1.1 Why this policy exists#
Bondtrail is a location-sharing platform used by families, including children and teenagers. That means we handle some of the most sensitive personal information there is: where a person is, right now, and where they have been.
This policy is written to be read, not filed. It explains what we collect, why, who sees it, how long we keep it, and what you can do about it. Where a feature sounds stronger than it is, we say so here rather than leaving you to discover it.
1.2 Who we are#
Bondtrail Technologies Inc. ("Bondtrail", "we", "us", "our") is responsible for the personal information described in this policy. Our registered office is at 2-38 Leighside Lane, Saint John, New Brunswick, Canada E2K 2R6.
This policy applies to the Bondtrail mobile application, our website at bondtrail.app, the page used to view a location shared through External Sharing, and our support channels (together, the "Services"). Capitalised terms have the meaning given in our Terms of Service.
1.3 The law we follow#
Bondtrail operates in Canada, and availability in the Apple App Store and Google Play is restricted to Canada. This policy is written to comply with:
- the Personal Information Protection and Electronic Documents Act (PIPEDA), the federal private-sector privacy law;
- An Act respecting the protection of personal information in the private sector, as amended by Quebec Law 25;
- the substantially similar private-sector statutes of Alberta and British Columbia, where they apply; and
- guidance issued by the Office of the Privacy Commissioner of Canada, including guidance on children's privacy, mobile applications and location data.
Where PIPEDA and Quebec Law 25 differ, we apply the higher Quebec standard to every user in Canada. We do not direct the Services to any other country. If we make them available elsewhere, we will publish a supplement for that market first.
1.4 Changes to this policy#
We may update this policy. Where a change is material — a new category of personal information, a new purpose, a new category of recipient, or a longer retention period — we will notify you in the App or by email at least thirty (30) days before it takes effect. Where the change requires your consent we will ask for it separately, rather than treating your continued use as agreement.
Summary at a glance#
The questions people actually ask. Not a substitute for the rest of the policy.
| Question | Short answer |
|---|---|
| Do you sell location data? | No. Not to anyone. Not to advertisers, not to data brokers, not to insurers, not to employers. |
| Do you use location for advertising? | No. There is no advertising in Bondtrail and we build no advertising profiles. |
| Is location sharing on by default? | No. It is off on every new account, at every age, until it is deliberately turned on. |
| Can I turn sharing off? | Yes, at any age, at any time. The change is recorded in the Circle Feed, but no push notification is sent. |
| Who can see my location? | Only members of your Circle, and only when your sharing is on. Not the public, not other Circles. |
| Can someone check my location without me knowing? | Yes. We do not record when one member views another member's location. What we do record is listed in section 11. |
| Does a Privacy Bubble stop you collecting my location? | No. It changes what your Circle sees. We still collect and keep your precise location to build your timeline, including when sharing is off in a Circle. |
| How long do you keep my location? | 30 days, for every member on every plan. A free plan displays 2 days of it. |
| Can I get my data or delete my account? | Yes. See section 18 for what is available in the App and what is available by request. |
| What happens in an emergency? | SOS overrides every privacy setting and shares your precise location with your Circle and your Emergency Contact. Bondtrail does not contact emergency services. |
| Do you make money from my data? | No. We make money when families subscribe. That is the whole model. |
These are commitments, not aspirations. If we need to change one, we will tell you before we do and ask for your consent where the law requires it.
- We do not sell personal information. We do not sell, rent, trade or licence location, movement, driving or behavioural data to anyone, at any price.
- We do not advertise, and we do not profile you for advertising. There is no advertising in the Services, we do not share location with advertising networks, and we do not build advertising profiles. Our analytics is configured so that advertising identifiers are not collected.
- We do not profile minors. Personal information about a member under 18 is used only to deliver the Services within that member's Circle and to support SOS. It is not used for behavioural targeting, marketing, or product experimentation directed at that individual.
- Sharing is off by default, at every age. Nobody appears on a map until they turn sharing on, and anyone can turn it off again. Nobody — including a guardian — can force sharing on or prevent it being switched off.
- We delete on a schedule, automatically. Deletion runs as a system process rather than something someone has to remember. Retention periods are in section 15.
Quebec Law 25 requires us to designate a person responsible for the protection of personal information and to publish their contact details. Ours are:
| Privacy Officer | Festus Asiyanbi |
| Title | Co-Founder and Chief Executive Officer, acting as Privacy Officer |
| legal@bondtrail.app | |
| Postal address | 2-38 Leighside Lane, Saint John, New Brunswick, Canada E2K 2R6 |
You can contact the Privacy Officer about anything in this policy, to exercise any right in section 18, or to make a complaint.
