Privacy Policy
The short version
- Your live location never leaves your phone. Pace and gate-crossing are worked out on your device. We never receive a live location, and we never receive a raw GPS trace.
- After a trip ends, the app sends us a summary (zone, times, average speed, outcome and similar). It contains no coordinates.
- We hold your email address so you can sign in with a one-time code. Without it you can't have an account.
- We use analytics and crash reports (PostHog and Sentry, both in the EU) to find and fix problems. The app has no switch to turn analytics off yet. You can ask us to remove your data.
- Our staff can see your email next to your trip summaries when helping with support. They cannot see where anyone is right now.
- We don't sell personal information, run advertising, or profile your driving beyond showing you your own pace.
- You can delete your account in the app (see Deleting your account) and ask us for a copy of your information at any time, free of charge.
1. Who we are and what this policy covers
PaceMate is a New Zealand, native-first average-speed pace-awareness app for Android, and the account and sync services behind it. It is operated by Lowburn Ventures Limited ("PaceMate", "we", "us"). PaceMate is currently distributed as an invite-only beta through Google Play's internal testing track, with invites sent to people on our waitlist. This policy applies to the beta and to later releases unless replaced by an updated version.
This policy explains how we handle personal information under the New Zealand Privacy Act 2020 and its Information Privacy Principles (IPPs). It also covers the PaceMate pages at this website.
This policy is a notice, not a consent form. When you sign in, the app asks you to tick a box saying "I agree to the Terms and have read the Privacy Policy". You are agreeing to the Terms, which are a contract. The Privacy Policy tells you what we do with your information. We do not rely on your ticking that box as your consent to collect or use it. We collect and use personal information only for the purposes described here, which are directly related to running PaceMate.
Our Privacy Officer is the Privacy Officer, Lowburn Ventures Limited, who you can reach at [email protected].
2. What we collect, why, and who sees it
We collect personal information directly from you, or from the app on your device. We collect only what we need to run PaceMate, keep your trip history, support you, and find and fix problems. We do not collect it by unlawful, unfair or unreasonably intrusive means. For each item below we say what it is, why we collect it, who can see it, and whether you have to provide it.
Account details
- What: your email address; an internal user ID we generate; a record of your plan or entitlement; and sign-in session tokens.
- Why: to create your account, let you sign in, and decide which features you can use. You sign in with a six-digit one-time code we email you through Cloudflare's email service. The code is valid for 10 minutes. We store it as a one-way hash (not the code itself) next to your email address until it is purged (see section 9). We do not use passwords. Session tokens are stored only as hashes on our server, and on your phone in Android's secure storage.
- Who sees it: us and our staff operators (see section 5), and Cloudflare as our host and email provider.
- Required? Yes. Your email address is needed to create an account. If you decline, the app can't be used.
Record of your acceptance of the Terms
- What: the version of the Terms and Privacy Policy you accepted, when you accepted, and your app version.
- Why: so we can show what you agreed to and when, and so the app can ask you to accept again when the documents change materially.
- Who sees it: us and Cloudflare (our host).
- Required? Yes, to use the app. We keep this record after you delete your account (see Deleting your account), linked only to a de-identified record.
Device and app information
- What: platform, app version and device model (and, with feedback, the Android version).
- Why: support, compatibility, and diagnosing problems.
- Who sees it: us, and the providers in section 5 who receive it through analytics, crash reports or feedback.
- Required? It is sent automatically as part of using the app.
Post-trip summaries
- What: after a trip through a covered zone ends (completed or cancelled), the app sends one summary: the zone and direction, entry and exit times, duration, surveyed distance, weighted speed limit, your estimated average speed and pace margin, the outcome, a confidence rating, your plan snapshot at the time, and the app version and platform. It contains no coordinates and no GPS trace . It is sent only after the trip ends. If it can't be sent straight away (for example, no signal), the app keeps it on your phone and retries.
- Why: to show you your trip history, support you, and (in de-identified form) improve our zone data.
- Who sees it: you; our staff operators (see section 5); Cloudflare as our host.
- Required? Sending is automatic for signed-in users. There is no setting to turn it off.
