Route2Bee · Last updated: September 2026
Route2Bee is provided by:
Lukas Schachtmaier & Johann Warkentin GbR
honeyapps
Rosenstraße 19
38550 Isenbüttel
Germany
Phone: +49 174 9783003
Email: info@honeyapps.de
We are the “controller” of your personal data under the EU General Data Protection Regulation (GDPR) and the “business” with respect to your personal information under the California Consumer Privacy Act as amended by the CPRA. Because we are established in the European Union, the GDPR applies to our processing regardless of where you live — so the protections described in Section 13 apply to you as well.
This policy explains what we collect, why, who we share it with, and the rights you have.
We collect this information directly from you and automatically from your device when you use the App. We do not buy personal information from data brokers, and we do not use advertising trackers or third-party analytics SDKs in the App.
Route2Bee uses continuous background GPS to detect and record your drives automatically. This requires access to your location even when the App is not in the foreground.
Why background access is required: automatic trip detection only works if the App can read GPS while your screen is locked or while you use other apps. Without this permission the core function of the App does not work. You may instead use the App to enter trips manually.
What happens to raw GPS data: individual GPS waypoints (coordinates, speed, accuracy, timestamp) are recorded locally on your device first. They are not deleted automatically, because they form part of the record supporting your mileage log.
What is synchronized to the cloud: once your device is online, both the summarized trip data (start/end address, distance, duration, tag, note) and the individual GPS waypoints of your trips are synchronized to your account. The waypoints make up the route of each trip, let the map view work across your devices, and are part of the evidence supporting your mileage log. They are stored exclusively on servers in the European Union (Frankfurt), and database-level access rules restrict them to your own account. When you delete your account, all waypoints are permanently and irreversibly deleted (see Section 14).
Low-power monitoring while idle: even when no trip is being recorded, the App uses low-power, reduced-accuracy location monitoring (roughly every 30 seconds, without activating the GPS chip) to detect the start of a new drive. These positions are evaluated on your device only; the App caches just a few anchor positions (such as the last known position). They are not added to your mileage log and not transmitted to our servers. You can turn this off at any time using the auto-tracking switch in the App settings.
Trip-detection diagnostics: so that we can investigate missed or interrupted trips, the App logs state changes of the automatic detection (such as “geofence triggered”, “recording recovered”, “GPS signal stale”), error codes, timestamps and whether battery optimization is active on your device, and uploads these entries to your account. They contain no coordinates. Legal basis: our legitimate interest in reliable trip detection, Art. 6(1)(f) GDPR.
Your control: you can revoke location permission at any time in your device settings. Doing so stops automatic trip detection.
Legal basis (GDPR): your explicit consent, Art. 6(1)(a) GDPR, given by granting the location permission on your device.
Route2Bee is not directed to children. We do not knowingly collect personal information from children under 13 years of age, and the App is not intended for their use. If you are a parent or guardian and believe a child under 13 has provided us with personal information, contact us at info@honeyapps.de and we will delete it promptly.
Users in the European Economic Area must have reached the age at which they can validly consent to processing under Art. 8 GDPR in their country (16 in Germany). We do not sell or share the personal information of consumers under 16 years of age.
To provide the App (GDPR Art. 6(1)(b) — performance of a contract):
With your consent (GDPR Art. 6(1)(a)):
Legitimate interests (GDPR Art. 6(1)(f)):
Legal obligation (GDPR Art. 6(1)(c)): keeping a record of your acceptance of the Terms and of email opt-outs.
We do not use your personal information for third-party advertising, profiling, automated decision-making, or cross-context behavioral advertising.
We have not sold or shared personal information in the preceding 12 months, and we do not do so today. “Sale” and “sharing” are used here as defined by the CCPA/CPRA, where “sharing” means disclosure for cross-context behavioral advertising. We do not disclose personal information to third parties for their own direct marketing purposes (California Civil Code § 1798.83, “Shine the Light”).
Sensitive personal information: precise geolocation is treated as sensitive personal information under the CPRA. We collect and use it solely to perform the service you requested — detecting and recording your drives — and for related security and error-diagnosis purposes. We do not use or disclose sensitive personal information for purposes that would give rise to a right to limit its use under Cal. Civ. Code § 1798.121. For that reason, we do not offer a separate “Limit the Use of My Sensitive Personal Information” control.
We disclose personal information to service providers only for the business purposes described in Section 8, under contracts that prohibit them from retaining, using or disclosing it for any other purpose.
To support the integrity of your mileage records, the App keeps additional data:
Audit log: each creation, edit, correction, deletion or finalization of a trip is logged with a timestamp, the type of action, the affected fields with prior and new values, and your user ID. The audit log is stored on your device and synchronized to the cloud.
Finalization: when you mark a trip as reviewed, it is finalized with a timestamp. Finalized trips can still be edited, but the change is recorded as a correction in the audit log; within your account, finalized trips are not permanently deleted individually, only flagged as deleted, so that your log remains traceable.
