Privacy policy
How Blue Light Maps Ltd collects, uses, and protects personal data.
Your privacy matters to us. Blue Light Maps Limited (âBlue Light Mapsâ, âweâ) builds mapping software for emergency responders, and this policy explains what personal information we collect, why we collect it, and what happens to it. We have tried to write it the way we would want to read it: grounded in what the product actually does.
Blue Light Maps is the data controller for the personal information described here. You can contact us about anything in this policy at data@bluelightmaps.com.
This policy is effective as of 28 March 2023. Last updated: 31 July 2026
The short version
- If you use the app, your location powers the mapping. Within 48 hours, we permanently de-identify position data so it is no longer linked to you or your device.
- Your personal information is stored on servers and databases in the UK and EU.
- We do not sell personal information and we do not use it for advertising.
- If you delete your account, we delete your personal information within 28 days.
- The small number of things we keep for longer are listed below, each with the reason why.
How this policy is organised
People come to Blue Light Maps in different ways, so this policy is in three parts. Start with the one that describes you:
- The responder app: you navigate with Blue Light Maps, as an individual subscriber or on a device provided by your organisation
- Our website and communications: you visit bluelightmaps.com, contact us, or receive updates from us
- Organisations we work with: you deal with us on behalf of an emergency service or another organisation
- Developer APIs: you build with our APIs, or use a service built on them
The sections from âHow long we keep personal informationâ onwards apply to everyone. As we release new products, we will add a part here for each one.
The responder app
Your account
If you subscribe directly with us (not via a third party App Store), we hold your email address, your name, and the organisation you tell us you belong to. We use these to run your account, handle invoicing, respond when you contact us, and tell you about important changes to the service. Subscriptions are handled by RevenueCat and either your app store or Stripe. Direct payments are processed by Stripe; we do not hold your card details ourselves.
If you subscribe through the Apple App Store or Google Play, your payment details and billing relationship sit with Apple or Google under their own privacy policies, and they never reach us. What we receive, through RevenueCat, is confirmation of your subscription status and receipt data, so we can unlock the service for you.
If you take part in a trial or pilot, we hold the sign-in details you create for it, managed through Auth0.
Deployments managed by your organisation work differently: see âIndividual subscriptions and managed deploymentsâ below.
Location while you navigate
The app uses your deviceâs position, speed, and heading to give you routing, ETAs, and improve the map for other users. This is the core of the product, and it cannot work without location access.
Within 48 hours, we permanently remove the link between position data and your account and device. In its place we use a random identifier that we cannot trace back to you, kept only so we can tell that a sequence of positions belongs to the same device. We use new identifiers each time we de-identify data, so journeys from different periods cannot be linked to each other. We keep this de-identified journey data to improve our routing and road data.
Blue Light Alert
When you drive under emergency conditions, if the Blue Light Alert add-on is enabled, anonymised sets of coordinates, times, and direction are shared with driver-facing platforms to warn other drivers of your presence. Today that means Google, including Waze. Over time we may add other providers, such as vehicle manufacturers, so that warnings reach more drivers. No personal information is ever included with this data.
Improving road closure data
Like other mapping providers, we automatically use location and speed data to detect road closures and keep closure information current. This data is de-identified on the same 48-hour schedule described above. We rely on our legitimate interest in keeping road data accurate for emergency response. You have the right to object at any time by contacting data@bluelightmaps.com.
Road reports
When you manually report a road closure or hazard, we keep the report together with a reliability history for the reporting device, so we can judge how much weight to give future reports from the same device. We keep reports and this reliability history for as long as they stay useful for that purpose: a long history is exactly what makes reliability judgements possible.
Route ratings
Rating a route is optional. If you rate one, we store the rating with the start and end locations of that journey so we can review and improve the routing algorithm. Ratings stay linked to your account for 3 months in case we need to contact you for more detail, and are then de-identified in the same way as position data.
Errors and diagnostics
When something goes wrong, we automatically collect technical details about the error and the state of the app using a third party, Sentry. We use this only to find and fix problems, and it is kept for 90 days.
