Privacy Policy

Last Updated: January 6, 2026

1. Introduction and Purpose

This Privacy Policy describes how HitchGuardian ("we," "us," "our," or "Company") collects, uses, discloses, retains, and otherwise processes personal information when you use our application (the "App"), website, and associated services (collectively, the "Services"). We are committed to protecting your privacy and ensuring you have a positive experience on our App. This Privacy Policy complies with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's Anti-Spam Legislation (CASL), provincial privacy laws, and internationally recognized privacy standards including GDPR, CCPA/CPRA, and Australian Privacy Act requirements.

Please read this Privacy Policy carefully. By accessing or using the Services, you acknowledge that you have read, understood, and agree to the practices described herein. If you do not agree with our privacy practices, please do not use the Services.

2. Canadian Privacy Compliance Framework

2.1 PIPEDA Compliance

This App is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal privacy legislation. We comply with PIPEDA's ten fair information principles:

  1. Accountability: We have designated a Privacy Officer responsible for our privacy practices and compliance with PIPEDA.
  2. Identifying Purposes: We clearly identify the purposes for which personal information is collected before or at the time of collection.
  3. Consent: We obtain your knowledge and consent before collecting, using, or disclosing personal information, except where inappropriate.
  4. Limiting Collection: We collect only the personal information necessary for the identified purposes.
  5. Limiting Use, Disclosure, and Retention: We use and disclose personal information only for the purposes for which it was collected and retain it only as long as necessary.
  6. Accuracy: We maintain personal information in as accurate, complete, and up-to-date form as necessary.
  7. Safeguards: We protect personal information against loss, theft, unauthorized access, disclosure, copying, use, or modification using appropriate security measures.
  8. Openness: We make detailed information about our privacy policies and practices readily available to users.
  9. Individual Access: Upon request, we provide individuals with access to their personal information and allow them to challenge its accuracy and completeness.
  10. Challenging Compliance: We establish procedures for individuals to challenge our compliance with these principles.

2.2 CASL Compliance

Any commercial electronic messages, including promotional emails, SMS messages, or in-app notifications, are sent only to individuals who have provided express, opt-in consent. We provide a clear, functioning unsubscribe mechanism in all commercial messages, and we honor opt-out requests within 10 business days. We do not harvest electronic addresses or use harvested contact information obtained from third parties for sending commercial messages.

2.3 Provincial Privacy Laws

We comply with applicable provincial privacy laws, including Ontario's Consumer Protection Act, 2023, British Columbia's Personal Information Protection Act (PIPA), Alberta's Personal Information Protection Act (PIPA), and Quebec's Law 25 (An Act to modernize legislative provisions as regards the protection of personal information).

3. Information We Collect

We collect personal information through various means to provide and improve the Services. The types of information we collect include:

3.1 Information You Provide Directly

Account Registration Information: When you create an account, we collect information such as your name, email address, phone number, postal address, date of birth, username, password, profile picture, and other information you choose to provide.

Profile and Preference Information: Information you voluntarily provide when setting up your profile, including your interests, preferences, language preferences, communication preferences, and other optional profile details.

Payment Information: If you make purchases, we collect information related to your transaction, including the products or services purchased, purchase amount, transaction date, and your payment method. Payment information is processed by third-party payment processors (such as Apple, Google, Stripe, or PayPal) and we do not store complete credit card information.

Communication: We collect information you provide when you communicate with us, including customer support inquiries, feedback, complaints, reviews, testimonials, and any attachments or documents you provide.

User-Generated Content: If the App allows you to upload, post, or share content (text, images, videos, comments), we collect and store this User-Generated Content along with metadata such as when you posted it and who it was shared with.

Survey and Form Responses: Information you provide when participating in surveys, questionnaires, contests, or other promotional activities.

3.2 Information Collected Automatically

Device Information: Information about your device, including device type (smartphone, tablet, computer), operating system version, unique device identifiers, device settings, mobile network information, and device manufacturer and model.

