Przejdź do treści
Spotlane
← Home

Privacy Policy

Last updated: 2026-08-27 · Version 1.4.0

Data Controller

The controller of your personal data is Łukasz Jagodziński, with its registered address at: ul. Sumakowa 10, 62-069 Palędzie, gm. Dopiewo, VAT ID (NIP): 7842195025.

For all matters relating to personal data protection, please contact us at: [email protected].

Data Protection Contact

The Controller has not appointed a Data Protection Officer. Please direct all questions and requests regarding personal data processing directly to the Controller at: [email protected].

Data We Collect

When you use the Application we may collect the following categories of data:

a) Account data: email address, username (handle), password (stored only as a cryptographic hash), optional phone number together with its verification status.

b) Profile data: profile picture, cover image, bio, garage (make, model, year, vehicle photos), follower and following relationships.

c) Location data you provide deliberately: GPS coordinates of a spot, place, meeting point, checkpoint or route — stored when you publish such content.

d) Real-time location data: your position during an active drive or meetup, shared with the crew on the live map — see the "Live Map and Location Sharing" section.

e) Approximate last device position: rounded (about 110 m) and kept solely so the server can decide whether a nearby event is worth a notification — see the "Push Notifications" section. It is never shown to anyone.

f) User content: photos and videos uploaded as spots, profile posts, place reviews, comments, meetup chat messages, group messages and direct messages.

g) Photo metadata (EXIF): camera model, capture date and — where present — GPS coordinates. We use it to assess how trustworthy a submission is; see "Photos: Plate Blurring, EXIF and Authenticity Checks".

h) Voice audio: streamed while a meetup voice conversation is running. We do not record it and do not store it on the server.

i) Advertising data: your selected ad mode (personalised / non-personalised / disabled), the record of consent given or withdrawn, and ad impression events.

j) Your device push token (Expo / APNs / FCM) and notification settings.

k) Technical data: IP address, browser or OS type, device identifier, activity logs, error and crash reports, timestamps.

l) OAuth data: identifiers from Google or Apple if you sign in via SSO.

Purpose and Legal Basis for Processing

We process your data for the following purposes:

a) Entering into and performing the service agreement (Art. 6(1)(b) GDPR): creating an account, logging in, managing your profile and garage, publishing spots, places and meetups, chat and direct messages, the live map and voice conversations during a meetup, service notifications in the Application, account export and deletion.

b) Legitimate interests of the Controller (Art. 6(1)(f) GDPR): security of the Application and accounts, abuse rate limiting, content moderation and handling reports, automatic licence-plate blurring, detection of manipulated photos, error diagnostics, aggregate statistics, notifications about nearby events, asserting and defending claims.

c) Compliance with legal obligations (Art. 6(1)(c) GDPR): tax, archiving, and other statutory requirements.

d) Consent (Art. 6(1)(a) GDPR): marketing push notifications, personalised advertising, product analytics, marketing communications — only after explicit consent is given and until it is withdrawn.

Consents are handled separately for each purpose; you can change them in the Application settings, and we keep a history of advertising consent changes as accountability evidence (Art. 7(1) GDPR).

Live Map and Location Sharing

Sharing your live position is always a deliberate act: it starts when you join a drive or an active meetup and stops when you leave. Outside that mode the Application does not track your location.

Who can see your position depends on the meetup's visibility. For a PUBLIC meetup, any signed-in user of the Application can open its live map — including users who have not RSVP'd — and will then see the positions of the drive's participants, yours included. For a private meetup only its participants can see positions, and for a group meetup — the group's members. Your position is never available without signing in and does not reach search engines or your profile; if you prefer not to be visible, turn off map visibility in the privacy settings or do not join the drive of a public meetup.

Live positions are ephemeral: the server relays them to participants and keeps them only for the duration of the session. We do not build a history of your routes from them and do not use them for profiling.

During a drive your operating system may display a notice that the Application is running in the background — that is what allows your position to keep reaching the crew while your phone is face down. You can revoke location access at any time in your system settings; this disables live map features while the rest of the Application keeps working.

Photos: Plate Blurring, EXIF and Authenticity Checks

Photos uploaded to the Application go through automatic licence-plate detection and blurring. The mechanism does its best but gives NO guarantee: it can miss a plate at a steep angle or in a format it does not know. When nothing is detected we publish the photo exactly as you uploaded it — so check the preview before publishing.

