The shortest accurate version.
- The free drive record, Garage, one vehicle, local history, and privacy controls can work without an account.
- Precise routes and vehicle history begin as private local records. Current source can automatically enable hosted writes after sign-in plus Pro entitlement, but that path must remain blocked until Trace adds an affirmative sync opt-in before the first upload.
- Trace currently has no advertising SDK, analytics SDK, session replay, data-broker integration, or cross-company tracking.
- Trace does not currently sell personal information or use it for targeted advertising.
- Trace will not sell or license identifiable or precise driving and location data to data brokers, advertisers, insurers, or employers.
- Deleting a local record, a Trace account, an Apple subscription, or a copy already saved by someone else are separate actions.
Vex Technologies Inc. is responsible for this Policy.
- Controller; CCPA business where applicable
- Vex Technologies Inc.
- Formation
- New York, United States
- Privacy contact
- support@builtbyvex.com
- Mailing address
- Pending public legal-notice address
In this Policy, “Trace,” “Vex,” “we,” “us,” and “our” refer to Vex Technologies Inc. as the operator of Trace and the controller or organization responsible for the processing described here, except where another party acts independently under its own notice. Vex is a “business” under the CCPA only where that law and its statutory applicability thresholds apply.
This Policy covers the Trace app, website, and linked services.
This Policy applies to the Trace iPhone app, the Trace product pages and legal or support materials hosted on the Vex-branded website, and related Trace services that link to it. It does not govern unrelated Vex products or general company pages unless they expressly link to this Policy. Section 6 adds website-specific details for the Vex contact form; the applicable recipient, retention, security, rights, and contact sections also govern that processing. This Policy does not control an independent third-party service or destination you choose, such as Apple, Google, a message recipient, a social network, or a file host.
Intelligence and AI mechanic features are excluded from the active product and this Policy. If they are reintroduced, Trace must identify the provider, inputs, purpose, retention, human-review rules, and safety boundaries before collection begins.
The local record can be detailed and sensitive.
Depending on the features you use, Trace can process and store locally:
| Category | Examples | Default |
|---|---|---|
| Vehicle and Garage | Year, make, model, trim, chassis, engine, VIN, odometer, photos, modifications, costs, receipt references, maintenance, milestones, build plans, and configuration history. | Private local |
| Trips and location | Precise route coordinates, timestamps, distance, duration, speed, elevation, stops, titles, notes, weather or place context, and the vehicle configuration attached to the drive. | Begins private local; hosted transfer requires an approved affirmative sync opt-in |
| Motion and telemetry | Sensor-derived samples, reduced telemetry projections, derived events, confidence states, and recording-quality information. Raw Core Motion samples are generally processed in memory. | Private local |
| Recovery and settings | Active-drive journals, privacy-zone coordinates, units, permissions explanations, notification preferences, policy acceptance, and withdrawal state. | Private local |
| Setup and profile state | Optional phone number, display or profile fields, acquisition source, and whether Contacts access was requested or granted. Current source stores a phone number locally but does not use it for a verified account-recovery service. | Private local; purpose requires release review |
| Media and documents | Vehicle photos, screenshots, imported video, rendered cards or video, OCR candidate text, and temporary export files. | Private local; user-directed export |
| Local account state | Account namespace, queued sync operations, entitlement state, and authentication session material protected through the app and Keychain paths. | Private local |
Demo and UI-test data is isolated and not eligible for production upload or public publishing. The local database is the immediate source of truth for the free core.
Current source can enable sync without a separate sync switch.
In the audited source, an account, writable namespace, and Pro entitlement can enable eligible hosted writes and promote existing eligible local records automatically. No separate sync-consent flag is mounted. That behavior is not approved for launch. Trace must add an affirmative, purpose-specific sync opt-in before the first hosted transfer—especially for precise routes or other sensitive data—and give accurate, just-in-time notice before entitlement or sign-in can cause an upload. Hosted data can include:
- account UUID, email, display name, handle, sign-in provider, session state, and notification endpoint;
- eligible profile, vehicle, configuration, modification, maintenance, milestone, Garage media and event, finalized trip summary, private route-point chunk, and sync records; durable local 4 Hz telemetry is not listed as a hosted data path in the audited map;
- eligible locally retained mechanic-case records if legacy or dormant source paths can queue them, even though mechanic features are excluded from the active product;
- profile, friendship, block, activity, public-card, leaderboard-consent, bounded board, referral, and report records;
- direct-message content and metadata; messages are not represented as end-to-end encrypted;
- private media placed in an authorized storage bucket and accessed through authenticated downloads; older builds or caches may have used bearer-style signed links and require migration review; and
- account-deletion request state and the minimum approved audit evidence needed to complete it.
