Privacy Policy
What Information Rallista Collects, How, and Why
Overview
Rallista, through its website and mobile apps, collects a variety of data, some personally identifiable, to provide functionality to you, to record usage data, to record diagnostic data for our team, and in certain cases for commercial purposes. The following outlines what, how, and why data are collected. This includes how data are secured and specifics about what is collected and why. Details about how to control your privacy can be requested from our support email, including how to delete data already saved on Rallista's services. If you have further questions, please contact us through the Rallista website support page to ensure that your request is completed.
California residents: see our Notice at Collection for a summary of the categories of personal information we collect, as required by the CCPA/CPRA.
Data Protection
The Rallista website and backend services for our apps operate on Google Cloud (including Firebase). The Rallista Directions API, which provides route calculation, is hosted on OVH Cloud. All data collected and stored directly by Rallista services are encrypted during transit and while stored. Data stored locally on your device are encrypted using industry-standard encryption.
For details on Google Cloud's privacy and security practices, please review their privacy policy and security overview at https://cloud.google.com/security/privacy/.
The Rallista App stores data both locally on a mobile device and remotely to provide consistent service. This Privacy Policy includes a section on How Information is Used and Why. Mobile App data, including Rallista's, can be protected by using a device passcode.
Data Transfer to the United States
All Rallista Services are stored on Google Cloud and OVH Cloud infrastructure in the United States. By using any Rallista services, you understand that your information will be transferred to, processed, and stored in the United States.
How Information is Used and Why
Rallista Website
The Rallista Website collects general site usage and diagnostic data automatically. This may include personally identifiable data such as your Internet connection IP address or device unique identifier. Additional personal data are collected if supplied by you, such as through creating an account, contacting us, or using support tools. Site usage data can include page visits, frequency of visiting the website, and so on. Diagnostic data pertain to failures within our system, which may include specifics such as which browser or device type you were using.
Rallista Account for Web and Mobile App
Accounts allow submitting personal information, such as your email address, username, profile photo, and a unique password. You may also use Rallista without creating an account through anonymous access, in which case your data is tied to your device. When organizing an event, event information is stored as specified by the account owner who created the event in the app. Any event associated with your account can be edited or deleted.
Product Updates and Marketing Communications
We may use your personal information (such as your name, email address, and contact details) to send you information about our products and services, including product updates, feature announcements, promotional offers, and other marketing communications. You may opt out of receiving marketing communications at any time by following the unsubscribe instructions included in such communications or by contacting us as described below.
Cookies
Cookies are small text files placed on your device by a website or online service. They allow the site to recognize your browser, remember preferences, and provide functionality. Cookies may be set by the site you are visiting ("first-party cookies") or by third-party services operating on that site ("third-party cookies"). Session cookies are deleted when you close your browser, while persistent cookies remain on your device until they expire or you delete them.
The Rallista website (rallista.app) uses a minimal set of cookies. We do not use advertising cookies, and we do not use cookies to track you across other websites.
| Cookie | Type | Provider | Purpose | Duration |
|---|---|---|---|---|
| Session identifier | First-party, session | Rallista | Maintains your logged-in state while you browse the Rallista website. | Expires when you close your browser. |
| Authentication token | First-party, persistent | Rallista (Firebase Auth) | Keeps you signed in between visits so you do not need to re-enter your credentials each time. | Up to 30 days of inactivity. |
For users located in the European Economic Area (EEA), the Rallista website will only set non-essential cookies with your prior consent. Essential cookies (such as those required to maintain your logged-in state) may be set without consent as they are strictly necessary for the website to function. If we introduce non-essential cookies in the future, we will present a consent banner allowing you to accept or decline these cookies before they are set.
Rallista Mobile App
The Rallista App collects a variety of information to provide functionality, aggregate usage data, and diagnostic data. The following tables outline what data Rallista stores online, when and why.
