Privacy Policy
Last updated: May 22, 2026 Effective date: [DATE OF FIRST PUBLICATION]
1. Who We Are
This Privacy Policy explains how we collect, use, and protect information when you use the Waitlot IQ mobile application (the "App").
The App is operated by Robert Ellis, an individual operating from Raleigh, North Carolina, United States ("we", "us", or "Operator"). For privacy purposes, we are the data controller of the personal information we collect through the App.
You can reach us at legal@waitlotiq.com.
The App is designed for adult rideshare drivers operating in the United States. We are not currently active in the European Union, the United Kingdom, or other regions outside the United States, but where applicable law from those jurisdictions reaches you, this Policy describes the rights it gives you.
2. What Information We Collect
We collect only what we need to run the App. Each category below is paired with what we collect, why, and whether it's linked to your identity.
2.1 Account information
- Email address — required for account creation and sign-in.
- Password — stored only as a salted hash by our authentication provider; we never see your password in readable form.
- Apple Sign-In identifier — if you choose Sign in with Apple, we receive a stable identifier and (with your permission) your email; we do not receive your Apple ID or device PIN.
Linked to your identity: yes. Why: to let you sign in, restore your data across devices, and contact you about your account.
2.2 Driver profile
- First name (required) — used to greet you in the App and identify your account when you contact support.
Optional fields. Each is volunteered by you and can be left blank or removed at any time from the Profile tab. We collect each only for the specific purpose listed:
| Field | What we use it for |
|---|---|
| Nickname | A friendlier display name in the App, shown only to you. |
| License plate | Helps you remember which vehicle you're tracking, especially if you switch between cars; reserved for future driver-identification features (e.g. roadside assistance, dispute resolution). We do not display your plate to other drivers and do not share it with any rideshare platform, the airport, or any third party. |
| Vehicle make, model, and color | Same purpose as license plate — your own reference, plus future features that may benefit from knowing vehicle type. Not displayed to other drivers. |
| Rideshare platforms you drive for (e.g. Uber, Lyft) | Filters the App's UI to platforms relevant to you (e.g. tier breakdowns, service-level standings). |
| Service tiers you offer (e.g. UberX, Comfort, Premier) | Determines which per-tier "you're Nth of M by check-in" standings the App computes for you. Aggregate counts per tier are visible to other drivers at the same airport in anonymized form (see §3.2); your specific tier list is not. |
Linked to your identity: yes. Why (overall): to personalize the App and to compute which service-level rankings to show you.
2.3 Location data
The App requires access to your device's GPS location, including in the background. This is the most sensitive category we handle and we limit it deliberately.
- We use location to detect when you cross the boundary of a participating airport staging lot (entry and exit).
- We store the timestamp and the airport identifier for each entry and exit. We do not store a continuous trail of your coordinates, your route, your destination, your trips outside of staging lots, or your home or work location.
- A current GPS fix is held briefly in memory while you are checked into a lot, to detect polygon-exit, and is not persisted.
Linked to your identity: yes (your lot sessions are linked to your account). Why: to detect lot entry and exit automatically without requiring you to tap a button, and to make sure check-ins are geographically plausible.
2.4 Session and trip data
For each session (each time you are in a lot), we store:
- The airport.
- Check-in and check-out timestamps and derived wait duration.
- Whether you marked the session as ending with a successful ride (and if so, the rideshare platform and tier you classified it as — these are your entries, not data we receive from any rideshare company).
- If you marked the session as ending without a ride, the reason you selected (e.g. "too long a wait," "called off the lot").
- Whether the check-in was GPS-verified or manually forced.
- Optional metadata you provide: surge multiplier, terminal, whether the ride was reserved or shared.
Linked to your identity: yes for raw session rows, scoped to your account by our Row-Level Security policy. Used in anonymized aggregate form for other features (see Section 3.2).
2.5 Device and technical information
- Operating system version and device model (to provide compatibility, e.g. iOS 17 vs 18).
