Route2Bee · Last updated: October 2026 (version 10)
Route2Bee is provided by:
Lukas Schachtmaier & Johann Warkentin GbR
honeyapps
Rosenstraße 19
38550 Isenbüttel
Germany
Phone: +49 174 9783003
Email: info@honeyapps.de
We are the “controller” of your personal data under the EU General Data Protection Regulation (GDPR) and the “business” with respect to your personal information under the California Consumer Privacy Act as amended by the CPRA. Because we are established in the European Union, the GDPR applies to our processing regardless of where you live — so the protections described in Section 13 apply to you as well.
This policy explains what we collect, why, who we share it with, and the rights you have.
We collect this information directly from you and automatically from your device when you use the App. We do not buy personal information from data brokers, and we do not use advertising trackers or third-party analytics SDKs in the App.
Route2Bee uses continuous background GPS to detect and record your drives automatically. This requires access to your location even when the App is not in the foreground.
Why background access is required: automatic trip detection only works if the App can read GPS while your screen is locked or while you use other apps. Without this permission the core function of the App does not work. You may instead use the App to enter trips manually.
What happens to raw GPS data: individual GPS waypoints (coordinates, speed, accuracy, timestamp) are recorded on your device and stay there. They are not deleted automatically, because they form part of the record supporting your mileage log; you can retrieve them at any time through the data export (Section 12).
What is synchronized to the cloud: once your device is online, the summarized trip data (start/end address, distance, duration, times, tag, note) and a simplified route for each trip are synchronized to your account. The simplified route is a smoothed line of at most 1,000 points that usually deviates no more than about 10 meters from the recorded path — without timestamps, speed or accuracy for any point. It lets the map view work on your other devices and after a reinstall, and documents the route you drove. Individual GPS waypoints are not transferred to the cloud. Waypoints transferred until October 2026 have been converted into such simplified routes and then deleted. Older versions of the App still send individual waypoints; our server usually converts them into a simplified route within one hour and then deletes them — in any case they are deleted after 24 hours at the latest. Everything is stored exclusively on servers in the European Union (Frankfurt), and database-level access rules restrict it to your own account. When you delete a trip or your account, its route is permanently and irreversibly deleted (see Section 14).
Low-power monitoring while idle: even when no trip is being recorded, the App checks your location roughly every 10 to 15 seconds to detect the start of a new drive — on iOS at reduced accuracy, on Android at full GPS accuracy because Android otherwise misses trip starts (on Android a persistent notification is shown while this runs). These positions are evaluated on your device only; the App caches just a few anchor positions (such as the last known position). They are not added to your mileage log and not transmitted to our servers. You can turn this off at any time using the auto-tracking switch in the App settings.
Trip-detection diagnostics: so that we can investigate missed or interrupted trips, the App logs state changes of the automatic detection (such as “geofence triggered”, “recording recovered”, “GPS signal stale”), error codes, timestamps and whether battery optimization is active on your device. From App version 1.0.73, it also records — when you complete setup and after that at most once a day — whether location access (in the foreground and in the background) and notifications are allowed, whether precise or only approximate location is granted (iOS), whether automatic detection is switched on in the App, and the operating system and App version. The App uploads these entries to your account. They contain no coordinates. Legal basis: our legitimate interest in reliable trip detection, Art. 6(1)(f) GDPR.
Your control: you can revoke location permission at any time in your device settings. Doing so stops automatic trip detection.
Legal basis (GDPR): your explicit consent, Art. 6(1)(a) GDPR, given by granting the location permission on your device.
Route2Bee is intended only for adults: you must be at least 18 years old to use the App (see our Terms of Service). The App is not directed to children, and we do not knowingly collect personal information from anyone under 18 — including children under 13 within the meaning of COPPA. If you are a parent or guardian and believe a minor has created an account, contact us at info@honeyapps.de and we will delete the account and its data promptly.
We do not sell or share the personal information of any user, and in particular not of consumers under 16 years of age.
