Privacy Policy

Effective date: 4 September 2026 (section 3.4 and database region) · Odoma Tracker · Tallinn, Estonia

GDPR · Article 13 disclosure

1. Who we are

This Privacy Policy applies to the mobile application Odoma Tracker (the "app"). Throughout this document, "the app" means Odoma Tracker.

The app is developed and maintained by Odoma Digipädevuse Selts ("we", "us", "our"), a non-profit association registered in Estonia (reg. no. 80659718), Tallinn, Harju maakond. Odoma Digipädevuse Selts is the data controller within the meaning of the GDPR.

For privacy-related questions, please contact us at privacy@odoma.ee.

2. What data the app processes on your device

Odoma Tracker processes the following categories of data on your device:

  • GPS / location data — Used to detect trip start and stop, calculate distance, and generate eco-driving and safety scores. Location data is processed entirely on-device and is never transmitted to our servers.
  • Motion and activity data (CoreMotion) — Used to distinguish driving from walking or stationary states. Processed on-device only.
  • Bluetooth proximity data — Used to detect your paired car as a trip start signal. Device names and identifiers are stored locally on your phone and are not transmitted to our servers.
  • Trip records — Trip start and stop time, distance, eco score, safety score, and trip purpose are stored locally on your device. They are not transmitted unless you explicitly choose to export, share, or participate in the optional research program described below.
  • Scanned receipts — The receipt image and the recognised fields are stored locally on your device. They are not transmitted except in the case described in section 3.3, and only on your explicit action.

3. What data is sent to our servers

Our servers receive only limited aggregate or bucketed metrics. We do not transmit raw GPS tracks, route histories, or trip-by-trip location data.

There are two independent server-side participation tracks. Each has its own toggle and can be enabled or disabled independently.

3.1 Public impact statistics & leaderboard (opt-in)

When you enable leaderboard participation in Settings (default: off), the following data is periodically sent:

  • anonymous_id — A randomly generated device identifier created on first launch and stored on your device — in the Keychain on iOS, in the app's private storage on Android. The same identifier is used for the optional Research participation Tier B (see 3.2).
  • avgScore — Your average eco-driving score.
  • tripCount — Your total number of recorded trips.
  • totalKm — Your total recorded driving distance in kilometres.
  • wastedCo2Kg — Estimated excess CO₂ associated with driving style.
  • fuelType — The fuel type selected by you in the app.
  • country — Country code (ISO 3166-1 alpha-2), derived from your device locale, not from GPS.
  • joinedAt — The date on which your aggregate impact profile was first created.
  • co2Norm — The CO₂ norm value for your vehicle.

This data feeds public impact statistics and, optionally, a public leaderboard at odoma.ee/<language>/impact/leaderboard.

3.2 Research participation — Crowd Dataset (opt-in, default off)

When you opt into Research participation (Settings → Research, or via the in-app prompt after your fifth qualifying trip), one or both of the following levels apply:

Basic study (Tier A)

For each completed self-driven trip, we send a record containing:

  • 28 numeric features in coarse buckets (no exact values): average and maximum speed, duration, distance, number of harsh acceleration and braking events, Safety Score, Eco Score, time-of-day bucket, day-of-week bucket
  • Country code (ISO 3166-1 alpha-2)
  • Operating-system major version (iOS or Android)
  • App version
  • row_id — A fresh random identifier generated for that single upload. It is not stored on your device and is never reused. This makes longitudinal analysis structurally impossible at the Basic level — we cannot link two trips back to the same device.

Individual study (Tier B)

Tier B is an additional, separately consented level. When enabled, each Crowd Dataset record described above is sent with anonymous_id instead of a fresh row_id. The anonymous_id is the same on-device identifier described in section 3.1, allowing us (and, in the future, our research partners) to analyse changes in your personal driving style over time.

We do not transmit, in either Tier A or Tier B:

  • GPS coordinates (start, finish, or route)
  • Addresses or place names
  • Bluetooth device names
  • Exact timestamps (only buckets)
  • Device manufacturer or model
  • Operating-system minor or build version
  • Your name, email, contact data, or any directly identifying information

On iOS, each request to our servers is signed with Apple App Attest so that we can verify it came from a genuine, unmodified instance of the official Odoma Tracker app; the signing key never leaves your device's Secure Enclave. On Android the hardware-backed equivalent (Play Integrity) is not yet enabled — those submissions are validated on the server only. This affects how we verify the sender, not what is sent.

3.3 Receipt-recognition feedback (anonymous, on your request)

The app can scan a receipt (for example, a fuel receipt) with the camera and recognise its fields. The receipt itself, its image, and the recognised fields are stored only on your device (see section 2) and are never transmitted automatically.

If a receipt was recognised inaccurately, you may — by your explicit action — send feedback "for study" to help us improve the recognition algorithm. Before sending, the app shows a preview of exactly what will be sent.

