Privacy Policy
This policy covers the mobile app ACom — Traffic
(com.grabow.commuter, Android and iOS)
and this website.
Last updated: 8 August 2026 · App version 10.0
In short
ACom has no user account. There is no registration, no sign-in, no email address, no profile. Your saved maps and settings live on your device only.
What the app does send to servers, it sends for a specific feature — and only the detail that feature needs:
| Feature | What is sent | To whom |
|---|---|---|
| Showing the map | The map view, technical connection data | Google (Maps SDK) |
| Traffic incidents | A grid tile containing your view | Our server → TomTom |
| Place search | Your search text, a coarsely rounded position | Our server → Google |
| Route check | Start and destination coordinates | Our server → TomTom |
| Wikimap | Map centre, language | Wikimedia |
| Advertising | Advertising ID, device data, approximate location | Google (AdMob) |
| Diagnostics & operation | Crash reports, usage statistics, device characteristics | Google (Firebase) |
What explicitly does not happen: we store no movement profiles, no trip history, no IP addresses and no coordinates on our servers. We do not sell data.
Controller
The controller within the meaning of the GDPR is:
B. Grabowski
Beethovenstr. 36
76275 Ettlingen
Germany
Email: grabow.commuter@gmail.com
No data protection officer has been appointed; the statutory conditions for appointing one are not met.
Data on your device
The following never leaves your device. It lives in the app's protected storage and is deleted when you uninstall the app or clear its data:
- your saved maps with name, view, zoom and start/destination markers
- all settings (units, night mode, map style, traffic layer and so on)
- which traffic incidents you have already read
- your incident filter
- the map view shown last
- the installation identifier
If your device makes a system backup (Android Backup, iCloud), it may include this data. That is controlled by your device vendor, not by the app.
Location data
ACom does not ask for your location at launch. It asks the first time you need it — when you tap Position. You can use the app fully without granting location access; only the features that require your own position fall away.
On the device
Location data is used to show your position on the map, to let the map follow you, and in bird view to turn the map into the direction of travel. This processing happens entirely on the device. The app keeps no location history — the last known position is held in memory only for as long as it is displayed.
Foreground only: ACom does not request background location permission and does not track your position when the app is closed.
What is transmitted
Your coordinates leave the device in three cases, each purpose-bound:
- Traffic incidents. What is sent is not your position but the rectangle the map currently shows — and even that only to determine a fixed tile of our worldwide grid. See below.
- Route check. The start and destination coordinates of the route being checked. If the start is your current location, that is your position at that moment.
- Place search. To rank suggestions, a position rounded to one decimal place is sent — a grid of roughly 11 kilometres. Anything finer is unnecessary, and would also cost more: an exact position would give every user their own cache entry.
Legal basis: Art. 6(1)(b) GDPR — the processing is necessary to provide the feature you requested.
Map display (Google Maps)
The map itself is drawn by the Google Maps SDK, which loads map tiles from Google's servers. Google thereby receives technically necessary data: your IP address, the requested map view, and device and connection characteristics. This processing is outside our control; it is inseparable from displaying the map.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google's privacy policy and the Google Maps Platform Terms apply.
Legal basis: Art. 6(1)(b) GDPR.
Traffic incidents (TomTom, via our server)
The traffic incidents come from TomTom. The app does not talk to TomTom directly, but through a server of our own (a Cloud Function in the europe-west1 region, i.e. inside the EU). There are two reasons: keeping the access key out of the app, and combining requests so the service stays affordable.
The second reason is the interesting one for privacy:
- Our server does not ask TomTom for your view but for a fixed tile of a worldwide grid. At German latitudes such a tile measures roughly 178 × 146 kilometres.
- The answer is cached for three minutes and shared by everyone in the same tile. The cache key contains only the tile — nothing about the caller.
- Only on the way back does the server trim the incidents down to the area your app actually asked about.
What TomTom learns is that somebody requested incidents for a region the size of half a federal state — not where you are.
What our server records
To keep costs controllable, the server keeps a consumption tally. Per installation identifier and calendar day (UTC) it writes one row containing: the number of requests, the number of tiles touched, the number of calls actually paid for at TomTom, the outcome (served, throttled, refused) and the self-declared reason (such as "layer switched on" or "list refreshed").
No IP address. No coordinates. No unaltered installation identifier — it is hashed to a 64-bit value before being written and cannot be traced back to a device afterwards. Each row carries a 35-day expiry and is deleted automatically.