Table 1. Detailed Data Collected and Stored by Rallista
| Data Collected | When | Why | Third Parties |
|---|---|---|---|
| Usage Data | While using a Rallista mobile app. | To provide Rallista with accurate usage information for the purpose of understanding how features in the apps are being used. | Usage data is collected and aggregated by Google Cloud (Firebase Analytics). Rallista does not collect advertising identifiers. |
| Diagnostic Data | When your Rallista app encounters an error or crashes. | To allow the Rallista team to troubleshoot errors. | Diagnostic data is collected and aggregated by Google Cloud (Firebase Crashlytics). |
| Your Email Address | When you sign up for a Rallista account. | To allow you to sign in, reset your password and other account functions. To send informational, marketing or other emails regarding Rallista. | Your email is provided to Google Cloud (Firebase) for authentication and app functionality. |
| Your Username and Profile Photo | When you create or update your Rallista account profile. | To display your identity within the app and to other participants in events. | Provided to Google Cloud (Firebase) for app functionality. |
| Your Device's Unique Identifier | When the app encounters an error or crashes, or for aggregate analytics. | Rallista uses your device's unique identifier to determine if multiple crashes or failures happened on a single device, and to measure app usage. Rallista does not use advertising identifiers. | Your device's unique identifier is used by Google Cloud (Firebase) to provide accurate crash, failure, and usage statistics. |
| Your Location | When you use your location to center the map, for turn-by-turn navigation, route calculation, or route recording. When you opt-in to sharing your car's location with other participants in an event. | To provide accurate mapping, navigation, route calculation, or shared car locations. | Location data may be sent to the Rallista Directions API for route calculation. Map tile requests and geocoding searches are processed by Stadia Maps. |
| Your Driving Statistics | Whenever you drive a route in Rallista. You may optionally sync your trip history across devices. | Rallista collects driver statistics to provide app functionality. Rallista may also use app statistics to determine how the app is being used. | Driving statistics are stored on Google Cloud (Firebase). |
| Your Event Data | When you save an event in Rallista, including event details, participant information, and start location. | To provide app functionality. | Event data is stored on Google Cloud (Firebase). Start location names may be processed by Stadia Maps for geocoding. |
| Your Drive Data | When you save a drive in Rallista, including route geometry, waypoints, and drive details. | To provide app functionality. | Drive route data is processed by the Rallista Directions API and stored on Google Cloud (Firebase). |
| Your Car Data | When you save a car in Rallista, including make, model, and photo. | To provide app functionality. | Car data is stored on Google Cloud (Firebase). |
| Your Photos | When you upload a profile photo, car photo, event photo, or drive photo. | To provide app functionality and display content within the app. | Photos are stored on Google Cloud (Firebase Cloud Storage). |
| Your Subscription Data | When you subscribe to a Rallista plan through the Apple App Store, Google Play Store, or Stripe. | To manage your subscription and provide access to premium features. | Payment processing is handled entirely by Apple, Google, or Stripe. Rallista does not store payment details such as credit card numbers or billing addresses. Subscription identifiers are stored on Google Cloud (Firebase). |
| Search Queries | When you search for a location within the app. | To provide geocoding and place autocomplete functionality. | Search queries and optional location context are sent to Stadia Maps. |
Mobile App Location
Rallista uses your mobile location to facilitate app functionality as described above. The following app functionality uses your location:
- To find nearby drives and events on the Rallista content browser screen.
- To center on your current location on the map screen.
- For the duration of turn-by-turn navigation. While navigating, Rallista will continue to use your location in the background (when another app is being used or the device screen is locked). Navigation status may also be displayed on the Lock Screen a live activity or navigation notification.
- For the duration of route recording. Rallista will continue to use your location in the background until recording is stopped (v2 only).
- For route calculation. Your location may be sent to the Rallista Directions API to compute driving routes.
- If you opt-in to car location sharing during an event. Your location is shared in real-time with other event participants and stored for the duration of the event.
