LEGAL
Privacy Policy
Last updated September 12, 2026
State-Specific Privacy & Compliance Addendum
1. Who we are
Macke's Software LLC operates RETUOR ("we," "us," or "our"). This policy covers information processed through the RETUOR app, website, accounts, memberships, and support. Contact admin@mackessoftware.com with privacy questions or requests. Our Terms of Use (EULA) separately describe the terms for using RETUOR.
2. Information we collect and how we collect it
Account and profile information. When you register, sign in, or edit your profile, we process your name, username, email, authentication credentials and session tokens, profile and cover photos, biography, home city or state, preferences, and contact details you provide. If you choose Sign in with Apple or Google, we receive the account identifier, authentication information, and name, email (including an Apple private relay address), or profile information supplied by the provider with your authorization. We do not receive your Apple or Google password.
Content and activity. We collect information you enter, upload, send, or generate through features: rides, routes and GPS tracks, stops, events, club memberships, posts, comments, ratings, messages, photos, marketplace listings, passenger-matching preferences, invitations, follows, favorites, game participation, achievements, points, and ride completion distances and times. Garage information includes bike details, mileage, fuel and maintenance records, and insurance or registration documents you choose to upload. We receive support correspondence, abuse reports, and voluntary tester survey responses.
Emergency contacts. If you add emergency contacts, we store the names, relationships, phone numbers, email addresses, and visibility choices you provide. Obtain permission before providing another person's information.
Location and movement. With device permission, we receive precise or approximate location and, where available, GPS timestamps, accuracy, speed, and direction for maps, nearby discovery, weather, navigation, route recording, ride progress, and location sharing. We also process locations you enter manually, search for, or include in routes or content. Saved location data can remain after a live location session ends.
Purchases. Apple processes App Store payments and Stripe processes website payments. We receive account-linked customer, transaction, product, and subscription identifiers, payment status, billing periods, and cancellation or renewal information to verify and manage membership. Website checkout may share your email and RETUOR account identifier with Stripe. We do not store full payment card numbers or card security codes.
Device and service information. Our services and providers process connection information such as IP address, request details, device or browser information, timestamps, errors, and performance records when you connect. Where push notifications are supported and enabled, we store a device notification token, platform, account association, and notification preferences. These records help deliver the service, troubleshoot problems, and protect accounts.
3. How we use information
We use this information to create and authenticate accounts; display profiles and content; provide maps, routing, weather, garage, rides, events, clubs, messaging, games, and community features; deliver notifications you select; calculate ride statistics and achievements; process and restore membership access; answer support requests; and evaluate feedback and improve functionality and reliability. We also use relevant records to investigate abuse, enforce our terms, prevent fraud, resolve disputes, and comply with legal obligations. Optional information is used for the feature for which it is provided. We do not use private documents or emergency contacts for advertising.
4. Device permissions and background location
Location-based features use device location when you grant access. If you choose Continue in Background while recording a dynamic route, RETUOR can continue collecting location in the background for that recording session, for up to one hour. Live sharing can disclose your position to the audience of the sharing feature you enable. Stop recording or sharing in the app, or revoke location permission in device settings, to stop that collection. Revoking permission does not automatically delete previously saved tracks or shared content.
Camera and photo access lets you take or select images to upload. Document access lets you choose files for supported imports or garage records. We receive the files you submit; granting permission alone does not upload your entire library. Calendar access is used when you choose to add a ride or event to your device calendar; RETUOR does not upload your calendar's other entries. You can deny or revoke permissions in iOS or Android settings. Features that depend on a permission may then be unavailable; unrelated features remain usable.
5. Sharing with other users
Profiles, posts, routes, ride participation, rankings, and other content are visible according to the feature's audience and available privacy settings. Public content can be viewed or copied by others. Messages are available to recipients, and club or ride content is available to eligible members. Ride hosts can receive emergency contact or contact information under the applicable sharing settings. Emergency contacts may also be visible publicly or to eligible friends when you select those options. Review those settings before providing sensitive information.