Optional cloud copies do not replace local authority. Current source can automatically promote eligible local records when a person is signed in with a writable namespace and has Trace Pro; no separate hosted-sync switch is mounted. That path requires an affirmative, purpose-specific disclosure before the first hosted transfer and must be reconciled with the release build. Friends and Leaderboards are mounted in the audited shell, including a readable user-caption feed; direct messages and public vehicle-card presentation are not mounted. Hosted, social, and deletion paths remain external release gates until deployed, isolated between accounts, monitored, and tested.
The current marketing site does not set tracking cookies.
The Vex-branded website that hosts these Trace materials includes a contact form. When you submit it, the endpoint receives your name, email address, optional organization, inquiry type, message, and a hidden anti-bot field. It uses the hidden field locally to reject automated submissions; a filled field returns a neutral response without delivery. Only valid visible submission fields are passed to Resend for delivery to the configured Vex recipient. If delivery is not configured or fails, the form reports that messaging is unavailable.
The Vex application code does not store a submitted message in an application database or send an automatic confirmation to the visitor. Resend and the receiving email system may retain delivered message data under their own operational and legal requirements. Vex Technologies Inc. is the operator. Receiving-email retention and deletion periods remain subject to final operational approval in Section 13.
Hosting and network providers may process ordinary request data such as IP address, timestamp, requested URL, user agent, referrer, and diagnostic logs. After a valid non-bot submission, the endpoint derives a truncated SHA-256 hash from the apparent network address and stores it in a process-memory rate-limit map for abuse prevention. The endpoint enforces a ten-minute window; expired entries are removed when a later valid submission triggers cleanup, and a process restart clears the map. An expired entry can remain in an idle warm process until either event occurs.
The current Vex website has no advertising tags, analytics service, session replay, or non-essential cookies. Browser session storage is used only to coordinate the visual transition between internal pages; it is not used to profile visitors or measure advertising. Any future analytics, advertising, or non-essential tracking requires a new data-map and privacy review before activation.
Information comes from you, your device, and selected providers.
- From you: information you enter, upload, import, publish, message, report, or send to support.
- From your device: location, motion, app state, device and OS information, permissions, notifications, and bounded diagnostics.
- From Apple or Google: sign-in identity you authorize, StoreKit product and verified entitlement state, and system service results.
- From optional services: authorized account, sync, social, public-card, referral, messaging, moderation, and delivery results.
- Derived by Trace: trip summaries, route projections, configuration snapshots, confidence states, aggregate cells, board facts, and other calculations needed for features you use.
Trace uses data to provide, protect, and support chosen features.
- record, recover, organize, display, compare, export, and share drives and vehicle history;
- authenticate accounts, keep account namespaces separate, sync eligible records, and restore verified access;
- provide opted-in friends, messages, reports, public cards, referrals, route activity, and boards;
- process verified subscriptions and explain entitlement state;
- secure the Services, prevent fraud and abuse, enforce policies, investigate incidents, and protect users;
- provide privacy-safe support and diagnose technical failures; and
- meet legal obligations and respond to valid legal process.
Trace currently does not use precise routes, VINs, private messages, receipts, symptoms, OCR text, or private build notes for advertising or general product analytics.
Location powers the record and receives the strongest boundary.
With your permission, Trace can use precise location during a drive and background location and motion to support automatic detection, continuation, and recovery. Samples can include latitude, longitude, time, course, speed, horizontal accuracy, and altitude where available. Trace uses these signals to build a route, calculate drive metrics, determine recording state, and create privacy-filtered outputs.
You can change location permission in iOS Settings. Denying or narrowing permission can disable or degrade automatic detection, background recording, route display, speed, distance, recovery, weather, and place context. The rest of the local product should remain available where technically possible.
This Policy is notice, not the device permission or blanket consent. Before public release, Trace must present a just-in-time in-app explanation before the first precise or background collection, distinguish manual recording from automatic detection, identify any hosted transfer, and provide a visible pause or withdrawal control. Trace must obtain a separate purpose-specific opt-in wherever law requires one; a general Terms acceptance or iOS permission alone does not authorize a new sensitive use.
A route may reveal a home, workplace, school, medical visit, religious practice, association, or daily routine. “Anonymous” is not automatically safe. Trace’s public and analytics boundaries therefore prohibit raw route publication by default.
Private data becomes visible only through a bounded choice.
- Trips, raw routes, private VINs, receipts, notes, messages, and full media are private by default.
- A share card is a newly rendered, endpoint-redacted artifact. Route-shape disguise reduces risk but cannot guarantee that a distinctive place, car, time, or route is unrecognizable.
