top of page

Privacy Policy

A legal disclaimer

Privacy Policy for TwoDown

 

Last updated: July 29, 2026

 

TwoDown ("TwoDown", "we", "our", "us") provides a mobile app for riders to discover nearby riders, connect, chat, coordinate ride events, and use optional safety features such as an emergency beacon.

 

This Privacy Policy explains what information we collect, how we use it, and what choices you have. It applies to the TwoDown iOS and Android apps and related web pages we operate (for example account confirmation links).

 

1. Information We Collect

 

A. Account and identity information

- Email address and authentication data (managed through Supabase Auth).

- Sign-in credentials or tokens when you choose Sign in with Apple or Google Sign-In.

- Basic account metadata (for example, account ID and account creation time).

 

B. Profile information you provide

- Display name.

- Profile photo and optional gallery images.

- Riding profile details such as bike make/model/year, riding style, short bio, region, gear details, and optional social links.

- Public **TwoDown Pro** badge / membership status shown on your profile when applicable.

 

C. Rider interaction and social data

- Encounter records generated by proximity matching.

- Swipe/connection decisions.

- Connection records between users.

- QR connect tokens and scan/connection activity when you use in-person QR connect.

- Co-rider connection requests when you connect with other participants of the same ride event.

- Ride event data (for example: event title/description, meetup location label and coordinates, schedule, membership/invite status, comments, check-ins, and participant roster visibility to other event viewers).

- Ride event routes you upload or draw in-app (for example GPX files, route distance, and start/end points), which may be shared with people who can view the event.

- Chat data for direct, group, and ride-event threads, including participants, titles/avatars, messages, optional attachments, optional shared message locations, system membership events, and message reactions.

- Safety and moderation submissions (for example rider reports and message reports).

- Block and mute preferences.

 

D. Location data

- Precise location data (latitude/longitude, timestamp, and accuracy) when proximity detection is enabled.

- Depending on your permissions, this can include background location updates while proximity ingestion is on.

- Location data is used to power encounter detection and related safety/privacy features (such as delay and blurred region labels).

- Emergency beacon location: if you activate an emergency beacon, we process and share your live location with the riders you alert for the duration of that beacon. Beacon location updates may be stored while the beacon is active and for a limited period afterward for safety history and troubleshooting.

- Nearby beacon matching: if you opt in to nearby beacon alerts and keep proximity enabled, we may use your recent location telemetry to determine whether you are within approximate range (about a few kilometers) of a beacon whose sender included nearby riders.

 

We do not publish your exact route or raw proximity telemetry to other users in encounter cards.

 

E. Phone number and contact discovery

If you choose to use invite/contact discovery features:

- Verified phone number: when you verify a phone number, we store a one-way cryptographic hash of your number (and related verification metadata such as last four digits and verification time). We do not store your full phone number in plain text after verification.

- Contact matching: if you grant contacts permission, phone numbers from your address book are hashed on your device and sent to our servers only to find matches with other users who opted in to contact discovery. We do not upload or store your full contact list.

- Discoverability preference: whether you allow other verified users to find you through contact matching.

- SMS verification: we use an SMS provider to send one-time confirmation codes when you verify your number.

 

F. Emergency beacon and medical information

If you use beacon or medical profile features:

- Beacon activation metadata (for example activation time, optional note, recipient scope, status, resolution, and recipient responses). Recipient scope may include your connections, selected ride-event participants, and/or opted-in nearby riders when the sender chooses those audiences.

- Beacon location snapshots and update history while a beacon is active.

- Medical / ICE profile (TwoDown Pro): optional information you provide such as blood type, allergies, medications, conditions, emergency contact details, and notes for responders. This is visible only to beacon recipients while you have an **active** beacon—not as part of your public profile.

 

G. Subscription and purchase information

If you purchase or restore TwoDown Pro:

- Subscription status, entitlement identifiers, product identifiers, store source (App Store or Google Play), and related purchase/renewal metadata processed through RevenueCat and your app store.

- We may sync entitlement status to your account so Pro features and your public Pro badge stay accurate.

- We do not receive or store your full payment card details; billing is handled by Apple or Google.

 

H. Notification and device data

- Push notification tokens (Expo/APNs/FCM), platform, app version, token health, and related delivery metadata.

- Notification event and delivery log records used to operate and debug notifications.

 

I. Local device storage

- App preferences stored on-device (for example onboarding completion, notification preferences, proximity toggle, and selected privacy preferences).

- On-device caches of recently viewed profiles, chats (including reactions), ride events, images, and temporary route files used for performance. These caches may remain on the device until overwritten, cleared by the app or OS, or removed when you uninstall the app.

 

2. How We Use Information

 

We use collected information to:

- Create and manage your account.

- Let you create and display your rider profile, including Pro badge status when applicable.

- Detect rider encounters and generate privacy-safe encounter cards.

- Enable swipes, connections, QR connect, co-rider connect, and ride-event coordination (including routes, rosters, and check-ins).

- Enable direct, group, and ride-event messaging, including reactions and attachments.

- Operate invite/contact discovery for users who opt in.