To provide the App (GDPR Art. 6(1)(b) — performance of a contract):
With your consent (GDPR Art. 6(1)(a)):
Legitimate interests (GDPR Art. 6(1)(f)):
Legal obligation (GDPR Art. 6(1)(c)): keeping a record of email opt-outs so that they are honored permanently.
We do not use your personal information for third-party advertising, automated decision-making, or cross-context behavioral advertising. We do not build profiles: to select and personalize product emails we only use your subscription status, simple figures from your mileage log, and averages and projections calculated from them (Section 9).
We have not sold or shared personal information in the preceding 12 months, and we do not do so today. “Sale” and “sharing” are used here as defined by the CCPA/CPRA, where “sharing” means disclosure for cross-context behavioral advertising. We do not disclose personal information to third parties for their own direct marketing purposes (California Civil Code § 1798.83, “Shine the Light”).
Sensitive personal information: precise geolocation is treated as sensitive personal information under the CPRA. We collect and use it solely to perform the service you requested — detecting and recording your drives — and for related security and error-diagnosis purposes. We do not use or disclose sensitive personal information for purposes that would give rise to a right to limit its use under Cal. Civ. Code § 1798.121. For that reason, we do not offer a separate “Limit the Use of My Sensitive Personal Information” control.
We disclose personal information to service providers only for the business purposes described in Section 8, under contracts that prohibit them from retaining, using or disclosing it for any other purpose.
So that changes to your mileage log remain traceable, the App keeps additional data. Whether your log meets any tax requirement depends mainly on the information you enter (Terms, Section 10).
Audit log: each creation, edit, correction, deletion or finalization of a trip is logged with a timestamp, the type of action, the affected fields with prior and new values, and your user ID. The audit log is stored on your device and synchronized to the cloud. In addition, our server itself logs every creation and change of a trip it receives (changed fields with prior and new values) and corrections of your vehicles’ initial odometer reading. The log can be included in the PDF export.
Export log: for each export (PDF, CSV, DATEV, self-issued receipt, and in the web app also Excel and the annual archive) we store the time, type of export, period, number of trips, the vehicle ID where applicable, the app version and a SHA-256 checksum of the export data; for exports from the web app, also the checksum of the downloaded file. Purpose: so that you can later trace which export was created when, and check whether an export file has been changed since. The export log is visible only to your account.
Reason and business partner: if you enter a reason or the name of a business partner you visited for a trip, we store and synchronize it like other trip data and include it in your exports. If it contains information about other people, enter only what your log needs.
Finalization: when you mark a trip as reviewed, it is finalized with a timestamp. Finalized trips can still be edited, but the change is recorded as a correction in the audit log; within your account, finalized trips are not permanently deleted individually, only flagged as deleted, so that your log remains traceable. When a trip is deleted — finalized or not — we immediately delete its route from our server and its GPS waypoints from your device; only the trip record flagged as deleted remains.
Retention periods:
We retain nothing after account deletion (apart from the short technical run-off described in Section 14). Any recordkeeping obligation for your mileage log (for example under IRS rules or your state tax authority) rests with you, not with us. Export your data before deleting your account, and export it periodically rather than relying on the App as your sole archive.
We use the following service providers. Each receives only what it needs for the stated purpose.
Supabase (database & authentication)
Supabase Inc., 970 Mission Street, San Francisco, CA 94103, USA
Server location: EU Central (Frankfurt, Germany)
Privacy: https://supabase.com/privacy
Purpose: storing trip data, user authentication. Supabase processes your IP address on every connection; Supabase Auth stores the IP address, user agent and timestamps of each sign-in for as long as the sign-in exists.
Brevo (email delivery)
Sendinblue SAS (“Brevo”), 17 rue Salneuve, 75017 Paris, France
Privacy: https://www.brevo.com/legal/privacypolicy/
Purpose: delivering every email we send you — sign-up confirmation, password reset, service and product emails (Section 9). Brevo receives your email address, display name and the content of the respective email, and produces delivery statistics that we use only to monitor delivery and troubleshoot problems. Brevo records opens and clicks for us only anonymously, without linking them to you. Links in our emails pass through a Brevo redirect address, which technically receives your IP address when you click. Servers located in the European Union.
