Last updated: 14 August 2026
This App Privacy Policy explains how Axon Rook LLC, a limited liability company organised under the laws of New Mexico, United States, with its principal place of business at 1209 Mountain Rd PI NE, STE N, Albuquerque, NM 87110, United States of America (“Lisbon Local”, “we”, “us”), processes personal data in the Lisbon Local mobile application for iOS and Android (the “App”).
We are the controller of the personal data described below. Contact: [email protected].
Because the App is directed at people in and travelling to Portugal, the EU General Data Protection Regulation applies to our processing under Article 3(2) GDPR, even though we are established in the United States.
This Policy covers the App only. Our website is covered by a separate Website Privacy Policy. Your use of the App is also governed by our Terms and Conditions.
1. Who this Policy is for
The App is intended for users aged 16 or over. We do not knowingly collect personal data from anyone under 16, and we do not knowingly collect personal information from children under 13 as defined by the U.S. Children’s Online Privacy Protection Act. If you believe a child has provided us with personal data, contact [email protected] and we will delete it.
2. What the App collects
2.1 Data you give us
- Account data — name or display name, email address, password (stored hashed), profile photo, and preferences.
- Content you submit — reviews, ratings, photographs, saved places, lists, and messages.
- Support correspondence — the content of any message you send us through the App.
- Purchase data — the record of in-app purchases and subscriptions. Payment is processed by Apple, Google, or our payment processor; we never receive or store your card details.
2.2 Data collected automatically
- Device data — device model, operating system version, App version, language, time zone, screen size, and a resettable advertising or device identifier.
- Usage data — screens viewed, features used, searches performed in the App, taps, session length, and timestamps.
- Diagnostic data — crash reports, error logs, and performance metrics.
- Approximate location derived from IP address.
- Push notification token, where you enable notifications.
2.3 Location data, including background location
Please read this section carefully.
The App uses your device’s precise location to show places near you, provide directions, and sort results by distance.
The App also collects your precise location in the background — that is, while the App is closed or not in use. We do this for one purpose only: to alert you when to get off your bus, tram, metro, or train. When you set a stop alert for a journey, the App compares your position against your destination stop so it can notify you as you approach it. This only works if the App can read your location while it is in the background, because you will normally have your phone locked or be using another app during the journey.
Background location is collected only while you have an active stop alert running. It starts when you set an alert and stops as soon as the alert fires, you cancel it, or the journey ends. We do not collect background location at any other time.
- Background location is off by default and is collected only after you grant the “Always Allow” permission. We ask for it separately from, and after, in-use permission.
- You can revoke it at any time in your device settings without losing access to the rest of the App. Only the feature described above stops working.
- iOS displays a periodic reminder showing where the App has used your location in the background. Android displays an ongoing indicator.
- We do not use background location to build advertising profiles, and we do not sell or share location data with data brokers.
- Precise location is retained in identifiable form for no longer than 30 days, after which it is aggregated or deleted.
2.4 Device permissions
Each permission below is optional, is requested only at the point it is needed, and can be refused or revoked at any time in your device settings. Refusing a permission disables the related feature but does not prevent you from using the rest of the App.
- Location — see Section 2.3.
- Camera and photo library — to let you attach photographs to reviews and your profile. We access only the images you select. We strip embedded EXIF location metadata from photographs on upload, so the images you post do not disclose where they were taken.
- Push notifications — to send you service messages and, where you consent, updates and offers. You can turn these off in your device settings at any time.
2.5 Tracking and advertising identifiers
On iOS, the App will not access the Identifier for Advertisers or track you across other companies’ apps and websites unless you grant permission through Apple’s App Tracking Transparency prompt. On Android, you can reset or delete your advertising ID in your device settings. Where consent is required, we will ask for it and you may withdraw it at any time.
3. Why we process it, and on what legal basis
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Providing the App, your account, and the features you use | Performance of a contract (Art. 6(1)(b)) |
| Location features while the App is in use | Consent via device permission (Art. 6(1)(a)) |
| Background location features | Separate, explicit consent via the “Always Allow” device permission (Art. 6(1)(a)) |
| Camera and photo access | Consent via device permission (Art. 6(1)(a)) |
| Push notifications — service messages | Contract (Art. 6(1)(b)); marketing notifications rely on consent (Art. 6(1)(a)) |
| Crash reporting, diagnostics, and stability | Legitimate interests (Art. 6(1)(f)) — keeping the App working |
| Product analytics and improvement | Consent where device or tracking identifiers are used (Art. 6(1)(a)); otherwise legitimate interests (Art. 6(1)(f)) |
| Security, fraud prevention, abuse detection, enforcing our Terms | Legitimate interests (Art. 6(1)(f)) |
| Purchases, refunds, and accounting records | Contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Complying with legal obligations and lawful requests | Legal obligation (Art. 6(1)(c)) |
| Establishing, exercising, or defending legal claims, including in a sale or restructuring of our business | Legitimate interests (Art. 6(1)(f)) |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object at any time — see Section 8.
