Privacy Policy
1. INTRODUCTION
This Privacy Policy describes how Andrew, an individual doing business as DashCash ("DashCash," "we," "us," or "our") collects, uses, stores, and discloses personal information when you use the DashCash mobile application for iOS and Android, and its limited web version (together, the "Service").
DashCash is an offline-first take-home pay and mileage tracker for delivery and rideshare drivers. This policy applies to the App and limited web version only. It does not cover any separate DashCash marketing or waitlist website, which is governed by its own notices if posted there.
The Service is offered only to users located in the United States. We do not direct or offer the Service to users in the European Economic Area, the United Kingdom, or other jurisdictions outside the United States.
Who we are:
- Entity: Andrew, an individual doing business as DashCash
- Privacy contact: andyzweibackdev@gmail.com
2. TWO WAYS THE APP CAN RUN: LOCAL-ONLY vs. CLOUD SYNC
DashCash is offline-first, and how your data is stored depends on how the app is configured:
- Local-only mode. If cloud sync is not configured, the app does not require an account and your data (trips, shifts, settings, vehicle info, and any location data) stays on your device. It is not transmitted to our servers.
- Cloud sync mode. If cloud sync is available and you create an account, the data described in Section 3 is synced to our cloud database (hosted by Supabase) so it can be backed up and restored. When you sign out while online, the app first attempts a final sync of any unsynced records to the cloud, then clears account data from your device. Signing out does not delete your data from the cloud (see Section 8).
The rest of this policy describes both modes and tells you which data goes to the cloud.
3. INFORMATION WE COLLECT
We collect only the information described below. We do not collect your phone number, date of birth, Social Security number or tax ID, government ID, payment card numbers, photos, camera or microphone input, contacts, calendar, advertising identifiers, push notification tokens, crash reports, or product analytics events (we do not track your in-app activity; subscription purchase events are processed as described in Section 3.6).
3.1 Account information (cloud sync mode only)
When you create an account we collect your email address, first and last name, and a password. Your password is transmitted to and hashed by our authentication provider (Supabase); we never store your plaintext password. Your signed-in session token is stored on your device so you stay logged in.
3.2 Profile, settings, and vehicle information
To calculate fuel costs and take-home pay, we collect: your driver type (rideshare or delivery), transport mode (car or bike), preferred gig platforms, fuel type, vehicle make and model (optional), fuel efficiency (MPG or mi/kWh), and local energy price ($/gallon or $/kWh). Device-only preferences (theme, language, onboarding status) stay on your device and are not synced.
3.3 Trip, shift, and earnings information
When you log deliveries and shifts we collect the information you enter and related records: trip name, platform, base pay, tips, miles, drive time, timestamps, per-trip fuel-cost snapshot values, and shift start/end times and mileage. This is personal financial information about your earnings. In cloud sync mode, these records are synced to our cloud database.
3.4 Location information (please read carefully)
Location is the most sensitive data the app handles. Here is exactly what happens:
- When location is accessed. Continuous GPS tracking runs only during an active shift when you use automatic mileage tracking, and only after you grant location permission. In addition, when you log a delivery, the app may capture a single, one-time location fix at that moment (using your last tracking fix if a shift is active, or a one-shot foreground reading if you have granted permission) to place the delivery pin described below. The app does not run always-on or continuous tracking outside of active shifts.
- Foreground and background. Automatic mileage requires "while using" permission and, to keep counting mileage while your phone is locked, "Always"/background location permission. On Android, a persistent notification ("Tracking shift mileage") is shown while tracking runs, as required by the operating system.
- Raw GPS trail (device only, temporary). During an open shift, the app records a trail of precise GPS points (latitude, longitude, timestamp) on your device only. These raw points are deleted from your device when the shift ends or tracking stops. Raw GPS trail points are never uploaded to the cloud.
- Encoded route (cloud in sync mode). When a shift ends, the raw trail is converted into an encoded route line (Google Encoded Polyline format, roughly meter-level precision) that is stored with the shift so you can view your route on a map. In cloud sync mode, this encoded route is synced to our cloud database.
- Trip location pins (cloud in sync mode). When you log a delivery, the app may attach the latitude/longitude of where you logged it, so it can be shown as a pin on your shift map. In cloud sync mode, these coordinates are synced to our cloud database.
- Shift mileage. Total miles derived from GPS are stored with the shift and synced in cloud sync mode.
- Web version. The web version has no GPS tracking and no maps.
You can decline location permissions or revoke them at any time in your device settings; the app remains usable with manually entered mileage.
3.5 Device and technical information
The app uses your device's network connectivity status (to trigger sync when you reconnect), device locale (to default the app language to English or Spanish), and randomly generated record identifiers (to sync reliably). We do not use analytics or advertising SDKs and do not collect device fingerprints or advertising IDs.
