motoguard

MotoGuard Privacy Policy

Version 1.0 · Effective 2026-07-28

This policy is published at mymotoguard.com/privacy. Read it together with our Terms of Service (mymotoguard.com/terms).


1. Who we are

MotoGuard is a motorcycle safety application. It detects a likely crash and, after a cancellable countdown, notifies the emergency contacts you have chosen by SMS and email so someone knows you may need help.

For the purposes of the GDPR, the data controller is:

Important safety note. MotoGuard is a best-effort safety aid, not an emergency service and not a replacement for 911 / 112 or any official emergency number. Notifications depend on your phone, its battery, and cellular coverage and may be delayed or fail to send. See our Terms of Service for the full safety disclaimer.


2. Data we collect

We collect only what the service needs. The categories below mirror our internal data inventory.

2.1 Account and contact data

Your name, email address, phone number, and a securely hashed password (we never store your password in readable form). We also store account settings you control — preferred language, your crash-countdown length, and your police-call opt-in toggle. This data identifies your account and lets you sign in.

2.2 Emergency contacts (third-party personal data)

The name, phone number, and email address of the people you designate as emergency contacts, together with the verification status of each channel. This is personal data about other people. You are responsible for making sure you have a lawful basis to give us their details and for informing them that you have listed them as an emergency contact who may be sent your location and information in a crash. Please add only people who have agreed to be contacted.

2.3 Precise location and crash telemetry

While a ride is armed and during a crash event, MotoGuard collects precise GPS location and motion/crash-sensor readings (for example accelerometer data, trip start/end, idle, speed, and tilt). Location and telemetry are used to detect a crash, to include a map link in emergency messages, and — for Pro plans — to provide ride history and location features you have enabled. Location is not collected when no ride is armed.

2.4 Health data (special-category / sensitive data)

Three optional fields you may choose to enter: blood type, medical conditions, and a free-text emergency note. This is health-related special-category data under GDPR Article 9 and sensitive personal information under the CPRA. It is:

2.5 Purchase records

If you subscribe to MotoGuard Pro, we store the in-app-purchase transaction identifiers (Apple transaction ID or Google Play purchase token) and your subscription plan and status. Purchases are processed by Apple and Google — we never receive or store your card number or payment credentials.

2.6 Diagnostics (opt-out crash reporting)

To keep a safety-critical app stable, we collect minimized crash and error diagnostics through Sentry. This is deliberately hard-minimized:

2.7 Session and security metadata

To keep your account secure we store login-session records: a coarse device/platform class (iOS, Android, or other) derived from your app's user-agent, an approximate country derived from your IP address (we do not store your precise IP long-term), and activity timestamps. We also keep a notification log recording that we sent (or attempted to send) an SMS, email, or push, so delivery can be audited. These records support authentication, abuse prevention, and troubleshooting.

2.8 Ride Share Checkpoints (opt-in, no location stored)

If you opt in to Ride Share Checkpoints for a ride, MotoGuard sends your location — as a Google Maps link — by SMS to the single priority-1 emergency contact you have verified: once when the ride starts, roughly once an hour while you ride, and once when it ends. These coordinates are fire-and-forget: they pass from your phone through our servers to the SMS and are never stored and never logged. The ride-share record we keep contains only session metadata (status, timestamps, and a checkpoint count) — it has no location columns. Ride Share Checkpoints are a social "I'm out riding" nudge; they are explicitly not live tracking and not safety monitoring, and updates stop if your phone loses signal or battery.


3. Purposes and lawful bases

What we do Data used GDPR lawful basis
Provide the core service: account, crash detection, emergency SMS/email notifications, subscriptions, and the features of your plan Account & contact data (2.1), emergency contacts (2.2), location & crash telemetry (2.3), purchase records (2.5), session metadata (2.7) Performance of a contract — Art. 6(1)(b)
Store and use your health data in emergency messages Health data (2.4) Explicit consent — Art. 9(2)(a) (and Art. 6(1)(a)). Withdrawable at any time; withdrawal erases the data
Keep the app stable with minimized crash diagnostics Diagnostics (2.6) Legitimate interest in the stability of a safety-critical app — Art. 6(1)(f) — with an opt-out
Send Ride Share Checkpoints you have turned on for a ride Location (2.3), one chosen contact (2.2) Consent — you initiate each share — Art. 6(1)(a)
Prevent fraud, abuse, and account takeover (rate limits, send caps, session anomaly checks) Session & security metadata (2.7), contact data Legitimate interest in securing the service — Art. 6(1)(f)
Meet legal, tax, and record-keeping obligations, and respond to lawful requests Purchase records (2.5), account data (2.1) Legal obligation — Art. 6(1)(c) — where applicable

Where we rely on legitimate interests, we have balanced them against your rights; you may object (see §7). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.