Individual subscriptions and managed deployments
Individuals subscribe personally, through an app store or directly with us; the account information we hold is described under âYour accountâ above. We send individual subscribers occasional product updates and marketing: see âProduct updates and marketingâ below, including how to opt out.
Managed deployments are set up by your organisation, often on shared in-vehicle tablets used across shifts. For these, we hold no names, email addresses, or other account information about an organisationâs users. Devices send location data, which is handled exactly as described above. If your organisation enables the location sharing add-on, the callsign or identity configured for a device is visible to other users of that deployment so crews understand which resources are which; that identity may be chosen and controlled automatically by your organisation, or by individual users.
Our website and communications
Visiting our website
Our website is delivered by Cloudflare and uses cookies for core functionality. We use Google Analytics to understand how the site is used; analytics cookies are set only if you accept them through the cookie banner, and until then only cookieless, aggregated signals are sent to Google. We do not use cookies for advertising. The app itself does not use cookies; it uses session tokens to keep you signed in.
When you contact us
If you email us, use the contact form on our website, or raise a support request, the correspondence is managed through a third party, Zoho. We keep it for as long as needed to resolve the issue and to maintain a sensible history of our support relationship with you.
Product updates and marketing
We only ever send marketing to individual subscribers and to people who have asked to hear from us, for example by getting in touch, signing up on our website, or leaving their details at an in-person event. You can opt out at any time using the link in any message or by contacting us. Notifications to individual subscribers are delivered through OneSignal using a device token, never your name or email address.
Organisations we work with
If you deal with Blue Light Maps on behalf of an emergency service or another organisation, in a procurement, legal, IT, or operational role, this part describes the personal information we hold about you and your colleagues. How the app treats your crewsâ data is covered in âThe responder appâ above.
Business contacts
We hold the contact information you share with us: your name, work email address, phone number, role, and organisation, together with our correspondence and records of meetings, trials, and agreements. We use this to run our relationship with your organisation: answering questions, arranging pilots and deployments, invoicing, and keeping you informed about the service. This information is managed in Zoho.
We keep these details on an ongoing basis: many people want to stay across what we are doing even when we are not actively working together. If that is not you, tell us and we will remove your details.
Custom data layers
Organisations can upload their own data layers, such as event plans, hydrant locations, and asset positions. These are geospatial data and contain no personal information, so they sit outside this policy; we treat them as your organisationâs confidential data.
Your organisationâs deployment
For devices in a managed deployment, we hold no names, email addresses, or account information about the people using them. Devices send location data, which is handled exactly as described in âLocation while you navigateâ, including the 48-hour de-identification. If your organisation enables the location sharing add-on, the callsigns or identities configured for devices are visible within your deployment, as described under âIndividual subscriptions and managed deploymentsâ.
Developer APIs
Alongside the responder app, we offer APIs that developers and organisations can build into their own systems, such as routing and isochrone calculation.
Your API account
If you sign up for API access, we hold the account details you give us, the API keys we issue you, and usage records for each key so we can run, meter, and secure the service. We manage accounts and billing ourselves, and invoicing runs through Zoho like our other business correspondence.
What happens to API requests
Requests to our APIs contain the data needed to answer them: a route calculation, for example, includes start and end coordinates. We use the content of a request only to compute the response. We do not store it, we do not use it to improve our products, and we do not share it.
There are two technical exceptions. Our API gateway automatically keeps an operational log of each request: the IP address it came from, the endpoint called, the time, and the response status, but not the content of the request. We use this log for security and reliability, and keep it for 14 days. And if a request fails, we keep technical details of the error so we can investigate and fix the problem, which can include the content of the failing request; error records are kept for 90 days, the same as âErrors and diagnosticsâ above.
Services built on our APIs
Our API customers build their own products. If you use one of them, the personal information it collects about you is the responsibility of that provider under its own privacy policy. What reaches us is the content of its API requests, which we handle as described above.