RevenueCat (in-app purchases)
RevenueCat Inc., San Francisco, USA
Privacy: https://www.revenuecat.com/privacy
Purpose: managing subscriptions and crediting referral rewards. RevenueCat receives a pseudonymous user ID (the identifier of your Route2Bee account) and subscription status (active/inactive, purchase date, expiry); for technical reasons also your device’s IP address, the store’s purchase receipts and the country of your store account. No payment data is transmitted to RevenueCat.
Apple App Store / Google Play Store
All in-app purchase payments are processed exclusively by Apple or Google. We never receive your payment details.
Google Maps SDK (Android)
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: map display in the App and determining the start and end address of a recorded trip through the operating system’s address service (reverse geocoding); for this, your device sends the coordinates of the start and end point to Google. Google’s privacy policy applies.
Apple Maps (iOS)
Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA
Privacy: https://www.apple.com/legal/privacy/
Purpose: map view of an individual trip on iOS devices, rendered through the operating system’s map component, and determining the start and end address of a recorded trip through the operating system’s address service (reverse geocoding); for this, your device sends the coordinates of the start and end point to Apple. Apple’s privacy policy applies.
MapTiler (map tiles in the trip list)
MapTiler AG, Zugerstrasse 22, 6314 Unterägeri, Switzerland (UID CHE-345.466.193)
Privacy: https://www.maptiler.com/privacy-policy/
Purpose: loading the map tiles behind the route previews in your trip list, and map backgrounds and address search in the web app. In the web app our server makes the request, so MapTiler receives only the map section or search text, not your IP address. In the App, requesting a tile transmits your device’s IP address and the coordinates of the requested tile. What is transmitted is the map section, not your route: a tile is coarse and covers several kilometers depending on zoom level. Your trip data, your GPS waypoints and your account are never transmitted to MapTiler. MapTiler states it retains IP addresses for up to two months for security purposes. If the service is not configured or unreachable, the App draws the route without a map background and nothing is sent to MapTiler.
Sentry (error and crash reports)
Functional Software Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA
Privacy: https://sentry.io/privacy/
Purpose: automatic capture of crashes and technical errors. Sentry receives technical error data (error message, device model, operating system, app version, runtime context such as language, time zone, memory and battery level and granted permissions), depending on the app version app-session information (start, end, whether a crash occurred), and a pseudonymous user identifier. Email address and user name are not sent; coordinates and requested web addresses are removed from the error context before transmission. For technical reasons Sentry receives your device’s IP address; Sentry does not store it (IP storage is switched off for our account). Data is ingested and stored in Sentry’s EU region.
OpenStreetMap / Nominatim (address search)
OpenStreetMap Foundation, 132 Maney Hill Road, Sutton Coldfield, B72 1JU, United Kingdom
Privacy: https://wiki.osmfoundation.org/wiki/Privacy_Policy
Purpose: searching and geocoding addresses during manual trip entry (suggestions appear while you type) and when you create or edit a known location (to determine its coordinates). The address text you type or the known location’s address (street, postal code, city — not its name) — and, when you open a manual trip that has no stored coordinates, its stored address (postal code and city) — and, technically unavoidable, your device’s IP address are transmitted; your account, trips and waypoints are not.
OSRM (route calculation for manual trips)
FOSSGIS e. V., Römerweg 5, 79199 Kirchzarten, Germany (operator of the public OSRM server router.project-osrm.org)
Purpose: when you open a manually entered trip that has no recorded waypoints, the App calculates the road route between start and end point for the map view. The coordinates of the start and end point and, technically unavoidable, your device’s IP address are transmitted; your account and other trips are not. The service is not used for automatically recorded trips.
Sign in with Apple
Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA
Privacy: https://www.apple.com/legal/privacy/
Purpose: optional sign-in. Apple sends us a pseudonymous user ID and, if you allow it, your email address (possibly an Apple relay address).
Google Sign-In
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Privacy: https://policies.google.com/privacy
Purpose: optional sign-in. Google sends us a pseudonymous account ID, your email address and, if available, your display name.
