CoRa-TrackLegal & Support

PRIVACY POLICY FOR THE CORA-TRACK APP AND CONNECTED TRACKING SERVICE

Last updated: 5 September 2026

1. Controller and contact

The controller responsible for processing personal data in connection with the CoRa-Track mobile application, the app account and the connected tracker service is:

TrackDown UG (haftungsbeschränkt) c/o Am Technologiehof Münster - GründerGarage Mendelstraße 11 48149 Münster Germany

Email: admin@cora-track.de Privacy contact: Tobias Nickut

No data protection officer has currently been appointed. Privacy enquiries can be sent to the address above.

2. Scope and intended use

CoRa-Track is an asset-tracking service for locating, protecting and managing the user's own trackers and associated assets. It is not intended for covert monitoring of people. Users must not attach or assign a tracker to another person or monitor a person without a valid legal basis and, where required, that person's prior knowledge and consent.

This policy covers the mobile app, app API, IoT communication with trackers, push notifications, subscriptions for tracker connectivity and the public app-account deletion and password-reset processes. The separate web-shop privacy policy applies to purchases of physical products.

3. Data processed, purposes and legal bases

3.1 Account, authentication and legal-document records

TrackDown processes the email address, password hash, email-verification state, account timestamps, accepted Terms versions, acknowledged Privacy Policy versions, cryptographic document hashes, locale and app version at acknowledgement, login and password-change timestamps, hashed one-time verification, reset and deletion tokens, token expiry and use status, refresh-token hashes, IP address, user agent and security events. Passwords, refresh tokens and one-time tokens are not stored in plain text on the server.

Purposes are account creation, authentication, secure session restoration, email verification, password reset, account administration, proof of the applicable contractual terms and privacy information, fraud and abuse prevention and protection of the service. The legal bases are Art. 6(1)(b) GDPR for providing the account and service, Art. 6(1)(c) GDPR for legal documentation duties and Art. 6(1)(f) GDPR for service security, abuse prevention and the establishment, exercise or defence of legal claims.

3.2 Tracker, pairing and configuration data

TrackDown processes pairing IDs, tracker factory identifiers such as the factory MAC address, hardware and firmware versions, SIM and cellular device identifiers where required for connectivity, SIM activation and permanent-deactivation timestamps, the scheduled manual-review date, shop order reference, product variant and purchase time, user-defined tracker names, authentication and proximity-key material, tracker parameters and their change history, provisioning timestamps, connectivity state, radio access technology, connection and disconnection causes and technical device status.

These data are required to associate a tracker with the account, authenticate and provision it, apply configuration, provide firmware updates, manage connectivity and operate the tracking service. The legal basis is Art. 6(1)(b) GDPR. Security-related processing is also based on Art. 6(1)(f) GDPR.

3.3 Tracker positioning and network-environment data

At the user's request or according to tracker configuration, TrackDown processes current or last-known tracker coordinates, positioning method, estimated horizontal accuracy, timestamps and technical positioning status. For network-based positioning, mobile-network data and detected WLAN access-point identifiers (BSSIDs), network names (SSIDs), channels and signal strengths may be processed. The BSSID and signal data required for a request may be sent to the Google Geolocation API, which returns an estimated position and accuracy.

Google Geolocation latitude and longitude are made available only for the permitted retention period and are automatically deleted no later than 30 consecutive calendar days after the relevant positioning event. Independently determined GNSS coordinates are not subject to this provider-specific 30-day limit but are deleted with the pairing or account unless a longer retention is legally required.

The legal basis for requested tracker positioning and display is Art. 6(1)(b) GDPR. Security and misuse prevention may additionally rely on Art. 6(1)(f) GDPR.

3.4 Phone location and map display

If the user grants the required operating-system permission, the phone's current location may be processed while the relevant map function is used to display the user's position and estimate distance to an asset. Map tiles, styles and related map requests are provided by Mapbox. The Mapbox mobile SDK may send de-identified location and usage telemetry to Mapbox by default. The visible, clickable Mapbox attribution control provides the Mapbox information and individual telemetry opt-out required by the SDK terms. The app clearly distinguishes network-based Google positioning from GNSS positioning. Denying or withdrawing phone-location permission prevents these phone-location functions but does not delete previously reported tracker locations.

Processing requested phone-location and map-display functions is based on Art. 6(1)(b) GDPR. Mapbox SDK telemetry is based on Art. 6(1)(f) GDPR, with the legitimate interests of reliable, secure and licence-compliant map operation; users can object by using the Mapbox telemetry opt-out in the attribution control. The operating-system permission can be withdrawn in the device settings at any time; the related phone-location function will then stop.