Authorized service personnel may access information to operate the service, investigate reports, or provide support. Messages are not represented as end-to-end encrypted. Other users may keep copies of information you shared with them, even after you remove it from RETUOR.
6. Service providers and other disclosures
We share information needed to perform a service with providers supporting RETUOR. Supabase provides authentication, database, and file storage. Apple and Google support their respective sign-in and device services. Apple and Stripe process purchases. Google Firebase Cloud Messaging delivers supported push notifications using device tokens and notification content. Hosting, email, and support services process the connection records and communications needed to operate those services.
Mapping, place search, geocoding, routing, and weather features can send coordinates, search text, map areas, or route waypoints to Apple Maps, Google Maps/Places/Routes, OpenStreetMap services (including Nominatim and Overpass), the OSRM routing service, and Open-Meteo, depending on the feature and service availability. Vehicle lookup uses the U.S. National Highway Traffic Safety Administration's vehicle information service. Providers receiving requests directly from your device also receive its connection information. Opening an external navigation app passes the destination or route you choose to that app.
Protection by third parties. We require third parties to whom we disclose user data, including service providers and any affiliated entities receiving it, to provide the same or an equal level of protection as described in this policy and required by Apple's App Review Guidelines. Providers acting on our behalf must limit processing to the authorized service, protect the information, and comply with applicable privacy obligations. Their own privacy notices also explain their handling of information when you use their services directly.
We may disclose relevant information when required by law or valid legal process, to investigate fraud or abuse, or to protect people's rights and safety. If RETUOR undergoes a sale or reorganization, information may transfer with the service subject to the protections in this policy and applicable notice requirements.
7. Advertising, tracking, and local storage
RETUOR does not sell personal information or share it for cross-app behavioral advertising. We do not use advertising identifiers to track you across other companies' apps or websites. The app stores session information, preferences, cached content, and downloaded routes on your device. Website features and sign-in or payment providers may use browser storage or cookies for authentication, security, and checkout. Clearing local storage can remove settings or sign you out; it does not delete server-side records.
8. Retention and account deletion
Account and feature records are generally retained while your account is active so that saved content, history, and memberships remain available. Retention depends on the record's purpose, whether you remove it, and any unresolved support, security, transaction, or legal need. We retain transaction and related compliance records as needed for accounting, refunds, disputes, fraud prevention, and legal duties. Backup and provider records may remain until their applicable retention cycles expire. We do not promise immediate erasure from every backup or from a payment provider's legally required records.
Start account deletion in RETUOR's Settings and follow the secure confirmation flow on our deletion page. The current process disables account access and schedules finalization after a 90-day restoration period. Signing in again during that period restores the account and cancels scheduled deletion. After that period, the deletion process removes sign-in access and replaces or clears the main profile's identifying fields. The account cannot then be restored through sign-in.
Related records are not all automatically erased by that process. Uploaded files, messages, posts, ride and garage records, emergency contacts, and other linked records may remain. You can remove content through available controls before requesting account deletion. To request deletion of remaining personal data or ask about an earlier deletion, email admin@mackessoftware.com. We will assess the request, verify your authority, and explain any retention required by law or other applicable limitation.
Account deletion and app removal do not cancel App Store subscriptions. Manage those separately in Apple's subscription settings. The website deletion flow cancels eligible RETUOR Premium subscriptions billed through Stripe.
9. Your choices and privacy requests
Edit your profile and emergency contacts, adjust audience and sharing settings, stop live location sharing, and manage notification preferences in the app. Revoke location, camera, photos, calendar, and notification permissions in device settings. You can also revoke RETUOR's sign-in authorization through your Apple or Google account; doing so may prevent that sign-in method from working and does not itself delete your RETUOR account or past data.
