Privacy Policy
Version 1.8 — In effect since 14 September 2026.
1. Introduction
This privacy policy describes how the ATEQO mobile application (“the App”) collects, uses and protects the personal data of its users (“you”). It is drafted in accordance with Regulation (EU) 2016/679 on the protection of personal data (“GDPR”) and the French Data Protection Act (loi Informatique et Libertés) of 6 January 1978, as amended.
Using the App implies acceptance of the terms of this policy. If you do not agree, you are advised not to use the App.
2. Data controller
The App is published by an independent developer, a working professional delivery driver, acting in a personal capacity.
- Contact for any question relating to data protection: cargo.app.admin@gmail.com
In the absence of a dedicated legal entity, the publisher acts as the data controller within the meaning of Article 4 of the GDPR for the data collected through the App.
3. Data collected and processed
3.1 Data you provide directly
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Account creation, authentication, password reset | Performance of a contract (Article 6(1)(b) GDPR) |
| Password | Authentication (stored in hashed form, never in plain text) | Performance of a contract |
| Username (optional) | Display in your profile | Consent (Article 6(1)(a)) |
| Sign-in via a Google account (optional, alternative to email) | Your name and Google email address are shared with us to create your account and generate an initial username (editable afterwards) | Performance of a contract (Article 6(1)(b) GDPR) |
| Application usage milestones (optional, see section 3.5) | Improving the application and measuring the effectiveness of our advertising campaigns | Consent (Article 6(1)(a)) — refused by default, revocable at any time |
| Delivery addresses you enter | Organising and optimising your route | Performance of a contract |
| Notes attached to a stop (optional) | Reminder for your deliveries | Performance of a contract |
| Starting point (“base”) address | Calculating the route from your depot or home | Performance of a contract |
| Personal profile: start-of-shift time, working days, average number of stops per route | Preparing your morning briefing, scheduling its reminder at the right time, and estimating your time saved across the week | Performance of a contract |
| Rescheduled deliveries: address, note, new date or return-to-depot status | Reminding you on the day and letting you put them back into a route | Performance of a contract |
3.2 Data collected automatically
| Data | When | Purpose |
|---|---|---|
| Precise GPS location | Only during active navigation (explicitly started by you) | Centring the map, calculating the distance to the next stop, detecting arrival (< 80 metres) |
| IP address, device type and OS version | When calls are made to the backend server | Rate limiting (anti-abuse), technical logs |
| Language, country (inferred from your device settings), account creation date and last sign-in date | At sign-in | Remembering your language across your devices; anonymised internal statistics (language / country breakdown) to improve the App |
| Hashed fingerprint of your device identifier, and the number of trial routes used on that device | At sign-in, on Android | Preventing the routes offered at signup from reopening each time a new account is created on the same device (see section 3.6) |
| Technical error reports from the App: error name and message, a short call stack excerpt, the screen or function involved, App version, platform, time. Cleaned on the device before sending: no email address, no delivery address, no coordinates, no token. Linked to your account if you are signed in | When an error occurs in the App | Detecting and fixing malfunctions (legitimate interest) |
3.3 Data processed on an ephemeral basis
| Data | Processing |
|---|---|
| Voice dictation of an address | When you tap the microphone in the add bar, your voice is processed by your device's own speech recognition engine. No recording is kept or sent to our servers: ATEQO only receives the recognised text, which you confirm before it joins your route. The microphone is only active for the length of the dictation. |
3.4 What we do not collect
- Your real first and last name — unless you choose to sign in via Google: your Google name is then shared with us to generate an initial username, which you can change at any time
- Your phone number
- Your date of birth
- Your banking data (handled directly by Google Play during a purchase, never by ATEQO)
- Your contacts, your calendar, your personal photos
- Your health or fitness data
- Any sensitive data (racial origin, political opinions, religion, etc.)
- Your Android advertising identifier: ATEQO never reads it and does not request the corresponding permission
- No profiling, no advertising displayed inside the application, no resale of data
3.5 Audience and advertising performance measurement
Since version 0.9.3, the application may measure the main steps of your usage using Google Analytics for Firebase. This measurement serves two purposes: improving the application, and learning which advertising campaigns bring users who actually use it.