Google (internet connectivity check, iOS)
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Privacy: https://policies.google.com/privacy
Purpose: the App for iOS (versions up to and including 1.0.73) regularly checks whether an internet connection is available — for example to show that you are offline, or to handle steps that need a connection (such as signing out) correctly. To do so, it calls a Google check address (clients3.google.com). For technical reasons Google receives your device’s IP address and the identifier of the App and operating system (user agent). Your location, account, trips and other content are not transmitted.
Vercel (website and web app hosting)
Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA
Privacy: https://vercel.com/legal/privacy-policy
Purpose: hosting the public version of this policy and the websites (honeyapps.de/route2bee and route2bee.de) and running the web app at route2bee.de (Section 11). The web app’s server functions run in Frankfurt, Germany; they process your trip data only for the duration of a request and do not store it. Standard server logs (IP address, user agent, timestamp, requested address) are processed on access; we do not write the contents of your trips into these logs.
Microsoft 365 (mailbox info@honeyapps.de)
Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland
Privacy: https://privacy.microsoft.com/
Purpose: receiving, handling and answering emails you send us (Section 9).
We have data processing agreements in place with the providers that process data on our behalf (Supabase, Brevo, RevenueCat, Sentry, Vercel, Microsoft), as required by Art. 28 GDPR, and service provider contracts as required by the CCPA/CPRA. Apple, Google, MapTiler, the OpenStreetMap Foundation and FOSSGIS e. V. (OSRM) process the data arising from the use of their services as independent controllers under their own privacy policies.
Legal bases and transfers (GDPR): Supabase — Art. 6(1)(b); storage in the EU, access by the US parent company under Standard Contractual Clauses (Art. 46(2)(c)). Brevo — Art. 6(1)(b) for service emails, Art. 6(1)(f) for product emails; EU. RevenueCat — Art. 6(1)(b); EU-US Data Privacy Framework (Art. 45) or Standard Contractual Clauses (Art. 46(2)(c)). Sentry — Art. 6(1)(f); EU region, EU-US Data Privacy Framework (Art. 45). MapTiler — Art. 6(1)(f); Switzerland, adequacy decision (Art. 45). OpenStreetMap / Nominatim — Art. 6(1)(b); United Kingdom, adequacy decision (Art. 45). OSRM — Art. 6(1)(b); Germany, no transfer. Sign in with Apple, Apple Maps, Google Sign-In and Google Maps — Art. 6(1)(b); transfers to Apple Inc. and Google LLC (USA) under the EU-US Data Privacy Framework (Art. 45). Google connectivity check (iOS) — Art. 6(1)(f); transfer to Google LLC (USA) under the EU-US Data Privacy Framework (Art. 45). Vercel — Art. 6(1)(b) for the web app, Art. 6(1)(f) for the websites; Standard Contractual Clauses (Art. 46(2)(c)), not the Data Privacy Framework. Microsoft 365 — Art. 6(1)(b) for questions about the App, otherwise Art. 6(1)(f); EU, and where Microsoft Corporation (USA) processes data, the EU-US Data Privacy Framework (Art. 45) or Standard Contractual Clauses (Art. 46(2)(c)).
We may also disclose personal information where required by law, valid legal process, or to protect our rights, safety or property, or those of our users.
Service emails: to perform our contract with you we send emails about your account — sign-up confirmation, password reset, notices when trips could not be saved, and notices about changes to this policy or the Terms (Art. 6(1)(b) GDPR). You cannot opt out of these while your account exists.
Product emails about Route2Bee: if you have purchased a Premium subscription (at least one paid billing period; a free trial alone does not count), we occasionally email you about our own, similar Route2Bee features and offers — for example a Premium offer, a note about the free trip limit, or the referral program. We do not send such emails to users who have not purchased anything. To select and personalize these emails we use your subscription status and simple figures from your mileage log (number of trips, distance driven and its calculated value at your mileage rate, date of your last trip) and, calculated from these, your average distance per day and a projection for the year. No further analysis takes place; the calculated values are used only for the content of the respective email. Legal basis under the GDPR is our legitimate interest in informing our customers about our own product (Art. 6(1)(f)); we point this out when you register or first sign in (including with Apple or Google) and in every such email. You can opt out at any time using the unsubscribe link in every such email or by emailing info@honeyapps.de; we honor opt-outs promptly, and every product email identifies us as the sender and includes a valid postal address, as required by the CAN-SPAM Act. After you opt out you will only receive service emails. We keep your opt-out on file so that it is honored permanently.