Log Data: Information automatically logged when you use the App, including:

  • IP address
  • The date and time of your access
  • Pages or features accessed and the duration of use
  • The source of traffic (how you accessed the App)
  • Search queries
  • Clicks and interactions within the App
  • Error logs and crash reports

Location Information: Depending on your device settings and App permissions, we may collect approximate location based on IP address. If you grant location permission, we collect precise GPS location data. Location information is used to provide location-based features and services.

Cookies and Similar Tracking Technologies: We use cookies (small text files stored on your device), web beacons, pixel tags, local storage, and similar technologies to recognize you and remember your preferences, track usage patterns and behavior, enable certain App features, analyze App performance and usage, deliver targeted content and advertisements, and prevent fraud. You can control cookie preferences through your browser or device settings, though some features may not work without them.

Analytics: We use analytics services (such as Google Analytics, Firebase, Mixpanel, or similar) to understand how users interact with the App, which features are used, how long sessions last, and general usage patterns. These analytics services may collect device information, usage data, and may use cookies or other tracking technologies.

Push Notifications: If you enable push notifications, we collect information about your device to deliver notifications. You can disable notifications in your device settings.

3.3 Information from Third Parties

Third-Party Services: If you choose to connect your account with third-party services (such as social media accounts like Facebook, Google, or Apple), we receive information that those services share with us in accordance with their authorization procedures, which may include your name, email address, profile picture, and other publicly available information.

Business Partners: We may receive information from our business partners, service providers, and other organizations with which we collaborate, in accordance with their privacy policies and applicable law.

Public Sources: We may collect information about you from publicly available sources to verify information or enhance your profile.

4. How We Use Your Information

4.1 Service Delivery and Improvement

  • Creating and maintaining your account
  • Delivering the Services and features you requested
  • Personalizing your experience and customizing the App to your preferences
  • Processing transactions and sending related confirmations
  • Providing customer support and responding to inquiries
  • Troubleshooting, debugging, and maintaining the App
  • Updating and improving App features, functionality, and performance
  • Conducting testing and quality assurance
  • Analyzing usage patterns to understand how users interact with the App

4.2 Communication

  • Sending account-related notifications (password resets, account verification, terms updates)
  • Sending service announcements and important notices
  • Responding to your requests, inquiries, or complaints
  • Sending marketing communications (only with your explicit consent)
  • Notifying you of changes to our Services or policies
  • Sending push notifications (only if you have enabled them)

4.3 Analytics and Research

  • Analyzing usage trends, user demographics, and engagement patterns
  • Measuring App performance and user experience
  • Conducting research to improve the Services
  • Creating anonymized, aggregated reports and statistics
  • Understanding user behavior to develop new features

4.4 Security and Legal Compliance

  • Protecting against fraud, abuse, and unauthorized access
  • Enforcing our Terms and Conditions and other agreements
  • Complying with legal obligations and law enforcement requests
  • Protecting our rights, privacy, safety, and property
  • Preventing and detecting illegal activity, fraud, or unauthorized use
  • Defending against legal claims and litigation
  • Complying with court orders, subpoenas, or government investigations

4.5 Marketing and Advertising

  • Sending promotional materials, special offers, and marketing communications (only with your consent)
  • Personalizing advertisements and content based on your interests and behavior
  • Conducting targeted advertising campaigns
  • Measuring the effectiveness of marketing campaigns

4.6 Sensitive Data Special Handling

If you provide sensitive personal information, such as health information, financial information, or information about protected grounds under human rights legislation (race, ethnic origin, religion, political views, sexual orientation), we process this information only with your explicit consent and take additional security measures to protect it.

5. Legal Basis for Processing (Canadian Framework)

Under PIPEDA, we process personal information based on the following grounds:

  • Consent: You have provided explicit, informed consent for collection, use, or disclosure.
  • Contractual Necessity: Processing is necessary to perform our obligations under an agreement with you.
  • Legal Obligation: Processing is required by law (e.g., tax requirements, legal holds).
  • Legitimate Interests: Processing is necessary for our legitimate business interests (e.g., fraud prevention, security, customer service) that do not override your rights.
  • Protection of Vital Interests: Processing is necessary to protect your or another person's vital interests.

