← Back to trackr.vigla.tech
TRACKR
Legal · Data protection⏰ ~30 min read

Privacy Policy for Trackr

Effective Date: November 15, 2025

Last Updated: November 15, 2025

1. Introduction

Welcome to Trackr. This Privacy Policy explains how TRACKR ("we," "our," or "us") collects, uses, discloses, and protects your personal information when you use our mobile application and services.

2. Data Controller Information

TRACKR is the data controller responsible for the collection, processing, and protection of your personal data when you use our application and services.

Data Controller Details

Legal Entity Name: TRACKR

Data Controller: TRACKR (our company)

Business Address: 10 Modupe St, Idimu, Lagos 102213, Lagos, Nigeria

Contact Email: [email protected]

Website: https://trackr.vigla.tech


Data Protection Officer

Name: Ifeoluwa Adeleke

DPO Email: [email protected]

For privacy inquiries and to exercise your data rights, please contact us using the information above.

3. Information We Collect

We collect and process the following categories of personal and non-personal information when you use our app:

3.1 Personal Identifiers

We collect personal identifiers that can be used to identify you:

3.2 Precise Location Data

Important: We collect precise location data when you use our vehicle tracking features. This includes:

  • Real-time GPS Coordinates: Latitude and longitude data
  • Location History: Historical record of vehicle locations
  • Background Location Tracking: When enabled for continuous tracking
  • Foreground Location: When app is actively in use
  • Address Information: Derived from GPS coordinates through geocoding
  • Speed and Direction: Vehicle movement data
  • Altitude: Elevation data from GPS

This location data is necessary for our core vehicle tracking functionality and is only collected when you have granted location permissions.

3.3 Device and Technical Information

We automatically collect technical information about your device and how you use our app:

3.4 App Activity and Usage Data

We collect information about how you interact with our app:

3.5 Photos and Media Files

We collect visual content when you use certain features:

Photo and Camera Privacy - Zero Storage/Camera Permissions:

  • No Camera Permission: We use Android's ACTION_IMAGE_CAPTURE intent to launch your device's built-in camera app. We only receive the final photo you choose to capture.
  • No Storage Permissions: We use Android Photo Picker (Android 13+) or system photo picker (older versions) to access gallery photos. These methods don't require READ_MEDIA_IMAGES, READ_EXTERNAL_STORAGE, or WRITE_EXTERNAL_STORAGE permissions.
  • Temporary Access Only: The system grants temporary access only to the specific photos you select - we never access your entire photo library.
  • Maximum User Control: You explicitly select each photo to share. No automatic or background photo access.

3.6 Sensitive Personal Information

We may collect the following sensitive personal information:

3.7 Diagnostic and Performance Data

We collect data to diagnose issues and improve app performance:

3.8 Communications

If you contact us, we may collect:

3.9 Social Media Information

If you use social login features, we receive:

3.10 Vehicle Data

Information about vehicles you register in the app:

3.11 Data We Do NOT Collect

For transparency, we explicitly state that we do NOT collect:

  • Microphone or audio recordings
  • Calendar information
  • Contacts or address book
  • SMS or text messages
  • Call logs or phone call information
  • Health or fitness data
  • Financial account information beyond payment processing
  • Government-issued identification documents

3A. Data Types Summary - Google Play Data Safety Format

In compliance with Google Play Store requirements, below is an explicit categorization of all data types we collect, organized by Google Play's Data Safety categories:

Data Types Declaration: This section explicitly lists all data types collected by our app, matching Google Play's Data Safety form categories for complete transparency.

