Legal

Privacy Policy

Last updated: October 8, 2026

CherrySpotter is built for professional rideshare drivers. This policy explains, in plain language, what the app does with information, what stays on your phone, and which service providers are involved.

On your deviceOffer readings, screenshots, and your preferences are stored locally on your phone.
Shared to run the serviceYour Google sign-in (email and account ID), your license, a hashed device ID, your phone model and permission settings, push token, and address or map lookups go to the providers listed below.
Never soldWe do not sell your data, show ads, or track keystrokes or passwords.

1.Information we collect

To run licensing, subscriptions, and notifications, the following information is sent to us or to our payment provider:

InformationWhy we need it
Google sign-inWhen you tap Sign in with Google, Google tells our server your Google email address and a unique account ID (never your Google password). We use them to tie your license to you, so there is no license key to keep or enter. The sign-in code Google gives the app is checked once and not stored. A sign-in session (a random code, kept on our side only as a one-way hash) keeps you signed in on that phone until you sign out; it expires after 180 days without use.
Acceptance of the termsWhen you tap I agree in the app, we record which version of the Terms of Service and Privacy Policy you accepted, the date and time, and the app version, against your account, so that we can show what you agreed to. We keep it for as long as your account exists and as long afterwards as needed for legal reasons.
Referral codeWhen you download CherrySpotter from a sales representative’s card or from a friend’s share link, the download carries a short code. The app sends it when you first sign in, and we record it against your account: which sales representative (or the website) the account is credited to, and which account’s share link you came from, if any. Every account also gets its own random code, which the app uses to make your personal share link and QR code. Sales representatives are told only how many people and payments are credited to them (account numbers, never names or email addresses). We keep it for as long as your account exists.
Device identifierYour license is tied to one Android device. The app sends the Android device ID when you sign in and activate; we store only a one-way hash of it, with activation times, to enforce one device per license and one free trial per device.
Phone model and settingsTo find out which phones the app runs well on, and to help when something cannot be switched on (for example Accessibility or the default assistant), the app reports your phone’s make and model, Android version and security patch level, the app version, where the app was installed from, and whether each permission the app uses (Accessibility, assistant, display over other apps, usage access, notifications, location, battery optimization) is on or off. It is stored against the same hashed device code as above, never with your name, email address, phone number, device serial or IMEI, and it contains no location or list of your apps. It is kept while you use the app and deleted 400 days after the phone was last seen.
Purchase detailsThe app opens a Stripe checkout page for your account. We create a Stripe customer with your Google email address and receive Stripe customer and subscription IDs and whether payments succeeded, so we can match payments to your license. Payments are processed by Stripe through Link. We never see your card details.
Push notification tokenLets us send you service notices such as license or app updates.
App integrity checksTo make sure a request comes from the genuine CherrySpotter app on a real, unmodified phone, the app sends Google Firebase App Check and Google Play Integrity tokens to our server, which checks them with Google. They contain nothing about you personally.
Basic app diagnosticsStandard analytics from Google Firebase, used to keep the app reliable.

2.Processed on your device

The features that make CherrySpotter useful work on your phone:

  • Reading offers. While a supported driver app is open, the app reads the offer screen (using Android’s Accessibility service and on-device screen capture and text recognition) to calculate figures such as dollars per mile and per hour.
  • Screenshots. You can save offer screenshots for your own records. They are stored on your device and can be deleted from the app at any time.
  • Your preferences. Settings such as your Home and Work addresses, your Places to avoid and Preferred places, your pay and offer limits and the Cherry card layout are stored locally.

We do not upload your offer screens, screenshots, or trip history to our servers.

3.Service providers that receive limited data

Some features need an outside service. Each receives only what it needs to do its job.

