Legal
Privacy Policy
CrashPin is a crowdsourced road-incident reporting app. This policy explains exactly what we collect, why, who sees it, and how to delete it.
Last updated: 3 August 2026 · Policy version
privacy-v2
Who we are
CrashPin is operated by PROVIDER_LEGAL_NAME ("we", "us"), a company incorporated in the Hong Kong Special Administrative Region, of PROVIDER_REGISTERED_ADDRESS. We are the data user (controller) for the information described below.
Privacy enquiries and data requests: privacy@crashpin.app.
Which privacy laws apply
Two regimes apply to CrashPin at the same time, and we comply with both:
- Hong Kong — the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO"), because we are a Hong Kong company. The regulator is the Office of the Privacy Commissioner for Personal Data ("PCPD").
- Australia — the Privacy Act 1988 (Cth) and the Australian Privacy Principles. CrashPin serves road users in South East Queensland and Northern New South Wales, which gives us an "Australian link" under section 5B of that Act. Being incorporated overseas does not remove those obligations, and we do not treat it as if it does. The regulator is the Office of the Australian Information Commissioner ("OAIC").
Where the two differ, we apply whichever gives you the stronger protection.
The short version
- To join we ask for an email address and nothing else. No name, no phone number, no date of birth, and no password.
- You are never named on the public feed. Incidents we publish carry no contributor identity at all — that is enforced in code, not just promised here.
- We collect your location only at the moment you submit a report, not in the background and not while the app is closed.
- We are a Hong Kong company, but your data is stored in Australia and you keep your full rights under Australian privacy law.
- We do not sell your data and we do not run third-party ad tracking.
What we collect
Account information
You can join openly, by invitation, or with a referral code. Either way we create an account holding: a generated account ID, the email address you gave, your trust level, any capabilities an operator has granted, the account that referred you (if any), and the date you joined. A session token is stored on your device so you stay signed in; it expires after 30 days and is revoked when you sign out or delete your account.
Location
When you submit a report, we collect the device location at that moment: latitude and longitude, accuracy, and — where the device provides them — speed, heading and whether the device appears stationary, walking or in a vehicle. We also store the location you confirm on the map, which may differ from your raw GPS position.
We do not track you in the background. CrashPin requests "while in use" location permission only. If you decline location permission you can still browse the map, but you cannot submit a live report.
Report content
The observation you submit: whether an incident appears present, the direction of travel, approximate vehicle count, obstruction level, whether emergency services were observed, a severity estimate, and an optional free-text note. Please do not put personal details of people involved in a crash into that note — see "Your responsibilities" below.
Photos (optional)
You may attach a photo. We store the image, its size, format, a checksum, and when it was captured and uploaded. EXIF metadata is stripped before any photo is used in published output. Photos are held for moderation and may be reviewed by us before publication.
Device integrity
To stop automated and fraudulent reporting, each report carries an installation attestation: an installation identifier, the platform (iOS/Android/web), and the result of an Apple App Attest or Google Play Integrity check. This tells us a report came from a genuine app install. It does not identify you personally.
Audit log
We record account and report actions — sign-in, submission, edit, cancellation, moderation — with the acting account ID and a timestamp. This exists for abuse investigation and safety-data integrity.
What we do not collect
No name, no phone number, no postal address, no date of birth, no password, no contact list, no advertising identifier, no background or continuous location, and no analytics SDK that profiles you across other apps.
If rewards ever become redeemable
Points are currently just points — there is nothing to cash out, and we ask for nothing beyond an email address. If we later allow points to be redeemed for something of real value, the law will require us to verify identity before paying anyone. That would mean asking for a legal name and possibly identity or tax details.
We would only ask at that point, only from people who choose to redeem, and only after telling you first. Nothing here obliges you to provide it, and declining would mean forgoing redemption rather than losing your account. We have written this section now rather than claiming "never", because a promise we might have to break is worse than one we can keep.
Why we use it
- To operate the service — placing your report on the map and combining it with nearby reports into a single incident.
- To assess confidence — location accuracy, device integrity, contributor trust level and the number of independent observations determine how confident an incident is.
- To prevent abuse — detecting fake, duplicated or automated reports.
- To meet legal obligations — responding to lawful requests and keeping records we are required to keep.