Personal information we collect#
Everything we collect, and a list of the things we deliberately do not.
5.1 Information you give us#
| Information | Why we collect it | Our basis |
|---|---|---|
| Full name | To create your account and identify you to your Circle | Performance of our contract with you |
| Email address | Authentication, account and safety communications | Performance of our contract |
| Phone number | Account verification by SMS | Performance of our contract |
| Age, and age classification by a Guardian | To assign your Age Class and Visibility Tier, and to gate consent | Legal obligation and consent |
| Profile photograph or avatar | So your Circle can recognise you | Consent |
| Emergency Contact mobile number | To send an SMS alert if you activate SOS | Your consent; see section 5.2 |
| Saved Place names and locations | To label places and show a place name instead of a position | Consent |
| Check-in responses, mood and private notes | To deliver the check-in feature | Consent |
| Posts and images in the Circle Feed | To deliver the feed feature | Consent |
| Support correspondence | To answer your question and keep a record | Legitimate interest and contract |
We hold a date of birth, entered on a date picker before any account is created. It is what allows a member to gain the controls available at 14, and again at 18, automatically on their birthday without anyone having to approve it.
5.2 Information you give us about other people#
When you designate an Emergency Contact you give us the mobile number of someone who may not use Bondtrail and who has not dealt with us directly. That person has rights too.
- We ask you to confirm that you have told them and have authority to provide their number.
- We give the Emergency Contact notice, at the latest with the first alert they receive, that we hold their number, why, and a link to have it removed.
- An Emergency Contact may ask us at any time to delete their number. We will, and we will tell you so you can designate someone else.
- We use their number only to deliver SOS alerts and that notice. We do not market to them or add them to a Circle.
- We hold it only while the designation is in force, and delete it within thirty (30) days of removal or account closure.
A member of any age may designate their own Emergency Contact, and it is theirs to choose. This is deliberate: a young person in difficulty should be able to reach the adult they actually trust, who is not always a parent. A Guardian does not approve or override that choice.
5.3 Location information#
Location is the most sensitive category we handle and section 7 is devoted to it. In summary we collect precise location, background location, location history, Place Events, driving information, and the location captured at the moment SOS is activated.
5.4 Information collected automatically#
| Information | Why we collect it | Our basis |
|---|---|---|
| Device identifiers, model, operating system version | To deliver the Services to your device, manage sessions and diagnose faults | Legitimate interest |
| Push notification token | To deliver notifications and SOS alerts | Performance of our contract |
| Battery level and charging status | To provide device-status information to Circle members where the member has turned location sharing on for that Circle | Performance of our contract |
| Device motion and activity signals | To detect driving and distinguish movement from a stationary device | Consent |
| Log data, IP address, timestamps | Security, abuse prevention, fault diagnosis | Legitimate interest |
| Crash reports and diagnostics | To fix faults | Legitimate interest; consent where the operating system requires it. Provided to us by Google Play Console and Apple App Store Connect |
| Basic analytics events | To understand how features are used so we can keep the App working and improve it. These carry an identifier for your app installation and your IP address, which our provider attaches and which cannot be switched off | Legitimate interest |
| Additional analytics events, only if you opt in | To take further reasonable steps to improve the product and inform business decisions. These events do not run unless you affirmatively turn them on in Settings | Consent |
| Subscription and transaction records | To manage your Subscription and meet tax and accounting obligations | Contract and legal obligation |
| Consent records | To evidence what you consented to and when | Legal obligation |
| Activity Log entries | To make the events in section 11 permanent and visible to the person concerned | Performance of our contract |
Bondtrail collects battery level and charging status from your device and sends them to our backend to provide device-status information. They are shared only with members of a Circle where you have turned location sharing on. They are not shared in a Circle where location sharing is off, and turning sharing off in one Circle does not affect a different Circle where sharing remains on.
5.5 What we do not collect#
We do not collect your contacts, call logs, SMS content, photo library, browsing history, microphone audio, health data, or biometric information. We do not use device sensors for any purpose other than the features described in this policy. We do not collect advertising identifiers and we do not track you across other apps or websites.
We treat the following as highly sensitive:
- Precise location and location history
- Location captured at the moment of an SOS activation, and SOS event records
- Any personal information about a member under 18
- Emergency Contact details
- Age and age classification
- Check-in mood responses and private notes
Under Quebec Law 25 the sensitivity of information affects what consent is required and how it must be obtained. We treat location as sensitive in every case, whatever the age of the member.
Location information in detail#
Location is the reason Bondtrail exists, so it gets its own section.