We log which email we sent you and when, to avoid sending the same message twice. Delivery runs through Brevo (Section 8). We never give your email address to third parties for their marketing and do not build a profile from your reading behavior.
Support requests: when you email us at info@honeyapps.de, we process your email address, your name if you provide it, and the content of your message in order to answer your request. The legal basis is Art. 6(1)(b) GDPR where your request concerns the App, your account or your subscription, and otherwise our legitimate interest in answering inquiries (Art. 6(1)(f) GDPR). The mailbox is hosted by Microsoft 365 (Microsoft Ireland Operations Ltd.) as our processor (Section 8). We delete the message once the request has been dealt with, unless a statutory retention obligation applies (for example for business correspondence).
In-app reminders: the App can remind you with notifications on your device — for example about month-end export, your odometer reading, or that no trip has been recorded for a few days. These reminders are scheduled locally on your device only, based on the trips stored there; no data is sent to us or to third parties for this. Only whether a reminder is switched on or off is saved with your account, like your other App settings (Section 11). You can turn off each reminder in the App settings or block notifications entirely in your device settings.
Rating prompt: occasionally the App asks you for a rating using the Apple or Google rating dialog. Whether and how you rate is handled solely by the respective store; we receive no data about it other than the publicly visible rating.
Route2Bee offers a referral program (“invite friends”). Participation is voluntary; the conditions are set out in Section 9 of the Terms of Service.
If you share your code: we store your personal invite code and, for each redemption, when it happened, whether and when a reward was earned, and how it was credited. Because the reward depends on it, we check whether the person you invited purchased an annual subscription and whether that purchase was refunded or reversed within 14 days. We also count how many of your invitations led to an annual subscription in the last 365 days (the limit, Section 9.6 of the Terms of Service).
If you redeem a code: we store which code you redeemed, when, and the status of your gift (3 additional months on an annual subscription). The person whose code you enter sees, in their invitation list, your first name (taken from your display name) and the status of the invitation — that is, whether the code has been redeemed, whether you purchased an annual plan, whether their reward has been credited, or that there is no reward (for codes redeemed through older App versions, also whether you cancelled your subscription early). No other data (email address, payment details, trips, locations) is shown. We point this out when you enter a code.
Invite links: the invite page on honeyapps.de displays the code from the link and uses no analytics or advertising tools; the honeyapps.de privacy notice applies to visiting it. If you install the App on Android through the link, Google Play passes the code to the App as part of the install referrer (Section 2). If you open the link with the App already installed, the App stores the code locally on your device. In both cases the code is only pre-filled during setup — it is redeemed only when you tap “Redeem”.
Clipboard: on iPhone you can insert a copied code by tapping “Paste”. The App reads the clipboard only after that tap, accepts nothing but a valid invite or partner code, and does not store or transmit any other clipboard content.
Legal basis: operating the referral program as part of our contract with you (Art. 6(1)(b) GDPR) and our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR). Showing your first name and the invitation status to the referrer is based on the referrer’s and our legitimate interest in making the reward traceable (Art. 6(1)(f) GDPR); you may object under Art. 21 GDPR (info@honeyapps.de). Rewards and gifts are credited through RevenueCat and the interfaces of Apple or Google (Section 8).