You have the right to withdraw consent for consent-based processing at any time, though this will not affect the lawfulness of processing conducted before withdrawal.

6. Sharing and Disclosure of Information

We may share your personal information with the following categories of recipients:

6.1 Service Providers and Processors

We share information with third-party service providers who perform functions on our behalf, including:

  • Payment Processors: Companies like Apple, Google, Stripe, PayPal, or similar payment platforms that process payments and financial transactions
  • Analytics Providers: Companies like Google Analytics, Firebase, Mixpanel, or Amplitude that analyze usage data
  • Cloud Services: Amazon Web Services (AWS), Google Cloud, Microsoft Azure, or similar providers that host our servers and databases
  • Communication Services: Email service providers, SMS providers, push notification services (Firebase Cloud Messaging, Apple Push Notification Service)
  • Customer Support: Help desk and customer support platforms (Zendesk, Intercom, Freshdesk)
  • Marketing Services: Email marketing platforms, advertising networks, and customer relationship management (CRM) systems
  • Security Services: Companies that provide fraud detection, cybersecurity, and data protection services

All service providers are contractually bound to use your information only as necessary to provide services to us, to implement appropriate security measures, and to comply with PIPEDA and other applicable privacy laws. We have Data Processing Agreements in place with all processors that handle personal information.

6.2 Third-Party Integration

If you authorize us to share data with third-party services (such as social media platforms, calendar services, or productivity tools), we share information as authorized by you. Your use of these third-party services is subject to their privacy policies and terms of service.

6.3 Legal Requirements and Law Enforcement

We may disclose personal information when required by law or when we believe, in good faith, that disclosure is necessary to:

  • Comply with court orders, subpoenas, warrants, or other legal processes
  • Enforce our Terms and Conditions and other agreements
  • Protect our rights, privacy, safety, or property
  • Prevent fraud or illegal activity
  • Respond to government or law enforcement requests
  • Protect against legal liability

When legally permitted, we will provide notice to affected individuals of government requests for their information.

6.4 Business Transfers

If HitchGuardian is involved in a merger, acquisition, bankruptcy, dissolution, reorganization, or similar transaction or proceeding, your personal information may be transferred as part of that transaction. We will provide notice of any such change and any choices you may have regarding your information.

6.5 Aggregated and De-Identified Information

We may share aggregated, anonymized, or de-identified data that cannot reasonably be linked back to you with third parties for research, marketing, analytics, and other purposes without restriction.

6.6 Public Sharing

If the App allows you to publicly share User-Generated Content, this content may be accessible to other users of the App and potentially to the public internet, depending on your privacy settings.

We do not sell personal information to third parties for their independent use as a primary business practice. Any sharing of information is as described in this policy or as authorized by you.

7. Data Retention and Deletion

7.1 Retention Periods

We retain personal information for the period necessary to fulfill the purposes for which it was collected, unless a longer retention period is required by law. Specific retention periods for different types of information are:

  • Account Information: Retained while your account is active and for a reasonable period afterward for business purposes. Upon account deletion, we delete or anonymize your account information within 30 days, except where retention is required by law.
  • Transaction Information: Retained for a minimum of 7 years to comply with Canadian tax and financial regulations.
  • Communication Logs: Retained for 3 years or as required for dispute resolution.
  • Cookies and Tracking Data: Retained for up to 13 months, or as specified in our Cookie Policy.
  • Analytics Data: Aggregated analytics data is retained indefinitely; personal analytics data is retained for 26 months.
  • Backup Data: Retained in our backups for up to 90 days for disaster recovery purposes.

7.2 Deletion Requests

You have the right to request deletion of your personal information, subject to certain exceptions:

  • Legal Hold: We cannot delete information subject to a legal hold, pending litigation, or regulatory investigation.
  • Contractual Obligations: We may retain information necessary to fulfill our contractual obligations.
  • Statutory Requirements: We must retain certain information to comply with law (e.g., tax records, financial records).
  • Legitimate Interests: We may retain information necessary for fraud prevention, security, or defending legal claims.

To request deletion, contact our Privacy Officer at the information provided in Section 13.

