๐ 1. Introduction
Welcome to PacMate, the all-in-one travel companion app. This Privacy Policy explains how Ram ("we", "us", "our"), the developer of PacMate, collects, uses, stores, and protects your personal data when you use the PacMate Android application.
By creating an account or using PacMate, you confirm you have read and understood this policy. If you do not agree, please uninstall the app and request deletion of your data by emailing support@pacmate.app.
๐ท๏ธ 2. Who We Are
- App name: PacMate
- Developer / Data Controller: Ram
- Contact: support@pacmate.app
- Governing jurisdiction: India
As the Data Controller (under GDPR) and Data Fiduciary (under India's DPDPA 2023), we determine the purposes and means of processing your personal data.
๐ 3. Data We Collect
We collect only the data needed to operate the features you use.
| Category | Data Points | Source | Required? |
|---|---|---|---|
| Account | Full name, email address, encrypted password | Signup form | Yes |
| Profile | Display name, phone number (optional), profile photo, home country, home currency, travel style, travel type, avatar selection | Profile setup | Partial |
| Trip & Budget | Trip destination, start/end dates, total budget, currency, expense title, expense amount, expense category, expense notes, trip total count | Budget & Trip screens | Only if feature used |
| Packing Lists | List name, trip destination, trip duration, packing items and categories | Packing screen | Only if feature used |
| Hidden Gems | Place name, description, category, tags, up to 6 photos (uploaded to Firebase Storage), GPS coordinates, city, country | Add Gem form | Only if feature used |
| Route Planner | Origin city, destination city, trip duration, daily budget, travel interests, pace preference, senior mode toggle, vegetarian-only toggle โ sent to Gemini AI for itinerary generation | Route Planner form | Only if feature used |
| Location | Precise GPS location (latitude/longitude) โ used for detecting nearby hidden gems and reverse-geocoding gem locations | Device GPS | Only for Gems feature |
| Device & Technical | FCM push notification token, last-seen timestamp, online status, app crash reports (anonymised via Firebase Crashlytics), anonymous usage events (Firebase Analytics) | Automatic | Yes (app function) |
| Authentication | Google account ID and profile data (name, email, profile picture) when using Google Sign-In | Google Sign-In | Only if Google login used |
โ๏ธ 4. How We Use Your Data
- Authentication: Verify your identity and maintain your session securely.
- Core app features: Display and sync your trips, budgets, packing lists, and gem contributions.
- AI itinerary generation: Your route planner inputs are sent to the Gemini API (Google) to generate a personalised travel itinerary. Results are cached for 24 hours in Firestore to minimise repeated API calls.
- Nearby gems discovery: Your GPS coordinates are used to find hidden gems within 5 km of your location. Coordinates are stored in Firestore only when you submit a gem.
- Push notifications: We use your FCM token to send in-app alerts (e.g., new gems discovered in a city you visited).
- Weather data: The Open-Meteo API fetches weather for a destination when creating a trip or generating a packing list. No personal data is sent to Open-Meteo.
- Currency conversion: Exchange rates are fetched from ExchangeRate-API and cached locally for 1 hour. No personal data is sent.
- Crash reporting & diagnostics: Firebase Crashlytics collects anonymised crash logs to help us fix bugs. Firebase Analytics tracks anonymous usage events.
- Biometric authentication: If you enable biometric lock, fingerprint/face data is processed entirely on your device by the OS. We never access or store biometric data.
โ๏ธ 5. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA) and United Kingdom, we process your data under the following lawful bases:
| Processing Activity | Lawful Basis |
|---|---|
| Creating and managing your account | Performance of a contract (Art. 6(1)(b)) |
| Storing trips, budgets, packing lists, expenses | Performance of a contract (Art. 6(1)(b)) |
| Sending push notifications | Consent (Art. 6(1)(a)) โ you grant notification permission |
| Accessing GPS for nearby gems | Consent (Art. 6(1)(a)) โ you grant location permission |
| Sending route planner inputs to Gemini AI | Performance of a contract (Art. 6(1)(b)) |
| Firebase Analytics & Crashlytics | Legitimate interests (Art. 6(1)(f)) โ app stability and improvement |
| Uploading profile photos and gem photos | Consent (Art. 6(1)(a)) โ you voluntarily upload |
๐ 6. Third-Party Services
PacMate uses the following third-party services. Each has its own privacy policy.
All Firebase services are operated by Google LLC and governed by the Google Privacy Policy. Firebase data may be stored on servers in the United States and other countries. By using PacMate, you consent to such international transfers.
๐ค 7. Data Sharing
- We do not sell your personal data to any third party, ever.