3.6 Subscription and purchase information (paid plans)
If you purchase a DashCash Pro subscription, the purchase itself is processed by Apple (App Store) or Google (Google Play) — we never receive your payment card number. To manage your subscription entitlements, we use RevenueCat, which receives: your authenticated app user identifier (your Supabase account UUID), your purchase and subscription events (product purchased, price and currency as reported by the store, start/renewal/cancellation/expiration, trial status), store receipt/transaction identifiers used to validate the purchase, and basic device metadata (platform, app version, locale). We do not send your account email, name, or other custom attributes to RevenueCat. RevenueCat uses this data on our behalf to determine your Pro entitlement and to provide us aggregate subscription analytics (such as revenue, conversion, and churn). This is not general product analytics: neither we nor RevenueCat track your screens, taps, trips, earnings, or location.
4. HOW WE USE INFORMATION
We use the information described above to:
- Create and maintain your account and authenticate you (cloud sync mode)
- Provide the core Service: logging trips and shifts, estimating fuel costs and take-home pay, and showing history and analytics
- Measure driving distance and display your shift route on a map, if you enable automatic mileage tracking
- Back up and sync your data across devices (cloud sync mode)
- Generate a fiscal-year spreadsheet export when you request one
- Determine and manage your Pro subscription entitlements, and understand aggregate subscription performance (Section 3.6)
- Maintain the security of the Service and comply with legal obligations
We do not use your information for advertising, we do not build advertising profiles, and we do not use your information for automated decisions that produce legal or similarly significant effects about you.
5. WHO RECEIVES YOUR INFORMATION
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. The parties that can process your data today are:
- Supabase (cloud sync mode): hosts our authentication and database, which contain your account, profile, vehicle, trip, shift, and location data described above. Supabase acts as our service provider. Cloud data is hosted in Canada (AWS region
ca-central-1, Montréal). If you use the Service from the United States, your synced information is transferred to and processed in Canada. - RevenueCat (paid plans): our subscription management provider, which receives the purchase and entitlement data described in Section 3.6 as our service provider and provides us aggregate subscription analytics. RevenueCat's privacy policy: https://www.revenuecat.com/privacy .
- Apple Maps / Google Maps: when you open a shift's route map, map tiles are requested from the device's map provider (Apple Maps on iOS; Google Maps on Android). This can expose your map viewport and route geometry to that provider under its own privacy policy (Apple: https://www.apple.com/legal/privacy/ ; Google: https://policies.google.com/privacy). The web version has no maps.
- Recipients you choose (export/share): if you export your fiscal-year spreadsheet, the file is generated on your device and handed to the operating system share sheet. Whatever app or person you choose to share it with receives that file, which contains your earnings data (pay, tips, miles, drive times, shift times). It does not contain your GPS coordinates, route lines, email, or password. Once shared, that copy is outside our control.
- Apple App Store / Google Play: as distribution platforms and payment processors for in-app subscriptions, the stores process your store account, payment, and purchase information under their own policies; we receive purchase confirmations and receipt data, never your payment card details.
- Legal disclosures: we may disclose personal information if we believe in good faith it is necessary to comply with a legal obligation or valid legal process, protect the rights, property, or safety of DashCash, our users, or the public, or defend against legal liability.
- Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction; this policy (or an equally protective successor) will continue to apply, and we will provide notice of any material changes.
Other than as described above, we do not use general product-analytics providers, advertising networks, social media widgets, or crash-reporting services in the app; the only analytics we receive are the aggregate subscription analytics described in Section 3.6. If we add any new service provider, we will update this policy before that provider begins receiving personal information.
6. DATA STORAGE AND SECURITY
- On your device: your trips, shifts, settings, and (during an active shift only) raw GPS trail are stored in the app's local database and app storage, protected by your operating system's app sandboxing and any device-level protections you enable (such as device encryption and passcode). Your session token is stored in app storage on your device.
- In the cloud (sync mode): data is transmitted over encrypted connections (TLS) and stored in our Supabase-hosted database in Canada. Passwords are hashed by the authentication provider. Database row-level security restricts each account's records to that account.
No method of transmission or storage is 100% secure, and we do not promise absolute security. Protect your account with a strong, unique password, and be careful where you share exported files.
7. RETENTION
- Raw GPS trail points: deleted from your device automatically when the shift ends or tracking stops.
- Local app data: remains on your device until you delete the records, sign out (which clears account-scoped local data), or uninstall the app.
- Cloud data (sync mode): your account, profile, vehicle, trips, shifts, encoded routes, and trip pins are retained while your account exists, and deleted within 30 days after your account is deleted, except where we must retain information to comply with law, resolve disputes, or enforce agreements. Residual copies may remain in our hosting provider's standard backups for the provider's own retention period until those backups rotate.
