Legal
Privacy Policy
Last updated: 2026-07-11
This Privacy Policy explains how Wetapoint collects, uses, and shares personal information when you use our website at wetapoint.com, our mobile applications, and any related APIs (together, the “Service”).
We act as a data controller for account holders who sign up directly. For personal data about end-users of an organisation that uses the Service (field operators, volunteers, staff), we act as a data processor on behalf of that organisation.
1. Who controls your data
MB "Wetapoint", Papiškių g. 19-1, LT-06282 Vilnius, Lithuania. Registration number: 308011788. For any privacy-related question, contact privacy@wetapoint.com.
2. What we collect
Account information
- Name, email address, and protected account credentials.
- Organisation name at registration.
- Optional profile details you choose to add: phone number, role description, profile photo.
Device location
- Real-time GPS coordinates while you are signed in and location sharing is enabled. If you grant background-location permission, sharing may continue while the app is in the background or your screen is locked, until you stop sharing, sign out, or disable the permission. Each location update includes latitude, longitude, altitude, accuracy, heading, speed, the network type in use (Wi-Fi, cellular, or unknown), the time it was recorded, the identifier(s) of any operation or event it relates to, and a device identifier (a stable random identifier generated when the app is installed), and general device information such as operating-system and device model.
Push notifications
- Device push tokens issued by Apple (APNs) and Google (Firebase Cloud Messaging), stored so we can deliver notifications to your device.
- When a notification is sent, its title, body, and a reference to the related record (for example, a task identifier) pass through Apple's or Google's push-notification infrastructure to reach your device.
Uploaded files and media
- Images, videos, and documents you attach to tasks, incidents, or messages.
- Push-to-talk (PTT) radio audio transmissions you record and send through organisational channels.
- Live video streams you broadcast via the mobile “Go Live” feature and talkback audio sent by dashboard operators. Live streams are relayed in real time through our media server and are not recorded or stored by Wetapoint.
- Camera feeds from customer-connected devices that are relayed through the Service.
Audit logs and metadata
- IP address, browser user-agent, and device information in server-side audit logs.
- Authentication events (sign-ins, token refreshes), request IDs, and operational telemetry.
Organisation-managed accounts
If your account is managed by an organisation (for example, as a field operator, volunteer, or staff member), the organisation is the data controller and determines what data is collected about you. Authorised administrators and operators in your organisation may be able to see your real-time location while you are on duty, messages you send in organisational channels, PTT radio transmissions, and task or incident activity attributed to you. Wetapoint processes this data on the organisation's behalf as a data processor.
Your organisation may create your account or provide account and role information about you. Ask your organisation for its own privacy notice and the legal basis on which it uses the Service.
Billing information
- Plan, billing email, and subscription history. Payment card details are collected and stored by Stripe — we never see full card numbers.
3. Why we use data and our lawful basis
For organisation-managed data, your organisation determines the purposes and lawful basis and Wetapoint processes the data on its documented instructions. Where Wetapoint acts as controller, the main purposes and bases are:
- Account, identity, device identifiers, service content, and enabled location: to provide the requested Service, authenticate users, support collaboration, and deliver notifications. The basis is performance of our contract or steps requested before entering it.
- Security and operational records: to protect users, prevent misuse, diagnose faults, and maintain reliable service. The basis is our legitimate interest in operating a safe and dependable Service. You may object where the law gives you that right.
- Billing and transaction records: to administer the subscription and meet tax, accounting, and other legal duties. The bases are contract performance and compliance with legal obligations.
- Marketing communications: consent where required. You can withdraw consent at any time.
Name, email, credentials, and the information needed for a selected feature are required to provide that account or feature. Without them, it may not work. Profile details, marketing consent, and features such as location sharing, camera, microphone, or notifications are optional; declining them only limits the relevant feature.
We do not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects, and we do not profile users for advertising.
4. Retention
- Account and profile data: retained while your account is active. When you request erasure yourself, profile information — name, contact details, credentials, and device tokens — is deleted immediately. When an organisation removes a member, that profile information is deleted after a 30-day administrative window. Limited identifiers may remain in restricted audit records, as described under “Disabling, deletion, and erasure” below.
- Location pings: retained according to your organisation's configured retention schedule, capped by plan (30 days on Free and Starter, 90 days on Team, 365 days on Business; custom on Enterprise), then deleted from primary storage. Location history remains personal data until it is actually deleted. Copies may persist in encrypted off-site backups until those backups age out (up to six months).
