Privacy policy
Last updated: 2026-10-08
This policy explains what Velomo (“we”, “us”) collects when you use the Velomo app and the velomo.app website, why, and what you can do about it. If anything is unclear, write to privacy@velomo.app.
In short
No ads, no selling of data, no tracking across other sites. You don’t need an account to use the app: your rides, saved places and settings stay on your phone. Our server only receives what it needs to work, and you can delete everything, on your phone and on our server, at any time.
Who is responsible
The Velomo team in Bangkok, Thailand, is the data controller for the app and this website under Thailand’s Personal Data Protection Act (PDPA). Contact: privacy@velomo.app.
This website
Sign-up to be notified. If you leave your email to hear when Velomo opens, we store the email, the city and phone type you chose, the page language and the date. We use it only to tell you when Velomo opens for you. To stop the same person signing up many times, we also store a one-way fingerprint of your internet address, from which the address itself cannot be read back.
No tracking cookies. The website sets no cookies for visitors. We may count visits with Cloudflare Web Analytics, which works without cookies and does not identify you. Only the Velomo team’s own sign-in to edit the website uses a cookie.
Hosting. The website, its database and its images are run by Cloudflare. Cloudflare processes your internet address and technical data to deliver the pages and protect them from attacks.
The app
What stays on your phone. Your location while you use the app, your rides (including their GPS tracks), saved places, recent searches, settings, profile and emergency contact. We can’t see any of it.
What our server receives, and why.
- A route you ask for: the start, stops and destination, and your route options. Used to calculate the route, then discarded.
- A place you search for: the text you type and the map area. Not stored by us.
- An anonymous account, made in the background the first time you send a report, move a place’s pin or turn on Friends: a random account number, when it was made and last used, the app version and the kind of device. No name, email or phone number.
- A hazard report you send: its type, location, time and route type, linked to your anonymous account so one rider can’t confirm a report twice and you can remove your own. The report itself is shown on the map without any account, for 3 days to a year depending on its type.
- A pin you move: the place, the old and new position. Used for everyone once two riders agree.
- Friends, if you turn them on: a random friends ID, the name and avatar colour from your profile, your distance, CO₂ and ride totals per week, month and all time, and who your friends are. Only you and your friends see it. Never your routes, places or photo.
- A live ride you choose to share: your position, direction, destination and route, visible to anyone with the link. Kept in memory only and gone 30 minutes after the last update.
Coming later. Sign-in with Google or email, to keep your rides when you change phones. We will update this policy, and tell you in the app, before it starts.
What we do not do
We do not sell your data or share it for advertising. We do not run ads. We do not read your contacts or messages. Emergency calls and messages from the app’s SOS screen go through your own phone apps, not through us.
Service providers
- Supabase (anonymous accounts and our database), Tokyo, Japan.
- Our own server for routing, place search and the app’s data, in Tokyo, Japan.
- Cloudflare (this website and its database, delivery of the app, encrypted backups).
- Map, font and search services that your phone or our server connects to while you use the app (such as OpenFreeMap for map images). They see your internet address, and their own privacy policies apply.
Each provider only receives what it needs for its job. We will disclose data if the law requires it, and tell you unless we are legally prevented from doing so.
Where data is stored
The app’s data is stored in Tokyo, Japan. Encrypted backups are kept for up to 30 days with Cloudflare in the Asia-Pacific region. This website runs on Cloudflare’s global network. Where data leaves Thailand, we rely on the safeguards the PDPA requires.
How long we keep it
- Route requests and searches: not stored.
- Anonymous account, reports, pin fixes, friends: until you tap “Delete my data” in the app. Reports also expire on their own (3 days to a year). A pin fix you made stays, but no longer points to you.
- Live ride: 30 minutes after the last update.
- Sign-up email on this website: until we have told you Velomo opened for you, and at most two years, or earlier if you ask.
- Backups: up to 30 days.
Your rights
You can ask to see, correct, export or delete your data, and you can object to how we use it or withdraw your consent. In the app, “Delete my data” removes everything on your phone and on our server at once. For anything else, email privacy@velomo.app and we will answer within 30 days. In Thailand you can complain to the Personal Data Protection Committee (PDPC); in the EU or UK, to your data protection authority.
Children
Velomo is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
When we change this policy we update the date at the top of this page and, for significant changes, tell you in the app before they take effect.