This policy explains how LeMoove handles personal data when you use the LeMoove app for iPhone and Android, the trackers and devices connected to it, and this website (lemoove.com). It’s written to be read: when a technical term can’t be avoided, we explain what it means.
Throughout this text, “LeMoove”, “we”, “us” and “our” refer to LeMoove, which is responsible for the app and this website. “You” means anyone who uses the app or visits the website. LeMoove is based in Brazil and follows the Brazilian General Data Protection Law (LGPD, Law No. 13,709/2018). If you live elsewhere, your local law may give you similar or additional rights, and you can exercise them through the same channel.
This policy complements the terms of use. The Privacy and security page summarizes the same content.
Who is responsible for your data
LeMoove is operated by NAS SOFTWARE, Brazilian company registration (CNPJ) No. 45.911.457/0001-96, based in São Paulo, Brazil. It is the controller of the personal data processed in the app and on this website: it decides why and how it’s used.
For any privacy matter, including exercising your rights, the channel is app.lemoove@gmail.com. This is also the channel for reaching the person in charge of data protection, as required by the LGPD.
The core idea: location with consent, inside a group
LeMoove exists so that people who know each other, like a family, can share their location with one another. Three rules shape everything in this policy:
- Nobody is located without taking part. To appear on the map, a person installs LeMoove on their own phone, joins a group with an invite code and allows location in the system settings. It’s not possible to locate someone by their phone number.
- Only the group sees. Your location is only delivered to people who, at that moment, share at least one group with you. This rule is enforced on the server, not just on the app’s screen.
- We keep less, for less time. Location data has retention periods and is deleted automatically (see How long we keep data).
What data we process
The data below is processed depending on the features you use and the permissions you grant. If you don’t use a feature, its data doesn’t exist.
Account data
- Name and email, provided by you or received from Apple or Google when you sign in with those accounts. With “Sign in with Apple”, Apple may provide a relay email instead of your real email.
- Password, when you create an account with email. It’s stored only as a hash, a transformation that doesn’t allow the original password to be recovered.
- Profile photo, if you choose one.
- Sign-in identifiers provided by Apple or Google, which link their account to your LeMoove account.
- Plan and subscription status (Free, Basic or Complete, expiry date and scheduled changes).
Location and motion
When you allow it, the app records your phone’s position, including in the background if you choose “Always” (iPhone) or “Allow all the time” (Android). Each record may contain:
- latitude and longitude, with the margin of error estimated by the phone;
- speed and heading;
- date and time;
- activity type detected by the phone’s sensors (still, on foot, on a bicycle or in a vehicle) and the confidence of that detection;
- battery level and whether the phone is charging.
From these records, the server calculates:
- trips, with distance, duration and speeds;
- stays: where you stopped and for how long, which lets the app show stops and recognize places you visit often;
- alert events, such as arriving at or leaving a place, trip start and end, speeding, low battery and proximity.
Driving report
On vehicle trips, the app records harsh acceleration, braking and cornering, speed and signs of phone use while driving, measured by the driver’s own phone. LeMoove uses them to calculate the driving score shown in the report.
Groups, places and alerts
- Groups you create or join: name, members, who manages the group and invite codes.
- Places you create: name, address, center, radius and the people chosen to receive alerts.
- Alert preferences: which alerts are on for each person, the chosen limits, quiet hours and the time zone used to apply them.
- Alert history: the alert type, the measurement (for example, the speed), the position and the time.
Chats, calls and SOS
- Messages you send in chat: text, photos, videos, audio, files and links.
- Voice and video calls: audio and video travel encrypted between the devices and are not recorded. To set up the connection, the devices exchange technical information, such as network addresses.
- SOS requests: the emergency message, your location at the time and the approximate address, sent to the people in your groups.
- When you send a link, the app may fetch a page summary (title and image) to show a preview. Your phone fetches it directly from the linked website.
GPS trackers and Bluetooth tags
- Trackers: device identification (IMEI and activation code), the name, type, license plate and photo you enter, positions sent by the tracker, ignition state, vehicle battery voltage, settings and commands sent to the device, and the people you shared the device with.
- Bluetooth tags: tag identification, name, the battery level it reports and the position of the phone that last saw it.
Device data
To deliver notifications and keep the app working on each phone, we record the device model, operating system (iOS or Android), app version, language, notification tokens and which permissions are granted (location, notifications, motion and others).
App usage and diagnostics
- App usage: screens opened and buttons tapped, recorded technically (for example, the screen name), without the content of your messages or your location.
- Crash reports: when the app closes unexpectedly, a technical report with the device state and the point in the code where the crash happened.
- Remote configuration: the app fetches operating parameters, such as texts and settings, that we can change without releasing a new version.