3A.1 Location Data Types

✅ Approximate Location

  • Collected: YES
  • Purpose: Vehicle tracking fallback, city-level location
  • Shared: With Firebase/Google (backend storage), Google Maps (display)
  • Optional/Required: Required for vehicle tracking

✅ Precise Location

  • Collected: YES
  • Purpose: Real-time vehicle tracking, GPS coordinates, location history
  • Shared: With Firebase/Google (backend storage), Google Maps (display and geocoding)
  • Optional/Required: Required for core vehicle tracking functionality

3A.2 Personal Information Data Types

✅ Name

  • Collected: YES
  • Purpose: User account creation, profile display
  • Shared: With Firebase Authentication, Google Sign-In, Apple Sign-In
  • Optional/Required: Required for account creation

✅ Email Address

  • Collected: YES
  • Purpose: Account creation, authentication, communication
  • Shared: With Firebase Authentication, Google Sign-In, Apple Sign-In
  • Optional/Required: Required for account creation

✅ User IDs

  • Collected: YES
  • Purpose: Unique user identification, account management
  • Shared: With Firebase services, Google/Apple authentication
  • Optional/Required: Required (automatically generated)

✅ Phone Number

  • Collected: YES (optional)
  • Purpose: Account verification, contact purposes
  • Shared: With Firebase if provided
  • Optional/Required: Optional

3A.3 Financial Information Data Types

✅ Purchase History

  • Collected: YES
  • Purpose: Track subscription status, premium features access
  • Shared: With Google Play Billing, Apple StoreKit, Firebase
  • Optional/Required: Only if using premium features

✅ User Payment Info

  • Collected: NO (processed by Google/Apple)
  • Purpose: N/A - Payment details handled by app stores
  • Shared: Directly with Google Play/Apple (we do NOT receive full card details)
  • Note: We only receive transaction IDs and purchase tokens, NOT credit card numbers

3A.4 Photos and Videos Data Types

✅ Photos

  • Collected: YES
  • Purpose: Vehicle documentation, profile pictures, VIN scanning
  • Shared: With Firebase Storage (cloud storage), Google ML Kit (VIN scanning - processed on-device)
  • Optional/Required: Optional (can use app without photos)

❌ Videos

  • Collected: NO
  • Purpose: N/A

3A.5 App Activity Data Types

✅ App Interactions

  • Collected: YES
  • Purpose: Analytics, feature usage tracking, app improvement
  • Shared: With Firebase Analytics, Google Analytics
  • Optional/Required: Collected automatically for all users

✅ In-App Search History

  • Collected: YES
  • Purpose: Vehicle searches, location searches within app
  • Shared: With Firebase (backend storage)
  • Optional/Required: Collected when using search features

✅ Other User-Generated Content

  • Collected: YES
  • Purpose: Vehicle information, maintenance notes, custom fields
  • Shared: With Firebase Firestore (backend storage)
  • Optional/Required: Optional user input

3A.6 Device or Other IDs Data Types

✅ Device or Other IDs

  • Collected: YES
  • Examples: Android ID, Advertising ID, Instance ID, Firebase Installation ID
  • Purpose: Analytics, app installations tracking, crash reporting, device identification
  • Shared: With Firebase, Google Analytics, Crashlytics
  • Optional/Required: Collected automatically
  • Note: Advertising ID can be reset in device settings

3A.7 App Info and Performance Data Types

✅ Crash Logs

  • Collected: YES
  • Purpose: Debug crashes, improve app stability
  • Shared: With Firebase Crashlytics
  • Optional/Required: Collected automatically when crashes occur

✅ Diagnostics

  • Collected: YES
  • Purpose: App performance monitoring, error tracking
  • Shared: With Firebase Performance Monitoring
  • Optional/Required: Collected automatically

✅ Other App Performance Data

  • Collected: YES
  • Examples: App launch time, screen load times, API response times, battery usage
  • Purpose: Performance optimization, user experience improvement
  • Shared: With Firebase Performance Monitoring, Google Analytics
  • Optional/Required: Collected automatically

3A.8 Files and Docs Data Types

✅ Files and Docs

  • Collected: YES (vehicle photos, VIN images)
  • Purpose: Vehicle documentation, profile pictures
  • Shared: With Firebase Storage (cloud storage)
  • Optional/Required: Optional (user-uploaded)

3A.9 Data Types We DO NOT Collect

For complete transparency, we explicitly state we do NOT collect the following data types:

  • Audio Files or Voice/Sound Recordings
  • Music Files
  • Video Files
  • Calendar Events
  • Contacts
  • Messages (SMS, Email, In-App)
  • Health and Fitness Data
  • Web Browsing History
  • Emails
  • Text Messages (SMS or MMS)
  • Other In-App Messages
  • Physical Address (we derive addresses from GPS coordinates via geocoding)
  • Race and Ethnicity
  • Political or Religious Beliefs
  • Sexual Orientation or Gender Identity
  • Other Sensitive Personal Info