- A public vehicle card uses an allow-list and excludes owner identity, VIN, odometer, receipts, private notes, and routes.
- Route-activity contribution is signed-in, explicit, delayed, and off by default; public output is aggregated and contains no raw route read path.
- Leaderboard participation is opt-in. The bounded result does not prove vehicle identity, legal road use, physical anti-cheat, or GPS accuracy.
- Blocking, unpublishing, or deleting can stop future access through Trace but cannot recall a screenshot, export, recipient copy, or crawler cache already created.
The audited application shell also contains a readable Friends feed with user captions. A visible feed item does not currently provide its own report or block control. The feed and other user-generated-content discovery must remain disabled for public release until item-level reporting, filtering, blocking, moderation, appeals, retention, and deletion are verified.
Your route is not an advertising product.
Trace does not currently sell personal information, share it for cross-context behavioral advertising, use targeted advertising, or combine it with third-party activity to track you across companies’ apps or websites. The app’s privacy manifest declares no tracking and no tracking domains.
Trace will not sell or license identified, pseudonymous, precise, or linkable route, location, speed, driving-behavior, vehicle, or visit-pattern data to a data broker, ad network, insurer, employer, lender, or similar third party. A future incompatible use will not begin merely because this Policy changed; it would require a new product flow, a documented risk review, and affirmative express opt-in consent where lawful, while preserving unrelated local-core access for someone who declines.
Trace may use truly aggregate or de-identified information to understand or explain the product only after applying documented safeguards and committing not to re-identify it. “De-identified” will not be used as a label for precise or readily linkable location data.
Because the current site does not sell or share personal information for targeted advertising and does not track visitors across companies, a Global Privacy Control or browser “Do Not Track” signal does not change its current behavior. If Trace later introduces processing covered by an opt-out signal, it must recognize and honor the signal where required before that processing begins.
The current site does not permit an advertising, analytics, or social-media third party to collect a visitor’s activity over time and across different companies’ websites or online services. The final hosting and CDN configuration must be checked before this statement becomes effective.
Active product data follows events; several production periods remain open.
| Data class | Current lifecycle | Unresolved production detail |
|---|---|---|
| Local trips, routes, vehicles, build history, and media | Until you delete the record or namespace, remove app data, or uninstall, subject to Apple-controlled backup and Keychain behavior. | Complete erase-all, media cleanup, and backup proof |
| Active-drive recovery | Until finalized, discarded, recovered, or the local account data is removed. | Physical lifecycle and storage-pressure proof |
| Hosted account and sync data | Until record or account deletion under the owner-scoped schema. | Deletion deadline, backup expiry, legal exceptions, and hosted proof |
| Messages, social records, cards, and reports | Feature-specific deletion; saved copies cannot be recalled. Social-report retention has a provisional 90-day design unless legal hold. | Final periods, purge, appeals, moderation access, and owner/counsel approval |
| Referrals and entitlements | For the offer, verified access, fraud prevention, and support lifecycle. | Approved fraud, tax, and deletion exceptions |
| MetricKit and logs | Raw diagnostic callback data is reduced in memory; bounded values can enter OS-managed Unified Logging. | Final archive behavior and provider retention |
| Website contact submissions | Submitted fields are processed for validation and abuse prevention. Valid visible fields are delivered through Resend when delivery is configured; the Vex application does not store the message in an application database. | Receiving-email retention and deletion period; requests may be sent to support@builtbyvex.com |
| Exports and recipient copies | Controlled by you, the recipient, Apple, or the destination after export. | Not recallable by Trace |
- Remote deletion completion
- Pending approval and production proof
- Backup retention
- Pending provider configuration
- Support and moderation retention
- Pending
Permissions, privacy, sharing, and deletion remain visible choices.
- Decline or change location, motion, Photos, Contacts, notifications, and other enabled permissions in the app or iOS Settings.
- Use Trace without an account for the free local core.
- Inspect a redacted share preview and choose whether and where to send it.
- Keep any mounted route-contribution or leaderboard participation off and revoke eligible publication later. Public-card presentation is not mounted in the current consolidated UI.
- Block or report an account or item where those controls are production-enabled.
- Initiate account deletion when signed in. Item-level trip and vehicle deletion engines exist, but their controls are not mounted in the current canonical profile UI.
- Manage or cancel an Apple subscription separately through Apple.
A JSON export engine exists, but no complete export control is mounted in the current canonical UI. Its output is a database archive, not a complete portability export: it can include private route data and omits media, sidecars, detailed telemetry/events, hosted truth, Social/authentication data, and provider records.