3.5 Status, proximity and sensor data

TrackDown processes tracker battery voltage; radio metrics such as RSSI, RSRP, RSRQ and SINR; cell and network information; proximity detections; buzzer, lost-device and proximity-fence requests and events; tracker pressure and temperature; and, if supported and requested, a smartphone barometer reference value. These data are used to show device status, estimate proximity and relative height, trigger alerts and diagnose technical problems. The legal basis is Art. 6(1)(b) GDPR.

3.6 Technical logs, WLAN identifiers and diagnostics

The tracker, API and IoT servers process timestamps, request paths, truncated or necessary IP and connection metadata, error information, security events, transferred data volumes and diagnostic messages. Logs are used to operate, secure and debug the service, detect attacks, enforce technical limits and investigate incidents. Authentication private keys and proximity private keys are not intended to be included in application logs.

General server and security logs are normally retained for up to 30 days. Where raw diagnostic log content contains WLAN SSIDs or BSSIDs, that raw field is automatically removed no later than 90 days after the entry. A longer restricted retention may occur only where necessary to investigate a specific security incident, comply with law or establish, exercise or defend legal claims. The legal basis is Art. 6(1)(f) GDPR and, where necessary to provide the requested service, Art. 6(1)(b) GDPR.

3.7 Push notifications

If notifications are enabled after a tracker is added, TrackDown processes a Firebase Cloud Messaging device token and sends event information such as loss or proximity alerts. On iOS, delivery also uses Apple Push Notification service. Notification permission is voluntary and can be withdrawn in system settings. Disabling it does not prevent use of the remaining app functions. Processing is based on Art. 6(1)(b) GDPR for the requested alert function.

3.8 Subscription, billing and connectivity-usage data

Subscriptions fund tracker mobile-network access and operation. TrackDown processes user ID, tracker factory identifier, payment-provider customer and subscription identifiers, selected plan, status, start and end dates, payment status, application-message and geolocation-request counts and transferred data volumes. To document the pre-contractual withdrawal information, an express request for immediate service performance and delivery of the contract confirmation by email, TrackDown also stores the withdrawal-information version and cryptographic document hash together with the acknowledgement, immediate-performance request and contract-confirmation timestamps. Payment-card data is entered into the external payment service provider's secure interface and is not stored by TrackDown UG.

SIM lifecycle data is also used to identify devices that have had no applicable paid subscription for six consecutive calendar months and submit the SIM for a manual deactivation review. The recorded end of the six-month period is only the earliest possible manual-deactivation date; review and deactivation may take place later, but never earlier. Notice of the possible deactivation is presented in the applicable contractual information and, before app-account deletion, together with the device-specific earliest date. Where a usable account or order contact email is still lawfully held, reminder emails are initiated manually; no automated inactivity-reminder email or permanent provider deactivation is performed. The legal basis is Art. 6(1)(b) GDPR for subscription and device-service administration and Art. 6(1)(c) GDPR for statutory accounting obligations. Fraud prevention, payment security and the prevention of indefinite connectivity costs for unused devices may also rely on Art. 6(1)(f) GDPR, balanced against the advance-notice and contact options described in the Terms.

3.9 Support, account deletion and withdrawal requests

For support and account-deletion processes, TrackDown processes contact and request content, a hashed one-time confirmation token, request time, IP address and user agent. Before account deletion, the app or confirmation page displays any applicable earliest permanent SIM-deactivation date and the consequences of deletion. The app-account email is deleted with the account, is not retained for SIM-lifecycle reminders and therefore cannot be used for a later reminder associated with that app account.

For a subscription withdrawal, TrackDown processes the subscription reference, declaration and confirmation timestamps, IP address and user agent and sends a receipt confirmation to the account email address. Where a subscription cannot be cancelled automatically during account deletion, limited contact and subscription identifiers may be sent to the responsible administrator so that cleanup can be completed. Processing is otherwise based on Art. 6(1)(b), Art. 6(1)(c) and Art. 6(1)(f) GDPR.

4. Recipients and processors

Personal data is disclosed only where necessary. Recipients and service providers may include:

  • STRATO AG, Germany, for hosting, infrastructure and email;
  • the external payment service provider and its affiliated entities for payment, subscriptions, billing, fraud prevention and legally required payment records;
  • Google Ireland Limited and affiliated Google entities for Firebase Cloud Messaging and Google Geolocation API requests;
  • Apple Distribution International Limited and affiliated Apple entities for APNs and App Store distribution;
  • Mapbox, Inc. and affiliated entities for map display and map resources;
  • Hologram and participating mobile-network operators for tracker SIM connectivity, network signalling and connectivity administration;
  • shipping, support, tax, accounting, legal and security service providers where required;
  • public authorities where disclosure is required by law.

