Location
ThrottleRun may collect approximate and precise location when a rider uses maps, searches near a route, records a ride, shares an active ride, reports a hazard, or completes location-based event verification. Ride recording is rider initiated, uses a persistent notification, can be stopped immediately, and does not request Android background-location permission.
Personal information
Name, email address, account ID, optional profile information, and manually entered emergency-contact or passenger names and phone numbers support account management, rider safety, clubs, and organized rides. ThrottleRun does not read the Android address book or call log.
Ride, route, and user-created content
Saved routes, waypoints, ride history, motorcycle and maintenance records, event registrations, waivers, checkpoint results, notes, club and event messages, GPX-derived route data, and organizer-provided document links are stored only when a rider or authorized organizer uses those features.
Purchases
The app receives subscription plan, entitlement, receipt, amount, status, and provider-reference information. Android opens website-managed checkout. Square secures and tokenizes payment-card fields; raw card numbers and card security codes do not reach ThrottleRun.
App activity and diagnostics
ThrottleRun records account actions, synchronization and delivery status, errors, application version, and security audit events needed to operate, protect, and troubleshoot the service. It does not include an advertising SDK, build an advertising profile, or sell rider activity.
Device identifiers
Paired-device IDs and an optional Firebase push token are used for device authentication, push delivery, session security, and revocation. Push tokens are encrypted in server storage.
Not collected by the Android package
The current Google Play package does not request contacts, call-log, SMS, microphone, camera, background-location, installed-app inventory, or broad file-system permissions. It does not collect raw payment-card details, advertising IDs, health records, or web-browsing history.
Encryption and deletion
Supported app and API traffic uses HTTPS. A signed-in rider can export account data and schedule account deletion in the rider profile. Public deletion instructions are available at throttlerun.org/data-deletion/. Privacy and data-safety questions can be sent to privacy@truecourse.tech.
Operational retention schedule
Temporary contact live-share links expire after 12 hours. A scheduled account deletion has a seven-day recovery period. API rate-limit and replay-protection records expire after 24 hours. Successful API telemetry is removed after 90 days, and resolved failure telemetry is removed after 365 days. Account, motorcycle, route, ride, maintenance, club, event, and message records remain available while the account or applicable workspace is active unless an authorized user deletes them. Limited de-identified event, security, billing, and audit evidence may remain when needed for disputes, fraud prevention, accounting, or legal obligations.
Sensitive values and credentials
Emergency-contact phone numbers, optional VIN values, push tokens, provider credentials, and webhook secrets use encrypted server storage. Passwords, device secrets, share tokens, invitation codes, and one-time credentials are stored as non-reversible hashes where the feature does not need to recover the original value. Payment-card numbers and card security codes are not stored by ThrottleRun.
Service providers and user-directed sharing
Configured map, routing, search, public-safety, payment, hosting, email, and push providers process only the request data needed to operate the selected feature. A rider may also direct ThrottleRun to share an active location with a club, event, emergency contact, or temporary link recipient.
Play Console declaration boundary
The Google Play Data Safety form must cover every released build, region, feature, and third-party software development kit for the Play package. This page describes version 0.19.7 behavior and must be reviewed again before each production submission.