use data we've already collected, we'll require your explicit consent before applying changes to your existing data.

12.4 Version History

  • Version 1.0 (February 2026): Initial version

πŸ“§ 13. Contact

β–Ό

Data Protection Officer (DPO)

Efficient AI Algorithms

πŸ“§ Email: legal@algoritmos.io

πŸ“ Location: Maricopa County, Arizona, USA

🌐 Web: algoritmos.io

Guaranteed Response Times

  • General inquiries: 5 business days
  • CCPA requests (California): 45 calendar days
  • GDPR requests (Europe): 30 calendar days
  • LGPD requests (Brazil): 15 calendar days
  • Abuse reports: 24-48 hours

Complaints to Authorities

If you're not satisfied with our response, you can file a complaint with:

  • California: California Attorney General's Office
  • EU: Your local data protection authority
  • Brazil: National Data Protection Authority (ANPD)