7.1 The kinds of location information we handle#
| Type | What it is |
|---|---|
| Precise location | Your position as reported by your device's GPS or equivalent sensors. Collected when the App has device-level location permission, including when sharing is off in a Circle, so we can build your timeline and support sharing in other Circles. |
| Foreground location | Location collected while the App is open on screen. |
| Background location | Location collected while the App is not open. Necessary so that presence, Place Events and SOS work when you are not looking at your phone. Collected only with your explicit device-level permission, which you can withdraw at any time. |
| Location history | A record of positions over time, used to show your Circle where you have been and to generate driving and place information. |
| Place Events | A record that you arrived at or left a Saved Place, and when. |
| Driving information | Trip start and end, duration, apparent speed and events such as heavy braking, derived from location and motion sensors. |
| SOS location | Your precise location captured at the moment you activate SOS. |
| Last known location | The most recent position we hold, shown when a device is offline. |
| Approximate location | A display state, not a category of data we hold. Inside a Saved Place, other members see the place name once you are within 150 metres of it. While a Privacy Bubble is active, other members see only that you are in a Bubble — no location at all. See section 7.4. |
7.2 Who receives your location#
Location is shared only with members of a Circle in which you have turned sharing on. If sharing is off in a Circle, your live location and presence are not shared with anyone in that Circle, including you. This does not affect sharing in another Circle where you have turned it on. Location is not published or disclosed to advertisers or data brokers.
External Sharing is not available. We plan to let adult members share their live location outside their Circle through a time-limited web link. That feature is not built and no location is shared outside a Circle today. When it ships, it will be available only to members aged 18 and over, and we will update this policy first.
7.3 Background collection and device permissions#
We can only collect location if your device operating system permits it. You control that permission and can withdraw it at any time in your device settings.
If you withdraw location permission, collection stops. Your account continues to work, but presence, Place Events, driving features and location in SOS will not function. We tell you this before you turn it off, not after.
7.4 Displayed precision and collected precision are different things#
7.5 Controlling location#
Depending on your age and settings you may: turn location sharing off for a Circle; activate a Privacy Bubble if you are 14 or over; leave a Circle; and edit or delete a Saved Place only if you created it. You cannot delete location history or your timeline. You may withdraw device location permission in your device settings. Section 18 explains how to exercise your privacy rights.
How we use personal information#
Why we hold each thing. If a purpose is not listed here, we are not doing it.
We use personal information only for the purposes below. If we want to use it for a new purpose we will identify that purpose and obtain fresh consent where the law requires it. Continuing to use the Services is not consent to a new purpose.
- To create and administer your account and your Circles.
- To deliver location sharing consistent with each member's settings and Visibility Tier.
- To generate Place Events, presence status, driving summaries, check-ins, the Circle Feed and weekly summaries.
- To deliver SOS alerts to your Circle and your Emergency Contact.
- To maintain the Activity Log described in section 11.
- To send service communications, including security and safety notices.
- To provide support and investigate reports of misuse.
- To detect, investigate and prevent fraud, abuse, unauthorised access and non-consensual tracking.
- To understand how features are used through basic analytics and, only after you opt in, additional analytics, so we can improve the product.
- To administer Subscriptions, process payments and meet tax and accounting obligations.
- To comply with law and respond to lawful requests.
We do not use personal information to advertise, to profile you for advertising, to score or rank you outside the features described in this policy, or to make any decision about you by automated means that produces a legal or similarly significant effect.
9.1 Consent is specific, not bundled#
Under PIPEDA and Quebec Law 25 consent must be meaningful and specific to purpose. The table below sets out what we ask you to agree to and who gives that agreement.
How we ask, today. During onboarding, you check a box to accept these Terms and acknowledge that you have read this Privacy Policy. An adult becoming a Guardian gives a separate, express consent when they complete verification and receive a Guardian Code. For the remaining purposes we show you an explanation at the point the feature is used, and you agree by continuing.
| What we ask you to consent to | Who consents |
|---|---|
| Collecting and using your precise location for Circle sharing | The member, or the Guardian for a member under 14 |
| Disclosing your precise location to your Circle if you activate SOS | The member, or the Guardian for a member under 14 |
| Disclosing your location to your Emergency Contact if you activate SOS | The member, by designating the contact |
| Storing an Emergency Contact's mobile number | The member designating them; the contact receives notice |
| Receiving other members' location as part of a Circle | Each member, on accepting an invitation |
| Collecting a minor's location | The Guardian, with the minor's participation appropriate to their age |
| Additional analytics | The member. Optional and off by default; these analytics run only after the member affirmatively opts in through Settings |
| Marketing communications | The member. Optional, opt-in, and never sent to anyone under 18 |
9.2 Device permissions are not the same as consent#
Granting a device permission tells your operating system that an app may access a sensor. It does not tell us what you want to share, or with whom. We ask for both: the device permission, and a separate in-app consent that explains the purpose.
