Privacy Policy
This policy explains what personal data Motobomb collects, how we use it, and your choices under UK GDPR and the Data Protection Act 2018.
Who we are
Motobomb is operated by Motobomb Ltd, United Kingdom. For data protection purposes, Motobomb Ltd is the data controller responsible for your personal data.
Information we collect
Account, sign-in and profile information
- When you sign in with Google, we may receive your Google account identifier and basic profile information you authorise, such as name, email address and profile picture.
- When you sign in with Apple, we may receive your Apple user identifier and any name or email address you choose to share. Apple may provide a private relay email address instead of your real email address if you use Hide My Email/private relay.
- We store your sign-in provider, authentication identifier and account status so you can access your account securely across sessions.
- Profile type, display name, profile image, account setup status and legal acceptance version.
- For photographers: business name, social links, website, tags, portfolio photos, approximate area, travel radius, list visibility and Pro status.
- For community profiles: display name, profile image, contribution history and contribution allowance information.
Photos, notes, reports and recommendations
- Photos, notes, descriptions and location details you submit as recommendations or community contributions.
- Report details you submit about locations, photographer profiles or community content.
- Admin review status and moderation outcomes, such as approved, rejected, resolved or hidden.
- Attribution data used with approved community content, such as your display name and profile image.
Location data
Location is used for map features, nearby functionality, directions and photographer location sharing where enabled. You can manage permissions in device settings.
Pro Photographer live sharing: if you enable Appear on Map, your current shared position is displayed to signed-in users while sharing is active. Sharing stops when you turn it off or when the auto-disable safeguard triggers after 8 hours. We do not aim to store a continuous movement history.
Approximate area: Pro photographers may save an approximate public area and rounded location information for discovery and Near Me filtering.
Subscriptions and purchases
Subscriptions and purchases may be processed by Google Play for Android or by Apple through the Apple App Store / StoreKit for iOS. We receive the purchase, receipt, transaction, subscription status and entitlement information needed to provide features such as Enthusiast Pro, Photographer Pro, ad removal and subscription status. We do not receive your full payment card details from Google Play or Apple.
Purchase and subscription data may include product ID, purchase token or receipt identifier, transaction/reference ID, subscription state, renewal/cancellation information, refund/reversal status, platform, country/currency where provided, and timestamps needed to verify access.
Device, usage and diagnostics
- Device model, OS version, app version, language and basic diagnostics.
- Crash logs and performance information to help fix bugs and improve reliability.
- Usage events needed to operate, secure and improve the app.
How we use your data
- Provide accounts, profiles, maps, lists, favourites, community content, reports and support.
- Show public photographer profiles and approved community content with appropriate attribution.
- Review recommendations, reports and community submissions.
- Operate contribution limits, contribution history and the Community Leaderboard.
- Verify and manage subscriptions, purchases and entitlements from Google Play, the Apple App Store / StoreKit or another relevant platform.
- Send essential service notifications such as location sharing reminders and auto-disable notices.
- Keep the service safe, prevent abuse, enforce our Terms and investigate reports.
- Improve performance, reliability and user experience.
Legal bases for processing
- Contract: to provide the app, account features, profiles, subscriptions and community features you request.
- Consent: for optional permissions such as location sharing, notifications and photo/media access where required.
- Legitimate interests: service security, abuse prevention, moderation, diagnostics and product improvement, balanced against your rights.
- Legal obligation: where we must retain certain records, such as accounting or tax information.
Publicly visible information
- Photographer profiles: business name, profile image, socials, portfolio photos, tags, Pro badge, website, approximate area and travel radius where provided.
- Live photographer location: shared location while Appear on Map is active.
- Community content: approved photos, notes and updates may be visible to other signed-in users and may include your display name and profile image.
- Leaderboard: your display name, profile image and approved contribution count may appear if you have qualifying approved contributions.
- Recommended places: submitted location names, coordinates, descriptions, access information and images may become visible if approved.
