Privacy Policy
AALA Technologies LLC
This Privacy Policy explains how AALA Technologies LLC, doing business as TriakaMap ("we," "us," or "our"), collects, uses, discloses, and protects personal information through the Service. The Location Data Policy supplements this Policy. If the two conflict regarding location information, the Location Data Policy controls.
1. Scope and Roles
This Policy applies when we determine the purposes and means of processing personal information through the Service. It does not govern third parties acting independently, including app stores, mapping providers, payment processors, operating-system providers, or websites reached through external links.
The Company is the controller, business, or responsible party for the processing described here, as those terms apply under relevant law. Contact details appear in Section 16.
2. Information We Collect
Category
Examples
Source
Account and profile
Name, username, email address, password hash, primary activity, age-eligibility confirmation, profile image, settings
You
Location and route
Precise and approximate coordinates, background location when enabled, shared live position, recorded route, GPX data, POIs, route conditions
Your device and you
User content and communications
Photos, route descriptions, comments, reports, direct and group messages, and other content you submit
You and other users
Subscription and transaction
Plan, trial, renewal status, purchase token, store receipt, transaction identifiers; we do not receive full card data from stores or Stripe
Apple, Google, Stripe, you
Device, network, and use
IP address, device and app identifiers, operating system, app version, product interactions, session and security events
Automatically
Support, safety, and legal
Support requests, moderation reports, evidence, appeals, consent records, legal requests, and correspondence
You, users, authorities
We do not intentionally collect personal information from anyone under 18. We do not use third-party advertising or cross-context behavioral advertising at launch. If analytics, advertising, social login, or new SDKs are introduced, we will reassess disclosures and consent before deployment.
3. How We Use Information
Provide accounts, maps, offline maps, navigation, route recording, live location sharing, community, messaging, and subscription features.
Authenticate users; maintain sessions; prevent fraud, spoofing, scraping, abuse, and unauthorized access; preserve security and audit evidence.
Process purchases, administer trials and entitlements, provide support, and communicate service or policy changes.
Personalize settings and display relevant route, weather, map, and community information.
Moderate content, investigate reports, enforce policies, protect users, respond to emergencies or lawful requests, and establish or defend legal claims.
Debug, maintain, measure, and improve reliability, accessibility, safety, and performance.
Comply with law, app-store requirements, tax and accounting duties, and valid legal process.
4. Legal Bases
Depending on the jurisdiction and activity, we process information to perform our contract with you; comply with law; pursue legitimate interests in providing, securing, improving, and enforcing the Service; protect vital interests in a genuine emergency; or based on consent. We rely on express consent where required for precise or background location, live sharing, optional communications, sensitive-data processing, or an activity that applicable law makes consent-based.
You may withdraw consent through the relevant device permission, feature control, account setting, or by contacting us. Withdrawal does not affect prior lawful processing and may prevent a feature from operating.
5. Location Information
Location processing is feature-specific. Live sharing is optional and off by default. You choose the group or accepted contact and may stop sharing. The most recent live position is designed to be overwritten and deleted when sharing is turned off, subject to short-lived technical copies, security logs, legal preservation, and the final verified retention schedule. Recorded routes persist until you delete them or your account, subject to the same qualifications. Review the Location Data Policy before enabling location features.
6. How We Disclose Information
Recipient
Purpose and data
Cloud, infrastructure, messaging, and development providers
Hosting, storage, authentication support, deployment, push notifications, security, and maintenance; categories depend on configured services
Map and data providers
Map tiles, geocoding, routing, weather, IP-derived region, and geographic features, including Mapbox, MapLibre-related sources, OpenStreetMap/Overpass, CARTO, ArcGIS, Google Maps, Open-Meteo, ipapi, and ip-api as actually configured
Payment providers and app stores
Stripe, Apple, and Google process payment and store records and return entitlement or transaction data
Other users
Username, public profile elements, content, routes or location you affirmatively share, and participation in groups or messages
Professional advisers and authorities
Information reasonably necessary for legal, audit, insurance, security, safety, compliance, or valid process
Transaction counterparties
Information subject to appropriate safeguards in a financing, merger, reorganization, asset transfer, or similar transaction
We do not sell personal information for money. At launch, we do not share personal information for cross-context behavioral advertising or targeted advertising. If that changes, we will provide required notice and opt-out mechanisms before the activity begins. We require processors and service providers by contract to protect information, use it only for documented authorized purposes, assist with rights and incidents, control subprocessors, and delete or return it when services end, subject to lawful retention.