This measurement is optional and based on your consent. It is offered when you create your account, through a checkbox that is unticked by default, and it remains changeable at any time from the “My account” tab. Until you consent, no identifier is transmitted: refusal is the default, including at the very first launch of the application.
What is transmitted is limited to the names of the steps reached and their counters: opening the application, adding a first address, starting and finishing a route, number of stops, display of the subscription screen. To this are added an installation identifier and, if you consented, an account identifier transmitted in hashed form.
No address, no GPS coordinates, no recipient name and no route content is transmitted for this purpose. The addresses you enter never leave your device through this channel.
The ateqo.fr website, which is separate from the application, measures its traffic using Google Analytics. This measurement is enabled only after your explicit consent and can be withdrawn at any time; it is described in the legal notice.
3.6 Preventing abuse of the trial offer
Since version 1.0, on Android, the application reads the identifier that the system assigns to ATEQO on your device (ANDROID_ID). It never transmits its value: it computes a SHA-256 hash of it, and only this fingerprint is sent to our database, together with the number of trial routes already used. The original identifier cannot be recovered from the fingerprint.
This fingerprint has a single purpose: preventing the routes offered at signup from reopening each time a new account is created on the same device. A second account created on that device works normally; it simply continues the trial count where it stood.
It is not used for advertising, audience measurement, or tracking you across applications. It is not passed to any third party other than our database host, and it is separate from the Android advertising identifier, which the application does not read (see section 3.4).
Legal basis: the publisher's legitimate interest in preventing misuse of its free offer (Article 6(1)(f) GDPR). You may exercise your right to object as described in section 7.
4. Recipients of your data
ATEQO relies on the following technical sub-processors. None of these third parties resells your data. Only the measurement described in section 3.5, subject to your consent, serves an advertising purpose — and it is limited to evaluating our own campaigns, without ever sending you advertising.
| Sub-processor | Service provided | Data transmitted |
|---|---|---|
| Supabase Inc. (United States) | Database hosting + authentication | Email, hashed password, username, personal profile (start-of-shift time, working days, average route size), hashed device fingerprint and the number of trial routes used on that device, technical error reports from the App (see section 3.2) |
| Google LLC — Google Sign-In (United States) | Alternative authentication to email | Name and email address of your Google account, only if you choose this sign-in method |
| Google LLC — Google Play Billing (United States) | Processing of premium payments and subscriptions | Payment is handled by your Google Play account — ATEQO receives no banking data |
| RevenueCat, Inc. (United States) | Technical subscription management (purchase validation, premium status) | Account identifier (anonymous) and subscription status — no banking data |
| Google LLC — Maps Platform (United States) | Mapping, geocoding, address suggestions | Addresses entered, search sessions |
| Vercel Inc. (United States) | Hosting of the backend API | IP address, HTTP headers, authentication tokens (validated then not stored) |
| Resend (Plus Five Five, Inc.) (processing in Ireland) | Delivery of authentication emails: signup confirmation and password reset | Your email address and the content of those messages |
| Google LLC — Analytics for Firebase (United States) | Audience measurement and performance of our advertising campaigns — only if you consented (see section 3.5) | Names of the steps reached and their counters, installation identifier, hashed account identifier. No address, no location. |
Your data is never sold, never passed to data brokers, and never used to send you advertising. The only sharing for an advertising purpose is the one described in section 3.5: it measures the effectiveness of our own campaigns, it is optional, and you can withdraw it at any time.
5. Transfers outside the European Union
With the exception of Resend, the sub-processors listed above are based in the United States. Transfers of data to these recipients are governed by:
- the standard contractual clauses adopted by the European Commission (decision 2021/914 of 4 June 2021);
- for providers that adhere to it: the EU-US Data Privacy Framework, deemed adequate by the European Commission in its decision of 10 July 2023.
These mechanisms ensure a level of data protection equivalent to that required by the GDPR.
