Legal
Privacy Policy
How ARO collects, uses, protects, retains, and discloses information—and the choices available to users.
- Effective
- July 19, 2026
- Last updated
- July 19, 2026
- Version
- 2026-07-19-v1
1. Overview
ARO is designed to minimize identifying information while still supporting community reporting and approximate map alerts for everyone in the community.
This Privacy Policy describes what we collect, why we collect it, how long we keep it, and the choices available to you.
2. Information we collect
Depending on how you use the service, we may process:
• Anonymous session tokens stored on your device
• Account details if you register (such as email, optional display name, language, and measurement preference)
• Approximate report locations and public summaries you choose to submit
• Confirmation responses and related metadata needed for confidence scoring
• Route analysis inputs you submit for comparison against public reports
• Technical logs needed for security, abuse prevention, and reliability
• Consent records for Terms of Service and Privacy Policy acceptance
• Optional Support records if you tip (amount, currency, cadence, status, timestamps, and Stripe payment or subscription references — never full card numbers)
3. What we do not publish
Exact observer GPS used only for local confirmation checks is distance-bucketed and is not retained as a precise public pin. Public map views show approximate areas, not exact submission points.
We do not sell personal information.
4. How we use information
We use information to:
• Operate the map, reporting, confirmation, and route tools
• Protect the service against abuse and fraud
• Provide optional account features
• Record legal consents and respond to privacy requests
• Process Optional Support tips through Stripe, manage saved payment methods you choose to keep, handle cancellations and refund requests, and keep accounting records
• Improve reliability and safety wording
• Comply with law where required
6. Retention
We retain information only as long as needed for the purposes above, including security, dispute resolution, and legal obligations. Report visibility may expire according to product rules even when underlying records remain for integrity or audit reasons.
7. Your choices
You may:
• Continue using anonymous sessions for many features
• Create or delete an account where supported
• Request data export or deletion through the privacy endpoints supported by the API
• Withdraw certain consents where the product allows
• Contact the operating organization with privacy questions
Some requests may be limited by legal, security, or integrity requirements.
8. Security
We use administrative and technical safeguards appropriate to a privacy-sensitive community safety tool. No method of transmission or storage is completely secure, and absolute anonymity cannot be guaranteed on the public internet.
9. Children
The service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
10. Policy updates
We may update this Privacy Policy and identify updates with a policy version date. If you create an account, we ask you to accept the current version. Material changes may require renewed consent where appropriate.
11. Sources of information
We receive information directly from you when you register, submit reports, confirm activity, upload media, configure alerts, apply for an organization listing, or use the evidence vault. We also receive technical information automatically from your browser or device and operational information from service providers used to run the platform.
Community reports and organization directory information may concern public events or organizations, but users must not submit unnecessary personal information about other people.
12. Location data
Location access is optional and requires device permission. It may be used to center the map, choose a report or alert-zone area, or determine whether a confirmation is local. Public report responses expose only an approximate area returned by the API.
Precise confirmation coordinates are used transiently to calculate a distance category and are not intended to remain in client state or become a public pin. Turning off location permission does not prevent all use; remote confirmation and manual map or coordinate entry may remain available.
13. Local storage and similar technology
The app uses browser local storage for anonymous-session tokens, registered-account access and refresh tokens, basic account display data, and locally dismissed notices. A progressive web app service worker may cache application files and selected pages for performance or offline access.
Clearing browser storage may sign you out, revoke local access to an anonymous session, or remove local preferences. ARO does not currently describe advertising cookies because advertising is not part of the documented product.
14. Account credentials and authentication
Registered account email addresses and credentials are processed to create accounts, authenticate users, recover passwords, prevent abuse, and protect the service. Passwords should be stored by the server as one-way hashes; the frontend never needs to retrieve a password.
Access and refresh tokens stored in the browser can grant account access. Protect your device, sign out on shared devices, and notify the operator through the published contact if you suspect compromise.
15. Reports, confirmations, media, and alerts
Report content can include an approximate location label, public summary, category, timing, and confidence-related information. Confirmations may include a response, a local/remote indicator, and a distance bucket. Media can include file metadata and processing status; approved sanitized derivatives may be public when the feature supports them.