The server additionally limits requests per IP address within a time window. That counter exists in memory only and is never stored.
TomTom provider: TomTom International B.V., De Ruijterkade 154, 1011 AC Amsterdam, Netherlands.
Legal basis: Art. 6(1)(b) GDPR for the request itself; Art. 6(1)(f) GDPR for the consumption tally (legitimate interest in operating the service in an abuse-resistant and financially sustainable way).
Address and place search
When you search for a place or an address, your search text goes through the same server of ours to Google's Geocoding and Places services, along with the position rounded to roughly 11 kilometres described above, so that nearer results rank higher.
Here too our server caches the result — suggestions for one hour, full place details for 24 hours — normalising capitalisation and whitespace to do so. The cache is keyed by search term, not by user: the same search by two different people is the same entry.
Legal basis: Art. 6(1)(b) GDPR.
Route check
When checking a route, the start and destination coordinates are sent through our server to TomTom to compute driving time, delay and possible alternatives. The request is not linked to your person and not stored permanently; it enters the consumption tally as described above, without coordinates.
If you then tap Navigate this way, ACom opens Google Maps or Waze with the start, the destination and a waypoint. From that moment the privacy policy of that app applies.
Legal basis: Art. 6(1)(b) GDPR.
Wikimap
When you switch on the Wikimap layer, the app queries Wikipedia's open geo search for articles near the map centre. Sent are the map centre, a search radius and your device language. No access key and no identifier are included; the Wikimedia Foundation sees the request with your IP address. The layer is off by default.
Provider: Wikimedia Foundation, Inc., 1 Montgomery Street, San Francisco, CA 94104, USA — privacy policy.
Legal basis: Art. 6(1)(b) GDPR (you switch the layer on yourself).
Installation identifier
On first launch the app generates a random number (a UUID) and stores it on the device. It is sent only to our own server and serves a single purpose there: telling one installation from another so that request limits can be shared fairly.
- It is not a device identifier — it does not come from the operating system and is not shared with other apps.
- It is linked to no person, no account and no advertising ID.
- On the server it is hashed before any storage.
- Uninstalling or clearing app data produces a new one, at no disadvantage to you.
Advertising and consent
ACom is free and funded by advertising, using Google AdMob (Google Ireland Limited). For this, AdMob processes among other things your device's advertising identifier (Android: Advertising ID, iOS: IDFA), your IP address, the approximate location derived from it, device characteristics, and which ads you were shown and whether you tapped them.
The consent form
If you are in the EU, the EEA, Switzerland or the United Kingdom, the app shows a consent form before the first ad, built on Google's User Messaging Platform (UMP) and following the IAB Transparency & Consent Framework. There you decide about personalised advertising and can see the list of participating vendors.
Until that decision is made the advertising SDK is not initialised. No advertising identifiers are collected before you answer.
If you decline you still see advertising, but non-personalised advertising, based essentially on context. No feature of the app depends on your consent.
On iPhone and iPad
Apple's own prompt ("Allow app to track?") comes first. Only afterwards does the Google form appear. If you refuse Apple's prompt the IDFA is not provided, regardless of what you choose in the Google form.
Changing or withdrawing consent
You can withdraw your consent at any time with effect for the future:
- In the app: ⋮ → Settings → Privacy → Privacy options. That opens the same form you saw on first launch. The entry appears only in the regions where the form applies.
- Android: Settings → Google → Ads — where the advertising ID can additionally be reset or deleted.
- iOS: Settings → Privacy & Security → Tracking — Apple's tracking permission.
- Or write to us at grabow.commuter@gmail.com.
More from Google: how Google uses data for advertising.
Legal basis: Art. 6(1)(a) GDPR (consent) for personalised advertising and access to the advertising identifier; Art. 6(1)(f) GDPR for serving non-personalised advertising to fund the free service.