- Operate emergency beacon alerts, including sharing live location and (for Pro users) medical information with recipients you alert, and matching nearby opted-in riders when that audience is selected.

- Process subscriptions, restore purchases, unlock Pro features, and reflect entitlement status.

- Send push notifications you request or enable.

- Provide safety features such as blocking, muting, and reporting.

- Maintain service security, prevent abuse, and troubleshoot system issues.

- Comply with legal obligations and enforce our Terms of Use.

 

3. How and Why We Process Location Data

 

TwoDown relies on proximity features. If you enable proximity ingestion and grant permissions, we process location telemetry in the foreground and (where permitted) background.

 

Encounter presentation uses privacy controls such as delayed visibility and blurred region labels. You can disable proximity ingestion in-app at any time; if disabled, new telemetry uploads stop for that device/account context.

 

Emergency beacon exception: activating a beacon is a deliberate choice to share your live location with selected recipients (for example your connections, a ride group, and/or opted-in nearby riders). A beacon is temporary and is not an always-on tracker. End or resolve a beacon when you no longer need help.

 

Nearby beacon alerts: receiving alerts from nearby non-connection beacons requires a separate in-app opt-in (default off) and an active proximity setting. Beacon senders must explicitly choose to include nearby riders.

 

Ride routes: when you draw or snap a ride route, waypoints may be sent to a routing service (such as OSRM) to align the path to roads. Stored route files and related map points may be visible to people who can view the ride event.

 

4. Sharing and Disclosure

 

We do not sell your personal information.

 

We share data only as needed to provide the service:

- Infrastructure and backend processing: Supabase (auth, database, storage, serverless functions).

- Authentication providers: Apple and/or Google when you sign in with those services.

- Push delivery providers: Expo Push Service and, depending on token/provider path, Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM).

- SMS verification: GatewayAPI (or equivalent SMS provider) to deliver phone verification codes.

- Subscriptions: RevenueCat, Apple App Store, and Google Play to manage TwoDown Pro purchases and entitlements.

- Route snapping: OSRM (or an equivalent routing service) when you draw or snap a ride route.

- Maps:Apple Maps and/or Google Maps for map display in the app.

- Beacon recipients: when you activate a beacon, alert details and live location (and Pro medical profile, if provided) are shared with the riders you alert, which may include connections, selected ride-event participants, and/or opted-in nearby riders.

- Other users of the service: as needed to operate social features you use (for example profiles, encounter cards, chat participants, ride-event details/routes/rosters, and public Pro badge status).

- Legal/safety disclosures: when required by law, legal process, or to protect users and the service.

 

5. Data Retention

 

We retain information while your account is active and as needed to operate the app.

 

Current implementation includes:

- Push token cleanup for stale/invalid tokens.

- In-app account deletion that attempts to remove your profile data, media you uploaded, messages you sent, ride participation/hosting data, encounter/swipe/connection data, privacy settings, reports, push tokens, contact-discovery hashes, beacon history, medical profile, and subscription entitlement records tied to your account.

 

Account deletion permanently removes your account access and initiates deletion of associated data we control. Some content may remain where it is part of another user's experience (for example messages other people sent in a shared thread, or ride-event records you hosted that other participants still need for history). On-device caches are not controlled by our servers after deletion. Some operational records (for example certain notification delivery logs, resolved beacon records needed for safety auditing, or purchase records retained by app stores, RevenueCat, or payment platforms) may remain if needed for service reliability, fraud prevention, auditing, or legal compliance, and may be retained in de-identified or minimally identifying form where possible.

 

6. Your Choices and Rights

 

Within the app, you can:

- Update profile details.

- Manage privacy settings (including encounter deck visibility, social link visibility, region blur, contact discoverability, and nearby emergency beacon alerts).

- Enable or disable push notifications.

- Enable or disable proximity ingestion.

- Verify or stop using phone/contact discovery features.

- Create, update, or delete your medical profile (Pro).

- Activate, resolve, or cancel emergency beacons, and choose beacon recipient audiences where available.

- Leave group or ride-event chats; mute threads; block/mute users; and submit safety reports.

- Manage or cancel TwoDown Pro through your Apple or Google account subscription settings.

- Delete your account from Settings, which permanently removes account access and initiates deletion of associated data as described above.

 

Depending on your jurisdiction, you may have additional rights (for example access, correction, deletion, restriction, objection, and portability). Contact us to make a request.

 

7. Children's Privacy

 

TwoDown is not directed to children under 13 (or the higher minimum age required by local law), and we do not knowingly collect personal information from children.

 

## 8. Security

 

We use reasonable technical and organizational safeguards to protect personal information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

 

9. International Processing

 

Your information may be processed in countries other than your own, including where our service providers operate. We take steps intended to protect data under applicable law.

 

10. Changes to This Policy

 

We may update this Privacy Policy from time to time. We will post the updated version in the app and/or at [https://twodownapp.com/privacy](https://twodownapp.com/privacy), with a revised "Last updated" date.

 

11. Contact

 

If you have questions or privacy requests, contact:

 

- Email: support@twodownapp.com

 

© 2026 by TwoDown.

 

bottom of page