PRIVACY POLICY

Effective date: August 18, 2026

This Privacy Policy explains how Hey Beep Beep Inc. ("Beep Beep," "we," "us," or "our") collects, uses, discloses, and protects personal information through the Beep Beep mobile application, websites, and related services (collectively, the "Service"). It also describes your privacy choices and rights.

1. Controller and contact information

Hey Beep Beep Inc., a Delaware corporation, is the controller of personal data processed for the purposes described in this Policy unless stated otherwise.

Hey Beep Beep Inc.

2041 East St. PMB 1311

Concord, CA 94520

Privacy inquiries and rights requests: privacy@heybeepbeep.com

2. Scope and age restrictions

Accounts are for adults age 18 or older. The Service includes family-oriented content that an adult may play for children, but children may not create accounts or independently use interactive features, submit recordings or other content, make purchases, or enable location, calendar, microphone, advertising, or tracking permissions.

We do not knowingly collect personal information directly from children under 13 in the United States or from children who cannot validly consent under applicable EEA law. If you believe a child has provided personal information directly, contact privacy@heybeepbeep.com. We will investigate and delete it where required. Parents should not include a child’s name, voice, precise location, calendar details, or other identifying information in submissions unless a specific feature clearly explains and lawfully supports that processing.

3. Personal information we collect

3.1 Information you provide

  • Account and contact information, such as name, email address, password or authentication token, country, language, and preferences.

  • Transaction and subscription information. Payment-card details are generally processed by the app store or payment processor; we may receive purchase status, product, price, currency, transaction identifiers, and limited billing details.

  • User Content and communications, such as voice recordings, transcriptions, text, trip ideas, ratings, feedback, support requests, survey responses, and other submissions.

  • Information you provide about travel preferences, household or audience type, interests, accessibility needs, and content settings. Avoid providing sensitive information unless requested and necessary.

3.2 Information collected through the Service

  • Precise and approximate location, which may include GPS coordinates, movement, direction, speed, nearby places, and background location when you have enabled it.

  • Routes and trips, such as origins, destinations, planned and traveled routes, stops, searches, saved places, timestamps, distance, duration, and interactions with stories or recommendations.

  • Device and usage information, such as IP address, device and advertising identifiers, operating system, app version, language, network, referring pages, clicks, sessions, feature use, diagnostics, performance, crash logs, and security events.

  • Audio and microphone information when you choose a voice feature, including a recording or live audio, transcription, commands, and associated metadata. We will indicate when the microphone is active.

  • Cookies, SDKs, pixels, local storage, and similar technologies used for authentication, preferences, analytics, attribution, fraud prevention, and, with consent where required, advertising or personalization.

3.3 Information from connected services and others

  • Calendar information you authorize us to access, such as event title, location, date and time, participants or notes where included, and related metadata.

  • Mapping, traffic, place, content, authentication, payment, analytics, advertising, and app-store partners.

  • Other users who share content, referrals, or trip information with you, and publicly available or licensed sources used to provide place and story information.

4. How we use personal information

  • Provide, personalize, and operate navigation assistance, routes, location-aware stories, recommendations, calendar-based trip suggestions, voice features, accounts, and subscriptions.

  • Process transactions, authenticate purchases, deliver receipts, and manage trials, renewals, cancellations, and customer support.

  • Understand feature use, diagnose crashes, measure performance, conduct research and testing, and improve the Service, including AI systems, subject to stated choices and appropriate safeguards.

  • Communicate about the Service, security, transactions, policy updates, support, and, where permitted, news or offers.

  • Protect users and the Service; detect fraud, abuse, security incidents, prohibited conduct, and violations of our Terms.

  • Comply with law, enforce agreements, establish or defend legal claims, and respond to lawful requests.

  • Measure and deliver advertising or sponsored content and attribute campaigns. Where required, we obtain consent before personalized advertising or tracking.

  • Create aggregated or de-identified information that we take reasonable measures not to re-identify, and use it for lawful business purposes.

5. EEA/Swedish lawful bases

For people in Sweden and the EEA, we rely on the following legal bases. The applicable basis depends on the feature and context.

