UVC

Privacy Policy

Privacy Policy

Last updated: 30 August 2026

This Privacy Policy explains how Universal Vehicle Cup (“UVC”, “we”, “us”) collects, uses, and shares information when you use the UVC mobile application (iOS and Android, bundle ID com.uvc.mobile), our public web host at app.univehcup.com, and our API at api.univehcup.com. Use of UVC is also governed by our Terms of Use at app.univehcup.com/terms.

Contact

For privacy questions, access requests, correction requests, or deletion requests, email:

shrampro@gmail.com

Operator: Yan Koshelev.

1. Who is responsible

The controller of personal data for UVC is Yan Koshelev.

Contact: shrampro@gmail.com.

2. What this policy covers

This policy covers:

  • The UVC mobile apps on iOS and Android
  • The public website app.univehcup.com (store links, deep-link fallbacks, public profiles, and race share pages)
  • The UVC API at api.univehcup.com that powers the apps

3. Account and identity

Sign-in is provided by Clerk. You may create an account with email and password, or with Google or Apple sign-in. Clerk processes authentication data (such as email address, password hashes managed by Clerk, OAuth identifiers, and session tokens). Clerk may also store profile fields such as name used only for authentication.

In UVC we store an app profile linked to your Clerk account, including a unique public nickname, optional avatar URL, language preference (for example English or Russian), unit system (metric or imperial), country preference, race countdown preference, and app points balance. You can change your country in Profile settings.

Your Clerk email and real name are not shown to other drivers on leaderboards, share cards, or public profiles. Other users see your nickname (and related race/result information described below).

4. Location and race telemetry

UVC is a location-based racing product. We do not continuously track your location when you are not racing or recording a path.

We use location in these situations:

  • During an active race: we record GPS samples (latitude, longitude, speed, heading, accuracy, and timestamps), including while the app is in the background when you grant background location permission. Samples are uploaded periodically (typically about every 60 seconds) and when you finish.
  • Near Me / start proximity: we may use your current position to rank nearby paths or to check that you are close enough to start.
  • Record my path: denser GPS is collected only while you choose to record a path for submission.
  • Country from IP (not GPS): when the app talks to our API, we may infer your country from the request IP address using a local GeoIP database on our servers. We store the country code only — not the IP address, city, or coordinates from this lookup. This is not continuous tracking and does not use GPS. We use it to default your unit system on first sign-in, show country in Settings, and operate the service (including targeting operator announcements). You can correct your country in Settings; we do not keep overwriting it from IP after it is set.

5. How race data is stored

Telemetry points and race results (duration, distance, speeds, path deviation, and derived track geometry) are stored on our servers (PostgreSQL with PostGIS hosted by Neon) so we can show your results, support challenges, and operate the service.

If your connection drops during a race, GPS points may be buffered on your device in a local SQLite database until they can be uploaded. Session and preference data may also be cached on device (for example via secure storage used by Clerk and local app storage).

6. Vehicles and photos

In your garage you may store vehicle details such as nickname, brand, model, generation, year, engine, body type, transmission, drivetrain, color, notes, and an optional VIN.

If you upload a vehicle photo (or catalog evidence photo), the image is stored using Vercel Blob as you provided it. We do not blur license plates. If you care about privacy, blur or cover plates before uploading.

7. Push notifications

With your permission we store an Expo push token for your account so we can send:

  • A foreground “race in progress” notification while GPS tracking runs during an active race (required for background tracking on Android)
  • Optional alerts when race results are ready
  • Occasional operator announcements (events, operations, or marketing) when push is enabled

8. Public website

app.univehcup.com does not provide in-browser sign-in or product accounts. It serves Universal Links / App Links, “get the app” pages, public nickname profiles, and race share cards.

Those pages display information that is already public in the product (for example nickname, path name, race duration, vehicle label). Hosting providers may process standard technical logs (such as IP address and user agent) when you load the site.

9. Service providers

We use trusted processors to operate UVC. They process data only as needed to provide their services:

  • Clerk — authentication and sessions
  • Neon — database hosting (profiles, races, telemetry, vehicles, push tokens)
  • Vercel — hosting for API, web, admin, and Blob file storage
  • Upstash Redis — API rate limiting
  • Expo / EAS — app builds, updates, and push relay to Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM)
  • MapLibre and OpenFreeMap — map tiles and rendering; tile servers may receive your device IP when maps load
  • Google and Apple — if you sign in with those providers

10. Analytics and crash reporting

We do not currently operate production analytics or crash-reporting SDKs in the mobile app. Product event logging is limited to development builds. If we enable observability tools later, we will update this policy.

11. What other users can see

Depending on features you use, other users may see your nickname, race results, challenge/share cards, and public profile information. They do not see your Clerk email or real name through UVC. Your country preference is not shown to other drivers on leaderboards, share cards, or public profiles.

12. Retention

We keep account, race, telemetry, vehicle, and related data while your account is active and as needed to provide racing history and the service. Country and other profile preferences are kept with your account until deletion. We do not currently publish a fixed automatic deletion schedule for race GPS after a set number of days.

You can request deletion as described below.

13. Account deletion

You may delete your account from Profile in the UVC app. That removes your Clerk authentication account and your UVC server data (profile, races, telemetry, vehicles, photos, challenge records, and related rows). Paths you submitted may remain on the service with the creator unlinked.

If anything remains after deletion, email shrampro@gmail.com and we will process cleanup.

14. Children

UVC is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided data, contact shrampro@gmail.com and we will take appropriate steps.

15. Your rights

Depending on where you live, you may have rights to access, correct, delete, or restrict processing of your personal data, and to object to certain processing. To exercise these rights, email shrampro@gmail.com. We may need to verify your request.

If you signed in with Google or Apple, you can also manage permissions in those accounts. You can revoke location and notification permissions in your device settings (some race features may then be unavailable).

16. Security

We use HTTPS in production and limit API access with authenticated sessions and rate limits. No method of transmission or storage is completely secure; please use a strong account password and keep your device updated.

17. Changes

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Continued use of UVC after an update means you accept the revised policy, unless applicable law requires otherwise.