Product analytics and session replay (PostHog)
- What: a set of usage events: app opened; sign-in verified or failed; screens viewed; the result of location and notification permission requests; trips started (zone, whether started manually or automatically, whether the app was in the foreground), completed (zone, outcome, duration), cancelled, or needing recovery; whether a detected approach to a zone looked like road travel (with the speed reading used for that check, but no position); zone data loaded; sync failures (a category, not the technical error text); the in-app tour; and when you submit feedback. The events are linked to your internal user ID, not your email address, and carry your app version and platform. We also record session replays of the app's non-driving screens (such as onboarding and choosing a zone), with text inputs and images masked. Replay is switched off while a trip is live. No GPS coordinates are sent to PostHog.
- Why: to understand how the beta is used and to find and fix problems.
- Who sees it: us, and PostHog (hosted in the EU).
- Required? There is currently no switch in the app to turn analytics or replay off. If you object, contact us (section 12) and we will work with you on what we can do, which can include deleting your account and your analytics data.
Crash reports (Sentry)
- What: when something goes wrong in the app or on our servers: an error message, a stack trace, coarse device, OS and app-version details, and recent technical log entries. Location-like fields are scrubbed before a report is sent.
- Why: to find and fix faults.
- Who sees it: us, and Sentry (hosted in the EU).
- Required? Sent automatically when a fault occurs. There is no in-app switch. If you object, contact us.
Reporting a problem in the app
- What: if you use "Report a problem", we receive the free text you type; device facts (app version, platform, device model, Android version); the screen you were on and, if relevant, the zone, direction and trip ID; a short tail of recent app log lines; your PostHog session-replay ID; and your internal user ID. We deliberately do not include your email address.
- Why: to diagnose and fix the problem you've reported.
- Who sees it: the report is filed as an issue in the PaceMate project's repository on GitHub, where it can be read by anyone with access to that repository. GitHub is a US-based provider.
- Please don't put sensitive information in the free text. That means no health details, passwords, other people's details, or your own location coordinates. Whatever you type is sent as you wrote it. The app removes coordinate-like numbers from the automatic log lines, but not from your own text.
- Fallback by email: if the report can't be filed (for example, you are offline), the app opens your email app with a prefilled message to us. When you send it, we receive it from your own email address, along with a short support ID that lets us match it to your analytics record.
- Required? No. Reporting a problem is optional.
This website
- What: the PaceMate pages at this website (the home, privacy and terms pages) use PostHog web analytics to count visits and see where visitors come from. Profiles are created only for identified people (we do not identify visitors to these pages). PostHog may use a cookie or similar browser storage for this, and receives your IP address as part of your browser's request.
- Why: to understand how many people visit and where from.
- Who sees it: us, and PostHog (EU).
Waitlist sign-up
You can join the beta waitlist on the home page of this website, before you have an account.
- What: your email address; whether you use an Android phone or an iPhone; your closest zone; how many times a week you drive through zones (1-2, 3-5, 6-10 or 11+); the time you joined; and the version of the Terms and this Privacy Policy you agreed to.
- Why: to invite you to the Android beta test on Google Play, and to decide which zones to invite people from first. To check the email address is yours, we email you a six-digit confirmation code through Cloudflare's email service. We use your email address to contact you only about your invite. If the email address you use for Google Play differs from the one you signed up with, we ask you to reply and tell us which to use.
- Where and who sees it: it is stored in Cloudflare's D1 database (see section 6). Our staff operators can see it in the admin portal (see section 5).
- On your device: after you join, your browser keeps a small note (in local storage, not a cookie) with your answers (phone type, closest zone and how often you drive), so the website can show "You're on the list" instead of the form. It does not contain your email address and is never sent to us. Clear your browser's site data to remove it.
- Required? Only if you want a beta invite. To be removed from the waitlist and have this information deleted, email [email protected].
Network information and support emails
- IP addresses. Your IP address is visible to Cloudflare when your app or browser connects to us, and we use it only transiently to rate-limit requests and prevent abuse. Providers such as PostHog and Sentry also see an IP address as part of ordinary network requests. We do not use IP addresses to work out where you are.
- Support emails. If you email us, we keep the correspondence (which includes your email address and whatever you tell us) to deal with your request.
3. What we do not do
- We never transmit your live location while a trip is in progress. All pace and gate-crossing calculation happens entirely on your device.
- We never upload a raw GPS trace. What reaches our servers is a post-trip summary, not a location trail.