Our authentication emails are delivered from within the European Union (Ireland region), with no transfer outside the EU for that processing. As Resend is a company established in the United States, the standard contractual clauses nonetheless apply to the contractual relationship.
6. Data retention periods
| Type of data | Retention period |
|---|---|
| User account (email, hashed password, username, language, country, sign-in dates) | For as long as your account exists. Deletion is possible directly within the App (Account tab → Account management → Delete account), on request by email, or after 3 years of total inactivity. |
| Hashed device fingerprint and trial route counter (see section 3.6) | The link between the fingerprint and your account is deleted along with your account. The fingerprint and its counter, which then no longer point to any account, are kept for as long as the trial offer exists, so that it does not reopen on that device. |
| Technical error reports (see section 3.2) | 90 days, then deleted automatically. Deleted along with your account if linked to it. |
| Addresses, stops, route history | Stored locally on your device only. Erased when the App is uninstalled. |
| GPS location | Held in RAM only for the duration of active navigation. Lost at the end of the session. |
| Server logs (IP, headers) | 30 days maximum on Vercel's side, in accordance with their standard hosting policy. |
| Subscription status (via Google Play / RevenueCat) | For as long as the subscription is active + the statutory accounting period (10 years for financial transactions). |
7. Your rights
In accordance with Articles 15 to 22 of the GDPR, you have the following rights over your personal data:
- Right of access (Article 15): obtain a copy of the data concerning you
- Right to rectification (Article 16): correct inaccurate data
- Right to erasure (Article 17, the “right to be forgotten”): request the deletion of your data
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20): receive your data in a structured format
- Right to object (Article 21)
- Right to withdraw your consent at any time, for processing based on consent
Exercising your rights
Send your request by email to cargo.app.admin@gmail.com. We undertake to respond within one month, in accordance with Article 12 of the GDPR.
Complaints
You also have the right to lodge a complaint with the French Data Protection Authority (Commission Nationale de l'Informatique et des Libertés, CNIL): www.cnil.fr.
8. Local storage on your device
ATEQO uses your device's native local storage mechanisms (localStorage on the webview side, @capacitor/preferences on the native Android side) to remember:
- the list of your current stops
- your favourite starting point
- your route history
- your rescheduled deliveries and pending returns to depot
- your personal profile (start-of-shift time, working days, average route size)
- your preferences (language, theme, sound, vibration, morning briefing)
This data remains exclusively on your device. It is never transmitted to a server. Uninstalling the App erases it permanently.
Morning briefing reminders are scheduled locally by your device, from the time you provided. ATEQO never sends you a notification from its servers and therefore stores no notification token.
ATEQO uses no advertising cookies and never sends you advertising. The only identifier shared with a third party is the one used for the measurement described in section 3.5, which is subject to your consent and revocable at any time.
9. Security
The following measures protect your data:
- Encryption in transit: all network communications use HTTPS with TLS 1.2 minimum.
- Passwords: stored only in hashed form (bcrypt) on the Supabase side, never in plain text.
- Row Level Security (RLS): active policies on the Supabase tables to ensure that a user can only access their own data.
- Purchase validation: subscriptions are verified directly with Google Play Billing (store-side validation via RevenueCat).
- No local storage of sensitive tokens: Supabase sessions use time-limited JWTs, automatically renewed.
No system is infallible. In the event of a data breach affecting your information, you will be informed within 72 hours of our becoming aware of it, in accordance with Article 34 of the GDPR.
10. Minors
ATEQO is intended for professional delivery drivers and is not designed for users under the age of 16. No collection of data from minors is intentional. If you are under 16, you are advised not to use the App.
If you are a parent or legal guardian and notice that a minor has provided data through the App, contact us at cargo.app.admin@gmail.com for immediate deletion.
11. Changes to this policy
This policy may evolve to reflect technical, legal or feature changes to the App. Any substantial change will be notified:
- by updating the “In effect since” date at the top of this document;
- for major changes (a new category of data, a new recipient, a change of purpose): by a notification within the App at your next sign-in.
Continued use of the App after notification constitutes acceptance of the new version.
12. Contact
For any question, request relating to your rights, or report of an incident:
Maximum response time: one month.