Rallista is also available on CarPlay (iOS) and Android Auto. When using these platforms, the same location data practices described above apply.
Mapbox Telemetry (Rallista v2 Only)
Rallista v2 uses Mapbox for map rendering and navigation. Mapbox offers an optional telemetry feature that, if you opt in, shares your location and map usage data with Mapbox to help improve their mapping products. This telemetry is disabled by default in the Rallista app. You can enable or disable it by tapping the Mapbox icon on the Rallista map screen. If you opt in, your data is governed by Mapbox's privacy policy at https://www.mapbox.com/legal/privacy. This clause applies only to Rallista v2; Rallista v3 and later versions do not use Mapbox.
Third-Party Services
Rallista uses the following third-party services that may process your data:
| Service | Provider | Data Processed | Purpose | Privacy Policy |
|---|---|---|---|---|
| Firebase (Auth, Firestore, Cloud Storage, Crashlytics, Analytics) | Account data, app data, photos, crash reports, usage analytics | Authentication, data storage, error reporting, usage analytics | https://firebase.google.com/support/privacy | |
| Stadia Maps | Stadia Maps | Search queries, map tile requests, viewport data | Geocoding, place autocomplete, map tile rendering | https://stadiamaps.com/privacy/ |
| App Store / In-App Purchases | Apple | Purchase and subscription data | Payment processing (iOS) | https://www.apple.com/legal/privacy/ |
| Google Play Billing | Purchase and subscription data | Payment processing (Android) | https://policies.google.com/privacy | |
| Stripe | Stripe | Purchase and subscription data | Payment processing (web) | https://stripe.com/privacy |
| OVH Cloud | OVHcloud | Route coordinates (origin, destination, waypoints) | Infrastructure hosting for the Rallista Directions API | https://us.ovhcloud.com/legal/data-processing-agreement/ |
| Mapbox (Rallista v2 only) | Mapbox | Map tile requests, location data (if telemetry opted in) | Map rendering, navigation, optional telemetry | https://www.mapbox.com/legal/privacy |
Rallista-Operated Services
The Rallista Directions API is a proprietary routing service built and operated by Rallista, hosted on OVH Cloud infrastructure. When you calculate a route, your origin, destination, and waypoint coordinates are sent to this service over an encrypted connection. OVH provides the hosting infrastructure but does not process or access route data for its own purposes. No data from this service is shared with external parties beyond what is necessary for hosting.
Data Retention
Rallista retains your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. The following outlines our general retention practices:
| Data Category | Retention Period |
|---|---|
| Account Data (email, username, profile photo) | Retained until you delete your account. |
| Usage Data (analytics) | Retained for up to 14 months from collection. |
| Diagnostic Data (crash reports) | Retained for up to 14 months from the date of the crash or error. |
| Location Data (navigation, route recording) | Processed in real-time for navigation; stored only when shared as part of an or event or through syncing detailed stats. Retained until you delete the associated drive, event, or account. |
| Drive, Event, Car, and Photo Data | Retained until you delete the data or your account. |
| Subscription Data | Transaction identifiers from Apple, Google, and Stripe are retained for the duration of the subscription. Upon account deletion, subscription records are disassociated from your personal data and retained in anonymized form for billing record-keeping purposes. |
| Search Queries | Processed in real-time by Stadia Maps; Rallista does not retain search queries beyond the active session. |
| Cookies | The Rallista website uses minimal cookies. Session cookies expire when you close your browser. Any persistent cookies expire after 30 days of inactivity. |
After the applicable retention period expires, data is deleted or anonymized. Exceptions include data that must be retained to comply with legal obligations (e.g., tax or billing records) or data referenced by other users' accounts as described in the Account Deletion section below.
Do Not Sell or Share My Personal Information
As described in the Notice at Collection section, Rallista does not sell your personal information as defined under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). Rallista does not share your personal information for cross-context behavioral advertising purposes.