7. International Transfers
8. Retention
Record
Provisional rule
Account/profile
For account life, then 90 days after account deletion
Recorded routes and submitted content
Until user deletion or account deletion, then 30 days, unless retained for a documented exception
Live location
Latest value overwritten and deleted when sharing stops; technical copies and logs for up to 24 hours after sharing ends
Debug telemetry
Up to 7 days, unless isolated for an active security or reliability investigation
Security, IP, anti-spoof, and audit logs
90 days, extended only for investigation, legal hold, or abuse prevention
Subscription, consent, and legal records
financial records for 7 years; consent and legal-hold records for 3 years or as required by applicable law
Deletion may be delayed where necessary to complete a transaction, protect security, comply with law, honor a legal hold, investigate abuse, exercise or defend claims, or preserve content that another user independently owns. We will restrict use during an exception when appropriate.
9. Your Choices and Rights
Access, correct, download, or delete information through available account controls, and use account deletion to request deletion of the account and associated information.
Disable precise or background location through device settings and stop live sharing in the Service.
Manage push notifications through device settings and marketing messages through the included unsubscribe method.
Request access, correction, deletion, portability, restriction, objection, or withdrawal of consent where local law provides the right.
Appeal a qualifying denial and contact the competent privacy regulator.
Opt out of sale, sharing, targeted advertising, or qualifying profiling if those activities are introduced.
Submit requests to [email protected]. We will verify identity in a proportionate manner. An authorized agent may submit a request where permitted, subject to proof of authority and identity verification. We will not discriminate for exercising privacy rights. If we deny an appealable request, our response will explain how to appeal.
10. U.S. State Disclosures
Residents of states with comprehensive privacy laws may have rights that vary by state. Precise geolocation may be treated as sensitive data. We will obtain consent or provide a limit-use mechanism where required before processing sensitive data beyond permitted purposes. We will honor legally recognized universal opt-out signals for applicable sale or targeted-advertising processing if such processing begins. The categories collected, sources, purposes, and recipient categories are described above.
California residents may request the categories and specific pieces of personal information collected, deletion, correction, and information about disclosures, and may exercise applicable rights to opt out or limit sensitive-information use. At launch we state that we do not sell or share personal information as those terms apply to cross-context behavioral advertising, subject to verification of every SDK and contract.
11. Canada
We use personal information for identified purposes with meaningful consent or another lawful basis, limit collection, apply safeguards, provide access and correction, and remain accountable for service providers, including processing outside Canada. Depending on operations and users, federal law and substantially similar provincial laws may apply, including private-sector requirements in Alberta, British Columbia, and Quebec. Quebec launch requires a privacy impact assessment for relevant systems and transfers outside Quebec, appropriate governance, and French-language review.
12. Brazil
For individuals in Brazil, the Company will provide transparent information about processing, identify applicable legal bases, honor data-subject rights, use safeguards for international transfers, maintain security and incident procedures, and identify the appropriate contact or data protection officer before launch. Requests may include confirmation, access, correction, anonymization, blocking, deletion, portability where regulated, information about sharing, withdrawal of consent, and review of qualifying automated decisions.
13. Mexico
14. Security and Incidents
We use administrative, technical, and physical safeguards designed for the nature and sensitivity of the information, including hashed passwords, access controls, encryption in transit, logging, and security monitoring. No system is completely secure. We will investigate suspected incidents, contain and remediate them, document decisions, and notify individuals or authorities when required.
15. Adults-Only Service
The Service is intended only for people 18 or older. We do not knowingly collect personal information from minors. A neutral age gate does not replace our duty to act when we obtain actual knowledge. If you believe a minor has submitted information, contact [email protected]. We may request information reasonably necessary to investigate and delete or restrict the account.
16. Changes and Contact
We may update this Policy. We will post the effective date and provide additional notice or obtain renewed consent when required. Material changes do not retroactively authorize a materially different use without an appropriate legal basis.
Privacy contact and rights requests:
AALA Technologies LLC
Attn: Privacy
30 N Gould St, Suite R, Sheridan, Wyoming 82801, United States
Email: [email protected]
Website: https://triakamap.com
Canada/Quebec privacy officer: AALA Legal Department
Brazil data protection contact: AALA Legal Department
Mexico privacy contact: AALA Legal Department