Processors acting on behalf of TrackDown are bound by data-protection obligations. Some providers process data as independent controllers for their own security, billing or regulatory duties.

Provider information: - Payment service provider: its identity, applicable terms and privacy information are displayed in the secure payment interface; - Google: https://policies.google.com/privacy - Google Maps Platform terms: https://cloud.google.com/terms/maps-platform/eea - Google Maps end-user terms: https://maps.google.com/help/terms_maps/ - Apple: https://www.apple.com/legal/privacy/ - Mapbox: https://www.mapbox.com/legal/privacy - Hologram Products Privacy Statement: https://www.hologram.io/products-privacy-statement/ - STRATO: https://www.strato.de/datenschutz/

5. International transfers

Some providers may process data outside the European Economic Area, particularly in the United States. Where no adequacy decision applies, transfers are based on appropriate safeguards such as the European Commission's Standard Contractual Clauses and supplementary measures. Where applicable, a provider's certification under the EU-US Data Privacy Framework may also be relied upon. Details can be requested at admin@cora-track.de.

6. Storage and deletion

Personal data is retained only for as long as necessary:

  • account and operational tracker data: until deletion of the account or pairing, unless a statutory retention duty or unresolved legal claim applies;
  • Google Geolocation latitude and longitude: no longer than 30 consecutive calendar days;
  • GNSS positions and other tracker history: until the pairing or account is deleted, subject to any shorter configured product limit and legal requirements;
  • access tokens: approximately 15 minutes; rotating refresh-token families: no longer than 180 days without a new login and revocable on logout or password change;
  • one-time email-verification, password-reset and deletion tokens: until used or expired; reset and deletion links normally expire after 24 hours;
  • push tokens: until replacement, removal or account deletion;
  • SIM factory identifiers, activation/deactivation state, purchase reference and manual-review deadline: for the device-service lifecycle and only as long as required for connectivity administration, statutory obligations or legal claims;
  • general server and security logs: normally up to 30 days; raw WLAN identifiers in diagnostic logs: no longer than 90 days, subject to incident/legal holds described above;
  • support correspondence: until completion and, where required, for the applicable limitation period;
  • invoices, payment and tax records: for applicable statutory periods, commonly six, eight or ten years depending on the record.

Deleting a pairing removes pairing-related operational data. Deleting the account removes the app account and associated operational data. Device-level SIM identifiers, purchase reference and lifecycle dates can remain without an account to administer the already supplied physical device. The deleted account email is not retained or linked to those records for a later reminder. Payment service providers, mobile-network operators and other independent controllers may retain records required by their own legal obligations.

7. Security

Connections between app and API use HTTPS with certificate validation. Passwords are hashed, access and refresh tokens are separated and rotated, refresh tokens are stored in the platform key store on the phone, requests are rate-limited, and tracker data is protected by authentication and account-ownership checks. Access to production systems and key material is restricted to authorized personnel. No system can guarantee absolute security. Suspected incidents should be reported to admin@cora-track.de.

8. No advertising, sale or cross-app tracking

TrackDown does not sell personal data, use it for third-party advertising or use advertising identifiers to track users across unrelated apps or websites. The app contains no third-party advertising SDK.

9. Automated technical actions

The service may automatically apply technical usage limits, schedule reconnects or create alerts from tracker events. A possible permanent SIM deactivation is reviewed and performed manually and cannot take place before the recorded six-month period has ended. The software does not autonomously send inactivity-reminder emails or contact the connectivity provider for this purpose; any reminder and provider deactivation are initiated manually. The service does not perform solely automated decision-making that produces legal or similarly significant effects within Art. 22 GDPR.

10. Requirement to provide data

Account, tracker, authentication and connectivity data are necessary to provide the service. Phone location, notifications and smartphone barometer access are optional; the related functions are unavailable when permission or sensor support is absent.

11. Data-subject rights

Subject to statutory requirements, data subjects have rights of access, rectification, erasure, restriction, data portability and objection to processing based on Art. 6(1)(e) or (f) GDPR. Where processing is based on consent, consent can be withdrawn at any time with future effect. The lawfulness of prior processing remains unaffected.

Requests can be sent to admin@cora-track.de. An app account can also be deleted in the app or through https://cora-track.com/en/account-deletion.

12. Complaint

Data subjects may lodge a complaint with a supervisory authority. The supervisory authority responsible for the controller is generally:

Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen Kavalleriestraße 2-4 40213 Düsseldorf, Germany https://www.ldi.nrw.de/

13. Changes

This policy is updated when the service, legal requirements or providers change. Material changes are presented in the app. Where renewed agreement to contractual Terms is required, this is requested separately; the Privacy Policy itself is provided for acknowledgement and transparency.