Version 2026-07-19
Privacy policy
This policy explains what personal information RouteBeer collects through the website, test-update signup, and beta app, why we use it, who we share it with, and the choices and rights available to you.
Who is responsible for your information
RouteBeer is currently operated by Ben Keenan, who is the data controller for the processing described in this policy.
Privacy questions and requests can be sent to [email protected].
Information we collect
Website and test updates
When you ask to receive RouteBeer test updates, we collect:
- your email address and preferred platform;
- whether you agreed to receive testing and product emails;
- the page, referral, and campaign information associated with your signup, where available;
- the form and privacy-policy versions and submission time; and
- basic request information such as your browser user agent, IP address, and security or delivery logs processed by Cloudflare.
TestFlight and Google Play testing
The testing buttons take you to Apple TestFlight or Google Play. RouteBeer does not send your test-update signup details to Apple or Google when you follow one of these links. Apple or Google may process your platform account, device, operating-system, installation, usage, crash, and feedback information under their own privacy terms.
RouteBeer receives the tester, installation, session, crash, and feedback information that Apple or Google makes available to app developers. For TestFlight invitations accepted through a public link, Apple does not show RouteBeer your name or email address, although feedback and diagnostic information may still be shared. Email invitations and Google Play testing tracks may identify testers through the account or email used to join.
Beta app
If you use the beta app, we collect information you provide and information created through your use of RouteBeer, including:
- account and authentication details, including your user ID, email address, sign-in provider, verification status, and sign-in metadata;
- profile information such as your username, photo, bio, preferences, and onboarding state;
- friend relationships, requests, crawl invitations, and participant details;
- routes, venue choices, place information, route visibility, saved routes, and likes;
- crawl schedules, participation, check-ins, progress, comments, photos, drink logs, ratings, game choices, and scores;
- notification tokens and preferences;
- privacy choices for analytics, crash reporting, session replay, and advertising;
- your marketing email choice, including whether you opted in or declined, when you decided, and the version of the consent wording you were shown;
- safety reports, support messages, and feedback; and
- technical and diagnostic information described below.
Marketing emails from the app
During account setup, and at any time afterwards in Privacy & data, the app offers an optional choice to receive emails about new RouteBeer features, updates, and events. This choice is unticked by default and is never required to create an account or use RouteBeer.
If you opt in, we use your account email address to send these emails. Whether or not you opt in, we record your choice, the time you made it, and the version of the consent wording you saw, as proof of your decision. You can opt out at any time using the Marketing emails toggle in Privacy & data or the unsubscribe link in any marketing email. Service emails that are needed to run your account, such as email verification, are separate and are not affected by this choice.
Location information
RouteBeer can request precise device location for nearby-route discovery, map positioning, distance and proximity checks, crawl progress, live sharing, and route recaps. RouteBeer only starts continuous location collection after you join an active crawl, see the in-app disclosure, grant device permission, and enable route recording or live location sharing.
- One-off location: the app may read your current position to show nearby routes, centre a map, or estimate distance to a venue. This is normally used on your device and is not stored as a live-location record.
- Live location: during an active private crawl, RouteBeer can store your latest latitude, longitude, timestamp, accuracy, and associated crawl so eligible participants in that private crawl can see your current position while live sharing is enabled.
- Route recording: while crawl tracking is active and Record route for recap is enabled, RouteBeer records precise trail points to calculate distance and create a route recap. Participants in the completed crawl can view recap trails.
- Check-ins and history: venue check-ins, timestamps, completed route history, distance, moving time, and recap information may be retained as part of your crawl history.
Background location: if route recording or live location sharing is enabled for an active crawl, RouteBeer continues collecting precise location when the app is in the background, closed, or not in use. On Android, an ongoing notification identifies when this collection is active. Collection stops when the crawl ends, you leave it, you switch off both location features, or you withdraw location permission.
Route recording and live sharing have separate controls. Switching off live sharing removes your current live-location record and stops other participants seeing your position, but does not delete an already recorded recap trail. Switching off route recording stops new trail points being stored. You can request deletion of retained location data or delete your account as described under Deletion requests.
Public crawls are designed to show venue or stop progress rather than precise participant locations. Device settings let you deny or withdraw location permission, but some nearby, check-in, live-map, and recap features will then be unavailable. RouteBeer does not use or share precise device or crawl location for advertising, analytics, or session replay.
Analytics, diagnostics, and session replay
The beta app uses Firebase Analytics, Firebase Crashlytics, and PostHog for product analytics, feature flags, crash and error reporting, and session replay where enabled. These services may process app and screen events, app version, device and session identifiers, feature usage, crash details, stack traces, and limited diagnostic context such as a crawl ID, game mode, or crawl status.