Rallista uses Firebase Analytics to collect aggregated usage data. This data is used solely for Rallista's internal analytics purposes and is not shared with Google for Google's own advertising or marketing purposes.
If you believe your data has been sold or shared in a manner inconsistent with this policy, please contact us at [email protected].
Sensitive Personal Information
Rallista collects precise geolocation data, which is classified as sensitive personal information under the CPRA, when you use location-based features such as navigation, route recording, and event car location sharing. This data is used solely to provide these features and is not used for any purpose other than providing the services you request.
You have the right to limit the use and disclosure of your sensitive personal information. Most Rallista features that use your location (such as navigation and route calculation) process location data in real-time on your device and do not store or track it. The event car location sharing feature is opt-in and shares your location with other event participants. You may limit Rallista's use of your precise geolocation by choosing not to use the car location sharing feature, or by disabling location permissions for the Rallista app through your device's system settings.
Your Privacy Rights
Rallista is committed to respecting your privacy rights under applicable law. Depending on your jurisdiction, you may have some or all of the following rights regarding your personal information. To exercise any of these rights, please contact Rallista support at https://rallista.app/feedback or by email at [email protected].
California Residents (CCPA/CPRA)
Notice at Collection
This section is provided pursuant to the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), and describes the categories of personal information Adventure Consortium Inc. ("Rallista," "we," "us") collects about you when you use the Rallista website, mobile apps, and related services, the purposes for which that information is used, and how long it is retained.
Categories of Personal Information Collected
| Category (CCPA §1798.140(v)) | Examples Collected by Rallista | Business Purpose | Retention Period |
|---|---|---|---|
| A. Identifiers | Email address, username, device unique identifier, IP address | Account creation and authentication, error diagnostics, usage analytics | Account data: until account deletion. Device identifiers and analytics: up to 14 months. |
| B. Personal information under Cal. Civ. Code §1798.80(e) | Name (username) | Account profile and display within the app | Until account deletion. |
| D. Commercial information | Subscription plan and transaction identifiers | Subscription management and access to premium features | Duration of subscription. Anonymized on account deletion. |
| F. Internet or other electronic network activity | Usage data, crash reports, browser/device type | App analytics and error diagnostics | Up to 14 months from collection. |
| G. Geolocation data | Precise location (GPS) | Navigation, route calculation, route recording, map centering, event car location sharing | Real-time processing for navigation. Stored only when shared in an event; retained until deletion of associated data or account. |
| H. Sensory data | Photos (profile, car, event, drive) | App functionality and content display | Until deletion of associated data or account. |
| K. Inferences | Driving statistics, app usage patterns | App functionality, understanding feature usage | Driving statistics: until account deletion. Usage analytics: up to 14 months. |
Categories C, E, I, and J as defined under CCPA §1798.140(v) are not collected by Rallista.
Sources of Personal Information
Rallista collects personal information from the following sources:
- Directly from you — when you create an account, update your profile, save drives or events, upload photos, or contact support.
- Automatically from your device — usage data, diagnostic data, device identifiers, and location data collected through the Rallista app and website.
- From third-party payment processors — subscription and transaction identifiers from Apple, Google, and Stripe (Rallista does not receive payment details such as credit card numbers).
Third Parties with Whom Personal Information Is Shared
Rallista shares personal information with the following categories of third parties, solely for the purposes described above:
- Cloud infrastructure and app services — Google Cloud (Firebase) for authentication, data storage, analytics, and error reporting.
- Mapping and geocoding — Stadia Maps for map tiles, geocoding, and place autocomplete.
- Route calculation infrastructure — OVH Cloud (hosting for the Rallista Directions API).
- Payment processors — Apple, Google, and Stripe for subscription and purchase processing.
For specific details, see the Third-Party Services table above.