Retention periods:
We retain nothing after account deletion. Any recordkeeping obligation for your mileage log (for example under IRS rules or your state tax authority) rests with you, not with us. Export your data before deleting your account, and export it periodically rather than relying on the App as your sole archive.
We use the following service providers. Each receives only what it needs for the stated purpose.
Supabase (database & authentication)
Supabase Inc., 970 Mission Street, San Francisco, CA 94103, USA
Server location: EU Central (Frankfurt, Germany)
Privacy: https://supabase.com/privacy
Purpose: storing trip data, user authentication
Brevo (email delivery)
Sendinblue SAS (“Brevo”), 7 rue de Madrid, 75008 Paris, France
Privacy: https://www.brevo.com/legal/privacypolicy/
Purpose: delivering every email we send you — sign-up confirmation, password reset, service and product emails (Section 9). Brevo receives your email address, display name and the content of the respective email, and produces delivery and open statistics that we use only to monitor delivery and troubleshoot problems. Servers located in the European Union.
RevenueCat (in-app purchases)
RevenueCat Inc., San Francisco, USA
Privacy: https://www.revenuecat.com/privacy
Purpose: managing subscriptions and crediting referral rewards. RevenueCat receives an anonymized user ID and subscription status (active/inactive, purchase date, expiry). No payment data is transmitted to RevenueCat.
Apple App Store / Google Play Store
All in-app purchase payments are processed exclusively by Apple or Google. We never receive your payment details.
Google Maps SDK (Android)
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Purpose: map display in the App. Google’s privacy policy applies.
Apple Maps (iOS)
Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA
Privacy: https://www.apple.com/legal/privacy/
Purpose: map view of an individual trip on iOS devices, rendered through the operating system’s map component. Apple’s privacy policy applies.
MapTiler (map tiles in the trip list)
MapTiler AG, Zugerstrasse 22, 6314 Unterägeri, Switzerland (UID CHE-345.466.193)
Privacy: https://www.maptiler.com/privacy-policy/
Purpose: loading the map tiles behind the route previews in your trip list. Requesting a tile transmits your device’s IP address and the coordinates of the requested tile. What is transmitted is the map section, not your route: a tile is coarse and covers several kilometers depending on zoom level. Your trip data, your GPS waypoints and your account are never transmitted to MapTiler. MapTiler states it retains IP addresses for up to two months for security purposes. If the service is not configured or unreachable, the App draws the route without a map background and nothing is sent to MapTiler.
Sentry (error and crash reports)
Functional Software Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA
Privacy: https://sentry.io/privacy/
Purpose: automatic capture of crashes and technical errors. Sentry receives technical error data only (error message, device type, operating system, app version) plus a pseudonymous user identifier. Email address, IP address and user name are stripped before transmission. Data is ingested and stored in Sentry’s EU region.
OpenStreetMap / Nominatim (address search)
OpenStreetMap Foundation, 132 Maney Hill Road, Sutton Coldfield, B72 1JU, United Kingdom
Privacy: https://wiki.osmfoundation.org/wiki/Privacy_Policy
Purpose: searching and geocoding addresses during manual trip entry. The address text you type and, technically unavoidable, your device’s IP address are transmitted; your account, trips and waypoints are not.
Sign in with Apple
Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA
Privacy: https://www.apple.com/legal/privacy/
Purpose: optional sign-in. Apple sends us a pseudonymous user ID and, if you allow it, your email address (possibly an Apple relay address).
Google Sign-In
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Privacy: https://policies.google.com/privacy
Purpose: optional sign-in. Google sends us a pseudonymous account ID, your email address and, if available, your display name.
GitHub Pages (website hosting)
GitHub Inc., 88 Colin P Kelly Jr St, San Francisco, CA 94107, USA
Purpose: hosting the public version of this policy and the marketing website (honeyapps.de/route2bee). Standard server logs (IP address, user agent, timestamp) are processed on access.
We have data processing agreements in place with the providers that process data on our behalf (Supabase, Brevo, RevenueCat, Sentry, MapTiler, GitHub), as required by Art. 28 GDPR, and service provider contracts as required by the CCPA/CPRA. Apple, Google and the OpenStreetMap Foundation process the data arising from the use of their services as independent controllers under their own privacy policies.
International transfers: your trip data is stored in the European Union. Where a provider processes data in the United States, transfers are made under the EU-US Data Privacy Framework or under Standard Contractual Clauses.
We may also disclose personal information where required by law, valid legal process, or to protect our rights, safety or property, or those of our users.
Service emails: to perform our contract with you we send emails about your account — sign-up confirmation, password reset, notices when you reach the free trip limit or when trips could not be saved, and notices about changes to this policy or the Terms (Art. 6(1)(b) GDPR). You cannot opt out of these while your account exists.
