Privacy policy
Your journeys. Your data.
This policy explains how Schpin handles personal information when you use the app, website, community and support services.
LAST UPDATED · 14 August 2026
Who controls your information
Schpin is the controller of personal information processed for the Service. The operator is identified in the applicable App Store listing and is based in United Kingdom. Privacy enquiries and rights requests can be sent to support@schpin.app.
This policy does not govern information independently processed by Apple, map providers, social platforms or websites you choose to visit.
Information you provide
- account identity, display name, username and profile details;
- route titles, comments, visibility, participants, reactions and reports;
- settings, consent choices and support communications; and
- information included in account access, correction, export or deletion requests.
Please do not include unnecessary sensitive information in titles, comments or support messages.
Drive and precise location data
When you deliberately start a Schpin and grant device permission, the app may process latitude, longitude, timestamps, accuracy, route points, distance, duration, device-reported speed and related motion or journey metrics. The app may continue an active recording in the background as described by the operating system.
We use this information to create your requested route journal, calculate metrics, recover interrupted recordings, synchronise devices and provide sharing features. We do not use Schpin as an emergency-location service, sell precise journey history or record drives merely because the app is installed.
Automatically collected information
We may receive IP address, device and operating-system type, app version, language, time zone, request timestamps, identifiers needed for notifications, session and security events, crash information, diagnostic logs and basic website analytics according to your choices.
We use this information to deliver requests, protect accounts, diagnose failures, prevent fraud and understand aggregate service reliability. We do not seek to create an advertising profile from your journeys.
Why we use information
Depending on the context, our UK GDPR lawful bases are:
- Contract: providing accounts, recording, synchronisation, journal, sharing and support features you request;
- Legitimate interests: securing the Service, preventing abuse, improving reliability, moderating content and establishing or defending legal claims, balanced against your rights;
- Consent: optional device permissions, non-essential analytics or communications where consent is required; and
- Legal obligation: responding to valid legal demands and meeting regulatory, accounting or safety duties.
You can withdraw consent at any time, without affecting processing that was lawful before withdrawal.
Visibility and social features
Private, followers and public visibility settings determine who can see a shared Schpin. A visible activity may include your profile, route shape, time, title, comment, chosen metrics, participants and reactions. Endpoint privacy tools reduce exposure but cannot guarantee that a place will be unidentifiable.
People who can view content may capture, copy or reshare it outside Schpin. Consider passengers, household members and frequently visited places before publishing. Blocking limits future interactions but may not erase information another person already lawfully received.
When information is shared
We may share information with:
- people you select through visibility, follow, participant and sharing controls;
- hosting, database, authentication, notification, mapping, diagnostics, support and security providers acting under contract;
- professional advisers, insurers, auditors, prospective business purchasers and group entities where necessary and protected;
- courts, regulators, police or other authorities when disclosure is legally required or reasonably necessary to protect rights, safety and security; and
- another organisation involved in a merger, acquisition, financing or transfer, subject to appropriate confidentiality.
We do not sell personal information or precise route history.
International transfers
Some suppliers may process information outside the UK. Where UK data-protection law requires safeguards, we use an adequacy regulation, the UK International Data Transfer Agreement or Addendum, or another recognised safeguard, together with supplementary measures where appropriate. Contact us for information about safeguards relevant to your data.
How long information is kept
We keep account and active service data while your account exists. Deleted activities and accounts are removed from active systems within a reasonable operational period, subject to synchronisation, moderation, fraud prevention, backups and legal obligations. Backup copies are overwritten on a rolling schedule.
Security logs are generally kept only as long as needed to investigate threats and maintain the Service. Support records and transaction evidence may be retained for limitation, tax or regulatory periods. We review retention according to purpose, sensitivity, legal requirements and risk rather than keeping precise location indefinitely without reason.
Security
We use proportionate technical and organisational measures designed to protect information, including encrypted transport, access controls, environment separation, protected device storage and restricted administrative access. We review dependencies and service activity for reliability and abuse.
No service can guarantee absolute security. Protect your device and app account, install updates and contact us promptly if you suspect unauthorised access. Do not send passwords or secret credentials by email.
Your rights
Subject to applicable law, you may ask for access, correction, deletion, restriction, portability or an objection to certain processing. Where processing is based on consent, you may withdraw it. You may also ask us to explain a decision that has a significant legal or similar effect if it was made solely by automated means; Schpin does not currently use solely automated decisions of that kind.
Your right to object: you may object at any time to processing based on legitimate interests, including related profiling. We will stop unless we demonstrate compelling legitimate grounds or need the information for legal claims.
Send requests to support@schpin.app. We may need to verify identity and clarify scope. We normally respond within one month, subject to lawful extensions.
Location and device controls
You can deny or revoke location permission in iOS Settings. Without location access, drive recording cannot function, but unrelated account features should remain available where technically possible. You can control notifications through device settings and optional sharing metrics inside Schpin.
Deleting local app data may not delete information already synchronised to your account. Use account deletion or contact us if you want server-held information erased, subject to lawful retention.
Children
Schpin is intended for people aged 16 and older and is not directed to children. We do not knowingly create accounts for children below the applicable digital-consent age without valid authorisation. If you believe a child has provided information improperly, contact us so we can investigate and take appropriate action.
Cookies and website storage
The website may use storage that is strictly necessary for sessions, security and preferences. Optional analytics storage is used only according to the cookie choice shown on the site where consent is required. You can change browser controls, although blocking essential storage may prevent account functions.
Complaints and policy changes
Please contact us first so we can address a concern. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint, or another competent supervisory authority where applicable.
We may update this policy as the Service, suppliers or law changes. We will publish the revised date and provide additional notice where a change materially affects your rights or use of precise location data.