Your data, our responsibility.
This Privacy Policy explains how Garidium LLC ("RVCockpit", "we", "us", "our") collects, uses, shares, and protects information when you use the RVCockpit web application at rvcockpit.com (the "Service").
By using the Service, you agree to the practices described here. If you don't agree, please don't use the Service.
1. Information We Collect
Account information
When you sign up, we collect your email address and a password (stored as a one-way salted hash — we cannot read your password). You can optionally set an avatar emoji shown to friends you share location with.
Trip and content data
Information you create in the app, including:
- Routes, waypoints, stop labels, dates, and notes
- Photos you upload to your trips, including any captions or location tags
- User preferences (units, daily-drive cap, vehicle profile dimensions, fuel pricing)
- POI favorites and custom imports
- Home base address, if you choose to set one
Location data
If — and only if — you enable live location sharing with specific friends, we collect your device's GPS coordinates while sharing is active and broadcast them to those specific recipients. You can stop sharing or revoke individual permissions at any time from the app. We do not collect location data when sharing is off.
Payment information
We do not store credit card numbers. Payment is processed by Stripe, Inc. Stripe stores your card and billing details on its own infrastructure and shares only minimal metadata with us (subscription status, plan, period end, last-4 digits for display). See Stripe's privacy policy.
Technical and log data
Our hosting and database providers automatically log basic technical data — IP address, browser/device type, request timestamps — for security and debugging. We do not run third-party advertising or analytics trackers.
2. How We Use Information
- Provide the Service — sign you in, save your trips, sync settings across devices, render the map, compute routes.
- AI features — when you use the AI copilot, the conversation contents (including any route/POI context the assistant needs) are sent to OpenAI for processing. We don't sell prompts and OpenAI does not train models on API data per their policy.
- Search RV-relevant places — your search queries and the relevant route/viewport coordinates are sent to Mapbox and (where you opt in) Google Places to find POIs.
- Process payments and subscription lifecycle via Stripe.
- Send transactional email (confirmation, password reset, billing receipts) via Resend.
- Communicate with friends you've authorized — sharing trips and live location with specific people you select.
- Investigate abuse and enforce our Terms.
We do not sell your personal information. We do not use your data for advertising. We do not run third-party trackers.
3. Third-Party Processors
We rely on a small set of vendors to operate the Service. Each receives only what's needed to perform its job:
4. When We Share With Others
We share your information only in these specific situations:
- With service providers above, as necessary to operate the Service.
- With friends you explicitly authorize — when you share a trip or live location, the recipient(s) you select can see what you've shared until you revoke that share.
- If you mark a photo public, that photo and its caption become visible to all RVCockpit users in the community feed. You can delete public photos at any time.
- To comply with law — valid subpoenas, court orders, or other legal process.
- To protect rights and safety — investigating fraud, abuse, or threats.
- In a business transaction — if Garidium LLC is acquired, merged, or sold, your information may transfer to the successor under terms at least as protective as this policy.
5. Location Data
Live location sharing is opt-in, granular, and revocable:
- It only runs when you explicitly start it; closing the app or signing out stops it.
- You choose which specific friends receive your location — not a public broadcast.
- You can revoke any individual recipient's permission at any time from the app.
- Coordinates are sent to recipients in near-real-time via Supabase Realtime; we don't retain a long-term location history beyond the current sharing session.
6. Payment Information
RVCockpit uses Stripe for all payment processing. We never see your full card number, CVC, or bank details. Stripe stores those on its PCI-DSS Level 1 infrastructure. We retain only what Stripe sends to our subscription webhook: customer ID, subscription status, plan, period end, payment method last-4 (for display purposes), and trial end date.
You can manage or cancel your subscription at any time via Setup → Subscription → Manage subscription in the app, which opens the Stripe-hosted Customer Portal.
7. Data Retention
We retain account and trip data for as long as your account is active. If you cancel your subscription, your data is preserved (we don't delete it) so you can resubscribe later without losing your trips. You may request deletion at any time per the next section.
Backups may retain deleted data for up to 30 days for disaster-recovery purposes before being overwritten in the normal backup rotation.
8. Your Rights
Regardless of where you live, you may:
- Access your personal information — most of it is visible directly inside the app (Setup → Subscription, Trips list, Photo journal). To request a copy of your full data, email sales@garidium.com.
- Correct account or trip data — most fields are editable in the app. Contact us if anything else looks wrong.
- Delete your account and associated data — email sales@garidium.com from the address on the account. We'll delete your data within 30 days, except for records we're legally required to retain (e.g., tax records).
- Export your trips, photos, and notes — contact us and we'll provide a JSON export.
- Opt out of non-essential email — transactional emails (account, billing) cannot be opted out without closing your account.
If you live in California, the EEA, the UK, or another jurisdiction with specific privacy rights (GDPR / CCPA / CPRA / etc.), the rights above apply to you, and you have additional rights under those laws (e.g., the right to lodge a complaint with your supervisory authority). Contact us to exercise any right.
9. Security
We protect your information with reasonable technical and organizational measures:
- All traffic between your browser and our servers is encrypted with TLS.
- Passwords are stored as bcrypt hashes; we never see your plaintext password.
- Database access is gated by row-level security policies — users can only read/write their own rows (with explicit exceptions for content you've shared).
- Third-party API keys (Mapbox, OpenAI, Google Places) are held server-side only and not shipped to your browser, except where the upstream API requires a referrer-locked browser key (Google Place Photos and Street View).
- Payment card data never touches our servers.
No system is perfectly secure. If you believe your account has been compromised, change your password and email us immediately.
10. Cookies and Local Storage
RVCockpit uses your browser's localStorage to remember settings (units, daily drive cap, etc.) and a Supabase auth session token so you stay signed in. We don't set third-party advertising cookies, and we don't run analytics like Google Analytics or Facebook Pixel.
11. Children's Privacy
RVCockpit is intended for users 18 and older. We don't knowingly collect personal information from anyone under 18. If you believe a child has signed up, contact us and we'll delete the account.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we'll update the "Last updated" date at the top, and for significant changes we'll notify you by email or an in-app banner. Continued use of the Service after the changes take effect means you accept the updated policy.
13. Contact
Questions, requests, or concerns? Reach out:
667 NE Emerson St
Port Saint Lucie, FL 34983
United States