Route2Bee · Last updated: July 2026
Route2Bee is provided by:
Lukas Schachtmaier & Johann Warkentin GbR
honeyapps
Rosenstraße 19
38550 Isenbüttel
Germany
Phone: +49 174 9783003
Email: info@honeyapps.de
We are the “controller” of your personal data under the EU General Data Protection Regulation (GDPR) and the “business” with respect to your personal information under the California Consumer Privacy Act as amended by the CPRA. Because we are established in the European Union, the GDPR applies to our processing regardless of where you live — so the protections described in Section 11 apply to you as well.
We collect this information directly from you and automatically from your device when you use the App. We do not buy personal information from data brokers, and we do not use advertising trackers or third-party analytics SDKs in the App.
Route2Bee uses continuous background GPS to detect and record your drives automatically. This requires access to your location even when the App is not in the foreground.
Why background access is required: automatic trip detection only works if the App can read GPS while your screen is locked or while you use other apps. Without this permission the core function of the App does not work. You may instead use the App to enter trips manually.
What happens to raw GPS data: individual GPS waypoints (coordinates, speed, accuracy, timestamp) are recorded locally on your device first. They are not deleted automatically, because they form part of the record supporting your mileage log.
What is synchronized to the cloud: once your device is online, both the summarized trip data (start/end address, distance, duration, tag, note) and the individual GPS waypoints of your trips are synchronized to your account. The waypoints make up the route of each trip, let the map view work across your devices, and are part of the evidence supporting your mileage log. They are stored exclusively on servers in the European Union (Frankfurt), and database-level access rules restrict them to your own account. When you delete your account, all waypoints are permanently and irreversibly deleted (see Section 12).
Low-power monitoring while idle: even when no trip is being recorded, the App uses low-power, reduced-accuracy location monitoring (roughly every 30 seconds, without activating the GPS chip) to detect the start of a new drive. This data is used only for trip-detection logic and is not stored. You can turn this off at any time using the auto-tracking switch in the App settings.
Your control: you can revoke location permission at any time in your device settings. Doing so stops automatic trip detection.
Legal basis (GDPR): your explicit consent, Art. 6(1)(a) GDPR, given by granting the location permission on your device.
Route2Bee is not directed to children. We do not knowingly collect personal information from children under 13 years of age, and the App is not intended for their use. If you are a parent or guardian and believe a child under 13 has provided us with personal information, contact us at info@honeyapps.de and we will delete it promptly.
Users in the European Economic Area must have reached the age at which they can validly consent to processing under Art. 8 GDPR in their country (16 in Germany). We do not sell or share the personal information of consumers under 16 years of age.
To provide the App (GDPR Art. 6(1)(b) — performance of a contract): automatic trip detection and recording; generating mileage reports and PDF/CSV exports; synchronizing your trips across your devices; managing your subscription and account.
With your consent (GDPR Art. 6(1)(a)): background GPS tracking for automatic trip detection.
Legitimate interests (GDPR Art. 6(1)(f)): improving app functionality, diagnosing errors and crashes, security and fraud prevention.
Legal obligation (GDPR Art. 6(1)(c)): retention of finalized records as described in Section 7.
We do not use your personal information for advertising, profiling, automated decision-making, or cross-context behavioral advertising.
We have not sold or shared personal information in the preceding 12 months, and we do not do so today. “Sale” and “sharing” are used here as defined by the CCPA/CPRA, where “sharing” means disclosure for cross-context behavioral advertising. We do not disclose personal information to third parties for their own direct marketing purposes (California Civil Code § 1798.83, “Shine the Light”).
Sensitive personal information: precise geolocation is treated as sensitive personal information under the CPRA. We collect and use it solely to perform the service you requested — detecting and recording your drives — and for related security and error-diagnosis purposes. We do not use or disclose sensitive personal information for purposes that would give rise to a right to limit its use under Cal. Civ. Code § 1798.121. For that reason, we do not offer a separate “Limit the Use of My Sensitive Personal Information” control.
We disclose personal information to service providers only for the business purposes described in Section 8, under contracts that prohibit them from retaining, using or disclosing it for any other purpose.
Audit log: each creation, edit, correction, deletion or finalization of a trip is logged with a timestamp, the type of action, the affected fields with prior and new values, and your user ID. The audit log is stored on your device and synchronized to the cloud.
Finalization: when you mark a trip as reviewed, it is finalized with a timestamp. Finalized trips can still be edited, but the change is recorded as a correction in the audit log; finalized trips are not permanently deleted, only flagged as deleted.
Retention periods:
You may keep your own records for the period required by the IRS or your state tax authority; we recommend exporting your data periodically rather than relying on the App as your sole archive.
We use the following service providers. Each receives only what it needs for the stated purpose.