Sale and Sharing of Personal Information
Rallista does not sell your personal information as defined under the CCPA/CPRA. Rallista does not share your personal information for cross-context behavioral advertising purposes.
Your California Privacy Rights
If you are a California resident, you have the following rights:
- Right to Know. You may request that Rallista disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, the business or commercial purpose for collecting it, and the categories of third parties with whom we share it.
- Right to Delete. You may request that Rallista delete personal information we have collected from you, subject to certain exceptions permitted by law (such as data needed to complete a transaction or comply with a legal obligation).
- Right to Correct. You may request that Rallista correct inaccurate personal information we maintain about you.
- Right to Opt-Out of Sale or Sharing. Rallista does not sell or share your personal information. If this changes, we will provide a clear opt-out mechanism.
- Right to Limit Use of Sensitive Personal Information. You may request that Rallista limit its use of your sensitive personal information (such as precise geolocation) to only what is necessary to provide the services you request.
- Right to Non-Discrimination. Rallista will not discriminate against you for exercising any of your privacy rights. You will not receive different pricing, a different quality of service, or be denied service for exercising your rights.
Rallista will respond to verifiable consumer requests within 45 days of receipt. If we need additional time, we will notify you of the extension and the reason for it. You may submit a request up to twice in a 12-month period.
To verify your identity, we may ask you to confirm information associated with your account, such as your email address.
European Economic Area, United Kingdom, and Switzerland Residents (GDPR / UK GDPR)
If you are located in the EEA, UK, or Switzerland, you have the following additional rights under the General Data Protection Regulation (GDPR) or UK GDPR:
- Right of Access. You may request a copy of the personal data we hold about you.
- Right to Rectification. You may request that we correct any inaccurate or incomplete personal data.
- Right to Erasure. You may request that we delete your personal data, subject to certain legal exceptions.
- Right to Restriction of Processing. You may request that we restrict the processing of your personal data in certain circumstances.
- Right to Data Portability. You may request a copy of your personal data in a structured, commonly used, and machine-readable format, and have it transmitted to another controller where technically feasible.
- Right to Object. You may object to our processing of your personal data based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent. Where processing is based on your consent (such as opting in to car location sharing during events), you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Right to Lodge a Complaint. You have the right to lodge a complaint with a supervisory authority in your country of residence if you believe our processing of your personal data violates applicable law.
Lawful Basis for Processing
Rallista processes your personal data on the following legal bases under the GDPR:
| Processing Activity | Lawful Basis |
|---|---|
| Providing core app functionality (navigation, route storage, events, account management) | Performance of a contract (Article 6(1)(b)) — necessary to provide the services you request. |
| Usage analytics (Firebase Analytics) | Legitimate interest (Article 6(1)(f)) — to understand how the app is used and improve our services. |
| Diagnostic data (Crashlytics) | Legitimate interest (Article 6(1)(f)) — to identify and fix errors. |
| Sending marketing or informational emails about Rallista services | Legitimate interest (Article 6(1)(f)) — to inform existing users about Rallista features and updates. You may opt out at any time by unsubscribing via the link in any marketing email or by contacting us. |
| Processing precise geolocation for navigation and route recording | Performance of a contract (Article 6(1)(b)) — necessary to provide location-based features you request. |
| Real-time car location sharing during events | Consent (Article 6(1)(a)) — you opt in to this feature per event. |
| Subscription and billing management | Performance of a contract (Article 6(1)(b)) and legal obligation (Article 6(1)(c)) — to manage your subscription and comply with financial record-keeping requirements. |
International Data Transfers
All Rallista services are hosted in the United States. If you are located outside the United States, your personal data will be transferred to and processed in the United States.
For transfers of personal data from the EEA, UK, or Switzerland to the United States, Rallista relies on the Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism to ensure an adequate level of protection for your data. Our primary data processor, Google (Firebase), incorporates SCCs into its Firebase Data Processing and Security Terms (https://firebase.google.com/terms/data-processing-terms), which apply automatically to all Firebase services used by Rallista. Our other third-party service providers (Stadia Maps, Stripe, Apple, Google Play) maintain their own international data transfer mechanisms, including SCCs where applicable. Please refer to the Third-Party Services table above for links to each provider's privacy policy and data processing terms.
