Map Editor

FriendTrack Privacy Policy

Last updated: 30 August 2026

FriendTrack lets you share your live location with people you choose, for a duration you choose, on maps of the places you visit together. Privacy is the core of the product, so this policy is written to be read: it describes exactly what data FriendTrack handles, why, and what happens to it. What you agree to by using FriendTrack is a separate document, the Terms of Use, which should be read together with this policy.

Who is responsible

The data controller is TNS Holding ApS (CVR 26694264), Denmark. For anything in this policy β€” questions, requests, complaints β€” contact privacy@friendtrack.net.

What we collect and why

Phone number

You sign in with your phone number: we send you a one-time code by SMS and verify it. Your phone number is used to deliver that code and to derive your account identifier β€” a keyed cryptographic hash. The identifier cannot be reversed back into your phone number, and your phone number is not part of your profile; it is retained in your account's sign-in record until you delete your account. Group invitations addressed to your phone number are likewise stored only in hashed form.

Profile

Your name or display name, and an optional avatar image. These are shown to members of your Groups so they can recognise you.

Location

Your GPS position is the heart of the app, and it is handled narrowly:

  • You choose who sees it. Your position is shared only with the Groups you actively start sharing to. Nothing is shared by default.
  • Your app only sends it while you're sharing. Your app sends your position to FriendTrack only while you have an active sharing session; the moment sharing ends, your app stops sending it. While you are sharing, we hold your live position in memory to relay it to your Group members and to place you on your venue map β€” it is not recorded as tracks or routes (see below).
  • You choose for how long. Sharing is time-bound and stops automatically when the duration you picked runs out. You can stop it at any time.
  • No tracks, no routes. FriendTrack does not record tracks, routes, or movement history. Your live position is streamed to your Group members and held in memory; only your most recent shared position is retained as part of a Group's stored state, and it is removed when you leave the Group or the Group is deleted.

One detail about storage, so the promise above is exact. A Group's stored state lives in Microsoft Azure, and Azure keeps short-lived backup copies of it so that a bad write or a failed deployment can be undone. Each copy is a snapshot of the Group as it stood β€” including the last position each member had shared at that moment. Superseded copies are kept for about a day (the cleanup that removes them runs on its own daily schedule, so the exact hour varies), and anything we delete stays recoverable in backup form for up to 30 days before it is erased. Nothing in FriendTrack reads these copies: they exist for recovery only, they are never analysed, and they are never sold or shared.

Device and notifications

A push-notification token identifying your device, so Group members can reach you with notifications (for example a meeting-point announcement). Notifications are routed through Azure Notification Hubs and delivered by your platform's push service β€” Google Firebase Cloud Messaging on Android, Apple Push Notification service on iOS.

Crash diagnostics

If the app crashes, a crash report (stack trace, device model, OS version, app version, and which screen you were on) is sent to Sentry, stored in their EU (Frankfurt) region. It also carries a random identifier for your installation of the app, which is what lets us tell how many people a crash affected; that identifier is not linked to your account and we hold no way to trace it back to you. We have configured Sentry not to collect personal information, and crash data is retained for 30 days. A crash report carries neither your position, nor your phone number, nor the name of any Group you are in.

Service logs

Running the service produces server logs: a record of the requests our servers handled, so that we can operate FriendTrack, investigate faults, and protect it against abuse. A log line can carry your account identifier β€” the keyed hash described under Phone number, never your name β€” and where a phone number appears it is masked to its country code and last three digits (+45•••••064). Sign-in codes are never written to a log. Service logs never contain your position: no coordinates, no place names, and no record of which venue map you are on next to your identifier.

Logs are kept for 30 days and then deleted automatically. They are held in the same European Azure infrastructure as the rest of the service, and no one outside it receives them. They exist to keep the service running, not to describe you: nothing builds a profile from them, they carry no advertising identifier, and they are never used to decide anything about you.

Maps you upload

If you use the Map Editor, the venue images and map data you upload are stored with your account. Maps belong to you alone β€” they are not linked to Groups or to other users' data.

Subscription

If you subscribe to FriendTrack Pro, the purchase itself happens in Apple's App Store or Google Play: your payment details go to the store, never to us, and are handled under the store's own privacy policy. We store no prices and no receipts. What we keep is a small record of the subscription, so that your account gets what you paid for: which store it was bought in, the store's transaction identifier, the tier and billing period, when the current period ends, the subscription's status (including whether it auto-renews), and when we last checked it against the store. We verify and refresh that record with the store that sold the subscription β€” Apple's App Store Server API or the Google Play Developer API. The record is deleted with your account; the purchase itself lives with your store account, so you can restore it there.

