Legal

Privacy Policy

CrashPin is a crowdsourced road-incident reporting app. This policy explains exactly what we collect, why, who sees it, and how to delete it.

Last updated: 3 August 2026 · Policy version privacy-v2

Who we are

CrashPin is operated by PROVIDER_LEGAL_NAME ("we", "us"), a company incorporated in the Hong Kong Special Administrative Region, of PROVIDER_REGISTERED_ADDRESS. We are the data user (controller) for the information described below.

Privacy enquiries and data requests: privacy@crashpin.app.

Which privacy laws apply

Two regimes apply to CrashPin at the same time, and we comply with both:

Where the two differ, we apply whichever gives you the stronger protection.

The short version

What we collect

Account information

You can join openly, by invitation, or with a referral code. Either way we create an account holding: a generated account ID, the email address you gave, your trust level, any capabilities an operator has granted, the account that referred you (if any), and the date you joined. A session token is stored on your device so you stay signed in; it expires after 30 days and is revoked when you sign out or delete your account.

Location

When you submit a report, we collect the device location at that moment: latitude and longitude, accuracy, and — where the device provides them — speed, heading and whether the device appears stationary, walking or in a vehicle. We also store the location you confirm on the map, which may differ from your raw GPS position.

We do not track you in the background. CrashPin requests "while in use" location permission only. If you decline location permission you can still browse the map, but you cannot submit a live report.

Report content

The observation you submit: whether an incident appears present, the direction of travel, approximate vehicle count, obstruction level, whether emergency services were observed, a severity estimate, and an optional free-text note. Please do not put personal details of people involved in a crash into that note — see "Your responsibilities" below.

Photos (optional)

You may attach a photo. We store the image, its size, format, a checksum, and when it was captured and uploaded. EXIF metadata is stripped before any photo is used in published output. Photos are held for moderation and may be reviewed by us before publication.

Device integrity

To stop automated and fraudulent reporting, each report carries an installation attestation: an installation identifier, the platform (iOS/Android/web), and the result of an Apple App Attest or Google Play Integrity check. This tells us a report came from a genuine app install. It does not identify you personally.

Audit log

We record account and report actions — sign-in, submission, edit, cancellation, moderation — with the acting account ID and a timestamp. This exists for abuse investigation and safety-data integrity.

What we do not collect

No name, no phone number, no postal address, no date of birth, no password, no contact list, no advertising identifier, no background or continuous location, and no analytics SDK that profiles you across other apps.

If rewards ever become redeemable

Points are currently just points — there is nothing to cash out, and we ask for nothing beyond an email address. If we later allow points to be redeemed for something of real value, the law will require us to verify identity before paying anyone. That would mean asking for a legal name and possibly identity or tax details.

We would only ask at that point, only from people who choose to redeem, and only after telling you first. Nothing here obliges you to provide it, and declining would mean forgoing redemption rather than losing your account. We have written this section now rather than claiming "never", because a promise we might have to break is worse than one we can keep.

Why we use it

Who we share it with

The public incident feed

Confirmed incidents are published to a feed used by road-safety and recovery services. Before anything is published, our systems remove every contributor identifier — account ID, contributor record, installation ID, referral ID, reward and moderation records, and the internal source ID linking an incident back to your specific report. A published incident carries the location, observation, timing, confidence and a source category of "crowd" — never who reported it.

This removal is enforced by an automated check that refuses to publish any record still containing an excluded field.

Service providers

We do not

Sell your personal information, share it with data brokers, or disclose your identity to any third party — including insurers, repairers and recovery operators.

Where your data is stored, and who can reach it

Your data is stored in Australia. All CrashPin databases and backups run in Amazon Web Services' Asia Pacific (Sydney) region. Reports submitted in Queensland and New South Wales stay on Australian infrastructure.

We are a Hong Kong company, so our personnel access that Australian infrastructure from Hong Kong. That access is a cross-border disclosure under Australian Privacy Principle 8, and we remain accountable for your data under the Australian Privacy Act when it is handled from Hong Kong — the same standards in this policy apply to it there.

Hong Kong's own cross-border transfer provision (PDPO section 33) has not been brought into force. We nonetheless follow the PCPD's recommended approach to cross-border transfers, and contractually bind any processor handling CrashPin data to the protections set out in this policy.

In plain terms: moving the company offshore did not move your data offshore, and did not reduce your rights under Australian law.

How long we keep it

Deleting your account

You can delete your account at any time from Account → Delete my account in the app. No email and no support request is required. If you no longer have the app installed, see crashpin.app/delete-account.

When you delete your account we immediately and permanently:

The incident data itself is kept. Once anonymised we cannot re-identify it, which also means we cannot restore your account or recover your report history. Deletion cannot be undone.

Your rights

You may ask us to:

Email privacy@crashpin.app. We aim to respond within 30 days, and will always respond within the 40 days required by the PDPO. We do not charge a fee for access or correction requests, although the PDPO would permit a reasonable one.

If you are not satisfied with our response, you can complain to either regulator — you do not have to go to the Hong Kong one just because we are a Hong Kong company:

Children

CrashPin is not directed at children and is not intended for anyone under 16. We do not knowingly collect information from children under 16. If you believe a child has an account, contact us and we will delete it.

Your responsibilities

Never use CrashPin while driving. Do not approach a crash scene, interact with people involved, or collect their personal details. Do not submit photographs of injured people, faces, or number plates. Reports that contain personal information about crash participants may be removed and the submitting account suspended.

Security

Data is encrypted in transit using TLS and stored in access-controlled infrastructure. No system is perfectly secure; if a breach affects you we will notify you and the relevant regulator as required by law.

Changes

If we make a material change we will update the date at the top of this page and notify you in the app before the change takes effect.

Governing law

This policy is governed by the laws of the Hong Kong Special Administrative Region. Nothing in it limits any right you have under the Australian Privacy Act 1988 (Cth), the Australian Consumer Law, or any other law of your own jurisdiction that cannot be excluded by agreement.

Contact

PROVIDER_LEGAL_NAME
PROVIDER_REGISTERED_ADDRESS
Hong Kong SAR
privacy@crashpin.app