01Who we are
OD Miles is a mileage tracking application offered by Pink Fox Ventures ("OD Miles," "we," "us"), located at 3905 Cole Valley Ln, Round Rock, TX 78681, United States.
For privacy questions or to exercise your rights, contact support@odmiles.com.
02Scope
This Privacy Policy describes how we collect, use, store, and share information when you use the OD Miles iOS application (the "App") and our website at odmiles.com.
03What data we collect
We collect only the data we need to operate the Service.
Account information
- Name — collected during signup to personalize and identify your account. If you use Sign in with Apple, Apple may provide this name to us.
- Email address — used to send you a one-time magic-link to sign in. We never see or store a password.
- User ID — a Supabase account identifier used to link your profile, trips, named places, vehicles, and subscription entitlement to your account.
Trip data
- Approximate and precise GPS coordinates while you are driving.
- Timestamps for trip start, end, and any mid-trip pauses.
- Distance, duration, and route polyline.
- Start and end address labels resolved through Apple MapKit reverse geocoding.
- Any classifications, purposes, businesses, vehicles, named places, or notes you assign.
Motion data
- CoreMotion automotive activity, used only in-memory to decide whether you are driving. We do not retain raw motion data.
Subscription receipt data
- Apple App Store transaction receipts used to validate your OD Miles Pro entitlement. We never see your payment method.
Diagnostics (local only, optional)
- If you enable the diagnostics setting, the App writes a local log of trip-engine events to your device for troubleshooting. This file never leaves your device unless you choose to export and share it with us.
Device information
- iOS version, app version, device model — only when you send us a support email or diagnostics export.
Data linked to your account
Name, email address, precise location, user ID, and purchase or receipt information are linked to your OD Miles account because they are stored against your account and are not anonymized. We use these data types for app functionality, including account access, trip recording, sync, subscription entitlement, support, and legal compliance.
04What we don't collect
- We do not use third-party analytics SDKs (no Mixpanel, Amplitude, Segment, Firebase Analytics, etc.).
- We do not use advertising SDKs.
- We do not access your contacts, photos, calendar, reminders, microphone, or camera.
- We do not track you across other apps or websites, so App Tracking Transparency does not apply.
- We do not combine your data with third-party data for advertising or ad measurement.
- We do not share your data with data brokers, advertising networks, or third-party ad partners.
- We do not sell your personal information to anyone.
05How we use your data
We use the data above to:
- Provide the core Service — auto-detect drives, classify, and generate reports.
- Authenticate you via magic-link email.
- Sync your records across your devices.
- Validate purchases and manage your subscription entitlement.
- Improve the accuracy and reliability of trip detection (in aggregate, never to build a profile about you).
- Send transactional emails (sign-in links, billing receipts).
- Respond to your support requests.
- Comply with legal obligations.
We do not use your data for advertising, profiling, or any automated decision-making with legal effect.
06Where your data is stored
- On your device: in iOS
UserDefaults, encrypted at rest by the operating system. - In our backend: with Supabase, our backend service provider, hosted on AWS infrastructure in the United States. Data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Subscription receipts: validated by Apple; not stored by us beyond the entitlement flag.
You can export your data as CSV or text at any time from the in-app Reports screen.
07Subprocessors and sharing
We share data only with the following service providers, and only to the extent necessary to provide the Service:
| Subprocessor | Purpose | Data shared | Privacy policy |
|---|---|---|---|
| Apple Inc. | App Store distribution, IAP, MapKit reverse geocoding, push notification delivery | Transaction receipts; address lookups | apple.com/legal/privacy |
| Supabase, Inc. | Hosted Postgres, authentication, real-time sync | All synced trip data, profile, named places, vehicles | supabase.com/privacy |
| Amazon Web Services | Underlying infrastructure for Supabase | Same as Supabase | aws.amazon.com/privacy |
We do not sell or rent your personal information. We do not share your data with advertisers, data brokers, or marketing partners.
We may disclose data when required by law (subpoena, court order, lawful government request), to enforce our Terms, or to protect the safety of users or the public.
08Location data — additional disclosure
Because OD Miles uses always-on background location, we want to be explicit:
- We collect precise location only when you are driving or about to drive, as detected by GPS speed and CoreMotion.
- The App enters a low-power "rest" mode using geofencing when you are stationary.
- Location data is used to record your trip mileage and route. It is not used for advertising, profiling, or any purpose other than running the Service.