- App version (to debug issues reported by users).
- Authentication tokens and session identifiers (necessary for security and to keep you signed in).
- iOS push notification token, if and when you grant notification permission. We do not currently send push notifications; this token would be retained for future operational alerts and is not used today.
Linked to your identity: yes. Why: technical operation, debugging, account security.
2.6 What we DO NOT collect
We want to be explicit about what's not in the list above:
- We do not use third-party analytics of any kind (no Firebase Analytics, no Mixpanel, no Sentry, no Segment, no advertising SDKs).
- We do not use advertising identifiers (IDFA) and do not show ads.
- We do not collect contact lists, photos, microphone audio, camera input, calendar data, or health data.
- We do not collect biometric data, facial recognition data, or device-level keychain entries (beyond authentication tokens).
- We do not collect routes, destinations, or trip-level location data. Location is sampled only at lot boundaries.
- We do not buy data about you from any third party.
If you have Apple's standard App Analytics enabled in your iOS Settings → Privacy → Analytics & Improvements, Apple may share aggregated app usage data with us in App Store Connect. That data is controlled by Apple, anonymized by Apple, and never linked to your account by us.
3. How We Use Your Information
3.1 To operate the App for you
- Sign you in and keep you signed in.
- Detect when you enter and leave a staging lot, and create / close session records.
- Show you your own session history, your trip classifications, and your stats.
- Send you local on-device notifications (e.g. "did you leave the lot with a ride?") — these are generated on your device, not sent from us.
- Personalize the dashboard, the map, and the Insights tab based on your selected airports, platforms, and service tiers.
3.2 To run shared, anonymized features
These are the features where Waitlot IQ becomes more useful than a personal logbook: live occupancy counts, "your standing" by check-in time, hour-of-day patterns, and across-airport comparisons.
For these, your active session contributes anonymously to aggregate counts shown to other drivers in the same lot. Specifically:
- Your active session is counted in the lot's total occupancy number.
- Your active session is counted in the per-service-level totals (for each tier you selected at onboarding).
- Other drivers can see their own check-in rank among drivers in their tier — but never your name, license plate, vehicle, or any other identifier.
We expose these aggregates via server-side functions that return only counts and the calling driver's own rank — never another driver's identity, time, or data. This is enforced by Row-Level Security policies on our database that prevent any client from reading another driver's session rows directly.
3.3 To debug and improve the App
If you report a bug, we may use your account information to reproduce the problem. We do not access driver data for any other reason.
3.4 To meet legal obligations
We may use or disclose information when we believe in good faith that doing so is necessary to comply with applicable law, respond to a subpoena, protect against fraud or abuse, or defend our legal rights.
4. Legal Bases for Processing (for users to whom GDPR applies)
For users whose data is protected by the EU GDPR or UK GDPR (which generally is not our user base, but to whom the laws may extend), the legal bases on which we process your data are:
| Processing activity | Legal basis |
|---|---|
| Account creation, authentication, providing the App | Contract (Art. 6(1)(b)) — necessary to perform the contract you accepted when agreeing to the Terms of Service. |
| Lot entry/exit detection, session storage, dashboards | Contract — these are the core App features you signed up for. |
| Optional profile fields (vehicle, plate, nickname) | Consent (Art. 6(1)(a)) — you choose whether to enter these. |
| Security, anti-abuse, fraud prevention | Legitimate interest (Art. 6(1)(f)). |
| Responding to legal requests | Legal obligation (Art. 6(1)(c)). |
You may withdraw consent for optional fields at any time by deleting them in the App or contacting us.
5. Who We Share Information With
We do not sell, rent, or share your personal information with third parties for their own purposes, including for their own marketing or advertising. We do not have any data-monetization business.