- We never sell your personal information to anyone, for any purpose.
- We do not show advertising or share your information for advertising.
- We do not use your location or trip data to build a profile of your driving for any purpose other than showing you your own pace.
- No tool we operate shows anyone's live or real-time position, including to our own staff.
4. Location and notifications: prominent disclosure
PaceMate collects location data to alert you when you are approaching an average-speed zone, to detect when you enter and exit a zone, and to calculate your average speed across it, even when the app is closed or not in use. This works because PaceMate asks for background location access (on Android, "Allow all the time"), so it can notice a zone approach with the screen off or the app closed.
This location data is processed on your device. It is never streamed or uploaded to us or to anyone else, and it is used only for those on-device purposes: the approach alert, zone entry and exit, the pace calculation and the matching on-device notifications. What we receive is the post-trip summary described in section 2, which contains no coordinates.
PaceMate also asks for Android's notifications permission, used for approach alerts and for the ongoing trip notification that shows your pace while a trip is live. You can change either permission at any time in your phone's settings. If you turn background location off, approach alerts and automatic zone detection will not work.
5. Who can see your information
Our staff
A small number of staff operators use a separate staff portal with its own access controls. Through it they can look up identified trip summaries after a trip is complete: your email address, the trip ID, the zone and the outcome. This is used for support. They can also see aggregate analytics. No endpoint or tool we operate shows anyone's live or real-time position. Staff access is limited to the people who need it.
Service providers who act for us
We use these providers to run PaceMate. They handle information on our behalf and for our purposes, not their own. Under the Privacy Act, information a provider holds for us as our agent is treated as held by us, so we remain responsible for it.
- Cloudflare: hosting, our database, email delivery of sign-in codes, and rate limiting. Cloudflare runs a global network, so data may be stored or processed outside New Zealand.
- PostHog (EU region): product analytics and session replay in the app, and web analytics on this website.
- Sentry (EU region): crash reports from the app and our servers.
- GitHub (US-based): holds the "Report a problem" feedback issues described in section 2.
We distribute the beta through Google Play. Google collects its own information about you and your device when you use Play, under Google's own privacy policy, and not on our behalf. Android's location services on your phone are provided by Google and your device maker. PaceMate uses them on your device (see section 4), and we do not receive that data.
6. Overseas storage and processing
Cloudflare, PostHog, Sentry and GitHub operate outside New Zealand, and some of your information will therefore be stored or processed overseas (PostHog and Sentry in the EU, Cloudflare on its global network, GitHub in the United States). Where we send personal information to an overseas provider, we take reasonable steps to make sure it is protected by safeguards comparable to those in the Privacy Act. We rely on the contractual terms we have agreed with each provider and on their published privacy and security commitments. Where a provider acts as our agent, we remain responsible for the information.
7. How we use and disclose information
We use personal information for the purposes it was collected for (section 2), or for directly related purposes, and we disclose it only to the people in section 5. In addition:
- We do not sell personal information and do not use it for advertising.
- We may disclose information to the New Zealand Police or another public authority where the law requires it, or where the Privacy Act permits it (for example, to prevent or lessen a serious threat to someone's life or health).
- If our business or the PaceMate product is sold or transferred, your information may be transferred to the new owner, who must handle it consistently with this policy.
- We may keep and use de-identified trip data, which no longer relates to an identifiable person, to maintain and improve PaceMate's zone data (see section 10).
8. Security and privacy breaches
We take reasonable steps to protect personal information against loss, misuse and unauthorised access. These include encrypting data in transit using TLS, storing sign-in codes and session tokens only as hashes, keeping your session tokens in Android's secure storage on your phone, and limiting staff access to those who need it.
If we have a privacy breach that is reasonably believed to have caused, or to be likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and affected people as soon as practicable, as required by Part 6 of the Privacy Act 2020.