3A.10 Data Collection and Sharing Summary

Data Type Category Collected? Shared? Purpose
Location (Precise & Approximate) ✅ YES ✅ YES Vehicle tracking
Personal Info (Name, Email, IDs) ✅ YES ✅ YES Account, authentication
Financial Info (Purchase History) ✅ YES ✅ YES Premium subscriptions
Photos ✅ YES ✅ YES Vehicle documentation
App Activity & Interactions ✅ YES ✅ YES Analytics, improvement
Device IDs ✅ YES ✅ YES Analytics, identification
Crash Logs & Diagnostics ✅ YES ✅ YES Bug fixing, stability
Videos ❌ NO ❌ NO N/A
Audio/Voice Recordings ❌ NO ❌ NO N/A
Contacts/Calendar ❌ NO ❌ NO N/A
Messages/SMS ❌ NO ❌ NO N/A
Health & Fitness ❌ NO ❌ NO N/A

4. Legal Basis for Processing (GDPR)

For users in the European Union, we process your personal data based on the following legal grounds:

5. How We Use Your Information

We use your information for the following purposes:

6. Data Sharing and Disclosure

6.1 We Do NOT Sell Your Personal Data

Important: We do not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration.

6.2 Service Providers

We share information with trusted service providers who assist us in operating our app:

These service providers are contractually obligated to protect your data and use it only for specified purposes.

6.3 Legal Requirements

We may disclose your information if required by law, court order, or governmental authority, or to protect our rights and safety.

6.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change.

6.5 Your Right to Know About Data Sharing

You have the right to know whether your personal data is being shared with third parties. Upon request, we will provide you with:

To request this information, contact us at [email protected]

7. Your Privacy Rights

7.1 Rights for EU Users (GDPR)

If you are located in the European Union, you have the following rights:

EU Supervisory Authorities: You can find your local data protection authority at: https://edpb.europa.eu/about-edpb/board/members_en

7.2 Rights for California Users (CCPA)

If you are a California resident, you have the following rights:

How to Exercise CCPA Rights: Contact us at [email protected] or [email protected]

7.3 Rights for Virginia Users (VCDPA)

If you are a Virginia resident, you have the following rights:

How to Exercise VCDPA Rights: Contact us at [email protected]

7.4 Rights for Brazilian Users (LGPD)

If you are located in Brazil, you have the following rights under LGPD:

How to Exercise LGPD Rights: Contact us at [email protected] or our DPO at [email protected]

7.5 How to Exercise Your Rights

To exercise any of these rights, please contact us at:

We will respond to your request within 30 days (or as required by applicable law).

8. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe we have violated your privacy rights:

9. How to Opt-Out of Data Sharing/Targeted Advertising

While we do not sell personal data or engage in targeted advertising, you can control your data as follows:

To opt-out of any data sharing or selling (which we do not currently engage in): Email [email protected] with subject line "Data Sharing Opt-Out Request"

10. Data Retention

We retain your personal information for as long as necessary to:

When you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it by law.

11. Data Security

We implement appropriate technical and organizational security measures to protect your data:

However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

12. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place, including:

13. Children's Privacy

Trackr is not intended for users under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

14. Third-Party Services, SDKs, and Data Sharing

We share your personal data with the following third-party services to operate our app and provide our services. Below is a comprehensive disclosure of all third-party services, SDKs, API endpoints, and what data is shared with each:

Data Sharing Disclosure: We share your data with third-party service providers ONLY to provide and improve our services. We do NOT sell your personal data to third parties.