Firebase services
For operation and diagnostics ACom uses several services of Google's Firebase platform. Each receives a pseudonymous installation identifier assigned by Firebase — not the same one described under Installation identifier.
| Service | Purpose | What it involves |
|---|---|---|
| Crashlytics | Finding crashes and severe errors | An error report with the call stack, device model, operating system and app version, timestamp; plus a note on whether the data import from version 9 succeeded |
| Analytics | Usage statistics: which screens are used, how many installations are active | Automatically collected events, coarse origin (country), device characteristics, pseudonymous installation identifier |
| Cloud Messaging | Occasional notices to users | A device token for delivery |
| Remote Config | Changing configuration values without an update | Fetching the configuration with the installation identifier |
| App Check | Making sure our server only serves genuine installations | An attestation token from Play Integrity (Android) or App Attest (iOS); Google evaluates device signals in the process |
None of this is linked to your name, and we do not use it to identify you. The provider is Google Ireland Limited; Google's Firebase privacy information applies.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in stable, abuse-resistant operation and in fixing faults. For Cloud Messaging your notification permission in the operating system applies in addition (Art. 6(1)(a) GDPR); you can withdraw it in the system settings at any time.
Jumps to other apps and websites
In several places ACom deliberately hands off to the outside world. From that moment our responsibility ends and the other provider's privacy policy applies:
- Google Maps / Waze — when starting navigation and when searching for petrol stations or car parks. The destination is handed over, plus start and waypoint where applicable.
- Parkopedia — ACom copies the place name to the clipboard and opens the website. No coordinates are passed.
- Incident map view — Open in browser calls a page hosted by us (
web-commuter.firebaseapp.com) that shows the incident on a TomTom map. - Sharing — which app you pick to send with is your choice in the system share dialog. The content is the links you generated.
Which permissions the app needs
| Permission | Purpose | Required? |
|---|---|---|
| Location (precise / approximate) | Own position on the map, following, bird view, start of the route check | No — requested the first time you tap Position |
| Notifications | Notices about the app | No — requested when the first message arrives |
| Internet / network state | Maps, incidents, search; detecting whether a connection exists | Yes, technically necessary |
| Advertising ID (Android) | Advertising, only after consent | Can be switched off in the system |
Recipients and international transfers
Recipients of personal data are the service providers named above: Google (Maps, AdMob, Firebase, Geocoding and Places), TomTom and the Wikimedia Foundation. There is no sale and no disclosure for other purposes.
Our own server functions run in the Google Cloud region europe-west1 (Belgium), with the associated database likewise inside the EU.
The providers named may transfer data to countries outside the EU and the EEA, in particular to the United States. Google Ireland Limited and Google LLC are certified under the EU-US Data Privacy Framework; the European Commission's Standard Contractual Clauses apply in addition. Despite these safeguards, access by authorities in third countries cannot be entirely ruled out.
Retention
| Data | Kept |
|---|---|
| Maps, settings, filters, read incidents | On the device, until you delete them or uninstall the app |
| Consumption tally rows on our server | 35 days, then deleted automatically |
| Incident cache | 3 minutes |
| Search suggestion / place detail cache | 1 hour / 24 hours |
| Crash reports, usage statistics, advertising data | According to Google's retention periods — see their privacy policies |
| Your email to support | Until the request is settled, then no longer than 6 months |
Your rights
Under the GDPR you have the right to:
- access the data we process about you (Art. 15)
- rectification of inaccurate data (Art. 16)
- erasure (Art. 17)
- restriction of processing (Art. 18)
- data portability (Art. 20)
- object to processing based on legitimate interests (Art. 21)
- withdraw consent with effect for the future (Art. 7(3))
We have no way of identifying you: there is no account, and the only identifier that reaches our server is stored hashed. We can therefore only answer an access request if you tell us your installation identifier yourself — and even then it shows nothing but request counts from the last 35 days. That is not an excuse; it is the consequence of deliberately storing nothing that could be used to find a person again.
For any request, write to grabow.commuter@gmail.com.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Ours is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg, Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
This website
commuter.drawla.app is hosted on Firebase Hosting
(Google Ireland Limited). Opening a page produces the usual server access
data: IP address, timestamp, the address requested, the amount of data
transferred and the browser identification. It serves operation and
security and is not analysed by us.
This website sets no cookies, embeds no third-party fonts, scripts or images, and uses no analytics or tracking tools. There is therefore nothing to consent to. The small amount of JavaScript on these pages runs entirely in your browser and sends nothing anywhere.
Legal basis: Art. 6(1)(f) GDPR.
Changes to this policy
When the app changes, this policy changes with it. The current version is always at commuter.drawla.app/en/privacy; the date at the top says when it was last revised.
This policy describes the state of affairs as of 8 August 2026 to the best of our knowledge. It is not legal advice. In case of doubt, the German version prevails.