These services are provided by Google Firebase and use app installation identifiers. We don’t use this data for advertising.
Purchases and subscriptions
Subscriptions are paid through the App Store (Apple) or Google Play (Google). We only receive from the stores what we need to unlock your plan: the product purchased, transaction identifiers, status, expiry date and renewal, cancellation or refund notifications. We never receive your card details or other payment information.
Support
When you write to support, we process your email, the content of your message and any attachments you send, to answer and resolve your request.
This website
- Preferences stored in your browser (local storage): the theme you chose (light or dark) and your answer to the measurement notice.
- Audience measurement (Google Analytics 4), only if you allow it in the cookie notice. We record pages viewed and clicks on buttons such as “Download”. Measurement is configured with anonymized IP and without Google advertising signals. Until you answer, or if you decline, none of this is loaded. You can change your choice at any time in “Cookie preferences” in the footer.
- Server technical logs, such as IP address, date, time and requested page, generated automatically on every visit to keep the website running and secure.
Why we use data, and on what legal basis
The LGPD requires every processing activity to have a legal basis. The table shows each purpose and the basis for it.
| Purpose | Data used | Legal basis (LGPD) |
|---|---|---|
| Create and maintain your account, sign in securely | Account data | Performance of a contract (art. 7, V) |
| Show your location to your group, calculate trips, stays and the driving report | Location and motion, driving report | Performance of a contract (art. 7, V), with your location permission in the phone’s system |
| Place alerts, automatic alerts and SOS | Location, groups, places, alert preferences | Performance of a contract (art. 7, V) |
| Chat and calls | Chats and call technical data | Performance of a contract (art. 7, V) |
| Trackers and tags | Device data | Performance of a contract (art. 7, V) |
| Send notifications to the right device | Device data | Performance of a contract (art. 7, V) |
| Unlock and maintain paid plans | Purchases and subscriptions | Performance of a contract (art. 7, V) and legal obligation (art. 7, II) |
| Fix crashes and understand how the app is used in order to improve it | Usage and diagnostics | Legitimate interest (art. 7, IX) |
| Security, fraud and misuse prevention, enforcing the terms | Account data, technical logs and, when necessary, the data involved in the case | Legitimate interest (art. 7, IX) and exercise of rights (art. 7, VI) |
| Handle support and data subject requests | Support | Performance of a contract (art. 7, V) and legal obligation (art. 7, II) |
| Measure website audience | Google Analytics 4 | Consent (art. 7, I) |
| Comply with legal obligations and orders from authorities | Whatever the obligation requires | Legal obligation (art. 7, II) |
When we rely on legitimate interest, we only process what’s necessary and respect your expectations and rights. You can object to this processing through the privacy channel.
We don’t use your data for advertising, we don’t show ads and we don’t sell personal data.
Who can see your data in LeMoove
| Data | Who sees it |
|---|---|
| Your location, trips, stays and battery | You and the people who share at least one group with you. Whoever leaves the group stops seeing. |
| Driving report | You and the people in your groups. |
| Places you create | Only you. The chosen people receive the alerts but can’t see or edit the place. |
| Alerts | Only whoever turned the alert on. |
| Chats | The participants of the chat. In a group chat, the group’s members. |
| SOS request | The people you chat with in the app. |
| Trackers and tags | Whoever registered the device and the people it was shared with. |
| Name and profile photo | The people in your groups and chats. |
The LeMoove team only accesses personal data when needed to run the service, handle one of your requests, investigate a bug or misuse, or comply with the law.
Who we share data with
We don’t sell or rent personal data. We only share data in the situations below.
Service providers
Companies that help us run LeMoove and process data according to our instructions and their own rules:
- Hosting: the servers that store the app’s and this website’s data.
- Google (Firebase): notification delivery on Android (Firebase Cloud Messaging), app usage measurement (Google Analytics for Firebase), crash reports (Firebase Crashlytics) and remote configuration (Firebase Remote Config).
- Apple: notification delivery on iPhone (Apple Push Notification service) and “Sign in with Apple”.
- Google: Google sign-in, maps and Street View (Google Maps), and the public server that helps devices find each other during a call (STUN). When showing the map, your phone requests the images directly from Google.
- System address services: to turn a position into an address, or an address into a position, the app uses the phone’s own system service, from Apple on iPhone and Google on Android.
- Google Analytics 4, on this website, only with your consent.
App stores
Apple and Google process subscription payments and tell us their status. Your payment data is handled under each store’s policies.
When required by law or to protect people
We may share data when required by law, by court order or at the request of a competent authority, or when necessary to protect someone’s life or safety and to defend ourselves in legal proceedings. Whenever the law allows, we notify the affected person.