4. Content you post is public
Reviews, ratings, photographs, and public lists are published in the App and on our website, and are visible to anyone, including search engines. Your display name and profile photo are shown alongside them. We strip EXIF location metadata from uploaded photographs. Do not post anything you are unwilling to make public, and do not include other people’s personal data without their agreement.
5. Who we share it with
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not sell or disclose location data to data brokers. We disclose it only to:
- Processors acting on our documented instructions under written data processing agreements — cloud hosting, crash reporting, analytics, push notification delivery, mapping, and customer support. A current list of processor categories is available on request from [email protected].
- Apple and Google, in connection with App distribution, in-app purchases, and platform services, acting as independent controllers under their own privacy policies.
- Mapping and directions providers, where you use those features. Your query and location are sent to them and processed under their own policies.
- Professional advisers — lawyers, accountants, insurers, and auditors, bound by confidentiality.
- Authorities, courts, and regulators, where legally required or necessary to establish, exercise, or defend legal claims.
- An acquirer or successor, in a merger, acquisition, financing, insolvency, or sale of assets.
6. Where we store it, international transfers, and how long we keep it
6.1 Storage and international transfers
Our servers are located in Helsinki, Finland, within the European Economic Area (provider: Hetzner Online GmbH).
Your personal data is stored in the EEA and is not transferred outside it. Although Axon Rook LLC is incorporated in the United States, personal data collected through the App is held on EEA infrastructure and is accessed only from within the EEA. We use only processors that store and process personal data within the EEA.
One exception applies. Where you download the App, make an in-app purchase, or receive push notifications, Apple or Google process data as independent controllers on their own infrastructure, which is located outside the EEA. That processing is governed by their privacy policies and their own transfer safeguards, not ours, and we cannot avoid it while distributing through their stores.
If our own arrangements change — for example if we engage a service provider outside the EEA — we will update this Policy before the transfer begins and will rely on an adequacy decision of the European Commission or on the Commission’s Standard Contractual Clauses under Article 46(2)(c) GDPR, with supplementary measures where required.
6.2 Retention
- Account data — for the life of the account, then up to 12 months after deletion to handle disputes and prevent abuse.
- Published content — indefinitely, unless you delete it or we remove it; we may retain it in anonymised form after account deletion.
- Precise location data, including background location — no longer than 30 days in identifiable form.
- Crash and diagnostic logs — 90 days.
- Analytics data — 14 months, then aggregated or deleted.
- Purchase, accounting, and tax records — 7 years, to meet United States federal and state tax and accounting requirements.
We may retain data longer where necessary to establish, exercise, or defend legal claims, or where a legal obligation requires it.
7. Deleting your account
You can delete your account and associated personal data from within the App at Settings → Account → Delete Account, or by emailing [email protected]. Deletion is subject to the retention periods in Section 6 and to any data we must keep by law. Deleting the App from your device does not delete your account.
8. Your rights
If the GDPR applies to you, you have the rights of access, rectification, erasure, restriction, and data portability; the right to object to processing based on legitimate interests and, at any time and without giving reasons, to direct marketing; and the right to withdraw consent at any time without affecting the lawfulness of prior processing.
If you are a United States resident, depending on your state you may have rights to know, access, correct, delete, and port your personal information, to opt out of sale, sharing, or profiling, and not to be discriminated against for exercising those rights. As stated in Section 5, we do not sell or share personal information.
To exercise any right, contact [email protected]. We respond within one month, extendable by two further months for complex requests. We may ask you to verify your identity. Requests that are manifestly unfounded or excessive, in particular because they are repetitive, may attract a reasonable fee or be refused, as permitted by Article 12(5) GDPR.
We do not carry out automated decision-making producing legal or similarly significant effects.
9. Complaints
Please contact us first at [email protected]. If the GDPR applies to you, you may also complain to the supervisory authority where you live or work — in Portugal, the Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, www.cnpd.pt.
10. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit and access controls. No mobile platform, network, or storage system is completely secure, and we cannot and do not guarantee absolute security. You are responsible for the security of your device and credentials and for all activity under your account. We will notify you and the competent supervisory authority of a qualifying personal data breach as required by Articles 33 and 34 GDPR, and will comply with applicable United States state breach notification laws.
11. Third-party services
The App links to and integrates third-party services including maps, booking and reservation tools, and business websites. We do not control those services and are not responsible for their content, practices, or privacy policies.
12. Changes to this Policy
We may update this Policy at any time. The “Last updated” date shows the current version. Where changes are material, we will give reasonable notice in the App or by email. Continued use of the App after a change takes effect constitutes acceptance of the revised Policy. Where a change requires your consent, we will ask for it.
13. Contact
Axon Rook LLC
1209 Mountain Rd PI NE, STE N
Albuquerque, NM 87110
United States of America
Email: [email protected]