9.3 Withdrawing consent#
- You may withdraw consent by contacting the Privacy Officer. Consent cannot be withdrawn in the App.
- Withdrawal takes effect for the purpose concerned, and we stop the relevant processing and delete or de-identify data we no longer have a basis to hold, on the schedule in section 15.
- We will tell you what will stop working before you withdraw, so the choice is informed.
- Withdrawing consent does not affect processing that already lawfully occurred, and does not delete Activity Log or SOS event records, which exist to protect you and others.
- Some consents are necessary for the Services to function. Withdrawing consent to location collection stops location collection after we give effect to your request. It does not close your account.
Timing. We respond to a withdrawal request within seventy-two (72) hours. Giving effect to it can take up to thirty (30) days where that is reasonable in the circumstances, for example where the request touches information held in more than one system. We will tell you when it is done.
9.4 Where we do not rely on consent#
We rely on performance of our contract with you for account administration and delivery of the Services you have requested; on legitimate interest for security, fraud prevention, fault diagnosis and product analytics; and on legal obligation for tax, accounting and consent record-keeping. Where we rely on legitimate interest you may object by contacting the Privacy Officer.
Quebec Law 25 requires that the most privacy-protective settings apply by default, and that functions allowing a person to be identified, located or profiled are deactivated until the person activates them.
- Nobody is visible by default. At any age. Sharing is off on every new account and does not begin until it is deliberately turned on.
- Every member can turn their own sharing off, at any age, at any time. Nobody can override that.
- An Emergency Contact is never pre-filled or assumed. Designating one is a deliberate act.
- Marketing is off unless you opt in, and is never sent to anyone under 18.
- Additional analytics does not run unless you affirmatively opt in.Basic analytics runs from install and carries an installation identifier and IP address, as section 5.4 explains.
- Advertising identifier collection is disabled in our analytics on both platforms.
- For a member under 14, a Guardian must have consented before the member can turn sharing on. The member is told when sharing is on and is shown an indicator while it is.
11.1 Visibility#
| Tier | Who | What the Circle can see |
|---|---|---|
| Tier 1 | Members under 14 | Nothing until the member turns sharing on, which requires prior Guardian consent. Once on: precise position, shown as a place name inside a Saved Place. No Privacy Bubble. The member can turn sharing off at any time. |
| Tier 2 | Members aged 14–17 | Nothing until the member turns sharing on. Once on: precise position, shown as a place name inside a Saved Place or a general area during a Privacy Bubble. The member can turn sharing off at any time. |
| Tier 3 | Members aged 18 and over | Nothing unless the member chooses to share. Same display options as Tier 2, plus External Sharing. |
11.2 The Activity Log#
Certain events are written to a permanent record. Every member of a Circle can read that Circle's Activity Log, at any age. No member can edit or delete an entry, including a Circle Administrator, and neither can we other than through deletion of the account.
Recorded: SOS activations; Privacy Bubble activations, automatic endings, and manual endings including the name of the member who ended it; a member joining or leaving a Circle; Circle creation; and changes to a member's role.
Not recorded: one member viewing another member's location, and anything else not listed above. A member turning their own sharing on or off is recorded in the Circle Feed, but is never shared through a push notification.
Emergency SOS and what it discloses#
SOS overrides every privacy setting you have. Read this before you need it.
12.1 What is disclosed, and to whom#
When a member activates SOS we disclose, to the members of that member's Circle and to the designated Emergency Contact, the member's name, their precise location at the moment of activation, the time of activation, and that they are asking for help. We do not include location history, check-in content or driving data.
How it reaches people differs. Members of the Circle receive a push notification that does not itself contain the location; they open the App to see it. An Emergency Contact who is not a Bondtrail user receives an SMS which does contain the name and location, because there is no App for them to open. That means our SMS provider handles a precise location — section 13.1 records this.
Activating SOS takes a deliberate action. You slide a button, and a seven-second countdown runs during which you can cancel. Nothing is sent until the countdown finishes. Once it has been sent, you can mark the event resolved.
12.2 The SOS record#
Every SOS activation is recorded, including the time, the location, and who was notified. This exists as a safety and audit trail, and is kept for thirty (30) days from the event — the same period as the rest of the location information we hold. No shorter period applies to members under 18.
