Privacy policy
Effective and last updated: 30 August 2026
This policy covers the Vayro Android app, its test services, and ridevayro.com. Vayro is currently available only to invited testers. The policy describes the current test build; it will be updated if the product or its data handling changes.
Controller and contact
Vayro is a privately operated pre-release service based in Sweden. The Vayro operator is the data controller for personal data handled by the app and website. Questions and data protection requests can be sent to privacy@ridevayro.com.
Data handled and why
| Data | When it is handled | Purpose | Legal basis |
|---|---|---|---|
| Account and sign-in data | Email address, username, account identifiers, invite code, sign-in provider, and a password hash if email/password sign-in is used. | Create and secure an account, sign a rider in, and connect account features. | Providing the service requested by the tester. |
| Location and search data | GPS samples used by the app. Search text and coordinates are sent to Vayro when online place search or reverse geocoding is used. | Show position, provide guidance, find places, and label map points. | Providing the requested navigation or search function. |
| Routes and rider content | Uploaded route names, descriptions, waypoints, route geometry, collections, favourites, reviews, and publication choices. | Sync selected routes and provide route and social features. | Providing the service; publication occurs only when the rider requests it. |
| Friends and live position | Friend requests and relationships. Latitude, longitude, heading, and time are transmitted only while live sharing is enabled. | Show a sharing rider's current position to accepted friends. | Providing the sharing function the rider has enabled. |
| Technical request data | IP address, request time, requested path, response status, and basic device or browser information may appear in service and security logs. | Deliver the service, diagnose faults, limit abuse, and maintain security. | Legitimate interests in operating and securing the service. |
What remains on the device
Downloaded map packages, app settings, recent searches, sign-in material, cached friend information, and device-only saved routes can be stored locally. Route calculation uses downloaded map data on the device. Vayro does not receive device-only route files unless a rider chooses a function that uploads them.
Deleting a remote Vayro account does not erase files already held on a device. Local data can be removed by clearing the app's storage or uninstalling it.
Location sharing
Live sharing is off unless the rider enables it. A sharing position is sent only to accepted friends who are connected to the service. The current position is held in server memory, not in the account database, and expires after 60 seconds if it is not refreshed. It is also removed when sharing stops or the connection closes. Vayro does not maintain a live-location history in the test service.
Visibility to other riders
- Usernames and friend relationships are used to connect riders.
- Private routes are limited to their owner.
- Routes a rider marks public can be shown to accepted friends.
- A route submitted and approved for the official listing can be shown to other signed-in riders together with its author's username.
- Reviews are visible wherever the reviewed route is visible.
Service providers and disclosures
Data is disclosed only where needed for the service or where law requires it:
- Cloudflare and hosting infrastructure process website and network requests. The current infrastructure is hosted in Europe.
- Google processes sign-in information if a rider chooses Google Sign-In. Android's Google Play services may provide device location samples under the device's Google and Android settings.
- Accepted friends and other signed-in riders receive only the information described in the visibility sections above.
- Authorities or other parties may receive data when disclosure is required by applicable law or necessary to protect legal rights.
Some providers may process data outside the European Economic Area under their own terms and applicable transfer safeguards.
Website data
The website is static. Vayro does not use advertising or analytics on it and does not set optional cookies. Cloudflare or the hosting service may process network metadata and may use strictly necessary security mechanisms when serving a request.
Retention
- Account records and uploaded content are kept while the test account remains open or until the relevant item is deleted.
- Live positions are removed as described above and are not stored as location history.
- Device-only information remains until the rider removes it from the device.
- Operational and security logs are kept only for troubleshooting, abuse prevention, and infrastructure security, then removed or rotated under the relevant service configuration.
- After an account-deletion request, residual copies may remain in restricted backups until those backups rotate. They are not used for ordinary service operation.
Sale, advertising, and automated decisions
Vayro does not sell personal data. The current app does not contain advertising or a third-party analytics SDK. Vayro does not make decisions with legal or similarly significant effects solely by automated processing.
Rights and account deletion
Depending on applicable law, a rider may request access, correction, deletion, restriction, or a portable copy of personal data, and may object to processing based on legitimate interests. A rider can also withdraw a sharing choice by turning that feature off.
Use the account deletion page or email privacy@ridevayro.com. Vayro may ask for limited information needed to verify that the requester controls the account.
A person in the EU or EEA may lodge a complaint with their local supervisory authority. In Sweden, this is the Swedish Authority for Privacy Protection (IMY).
Children
The test service is not intended for anyone under 18. Vayro does not knowingly accept accounts from children.
Security and changes
Reasonable technical and organisational measures are used to protect service data, but no system can be guaranteed secure. Material changes to this policy will be dated here and, when appropriate, communicated in the app or to testers before taking effect.