Product emails about Route2Bee: from time to time we email registered users about Route2Bee features and offers — for example a reminder to record your first trip, a Premium offer, or the referral program. Legal basis under the GDPR is our legitimate interest in informing our users about our own product (Art. 6(1)(f)); we point this out when you register. You can opt out at any time using the unsubscribe link in every such email or by emailing info@honeyapps.de; we honor opt-outs promptly, and every product email identifies us as the sender and includes a valid postal address, as required by the CAN-SPAM Act. After you opt out you will only receive service emails. We keep your opt-out on file so that it is honored permanently.
We log which email we sent you and when, to avoid sending the same message twice. Delivery runs through Brevo (Section 8). We never give your email address to third parties for their marketing and do not build a profile from your reading behavior.
Route2Bee offers a referral program (“invite a friend”). Participation is voluntary; the conditions are set out in the Terms of Service.
If you share your code: we store your personal invite code and, for each redemption, when it happened, whether and when the reward became due, and how it was credited. To decide that, we check the subscription status of the person you referred, because the reward depends on it.
What the referrer sees about you if you redeem a code: the person whose code you enter sees, in their invitation list, your first name (taken from your display name) and the reward status — that is, whether you already use Premium, whether the subscription is still running, or whether the reward has been credited. No other data (email address, trips, locations) is shown. We point this out when you enter a code.
Legal basis: operating the referral program as part of our contract with you (Art. 6(1)(b) GDPR) and our legitimate interest in preventing abuse (Art. 6(1)(f) GDPR). Rewards are credited through RevenueCat (Section 8).
If you delete your account, your referral data is deleted. A reward another person has already earned through your redemption remains with them, without any reference to you.
Your trips are stored primarily in a local SQLite database on your device. On iOS this data is additionally protected by the operating system’s Data Protection API. Cloud synchronization — covering your trips, the GPS waypoints that make up their routes, your companies, vehicles, known locations, route templates, settings and the audit log — runs through Supabase, whose servers for this project are operated in the EU Central region (Frankfurt, Germany). All data transfers are TLS-encrypted, and row-level security restricts every record to the account that created it.
Your account is secured by Supabase Auth (email/password, Sign in with Apple or Google Sign-In). We never have access to your password. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
If you are a California resident, you have the following rights:
Categories of personal information collected in the preceding 12 months: identifiers (email address, display name, user ID, invite code); commercial information (subscription status and history, referral rewards); geolocation data, including precise geolocation; internet or other electronic network activity information (device type, operating system, app version, crash data, trip-detection diagnostics, email log); and other information you voluntarily provide (notes, vehicle details, install source). Sources: directly from you, and automatically from your device. Business purposes: as described in Section 5. Disclosures for a business purpose: to the service providers listed in Section 8.
How to exercise your rights: use the in-app controls (Settings → “Export data” and Settings → “Delete account & data”), or email info@honeyapps.de from the address associated with your account. We verify requests by confirming control of that email address; for data-export and deletion requests made in the App, you are already authenticated. An authorized agent may submit a request on your behalf with written permission signed by you, and we may still ask you to verify your identity directly.
We respond to verifiable requests within 45 days, extendable once by a further 45 days where reasonably necessary, and we will inform you of any extension.
If you live in a U.S. state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana), you have rights comparable to those in Section 12 — to confirm processing and access your data, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, sale, and certain profiling (none of which we do). If we decline your request, you may appeal by replying to our decision at info@honeyapps.de; if we deny the appeal you may contact your state Attorney General.
Because we are established in the EU, the GDPR applies to our processing of your data regardless of where you live. Under it you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) — in particular to product emails, see Section 9 — and withdrawal of consent at any time (Art. 7(3)), for example by revoking location permission in your device settings.
To exercise any of these rights, contact info@honeyapps.de. You also have the right to lodge a complaint with a supervisory authority. Ours is: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany — poststelle@lfd.niedersachsen.de.
You can delete your account in the App under Settings → “Delete account & data”, or by emailing info@honeyapps.de.
What is deleted: everything — account data, trips (including finalized ones), GPS waypoints, audit log, vehicles, companies, known locations, templates, settings, diagnostics and email logs, install source, referral data and Terms-acceptance records. Deletion takes effect immediately and is irreversible; we keep no copy.
Export first: a mileage log is typically subject to recordkeeping obligations that rest with you as the taxpayer (for example under IRS rules, generally at least three years, or longer under your state’s rules). Export your trips before deleting your account (PDF, CSV or JSON). After deletion we cannot restore anything.
Subscription: deleting your account does not cancel an active subscription — cancel that in your App Store or Google Play account settings.
We may update this Privacy Policy, for example when we add features or service providers. The current version is always available in the App and at honeyapps.de/route2bee/en/privacy. We will notify you of material changes by email or in-app notification, and will update the “Last updated” date above.
Questions about privacy:
Lukas Schachtmaier & Johann Warkentin GbR
honeyapps
Rosenstraße 19
38550 Isenbüttel
Germany
Phone: +49 174 9783003
Email: info@honeyapps.de