SDK Declaration - Complete List of All SDKs Used

Below is the complete list of all third-party Software Development Kits (SDKs) integrated into our app:

All SDKs Integrated in Trackr App:

SDK Name Provider Purpose Data Shared
Firebase Core SDK Google LLC Backend infrastructure Device info, app version
Firebase Authentication SDK Google LLC User authentication Email, name, user ID, tokens
Cloud Firestore SDK Google LLC Database storage All user data, vehicle data
Firebase Storage SDK Google LLC File storage Photos, images, documents
Firebase Analytics SDK Google LLC Usage analytics App interactions, usage patterns
Firebase Crashlytics SDK Google LLC Crash reporting Crash logs, stack traces
Firebase Performance Monitoring SDK Google LLC Performance tracking App performance metrics
Google Maps SDK for Android/iOS Google LLC Map display Location data, map interactions
Google Places SDK Google LLC Location search Search queries, location data
Geocoding SDK Google LLC Address conversion GPS coordinates, addresses
Firebase Installations SDK Google LLC Device instance management Installation IDs, device info
Google Play Services FIDO Google LLC Biometric authentication Biometric auth tokens (on-device)
ML Kit Barcode Scanning Google LLC VIN barcode scanning Barcode images (on-device)
ML Kit Digital Ink Recognition Google LLC Handwriting recognition Digital ink data (on-device)
ML Kit Face Detection Google LLC Face detection in images Face detection data (on-device)
ML Kit Image Labeling Google LLC Image content identification Image labels (on-device)
ML Kit Language ID Google LLC Language identification Text samples (on-device)
ML Kit Object Detection Google LLC Object detection in images Object detection data (on-device)
ML Kit Smart Reply Google LLC Suggested text responses Message text (on-device)
ML Kit Translate Google LLC Text translation Text to translate (on-device)
Google Sign-In SDK Google LLC Social authentication Google account email, name, ID
Sign in with Apple SDK Apple Inc. Social authentication Apple ID, email, name
Google Play Billing SDK Google LLC Payment processing Purchase tokens, subscription status
StoreKit SDK (iOS) Apple Inc. Payment processing Receipt data, transaction IDs
Cached Network Image SDK Open Source Image caching Image URLs, cached files
Lottie SDK Airbnb (Open Source) Animation rendering None (local only)
Provider SDK Flutter Team State management None (local only)
Shared Preferences Flutter Team Local storage None (device only)

Total SDKs Integrated: 28 SDKs

SDKs that share data externally: 17 SDKs

SDKs that process data locally only: 11 SDKs (8 ML Kit modules process on-device + Lottie, Provider, Shared Preferences)

Note: Most ML Kit modules (Barcode Scanning, Digital Ink Recognition, Face Detection, Image Labeling, Language ID, Object Detection, Smart Reply, Translate) process data entirely on-device without sending it to external servers, providing maximum privacy for AI/ML operations.

SDK Integration Disclosure

All SDKs listed above are integrated into this version of our app. Each SDK has been carefully selected to provide specific functionality essential to our app's operation. We continuously review our SDK integrations to ensure they meet our security and privacy standards.

If we integrate new SDKs in future versions: We will update this privacy policy to reflect any new SDKs and notify users of changes to our data collection and sharing practices.

14.1 Firebase Services (Google LLC)

Purpose: Backend infrastructure, user authentication, database, file storage, and analytics

Data Shared:

SDKs Used:

Endpoints/Domains:

Privacy Policy: https://policies.google.com/privacy

14.2 Google Maps Platform

Purpose: Display maps, geocode addresses, calculate routes, and provide location services

Data Shared:

SDKs Used:

Endpoints/Domains:

Privacy Policy: https://policies.google.com/privacy

14.3 Google ML Kit

Purpose: On-device text recognition for VIN scanning

Data Shared:

SDKs Used:

Note: Image processing happens on-device. Images are NOT uploaded to Google servers.

Privacy Policy: https://policies.google.com/privacy

14.4 Google Sign-In

Purpose: Enable authentication via Google account

Data Shared:

SDKs Used:

Endpoints/Domains:

Privacy Policy: https://policies.google.com/privacy

14.5 Sign in with Apple

Purpose: Enable authentication via Apple ID

Data Shared:

SDKs Used:

Endpoints/Domains:

Privacy Policy: https://www.apple.com/legal/privacy/

14.6 In-App Purchase Providers

Purpose: Process premium subscription payments

Data Shared:

SDKs Used:

Endpoints/Domains:

Note: Payment card details are handled directly by Google/Apple. We do NOT store or access your full payment information.