We do use the following infrastructure providers as processors acting on our behalf. They handle data only to provide their service to us:
| Provider | What they do for us | Where they process data |
|---|---|---|
| Supabase Inc. | Authentication, database (PostgreSQL), and real-time messaging. All of your account, profile, and session data is stored on Supabase infrastructure. | United States. |
| Apple Inc. | App distribution (App Store), device-level authentication (Sign in with Apple, if used), and Apple Push Notification service (when we later send notifications). | Global, per Apple's terms. |
Each of these is a major infrastructure provider with its own privacy commitments. They process data under our instructions; they do not use it for their own purposes.
We may also disclose information if legally required — for example, in response to a valid subpoena, court order, or government request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
If we are ever involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We would notify you (by email and/or in-App) before your data became subject to a different privacy policy.
6. Location Data — Additional Detail
Because location is the most sensitive category we collect, we want to be extra-clear:
- Permission grants are managed by iOS. You can grant location permission at "While Using," "Always," or deny it. You can revoke it at any time in iOS Settings → Privacy & Security → Location Services → Waitlot IQ.
- "Always" permission is required for background detection. If you grant only "While Using," automatic lot entry/exit detection while the App is closed will not work; you can still use the App actively.
- iOS shows a small location-services indicator in the status bar when the App is using location. You can see in real time when it's active.
- We sample your location only at lot boundaries. When you are nowhere near a participating airport, the App does not log your position. We do not track your movement between airports, or your time off-duty.
- We do not sell location data to anyone, ever. No data brokers, no advertising networks, no insurance companies, no rideshare platforms.
7. International Data Transfers
Our infrastructure (Supabase) is located in the United States. If you access the App from outside the United States, your data is transferred to and processed in the United States, which may have data-protection rules different from those of your country.
If you are an EU, UK, or Swiss user, transfers to the United States are made under the European Commission's Standard Contractual Clauses (SCCs) or an equivalent legal mechanism, as part of our infrastructure provider's compliance program.
8. How Long We Keep Your Data
| Data | Retention |
|---|---|
| Active account, profile, and session history | While your account is open. |
| Deleted account — profile and identifiable data | Removed within 30 days of deletion. |
| Anonymized aggregate data (occupancy snapshots, hourly patterns) derived from your activity | Retained indefinitely. By design this data cannot be tied back to you after deletion. |
| Backups | Up to 90 days from the point of capture, then cycled out. |
| Records required by law (e.g. fraud investigations, tax records) | As long as legally required, then deleted. |
If you'd like an explicit confirmation that your data has been deleted, email us and we'll respond.
9. Your Rights
You have rights over the data we hold about you. These vary by jurisdiction, but we offer the following to everyone:
Everyone
- Access — see what data we have on you. Most of it is visible in the App's Profile tab; for the rest, email us.
- Correction — fix anything wrong. Most fields are editable in-App; for the rest, email us.
- Deletion — we provide in-App account deletion in your Profile tab. This removes your profile and identifiable session data per Section 8. Aggregate, anonymized statistics derived from your past sessions are retained.
- Portability — receive a copy of your data in a structured, machine-readable format (we'll provide JSON on request).
- Objection / withdrawal of consent — you can stop using the App at any time, or revoke specific permissions (location, notifications) at the iOS level.
To exercise any of these rights, email legal@waitlotiq.com. We respond within 30 days.
California residents (CCPA / CPRA)
If you are a California resident, you have, in addition:
- The right to know what personal information we collect, use, disclose, and (if applicable) sell or share. We do not sell or share personal information as those terms are defined under CCPA/CPRA.
- The right to delete personal information we have collected from you.
- The right to correct inaccurate personal information.
- The right to limit use of sensitive personal information.
- The right to non-discrimination for exercising your rights — we will not deny service, charge a different price, or provide a different level of service because you exercised your privacy rights.
- The right to designate an authorized agent to make requests on your behalf.
To exercise these rights, email legal@waitlotiq.com with "California Privacy Request" in the subject line. We may need to verify your identity (typically by confirming you can sign in to the email associated with your account).
EU / UK residents (GDPR)
If GDPR or UK GDPR applies to you, in addition to the above you have:
- The right to lodge a complaint with your local data protection supervisory authority if you believe we have not handled your data lawfully.