Email admin@mackessoftware.com to request access, correction, a copy, or deletion of personal data, withdraw consent, or object to or request limits on processing where applicable law provides those rights. Identify your RETUOR account and request; do not send your password or payment card details. We may verify identity or authority before releasing or changing data. We respond within applicable legal time limits and explain any exception. Withdrawing consent stops the relevant future processing but does not undo prior lawful processing. You may also raise a concern with your local data protection authority.
10. Security and processing locations
We use HTTPS for production service connections and account and access controls to help protect information. No storage or transmission method can guarantee absolute security. Protect your device and credentials, and report suspected unauthorized access to our support address. RETUOR and its providers may process data in the United States and other countries where they operate. Applicable privacy and international-transfer requirements continue to apply to that processing.
11. Children's privacy
RETUOR is intended for riders and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can investigate and address its deletion. Users must also meet the age and consent requirements applicable where they live.
12. Policy changes and contact
We publish changes on this page and update the date above. For material changes, we will provide additional notice and obtain consent where required before using information for a new purpose. Privacy questions and requests should be sent to Macke's Software LLC at admin@mackessoftware.com.
RETUOR PRIVACY POLICY: STATE-SPECIFIC PRIVACY & COMPLIANCE ADDENDUM
Effective Date: August 5, 2026
Last Updated: September 12, 2026
This State-Specific Privacy & Compliance Addendum supplements the RETUOR Privacy Policy and applies to users residing in Texas, California, Massachusetts, Washington, Illinois, and other jurisdictions with enhanced consumer privacy frameworks.
1. Notice at Collection and Data Retention (California CCPA/CPRA)
Prior to or at the point of collection, RETUOR provides notice of the categories of personal information collected, the business/commercial purpose for collection, and the applicable retention schedule.
| Category of Personal Information Collected | Source & Business Purpose | Retention Period |
|---|---|---|
| Identifiers & Contact Info (Name, email, handle, phone number) | Account registration, authentication, user communication, and safety enforcement. | Retained for active account duration plus 24 months post-account deletion for legal compliance. |
| Precise Geolocation Data (GPS coordinates within 1,750 feet) | Real-time map navigation, route tracking, safety features, ride history, and “Backpackers” passenger matching. | Processed continuously while feature is active; raw location logs stored for 90 days, then anonymized/aggregated. |
| Biometric Information (Facial geometry scans for account/driver verification) | User identity verification, safety checks for “Backpackers” feature, fraud prevention. | Retained until verification is complete or a maximum of 3 years from last user interaction, whichever is sooner. |
| Gamification & Activity Data (Rides logged, points, achievements, leaderboards) | App engagement, feature functionality, challenges, community leaderboards, and promotional rewards. | Retained for the life of the account unless user requests deletion or opts out of gamification rewards. |
| Commercial & Purchase Data (Subscription history, app store transactions) | Payment processing, subscription management, and audit records. | Retained for 7 years to satisfy federal and state tax and financial auditing mandates. |
2. Sensitive Personal Data Disclosures & Opt-In (Texas TDPSA & California CPRA)
Under Texas (TDPSA) and California (CCPA/CPRA) law, Precise Geolocation Data and Biometric Information are classified as Sensitive Personal Data.
Mandatory Statutory Notices
- NOTICE: We may sell or share your sensitive personal data.
- NOTICE: We may sell or share your biometric personal data.
Separate Opt-In Requirement
In compliance with Tex. Bus. & Com. Code Ch. 541, acceptance of RETUOR’s general Terms of Service or Privacy Policy DOES NOT constitute consent to collect or process Sensitive Personal Data.
- Precise Geolocation tracking requires an explicit, separate in-app opt-in prompt prior to initial activation.
- Users may revoke geolocation consent or exercise their statutory right to restrict sensitive data processing at any time via the in-app settings menu using the “Limit the Use of My Sensitive Personal Information” toggle.
3. Minors & Youth Privacy Protections (Texas SCOPE Act & Federal COPPA)
In compliance with the Texas Securing Children Online through Parental Empowerment (SCOPE) Act (Tex. Bus. & Com. Code Ch. 509):
- Mandatory Age Verification: All users must register and verify their age upon account creation. Age modification is restricted post-registration.