Reports, moderation and admin review
Reports about locations, photographer profiles and community content are sent to Motobomb admin review. Reports may include the reported item, reason, notes, reporter information and relevant profile/location details. Reports are usually used for moderation and may not receive a direct reply.
Use Help & Support for account help, deletion requests or anything that requires a direct response.
Permissions the app uses
- Location: map features, Near Me, location sharing and proximity alerts.
- Notifications: service alerts, sharing reminders, auto-disable notices and optional updates.
- Photos/Media: profile images, portfolio images and community contribution images you choose to upload.
- Internet: authentication, maps, syncing, subscriptions, ads, app-store entitlement checks and support.
- Foreground/background services: to support essential location-sharing or notification behaviour where enabled.
Third-party services
- Google Firebase: authentication, Firestore database, Firebase Storage, diagnostics and cloud services.
- Google Sign-In: sign-in and basic account information where you choose to sign in with Google, such as your name, email address and profile picture where authorised.
- Sign in with Apple: sign-in and basic account information where you choose to sign in with Apple, including your Apple user identifier and any name/email details you choose to share, which may include a private relay email address.
- Google Maps: map display, directions and related location features.
- Google Play Billing: Android subscriptions, in-app purchases, purchase verification, subscription status and refund/reversal signals.
- Apple App Store / StoreKit: iOS subscriptions, in-app purchases, receipt/transaction verification, subscription status and refund/reversal signals.
- Google AdMob: advertising unless removed or otherwise unavailable.
- Apple and Google platform services: app distribution, updates, purchase management, crash or device-level diagnostics and security checks where applicable.
App stores, platforms and website use
Motobomb uses one shared Privacy Policy for the Android app, iOS app and website. The exact data processed may depend on how you access the service.
- If you use Android, Google Play and Google platform services may process purchase, subscription, refund, device, diagnostic and app-install information under Google's own terms and privacy policies.
- If you use iOS, Apple, Sign in with Apple, App Store and StoreKit services may process sign-in, purchase, subscription, refund, device, diagnostic and app-install information under Apple's own terms and privacy policies.
- If you use the website, we may process basic technical information such as browser/device information, page requests and security logs.
- Platform providers may give Motobomb limited sign-in, entitlement, subscription, transaction, refund/reversal or diagnostic information needed to operate the service, but they do not provide us with your full payment card details.
Data retention and deletion
- Account/profile data: kept while your account is active and deleted or anonymised when your account is deleted, subject to legal or security needs. Some sign-in identifiers may remain in security, deletion or audit records where necessary.
- Profile and portfolio images: stored while active and removed when deleted from your profile or when your account is deleted.
- Community content: approved content may remain visible until removed, hidden or deleted. If your account is deleted, we may remove or anonymise attribution where reasonably possible.
- Reports and moderation records: may be retained to protect the service, investigate abuse and evidence moderation decisions.
- Live location sharing: stored only while sharing is active and removed when sharing ends or auto-disables.
- Purchase and entitlement records: retained as needed to provide paid features, process account support, prevent fraud, handle disputes and meet legal/accounting requirements.
- Diagnostics: crash logs and anonymised/aggregated analytics may be retained for a limited period.
You can delete your account from Menu → Settings → Delete Account.
International transfers and security
Some providers may process data outside the UK or EEA. Where required, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms.
We use technical and organisational measures such as Firebase Authentication, Firestore/Storage rules, entitlement checks and restricted admin access. No system is completely secure, so we cannot guarantee absolute security.
Your rights
Under UK GDPR and EU GDPR where applicable, you may have rights to access, correct, delete, restrict, object to processing, request portability and withdraw consent where we rely on consent.
To exercise your rights, contact us via Help & Support or email contact.motobomb@gmail.com. You also have the right to complain to the Information Commissioner's Office (ICO).
Children's privacy
Users under 13 require parent or guardian consent. We do not knowingly collect personal data from children under 13 without appropriate consent and do not knowingly serve personalised ads to children under 13.
Changes to this policy
We may update this Privacy Policy from time to time. Material updates may be shown in the app and may require you to accept the new version before continuing.