Privacy Policies:

14.7 Image Hosting Services

Purpose: Serve and cache vehicle images and app assets

Data Shared:

SDKs Used:

Endpoints/Domains:

14.8 Additional Third-Party SDKs

Local Processing (No Data Sharing):

14.9 Complete List of External Endpoints

Our app may connect to the following domains and endpoints to provide our services:

Google/Firebase Endpoints:

  • firestore.googleapis.com
  • identitytoolkit.googleapis.com
  • firebasestorage.googleapis.com
  • firebaseinstallations.googleapis.com
  • fcm.googleapis.com
  • firebase-settings.crashlytics.com
  • app-measurement.com
  • maps.googleapis.com
  • places.googleapis.com
  • geocoding.googleapis.com
  • roads.googleapis.com
  • accounts.google.com
  • oauth2.googleapis.com
  • play.googleapis.com
  • www.googleapis.com

Apple Endpoints:

  • appleid.apple.com
  • buy.itunes.apple.com

Content Delivery Networks (CDN):

  • Various Google Cloud CDN endpoints for image and content delivery

14.10 Data Sharing Summary

We share your personal data with the above third-party services for the following purposes:

All third-party service providers are contractually obligated to:

14.11 Changes to Third-Party Services

If we add new third-party services or endpoints that process your personal data, we will update this Privacy Policy and notify you through the app or via email. We will obtain your consent where required by law before sharing your data with new third parties.

14.12 Your Rights Regarding Third-Party Data Sharing

You have the right to:

To exercise these rights, contact us at [email protected]

15. Device Permissions We Request

Our app requests the following device permissions to provide its features and services. Below is a comprehensive list of all permissions, including why we need them, when they're used, and whether they're required:

Permission Transparency: We only request permissions that are necessary for our app's functionality. You have control over these permissions through your device settings and can revoke them at any time (though this may limit app functionality).

15.1 Location Permissions (Dangerous - Requires User Approval)

ACCESS_FINE_LOCATION - Precise Location

Android Permission: android.permission.ACCESS_FINE_LOCATION

Purpose: To access your device's precise GPS location for real-time vehicle tracking

Why We Need It: Essential for our core vehicle tracking functionality - allows us to track your vehicle's exact location with high accuracy (within meters)

When It's Used: When you enable vehicle tracking or view vehicle location on the map

Data Collected: Precise GPS coordinates (latitude, longitude), altitude, speed, bearing, accuracy

Required: Yes, for vehicle tracking features

Can Be Revoked: Yes, through device settings (will disable vehicle tracking)

ACCESS_COARSE_LOCATION - Approximate Location

Android Permission: android.permission.ACCESS_COARSE_LOCATION

Purpose: To access approximate location (accurate to city block level)

Why We Need It: Fallback for when precise location is unavailable; used for less accurate vehicle location tracking

When It's Used: When GPS signal is weak or as an alternative to precise location

Data Collected: Approximate location coordinates, network-based location

Required: Yes, as fallback for location tracking

Can Be Revoked: Yes, through device settings

ACCESS_BACKGROUND_LOCATION - Background Location

Android Permission: android.permission.ACCESS_BACKGROUND_LOCATION

Purpose: To continue tracking vehicle location even when the app is not actively open

Why We Need It: Enables continuous vehicle tracking and real-time monitoring without requiring the app to be open

When It's Used: When you enable continuous/background vehicle tracking

Data Collected: GPS coordinates collected in the background at regular intervals

Required: No, but required for 24/7 vehicle monitoring

Can Be Revoked: Yes, you can limit location to "Only while using the app" in device settings

User Control: Android 10+ users are explicitly prompted to allow background location separately

15.2 Network Permissions (Normal - Granted Automatically)

INTERNET - Internet Access

Android Permission: android.permission.INTERNET

Purpose: To access the internet for all online features

Why We Need It: Essential for connecting to Firebase backend, Google Maps, authentication, and all cloud features

When It's Used: Continuously while the app is running and needs to sync data, authenticate, load maps, etc.