-
Prohibition on Minor Tracking: If an account holder
is identified as a minor (under 18 years of age), RETUOR
automatically:
- Disables all precise geolocation tracking, location sharing, and map-pin broadcasting features.
- Blocks the user from opting into the “Backpackers” passenger-matching feature.
- Excludes the user from targeted advertising and data transfer/sale programs.
- Verifiable Parental Consent: Users under the age of 13 are prohibited from using the Service without verifiable parental consent under COPPA.
4. Biometric Data Retention & Destruction Policy (Illinois BIPA)
If RETUOR utilizes facial recognition or biometric verification software (e.g., for user profile validation or “Backpackers” driver verification), collection is subject to the Illinois Biometric Information Privacy Act (740 ILCS 14/):
- Written Consent: RETUOR will not capture, collect, or store biometric identifiers or biometric information without first obtaining express, signed written consent from the user.
- Purpose & Duration: Biometric data is collected solely for identity verification and platform safety.
-
Destruction Schedule: RETUOR will permanently
destroy a user’s biometric identifiers and information upon the
earliest occurrence of:
- The date the initial purpose for collecting the biometric data has been satisfied;
- Account termination or deletion request by the user; or
- Three (3) years from the user’s last intentional interaction with the Service.
5. Healthcare Geofencing & Location Safeguards (Washington MHMDA)
In accordance with Washington’s My Health My Data Act (MHMDA) and state health privacy standards:
- Geofence Restrictions: RETUOR strictly prohibits the implementation of virtual perimeters (geofences) within 1,750 feet of any healthcare facility, medical clinic, hospital, reproductive health center, or mental health facility for the purpose of tracking, identifying, profiling, or collecting data from consumers.
- Location Processing Limitations: Location data gathered during navigation near healthcare facilities is used strictly for real-time routing and is neither logged for health-profiling purposes nor shared with third-party data brokers.
6. Gamification & Financial Incentive Notice (California CCPA/CPRA)
RETUOR offers points, badges, leaderboards, challenges, and virtual achievements (“Gamification Features”) to reward user participation and safety logging.
- Value Disclosure: The collection of user activity and route data via Gamification Features enhances RETUOR’s product quality and user engagement. While points have no direct cash value, RETUOR calculates the underlying data value using the operational expenses associated with maintaining the feature.
- Opt-Out Right: Participation in Gamification Features is voluntary. Users may decline participation or withdraw from public leaderboards at any time in the app settings without impacting their access to core navigation or basic service functionality.
7. Data Security & Technical Safeguards (Massachusetts 201 CMR 17.00)
To protect user personal data in compliance with Massachusetts Standards for the Protection of Personal Information:
- Written Information Security Program (WISP): RETUOR maintains a comprehensive administrative, technical, and physical security framework.
- Encryption Standards: RETUOR encrypts all user credentials, personal identifiers, sensitive location records, and financial details both in transit (using TLS 1.3 encryption) and at rest (using AES-256 bit encryption).
- Access Controls: Technical access to personal data is restricted to authorized personnel operating with unique credentials and multi-factor authentication under strict confidentiality obligations.
8. Consumer Privacy Rights & Request Mechanisms
Residents of covered states possess specific statutory privacy rights regarding their personal data:
- Right to Know / Access: Confirm whether RETUOR processes your data and obtain a portable copy of personal information.
- Right to Delete: Request deletion of personal information collected from or about you, subject to statutory legal retention exemptions.
- Right to Correct: Request correction of inaccurate or out-of-date personal information.
- Right to Opt-Out of Sale / Sharing / Targeted Advertising: Direct RETUOR to stop selling or sharing your personal data with third parties for cross-context behavioral advertising.
- Right to Non-Discrimination: Exercise any of these privacy rights without receiving degraded service levels, discriminatory pricing, or denied service access.