Privacy Policy

DAGAR Ltd (SIA) · Riga, Latvia · Version 1.0 · Effective 15 July 2026 · Contact: hello@crossaware.com
The short version: your location never leaves your phone. CrossAware detects danger zones and lowers your media volume entirely on your device. On our servers we keep only your account e-mail and anonymous safety statistics — never your GPS trail.

1. Who we are

CrossAware is a safety application operated by DAGAR Ltd (SIA), a company registered in Riga, Latvia. We are the data controller for the personal data described in this policy. For any privacy question or request, write to hello@crossaware.com.

2. What data we collect — and what we deliberately don't

CrossAware is built on a privacy-by-design principle: the app's core function — comparing your position against our danger-zone database (railway crossings and dangerous intersections in Riga) and reducing media volume — runs entirely on your device. Because of this architecture, we collect far less than a typical location app:

DataWhere it is storedWhy we need itHow long we keep it
Account e-mail and an encrypted (hashed) passwordSupabase database, hosted in the EUSign-in and subscription managementUntil you delete your account, plus 30 days in backups
Real-time GPS positionYour device only — never uploadedDetecting proximity to danger zonesNot stored; processed in memory and discarded
Anonymous usage events (which mapped zone triggered an alert, and when — with no coordinate trail and no identity attached)Supabase analytics tables (EU)Measuring that the product works and pruning zones that produce false alarms24 months, then aggregated into statistics
Waitlist e-mail (if you signed up on crossaware.com)Website form providerOne launch notificationDeleted after the launch campaign, or immediately on request
Payment detailsStripe (PCI-DSS certified processor)Paid subscriptionsPer Stripe's policy — we never see or store your card number

We do not collect: your continuous location or movement history, your name, your contacts, microphone or camera data, or any advertising identifiers. The background location permission Android asks for is used exclusively on your device — it does not mean your location is sent to us.

3. How we store and protect your data

4. Legal bases for processing (GDPR Article 6)

We process account data to perform our contract with you (providing the safety service). We process anonymous usage events under our legitimate interest in keeping the danger-zone database accurate and the product functional. We send the waitlist launch e-mail based on your consent, which you can withdraw at any time by replying "unsubscribe".

5. Your rights, including deletion

Under the GDPR you have the right to access, correct, delete or export your personal data, to restrict or object to its processing, and to withdraw consent. To request deletion: use "Delete account" inside the app, or e-mail hello@crossaware.com from your registered address — we confirm and complete deletion within 30 days, including backups within a further 30 days. You may also lodge a complaint with the Latvian Data State Inspectorate (dvi.gov.lv) or your local supervisory authority.

6. Children

CrossAware is often used by school-age children whose parents purchase the subscription. Users under 16 need a parent's or guardian's consent, which we request during signup (GDPR Article 8). Child accounts follow exactly the same on-device privacy model as adult accounts — we never collect more data from a minor.

7. Changes to this policy

We will post any updates on this page. For material changes we will additionally notify you in the app or by e-mail before they take effect.