PostHog is configured to capture events anonymously — events are not linked to your account or personal profile. PostHog is also configured to mask text and images in session replay. We do not intentionally include private comments, uploaded photos, precise coordinates, passwords, or payment information in analytics or diagnostic event properties.
You can switch product analytics, crash reporting, and session replay on or off in the app's privacy settings. Essential feature-flag checks may continue without creating an analytics profile because they control which app features are available.
The public website does not currently run RouteBeer product analytics or session replay. If that changes, we will update this policy and the cookie notice and introduce any consent controls required before non-essential tracking starts.
Advertising and advertising consent
The app uses Google AdMob and the Google Mobile Ads SDK to display ads. The SDK may automatically collect and share:
- your IP address, which may be used to estimate general location;
- ad and app interactions such as app launches, ad impressions, taps, and video views;
- diagnostic information about the app and advertising SDK; and
- device or advertising identifiers, including the Android advertising ID or Apple's advertising identifier where available and permitted.
Google and participating advertising partners may use this information to deliver and measure ads, limit repeated ads, produce aggregated reporting, detect fraud and abuse, and personalise ads where you have consented. If personalised advertising is unavailable or you do not consent, the app may still show non-personalised or limited ads based on factors such as the app's content and your general location.
For users in the EEA, UK, and Switzerland, RouteBeer uses Google's User Messaging Platform to present advertising privacy choices before requesting ads where required. You can accept, refuse, or manage the listed purposes and advertising partners. Where the app indicates that privacy options are required, you can revisit or withdraw those choices from Privacy & data in the app by selecting Manage ad privacy.
On iOS, RouteBeer may also ask for permission under Apple's App Tracking Transparency framework before accessing the advertising identifier. Refusing this permission does not prevent you using RouteBeer and does not stop all ads, but it limits tracking and personalised advertising. You can change this permission in iOS Settings. Android users can reset or delete their advertising ID using Android's privacy settings.
RouteBeer does not intentionally send Google your name, email address, private comments, uploaded photos, or precise crawl location for advertising. To learn more, see how Google uses information from apps that use its services and the Google privacy policy.
Why we use your information and our lawful bases
- Providing the beta service — contract: we use account, profile, route, crawl, location, content, and notification data to provide the features you request and administer your beta access.
- Testing, product, and marketing emails — consent: we use your test-update signup, or the marketing choice you make in the app, to send invitations, updates, and news about new features and events where you have agreed to receive them. You can withdraw consent at any time using the unsubscribe link in any email, the Marketing emails toggle in the app's Privacy & data settings, or by contacting us.
- Advertising — consent and legitimate interests: where required, we rely on your consent for advertising identifiers, local device access, and personalised advertising. Where permitted, we have a legitimate interest in showing contextual or non-personalised ads to help fund RouteBeer, measuring basic ad performance, and preventing advertising fraud. You can refuse or withdraw advertising consent without losing access to the app.
- Safety, security, support, and service improvement — legitimate interests: we use reports, technical logs, fraud-prevention information, diagnostics, and limited product-usage information to protect RouteBeer and its users, resolve problems, and improve the beta. Our interests are running a safe, reliable service and learning whether features work. You can object to processing based on legitimate interests.
- Legal and regulatory requirements — legal obligation or legitimate interests: we may retain or disclose limited information where reasonably necessary to comply with law, establish or defend legal claims, or respond to regulators.
You do not have to sign up for test updates or provide optional profile, content, analytics, diagnostic, replay, or live-sharing information. Information marked as required is needed to create an account, administer beta access, or provide the feature you requested.
Who processes or receives your information
We do not sell your personal information. We share it only as needed to operate RouteBeer, provide features you request, protect users, or meet legal obligations.
- Cloudflare: website delivery, security, Pages Functions, and test-update signup storage.
- Loops: contact management and delivery of testing, product, and marketing emails you agreed to receive.
- Google and Firebase: authentication, Firestore database, file storage, cloud functions, messaging, app protection, analytics, Crashlytics, Google sign-in, maps, places, route estimates, and AI-assisted route generation. AI-assisted route generation uses Google's AI APIs to suggest venue sequences based on criteria you provide; we do not send personal information such as your name or account details to these APIs. Firebase App Check processes device integrity information to protect the service against abuse; this is not used for analytics or advertising.
- Google AdMob and advertising partners: ad delivery, personalisation where permitted, measurement, reporting, frequency control, and fraud prevention. The advertising partners available for a particular user are shown in Google's advertising privacy form where required.
- PostHog: app analytics, feature flags, diagnostics, and masked session replay.
- Apple and Google: sign-in, TestFlight or Google Play beta distribution, tester administration, installation and usage reporting, crashes, and tester feedback where applicable.