Data Shared: All data sent to/from our backend services (see Section 14 for details)

Required: Yes, app cannot function without internet access

Permission Type: Normal permission (automatically granted, no user prompt)

ACCESS_NETWORK_STATE - Network State

Android Permission: android.permission.ACCESS_NETWORK_STATE

Purpose: To check if the device is connected to the internet

Why We Need It: Allows app to determine if internet connection is available before attempting to sync data or make API calls

When It's Used: Continuously to monitor network connectivity and provide appropriate user feedback

Data Collected: Network connection status (WiFi, cellular, offline), network type

Required: Yes, for proper error handling and offline mode

Permission Type: Normal permission (automatically granted, no user prompt)

15.3 SDK-Required and Auto-Generated Permissions (Normal - Granted Automatically)

The following permissions are automatically added by our integrated SDKs (Firebase, Google Play Services, etc.) and are required for their functionality. These are "Normal" permissions that don't require user approval:

BILLING - Google Play Billing

Android Permission: com.android.vending.BILLING

Purpose: To process in-app purchases and manage subscriptions through Google Play Store

Why We Need It: Required by Google Play Billing Library for premium subscription features

When It's Used: When you purchase premium subscriptions or make in-app purchases

Added By: in_app_purchase Flutter package / Google Play Billing SDK

Permission Type: Normal permission (automatically granted)

FOREGROUND_SERVICE - Foreground Services

Android Permission: android.permission.FOREGROUND_SERVICE

Purpose: To run background location tracking with a persistent notification

Why We Need It: Required for continuous vehicle tracking when app is in background (shows notification)

When It's Used: When you enable 24/7 vehicle tracking - displays persistent notification while tracking

Added By: Firebase SDKs / Location tracking services

Permission Type: Normal permission (automatically granted)

User Visibility: Foreground services always show a notification, so you're always aware when tracking is active

WAKE_LOCK - Keep Device Awake

Android Permission: android.permission.WAKE_LOCK

Purpose: To prevent device from sleeping during critical operations

Why We Need It: Ensures location updates and data sync complete even if screen turns off

When It's Used: During active vehicle tracking or data synchronization

Added By: Firebase SDKs (Cloud Messaging, Analytics)

Permission Type: Normal permission (automatically granted)

RECEIVE_BOOT_COMPLETED - Auto-start on Boot

Android Permission: android.permission.RECEIVE_BOOT_COMPLETED

Purpose: To receive notification when device finishes booting

Why We Need It: Allows app to restart scheduled tasks (like vehicle tracking alerts) after device restart

When It's Used: When device boots/restarts and you have active vehicle tracking enabled

Added By: Firebase SDKs (Cloud Messaging)

Permission Type: Normal permission (automatically granted)

READ_GSERVICES - Google Services Framework

Android Permission: com.google.android.providers.gsf.permission.READ_GSERVICES

Purpose: To access Google Services Framework configuration

Why We Need It: Required by Google Maps, Firebase, and other Google services

When It's Used: Continuously by Google SDKs for configuration and authentication

Added By: Google Maps SDK, Firebase SDKs

Permission Type: Normal permission (automatically granted)

C2DM RECEIVE - Cloud Messaging

Android Permission: com.google.android.c2dm.permission.RECEIVE

Purpose: To receive push notifications from Firebase Cloud Messaging

Why We Need It: Enables real-time alerts for vehicle events, geofence breaches, maintenance reminders

When It's Used: When you have notifications enabled for vehicle alerts

Added By: Firebase Cloud Messaging SDK

Permission Type: Normal permission (automatically granted)

DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION - Security Permission

Android Permission: trackr.com.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Purpose: Internal Android security permission for broadcast receivers

Why We Need It: Automatically added by Android build tools (Android 13+) to secure internal app components

When It's Used: Always present for security purposes (Android 13+)

Added By: Android build system (automatically generated)

Permission Type: App-internal permission (not accessible by other apps)

Important Notes About SDK Permissions:

  • Automatically Added: These permissions are automatically added by Google Play Services, Firebase, and other SDKs when you integrate them
  • No User Prompt: All are "Normal" permissions that don't require explicit user approval
  • Required for Functionality: Removing these would break core app features (maps, notifications, payments, etc.)
  • Industry Standard: These same permissions are used by millions of apps that integrate Firebase and Google services

15.4 Permission Summary Table

Permission Type Required? Purpose
Fine Location Dangerous Yes Precise vehicle tracking
Coarse Location Dangerous Yes Approximate vehicle location
Background Location Dangerous No* 24/7 vehicle monitoring
Internet Normal Yes Online features
Network State Normal Yes Check connectivity

*Background location is required only if you want 24/7 continuous vehicle tracking. You can use the app with foreground-only location access.