The submitted record contains:

  • Structural receipt fields (these do not identify you): vendor, date, total, currency, VAT rate and amount, net amount, category, payment method, receipt number, document code, store registration code;
  • The list of fields you corrected manually — this is the useful learning signal;
  • Schema version, record creation time, app build number, locale;
  • Redacted receipt text. Hard-form personal data is automatically stripped from the recognised text and replaced with placeholders: IBAN → [IBAN], Estonian isikukood → [ISIKUKOOD], card numbers → [CARD], names (by the "Müüja/Teenindaja/Kassapidaja" anchors and by the device owner's known names) → [NAME]. You see on screen the exact redacted text that will be sent, and you decide whether to send it or not.

Anonymity. The record contains no device identifier, anonymous_id, or any other identifier. The client adds no such fields; additionally, the server checks every submission and rejects it in full, without storing it, if it contains any known identifier field (anonymous_id, pseudo_id, device_id, user_id, and the like). Submissions therefore cannot be linked to each other, to the user, or to your other data in Odoma Tracker.

Integrity. On iOS each submission is signed with Apple App Attest to confirm it came from a genuine, unmodified instance of the official app; the signing key never leaves the device's Secure Enclave. On Android the hardware-backed equivalent (Play Integrity) is not yet enabled.

Server-side storage. Received records are stored append-only, admin-only, are not part of any published or partner-shared dataset, and are used solely to improve receipt-recognition quality. Retention is up to 12 months from receipt, after which the record is automatically deleted.

Legal basis. GDPR Article 6(1)(a) — your consent, given separately for each submission. Because the record is anonymous by construction and minimal in scope, a specific submission cannot be withdrawn after the fact (it cannot be located — it is linked to nothing); you control the transfer before it happens via the preview (see also section 7 on GDPR Article 11).

The app can work linked to your employer's dashboard Odoma for companies (dashboard.odoma.app). The link is enabled only by you: you enter the company's invitation code in the app. Until there is a link, not a single trip or receipt leaves the phone for the servers.

After linking, only trips marked as work trips and the receipts you chose to hand over to the company are sent to the dashboard server: date and time, start and end addresses, distance, odometer readings, purpose, site, compensation amount and a simplified route line (no more than a few dozen points) from which the dashboard determines the site and the time spent there; for a receipt — the photo and the recognised fields. Personal trips are never transferred. If you change a work trip to personal, its server copy is deleted.

The dashboard operator is the commercial company ODOMA SERVICES OSAÜHING (reg. code 17589729); it processes this data on behalf of your employer, and the employer is the controller of this data. Details, retention periods and your rights regarding this data are in the dashboard privacy policy. The link can be broken in the app at any time: after that no new trips go to the server, and the deletion of data already transferred is agreed with your employer.

The phone's diagnostic logs (including coordinates) go to the dashboard server only in developer mode, which you enable yourself in the settings; in normal operation they stay on the phone.

4. Legal basis for processing (GDPR Article 6)

Article 6(1)(a) GDPR — Consent

The following processing relies on your explicit consent, which you may withdraw at any time in Settings:

  • Public leaderboard participation
  • Receipt-recognition feedback (section 3.3) — consent is given separately for each submission
  • Research participation (Tier A, Basic study)
  • Research participation (Tier B, Individual study)

Article 6(1)(f) GDPR — Legitimate interests (impact statistics)

We process the limited aggregate metrics described in Section 3.1, linked to your anonymous_id, in order to measure the environmental and behavioural impact of the app. This processing is necessary to:

  • Demonstrate the effectiveness of our non-profit environmental mission;
  • Improve the eco-driving and safety scoring algorithms shipped to all users in future versions;
  • Understand how the user base evolves over time.

We consider this processing proportionate because the data is aggregate, contains no raw GPS or directly identifying information, and is linked only to a device-generated identifier.

You have the right to object at any time by contacting us at privacy@odoma.ee.

5. How long we retain data

  • On-device trip data — Stored until you delete individual trips or uninstall the app. This data remains under your control.
  • Public impact statistics — Retained while leaderboard participation is enabled. Removed within 7 days after you disable leaderboard participation.
  • Crowd Dataset Tier A (Basic study) — Retained for up to 24 months from upload date, then automatically deleted.
  • Crowd Dataset Tier B (Individual study) — Retained for up to 24 months from your last contribution. After 12 months of inactivity, your records are automatically purged. You may also request immediate deletion at any time by tapping "Delete my data" in Settings → Research.
  • Receipt-recognition feedback (section 3.3) — Up to 12 months from receipt, then automatically deleted. A record cannot be linked to you or deleted on request, because it is anonymous by construction.

6. Data sharing and third parties

We do not sell or rent your data, and we do not share it with advertising networks, data brokers, or third-party analytics SDKs.