Partner codes: if you redeem a partner’s code (for example a creator’s, Section 9a of the Terms of Service), we store the code, when you redeemed it, and whether it was pre-filled from a partner link or entered by you. We use this to show you the partner annual plan and to measure how many users reach Route2Bee through a partner, use the App and purchase a subscription — including to settle accounts with the partner. The partner only receives aggregate numbers, never your name, email address or any other information about you. The partner page on honeyapps.de, the install referrer and pre-filling work as described for invite links. For iPhone installs through a partner link, Apple shows us only aggregate download numbers per link in App Store Connect, nothing about individual people. Legal basis: Art. 6(1)(b) GDPR (providing the offer) and Art. 6(1)(f) GDPR (our legitimate interest in measuring and settling partner collaborations).
If you delete your account, your referral and partner data is deleted. A reward or gift another person has already received remains with them, without any reference to you.
Your trips are stored primarily in a local SQLite database on your device. On iOS this data is additionally protected by the operating system’s Data Protection API. Cloud synchronization — covering your trips, a simplified route for each trip (no individual GPS waypoints, Section 3), your companies, vehicles, known locations, route templates, settings, the audit log and the export log — runs through Supabase, whose servers for this project are operated in the EU Central region (Frankfurt, Germany). All data transfers are TLS-encrypted, and row-level security restricts every record to the account that created it.
Your account is secured by Supabase Auth (email/password, Sign in with Apple or Google Sign-In). We never have access to your password. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Web app (route2bee.de): with Premium you can also use your mileage log in a web browser. Your browser only talks to our server at Vercel (server functions in Frankfurt, Germany, Section 8), never directly to the database. The server reads and writes your data using your own sign-in at Supabase (the same access rules as in the App), creates exports (PDF, receipt, Excel, CSV, DATEV, annual archive) and delivers them to you directly; the files are not stored there.
Web app cookies: we only set strictly necessary cookies. As soon as you start signing in, a cookie holding the email address the code was requested for is created when you sign in with an email code (for at most 15 minutes), or, when you sign in with Apple or Google, a short-lived security cookie holding a verification value (PKCE) that is only needed until you return from Apple or Google (valid for at most 12 hours, deleted when you return). After you sign in, we set your sign-in session and the time of your sign-in and last activity (for automatic sign-out after 60 minutes of inactivity, or after 12 hours at the latest); these sign-in cookies are valid for at most 12 hours. These cookies are only sent over encrypted connections (HTTPS), cannot be read by scripts and are deleted when you sign out. After you sign in, the web app also stores your browser’s time zone (e.g. “America/New_York”) in a cookie so that trips, times and exports appear in your local time. Your browser sends this value with every request to our server; the server only uses it to display or export that request and does not store it. The cookie is only sent over HTTPS and is deleted when you sign out — including automatic sign-out — after one year at the latest; without it, times are shown in German time. So that the page reloads at most once for the time zone, your browser remembers for the duration of the session (sessionStorage) that it has already reloaded for it; without this marker the page could keep reloading. These cookies and the marker are strictly necessary for the service you requested. Neither the web app nor the route2bee.de website uses analytics or advertising cookies or loads content from third parties. For the information pages of route2bee.de (without sign-in, including counting page views without cookies and without personal reference), the route2bee.de privacy notice (German, https://route2bee.de/datenschutz) also applies.
Protection against sign-in abuse: to slow down attempts to guess passwords and sign-in codes, our server counts failed sign-in attempts in the web app per IP address and per email address and temporarily blocks further attempts after several failures. These counters are only kept in the server’s memory and are not stored permanently; a block lasts at most one hour. A counter remains at most until the respective server instance restarts, usually much shorter. Legal basis: Art. 6(1)(f) GDPR (our legitimate interest in keeping accounts secure).
Live sync between the App and the web app: so that open pages of the web app show changes promptly, our server logs, for each change to your data, only which record was created, changed or deleted and when — without any content. We delete these entries after 30 days. Legal basis: Art. 6(1)(b) GDPR.
Maps and address search in the web app: our server requests map tiles and address suggestions from MapTiler on your behalf (Section 8). For address suggestions, your browser sends the search text to our server while you type, and the server forwards it to MapTiler; MapTiler receives only the coordinates of the map section or your search text, not your IP address, account or trips. Under “Account & security” we show the devices your account is signed in on (device type and timestamps from your sign-in data at Supabase, no IP address), and you can end individual sign-ins. When you check an export file (“Verify export”), your browser computes its checksum; only that checksum is sent to us, never the file.