12.3 Where the member is a minor#
The composition of a minor's Circle is controlled by their Guardian. SOS records for a minor are accessible only to the Guardian who administers that account.
One exception, stated plainly: a minor may designate their own Emergency Contact, so an SOS alert can reach a person outside the Circle whom the Guardian has not approved. Section 5.2 explains why we made that choice.
12.4 Third parties involved in delivery#
To deliver an SOS alert to an Emergency Contact who is not a Bondtrail user, we pass their mobile number and the alert content — including the member's name and precise location — to Twilio, our SMS provider. We use Twilio in the same way to deliver a Guardian invitation. Twilio is contractually restricted to delivering the message and may not use the information for its own purposes.
12.5 Limitations#
Delivery depends on device power, sensors, permissions, connectivity and third-party networks. We cannot guarantee that an alert will be generated, delivered, received or acted upon, and we cannot guarantee the accuracy of the location transmitted. No one at Bondtrail monitors or responds to SOS activations.
Service providers and other disclosures#
Who else touches your information, what they get, and what they may never do.
13.1 Who processes information for us#
These providers process personal information on our instructions only, for the purposes we specify, and may not use it for their own purposes. We have signed data processing agreements with each. The current list is also published on our Subprocessors page.
| Provider | What it receives | Purpose | Location |
|---|---|---|---|
| Contabo | All categories, including location, SOS records and Emergency Contact numbers | Hosting and database infrastructure | United States (Contabo is a German company operating US datacentres) |
| Google — Firebase Cloud Messaging | Push notification tokens and notification content | Delivery of notifications and SOS alerts to Bondtrail users | United States |
| Apple — Push Notification service | Push tokens and notification content, for iOS devices | Relay of notifications to iOS devices | United States |
| Google Maps Platform (Android) and Apple MapKit (iOS), via Expo MapView | Coordinates required to render a map | Displaying location on a map | United States |
| Google Analytics for Firebase | Basic analytics events with a persistent app-instance identifier and IP address, plus additional analytics events only after the member has opted in. Advertising identifier collection is disabled | Understanding how features are used and improving the product | United States |
| Apple App Store and Google Play analytics | Aggregate install and usage statistics provided to us by the stores | Understanding downloads and retention | United States |
| Twilio | Mobile numbers, and message content including a member's name and precise location in an SOS alert. Also used for phone verification, Guardian invitations and contact-removal links | SMS delivery | United States |
| Didit | Information submitted by an adult to verify adult status | Identity verification before a Guardian Code is issued | United States |
| Stripe, and Apple and Google in-app purchase | Subscription status and transaction records. We never receive your full card number | Payment and subscription processing | United States |
| Google Play Console and Apple App Store Connect | Crash and diagnostic reports, and aggregate install and usage statistics | Fixing faults and understanding downloads | United States |
| Authentication | We run authentication on our own servers. No third party holds your credentials | Signing you in | United States, with our other systems |
13.2 Identity verification#
Before an adult can hold Guardian permissions and consent on behalf of a child, we need reasonable confidence that they are an adult. We use Didit for this.
- We ask for the minimum required to establish adult status.
- Verification information is submitted to the provider, not to us. We receive the outcome and a reference number. We do not receive or store your identity document.
- Verification applies to adults only. We never ask a child to verify their identity.
- We do not use facial recognition or facial age estimation. If we ever introduce a method involving biometric characteristics we will obtain your express consent separately, notify the Commission d'accès à l'information as Quebec law requires, and update this policy first.
Identity verification confirms that a person is an adult. It does not confirm that they are a particular child's parent or guardian. That link is established by the child confirming, in the App, that the person holding the Guardian Code is in fact their parent or guardian.
13.3 Disclosures required by law or necessary for safety#
We may disclose personal information where we are legally required to; where it is necessary to establish, exercise or defend a legal claim; where we believe in good faith that disclosure is necessary to prevent imminent serious harm to a person; or where otherwise permitted or required by law.
We do not give any government or law enforcement agency direct, standing or bulk access to location data. We assess each request, require lawful authority, disclose only what the request compels, and where we are legally permitted to do so we will tell the affected member.
13.4 Corporate transactions#
If Bondtrail is involved in a merger, acquisition, financing or sale of assets, personal information may be disclosed to the parties involved, subject to confidentiality obligations. If the Services change hands we will notify you, and any acquirer remains bound by this policy until you are given notice of, and where required consent to, any change.
13.5 We do not sell personal information#
We do not sell, rent, trade or licence your personal information. Not your location, not your driving information, not anything else. We do not share it for cross-context behavioural advertising.
