Privacy Policy
This Privacy Policy explains how Vroom One (“Vroom One”, “we”, “us”) collects, uses, shares, and protects your personal data when you use the Vroom One web portal and the Vroom One iOS and Android apps (together, the “Service”). It is written to meet our obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who is responsible for your data
Vroom One is the data controller for the personal data we process to operate the Service, to manage your account, and to keep the platform secure.
Driving events are created and run by organisers. When you take part in an event, the organiser decides what participant information to collect through the Service and why — for those purposes the organiser is also a data controller, and you should refer to the organiser’s own privacy information for details of how they use your data. Vroom One acts as the organiser’s processor for the event data they manage through the platform.
2. Information we collect
Account information
When you register, we collect your name (or display name), email address, and a securely hashed password. If you sign in with Google, we receive your name and email address from Google. Participants may also provide a mobile number. Each account is given a unique Vroom One identifier.
Event participation
When you join an event, we process your display name and contact details, any emergency contact you provide, your vehicle details, your group and RSVP status, and records of any event documents you acknowledge or sign (including a captured signature image where a document requires one).
Location and telemetry
While you are actively taking part in an event and with your consent, the app collects your device’s location and related telemetry — latitude and longitude, speed, heading, accuracy, and timestamps — and shares it with your organiser so the drive can be coordinated and participants kept safe. Location sharing is limited to the duration of the event and stops when the drive ends. You can turn it off at any time through your device settings or by leaving the event.
Photos, documents, and other content
You may upload content such as event photos, organisation branding, and documents. We store this content and associated metadata (file name, type, size, caption, and timestamps) to provide the Service.
Notifications
If you enable push notifications, we store a device token (from Apple or Google) so we can deliver notifications to your device, along with the notifications shown in your in-app notification centre.
Technical and usage data
To operate and secure the Service we process technical data including your IP address, device and browser information, session records, and diagnostic and error data. On the web portal we use a small number of strictly necessary cookies for sign-in and security (see “Cookies and sessions” below). We do not use advertising or third-party tracking cookies.
Feedback and support
If you report a bug or send feedback, we collect the message you write, the severity you choose, your IP address, and — if you provide them — your email address and a screenshot, so we can investigate and respond.
3. How and why we use your data
We use your personal data on the following legal bases under the UK GDPR:
- To perform our contract with you — to create and manage your account, let you join and run events, provide navigation and event information, and deliver the features you use.
- With your consent — to collect and share your live location and telemetry during an event, and to send push notifications. You can withdraw consent at any time.
- For our legitimate interests — to keep the Service secure, prevent abuse and fraud, diagnose and fix faults, understand and improve how the Service is used, and respond to your feedback, in a way that is balanced against your rights.
- To comply with our legal obligations — for example to respond to lawful requests and to keep records we are required to keep.
4. Who we share your data with
We do not sell your personal data. We share it only as needed to run the Service:
- Your event organiser, where you take part in their event — including your participation details and, with your consent, your live location during the event.
- Service providers (sub-processors) that help us run the platform, each handling only the data needed for their function:
- Render — cloud hosting and infrastructure for the Service and its database.
- Mapbox — mapping, route, and navigation services; receives route waypoint coordinates to compute directions.
- Google — “Sign in with Google” authentication, and Firebase Cloud Messaging for Android push notifications.
- Apple — the Apple Push Notification service for iOS notifications.
- Email delivery provider — to send account, verification, and event emails to your address.
- Sentry — error and crash monitoring; receives diagnostic data about faults, which may include technical context.
- Linear — our issue tracker, which receives the content of bug reports and feedback you choose to send.
We may also share data where required by law, to protect the rights, safety, or property of users or the public, or as part of a business transfer (for example a merger or acquisition), in which case we will ensure your data remains protected.
5. International transfers
The Service is hosted on infrastructure located in the United States, and some of our providers are based outside the UK. Where we transfer personal data outside the UK, we rely on appropriate safeguards recognised under UK data protection law — such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision — so that your data continues to be protected.
6. How long we keep your data
We keep personal data for as long as your account is active and for as long as needed to provide the Service, to comply with our legal obligations, resolve disputes, and enforce our agreements. Location and telemetry collected during an event is retained to provide event history and analytics to the organiser and is then deleted or anonymised in line with our retention practices. When data is no longer needed, we delete or anonymise it.
Event document signatures
A signature image is kept for three months after the event ends, then deleted. The acknowledgement record, including the legal name, email address, answer, timestamp, authentication method, IP address, browser information and document hash, is retained beyond that period for the establishment, exercise or defence of legal claims. Deleting the image does not delete that record.
If you request erasure before the event has started, we remove the signature image, typed name and sealed signature and identity-proof records. No further certificate can be generated. We cannot recall copies already downloaded by other people. An event has started once it first becomes live, including an event still underway or later cancelled or reopened. If it has started, we remove the image and typed name immediately and remove your legal name and email from live views and ordinary exports. The sealed evidence record retains the signatory identity and answer metadata for legal claims without a fixed expiry. The response to your request explains exactly what was deleted, what was retained and why. Where historic event records are incomplete, we remove the image and typed name and redact live identity while the request awaits an audited history review. We keep sealed metadata until that review determines whether the event had started.
7. Your rights
Under the UK GDPR you have the right to:
- access a copy of the personal data we hold about you;
- ask us to correct inaccurate or incomplete data;
- ask us to erase your data in certain circumstances;
- restrict or object to certain processing, including processing based on our legitimate interests;
- request a copy of certain data in a portable format;
- withdraw consent at any time where we rely on it (for example for location sharing or push notifications), without affecting processing already carried out.
To exercise any of these rights, contact us using the details below. We will respond within the time limits set by law. Where the data relates to an event run by an organiser acting as controller, we may direct your request to that organiser or handle it together with them.
8. Cookies and sessions
The web portal uses a small number of strictly necessary cookies to keep you signed in and protect against cross-site request forgery. These hold your session and security tokens and are essential for the portal to work. We do not use advertising, analytics, or third-party tracking cookies.
9. Security
We take appropriate technical and organisational measures to protect your personal data, including encryption in transit, hashing of passwords and tokens, access controls, and session management with the ability to revoke sessions. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to any incident.
10. Children
The Service is not directed at children, and you must be at least 16 years old to create an account. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, give you additional notice.
12. Contact and complaints
If you have any questions about this Privacy Policy or how we handle your data, or to exercise your rights, contact us at support@vroomtours.app.
If you are in the UK and you are unhappy with how we have handled your personal data, you also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk. We would welcome the chance to address your concerns first.