Legal basis

Typical processing

Notes

Contract

Account, requested routes, stories, connected features, purchases, support

Needed to provide features you request.

Consent

Precise/background location where required; calendar; microphone; non-essential cookies/SDKs; personalized ads; marketing

You may withdraw consent prospectively in the app, device, cookie controls, or by contacting us.

Legitimate interests

Security, fraud prevention, essential analytics, service improvement, legal claims, limited direct marketing

We balance our interests against your rights and expectations. You may object in certain cases.

Legal obligation

Tax, accounting, consumer requests, lawful orders, regulatory compliance

Processing required by applicable law.

Vital interests

Rare urgent safety situations

Used only where necessary to protect a person and another basis is unavailable.

We do not condition unrelated core service access on consent to personalized advertising. If we plan to use personal data for a materially different purpose, we will provide additional notice and obtain consent where required.

6. How we disclose personal information

We may disclose personal information to:

  • Service providers and processors that host data, provide maps, routing, places, AI, speech-to-text, audio, authentication, communications, customer support, payments, analytics, crash reporting, security, and other operations under contractual restrictions.

  • Advertising, attribution, and sponsored-content partners when enabled. Depending on the technology and law, disclosure of identifiers, usage, or location for cross-context behavioral advertising may be considered a "sale," "sharing," or targeted advertising even if no money is exchanged. We provide required consent and opt-out controls.

  • App stores and connected services at your direction or as needed to complete a transaction or requested integration.

  • Professional advisers, auditors, insurers, financing sources, and corporate transaction participants, subject to appropriate confidentiality and legal safeguards.

  • Authorities, courts, or others when reasonably necessary to comply with law, protect rights and safety, investigate misconduct, or establish or defend claims.

  • Other people when you intentionally share content or direct us to disclose it.

We do not disclose precise location, calendar content, or voice recordings to data brokers. We do not permit personalized advertising based on information we know relates to a child.

7. Advertising, cookies, and mobile controls

Where required, non-essential analytics and advertising technologies are disabled until you consent. You may change choices through in-app privacy settings, the website cookie controls, device settings, or platform privacy settings. Limiting tracking may not remove contextual ads. Mobile operating systems may provide controls for location, microphone, calendar, notifications, and advertising identifiers.

For U.S. state privacy laws that apply to us, we will honor recognized opt-out preference signals where legally required and technically applicable. Provide a conspicuous "Your Privacy Choices" link if the launch configuration involves sale, sharing, or targeted advertising.

8. Location, calendar, and voice controls

  • Location: Choose approximate or precise access and, where supported, while-in-use or background access in device settings. Background location should be requested only when needed for a clearly explained feature.

  • Calendar: Choose which account or calendars to connect where supported. Disconnecting stops new access but does not automatically erase previously imported data; use account deletion or contact us to request deletion.

  • Microphone and voice: Microphone access occurs only after permission and user action. Any voice or audio data retained with your consent will be stored and deleted according to the retention periods described in Section 9. You may delete saved recordings through a requested deletion.

9. Data retention

We retain personal information only as long as reasonably necessary for the purposes described, including to provide the Service, maintain security, resolve disputes, comply with law, and enforce agreements. We use criteria such as account status, sensitivity, user expectations, feature need, legal limitation periods, and backup cycles.

  • Account and transaction records: Account data for the life of the account plus 30 days; legally required transaction records for 7 years.

  • Precise location and trip history: Precise GPS data for 30 days; trip history for 12 months.

  • Calendar-derived data: 90 days.

  • Raw voice recordings and transcripts: 30 days.

  • Analytics, crash logs, and security logs: Analytics and crash logs for 12 months; security logs for 24 months.

  • Deleted data and backups: 30 days.

10. International data transfers

Beep Beep is based in the United States, and personal data may be processed in the United States and other countries that may not provide the same legal protections as Sweden or the EEA. Where required, we use approved safeguards such as an adequacy decision, the EU Standard Contractual Clauses, the EU-U.S. Data Privacy Framework for participating recipients, and supplementary technical and organizational measures. You may request information about applicable safeguards at privacy@heybeepbeep.com. When we transfer personal data outside the European Economic Area, we use legally recognized safeguards, such as adequacy decisions, the EU–U.S. Data Privacy Framework, or the European Commission’s Standard Contractual Clauses, as applicable.

