Privacy Policy

Last updated: May 22, 2026 Effective date: [DATE OF FIRST PUBLICATION]


1. Who We Are

This Privacy Policy explains how we collect, use, and protect information when you use the Waitlot IQ mobile application (the "App").

The App is operated by Robert Ellis, an individual operating from Raleigh, North Carolina, United States ("we", "us", or "Operator"). For privacy purposes, we are the data controller of the personal information we collect through the App.

You can reach us at legal@waitlotiq.com.

The App is designed for adult rideshare drivers operating in the United States. We are not currently active in the European Union, the United Kingdom, or other regions outside the United States, but where applicable law from those jurisdictions reaches you, this Policy describes the rights it gives you.


2. What Information We Collect

We collect only what we need to run the App. Each category below is paired with what we collect, why, and whether it's linked to your identity.

2.1 Account information

Linked to your identity: yes. Why: to let you sign in, restore your data across devices, and contact you about your account.

2.2 Driver profile

Optional fields. Each is volunteered by you and can be left blank or removed at any time from the Profile tab. We collect each only for the specific purpose listed:

Field What we use it for
Nickname A friendlier display name in the App, shown only to you.
License plate Helps you remember which vehicle you're tracking, especially if you switch between cars; reserved for future driver-identification features (e.g. roadside assistance, dispute resolution). We do not display your plate to other drivers and do not share it with any rideshare platform, the airport, or any third party.
Vehicle make, model, and color Same purpose as license plate — your own reference, plus future features that may benefit from knowing vehicle type. Not displayed to other drivers.
Rideshare platforms you drive for (e.g. Uber, Lyft) Filters the App's UI to platforms relevant to you (e.g. tier breakdowns, service-level standings).
Service tiers you offer (e.g. UberX, Comfort, Premier) Determines which per-tier "you're Nth of M by check-in" standings the App computes for you. Aggregate counts per tier are visible to other drivers at the same airport in anonymized form (see §3.2); your specific tier list is not.

Linked to your identity: yes. Why (overall): to personalize the App and to compute which service-level rankings to show you.

2.3 Location data

The App requires access to your device's GPS location, including in the background. This is the most sensitive category we handle and we limit it deliberately.

Linked to your identity: yes (your lot sessions are linked to your account). Why: to detect lot entry and exit automatically without requiring you to tap a button, and to make sure check-ins are geographically plausible.

2.4 Session and trip data

For each session (each time you are in a lot), we store:

Linked to your identity: yes for raw session rows, scoped to your account by our Row-Level Security policy. Used in anonymized aggregate form for other features (see Section 3.2).

2.5 Device and technical information

Linked to your identity: yes. Why: technical operation, debugging, account security.

2.6 What we DO NOT collect

We want to be explicit about what's not in the list above:

If you have Apple's standard App Analytics enabled in your iOS Settings → Privacy → Analytics & Improvements, Apple may share aggregated app usage data with us in App Store Connect. That data is controlled by Apple, anonymized by Apple, and never linked to your account by us.


3. How We Use Your Information

3.1 To operate the App for you

3.2 To run shared, anonymized features

These are the features where Waitlot IQ becomes more useful than a personal logbook: live occupancy counts, "your standing" by check-in time, hour-of-day patterns, and across-airport comparisons.

For these, your active session contributes anonymously to aggregate counts shown to other drivers in the same lot. Specifically:

We expose these aggregates via server-side functions that return only counts and the calling driver's own rank — never another driver's identity, time, or data. This is enforced by Row-Level Security policies on our database that prevent any client from reading another driver's session rows directly.

3.3 To debug and improve the App

If you report a bug, we may use your account information to reproduce the problem. We do not access driver data for any other reason.

3.4 To meet legal obligations

We may use or disclose information when we believe in good faith that doing so is necessary to comply with applicable law, respond to a subpoena, protect against fraud or abuse, or defend our legal rights.


4. Legal Bases for Processing (for users to whom GDPR applies)

For users whose data is protected by the EU GDPR or UK GDPR (which generally is not our user base, but to whom the laws may extend), the legal bases on which we process your data are:

Processing activity Legal basis
Account creation, authentication, providing the App Contract (Art. 6(1)(b)) — necessary to perform the contract you accepted when agreeing to the Terms of Service.
Lot entry/exit detection, session storage, dashboards Contract — these are the core App features you signed up for.
Optional profile fields (vehicle, plate, nickname) Consent (Art. 6(1)(a)) — you choose whether to enter these.
Security, anti-abuse, fraud prevention Legitimate interest (Art. 6(1)(f)).
Responding to legal requests Legal obligation (Art. 6(1)(c)).

You may withdraw consent for optional fields at any time by deleting them in the App or contacting us.


5. Who We Share Information With

We do not sell, rent, or share your personal information with third parties for their own purposes, including for their own marketing or advertising. We do not have any data-monetization business.

We do use the following infrastructure providers as processors acting on our behalf. They handle data only to provide their service to us:

Provider What they do for us Where they process data
Supabase Inc. Authentication, database (PostgreSQL), and real-time messaging. All of your account, profile, and session data is stored on Supabase infrastructure. United States.
Apple Inc. App distribution (App Store), device-level authentication (Sign in with Apple, if used), and Apple Push Notification service (when we later send notifications). Global, per Apple's terms.