7.3 Secure Destruction

When information is deleted, it is securely destroyed using methods appropriate to the sensitivity of the information, such as:

  • Overwriting with random data
  • Physical destruction of storage media
  • Encryption key deletion (for encrypted data)
  • Anonymization or de-identification

8. User Rights and Choices

8.1 Access and Portability

Right to Access: You have the right to request access to the personal information we hold about you. We will provide you with a copy of your information in a clear, understandable format within 30 days of your request (or as required by law).

Right to Data Portability: You have the right to receive a copy of your personal information in a structured, commonly used, machine-readable format and to transmit that data to another organization where technically feasible.

To exercise these rights, contact our Privacy Officer at the information provided in Section 13.

8.2 Correction and Amendment

Right to Correct: You have the right to request correction of inaccurate or incomplete information. We will correct information and notify other parties to whom the information has been disclosed (where applicable) within 30 days.

You can also correct some information directly by updating your account settings.

8.3 Withdrawal of Consent

For any processing based on your consent, you have the right to withdraw consent at any time. Withdrawal of consent will not affect the lawfulness of processing conducted before withdrawal, but will stop further processing based on that consent.

To withdraw consent, contact us at the information provided in Section 13 or adjust your privacy settings in the App.

8.4 Communication Preferences

You can manage your communication preferences by:

  • Adjusting notification settings within the App
  • Clicking "Unsubscribe" links in marketing emails
  • Disabling push notifications in your device settings
  • Opting out of analytics and tracking by using your browser's "Do Not Track" feature or by contacting us
  • Using your device's advertisement preference settings to limit personalized advertising

8.5 Cookie Control

On your first visit to our website, we show a consent banner before any analytics or tracking cookies load. Nothing is set until you make a choice. If you click Decline, or simply leave without deciding, no analytics scripts are loaded. If you click Accept, we load Google Analytics and Vercel Analytics to understand which pages help operators. You can change your decision at any time by clicking the "Manage cookies" link in the footer, which clears your stored choice and re-presents the banner. You can also control cookies through your browser settings:

  • Most browsers allow you to refuse cookies or alert you when cookies are being sent
  • Disabling cookies may affect App functionality
  • Visit www.allaboutcookies.org for more information on managing cookies across different browsers

8.6 Location Services

You can control location information collection through:

  • Device location settings (iOS Settings > Privacy > Location Services)
  • App-level location permissions
  • GPS, Bluetooth, and WiFi can be toggled in device settings

8.7 Deletion of Account and Data

You can request complete deletion of your account, which will result in:

  • Deletion of your account information
  • Anonymization of any public content you posted
  • Removal of your access to the Services

Note that some information may be retained as described in Section 7.

9. International Data Transfers

9.1 Cross-Border Transfers

The App may store, process, or transfer your personal information to servers and facilities located in the United States, Canada, or other countries where we or our service providers operate. When personal information is transferred across borders, we implement appropriate safeguards to protect your information, including:

  • Standard Contractual Clauses (SCCs): Contractual agreements approved by the European Commission for GDPR compliance
  • Binding Corporate Rules (BCRs): For transfers within our corporate group
  • Adequacy Determinations: Where applicable
  • Explicit Consent: Your informed consent to cross-border transfer

By using the Services, you consent to the transfer of your information to jurisdictions outside of Canada.

9.2 Third-Country Transfers

We ensure that any third-party service providers in jurisdictions outside Canada are subject to legal frameworks providing adequate data protection or have entered into adequate contractual safeguards (Data Processing Agreements with Standard Contractual Clauses).