4. Who processes your data for us (sub-processors)

We do not sell your personal information. We share it only with vendors who process it on our behalf, under contract, to deliver the service:

Processor Purpose
Cloudflare Application hosting, edge compute, database, and content delivery
Twilio Sending emergency and ride-share SMS, and AI voice calls where your plan supports them
Resend Sending transactional and emergency email
Sentry Minimized crash/error diagnostics (EU data residency; see §2.6)
Apple App Store in-app-purchase processing and subscription management
Google Google Play in-app-purchase processing and push-notification delivery (Firebase Cloud Messaging)

Each processor receives only the data needed for its function. We do not use advertising networks or analytics brokers.


5. International transfers

MotoGuard's processors operate globally, so your data may be processed in countries outside your own, including the United States. Where data is transferred out of the European Economic Area or the United Kingdom, we rely on appropriate safeguards — principally the European Commission's Standard Contractual Clauses (and the UK Addendum) or an adequacy decision where one applies. Our crash and error diagnostics are pinned to EU data residency (see §2.6). You may contact us at privacy@mymotoguard.com for information about the safeguards that apply to a specific transfer.


6. How long we keep your data (retention)

Account data, emergency contacts, health data (while consent stands), and purchase records are kept for the life of your account. When you delete your account, all of your data is removed immediately in a full cascade (see §7). Event and log data are pruned automatically on the schedule below, which differs by subscription tier. These periods mirror our production retention configuration exactly.

Data Free Pro
Location events (telemetry, trip start, trip end, idle, geofence enter/exit) 30 days 365 days
Safety events (crash, tamper, harsh braking, speeding, tilt, unexpected movement) 90 days 730 days (2 years)
Notification log (record that an SMS/email/push was sent) 90 days 730 days (2 years)
Login-session records Revoked sessions: 30 days after revocation. Inactive sessions: 120 days after last use (90-day refresh-token lifetime + 30-day grace). Same
Abuse-prevention counters (rate-limit / send-cap counters) Deleted once expired — typically within about a day; legacy rate-limit rows after 7 days. Same

Notes:


7. Your rights

Subject to the conditions in applicable law, you have the right to:

How to exercise your rights:

Withdrawing health-data consent (in Settings) erases your blood type, medical conditions, and emergency note. Turning off diagnostics (in Settings) stops crash-diagnostic collection immediately.


8. California privacy rights (CCPA / CPRA)

This section applies to California residents.

Categories of personal information we collect (California statutory categories), and the corresponding data described in §2:

Statutory category Examples in MotoGuard
Identifiers Name, email, phone number, account ID
Customer records (Cal. Civ. Code § 1798.80) Name, phone number, contact details
Commercial information Subscription plan and in-app-purchase transaction records
Geolocation data Precise location and crash telemetry
Internet or network activity Crash/error diagnostics, session metadata
Sensitive personal information Precise geolocation; health data (blood type, medical conditions, emergency note)

We do not sell or share your personal information. We have not sold personal information, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We do not use or disclose your sensitive personal information for any purpose other than providing the service you requested.

Your California rights: to know/access the personal information we collect and how we use it; to delete it; to correct inaccurate information; to opt out of the sale or sharing of personal information (not applicable — we do neither); to limit the use of sensitive personal information (we already restrict it to service provision); and to not receive discriminatory treatment for exercising any of these rights.

How to exercise: use the in-app Download my data and account deletion options, or contact privacy@mymotoguard.com. We will verify your request against your account before acting. You may use an authorized agent as permitted by law.


9. Children's privacy

MotoGuard is not directed at children. We do not knowingly collect personal data from anyone under 16 (or under the minimum age of digital consent in your jurisdiction, and under 13 for the purposes of the U.S. COPPA). If you believe a child has provided us personal data, contact privacy@mymotoguard.com and we will delete it.


10. Changes to this policy

We may update this policy as the service or the law evolves. When we make a material change, we will notify you in the app or by email and update the "Effective" date above. Continued use of MotoGuard after a change takes effect means you accept the updated policy.


11. Contact us