- You can revoke location permission at any time in iOS Settings → Privacy & Security → Location Services → OD Miles. The auto-detection feature will stop working; manual trip entry will continue to work.
09Data retention
- Trip records and account data are retained for as long as your account exists.
- The local diagnostics log is automatically trimmed to 1 MB.
- When you request account deletion from in-app Settings → Account & Sync → Delete Account, or by emailing support@odmiles.com from the email address linked to your OD Miles account, your data is removed from our active backend within 30 days after we verify the request. Subprocessor backup retention may extend this by an additional 30 days, after which data is fully purged.
10Children's privacy
OD Miles is not directed to children under 13 and we do not knowingly collect personal information from anyone under 13. Our Terms of Service require users to be at least 18. If you believe a child has provided us personal information, contact support@odmiles.com and we will delete it.
11Your privacy rights
All U.S. users — regardless of state — have the following rights:
- Access — request a copy of the personal information we hold about you.
- Correction — request that inaccurate information be corrected.
- Deletion — request deletion of your account and associated data.
- Portability — receive your data in a portable format (CSV or text via in-app export).
Residents of California (CCPA / CPRA)
In addition to the above, you have:
- The right to know what categories of personal information are collected, the purposes of collection, the categories of third parties we share with, and the categories sold or shared. We have set out this information in Sections 3, 5, and 7.
- The right to delete your personal information, subject to legal exceptions.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of personal information. We do not sell or share personal information, so no opt-out is required. We will not discriminate against you for exercising any CCPA right.
- The right to limit the use of "sensitive personal information." Your precise location is sensitive PI under CCPA. We only use it to provide the Service as described above and never for inferences about you.
Residents of other states with comprehensive privacy laws
Currently including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, New Jersey, Delaware, New Hampshire, Maryland, Minnesota, and others as state laws come into effect. Your rights are substantively similar to the California rights above. Email support@odmiles.com to exercise them.
12How to exercise your rights
- In-app: Settings → Account & Sync → Delete Account (deletion); Reports → Export (portability).
- By email: support@odmiles.com for deletion and other privacy requests.
We will respond within 45 days. We may need to verify your identity before fulfilling the request (typically by emailing the address linked to your account). You may designate an authorized agent to make a request on your behalf with appropriate authorization.
13Security
We use industry-standard security practices:
- TLS 1.2+ for all data in transit between the App and our backend.
- AES-256 encryption at rest in Supabase / AWS.
- iOS keychain for credential and session token storage on-device.
- Magic-link authentication (no passwords to leak).
- Principle of least privilege for internal access; access is logged.
No system is 100% secure, and we cannot guarantee that unauthorized third parties will never gain access. If we become aware of a security incident affecting your data, we will notify you and applicable regulators as required by law.
14International users
OD Miles is intended for use by U.S. residents. If you access the Service from outside the United States, your data will be transferred to and processed in the United States, where privacy laws may differ from those of your country.
15Changes to this policy
We may update this Privacy Policy from time to time. For material changes, we will notify you in-app and by email at least 7 days before the changes take effect. The "Last updated" date at the top reflects the latest revision.
16Contact
OD Miles
Pink Fox Ventures
3905 Cole Valley Ln
Round Rock, TX 78681
support@odmiles.com
A1Appendix: App Store Privacy Nutrition Label
For transparency, we publish the data declarations we provide to Apple's App Privacy Nutrition Label:
| Data type | Collected? | Linked to user? | Used for tracking? | Purpose |
|---|---|---|---|---|
| Email address (Contact info) | Yes | Yes | No | App functionality |
| Precise location | Yes | Yes | No | App functionality |
| Coarse location | No | — | — | — |
| Name | Yes | Yes | No | App functionality |
| Purchases (receipt) | Yes | Yes | No | App functionality |
| User ID (Supabase UUID) | Yes | Yes | No | App functionality |
| Device ID | No | — | — | — |
| Product interaction | No (local diagnostics only unless you choose to export) | — | — | — |
| Advertising data | No | — | — | — |
| Crash / performance data | No | — | — | — |
| Health & fitness | No | — | — | — |
| Financial info | No (Apple handles payment) | — | — | — |
| Contacts / photos / audio | No | — | — | — |
Tracking: No data is used to track you across apps or websites. We do not link your data with third-party data for advertising or advertising measurement, and we do not share your data with data brokers. App Tracking Transparency prompt is therefore not required.