Privacy Policy

DAGAR Ltd (SIA) · Riga, Latvia · Version 1.1 · Effective 3 August 2026 · Contact: hello@crossaware.com
The short version: CrossAware compares your position against our danger-zone database and lowers your media volume in real time, on your device. We do not keep a continuous trail of where you go. We do store a short log of the moments you enter or leave a danger zone (the zone and the time, linked to your account, but not your coordinates) so you can see your own activity history. That log is automatically deleted after 90 days, and you can export or delete it yourself at any time in the app.

1. Who we are

CrossAware is a safety application operated by DAGAR Ltd (SIA), a company registered in Riga, Latvia. We are the data controller for the personal data described in this policy. For any privacy question or request, write to hello@crossaware.com.

2. What data we collect — and what we deliberately don't

CrossAware is built on a privacy-by-design principle: the app's core function — comparing your position against our danger-zone database (railway crossings and dangerous intersections in Riga) and reducing media volume — runs entirely on your device. Because of this architecture, we collect far less than a typical location app:

DataWhere it is storedWhy we need itHow long we keep it
Account e-mail and an encrypted (hashed) passwordSupabase database, hosted in the EUSign-in and subscription managementUntil you delete your account, plus 30 days in backups
Continuous real-time GPS position (while monitoring is active)Your device only — the continuous stream is never uploadedDetecting proximity to danger zonesNot stored; processed in memory and discarded
Danger-zone entry/exit events — the zone, whether you entered or left, and the time, linked to your account (we do not store the GPS coordinates of the crossing)Supabase database, hosted in the EUShowing your in-app activity log and recent safety statisticsAutomatically deleted 90 days after the event. You can also export or delete this history yourself in the app at any time
Waitlist e-mail (if you signed up on crossaware.com)Website form providerOne launch notificationDeleted after the launch campaign, or immediately on request
Payment detailsStripe (PCI-DSS certified processor)Paid subscriptionsPer Stripe's policy — we never see or store your card number

We do not collect: a continuous trail of your movements, your name, your contacts, microphone or camera data, or any advertising identifiers. We log only the discrete moments you cross into or out of a danger zone (see the table above) — not where you are the rest of the time. The background location permission Android asks for is used on your device to detect those crossings; the continuous position stream itself is never sent to us.

3. How we store and protect your data

4. Legal bases for processing (GDPR Article 6)

We process account data and your danger-zone entry/exit history to perform our contract with you — providing the safety service and the in-app activity log and statistics. In line with data minimization, that history is kept for a limited 90-day window and then deleted automatically. We send the waitlist launch e-mail based on your consent, which you can withdraw at any time by replying "unsubscribe".

5. Your rights, including deletion

Under the GDPR you have the right to access, correct, delete or export your personal data, to restrict or object to its processing, and to withdraw consent. To export or delete just your location history: open Settings → Data & Privacy in the app, where you can download it as a file or delete it instantly. To delete your whole account: use "Delete account" inside the app, or e-mail hello@crossaware.com from your registered address — we confirm and complete deletion within 30 days, including backups within a further 30 days. You may also lodge a complaint with the Latvian Data State Inspectorate (dvi.gov.lv) or your local supervisory authority.

6. Children

CrossAware is designed to be set up and supervised by a parent or guardian, typically for a school-age child, and includes a parental PIN lock so a child cannot disable safety monitoring. Where a user is below the age of digital consent, the supervising parent or guardian is responsible for providing that consent on the child's behalf (GDPR Article 8). A child's account follows exactly the same privacy model as any other account — we never collect more data from a minor.

7. Changes to this policy

We will post any updates on this page. For material changes we will additionally notify you in the app or by e-mail before they take effect.