Legal

TORP App Privacy Policy

Last updated:

1. About This Policy

This policy explains what the TORP App does with your data. It covers the TORP App for iOS and Android only.

Our website privacy policy covers the torpmotors.com website and online store, including your rights as a data subject, how we secure data, and how to contact us or complain. This policy does not repeat those sections. Read the two together.

2. Who Is Responsible

The TORP App is published by Torp d.o.o., Ribarska 1A, 51000 Rijeka, Croatia. We are the data controller for the processing described here.

For any question about this policy, or to exercise your data-protection rights, contact us at info@torp.hr.

3. You Do Not Need an Account

The TORP App has no user accounts. There is no sign-up, no login, and no password to create. Pairing, tuning, ride logging, the lap tracker and firmware updates all work without you identifying yourself.

Two things in the app are not accounts:

  • Your controller can have an optional Bluetooth password. It is a device PIN, held on your phone, not a login for a TORP service.
  • If you transfer ownership of a controller, our support process asks for an email address so that we can send a verification email. That is one-off email handling. No account is created.

The only stable identifier the app associates with you is the hardware serial number of your controller.

4. What Stays on Your Phone

The app writes to a local database on your device. The following never leaves it. There is no upload path for any of it in the app:

  • your ride GPS data, meaning latitude, longitude and altitude;
  • everything the lap tracker records, meaning track shapes and their coordinates, lap times, session records, per-lap telemetry and metrics; and
  • your drag and acceleration test sessions.

This data is read back only on your own device, to draw your ride list, your ride map and your lap results. If you delete the app, it goes with it.

Section 8 covers the separate question of map providers, which do receive location while a map or navigation screen is open.

5. What the App Sends to TORP

The app uploads controller diagnostic data to our own server at controller-api.torpmotors.com. That data is:

  • live controller telemetry: current, voltage, speed, motor, MOSFET and battery temperatures, state of charge, trip distance, power, odometer, duty cycle, wheel speeds, fault and warning codes, cell voltages and timestamps;
  • daily peak values, fault logs, BMS information and hardware status;
  • configuration and calibration snapshots; and
  • the serial number of the controller the data came from.

We use it to diagnose faults, judge warranty claims, find failure patterns across the fleet, and improve firmware and product design.

This upload is on by default. The app has a diagnostic sharing setting that switches all of it off. Until you turn it off, your controller’s diagnostic data is sent to us.

No location data is included. There is no latitude, longitude or altitude field in anything the app sends to our server.

6. Firmware Updates

Firmware comes from our own server at controller-api.torpmotors.com. We do not use a third-party distribution network for it.

When the app checks for an update it sends us your controller’s serial number, the app version, your device’s operating system platform, the software version currently installed, and whether you have opted into beta releases. Where a display, wiring harness or BMS is connected, it also sends that module’s serial number, software version and device type.

Downloading the firmware file itself sends no identifiers at all. After the update is installed, the app confirms it by sending the device serial number and the new version.

The only identifiers involved are hardware serial numbers, the app version and the name of your operating system platform. The app does not send a phone identifier, an IMEI or an advertising ID. The Android build removes the advertising ID permission from its manifest.

7. Support Requests

The Report button in the app does not send anything to our API. It opens our public contact form at torpmotors.com/contact in an in-app browser, and fills in the hardware setup of the connected bike so that you do not have to type it out: bike model, motor, battery type, TORP controller model and controller serial number.

You write the message yourself and submit it on the website, where it is handled as any other contact form submission. No screenshot, log file or image is captured or sent.

8. Location

Where the app uses your location, it uses it while the app is open. The background location permission is not declared, so the app cannot access your location when it is not in use.

Android asks for location permission for two unrelated reasons:

  • Bluetooth scanning on Android 11 and below. On those versions the operating system itself requires location permission before an app may scan for Bluetooth LE devices, even though no location is being used. On Android 12 and above the app uses the dedicated Bluetooth scan and connect permissions and does not need location for Bluetooth at all.
  • Actual GPS features: plotting your rides on the map, recording coordinates in your local ride log, the lap tracker recording track layouts and detecting start and finish gates, turn-by-turn navigation, and the speed and G-force camera overlay.

On Android 12 and above, location is a separate and optional request. You can decline it and keep using the app. The app tells you what declining costs you: ride tracking on the map, ride log sharing, the lap tracker and navigation.

Your location is not sent to TORP. It is sent to the map and navigation providers named in section 9, and only while you have one of those screens open.

9. Services We Use

Google Firebase, from Google, provides four things in the app:

  • Crashlytics records crashes and errors, including Flutter and native crashes, non-fatal errors we log deliberately, custom keys and breadcrumb logs, so that we can find and fix faults.
  • Analytics starts with the app and records how the app is used: connecting to a device, disconnection, a failed connection, riding mode changes, settings changes and screen views. It also records your controller type, firmware version and bike type as properties. The identifier Analytics uses for you is the Bluetooth device name of your controller.
  • Cloud Messaging delivers push notifications. Subscriptions are by topic, such as all users, your platform, firmware updates, promotions and app updates. No per-user messaging token is stored on our server.
  • Remote Config delivers configuration values to the app.

Google Play In-App Update offers app updates inside the Android app.

Map and navigation providers receive your location while the relevant screen is open, because they need it to draw the map or route you: Mapbox for map tiles and static map images, and Google Maps SDK, Google Places Autocomplete, Google Geocoding and the Google Navigation SDK for maps, place search and navigation.

The app contains no advertising SDK and no attribution SDK.

10. International Transfers

Our own server is operated by us and hosted in the European Union.

Google and Mapbox are able to process data outside the European Economic Area. Where that happens, those transfers rely on the safeguards those providers put in place, such as the European Commission’s standard contractual clauses. Section 9 of our website privacy policy sets out our general position on transfers.

11. How Long We Keep It

Diagnostic data we receive is kept only for as long as it is reasonably needed for the purposes in section 5, including the length of the applicable warranty period, after which it is deleted or anonymised.

Crash and analytics data is kept for the retention period set in Firebase for the relevant product.

Data that stays on your phone stays there until you delete it or uninstall the app. We cannot delete it for you, because we never receive it.

12. Your Rights

You have the rights set out in section 11 of our website privacy policy, including access, rectification, erasure, restriction, portability and objection, and the right to complain to the Croatian Personal Data Protection Agency (AZOP).

For app data, two practical points help us act on a request:

  • Quote the serial number of your controller. Without it we usually cannot connect diagnostic data to you, because nothing else in it identifies you.
  • Data described in section 4 is on your device only. You do not need to ask us to erase it, and we are not able to.

You can stop the processing described in section 5 at any time by turning off diagnostic sharing in the app.

13. Children

The TORP App is not directed at children, and orders for TORP products may not be placed independently by minors. Our products are high-performance components for electric motorcycles, and section 20.1 of our Terms & Conditions sets out who should be riding a vehicle fitted with them.

14. Changes to This Policy

If we change what the app collects or who receives it, we will update this policy and the date shown at the top of this page. Where a change requires your consent, we will ask for it in the app.

15. Contact

Torp d.o.o. Ribarska 1A 51000 Rijeka Croatia

Email: info@torp.hr