Use one designated public inbox to exercise applicable privacy rights.
Depending on your location and whether a law applies to Trace, you may request access, correction, deletion, portability, restriction, withdrawal of consent, or information about collection and disclosure. You may also have rights to opt out of sale, sharing, targeted advertising, or certain profiling; limit use of sensitive information; appeal a denied request; use an authorized agent; and receive equal service without retaliation for exercising a right.
Submit a request to support@builtbyvex.com. Vex will verify a request only to the degree reasonably necessary and will not ask for raw routes, passwords, tokens, or unrelated sensitive information. Response periods, authorized-agent handling, appeals, and any extension will follow applicable law. The production tracking and deletion workflow must be verified before this Policy becomes effective.
California disclosures are built into this Policy.
This Policy identifies the categories collected, sources, purposes, recipients, and retention criteria. Precise geolocation, authentication data, and certain derived or visit information can be sensitive personal information. Trace uses those categories only for the chosen app functionality, security, integrity, and other purposes that the final notice and applicable law allow.
During the 12 months before this review version, Trace has not operated a public production service that sells or shares personal information for targeted advertising. Trace does not provide personal information so another business can market directly to you. These statements must be rechecked against actual public operation and statutory thresholds before they become effective.
Trace does not intentionally infer health status from a route.
A precise route or stop can incidentally reveal a visit to a hospital, clinic, pharmacy, counselor, reproductive-health provider, or other sensitive place. Trace does not currently classify these visits, build health profiles, advertise from them, or sell them.
Washington, Nevada, or another jurisdiction may treat location that identifies an attempt to obtain health services as consumer health data and may require a separate, homepage-linked notice and consent flow. Before offering Trace in such a region, the operator and counsel must determine whether a separate Consumer Health Data Privacy Policy is required and must implement it before processing begins.
Broad availability does not replace regional privacy requirements.
Trace may be offered through selected App Store storefronts in the United States and other countries and regions. Exact storefront availability is maintained in App Store Connect and may change. Availability in a storefront does not waive local consumer or data-protection law.
If Trace offers the Services to people in, or monitors the behavior of people in, the European Economic Area, United Kingdom, or Switzerland, Vex must identify the applicable lawful bases, hosting region, international-transfer mechanism, representative where required, complaint authority, and relevant objection, restriction, withdrawal, and portability rights. Apple DSA trader verification addresses storefront disclosure only; it does not resolve these privacy obligations.
- Storefront scope
- Broad international availability through selected App Store storefronts; exact selections are maintained in App Store Connect.
- Apple EU trader status
- Owner reported complete; production storefront verification pending
- Production hosting region
- Pending production verification
- EU representative
- Pending applicability decision
- UK representative
- Pending applicability decision
Trace is for adults age 18 and older.
Trace is intended only for people who are at least 18 years old. It does not offer a child or parental-consent account path and is not directed to children. If Vex learns that a person under 18 created an account or supplied personal information, Vex may close the account and delete the information as required by law.
The release must present and enforce the age rule before account creation and before hosted location or profile data is uploaded. Apple’s storefront age rating is a separate content-suitability label and must be completed accurately for the shipping build.
A parent or guardian who believes a person under 18 supplied personal information to Trace may contact support@builtbyvex.com. Vex will investigate and take the action required by applicable law.
Trace uses layered safeguards, but no system is perfectly secure.
Current safeguards include the iOS app sandbox, account-scoped local namespaces, Keychain session storage, encrypted network transport, owner-scoped database rows, row-level security, private Storage authorization, server-side validation, allow-listed public projections, redacted share artifacts, environment isolation, and minimum-necessary diagnostics.
These source-level controls do not prove a production deployment. Trace cannot guarantee absolute security, uninterrupted availability, or that a third party will never defeat a safeguard. A public launch requires incident response, access review, secrets management, backup and recovery, breach-notification procedures, and hosted verification.
New collection means a new review.
Trace will update the date and version when this Policy changes. Material changes will receive reasonable notice through the app, website, email, or another appropriate channel, and the app is designed to require renewed acknowledgment when a material notice version changes. Acknowledgment is not consent to a new purpose. Where law requires consent rather than notice, Trace will obtain a separate purpose-specific opt-in before the new processing begins.
One public inbox handles privacy and security requests.
Use the designated public email below for a privacy request, security report, account-deletion issue, or question about this Policy. Do not include passwords, authentication tokens, raw routes, or unrelated sensitive records in an initial message.
- Privacy and rights requests
- support@builtbyvex.com
- Security reports
- support@builtbyvex.com
- Mailing address
- Pending public legal-notice address