You may request additional details about our data transfer mechanisms by contacting us at [email protected].
Other US State Privacy Laws
Residents of Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and other states with comprehensive privacy legislation may have similar rights to those described above, including the right to access, delete, and correct personal information, and the right to opt out of targeted advertising, profiling, and sale of personal information. To exercise these rights, please contact us at [email protected].
Managing Your Privacy
Access to Data
To access account data, please log in to the Rallista App. If you would like to download all account data in a portable format, please contact Rallista support at https://rallista.app/feedback.
Manage and Correct Data
You may update your profile information (username, profile photo) directly within the Rallista App. To correct other personal information we hold about you, or to request a full export of your data, please contact Rallista support at https://rallista.app/feedback.
Revoke Consent and Control Your Privacy
You can control your privacy in the following ways:
- Location access. Revoke or modify location permissions for the Rallista App through your device's system settings (iOS: Settings > Privacy & Security > Location Services > Rallista; Android: Settings > Apps > Rallista > Permissions).
- Analytics. You may opt out of Firebase Analytics data collection using the analytics toggle in the Rallista App's settings, or by contacting us at [email protected].
- Notifications. You may manage push notification preferences using the notification toggle in the Rallista App's settings, or through your device's system notification settings.
- Marketing emails. You may unsubscribe from marketing emails at any time by using the unsubscribe link included in every marketing email, or by contacting us at [email protected]. Opting out of marketing emails will not affect transactional or account-related communications.
- Car location sharing. You may stop sharing your car's location during an event at any time within the app.
- Account deletion. You may delete your entire account as described below.
- App removal. You may delete the Rallista app and leave the website at any time.
Cookies
The Rallista website uses cookies as described in the Cookies section above. You can control and manage cookies through your browser settings. Most browsers allow you to view, delete, or block cookies. Common browser cookie settings:
- Safari: Settings > Privacy > Manage Website Data
- Chrome: Settings > Privacy and security > Cookies and other site data
- Firefox: Settings > Privacy & Security > Cookies and Site Data
- Edge: Settings > Cookies and site permissions > Manage and delete cookies and site data
Please note that blocking or deleting cookies may affect your experience on the Rallista website, including your ability to remain logged in.
Complaints
Any complaints about data privacy, collection, or information usage can be submitted to Rallista through https://rallista.app/feedback or directly by email to [email protected]. If you are located in the EEA, you also have the right to lodge a complaint with your local data protection supervisory authority.
Privacy Policy Updates
Rallista maintains the right to update its Privacy Policy at any time. If we make material changes to this Privacy Policy, we will notify you by email (sent to the email address associated with your account) or through an in-app notification before the changes take effect. We encourage you to review this policy periodically for any non-material updates.
Deleting Account
The Rallista App allows you to completely delete your account from within the app's settings. Account deletion requires password re-authentication. You may also request account deletion by contacting Rallista support at https://rallista.app/feedback or by email at [email protected]. All data directly associated with your account will be deleted with some exceptions. Exceptions include any historic billing information (e.g., previously completed invoices) and completed events that other user accounts reference (e.g., an event that another user participated in and saved their route). If you have additional questions or concerns, please contact Rallista support at https://rallista.app/feedback.
Children's Privacy
Rallista is not directed at children under the age of 13 (or under 16 in the EEA). We do not knowingly collect personal information from children under these ages. Our Terms of Use require users to be at least 18 years of age. If we learn that we have collected personal information from a child under the applicable age, we will take steps to delete that information promptly. If you believe that a child under the applicable age has provided personal information to Rallista, please contact us at [email protected].
Updated May 22, 2026