- Subscription records: entitlement and purchase-event records are retained while needed to honor your subscription and for accounting/tax compliance. When you delete your account, we delete or dissociate the RevenueCat app user identifier associated with your account as part of that process, subject to records the stores or RevenueCat must retain for their own billing and compliance purposes.
- Service logs: our hosting/authentication provider maintains standard service and authentication logs for security purposes for its own retention period under its standard practices.
8. YOUR CHOICES AND RIGHTS
In the app today, you can:
- Delete individual trips (deletion syncs to the cloud in sync mode)
- Sign out, which clears account data from that device (cloud data remains)
- Export a fiscal-year spreadsheet of your earnings data
- Revoke location permission at any time in device settings
Account and data deletion. To delete your account and all associated cloud data (including profile, vehicle, trips, shifts, encoded routes, trip location pins, and the RevenueCat app user identifier), use Delete Account in Profile settings in the App, or email us at andyzweibackdev@gmail.com from your account email with the subject "Delete my account." We will verify email requests and complete deletion within 30 days, subject to legal retention exceptions, and confirm when done. In-app deletion is processed promptly for the signed-in account; the 30-day period is an outer bound that also covers email requests and backup cleanup.
Access, correction, and portability. You can view and edit your data in the app. You may also request a copy of the personal information we hold about you, or ask us to correct it, using the contact above.
State privacy rights. Depending on your state of residence, you may have legal rights to access, correct, delete, and receive a portable copy of your personal information, and to not be discriminated against for exercising these rights. We honor the requests described below for all US users regardless of state.
- California residents (CCPA/CPRA): you have the rights to know, access, correct, and delete personal information, and to limit use of sensitive personal information. We do not sell or share personal information (as those terms are defined by the CCPA), including the precise geolocation and financial information described in this policy, and we have no actual knowledge of selling or sharing personal information of consumers under 16. Because we do not sell or share personal information, no opt-out is required, but you may still contact us with any request. We use sensitive personal information (precise geolocation during shifts; earnings records you log) only to provide the Service features you request, which does not require a "Limit" option under the CPRA. We will not discriminate against you for exercising your rights. You may use an authorized agent by providing signed permission; we will verify requests using your account email.
- Residents of other states with privacy laws (including Colorado, Connecticut, Texas, Virginia, and others): you may have similar rights of access, correction, deletion, and portability, and the right to opt out of targeted advertising and sales — practices we do not engage in.
To exercise any right, contact andyzweibackdev@gmail.com. We may need to verify your identity (normally by matching your account email) before acting on a request. If we decline a request, you may appeal by replying to our decision, and we will respond to your appeal as required by applicable state law.
9. USERS OUTSIDE THE UNITED STATES
The Service is intended for United States users only. Our cloud infrastructure is located in Canada. If you access the Service from outside the United States, you do so on your own initiative. Your information may be transferred to and processed in Canada (and, where applicable, by service providers in other jurisdictions) under this policy. Our contract with you is governed as described in our Terms.
10. CHILDREN'S PRIVACY
The Service is not directed to children. You must be at least 13 years old to use the Service. The app collects precise location during shifts and earnings records, and is designed for working gig drivers. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us at andyzweibackdev@gmail.com and we will delete it.
11. AUTOMATED DECISION-MAKING
We do not make decisions based solely on automated processing that produce legal or similarly significant effects about you. Fuel-cost and take-home estimates are arithmetic performed on the numbers you and your GPS provide, for your information only.
12. THIRD-PARTY LINKS AND PLATFORMS
The map screens are provided by Apple or Google as described in Section 5. DashCash is an independent tool and is not affiliated with, endorsed by, or connected to DoorDash, Uber, Uber Eats, Lyft, Instacart, Grubhub, or any other gig platform; platform names appear in the app only as labels for categorizing your own entries.
13. NOT TAX, LEGAL, OR FINANCIAL ADVICE
DashCash is a tool to help you understand your income and track your finances as a gig driver. All figures in the app — including fuel cost, take-home pay, deduction summaries, and the fiscal-year export — are estimates calculated from the numbers you enter and, if enabled, GPS-measured mileage. They are provided for your personal information only.
DashCash is not a tax preparation, filing, or advisory service, and nothing in the app constitutes tax, legal, accounting, or financial advice. The app does not apply IRS standard mileage rates, does not file returns, does not connect to the IRS or any tax authority, and is not a substitute for professional tax preparation. You are responsible for the accuracy of the information you enter and for your own tax obligations. Consult a qualified tax professional before relying on any figures from the app for tax filing or financial decisions.
14. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. If we make material changes — including adding any new category of data collection or any new third-party recipient — we will notify you in the app and/or by email before the change takes effect, and we will update the "Last updated" date above. Your continued use of the Service after the effective date of an updated policy means the updated policy applies.
15. CONTACT US
Questions, requests, or complaints:
- Privacy requests: andyzweibackdev@gmail.com