Privacy Policy
Last updated: 22 January 2025
Geofin (“Geofin”, “we”, “our”) is a family location and safety service. This Privacy Policy explains how we collect, use, share, and protect personal information when you or your household uses the Geofin mobile, web, and wearable applications (“Services”).
Information we collect
- Account details. Parent or guardian name, email address, phone number, password hashes, and plan selections created when you register or contact Geofin.
- Circle profile data. Display names, avatars, shared notes, and relationship tags you add for family members, caregivers, or guests.
- Location & motion data. GPS coordinates, heading, speed, place entry and exit events, and voluntary check-ins collected to deliver location awareness and alerts. Unless you enable timeline history, raw location data remains on-device and is deleted as soon as alerts are processed.
- Safety events. SOS triggers, crash detection telemetry, audio snippets, and status updates you elect to send to trusted contacts.
- Device & diagnostics. Hardware model, OS version, crash logs, notification tokens, and app version required to keep the Services secure and reliable.
How we use information
- Provide real-time location awareness, arrival notifications, and safety automations.
- Maintain shared maps, timelines, and messaging for your chosen family circles.
- Respond to support requests, billing questions, or feature feedback.
- Prevent fraud, abuse, or unauthorised access to location information.
- Comply with legal obligations and enforce our Terms of Service.
Legal bases for processing
We process personal information under the following legal bases: consent (for optional features such as place history), contract (to deliver the Services you request), legitimate interest (for security and analytics), and compliance with legal obligations.
Sharing and disclosures
Geofin does not sell personal information. We may share limited data with trusted processors who provide hosting, map tiles, analytics, crash reporting, or customer success tooling. Each partner is bound by confidentiality agreements and can only process data on our behalf. We may disclose information if legally required or necessary to protect the safety of our users.
International transfers
Data is primarily hosted within the European Union. If international transfers occur, we use Standard Contractual Clauses or another lawful mechanism and apply technical safeguards such as encryption in transit and at rest.
Data retention
Account records are stored for the life of your subscription and retained up to 12 months after cancellation for legal and accounting obligations. Optional timeline history is retained for the period you select (from 24 hours to 30 days). SOS events and diagnostics may be retained up to 24 months to improve incident response. You can request deletion at any time.
Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to the processing of your data, and to data portability. Send any request to privacy@geofin.app and we will respond within 30 days. You can also manage sharing controls directly in the app.
Children’s privacy
Geofin is designed for households where a parent or guardian manages the account. We do not allow minors to create standalone accounts. Guardians are responsible for obtaining any required consent before adding children to their circles.
Security
We use TLS encryption, key management, role-based access controls, and continuous monitoring to protect your information. While no system is perfectly secure, we investigate and remediate suspected incidents promptly. Report vulnerabilities to security@geofin.app.
Changes to this policy
We may update this Privacy Policy to reflect product updates or regulatory changes. We will notify account owners of material updates via email or in-app notice. Continued use of Geofin after an update constitutes acceptance of the revised policy.
Contact
Questions, complaints, or data requests can be sent to privacy@geofin.app or to our Data Protection Officer at the same address. If you are in the EU or UK you may also lodge a complaint with your local data protection authority.