Each of these is a major infrastructure provider with its own privacy commitments. They process data under our instructions; they do not use it for their own purposes.

We may also disclose information if legally required — for example, in response to a valid subpoena, court order, or government request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

If we are ever involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We would notify you (by email and/or in-App) before your data became subject to a different privacy policy.


6. Location Data — Additional Detail

Because location is the most sensitive category we collect, we want to be extra-clear:


7. International Data Transfers

Our infrastructure (Supabase) is located in the United States. If you access the App from outside the United States, your data is transferred to and processed in the United States, which may have data-protection rules different from those of your country.

If you are an EU, UK, or Swiss user, transfers to the United States are made under the European Commission's Standard Contractual Clauses (SCCs) or an equivalent legal mechanism, as part of our infrastructure provider's compliance program.


8. How Long We Keep Your Data

Data Retention
Active account, profile, and session history While your account is open.
Deleted account — profile and identifiable data Removed within 30 days of deletion.
Anonymized aggregate data (occupancy snapshots, hourly patterns) derived from your activity Retained indefinitely. By design this data cannot be tied back to you after deletion.
Backups Up to 90 days from the point of capture, then cycled out.
Records required by law (e.g. fraud investigations, tax records) As long as legally required, then deleted.

If you'd like an explicit confirmation that your data has been deleted, email us and we'll respond.


9. Your Rights

You have rights over the data we hold about you. These vary by jurisdiction, but we offer the following to everyone:

Everyone

To exercise any of these rights, email legal@waitlotiq.com. We respond within 30 days.

California residents (CCPA / CPRA)

If you are a California resident, you have, in addition:

To exercise these rights, email legal@waitlotiq.com with "California Privacy Request" in the subject line. We may need to verify your identity (typically by confirming you can sign in to the email associated with your account).

EU / UK residents (GDPR)

If GDPR or UK GDPR applies to you, in addition to the above you have:

Because we do not actively serve the EU/UK and have no establishment there, we have not appointed an EU/UK representative. If our user base expands, we will update this Policy and appoint one.

Other US states

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Jersey, New Hampshire, Minnesota, and Maryland (among others) have rights similar to those of California residents under their respective state privacy laws. We honor those rights in the same way — email legal@waitlotiq.com and we will respond per the applicable law.


10. Children

The App is intended for adult rideshare drivers and is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18, and specifically do not collect information from anyone under 13 in compliance with the Children's Online Privacy Protection Act (COPPA).

If you believe a child under 18 has provided us with personal information, please email legal@waitlotiq.com and we will delete it.


11. How We Protect Your Data

We take security seriously, but we want to be honest about what's achievable:

No system is perfectly secure. If we ever become aware of a data breach affecting your personal information, we will notify you and any required regulators in accordance with applicable law, generally within 72 hours of discovery for EU/UK users (per GDPR Article 33) and per state-specific timelines for US users.


12. Push Notifications

We do not currently send remote push notifications. The App may register for Apple's Push Notification service to retain the option to send operational alerts in the future (e.g. "lot occupancy spiked at your usual airport"). When and if we begin sending such notifications, you'll receive an iOS-level permission prompt before any are delivered, and you can disable them at any time in iOS Settings.

The App does generate local on-device notifications — for example, when it detects you've left a staging lot and prompts you to classify the trip. These are generated by the App on your device and are not sent from our servers; we do not see them.


13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top, and for material changes we will notify you in-App, by email, or both, before the changes take effect.

Your continued use of the App after the effective date of a revised Policy constitutes acceptance of the revised Policy. If you do not accept the revised Policy, you must stop using the App and may delete your account.

We will keep prior versions of this Policy available on request so you can see what changed.


14. Apple App Privacy ("Nutrition Label") Mapping

For consistency with what's shown on the App Store listing, the following is how this Policy maps to Apple's App Privacy questions:

Apple category Collected? Linked to identity? Used for tracking? Notes
Contact Info — Email Yes Yes No Account creation.
Contact Info — Name Yes (first name) Yes No Profile.
Contact Info — Phone, Address No
Identifiers — User ID Yes Yes No Account UUID.
Identifiers — Device ID, IDFA No We do not use IDFA.
Location — Precise Location Yes Yes No At lot boundaries only; not continuous.
Location — Coarse Location No We use precise location at lot boundaries; we do not collect coarse location separately.
User Content Yes (driver-entered trip classifications, vehicle info) Yes No
Usage Data No No third-party analytics.
Diagnostics No We do not collect crash logs ourselves. Apple's standard system crash reporting may still apply per Apple's terms.
Financial Info, Health & Fitness, Sensitive Info, Contacts, Browsing History, Search History, Other No

"Used for tracking" in Apple's sense means linking data with third-party data for advertising or sharing with data brokers. We do not do this for any category.


15. Contact

For any privacy question, request, or complaint:

Robert Ellis Raleigh, North Carolina, United States Email: legal@waitlotiq.com