Alert zones return a label, grid reference, and radius rather than a decrypted exact center. Notification destinations are protected by the server and ordinary API responses return only a destination hint.
17. Retention details
Retention is feature-specific and can vary by deployment. Current backend defaults are configurable and may include approximately:
• Reports and processed media: up to 90 days
• Original media: 14 days
• Rejected media: 3 days
• Notification delivery logs: 60 days
• Inactive anonymous sessions: 30 days
• Evidence-vault entries: 365 days by default, with user-selected periods up to 1,825 days
Operational backups, security records, consent records, legal holds, and records needed to resolve disputes may follow different schedules. Public visibility can end before backend deletion. Retention schedules may vary by deployment.
18. Legal bases and purpose limitation
Where a law requires a legal basis, processing may rely on performance of a requested service, consent, legitimate interests in operating and securing the platform, compliance with legal obligations, or protection of vital interests. The applicable basis depends on the feature and jurisdiction.
Information should not be reused for unrelated political targeting, discriminatory profiling, advertising, or sale. Materially new purposes require an updated notice and, where required, consent.
19. Service providers and disclosures
Categories of recipients may include cloud hosting, database, mapping and directions, email delivery, object storage, payment processing (Stripe for Optional Support), security, monitoring, and professional advisers. Providers should receive only the information reasonably needed for their work and be bound by appropriate safeguards.
Information may be disclosed in response to valid legal process, to protect users or the public, to investigate abuse, or during a merger, financing, reorganization, or transfer of the service. The operator should evaluate and narrow government or legal demands where legally permitted.
20. Data sale, advertising, and political use
ARO does not sell personal information as that term is commonly understood and does not use personal information for targeted political advertising. The platform is nonpartisan and should not be used to infer political affiliation, immigration status, ethnicity, religion, or other sensitive traits.
If future business practices introduce advertising, analytics sharing, or activity that applicable law defines as a sale or sharing, this Policy and user controls must be updated before that activity begins.
21. Privacy rights and requests
Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing; withdraw consent; opt out of certain sales or sharing; and appeal a denied request. The API supports authenticated export, deletion, and consent management, but availability in the interface may vary.
The operator may need to verify identity, protect other people’s rights, retain legally required records, or reject abusive requests. Authorized-agent requests may require proof of authority. Users should not be discriminated against for exercising applicable privacy rights.
22. Security and incident response
Safeguards may include encryption, hashing, access controls, token rotation, rate limits, audit records, moderation, metadata removal, and retention controls. These measures reduce risk but cannot guarantee security or anonymity.
If a security incident requires notice under applicable law, the responsible operator will provide notice through legally appropriate channels. Users should avoid entering unnecessary identifying or sensitive information.
23. International transfers
Hosting and service providers may process information outside your state, province, or country. Where required, the operator must implement an appropriate transfer mechanism and disclose relevant processing locations.
24. Children and sensitive users
The service is not directed to children under 13, and the operator does not knowingly seek personal information from them. Jurisdictions with a higher digital-consent age may impose additional requirements.
Because community-safety information can be sensitive, all users should minimize identifying details about themselves and others. Contact the operator to request review of information believed to concern a child.
25. Do Not Track and preference signals
Browser “Do Not Track” signals are not governed by a single accepted standard. The operator should honor legally required opt-out preference signals where applicable. The documented service does not use personal information for cross-context behavioral advertising.
26. Contact and complaints
Privacy questions, rights requests, complaints, and security reports may be sent to support@aromap.org. For Optional Support privacy or billing questions, you may also use the same address or the in-app contact form.
If you are not satisfied with our response, you may have the right to contact a data-protection or consumer authority where you live.
27. Optional Support payments
When you send Optional Support, Transup Tech LLC receives payment details needed to recognize your tip and manage subscriptions: amount, currency, cadence (one-time or monthly), status, timestamps, and Stripe identifiers. Stripe processes the payment and stores card data. ARO and Transup Tech LLC never see or store your full card number, CVV, or banking credentials. We may show only card brand and last four digits for cards you choose to save.
Support history is used to display your tips in the app, process cancellations and refund requests, prevent fraud, keep financial records, and comply with law. Optional Support is voluntary and is not a charitable donation. See the Refund and Cancellation Policy for how to cancel monthly support or request a refund.