Privacy Policy
Last updated · 12 August 2026
Introduction
Rowta ("we", "our", "us") is operated by Sett & Stone Ltd. This Privacy Policy explains how we collect, use, and protect your information when you use our mobile application.
Information we collect
Data you provide
- Account credentials (via Sign in with Apple — we never see your password)
- Display name
- Trip data: names, dates, stop locations, expenses, notes
- Photos you attach (expense receipts and trip cover photos) — only the photos you choose; we never scan your photo library
Location data
- We store locations only when you explicitly add a stop to a trip
- Live location sharing (optional): if you turn on live location sharing during an active trip, we collect your GPS position — including in the background while you drive — and share it with the members of that trip. Sharing stops when the trip ends or when you turn it off
- While a journey is live, each position update (latitude, longitude, heading, speed and estimated arrival time) is sent to our servers and stored with that trip in our cloud (Cloudflare D1) so trip members can follow your progress. It is visible only to members of that trip — never publicly. Positions are deleted 30 days after they are recorded, and immediately if you delete the trip or your account (see Data retention)
- Outside of active-trip sharing, we do not track your location in the background or collect GPS data continuously
- Map searches are processed by Apple MapKit on your device
Photos
- Expense receipts: a receipt photo you attach to an expense is uploaded to our cloud storage (Cloudflare R2) and is visible to every member of that trip, alongside the expense
- A receipt is deleted when you remove it, when the expense it belongs to is deleted, or — for trips you own — when you delete your account
- A receipt you attached to an expense on a trip someone else owns stays with that trip if you delete your account. The expense it documents belongs to that trip's shared record, and removing the evidence for it would leave the other members with a cost they can no longer verify
- Trip cover photos stay on your device — they are stored locally and are never uploaded to our servers or shared with other members
- We never scan or index your photo library
Push notifications
- If you allow notifications, your device registers a push token with Apple Push Notification service (APNs). We store that token on our servers (Cloudflare D1) so we can send notifications to your device
- We use it to tell you about trip invites, trips starting and ending, stops and expenses added to a trip you're on, journey and ETA updates from people you're travelling with, and settlement activity such as a payment being marked as paid. You can turn each of these off individually in the app's notification settings
- The token identifies your device, not your location or your trip content
- Your token is deleted when you sign out or delete your account, and tokens Apple reports as invalid are removed automatically
Automatically collected
- Anonymised usage analytics (e.g. "trip created", "expense added" — no personal details)
- Crash reports
- Device type and iOS version
How we use your data
- To store and sync your trips across devices
- To enable trip sharing with people you invite
- To calculate expense splits and balances
- To share your live position with trip members while you have a journey running
- To send the push notifications you've enabled (trip invites, journey and ETA updates, settlement activity)
- To improve the app (using anonymised, aggregated data only)
Trip sharing
When you share a trip with others:
- They can see all trip stops, expenses (including any receipt photos attached to them), and member details
- They can add and edit stops and expenses
- You (the trip owner) can remove members at any time
- Sharing is always initiated by you — we never share your trips without your action
Data storage
- Trip data is stored locally on your device (SwiftData) and optionally synced to our cloud (Cloudflare D1)
- Receipt photos are stored in Cloudflare R2; live journey positions and push notification tokens are stored in Cloudflare D1
- All data is encrypted in transit (TLS 1.3)
- You can use Rowta entirely offline — cloud sync is optional
- You can delete your account and all cloud data at any time
Third-party services
- Cloudflare Workers + D1 — Cloud sync and API. See Cloudflare's privacy policy.
- Cloudflare R2 — Storage for the receipt photos you attach to expenses. See Cloudflare's privacy policy.
- Apple Push Notification service (APNs) — Delivers push notifications to your device and issues the device token we store. See Apple's privacy policy.
- PostHog — Anonymised analytics, EU-hosted. See PostHog's privacy policy.
- Apple MapKit — Map search, processed on-device.
Where your data is processed
Sett & Stone Ltd is a UK company, but the infrastructure we use is global. Cloudflare stores and processes data on servers that may sit outside the United Kingdom — in practice, currently within the European Economic Area. Apple's Push Notification service and PostHog likewise operate outside the UK.
Where data is transferred out of the UK, we rely on the UK government's adequacy regulations for the EEA, and otherwise on the International Data Transfer Addendum to the EU Standard Contractual Clauses. Cloudflare acts as our processor under its Data Processing Addendum, which incorporates those clauses.
Data retention
We keep data only for as long as it's useful to you, and no longer than the periods below.
- Trips, stops, expenses and balances — kept while your account is active, so your trips stay available across your devices and to the people you've shared them with
- Live journey positions — automatically purged 30 days after they are recorded. They are also deleted straight away if the journey's trip is deleted, or when you delete your account
- Receipt photos — kept until you remove the photo, delete the expense it's attached to, or delete your account. Receipts on trips owned by someone else stay with that trip
- Push notification tokens — deleted when you sign out or delete your account, or when Apple reports the token as no longer valid
- Anonymised analytics and crash reports — retained in aggregate; they are not linked to your account or identity
You can delete your account and its cloud data at any time from Settings → Account → Delete Account in the app, or by emailing [email protected]. Deletion removes your account, your trips, your journey positions, the receipt photos on trips you own, and your push token from our live systems immediately. Where an expense or settlement you created is part of a trip belonging to someone else, your membership record is anonymised rather than deleted — and any receipt you attached to it stays with that trip — so the remaining members' balances stay correct and verifiable. Residual copies held in our infrastructure provider's encrypted point-in-time backups age out within 30 days.
Your rights
Under GDPR and UK data protection law, you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and all data
- Export your data
- Withdraw consent
Children's privacy
Rowta is intended for users aged 13 and over.
Changes
We may update this policy. Significant changes will be communicated via the app.
Contact
Email [email protected].