11. Security

We use administrative, technical, and physical safeguards designed to protect personal information, taking into account its sensitivity and risk. No system is completely secure. You are responsible for protecting account credentials and should notify us promptly of suspected compromise. We maintain incident-response processes and will provide breach notices when legally required.

12. Your choices and rights

Depending on where you live and subject to exceptions, you may have the right to access, obtain a copy of, correct, delete, restrict, or object to processing of personal information; withdraw consent; receive portable data; opt out of sale, sharing, targeted advertising, profiling, or marketing; and appeal a denied request. You will not be discriminated against for exercising applicable rights.

Submit a request through support@heybeepbeep.com or privacy@heybeepbeep.com. We may verify your identity and authority. Authorized agents may submit requests where permitted, but we may require proof of authorization and direct verification. We respond within legally required timeframes.

12.1 Sweden and EEA

You may withdraw consent at any time without affecting earlier lawful processing. You may object to direct marketing at any time and, in certain circumstances, to processing based on legitimate interests. You may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or another competent supervisory authority. We encourage you to contact us first so we can address your concern.

12.2 U.S. state disclosures

If a U.S. state privacy law applies to Beep Beep and to your information, the categories described in Sections 3 and 6 also describe the categories collected and disclosed during the preceding 12 months. We collect them for the business and commercial purposes in Section 4. Whether advertising disclosures constitute sale or sharing depends on the deployed SDKs and applicable law. We do not knowingly sell or share personal information of consumers under 16 without legally required affirmative authorization. California residents may have the right to request access to, correction of, or deletion of their personal information; to receive information about our collection, use, and disclosure of personal information; to opt out of the sale or sharing of personal information; to limit certain uses and disclosures of sensitive personal information; and to exercise these rights without discriminatory treatment. Requests may be submitted by contacting privacy@heybeepbeep.com. We may verify the requester’s identity and will respond within the time required by applicable law. California residents may also authorize an agent to submit a request on their behalf.

12.3 California Notice at Collection

Notice at Collection for California Residents: Hey Beep Beep Inc. collects the categories of personal information described in Section 3, including identifiers and account information, precise geolocation and trip information, device and usage information, calendar information when enabled, voice or audio information when activated, community submissions, purchase information, and related inferences. We use this information for the purposes described in Section 4, including providing, securing, personalizing, supporting, and improving Beep Beep. We do not sell personal information or share it for cross-context behavioral advertising. We retain each category as described in Section 9. For additional information about our privacy practices and your choices, please review the other sections of this Privacy Policy.

13. Automated processing and AI

We may use algorithms and AI to select stories, infer likely trip context or audience preferences, generate or summarize content, transcribe voice, and recommend routes or stops. These functions may use location, route, calendar-derived signals, interactions, or preferences. We do not use solely automated processing to make decisions that produce legal or similarly significant effects about you. We do not use solely automated processing to make decisions that produce legal or similarly significant effects about you. You may contact us at privacy@heybeepbeep.com with questions or requests concerning personalization. You may manage personalization through the Privacy and Personalization settings in the app or contact us at privacy@heybeepbeep.com with questions.

14. Third-party services

The Service may link to or integrate with third-party services. Their privacy practices are governed by their own policies. Review permission screens and third-party terms before connecting an account or visiting a link. We are not responsible for independent third-party practices.

15. Changes to this Policy

We may update this Policy to reflect product, legal, or operational changes. We will post the updated version and revise the effective date. If changes are material, we will provide additional notice and obtain consent where required. Earlier versions will be available at www.heybeepbeep.com.

16. Contact us

Hey Beep Beep Inc.

2041 East St. PMB 1311

Concord, CA 94520

Privacy: privacy@heybeepbeep.com

Support: support@heybeepbeep.com

Website: www.heybeepbeep.com

Adventure

Your cheerful road trip storyteller for families.

Explore

Journey

© 2025. All rights reserved.