If you are a California resident, you have the following rights:
Categories of personal information collected in the preceding 12 months: identifiers (email address, display name, user ID, invite code, IP address); commercial information (subscription status and history, referral rewards, invite and partner codes redeemed); geolocation data, including precise geolocation; internet or other electronic network activity information (device type, operating system, app version, crash data, trip-detection diagnostics, email log); and other information you voluntarily provide (notes, vehicle details, install source). Sources: directly from you, and automatically from your device. Business purposes: as described in Section 5. Disclosures for a business purpose: to the service providers listed in Section 8. At your direction, if you redeem a friend’s invite code, that person sees your first name and the invitation status (Section 10).
How to exercise your rights: use the in-app controls (More → My Data (GDPR) → “Export data” and More → My Data (GDPR) → “Delete account & data”), the web app (“Account & security” → data access report and account deletion), or email info@honeyapps.de from the address associated with your account. We verify requests by confirming control of that email address; for data-export and deletion requests made in the App, you are already authenticated. An authorized agent may submit a request on your behalf with written permission signed by you, and we may still ask you to verify your identity directly.
We respond to verifiable requests within 45 days, extendable once by a further 45 days where reasonably necessary, and we will inform you of any extension.
If you live in a U.S. state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana), you have rights comparable to those in Section 12 — to confirm processing and access your data, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, sale, and certain profiling (none of which we do). If we decline your request, you may appeal by replying to our decision at info@honeyapps.de; if we deny the appeal you may contact your state Attorney General.
Because we are established in the EU, the GDPR applies to our processing of your data regardless of where you live. Under it you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) — in particular to product emails, see Section 9 — and withdrawal of consent at any time (Art. 7(3)), for example by revoking location permission in your device settings.
To exercise any of these rights, contact info@honeyapps.de. We respond without undue delay and in any event within one month (Art. 12(3) GDPR). You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in the EU member state of your habitual residence, your place of work or the place of the alleged infringement. Ours is: Der Landesbeauftragte für den Datenschutz Niedersachsen (State Commissioner for Data Protection of Lower Saxony), Prinzenstraße 5, 30159 Hannover, Germany — poststelle@lfd.niedersachsen.de.
You can delete your account in the App under More → My Data (GDPR) → “Delete account & data”, in the web app under “Account & security”, or by emailing info@honeyapps.de.
What is deleted: everything — account data, trips (including finalized ones), routes and GPS waypoints, audit log, export log, vehicles, companies, known locations, templates, settings, diagnostics and email logs, install source, referral and partner-code data and Terms-acceptance records. We also request deletion of your customer record at RevenueCat; until RevenueCat confirms the deletion, we keep only your account identifier in order to follow it up. Deletion takes effect immediately and is irreversible; we keep no copy. As a technical run-off, your data disappears from our database provider’s automatic backups (after 8 days at the latest; we never restore individual accounts from these backups) and from the content-free change journal used for live sync (by the following day at the latest, Section 11). Further exceptions are data we do not hold: error reports already sent to Sentry (up to 90 days), Brevo’s delivery log, and purchase records held by Apple or Google.
Export first: a mileage log is typically subject to recordkeeping obligations that rest with you as the taxpayer (for example under IRS rules, generally at least three years, or longer under your state’s rules). Export your trips before deleting your account (PDF, CSV or JSON). After deletion we cannot restore anything.
Subscription: deleting your account does not cancel an active subscription — cancel that in your App Store or Google Play account settings.
We may update this Privacy Policy, for example when we add features or service providers. The current version is always available in the App and at honeyapps.de/route2bee/en/privacy. We will notify you of material changes by email or in-app notification, and will update the “Last updated” date above.
Questions about privacy:
Lukas Schachtmaier & Johann Warkentin GbR
honeyapps
Rosenstraße 19
38550 Isenbüttel
Germany
Phone: +49 174 9783003
Email: info@honeyapps.de