Legal

Privacy Policy

Effective date: August 24, 2026  ·  Provider: AALA Technologies LLC

AALA Technologies LLC

This Privacy Policy explains how AALA Technologies LLC, doing business as TriakaMap ("we," "us," or "our"), collects, uses, discloses, and protects personal information through the Service. The Location Data Policy supplements this Policy. If the two conflict regarding location information, the Location Data Policy controls.

1. Scope and Roles

This Policy applies when we determine the purposes and means of processing personal information through the Service. It does not govern third parties acting independently, including app stores, mapping providers, payment processors, operating-system providers, or websites reached through external links.

The Company is the controller, business, or responsible party for the processing described here, as those terms apply under relevant law. Contact details appear in Section 16.

2. Information We Collect

Category

Examples

Source

Account and profile

Name, username, email address, password hash, primary activity, age-eligibility confirmation, profile image, settings

You

Location and route

Precise and approximate coordinates, background location when enabled, shared live position, recorded route, GPX data, POIs, route conditions

Your device and you

User content and communications

Photos, route descriptions, comments, reports, direct and group messages, and other content you submit

You and other users

Subscription and transaction

Plan, trial, renewal status, purchase token, store receipt, transaction identifiers; we do not receive full card data from stores or Stripe

Apple, Google, Stripe, you

Device, network, and use

IP address, device and app identifiers, operating system, app version, product interactions, session and security events

Automatically

Support, safety, and legal

Support requests, moderation reports, evidence, appeals, consent records, legal requests, and correspondence

You, users, authorities

We do not intentionally collect personal information from anyone under 18. We do not use third-party advertising or cross-context behavioral advertising at launch. If analytics, advertising, social login, or new SDKs are introduced, we will reassess disclosures and consent before deployment.

3. How We Use Information

Provide accounts, maps, offline maps, navigation, route recording, live location sharing, community, messaging, and subscription features.

Authenticate users; maintain sessions; prevent fraud, spoofing, scraping, abuse, and unauthorized access; preserve security and audit evidence.

Process purchases, administer trials and entitlements, provide support, and communicate service or policy changes.

Personalize settings and display relevant route, weather, map, and community information.

Moderate content, investigate reports, enforce policies, protect users, respond to emergencies or lawful requests, and establish or defend legal claims.

Debug, maintain, measure, and improve reliability, accessibility, safety, and performance.

Comply with law, app-store requirements, tax and accounting duties, and valid legal process.

4. Legal Bases

Depending on the jurisdiction and activity, we process information to perform our contract with you; comply with law; pursue legitimate interests in providing, securing, improving, and enforcing the Service; protect vital interests in a genuine emergency; or based on consent. We rely on express consent where required for precise or background location, live sharing, optional communications, sensitive-data processing, or an activity that applicable law makes consent-based.

You may withdraw consent through the relevant device permission, feature control, account setting, or by contacting us. Withdrawal does not affect prior lawful processing and may prevent a feature from operating.

5. Location Information

Location processing is feature-specific. Live sharing is optional and off by default. You choose the group or accepted contact and may stop sharing. The most recent live position is designed to be overwritten and deleted when sharing is turned off, subject to short-lived technical copies, security logs, legal preservation, and the final verified retention schedule. Recorded routes persist until you delete them or your account, subject to the same qualifications. Review the Location Data Policy before enabling location features.

6. How We Disclose Information

Recipient

Purpose and data

Cloud, infrastructure, messaging, and development providers

Hosting, storage, authentication support, deployment, push notifications, security, and maintenance; categories depend on configured services

Map and data providers

Map tiles, geocoding, routing, weather, IP-derived region, and geographic features, including Mapbox, MapLibre-related sources, OpenStreetMap/Overpass, CARTO, ArcGIS, Google Maps, Open-Meteo, ipapi, and ip-api as actually configured

Payment providers and app stores

Stripe, Apple, and Google process payment and store records and return entitlement or transaction data

Other users

Username, public profile elements, content, routes or location you affirmatively share, and participation in groups or messages

Professional advisers and authorities

Information reasonably necessary for legal, audit, insurance, security, safety, compliance, or valid process

Transaction counterparties

Information subject to appropriate safeguards in a financing, merger, reorganization, asset transfer, or similar transaction

We do not sell personal information for money. At launch, we do not share personal information for cross-context behavioral advertising or targeted advertising. If that changes, we will provide required notice and opt-out mechanisms before the activity begins. We require processors and service providers by contract to protect information, use it only for documented authorized purposes, assist with rights and incidents, control subprocessors, and delete or return it when services end, subject to lawful retention.