Business reorganization
If LeMoove goes through a merger, acquisition or transfer of the service, data may be transferred to the new owner, who must respect this policy. We’ll let you know beforehand.
International transfers
Some providers, such as Google and Apple, process data on servers outside Brazil, mainly in the United States. These transfers follow what the LGPD allows (arts. 33 to 36), based on the contractual safeguards and certifications adopted by these providers.
How long we keep data
The periods below are applied automatically by the server.
| Data | Period |
|---|---|
| Location points (the map trail) | 30 days |
| Positions sent by trackers | 30 days |
| Alert history | 90 days |
| Stays (where and how long you stayed) | 1 year |
| Subscription purchase records | 1 year |
| Account, groups, places, preferences, devices and chats | While the account exists, or until you delete them |
| Crash reports and app usage data | Google Firebase retention periods |
| Website measurement (Google Analytics 4) | The configured period, 14 months at most |
| Support emails | As long as needed to handle the request and keep a record of it |
What the app shows also depends on your plan: trip history is shown for 1, 7 or 30 days. Stays are kept longer because they’re what lets the app recognize the places you visit often.
When the law requires it, as with Brazil’s Internet Civil Framework (Law No. 12,965/2014), we keep app access logs (date, time and IP address) for the legal period, and we may keep data for as long as needed to meet legal obligations or defend ourselves in legal proceedings.
How we protect data
- The app only talks to our servers over encrypted connections (HTTPS and WSS).
- Calls use WebRTC, which encrypts audio and video in transit.
- Passwords are stored only as a hash.
- Server-side access rules make sure each person can only read the data they’re allowed to see, regardless of what the app shows.
- Team access to the systems is limited to those who need it to run the service.
No system is completely immune to failures. If a security incident happens that may bring you relevant risk or harm, we’ll notify you and Brazil’s National Data Protection Authority (ANPD), as the LGPD requires.
Your rights
Under the LGPD (art. 18), you can request, at any time:
- confirmation that we process your data;
- access to the data;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary or excessive data, or data processed in breach of the law;
- portability of the data to another provider;
- deletion of data processed based on your consent;
- information about who we share your data with;
- information about the possibility of not consenting and the consequences of refusing;
- withdrawal of consent;
- objection to processing based on other legal grounds, when the law isn’t being followed;
- review of decisions made solely by automated processing that affect your interests.
To exercise these rights, write to app.lemoove@gmail.com from your account email. We may ask for information to confirm the request is yours, to protect your data from others. We reply within the periods set by the LGPD. You can also file a complaint with the ANPD or your local data protection authority.
Some actions you can take yourself in the app, right away:
- correct your name and photo in your profile;
- leave a group, stopping sharing your location with it;
- delete places and turn off alerts;
- delete your account, in Profile, “Delete my account”.
Phone permissions and how to control them
iPhone and Android ask for your permission before LeMoove uses each sensitive feature, and you can change your answer at any time in your phone’s settings.
| Permission | What it’s for | If you deny it |
|---|---|---|
| Location, including in the background | Showing you to your group, arrival and departure alerts, trips | With “While using the app”, the app only gets your position with the screen open. Without permission, you don’t appear on the map. |
| Motion and fitness | Knowing whether you’re still, walking or driving, to save battery and classify trips | The app uses more battery and trips are less accurate. |
| Notifications | Alerts, place notices, SOS and messages | Alerts don’t arrive. |
| Camera, microphone, photos and files | Profile photo, sending photos, videos, audio and files in chat, calls | Those specific features don’t work. |
| Bluetooth | Pairing and finding Bluetooth tags | Tags don’t work. |
Children and teenagers
LeMoove can be used by children and teenagers within a family group, with the involvement and authorization of at least one parent or legal guardian, who should supervise the use. Children’s and teenagers’ data is processed in their best interest, as required by art. 14 of the LGPD, and limited to what the app needs to work.
Parents and guardians should talk to the child or teenager about location sharing and use the app as a tool for care, not surveillance. If you’re a guardian and believe a child’s data was processed without your authorization, write to app.lemoove@gmail.com.
Account deletion
You can delete your account in the app, in Profile and Delete my account. Deletion is permanent: the account stops working and can’t be recovered.
When you delete your account, we delete the account and the personal data linked to it, except what we must keep by law or to exercise our rights, such as purchase records, for the periods listed in How long we keep data.
Deleting your account doesn’t cancel your subscription. It’s billed by the App Store or Google Play and must be cancelled there.
Changes to this policy
We may update this policy to reflect changes in LeMoove or in the law. The date of the last update is shown at the top of the page. When a change is significant, we’ll notify you in the app or by email before it takes effect.
Contact
For questions, requests about your data or to reach the person in charge of data protection, write to app.lemoove@gmail.com. You’ll also find other options in the support center.