Privacy Policy

Last updated: August 26, 2026

1. Who We Are

Bracco (the "App") is a vehicle GPS tracking companion developed by Matteo Crippa ("we", "us", "our"). It shows live position and history of your GPS tracker, geofences, and push alerts. Because the App processes precise geolocation data, this policy details what we collect and why.

2. Data We Collect

  • Account — email and password (hashed with PBKDF2, never stored in plain text).
  • Devices — tracker IMEI, optional name, and SIM phone number for SMS configuration.
  • Location — position, speed, heading, ignition/battery state, trips, and raw tracker frames.
  • Consent record — version and timestamp of your geolocation consent.
  • Push token — device token for push notifications.
  • Purchases — subscription product, transaction ID, status/expiry. Payments are handled by Apple; we never see your card details.
  • Analytics — internal ID and event name only (e.g. "signup"). No email, IP, or location.

3. Legal Basis & Purposes

PurposeLegal basis (GDPR)
Provide the service (auth, trackers, history, trips)Contract — Art. 6(1)(b)
Process subscriptions via AppleContract — Art. 6(1)(b)
Send push alerts you enableContract — Art. 6(1)(b)
Precise geolocation processingExplicit consent — Art. 6(1)(a)
Abuse and fraud preventionLegitimate interest — Art. 6(1)(f)

Geolocation consent is collected at sign-up via an unticked checkbox. You can withdraw at any time from Settings → Geolocation consent — recording stops and all stored location history is permanently deleted. Your account (email, devices) remains active.

4. Sharing & Transfers

We do not sell or trade your data. We share it only with:

  • Cloudflare — backend hosting (EU) and transactional email.
  • Oracle Cloud — network infrastructure (EU) receiving tracker data.
  • Apple — App Store, APNs, and in-app purchases.
  • OpenStreetMap (Nominatim) — reverse geocoding. Coordinates are sent only when needed and cached per device.

Data is stored primarily in the EU/EEA. Transfers outside the EU are protected by Standard Contractual Clauses.

5. Retention

DataFree planPro subscription
Positions7 days6 months
Raw tracker frames7 days30 days
Data-usage summaryCurrent month6 months
Analytics events90 days
Account dataUntil you delete your account

Data is deleted automatically when these limits expire. Deleting your account permanently deletes everything associated with it.

6. Your Rights

Under the GDPR you have the right to:

  • Access your data;
  • Export your data from Settings → Export my data;
  • Rectification of inaccurate data;
  • Erasure — delete your account from Settings → Delete account;
  • Restrict or object to processing;
  • Withdraw consent at any time;
  • Lodge a complaint with the Garante per la protezione dei dati personali (www.garanteprivacy.it).

To exercise any right, contact us via the support form below. We respond within 30 days.

7. Security

Passwords are hashed with PBKDF2, all traffic uses HTTPS, data is stored in the EU, and infrastructure is non-privileged. We follow GDPR breach notification rules (authority within 72 hours, direct notification when risk is high).

8. Children

The App is not intended for children under 16. We do not knowingly collect data from children.

9. Changes

Material changes are announced in the App or by email at least 30 days before they take effect.

10. Contact

Governed by Italian law (GDPR, ePrivacy Directive, D.Lgs. 196/2003).