Additional SDK-Required Permissions: Our app also uses 7 additional "Normal" permissions that are automatically added by Firebase, Google Play Services, and other SDKs (BILLING, FOREGROUND_SERVICE, WAKE_LOCK, RECEIVE_BOOT_COMPLETED, READ_GSERVICES, C2DM RECEIVE, DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION). These are documented in detail in Section 15.3 above. These permissions don't require user approval and are industry-standard for apps using Firebase and Google services.

15.5 How to Manage Permissions

You can control app permissions at any time:

Note: Revoking certain permissions (like location) will disable related features (like vehicle tracking).

15.6 Permissions NOT Requested

For transparency, we explicitly state that we do NOT request:

  • Camera permission (CAMERA) - We use the system camera app via intents (ACTION_IMAGE_CAPTURE) for VIN scanning and vehicle photos, which doesn't require camera permission
  • Photo/Video permissions (READ_MEDIA_IMAGES, READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE) - We use Android Photo Picker and system photo picker which don't require storage permissions
  • Microphone or audio recording permission
  • Contacts or address book access
  • Calendar access
  • SMS or phone call permissions
  • Body sensors or health data permissions
  • Bluetooth permissions
  • NFC permissions

15.7 Photo and Camera Access via System Pickers

We use Android's privacy-first approach to access photos and camera without requesting storage or camera permissions.

Android Photo Picker (Android 13+)

On Android 13 and newer, we use the built-in Android Photo Picker:

  • Zero Permissions Required: Photo Picker doesn't require READ_MEDIA_IMAGES or any storage permissions
  • Maximum Privacy: You select specific photos to share - we never access your entire photo library
  • Temporary Access Only: System grants temporary read access only to the photos you select
  • Modern UI: Clean, consistent Google Photos-style interface
  • User Control: You see exactly which photos you're sharing before confirming

System Photo Picker (Android 6-12)

On older Android versions, we use the system photo picker with scoped storage:

  • No Storage Permission Needed: Android's scoped storage allows access to user-selected photos without READ_EXTERNAL_STORAGE permission
  • Intent-Based Access: Uses ACTION_PICK or ACTION_GET_CONTENT intents
  • Limited Scope: Access only to photos you explicitly select, not entire storage

Camera Access via Intent (All Android Versions)

For taking new photos, we use the system camera app:

  • No Camera Permission Required: Uses ACTION_IMAGE_CAPTURE intent to launch system camera
  • Enhanced Security: We never directly access your camera hardware
  • Better Privacy: We only receive the final photo you choose to capture
  • Familiar Experience: You use your device's built-in camera app
  • Full Control: You can cancel at any time without sharing anything

Technical Implementation: The image_picker Flutter package (v1.0.7) automatically selects the appropriate method based on your Android version, always choosing the most privacy-preserving option available. This follows Google Play's Photo and Video Permissions policy and Android's recommended best practices.

When You Use These Features:

  • Scanning VIN → System camera app launches (no camera permission needed)
  • Adding vehicle photo from camera → System camera app launches (no camera permission needed)
  • Selecting vehicle photo from gallery → Photo Picker or system gallery picker launches (no storage permission needed)

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by:

Your continued use of Trackr after changes constitutes acceptance of the updated policy.

17. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:

Data Controller

TRACKR is the data controller responsible for your personal data.

Legal Entity: TRACKR (our company)

Contact Email: [email protected]

Business Address: 10 Modupe St, Idimu, Lagos 102213, Lagos, Nigeria

Website: https://trackr.vigla.tech


Data Protection Officer

Name: Ifeoluwa Adeleke

Contact Email: [email protected]

You have the right to contact us at any time regarding your personal data, privacy rights, or any concerns you may have about how your information is processed.