Supabase (database & authentication)
Supabase Inc., 970 Mission Street, San Francisco, CA 94103, USA
Server location: EU Central (Frankfurt, Germany)
Privacy: https://supabase.com/privacy
Purpose: storing trip data, user authentication
RevenueCat (in-app purchases)
RevenueCat Inc., San Francisco, USA
Privacy: https://www.revenuecat.com/privacy
Purpose: managing subscriptions. RevenueCat receives an anonymized user ID and subscription status. No payment data is transmitted to RevenueCat.
Apple App Store / Google Play Store
All in-app purchase payments are processed exclusively by Apple or Google. We never receive your payment details.
Google Maps SDK (Android)
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: map display in the App.
Sentry (error and crash reports)
Functional Software Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA
Privacy: https://sentry.io/privacy/
Purpose: automatic capture of crashes and technical errors. Sentry receives technical error data only (error message, device type, operating system, app version) plus a pseudonymous user identifier. Email address, IP address and user name are stripped before transmission. Data is ingested and stored in Sentry’s EU region.
OpenStreetMap / Nominatim (address search)
OpenStreetMap Foundation, 132 Maney Hill Road, Sutton Coldfield, B72 1JU, United Kingdom
Purpose: searching and geocoding addresses during manual trip entry. Only the address text you type is transmitted.
Sign in with Apple
Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA
Purpose: optional sign-in. Apple sends us a pseudonymous user ID and, if you allow it, your email address (possibly an Apple relay address).
Google Sign-In
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: optional sign-in. Google sends us a pseudonymous account ID, your email address and, if available, your display name.
Brevo (transactional email)
Sendinblue GmbH / Brevo, Germany
Purpose: delivery of account emails such as address confirmation and password reset. Brevo receives your email address and the message content.
We have data processing agreements in place with these providers as required by Art. 28 GDPR, and service provider contracts as required by the CCPA/CPRA.
International transfers: your trip data is stored in the European Union. Where a provider processes data in the United States, transfers are made under the EU-US Data Privacy Framework or under Standard Contractual Clauses.
We may also disclose personal information where required by law, valid legal process, or to protect our rights, safety or property, or those of our users.
Your trips are stored primarily in a local SQLite database on your device. On iOS this data is additionally protected by the operating system’s Data Protection API. Cloud synchronization — covering your trips, the GPS waypoints that make up their routes, your companies, vehicles, known locations and the audit log — runs through Supabase, whose servers for this project are operated in the EU Central region (Frankfurt, Germany). All data transfers are TLS-encrypted, and row-level security restricts every record to the account that created it.
Your account is secured by Supabase Auth. We never have access to your password. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
If you are a California resident, you have the following rights:
Categories of personal information collected in the preceding 12 months: identifiers (email address, display name, user ID); commercial information (subscription status and history); geolocation data, including precise geolocation; internet or other electronic network activity information (device type, operating system, app version, crash data); and other information you voluntarily provide (notes, vehicle details). Sources: directly from you, and automatically from your device. Business purposes: as described in Section 5. Disclosures for a business purpose: to the service providers listed in Section 8.
How to exercise your rights: use the in-app controls (Settings → “Export data” and Settings → “Delete account & data”), or email info@honeyapps.de from the address associated with your account. We verify requests by confirming control of that email address. An authorized agent may submit a request on your behalf with written permission signed by you, and we may still ask you to verify your identity directly.
We respond to verifiable requests within 45 days, extendable once by a further 45 days where reasonably necessary, and we will inform you of any extension.
If you live in a U.S. state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana), you have rights comparable to those in Section 10 — to confirm processing and access your data, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, sale, and certain profiling (none of which we do). If we decline your request, you may appeal by replying to our decision at info@honeyapps.de; if we deny the appeal you may contact your state Attorney General.
Because we are established in the EU, the GDPR applies to our processing of your data regardless of where you live. Under it you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), and withdrawal of consent at any time (Art. 7(3)).
To exercise any of these rights, contact info@honeyapps.de. You also have the right to lodge a complaint with a supervisory authority. Ours is: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany — poststelle@lfd.niedersachsen.de.
You can delete your account in the App under Settings → “Delete account & data”, or by emailing info@honeyapps.de. Deleting your account does not cancel an active subscription — cancel that in your App Store or Google Play account settings.
What happens on deletion: personal data in finalized trips (addresses, GPS coordinates, notes) is anonymized. The tax-relevant trip skeleton (date, distance, purpose, odometer) and the audit log are retained for the statutory retention period that applies to us, then deleted automatically. All GPS waypoints, non-finalized trips and all other data are deleted immediately and irreversibly. This retention is a recognized exception to the right of deletion under both the CCPA (Cal. Civ. Code § 1798.105(d)) and the GDPR (Art. 17(3)(b)).
We may update this Privacy Policy. The current version is always available in the App. We will notify you of material changes by email or in-app notification, and will update the “Last updated” date above.
Questions about privacy:
Lukas Schachtmaier & Johann Warkentin GbR
honeyapps
Rosenstraße 19
38550 Isenbüttel
Germany
Phone: +49 174 9783003
Email: info@honeyapps.de