- PTT radio audio: content is deleted 30 days after recording. Minimal event metadata may be retained where needed for security, accountability, or legal obligations, no longer than the applicable audit-record period.
- Live video: not stored. Streams are relayed in real time and discarded when the broadcast ends.
- Audit records: identifiers are removed from audit records on a categorised schedule — after 1 year for authentication and technical security events, after 3 years for operational activity records, and after 7 years for administrative, account, and billing governance records. The event record itself (action type and timestamp) is retained append-only.
- Backups: rolling 14-day window of on-server database backups, plus encrypted off-site backups kept on a rolling snapshot schedule of 14 daily, 8 weekly, and 6 monthly snapshots (approximately six months at most). Data inside a backup is purged when the snapshot itself ages out. If a backup is restored, our retention and deletion processes are re-applied to the restored data.
- Billing records: retained for the period required by the accounting and tax legislation applicable to us.
- Organisation data after subscription ends: when an organisation's subscription is terminated or deactivated, its administrators retain export-only access for 30 days. After that window an automated process permanently deletes the organisation's data from primary storage, keeping only a minimal billing and audit record. Copies in encrypted off-site backups age out on the snapshot schedule above (up to approximately six months).
Disabling, deletion, and erasure
Three different actions have three different effects:
- Disabling a user: when an organisation administrator disables a user, access is revoked immediately — active sessions and refresh tokens are invalidated, push and device tokens are removed, sign-in is blocked, and location reporting and realtime connections stop. Disabling an account does not by itself delete the user's historical activity. Who disabled the account, and when, is recorded.
- Profile deletion: when you request erasure from your account settings, profile information that is no longer required — name, contact details, credentials, and device tokens — is deleted immediately. When an organisation removes a member, the same profile information is deleted after a 30-day administrative window. Content previously contributed to the organisation's workspace (tasks, incidents, message threads) may remain under the organisation's retention instructions and may be displayed as contributed by a deleted user.
- Organisation deletion: as described under “Organisation data after subscription ends” above.
Limited identifiers may remain in restricted audit records where necessary for security investigations, compliance with applicable law, or the establishment, exercise or defence of legal claims; these records are retained only for the periods in the audit-record schedule above and are not used for ordinary product functionality. Location history, audio recordings, and other operational data are deleted according to the organisation's configured retention schedule. Removing a user's profile does not make such data anonymous where the individual may still be identifiable from the remaining information.
You can download a machine-readable export of your data and request erasure of your account from your account settings inside the Service.
5. Recipients and sub-processors
We share personal information only with the service providers listed on our Sub-processors page. Each is bound by contract to process data only on our instructions.
Push notifications are delivered through Apple Push Notification service (for iOS devices) and Google Firebase Cloud Messaging (for Android devices). Your device push token and the content of each notification (title, body, and a reference to the related record) pass through Apple's or Google's infrastructure for delivery only.
We do not sell personal information.
6. International transfers
The Service is hosted in the European Union. Some service providers may process data outside the EEA. Where a restricted transfer occurs, we require an applicable lawful safeguard in the provider's terms, such as an adequacy decision or recognised framework, or the European Commission's Standard Contractual Clauses, as appropriate to that provider and transfer.
7. Your rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you.
- Have inaccurate information corrected.
- Have your information deleted where no overriding legal ground requires retention.
- Restrict or object to certain processing.
- Receive a portable copy in a structured, machine-readable format.
- Withdraw consent at any time where processing is consent-based.
- Lodge a complaint with your local supervisory authority, including Lithuania's State Data Protection Inspectorate (VDAI).
How to exercise your rights
Email privacy@wetapoint.com. We respond without undue delay and normally within one month. Where permitted, we may extend this by up to two further months because of the request's complexity or number; we will tell you within the first month and explain why.
8. Cookies
See our Cookie Policy for the full list and your options.
9. Children
The Service is not intended for children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@wetapoint.com and we will delete it.
10. Changes to this policy
Material changes will be announced to active account holders by email at least 30 days before they take effect. The “Last updated” date at the top reflects the most recent revision.
11. Contact
MB "Wetapoint", Papiškių g. 19-1, LT-06282 Vilnius, Lithuania.
privacy@wetapoint.com