About
Privacy Policy
Effective date: August 16, 2026
This Privacy Policy explains what information bikelanebumps.org and the BumpWatch Apple Watch app (together, "BumpWatch," "we," "us," or "our") collect, how it's used, and how it's shared. There is no account or sign-up for either the app or the website — most of what follows is simpler as a result.
1. Information We Collect
From the BumpWatch Watch app
When you use BumpWatch to record a ride, the app collects and uploads:
- Location data: GPS coordinates, accuracy, and speed at the moment each bump is detected.
- Bump data: the severity (peak acceleration) and timestamp of each detected bump.
- Ride metadata: a randomly generated ride ID, along with the ride's start and end time and total bump count.
We do not collect your name, email address, Apple ID, phone number, or any device identifier. Ride data isn't tied to you as a person in any way we can see — it's tied only to the random ID generated for that one ride.
BumpWatch uses your Watch's accelerometer continuously while recording to detect bumps, but that raw motion stream is processed on your Watch and never leaves it — only the individual bump events described above are uploaded.
BumpWatch also starts an Apple HealthKit workout session while recording, which is what lets it keep tracking your ride in the background. This creates a normal workout entry in your own Health app, the same as any fitness app would. That entry stays in your personal Health data, governed by Apple and your iCloud account — we don't access, read, or upload any of your broader Health data, and the workout entry itself is never sent to us.
From bikelanebumps.org
The website reads the public ride and bump data described above to render the heatmap and stats. If you allow it, your browser's own location (used only to center the map on your area) is requested through your browser's native permission prompt — that location is used entirely on your device to position the map and is never sent to us or stored anywhere. We don't use cookies, accounts, or any third-party analytics or advertising trackers on this website.
2. How Information Is Used
Ride and bump data is used for exactly one thing: rendering the public heatmap and the summary stats on this site.
3. How Information Is Shared
Everything submitted is public. Because there's no account system, there's no private view of ride data — every bump anyone uploads through BumpWatch appears on the public heatmap, including its exact GPS location, severity, and timestamp. If you're recording rides on routes that could identify you (like the streets right around your home), keep in mind that data is visible to anyone who visits this site.
Service providers: Ride and bump data is stored using Google Firebase (Cloud Functions and Cloud Firestore), hosted on Google Cloud infrastructure. Google acts only as our infrastructure provider and does not use this data for its own purposes. The website's map tiles are served by CARTO, built from OpenStreetMap data; the mapping library (Leaflet) is loaded from a public CDN (unpkg.com). Requests to these third parties are subject to their own standard server logging.
We do not sell data, and we don't share it with anyone for advertising or marketing purposes.
Legal requirements: We may disclose information if required by law.
4. Data Retention and Removal
Ride and bump data is kept indefinitely, since the map's value comes from building up a complete picture over time. Because data isn't tied to an account, we can't look it up by who submitted it — if you'd like a ride removed, email us with the approximate date, time, and route, and we'll do our best to locate and remove it.
5. Security
Ride data is uploaded over HTTPS and written to Firestore through a Cloud Function protected by a private key embedded in the app — it isn't written to the database directly by any client. Firestore's own access rules allow public read access (so the map can load without an account) but block public write access entirely. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.
6. Children's Privacy
BumpWatch isn't directed at children, and since it doesn't collect names, emails, or any other personal identifiers from anyone, there's no age-gated account data to speak of.
7. Changes to This Policy
We may update this policy from time to time. If we make material changes, we'll update the effective date above.
8. Contact Us
Questions about this policy, or a data removal request, can be sent to:
This document is provided for informational purposes and is not legal advice. If you have questions about how it applies to your specific situation, consider consulting an attorney.