How long we keep personal information
| Information | How long |
|---|---|
| Account details | While your account exists; deleted within 28 days of account deletion |
| Position data (location, speed, heading) | Linked to you for up to 48 hours, then permanently de-identified |
| Route ratings | Linked to your account for 3 months, then de-identified |
| Road reports and device reliability history | For as long as useful for judging report reliability |
| Error and diagnostic data | 90 days |
| Support correspondence | While relevant to our support relationship with you |
| Business contact details and correspondence | On an ongoing basis, so we can keep you informed; removed when you ask |
| API gateway logs | 14 days |
We may keep specific records for longer where we have a legal, accounting, or reporting obligation, or to establish, exercise, or defend legal claims.
Who we share personal information with
We use a small number of service providers to run Blue Light Maps, each doing a specific job:
- Auth0: sign-in and account security
- RevenueCat and your app store: subscription management
- Stripe: payment processing for direct subscriptions
- Sentry: error and crash reporting
- Zoho: support, email, invoicing, business contact records, and website contact form submissions
- OneSignal: product update and marketing notifications for individual subscribers, using device tokens only, never names or emails
- Krystal: UK-based server hosting
- AWS: database hosting, in UK and EU regions
- Cloudflare: website delivery
- Google Analytics: website usage statistics, only if you accept analytics cookies
We also disclose information where the law requires it: to courts, regulators, or law enforcement, or to establish, exercise, or defend our legal rights. If Blue Light Maps is acquired, personal information would transfer with the business, and this policy would continue to apply to it.
Separately, Blue Light Alert warnings go to the driver-facing platforms named in that section; those contain anonymised coordinates only, never personal information.
That is the whole list. We do not sell personal information, we do not share it with advertisers, and we do not pass it to marketing partners.
Where your data lives
Your personal information is stored on servers and databases in the United Kingdom and the European Union: our servers are hosted in the UK with Krystal, our database runs in AWS UK and EU regions, and our sign-in (Auth0), error reporting (Sentry), and support (Zoho) providers are all configured for UK and EU data residency.
There are a small number of exceptions involving processing in the United States. RevenueCat, which manages individual subscriptions, processes data in the US under EU Standard Contractual Clauses and the UK Addendum. OneSignal, which delivers our notifications, processes device tokens in the US. For our website only, Cloudflare (delivery) and Google Analytics (statistics, only with your consent) also involve US processing. These transfers are protected by the EU-US Data Privacy Framework and the UK-US Data Bridge, or standard contractual clauses. Nothing else leaves the UK and EEA.
Our legal bases
Where UK and EU data protection law asks us to name a legal basis, ours are: performance of a contract (running the app and your account), legitimate interests (improving routing and road data, judging report reliability, keeping the service secure, and managing our relationships with the organisations we work with), consent where we ask for it (such as device location permission and marketing), and compliance with legal obligations.
If we ever rely on consent from someone under 16, we will seek a parent or guardianâs agreement. Our products are not aimed at children under 13, and we do not knowingly collect their personal information.
Your rights
You can ask us at any time to:
- Access the personal information we hold about you
- Correct anything inaccurate or out of date
- Delete your personal information (account deletion is available in-app; we delete within 28 days)
- Restrict or object to processing, including any processing based on legitimate interests
- Port your data: we will provide it in a machine-readable format
Contact data@bluelightmaps.com to exercise any of these. We may ask you to confirm the request from your registered email address. If you are unhappy with how we handle your personal information, you can complain to the Information Commissionerâs Office (ico.org.uk) or your local data protection authority.
Security
We hold Cyber Essentials Plus certification and protect personal information with encryption in transit, access controls, and UK/EU-only hosting. No method of electronic transmission or storage is 100% secure, and no one can honestly guarantee absolute data security; we work to make a breach as unlikely, and as limited, as possible.
Third-party links
The app and website may link to third-party sites, such as Ordnance Survey copyright pages or Wikipedia articles for points of interest. Those sites have their own privacy policies, and this one does not cover them.
Changes to this policy
When we change this policy, we will post the update here. If a change is significant, we will contact all registered users with the details before it takes effect, and where the law requires it we will ask for your consent.