10. Data Security

10.1 Security Measures

We implement comprehensive technical, administrative, and physical security measures appropriate to the sensitivity of the personal information, including:

Technical Safeguards:

  • Encryption of data in transit using TLS/SSL protocols (minimum 256-bit encryption)
  • Encryption of sensitive data at rest using AES-256 encryption
  • Secure password hashing (bcrypt, scrypt, or similar)
  • Regular security updates and patches
  • Web application firewalls and intrusion detection systems
  • Secure API authentication (OAuth 2.0, API keys)

Administrative Safeguards:

  • Access controls limiting employee access to personal information on a need-to-know basis
  • Confidentiality agreements with all employees and contractors
  • Regular privacy and security training for employees
  • Audit trails and logging of access to personal information
  • Privacy by design principles in product development

Physical Safeguards:

  • Secured data center facilities with controlled access
  • Video surveillance and security personnel
  • Locked storage for physical documents containing personal information
  • Environmental controls (temperature, humidity, fire suppression)

10.2 Data Breach Notification

In the event of a data breach that poses a real risk of significant harm to individuals, we will:

  1. Notify affected individuals as soon as feasible, but without undue delay
  2. Notify the Office of the Privacy Commissioner of Canada (OPC)
  3. Provide information about the breach, steps taken to mitigate harm, and measures individuals can take to protect themselves
  4. Maintain records of all breaches for 24 months

Notifications will include:

  • Description of the breach circumstances
  • Date or approximate period of the breach
  • Description of personal information involved
  • Number of individuals affected
  • Steps we have taken to reduce risk of harm
  • Steps individuals can take to protect themselves
  • Contact information for further inquiries

10.3 Your Security Responsibility

While we implement strong security measures, no system is completely secure. You are responsible for:

  • Protecting your password and login credentials
  • Not sharing your account with others
  • Logging out of your account when using shared devices
  • Monitoring your account for unauthorized activity
  • Reporting suspected security breaches to us immediately
  • Keeping your device software and applications updated

11. Children and Minors

11.1 Age Requirements

The Services are not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we discover that we have collected information from a child under 13, we will delete such information immediately and may terminate the child's account.

For users under 18, we comply with enhanced protections, including:

  • Parental consent verification for users under 18 (where required)
  • Limiting collection to information necessary for the Services
  • Not using personal information from minors for behavioral advertising
  • Providing enhanced controls over User-Generated Content
  • Not disclosing personal information to third parties without consent

11.2 Parental Involvement

Parents or guardians of users under 18 may contact us to review information we have collected, request deletion of their child's information, refuse further collection or use of their child's information, or revoke consent previously provided. Contact information is provided in Section 13.

12. Third-Party Services and Links

12.1 Third-Party Privacy Policies

The App may integrate with or link to third-party services, including social media platforms, payment processors, analytics services, and external websites. These third-party services have their own privacy policies and terms of service, and we are not responsible for their privacy practices. We encourage you to review their privacy policies before providing your information.

Third-party services we use include:

  • Google Analytics / Google Cloud
  • Amazon Web Services (AWS)
  • OpenAI
  • Grid-Atlas
  • Apple App Store / Apple Pay
  • Google Play Store / Google Pay

12.2 Social Media Features

If the App includes social media features (such as login with Facebook, Google, or Apple), these features may collect your information including IP address, the page you visited, and set cookies, even if you do not have an account with that service. Social media companies' privacy policies govern their collection and use of this information.

12.3 External Links

The App may contain links to external websites. We do not endorse, control, or have responsibility for these websites. Your access to external sites is at your own risk and subject to their terms and conditions.

13. Contact Information and Privacy Officer

If you have questions, concerns, or complaints about this Privacy Policy or our privacy practices, or wish to exercise any of your rights, please contact:

Privacy Officer

HitchGuardian

Email: [email protected]

Mailing Address: Calgary, Alberta, Canada

Phone: +1 587 343 6183

Website: www.hitchguardian.me

Office Hours: Mon - Fri 09:00 - 16:00

Response Time: We will respond to all inquiries within 30 days of receipt.

For data access requests, deletion requests, or other formal rights requests, we may ask you to verify your identity and may request reasonable fees to cover costs of providing information (though access is typically provided at minimal or no cost).

Escalation and Complaint Process

  1. Request escalation to our Privacy Officer for further review
  2. File a complaint with the Office of the Privacy Commissioner of Canada (OPC):

    Website: www.priv.gc.ca

    Phone: 1-888-773-8100

    Mail: Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau, QC K1A 1H2

If you are in a province with a provincial privacy commissioner (Quebec, Ontario, Alberta, BC), you may also file a complaint with your provincial commissioner.