Our server infrastructure is hosted on Google Firebase: functions and files in the EU (europe-west3, Frankfurt) region, the Firestore database in the europe-west2 (London, United Kingdom) region; the transfer to the United Kingdom relies on the European Commission's adequacy decision, valid until 27 December 2031. Firebase is used solely to operate our backend API and store the limited metrics described above. We use Firebase under Google's applicable data processing terms.

Future insurance pilots (Tier B only)

We are exploring partnerships with insurance companies to enable discount programs for careful drivers, based on Crowd Dataset Tier B data. No such program is currently active. Before any sharing of your anonymous_id-linked records with an insurance partner takes place:

  • A written joint controller or data processor agreement (GDPR Art. 26 / 28) will be in place;
  • The specific partnership and data flow will be disclosed in the app and on this page;
  • We will obtain your explicit, separate opt-in consent for that specific program before any sharing happens. Existing Tier B consent does not by itself authorise sharing with a specific insurer.

If you have only Tier A consent (not Tier B), your data carries no anonymous_id and is structurally non-linkable to you, so it cannot be shared with insurance partners as your data.

7. Your rights under GDPR

If you are located in the EU/EEA, you have the following rights:

  • Access (Art. 15) — Request a copy of the data associated with your anonymous_id.
  • Rectification (Art. 16) — Request correction of inaccurate data.
  • Erasure (Art. 17) — Request deletion of all server-side data associated with your anonymous_id. The fastest way is the in-app "Delete my data" action in Settings → Research:
    1. Collection pauses immediately.
    2. A signed withdrawal request is sent to our server.
    3. All records linked to your anonymous_id in the Tier B Crowd Dataset are deleted within 30 days.
    4. You may continue using all app features, including the Basic study (Tier A), without anonymous_id linkage.
  • Restriction (Art. 18) — Request that we restrict processing while a dispute is being resolved.
  • Data portability (Art. 20) — Request your data in a structured, machine-readable format.
  • Objection (Art. 21) — Object to processing based on our legitimate interests.
  • Withdraw consent (Art. 7(3)) — Disable any opt-in toggle at any time in Settings.

Processing not requiring identification (GDPR Art. 11). Some data is anonymous by construction — primarily receipt-recognition feedback (section 3.3) and Crowd Dataset Tier A. Such records contain no identifier and cannot be matched to you. Under GDPR Article 11, where the controller is unable to identify the data subject, the rights of access, rectification, erasure, and portability (Art. 15–20) do not apply to that data, because we cannot locate "your" records among the anonymous ones. We are not required to, and will not, collect additional data solely in order to identify you. Control over such data is exercised before submission — through the opt-in toggles and the pre-send preview.

To exercise any right, contact privacy@odoma.ee. We respond within 30 days. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at aki.ee.

8. Children

Odoma Tracker is not directed at children under the age of 16. We do not knowingly collect data from anyone under 16. If you believe that a child has used the app and transmitted data to us, please contact us so that we can delete it.

9. Changes to this policy

We may update this Privacy Policy as the app evolves. Material changes will be communicated in the app release notes and on this page together with an updated effective date. Continued use of the app after a material change takes effect constitutes acceptance of the updated Privacy Policy.

Change log

  • 2026-09-04 (v1.7.0) — Added section 3.4 "Link to your employer — Odoma for companies": what goes to the employer's dashboard and when (only work trips and handed-over receipts, a simplified route line), who operates the dashboard, a link to its policy; the database region clarified (europe-west2, London) and the basis for the transfer.
  • 2026-08-22 (v1.6.0) — Android release. The policy now names both apps (iOS and Android) where it previously named only iOS. The Crowd Dataset field "iOS major version" is described as the operating-system major version (nothing changed on the wire — the app has always sent only the major version); the on-device identifier store is named per platform (Keychain on iOS, app-private storage on Android); App Attest is scoped to iOS, with the Android status stated plainly. No change to what is collected, why, or with whom it is shared.
  • 2026-05-16 (v1.4.0) — Added section 3.3 "Receipt-recognition feedback": anonymous by construction (server rejects known identifier fields), per-submission consent, pre-send preview, automatic text redaction (IBAN/isikukood/cards/names), App Attest, 12-month retention. Added corresponding lines to sections 2 and 5 and a GDPR Article 11 note (processing not requiring identification) to section 7. Defined "the app" as Odoma Tracker in section 1.
  • 2026-05-09 (v1.3.0) — Added Crowd Dataset (Research participation) section: Tier A (Basic study, fresh row_id per upload, no longitudinal linkage) and Tier B (Individual study, linked to device pseudonym). Added withdrawal mechanics (in-app "Delete my data" → server-side deletion within 30 days). Disclosed shared anonymous_id between leaderboard and Tier B. Disclosed future intent for insurance partnerships under separate opt-in.
  • 2026-04-30 (v1.2.0) — Initial public version.

Questions or requests: privacy@odoma.ee Odoma Tracker · Tallinn, Estonia · odoma.ee