When a plate IS detected we publish the blurred version. For spot photos we then keep a private copy of the original — unreachable for other users and used solely for moderation and appeals. For garage vehicle photos the original is replaced by the blurred version and deleted, so no copy of it remains.

The automation is effective but not infallible. If you spot an unblurred plate or any other detail you did not intend to publish, report it to [email protected] or delete the photo — we act without delay.

We also analyse technical properties of the file (EXIF metadata, including GPS coordinates written by the camera, and signals indicating editing) to assess how trustworthy a submission is and to limit fake content. This analysis serves moderation and is not published alongside the photo.

When you publish a photo showing other people or someone else's vehicle, you are responsible for having a legal basis to disseminate their image — see the Terms.

Chat, Direct Messages and Voice Conversations

Messages in meetup chats, groups and direct messages are stored on the server so we can deliver them and show conversation history. We do not use end-to-end encryption — the Controller is technically able to access message content and does so solely for moderation, handling reports and meeting legal obligations.

Meetup voice conversations run on a media server we operate ourselves (LiveKit). Audio is streamed between participants and is neither recorded nor stored. When a direct connection is not possible, traffic may be relayed through a TURN server provided by Cloudflare — it forwards the encrypted stream and has no access to its content.

The Application currently has no way to delete an individual message — the content stays in the conversation until the whole conversation or the account is deleted. If a specific message has to go sooner, write to [email protected].

Copies recipients kept outside the Application (e.g. screenshots) remain beyond our control — nothing we do on our side can undo those.

Sharing Your Calendar by Link

In the web panel you can generate a link to your calendar (spotlane.app/k/…). Anyone who receives it opens the page WITHOUT logging in — the address itself is effectively the password. Send it only to people you want to show your plans to, and bear in mind they can pass it on.

The link is created solely at your request, and what it shows is governed by separate toggles. By default it shows only PUBLIC meetups you are going to — with the name, place and time, i.e. information that is public anyway. The other layers (meetups you are interested in, crew rides, busy days) are off by default.

The "busy days" layer works differently from the others, which is why we describe it separately: it discloses only the DATE of a day on which you have declared attendance at a non-public meetup. It reveals no name, no place, no time and no number of events that day; the recipient learns only that the day is taken. It does not cover events you are merely interested in.

Note two consequences. First — you are sharing information about YOUR availability, but the date of a non-public meetup indirectly concerns its organiser too; if several people from one crew share calendars, a busy day common to all of them may reveal that something is happening that day. Second — days are counted in YOUR timezone, recorded when the link was created, not in the viewer's.

You keep control throughout: at any time you can change the layers, set an expiry date, generate a new address (the old one stops working immediately) or stop sharing altogether. Calendar pages are not indexed by search engines and are not listed in the sitemap. What a recipient has already saved is beyond our reach, though — a link opened earlier may have been copied.

Push Notifications

We send service notifications — about your account, meetups, messages and other users' activity, including nearby events — as part of providing the service: to perform our agreement with you and in our legitimate interest. Their delivery requires the notification permission you grant in your device's operating system; in the Application settings you additionally choose what we notify you about. To deliver them we register your device's push token.

We send marketing communications by push only on the basis of your separate, explicit consent. The marketing communications toggle is off by default and stays off until you turn it on yourself; you can withdraw your consent at any time.

Notifications about nearby events require a distance comparison. We perform it server-side using the approximate last position of your device (rounded to about 110 m, kept as the last point only and taken into account for a few hours after it was recorded). That position is never shown to other users nor included in the notification content.

You can turn notifications off at any time in the Application or system settings. Regardless of those settings we email you when your password changes: the change signs out every device, so if someone else made it you need a chance to react.

Advertising and Advertising Identifiers

The mobile Application displays advertising delivered by Google AdMob. You can choose between three modes: personalised ads, non-personalised ads, and ads disabled (where your plan provides for it).

Personalised ads require your consent and the use of your device's advertising identifier. On Apple devices the system App Tracking Transparency prompt appears as well — declining it means non-personalised ads, and the Application keeps working without restrictions.

We record the history of advertising consent given and withdrawn (date, selected mode, legal basis) — we need it to demonstrate accountability. We also record technical ad impression events (placement, outcome, variant) to account for and optimise monetisation.

You can change the ad mode in the Application settings at any time; the change applies to subsequent impressions immediately. Google's rules are described at https://policies.google.com/technologies/ads.