What we never collect

  • No advertising identifiers, no trackers, no analytics profiles.
  • No contacts upload β€” invitations use codes you share yourself.
  • No location history β€” no tracks, no routes. See above for the short-lived backup copies of a Group's stored state.
  • We never sell data, and never share it with anyone beyond the processors listed below.

We never monetise your location

This is a permanent commitment, not a setting you can lose track of. FriendTrack does not sell, license, broker, or otherwise share your location β€” raw, aggregated, anonymised, or derived β€” with any third party, for any consideration, ever. That includes footfall or analytics products built on where people are. We do not use your location for advertising, and the app carries no advertising at all.

FriendTrack earns money only when you choose to pay for your own experience, through a FriendTrack subscription. That is the entire business model: there is no revenue line your location could serve, and no version of this product in which one appears. The commitment rests on that promise, not on an absence of data β€” where data about where you are does exist, such as the stored last position and the short-lived backup copies described above, it is used for the purpose you gave it and for nothing else.

Who processes data on our behalf

ProcessorPurposeWhere
Microsoft Azure Hosting and storage of all service data; service logs (Azure Monitor Log Analytics); push-notification routing (Azure Notification Hubs) European Union
Infobip Delivering sign-in SMS codes to your phone number EU-based; SMS delivery routes via networks in your country
Google (Firebase Cloud Messaging) Delivering push notifications to Android devices Global delivery network, under EU standard contractual clauses
Apple (Push Notification service) Delivering push notifications to iOS devices Global delivery network, under EU standard contractual clauses
Apple (App Store Server API) Verifying FriendTrack Pro subscriptions bought through the App Store: we send the store's transaction identifier to check the subscription's current status Apple's global infrastructure
Google (Google Play Developer API) Verifying FriendTrack Pro subscriptions bought through Google Play: we send the store's transaction identifier to check the subscription's current status Google's global infrastructure
Sentry Crash reporting EU (Frankfurt); data processing agreement in place

All service data is stored within the European Union. Where a processor's delivery network operates outside the EU (SMS and push delivery), transfers are covered by the processor's EU standard contractual clauses.

Legal basis (GDPR)

  • Performance of contract β€” account, profile, Groups, location sharing, and your FriendTrack Pro subscription record exist to provide the service you signed up for.
  • Consent β€” location access is granted by you through your device's permission system and can be withdrawn there at any time; sharing to a Group is always your explicit action.
  • Legitimate interest β€” crash diagnostics and service logs, to keep the app working, to investigate faults, and to protect the service against abuse. You have the right to object to processing on this basis at any time; see Your rights below.

Retention

Your account data β€” including any FriendTrack Pro subscription record β€” is kept until you delete your account. Sign-in codes expire within minutes. Crash reports and service logs are deleted after 30 days. A Group's data (its name, members, and meeting point) is deleted when its last member leaves. Beyond those, Azure holds short-lived backup copies: about a day for superseded Group state, and up to 30 days for data that has been deleted (see Location, above).

Deleting your account

You can delete your account directly in the app, which removes your profile, group memberships, device tokens, and maps. That takes effect immediately in the app; for up to 30 days afterwards the deleted data remains recoverable in Azure's backups, which no part of FriendTrack can read, before it is erased for good. Service logs are the one part deletion does not reach: a log line already written keeps your account identifier until it ages out on its own 30-day schedule. Nothing re-creates it, and once those 30 days have passed no log line refers to you at all. You can also exercise this or any other right by writing to privacy@friendtrack.net.

Your rights

Under the GDPR you can request access to your data, correction, deletion, restriction of processing, data portability, or object to processing β€” contact privacy@friendtrack.net. You can also lodge a complaint with the Danish Data Protection Agency (Datatilsynet) or your local supervisory authority.

Children

FriendTrack is not directed at children under 13, and we do not knowingly collect data from them.

Changes

If this policy changes, the new version is published at this address with an updated date above. That date is how you can tell a revision has happened, so check back here for the current version.

An unhandled error has occurred. Reload πŸ—™

Reconnecting…

The connection to FriendTrack dropped. Trying to pick up where you left off.

Couldn't reach FriendTrack. Reload to start a new session.