7. International Transfers

8. Retention

Record

Provisional rule

Account/profile

For account life, then 90 days after account deletion

Recorded routes and submitted content

Until user deletion or account deletion, then 30 days, unless retained for a documented exception

Live location

Latest value overwritten and deleted when sharing stops; technical copies and logs for up to 24 hours after sharing ends

Debug telemetry

Up to 7 days, unless isolated for an active security or reliability investigation

Security, IP, anti-spoof, and audit logs

90 days, extended only for investigation, legal hold, or abuse prevention

Subscription, consent, and legal records

financial records for 7 years; consent and legal-hold records for 3 years or as required by applicable law

Deletion may be delayed where necessary to complete a transaction, protect security, comply with law, honor a legal hold, investigate abuse, exercise or defend claims, or preserve content that another user independently owns. We will restrict use during an exception when appropriate.

9. Your Choices and Rights

Access, correct, download, or delete information through available account controls, and use account deletion to request deletion of the account and associated information.

Disable precise or background location through device settings and stop live sharing in the Service.

Manage push notifications through device settings and marketing messages through the included unsubscribe method.

Request access, correction, deletion, portability, restriction, objection, or withdrawal of consent where local law provides the right.

Appeal a qualifying denial and contact the competent privacy regulator.

Opt out of sale, sharing, targeted advertising, or qualifying profiling if those activities are introduced.

Submit requests to [email protected]. We will verify identity in a proportionate manner. An authorized agent may submit a request where permitted, subject to proof of authority and identity verification. We will not discriminate for exercising privacy rights. If we deny an appealable request, our response will explain how to appeal.

10. U.S. State Disclosures

Residents of states with comprehensive privacy laws may have rights that vary by state. Precise geolocation may be treated as sensitive data. We will obtain consent or provide a limit-use mechanism where required before processing sensitive data beyond permitted purposes. We will honor legally recognized universal opt-out signals for applicable sale or targeted-advertising processing if such processing begins. The categories collected, sources, purposes, and recipient categories are described above.

California residents may request the categories and specific pieces of personal information collected, deletion, correction, and information about disclosures, and may exercise applicable rights to opt out or limit sensitive-information use. At launch we state that we do not sell or share personal information as those terms apply to cross-context behavioral advertising, subject to verification of every SDK and contract.

11. Canada

We use personal information for identified purposes with meaningful consent or another lawful basis, limit collection, apply safeguards, provide access and correction, and remain accountable for service providers, including processing outside Canada. Depending on operations and users, federal law and substantially similar provincial laws may apply, including private-sector requirements in Alberta, British Columbia, and Quebec. Quebec launch requires a privacy impact assessment for relevant systems and transfers outside Quebec, appropriate governance, and French-language review.

12. Brazil

For individuals in Brazil, the Company will provide transparent information about processing, identify applicable legal bases, honor data-subject rights, use safeguards for international transfers, maintain security and incident procedures, and identify the appropriate contact or data protection officer before launch. Requests may include confirmation, access, correction, anonymization, blocking, deletion, portability where regulated, information about sharing, withdrawal of consent, and review of qualifying automated decisions.

13. Mexico

14. Security and Incidents

We use administrative, technical, and physical safeguards designed for the nature and sensitivity of the information, including hashed passwords, access controls, encryption in transit, logging, and security monitoring. No system is completely secure. We will investigate suspected incidents, contain and remediate them, document decisions, and notify individuals or authorities when required.

15. Adults-Only Service

The Service is intended only for people 18 or older. We do not knowingly collect personal information from minors. A neutral age gate does not replace our duty to act when we obtain actual knowledge. If you believe a minor has submitted information, contact [email protected]. We may request information reasonably necessary to investigate and delete or restrict the account.

16. Changes and Contact

We may update this Policy. We will post the effective date and provide additional notice or obtain renewed consent when required. Material changes do not retroactively authorize a materially different use without an appropriate legal basis.

Privacy contact and rights requests:

AALA Technologies LLC

Attn: Privacy

30 N Gould St, Suite R, Sheridan, Wyoming 82801, United States

Email: [email protected]

Website: https://triakamap.com

Canada/Quebec privacy officer: AALA Legal Department

Brazil data protection contact: AALA Legal Department

Mexico privacy contact: AALA Legal Department