We do not share location, driving or behavioural information with insurers, employers, advertisers or data brokers. If that were ever to change, it would require your consent, asked for separately and specifically, and you would be free to decline and keep using Bondtrail.
14.1 Age classes and whose consent is required#
| Age | Consent standard | What this means in practice |
|---|---|---|
| Under 14 | Guardian consent required by law | Bondtrail has no minimum age. A verified adult must consent through the Guardian process in section 14.2 before an account becomes active and before the member can turn sharing on. The member can turn sharing off themselves at any time. |
| 14 to 17 | The minor may consent for themselves | The minor consents in their own right and receives an age-appropriate notice. Sharing is off until they turn it on. |
| 18 and over | Consents for themselves | Full autonomy over sharing. |
Why 14. Article 14 of Quebec's Act respecting the protection of personal information in the private sector provides that the consent of a minor under 14 is given by the person having parental authority or by a tutor, and that a minor of 14 or over may consent for themselves. We apply that standard to every member in Canada. Bondtrail sets no minimum age of its own; what age determines is who gives consent.
14.2 Age assurance#
We cannot verify age with certainty. No consumer application can. What we do is make a reasonable and documented effort:
- a date of birth before any account is created;
- identity verification of the adult who becomes a Guardian, confirming adult status;
- in-app confirmation by the minor that the adult is genuinely their parent or guardian;
- age classification of every member of a Circle by the Guardian; and
- a permanent record of each of these steps.
How a Guardian relationship begins. A verified adult is issued a Guardian Code and gives it to the member. Codes are single use and remain valid until they are used. A verified adult can generate a fresh one at any time using the Regenerate Code control.
The member then confirms in the App that the adult is genuinely their parent or guardian. Only at that point does the account become active and the Circle leave provisional mode. A member under 14 cannot create or use an account before this is complete.
Identity verification establishes that a person is an adult. It does not establish that they hold parental authority over a particular child. The member's confirmation is what connects the two.
14.3 What we do and do not do with a minor's information#
- We use a minor's personal information only to deliver the Services within their Circle and to support SOS.
- We do not use it for behavioural targeting, marketing, or product experimentation directed at that individual.
- We do not send marketing communications to any member under 18.
- A minor cannot share their location outside their Circle.
- A minor's Circle composition is controlled by their Guardian, except that a minor may choose their own Emergency Contact.
14.4 What Guardians can do#
A Guardian may access, correct, export and delete their child's personal information, and may withdraw consent on their child's behalf, by contacting the Privacy Officer. A Guardian may also close a child's account.
Reviewing who is in a child's Circle. A Guardian manages Circle membership from the Circle settings screen, which is the same member-management screen every administrator uses. There is no separate Guardian review screen and Bondtrail does not prompt a Guardian to check membership. Keeping a child's Circle to people who should see that child's location is something a Guardian needs to do themselves.
What a Guardian cannot do: force a child of any age to share their location, or prevent a child turning sharing off. Changes to sharing are recorded in the Circle Feed but are not sent by push notification. Guardians should understand this before relying on Bondtrail. The absence of a location does not mean anything is wrong, and it does not mean anything is right either.
14.5 What minors can do#
A member of any age may turn their own sharing on and off, and read their Circle's Activity Log. A member aged 14 to 17 may also activate a Privacy Bubble. A minor may contact the Privacy Officer directly with a question or complaint, and we will treat them as a person with rights rather than as their Guardian's dependant, while involving the Guardian where the law requires it.
14.6 Children's Privacy Notice#
A separate Children's Privacy Notice, written in plain, age-appropriate language, explains what we collect about minors, who can see a minor's location, how SOS works, what Guardians can do, and how to contact the Privacy Officer. It is published on our website and reachable from Settings.
How long we keep information#
Deletion schedules for every category. These are maximums, not intentions.
15.1 Retention schedule#
| Category | Maximum retention | Why |
|---|---|---|
| Location, including history, Place Events and driving information | 30 days from capture | The same for every member on every plan. A free plan displays 2 days of it and no driving history; a paid plan displays 30 days. Display and retention are different things |
| SOS event records | 30 days from the event | Safety audit trail. No shorter period applies to members under 18 |
| Account and identity information | Life of the account, plus 30 days | Contract performance; supports a late access request |
| Emergency Contact numbers | While the designation is in force; deleted within 30 days of removal or account closure | No basis to keep them beyond the designation |
| Check-in content and private notes | 30 days from capture | The same for every member on every plan. Private notes are never shown to other members |
| Consent records | Life of the account, plus 5 years | We must be able to evidence what was consented to and when |
| Analytics data | 1 year from capture | Product improvement |
| Activity Log entries | Life of the account | The log only works if it cannot be selectively erased. Deleted with the account |
| Security and access logs | 30 days | Security investigation |
| Circle Feed posts and images | While the Circle exists; deleted within 30 days of the author deleting the post, leaving the Circle or closing their account | Content belongs to the person who posted it |
| Identity verification outcome and reference | Life of the account, plus 30 days. We do not hold the underlying identity document | We must be able to show that adult status was verified |
| Backups | On a rolling cycle. Deletion is re-applied if a backup is restored | Disaster recovery. Deleted information persists in backups until the cycle completes |
15.2 Deleting your account#
When you delete your account we begin deletion across our production systems. We aim to complete it within thirty (30) days, except that:
- information we are legally required to keep is retained for the periods above;
- SOS event records are retained for their defined period; and
- information already delivered to other members of your Circle, such as a post in the Circle Feed, may remain visible to them.