- We do not rent or trade your data for advertising purposes.
- We share data with Google LLC solely to operate the Firebase, Maps, and Gemini services described above.
- Hidden gem content (place name, description, category, photos, approximate location) you post is visible to other PacMate users on the community map by design. Your personal account details (email, phone) are never shown publicly.
- We may disclose data if required to do so by law, court order, or lawful government authority.
๐ 8. Data Storage & Security
- All data is stored in Google Cloud (Firebase) infrastructure, protected by Google's enterprise-grade security.
- Data in transit is protected by TLS encryption.
- Firebase Security Rules restrict access so users can only read and write their own data.
- Sensitive tokens (session, FCM) are stored using flutter_secure_storage on your device, backed by Android Keystore.
- Biometric data (fingerprint/face) is never transmitted โ processed entirely on-device by the Android OS.
- We apply rate limiting on authentication (5 attempts per 15 minutes) to protect accounts from brute-force attacks.
- Firebase App Check verifies that API requests originate from the genuine PacMate app.
๐ 9. Data Retention
- Account data is retained for as long as your account is active.
- Trip, budget, packing list, and expense data is retained until you delete it within the app or delete your account.
- Hidden gem posts remain on the community map until you delete them or your account is deleted.
- Push notification tokens (FCM) are refreshed automatically and expire when you sign out.
- AI itinerary cache (Gemini results) is stored in Firestore for 24 hours, then purged.
- Currency rate cache is stored locally on your device for 1 hour.
- Crash logs (Firebase Crashlytics) are retained per Google's standard retention policy (90 days).
- When you delete your account, all personal data is removed from Firestore and Firebase Storage within 30 days.
โ 10. Your Rights
Depending on where you live, you have the following rights regarding your personal data:
- Access Request a copy of the personal data we hold about you. (GDPR Art. 15 ยท PIPEDA ยท DPDPA ยง11)
- Rectification Correct inaccurate data. You can update your name, home country, currency, travel style, and profile photo directly in the app under Profile โ Edit. (GDPR Art. 16 ยท DPDPA ยง12)
- Erasure Delete your account and all associated data at any time from within the app or by emailing us. We will process requests within 30 days. (GDPR Art. 17 ยท DPDPA ยง13)
- Portability Request an export of your personal data in a machine-readable format. Email support@pacmate.app. (GDPR Art. 20)
- Objection Object to processing based on legitimate interests (e.g., analytics). Email us to opt out of Firebase Analytics. (GDPR Art. 21)
- Withdraw Consent Revoke location, camera, or notification permissions at any time in your device Settings โ Apps โ PacMate โ Permissions. Revoking location disables the Nearby Gems feature; all other features continue to work.
- Complaint EEA/UK users may lodge a complaint with their local data protection authority (e.g., the ICO in the UK or your national DPA). (GDPR Art. 77)
- Consent (COPPA) US users under 13 must not use PacMate. We do not knowingly collect data from children under 13. (COPPA)
- Transparency (PIPEDA) Canadian users have the right to know what data we hold and how it is used, and to withdraw consent at any time. (PIPEDA Principle 9)
To exercise any of these rights, contact us at support@pacmate.app. We will respond within 30 days.
๐ถ 11. Children's Privacy
PacMate is not directed at children. Under the US Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal data from children under the age of 13. Under India's Digital Personal Data Protection Act, 2023 (DPDPA), we do not process personal data of children under the age of 18 without verifiable parental consent.
If you believe a child has created an account, please contact us at support@pacmate.app and we will delete that account promptly.
๐ 12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, the "Last Updated" date at the top of this page will be revised. For significant changes, we will notify you via an in-app notification. Continued use of PacMate after the effective date constitutes acceptance of the updated policy.
๐ 13. Governing Law
This Privacy Policy is governed by the laws of India. Any disputes arising from this policy shall be subject to the exclusive jurisdiction of the courts of India.
PacMate complies with India's Digital Personal Data Protection Act, 2023 (DPDPA). As a Data Fiduciary under the DPDPA, we process personal data only for the purposes described in this policy, maintain reasonable security safeguards, and honour data principal rights including the right to access, correct, and erase personal data.
๐งโโ๏ธ 14. Grievance Officer
In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (DPDPA), a Grievance Officer has been appointed to address data privacy complaints and concerns.
- Name: Ram
- Designation: Grievance Officer, PacMate
- Email: support@pacmate.app
- Response Time: Within 30 days of receipt of the grievance
๐ง 15. Contact Us
- App: PacMate
- Developer: Ram
- Email: support@pacmate.app
- Jurisdiction: India