Sharing of Data

Your data may be shared only with:

a) Processors acting on our behalf — under data processing agreements. These are in particular: the provider of the server infrastructure running the Application and its file storage; Cloudflare (traffic protection and delivery, TURN relay for voice); Google (Google sign-in, maps, AdMob advertising, Firebase analytics); Apple (Apple sign-in, APNs notifications); Expo (push delivery service); Resend (transactional email); Twilio (SMS codes for phone sign-in); MapTiler AG, Switzerland/EEA (map tiles); Sentry — Functional Software, Inc., USA (error monitoring, where enabled).

b) Public authorities: solely on the basis of applicable law.

c) Other Application users: in respect of the content you publish — public profile and garage, spots, places and reviews, posts, open meetups, and during an active drive or meetup also your live position — to the audience determined by the meetup's visibility (for a public meetup: any signed-in user with its live map open), as described in the "Live Map and Position Sharing" section.

We do not sell your personal data and do not share it with data brokers.

Transfers Outside the EEA

Some of our technical infrastructure providers may process data outside the European Economic Area — in particular Sentry (Functional Software, Inc., USA) where error monitoring is enabled, and Google and Apple services. In such cases we ensure appropriate safeguards in accordance with Chapter V GDPR, primarily the standard contractual clauses adopted by the European Commission.

Retention Periods

We process data for the period necessary to fulfil the stated purposes:

a) Account and profile data: for as long as you maintain an active account, and after deletion — for the period required by law (generally no longer than 5 years).

b) Technical and security logs: up to 12 months from the event.

c) Publicly published content: until removed by the user or the Controller.

d) Live map positions: only for the duration of the drive or meetup; no history remains afterwards.

e) Chat, group and direct messages: until the whole conversation or the account is deleted — an individual message cannot currently be deleted by the user.

f) Photo originals from before plate blurring — created ONLY when a plate was detected, and only for spots: for as long as the content is published, solely for moderation and appeals; deleted together with the content. For garage photos the original is deleted right after blurring, and when nothing is detected no separate copy is created at all.

g) Advertising consent records and ad impression events: up to 24 months — as consent accountability evidence and a basis for settlement.

h) Data packages provided on request: up to 7 days after they are made available, then deleted.

Account Export and Deletion

A copy of your data and deletion of your account are handled on request: write to [email protected] and we will respond without undue delay and at the latest within one month of receiving the request (Art. 12(3) GDPR). Where the request is complex we may extend that period by a further two months, telling you so and why.

When we carry out a deletion we erase or anonymise the account data, retaining only what the law or the defence of claims requires. A deletion requested from within the Application is treated as such a request.

Content you posted in conversations with other users may remain visible in their message history without any link to your profile.

Your Rights

Under the GDPR you have the following rights:

a) Right of access (Art. 15 GDPR).

b) Right to rectification (Art. 16 GDPR).

c) Right to erasure (Art. 17 GDPR) — the "right to be forgotten".

d) Right to restriction of processing (Art. 18 GDPR).

e) Right to data portability (Art. 20 GDPR).

f) Right to object (Art. 21 GDPR) — in particular against processing based on legitimate interests.

g) Right to withdraw consent at any time — without affecting the lawfulness of processing carried out before withdrawal.

h) Right to lodge a complaint with a supervisory authority: President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl.

Submit requests to: [email protected].

Data Security

We apply appropriate technical and organisational measures to protect your data against unauthorised access, loss, destruction or disclosure — including transport encryption (TLS), data-at-rest encryption, access controls and regular audits.

Passwords are stored only as cryptographic hashes — we do not know them and cannot read them.

Sessions rely on short-lived tokens. A password change invalidates every session on every device IMMEDIATELY and disconnects connections in progress: voice rooms as well as open chat and live-map connections. Signing out ends that device's session (and signing out everywhere ends the rest), while an access token issued moments earlier expires on its own within some fifteen minutes. An attempt to enter a voice room with a token issued before the session was invalidated is cut off automatically within seconds of joining.

Sensitive operations (sign-in, registration, password reset, SMS codes) are rate limited to reduce account takeover attempts.

Changes to This Policy

We may update this Policy. We will notify you of significant changes at least 14 days in advance by sending a notice to the email address associated with your account or by displaying a notification in the Application.

Contact

If you have any questions about this Policy, please contact us:

Łukasz Jagodziński

ul. Sumakowa 10, 62-069 Palędzie, gm. Dopiewo

Email: [email protected]