15.3 Backups#
Backups run on a schedule. Deleted information persists in backups until the cycle expires. We do not restore deleted personal information from backup except to recover from a system failure, and where we do, deletion is re-applied.
16.1 What is in place#
- HTTPS and TLS in transit. Traffic between your device and our servers is protected using HTTPS and TLS.
- Passwords. We run authentication on our own servers and store passwords hashed, never in plain text. No third party holds your credentials. Phone numbers and email addresses are verified through a third-party verification service.
- Multi-factor authentication on the administrative accounts used to reach our infrastructure, databases, developer accounts and vendor consoles.
- Data processing agreements with every provider that handles personal information on our behalf.
- Advertising identifier collection disabled in our analytics on both platforms.
16.2 What HTTPS and TLS do and do not mean#
HTTPS and TLS protect information while it travels between your device and our servers. That is not the same as end-to-end encryption and we do not claim it is. Because Bondtrail routes location between Circle members, maintains an Activity Log and delivers SOS alerts, our systems can process location data.
16.3 If something goes wrong#
Where a confidentiality incident presents a risk of serious injury we will notify the Commission d'accès à l'information du Québec and the Office of the Privacy Commissioner of Canada, and affected individuals, without delay and consistent with our obligations under Quebec Law 25 and PIPEDA.
16.4 No system is completely secure#
No method of transmission or storage is completely secure and we cannot guarantee absolute security. What we can do is apply safeguards proportionate to the sensitivity of the information, improve them, and tell you promptly if something goes wrong.
16.5 Your part#
Use a strong, unique password. Keep your device locked and updated. Tell us immediately at legal@bondtrail.app if you think your account has been accessed without your authorisation.
Where your information is processed#
Our servers are in the United States. Here is what that means for you.
17.1 Our servers are in the United States#
Bondtrail is a Canadian company. Our primary database and application servers are hosted with Contabo in the United States. Contabo is a German company operating datacentres in the United States. This means your personal information — including location information, and including location information about children in your Circle — is stored and processed in the United States.
17.2 Our team works from Canada and Nigeria#
Two of Bondtrail's three founders are based in Nigeria and hold backend and infrastructure responsibilities. Administrative access to systems holding personal information is therefore exercised from Nigeria as well as from Canada. We disclose this because it is a cross-border access arrangement and you are entitled to know about it.
17.3 What that means#
Personal information stored in the United States is subject to United States law while it is there. United States authorities may in some circumstances compel a provider to disclose data held on their systems, including under legislation with extraterritorial effect. Those powers exist regardless of the contractual protections we put in place, and we cannot promise you they will never be used.
Our position: we do not voluntarily disclose personal information to any government or agency; we require lawful authority for every request and assess each one; we disclose only what a request compels; and where we are legally permitted to tell the affected person, we do.
17.4 What we do about it#
- We have data processing agreements in place with our providers.
- We protect personal information in transit using HTTPS and TLS.
- Quebec Law 25 requires a privacy impact assessment before personal information is communicated outside Quebec. A privacy impact assessment dated 8 July 2026 exists, and an assessment of this transfer has been carried out.
17.5 Our intention#
We intend to move primary data storage to Canadian infrastructure. We are not going to give you a date we cannot commit to, and we will not describe it as done before it is.