9. How long we keep information
We keep personal information only as long as we need it for the purposes in this policy or as the law requires.
| Information | How long we keep it | Why |
|---|---|---|
| Email address, user ID, plan record | While your account exists. Removed when you delete your account. | To run your account. |
| Sign-in codes (hashed) | Valid for 10 minutes. Expired codes older than 24 hours are purged when a later code is requested, so a code can stay a little longer if nobody requests one. Removed when you delete your account. | To sign you in securely and limit repeated requests. |
| Session tokens (hashed on our server) | Access tokens last 45 minutes and refresh tokens 30 days, and signing out revokes them. Deleted when you delete your account. | To keep you signed in. |
| Post-trip summaries | While your account exists. On account deletion they are de-identified and may be kept (section 10). | Your trip history, support, and improving zone data. |
| Record of your acceptance of the Terms | Kept after account deletion, linked only to a de-identified record, for as long as we may need it to deal with a dispute about what was agreed. | Evidence of what you agreed to and when. |
| PostHog analytics and replays | Until they expire under our PostHog project's retention settings, or until we remove them after you delete your account or ask us to. | Understanding use and fixing problems. |
| Sentry crash reports | Until they expire under our Sentry project's retention settings, or until we remove them on request. | Finding and fixing faults. |
| Feedback issues on GitHub | Until we remove them, which we do on request or after account deletion. | Fixing what you reported. |
| Support emails | As long as needed to deal with your request and any follow-up. | Supporting you. |
| IP addresses we see for rate limiting | Used transiently. We do not store them in your account. | Preventing abuse. |
| Cloudflare database backups | Backups and point-in-time recovery may hold data, including data you have deleted, for up to 30 days. | Recovering from faults. |
| Data on your phone | Until you clear the app's data or uninstall the app. | The app working offline. |
10. Deleting your account
You can delete your account in either of two ways:
- In the app: go to Settings, then Account, and choose "Delete my account". You don't need to email us or sign in again.
- By email: write to [email protected] from the address on your account. We will verify it is you (section 11).
When you delete your account, this happens in one step:
- Your email address is removed.
- Your sign-in sessions, any sign-in codes and your plan record are deleted, and you are signed out.
- Your trip summaries are re-attached to a new random identifier. It no longer connects to you, or to any ID we hold in our analytics, crash-reporting or feedback tools, and we keep no key to link it back to you. The summaries become de-identified data, which we may keep for analytics and for improving our zone data.
- We keep the record of your acceptance of the Terms, linked only to that de-identified record, as evidence of what was agreed.
Copies in our other tools. Data held in PostHog, Sentry and GitHub feedback issues is linked to your internal user ID, not your email. We will remove it by hand, after you delete your account or when you ask us to, within 20 working days. This is a manual process: we do it ourselves, and it does not happen automatically when you tap the button in the app.
Backups. Cloudflare database backups and point-in-time recovery may hold data for up to 30 days after deletion.
De-identified data. Because de-identified trip summaries no longer relate to an identifiable individual, you can't ask to access or correct them afterwards.
On your phone. Uninstalling the app removes the data held on your device. It does not delete your account, so use one of the options above as well.
11. Your rights: access, correction and accuracy
Under the Privacy Act 2020 you have the right to ask whether we hold personal information about you, to be given access to it, and to ask for it to be corrected. We do not charge for access or correction requests. We will respond within 20 working days of receiving your request.
To make a request, email [email protected]. Because we need to be sure information goes only to the person it is about, we will first verify your identity by emailing a one-time code to the email address registered on your account. If we can't give you access to something, or can't make a correction you ask for, we will tell you why. Where we decline to correct information, you may ask us to attach a statement of the correction you sought.
We take reasonable steps to check that personal information is accurate, up to date and not misleading before we use it. We don't ask for, record or use any identifier assigned to you by another agency, such as a driver licence number. The only identifier we use is our own internal user ID.
12. Questions, objections and complaints
If you have a question, want to object to how we use your information (for example analytics or replay), or have a complaint, email the Privacy Officer, Lowburn Ventures Limited, at [email protected]. We will respond within 20 working days.
If you are not satisfied with our response, you can complain to the Office of the Privacy Commissioner: privacy.org.nz, 0800 803 909.
13. Children
PaceMate is for licensed drivers and is not directed at anyone under 16. We do not knowingly collect personal information from people under 16. If you think a child has given us information, contact us and we will delete it.
14. Changes to this policy
We may update this policy, for example if the analytics or crash reporting we use changes. If we make a material change, we will publish a new version (with a new version number and an updated date at the top of this page) and the app will ask you to accept the updated Terms again before you continue.
15. Contact
Privacy Officer, Lowburn Ventures Limited. [email protected]