- Other crawl participants: information you choose to share in a crawl, such as your profile, participation, check-ins, comments, photos, scores, and—where enabled—live location or recap trail.
- Service providers introduced later: for example, an email or support provider. We will update this policy where a material new use or recipient is introduced.
For more information, see the privacy information published by Cloudflare, Loops, Firebase, Apple TestFlight, Google, and PostHog.
International transfers
RouteBeer's main Firestore database is located in London (europe-west2), and PostHog is configured to use its EU service. Some providers operate globally or process particular services outside the UK. For example, Firebase Authentication is operated from the United States, while other Firebase services may use global infrastructure.
Where personal information is transferred outside the UK, we rely on the safeguards made available by the relevant provider, such as UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, or approved contractual safeguards. You can contact us for more information about the safeguards relevant to your data.
How long we keep information
- Test-update signups: we review inactive records after 12 months. If you withdraw, we remove you from active email use within 30 days and may keep only the minimum suppression record needed to avoid contacting you again.
- App marketing choices: your marketing email choice, decision time, and consent wording version are kept with your account as proof of your decision, including where you decline or later opt out. If you opt out, we stop sending marketing emails promptly and keep the updated record. When your account is deleted, your email address is removed from marketing use and we may keep only the minimum suppression record needed to avoid contacting you again.
- Account and profile: kept while your account is active, then deleted or anonymised through the account-deletion process, subject to limited safety or legal exceptions.
- Current live location: used only for an active crawl and removed when live sharing is switched off, you leave, or tracking ends. If immediate deletion fails because a device is offline or interrupted, the record may remain until the next cleanup.
- Raw recap trails: currently kept with completed crawl history for up to 24 months. Non-precise totals such as distance and moving time may remain when the raw trail is deleted or anonymised.
- Completed crawls, check-ins, scores, and shared content: kept for up to 24 months for history, recaps, support, and safety, unless deleted sooner.
- Analytics and diagnostics: Firebase Analytics user and event data is retained for up to 14 months, which is the current project setting. Firebase Crashlytics crash reports are retained for up to 90 days. PostHog analytics events are captured anonymously and not linked to your account; they may be retained indefinitely as aggregate product data.
- Advertising: advertising consent choices are stored on your device and may be recorded by Google's consent platform. Google and advertising partners retain advertising identifiers, interactions, diagnostics, and reporting data under their own retention policies. RouteBeer receives aggregated advertising reports rather than a copy of an individual advertising profile.
- Session replay: the current PostHog project retains recordings for up to 30 days.
- Safety reports: open reports are kept while investigated; resolved reports may be kept for up to 24 months, or longer where a documented legal or safety need applies.
- Beta administration: tester and invite records are kept during beta and for up to 12 months afterwards unless you become an active user.
- Privacy and support requests: a minimal record of the request and response may be kept for up to 24 months after closure.
Backups and provider logs may take additional time to cycle out. During that period they are protected and are not returned to active use except for disaster recovery or security purposes.
Your rights
UK data-protection law may give you rights to:
- ask for a copy of your personal information;
- correct inaccurate or incomplete information;
- ask us to delete or restrict our use of information;
- receive information you provided in a portable format where applicable;
- withdraw consent at any time where we rely on consent; and
- object to processing based on legitimate interests.
You can object to direct marketing at any time. Use the unsubscribe link in an email, switch off Marketing emails in the app's Privacy & data settings, or contact [email protected]. Withdrawing consent does not affect processing already carried out.
These rights are not absolute and may depend on why we process the information. To make a request, email us from the address associated with your test-update signup or account. We may ask for enough information to verify your identity.
Deletion requests
We respond to deletion requests without undue delay and normally within one month after receiving the request or any information reasonably needed to verify it.
To request deletion, email [email protected] from the address associated with your account. Verified requests are handled using our administrative tools and include the RouteBeer account and user-scoped app data we control. Shared crawl history may be anonymised where removing the entire shared record would affect other participants. We may retain narrowly limited information where necessary for an unresolved safety report, legal obligation, dispute, or legal claim, and will explain any applicable exception.
Automated decisions
RouteBeer does not currently make decisions based solely on automated processing that have legal or similarly significant effects on you.
Security
We use access controls, authentication, encrypted provider connections, app attestation, and service security controls intended to protect personal information. No online service can guarantee absolute security, so please contact us promptly if you believe your account or information has been compromised.
Complaints
Please contact us first so we can try to resolve your concern. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint or by calling 0303 123 1113.
Children
RouteBeer is intended only for adults aged 18 or over. We do not knowingly collect information from children or market RouteBeer to under-18s. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate.
Changes
We may update this policy as RouteBeer develops. The version date at the top shows when it was last updated. If a change materially affects how we use personal information, we will provide an appropriate notice in the app, on the website, or by email.