Who we share it with
The public incident feed
Confirmed incidents are published to a feed used by road-safety and recovery services. Before anything is published, our systems remove every contributor identifier — account ID, contributor record, installation ID, referral ID, reward and moderation records, and the internal source ID linking an incident back to your specific report. A published incident carries the location, observation, timing, confidence and a source category of "crowd" — never who reported it.
This removal is enforced by an automated check that refuses to publish any record still containing an excluded field.
Service providers
- Amazon Web Services — hosting and databases, in the Asia Pacific (Sydney) region.
- Google Maps Platform — map tiles and address lookup. Map interactions are subject to Google's Privacy Policy.
- Apple and Google — app distribution and the device integrity checks described above.
We do not
Sell your personal information, share it with data brokers, or disclose your identity to any third party — including insurers, repairers and recovery operators.
Where your data is stored, and who can reach it
Your data is stored in Australia. All CrashPin databases and backups run in Amazon Web Services' Asia Pacific (Sydney) region. Reports submitted in Queensland and New South Wales stay on Australian infrastructure.
We are a Hong Kong company, so our personnel access that Australian infrastructure from Hong Kong. That access is a cross-border disclosure under Australian Privacy Principle 8, and we remain accountable for your data under the Australian Privacy Act when it is handled from Hong Kong — the same standards in this policy apply to it there.
Hong Kong's own cross-border transfer provision (PDPO section 33) has not been brought into force. We nonetheless follow the PCPD's recommended approach to cross-border transfers, and contractually bind any processor handling CrashPin data to the protections set out in this policy.
In plain terms: moving the company offshore did not move your data offshore, and did not reduce your rights under Australian law.
How long we keep it
- Session tokens — 30 days, then they expire automatically.
- Account records — until you delete your account.
- Reports and incidents — retained as road-safety records. After you delete your account these remain, but with the link to you severed (see below).
- Audit records — up to 24 months for abuse investigation.
Deleting your account
You can delete your account at any time from Account → Delete my account in the app. No email and no support request is required. If you no longer have the app installed, see crashpin.app/delete-account.
When you delete your account we immediately and permanently:
- delete your account record, including the email address you gave;
- delete your referral code and revoke all active sessions;
- replace your account ID on every report you submitted with an anonymous marker, so those reports can no longer be traced back to you.
The incident data itself is kept. Once anonymised we cannot re-identify it, which also means we cannot restore your account or recover your report history. Deletion cannot be undone.
Your rights
You may ask us to:
- Give you a copy of your data. Under the PDPO this is a data access request; under Australian law it is an access request. Either way, email us.
- Correct data that is wrong. Under the PDPO this is a data correction request. You can also edit your own reports in the app within the correction window.
- Delete your account. Settings → Delete account. No email required.
- Object to how we use your data, or ask us to restrict it, where the GDPR or UK GDPR applies to you.
Email privacy@crashpin.app. We aim to respond within 30 days, and will always respond within the 40 days required by the PDPO. We do not charge a fee for access or correction requests, although the PDPO would permit a reasonable one.
If you are not satisfied with our response, you can complain to either regulator — you do not have to go to the Hong Kong one just because we are a Hong Kong company:
- Australia — Office of the Australian Information Commissioner, oaic.gov.au
- Hong Kong — Office of the Privacy Commissioner for Personal Data, pcpd.org.hk
- Elsewhere — your local supervisory authority.
Children
CrashPin is not directed at children and is not intended for anyone under 16. We do not knowingly collect information from children under 16. If you believe a child has an account, contact us and we will delete it.
Your responsibilities
Never use CrashPin while driving. Do not approach a crash scene, interact with people involved, or collect their personal details. Do not submit photographs of injured people, faces, or number plates. Reports that contain personal information about crash participants may be removed and the submitting account suspended.
Security
Data is encrypted in transit using TLS and stored in access-controlled infrastructure. No system is perfectly secure; if a breach affects you we will notify you and the relevant regulator as required by law.
Changes
If we make a material change we will update the date at the top of this page and notify you in the app before the change takes effect.
Governing law
This policy is governed by the laws of the Hong Kong Special Administrative Region. Nothing in it limits any right you have under the Australian Privacy Act 1988 (Cth), the Australian Consumer Law, or any other law of your own jurisdiction that cannot be excluded by agreement.
Contact
PROVIDER_LEGAL_NAME
PROVIDER_REGISTERED_ADDRESS
Hong Kong SAR
privacy@crashpin.app