- The right to restrict processing in certain circumstances.
- The right not to be subject to a decision based solely on automated processing that has legal or similarly significant effects on you. We do not engage in any such automated decision-making.
Because we do not actively serve the EU/UK and have no establishment there, we have not appointed an EU/UK representative. If our user base expands, we will update this Policy and appoint one.
Other US states
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Jersey, New Hampshire, Minnesota, and Maryland (among others) have rights similar to those of California residents under their respective state privacy laws. We honor those rights in the same way — email legal@waitlotiq.com and we will respond per the applicable law.
10. Children
The App is intended for adult rideshare drivers and is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18, and specifically do not collect information from anyone under 13 in compliance with the Children's Online Privacy Protection Act (COPPA).
If you believe a child under 18 has provided us with personal information, please email legal@waitlotiq.com and we will delete it.
11. How We Protect Your Data
We take security seriously, but we want to be honest about what's achievable:
- All network traffic between the App and our backend uses TLS (HTTPS / WSS).
- Passwords are stored only as salted hashes by our authentication provider; we cannot read them.
- Database access is gated by Row-Level Security policies: even with a valid auth token, your session can only read its own driver's rows. Aggregate features are exposed via server-side functions that return counts but never identities.
- Authentication tokens are stored in the iOS Keychain on your device.
- We follow standard practice for backups and access control on our infrastructure.
No system is perfectly secure. If we ever become aware of a data breach affecting your personal information, we will notify you and any required regulators in accordance with applicable law, generally within 72 hours of discovery for EU/UK users (per GDPR Article 33) and per state-specific timelines for US users.
12. Push Notifications
We do not currently send remote push notifications. The App may register for Apple's Push Notification service to retain the option to send operational alerts in the future (e.g. "lot occupancy spiked at your usual airport"). When and if we begin sending such notifications, you'll receive an iOS-level permission prompt before any are delivered, and you can disable them at any time in iOS Settings.
The App does generate local on-device notifications — for example, when it detects you've left a staging lot and prompts you to classify the trip. These are generated by the App on your device and are not sent from our servers; we do not see them.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top, and for material changes we will notify you in-App, by email, or both, before the changes take effect.
Your continued use of the App after the effective date of a revised Policy constitutes acceptance of the revised Policy. If you do not accept the revised Policy, you must stop using the App and may delete your account.
We will keep prior versions of this Policy available on request so you can see what changed.
14. Apple App Privacy ("Nutrition Label") Mapping
For consistency with what's shown on the App Store listing, the following is how this Policy maps to Apple's App Privacy questions:
| Apple category | Collected? | Linked to identity? | Used for tracking? | Notes |
|---|---|---|---|---|
| Contact Info — Email | Yes | Yes | No | Account creation. |
| Contact Info — Name | Yes (first name) | Yes | No | Profile. |
| Contact Info — Phone, Address | No | — | — | — |
| Identifiers — User ID | Yes | Yes | No | Account UUID. |
| Identifiers — Device ID, IDFA | No | — | — | We do not use IDFA. |
| Location — Precise Location | Yes | Yes | No | At lot boundaries only; not continuous. |
| Location — Coarse Location | No | — | — | We use precise location at lot boundaries; we do not collect coarse location separately. |
| User Content | Yes (driver-entered trip classifications, vehicle info) | Yes | No | — |
| Usage Data | No | — | — | No third-party analytics. |
| Diagnostics | No | — | — | We do not collect crash logs ourselves. Apple's standard system crash reporting may still apply per Apple's terms. |
| Financial Info, Health & Fitness, Sensitive Info, Contacts, Browsing History, Search History, Other | No | — | — | — |
"Used for tracking" in Apple's sense means linking data with third-party data for advertising or sharing with data brokers. We do not do this for any category.
15. Contact
For any privacy question, request, or complaint:
Robert Ellis
Raleigh, North Carolina, United States
Email: legal@waitlotiq.com