18.1 What you can ask for#
| Right | What it means | Our response time |
|---|---|---|
| Access | A copy of the personal information we hold about you, and information about how it is used and to whom it has been disclosed | 30 days |
| Correction | Correction of inaccurate or incomplete information. Most profile information can be corrected in the App immediately | 30 days |
| Deletion | Deletion of your personal information, subject to what we must lawfully retain | 30 days |
| Portability | A copy in a structured, commonly used, machine-readable format | 30 days |
| Withdraw consent | Withdrawal of any consent you have given | Response within 72 hours; up to 30 days to give full effect where reasonable |
| Object | Objection to processing carried out on the basis of legitimate interest, including analytics | 30 days |
| Emergency Contact removal | If you are named as someone's Emergency Contact, you can ask us to delete your number even though you are not a user | 30 days |
| Complain | To challenge our compliance with privacy law | Acknowledged within 5 days; resolved within 30 days |
18.2 How to exercise a right#
You can see what we hold, download a copy, correct your details and delete your account from Settings, under Privacy and Legal. To withdraw consent or exercise another privacy right, contact the Privacy Officer at legal@bondtrail.app. We will action any request within the timeframes above.
We may ask you to verify your identity before acting on a request, in proportion to the sensitivity of the information. We will not use information provided for verification for any other purpose.
Exercising a right is free.
18.3 If we say no#
If we refuse a request in whole or in part, we will tell you why, tell you which provision we rely on, and tell you how to complain — to us, and to the regulator.
18.4 Complaints#
Contact the Privacy Officer first. We will acknowledge within five (5) days and aim to resolve within thirty (30) days.
If you are not satisfied, you may complain to:
| Office of the Privacy Commissioner of Canada | 30 Victoria Street, Gatineau QC K1A 1H3 · 1-800-282-1376 · priv.gc.ca |
| Commission d'accès à l'information du Québec (Quebec residents) | cai.gouv.qc.ca |
| Office of the Information and Privacy Commissioner of Alberta (Alberta residents) | oipc.ab.ca |
| Office of the Information and Privacy Commissioner for British Columbia (BC residents) | oipc.bc.ca |
Quebec Law 25 gives you rights and gives us obligations beyond the federal baseline. In addition to everything above:
- Our Privacy Officer is identified in section 4 and their contact details are published on our website.
- Privacy by default applies: functions that allow a person to be located are deactivated until deliberately activated. Section 10 explains how, including where we fall short of the ideal.
- You have the right to portability and to erasure, as set out in section 18.
- We will report a confidentiality incident presenting a risk of serious injury to the Commission d'accès à l'information and to affected individuals without delay.
- We do not use personal information to render a decision based exclusively on automated processing. If we ever do, we will tell you at the time, explain the information and factors used, and give you the right to make representations to a person who can review the decision.
We conducted a privacy impact assessment before launching this platform, and we conduct one before any cross-border transfer. A confidentiality incident register will be in place before launch.
A note for Quebec residents. We do not market Bondtrail specifically in Quebec, but the App can be downloaded anywhere in Canada, so Quebec residents may use it and Law 25 applies to them. This policy is published in English. Whether a French version is required under the Charter of the French Language is a question we have put to counsel.
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significant effects.
Some features are automated: driving detection classifies movement automatically, Place Events are generated automatically, and Privacy Bubbles end automatically when a radius or period is exceeded. These are feature behaviours within your Circle. They do not determine your access to the Services, your price, or any right, and you can always see and question the outcome.
Driving classifications are estimates and are frequently wrong at the margins. They may treat a bus, train, cycle or passenger journey as driving, and may miss trips. They must not be relied on for insurance, employment or legal purposes.
Our website uses strictly necessary cookies to deliver the page and keep it secure. We do not currently use analytics or other non-essential cookies. If we introduce any, we will present a consent banner first and update this section.
We do not use advertising cookies and we do not permit third-party advertising trackers on our properties. You can manage cookies in your browser settings.
We offer the Services in Canada and have restricted store availability accordingly. We do not direct the Services to, or solicit users in, any other country.
If we expand into another market we will prepare a privacy impact assessment for that market and publish a regional supplement addressing the applicable framework — which may include COPPA and United States state privacy legislation, the EU and UK GDPR, and children's codes — before making the Services available there.
We publish privacy disclosures through the Apple App Privacy labels and the Google Play Data Safety form, and maintain them so they are consistent with this policy.
Consistency matters more than usual here. Both stores compare the declared behaviour against the app. Background location collection, children's data, and data shared with third parties each attract additional review. Where this policy and a store disclosure differ, treat this policy as the more detailed statement and correct the disclosure.
| Privacy Officer | Festus Asiyanbi, Co-Founder and Chief Executive Officer, legal@bondtrail.app |
| Bondtrail Technologies Inc. | 2-38 Leighside Lane, Saint John, New Brunswick, Canada E2K 2R6 |
| General enquiries | hello@bondtrail.app |
| Security | legal@bondtrail.app |
| Trust and safety | legal@bondtrail.app |
This Privacy Policy should be read together with our Terms of Service and our Children's Privacy Notice.