14. International Privacy Compliance

14.1 GDPR Compliance (EU, UK, Switzerland, Iceland, Liechtenstein, Norway)

If you are a resident of the European Union, United Kingdom, Switzerland, Iceland, Liechtenstein, or Norway, the following additional terms apply:

Legal Basis for Processing: We process personal information on the following lawful bases:

  • Consent: Where you have provided explicit, informed consent
  • Contract: Where processing is necessary to perform services
  • Legal Obligation: Where required by EU/Member State law
  • Vital Interests: Where necessary to protect vital interests
  • Public Task: Where necessary for performance of tasks in the public interest
  • Legitimate Interests: Where our interests don't override your rights

Your GDPR Rights:

  • Right to access your personal data
  • Right to rectification (correction) of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent
  • Rights related to automated decision-making and profiling
  • Right to lodge a complaint with your supervisory authority

International Transfers: We transfer personal data from the EU using appropriate safeguards including Standard Contractual Clauses and ensuring your data is protected to an equivalent standard.

Data Protection Officer: For EU residents, contact our Data Protection Officer at [email protected]

Supervisory Authority: You have the right to lodge a complaint with your competent supervisory authority. For EU residents, contact your national Data Protection Authority.

14.2 CCPA/CPRA Compliance (California)

If you are a California resident, the following additional rights apply:

Consumer Rights:

  • Right to know: What personal information is collected, used, and shared
  • Right to delete: Personal information we have collected from you (with exceptions)
  • Right to opt-out: Of the sale or sharing of personal information
  • Right to limit: Use of sensitive personal information
  • Right to non-discrimination: You will not be discriminated against for exercising your rights

Exercising Rights: To exercise any of these rights, contact us at [email protected] or through https://www.hitchguardian.me/ccpa. We will respond within 45 days.

Shine the Light Law: California residents can request information about sharing of personal information with third parties for their direct marketing purposes.

Do Not Sell or Share My Personal Information: Click [HERE] to opt-out of the sale or sharing of your personal information.

14.3 Australian Privacy Act Compliance

If you are an Australian resident, we comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Your Rights:

  • Right to access your personal information
  • Right to request correction of inaccurate information
  • Right to complain about breaches of the APPs
  • Right to request we not hold personal information
  • Right to be given reasons for decisions made about you using personal information

Complaint Process: File a complaint with the Office of the Australian Information Commissioner (OAIC):

Website: www.oaic.gov.au

Phone: 1300 363 992

14.4 Other Jurisdictions

We comply with privacy laws in all jurisdictions where we operate, including:

  • Singapore Personal Data Protection Act
  • New Zealand Privacy Act
  • Japan Act on the Protection of Personal Information (APPI)
  • South Africa Protection of Personal Information Act (POPIA)

15. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:

  1. Posting the updated policy on the App and website with a new "Last Updated" date
  2. Sending you an email notification of significant changes
  3. Requesting your consent where required by law

Your continued use of the Services following notification of changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this policy periodically to stay informed about how we protect your information.

16. Canadian-Specific Provisions

16.1 Accountability

We have designated a Privacy Officer responsible for our compliance with PIPEDA and other privacy laws. Our Privacy Officer oversees privacy practices, responds to privacy inquiries, and conducts regular privacy audits.

16.2 Privacy Impact Assessments

Before implementing new technologies or processing personal information in new ways that may impact privacy, we conduct Privacy Impact Assessments (PIAs) to identify and mitigate privacy risks.

16.3 Complaints and Dispute Resolution

If you have a privacy complaint, we encourage you to contact us directly first. If we cannot resolve your concern, you may file a complaint with the Office of the Privacy Commissioner of Canada.

16.4 Business Contact Information Exemption

This Privacy Policy does not apply to business contact information (such as business name, business address, business phone number, business email) collected, used, or disclosed solely for the purpose of contacting a person in their professional capacity in relation to their employment, profession, or business.

Effective Date: January 6, 2026

Version: 1.0

Language: English

For questions about this Privacy Policy, contact our Privacy Officer at [email protected].