ProviderWhat it doesWhat it may receive
Stripe (Link)Payments, sales tax and VAT, receipts, refunds, and subscription management, as merchant of record (“Sold through Link”)Your name, billing address, payment method, and email at checkout. We never see or store your card or bank details. Link has its own privacy policy and lets you manage or delete your orders at link.com.
Our servers (cherryspotter.com)Receive payment notifications from Stripe, create and check licenses, record which device a license is on, pass address and route lookups on to the mapping service, watch for abuse such as shared or copied licenses and repeated free trials, and deliver notificationsYour Google email address and account ID, Stripe customer and subscription IDs, a hashed sign-in session, a hashed device ID, your phone make, model, Android version and permission on/off settings, activation times, and your push token. For abuse prevention we also keep an activity log (see Retention below): your license number, a short hashed device code, a scrambled hash of your internet connection (not the address itself), your country as seen by our network provider, and whether the app runs in your main Android profile. The address you search for is passed to the mapping service and is not stored by us.
Zoho MailDelivers support messages and replies, and our own alert emails (we send no license keys or marketing to customers)Your email address and anything you write to us.
Google (Sign in with Google, Firebase, Play Integrity)Sign-in, push notifications, analytics, and checks that requests come from the genuine appFor sign-in: your Google email and account ID are passed to us. Push token, basic app diagnostics, and the App Check and Play Integrity tokens go to Google. Google has its own privacy policy.
Mapping and routing services (LocationIQ; our own address search server, which uses OpenStreetMap data; Photon/Komoot, the public service, only as a backup)Turn addresses into locations and calculate distance and ETAStreet and city names from an offer, your saved home address, and coordinates needed to compute a route. Address lookups for an offer go through our server to our own address search server and are not stored by us. Only when that server does not answer does the app ask the public Photon service directly, which then sees the street and city text and the map area. These lookups do not include your name or account details.

These providers have their own privacy policies, and we encourage you to review them.

4.Android permissions we request

Every permission is optional to grant, but some features will not work without it. The setup guide in the app explains each one.

PermissionUsed for
Accessibility serviceReading the offer displayed in the Uber or Lyft driver app so figures can be calculated. It does not read keystrokes or passwords.
Display over other appsDrawing the Cherry card on top of the driver app.
Usage accessKnowing when a driver app is open, so CherrySpotter only runs when needed and saves battery.
Location (precise, approximate, and background)Working out your distance to a pickup and your ETA home (a beta feature). Your location history is not stored. When Direction & ETA asks for a route, your current position goes through our server to the mapping service and we do not keep it.
Screen captureReading the offer on screen and saving screenshots you request.
NotificationsService notices from us.
Background activity and battery optimizationKeeping the app ready the moment an offer arrives.
Default assistantTaking an instant snapshot of the current screen.

5.What we don’t do

  • We do not sell or rent your personal information.
  • We do not show ads or share data with advertisers.
  • We do not collect your contacts, call logs, or messages.
  • We do not track keystrokes or read passwords.
  • We do not store your GPS location history or your passengers’ details on our servers.
  • We do not accept, decline, or cancel trips for you. You keep 100% manual control.

6.Retention and deletion

On your device: local data such as screenshots and preferences stays until you delete it in the app or uninstall CherrySpotter.

Account, license and device records: kept while your license is active and afterward only as long as needed for billing, fraud prevention, and legal obligations. Signing out ends the sign-in session on that phone. To request deletion, email us at the address below.

Activity log: the abuse-prevention log described above is kept for 60 days and then deleted.

7.Your choices and rights

You can revoke any Android permission at any time in your phone’s settings, cancel your subscription from Manage subscription in the app (or at link.com), sign out in the app, and delete local data in the app. If you ask Stripe to delete your Link data, Stripe cancels the subscriptions sold to you through it, which ends your license. Depending on where you live, you may also have the right to request access to, correction of, or deletion of your personal information. To make a request, contact us below and we will respond within a reasonable time.

8.Security

Information sent from the app and from our website to our servers and to our providers travels over encrypted HTTPS connections. There are no license keys to steal or share: your license is tied to your Google account, and sign-in sessions and device IDs are stored only as one-way hashes, and our services run with the least access they need. Payment notifications from Stripe are accepted only when their cryptographic signature checks out. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security.

9.Other important notes

  • Independent product. CherrySpotter is not affiliated with, endorsed by, or sponsored by Uber or Lyft. Their apps and data are governed by their own privacy policies.
  • Map data. Address search uses map data © OpenStreetMap contributors, available under the Open Database License (openstreetmap.org/copyright).
  • Age. The app is intended for licensed drivers who are at least 18 years old. We do not knowingly collect information from children.
  • Changes. We may update this policy. When we do, we will change the “Last updated” date above. If a change is significant, we will also notify you in the app.

10.Contact us

CherrySpotter is owned and operated by Robert Antonio Giambalvo Daniella, a sole proprietor, who is responsible for the personal information described in this policy.

Questions or requests about this policy or your data:

support@cherrypickerapp.com