Looqate

Privacy Policy

Last updated: 16 August 2026

This Privacy Policy explains how Looqate (“we”, “us”) handles personal data when you use the Looqate website, progressive web app, iOS app, or Android app (Trusted Web Activity) (together, the “Service”). You can browse the public map and open directions without creating an account. Some features (ratings, suggestions, viewing access codes, and saved map filters) require an account.

It is written to match how the product works today. It is not legal advice. If you need formal advice for your jurisdiction, consult a qualified lawyer.

Who we are

Looqate is operated as an independent project. For privacy requests, contact [email protected].

What we collect

  • Account data. Name, email address, and linked sign-in provider details from Apple or Google (including OAuth tokens needed to keep that provider linked), or your email when you choose “Continue with email” (magic-link sign-in). You can edit your display name in Account; it is stored for your account UI only and is not shown to other users on the map or on contributions. We only create or sign you in when the email is verified — Apple or Google must report it as verified, or you must open the one-time link we email you. Apple may share a private relay email and only sends your email/name on the first authorization. We also store your role in the Service (for example user, contributor, or admin) and any ban status set by operators. In the Looqate iOS app, “Continue with Apple” and “Continue with Google” may use Apple’s and Google’s native Sign-In SDKs on your device (which can use accounts already on the device) and then send an ID token to our servers to create your session. The Android app opens the same Service in a Trusted Web Activity (Chrome) and uses the web sign-in flows (Google, Apple, or email magic link), not those native iOS SDKs.
  • Android beta waitlist. You can join an optional Play Store beta waitlist from the public waitlist page, from Account on Android (signed in), or from the map (email only, no account required). We store the invite email you provide and, when you are signed in, link it to your user id. Joining creates a membership row; leaving (while signed in) or an operator remove deletes that row. Operators may mark membership pending, active (invite sent / on the tester list), or inactive, and may email you a Google Play closed-testing invite link when a spot is ready (via Resend, to the waitlist email you gave). We do not sell this list. Deleting your account removes linked memberships. Guests (and anyone) can email [email protected] to ask to be removed.
  • Session data. Session tokens, expiry, and technical session metadata such as IP address and user agent when provided by the auth stack.
  • Map contributions. Toilet (location) records you create, suggest, or edit, including name, description, address text, map coordinates, and who-can-use types when set (for example men’s, women’s, unisex, and disabled — one or more). Signed-in users may suggest a new toilet; until an admin approves it, that place and any attributes you add on it (for example access codes and costs) are visible only to you and to operators. You may permanently delete (withdraw) your own pending suggestion before it is approved, and you may delete a rejected suggestion that still appears only to you. After approval it appears on the public map like other toilets. Contributors and admins may add toilets that go live immediately. Signed-in users may also suggest who-can-use types and mark them accurate or inaccurate (same accuracy checks as other attribute suggestions). Operators may update name, address (including refreshing address text from map coordinates via Photon), override who-can-use types, promote or demote type suggestions, and approve or reject pending toilet suggestions. You may also submit other attribute suggestions (for example access codes and costs). These are associated with your account.
  • Reviews. Ratings and related review scores you submit about locations, linked to your account. This includes accuracy checks on attribute suggestions (including who-can-use types), problem reports you submit from a toilet (selected issues and optional details), stored with your account against that place.
  • Map filters. Preferences for which location attributes to show on the map (for example who can use a toilet, access code, and cost). When you are signed in, these preferences are stored on your account and also kept in local storage on this device so they still apply offline. Without an account, filters you choose apply only for the current visit and are not saved on our servers or in local storage.
  • Device location (optional). If you allow geolocation in the browser, the iOS app, or the Android app, your device may share precise GPS location with the Service so we can centre the map on first load (when already allowed), follow your position, and show nearby places. Permission is controlled by your browser or device (on Android, the system location dialog may be used via location delegation); we may remember locally that you previously granted it.
  • Default map centre. If device location is unavailable or denied, the map centres on a default area (London). This does not use IP-based geolocation or the browser geolocation prompt.
  • Device motion / compass (optional). If you turn on compass / heading mode on the map, the Service may read device orientation and motion sensors on your device so the map can rotate with your heading. On the iOS app this uses the system motion permission; in a browser or the Android Trusted Web Activity it uses the site motion-and-orientation permission. Heading data stays on your device for map display and is not uploaded to our servers.
  • Address and place lookup (Photon). When you or an operator look up or refresh an address from map coordinates, the Service sends those coordinates to the Photon reverse geocoder (hosted by Komoot at photon.komoot.io). When you search for a place in the map search bar (for example a station or neighbourhood), the Service sends your typed query and optional map-bias coordinates to Photon’s forward geocoder at the same host. Photon may process the request (including technical metadata such as IP address) under its own policy. Returned address text from reverse lookups may be stored on the toilet record. Place-search results are used to move the map and are not stored as your search history.
  • Local preferences. On your device we may store theme preference, offline-map preference, signed-in map filters, a “your locations” map filter (when signed in), an admin-only unpublished filter (when you have the admin role), and similar UI settings in local storage (see Cookies and similar technologies).
  • Offline map cache (opt-in). If you turn on Save map offline in Your data, we may store on your device (1) a snapshot of toilet pins (ids, names, coordinates, addresses, who-can-use types, and related map-filter fields from the last successful sync) in IndexedDB, and (2) map tiles, sprites, and fonts you have already viewed (from OpenFreeMap) in the browser’s Cache Storage. This data can become stale until you are online again. You can turn the setting off (stops new caching) and Clear offline cache from Your data, or clear site data in your browser.
  • Error and problem reports. In production builds we use Sentry to capture application errors. Reports can include technical details such as stack traces, browser information, and the page or action that failed. When you choose Report a problem on a toilet, we may also send a copy of that report to Sentry for operator triage (selected issues, optional details, and toilet identifier and name/URL), along with device or browser context Sentry attaches. From Account you can also choose Send feedback and submit a short message in the app; we may send that message to Sentry for operator triage together with your account name and email so we can follow up. We do not intentionally send authentication secrets in these Sentry reports.
  • Product analytics (PostHog). We use PostHog to understand how the Service is used and to capture some client-side errors (for example page views and product events such as starting sign-in, requesting map location, waitlist actions, toilet problem reports, Account feedback, or suggesting a toilet). On first visit we ask whether to allow analytics cookies. If you choose Accept analytics, PostHog may use cookies and/or local storage for an analytics id and session data, and when you are signed in we may link events to your account id and basic account properties (such as email, display name, and role). If you choose Essential only, PostHog runs in cookieless mode: it does not set analytics cookies or store an analytics id on your device, and visitors are counted with a privacy-preserving server-side hash without linking to your account identity. We do not use PostHog for advertising.
  • Map tiles and assets. The map loads tiles, sprites, and fonts from third-party map infrastructure (currently OpenFreeMap). Those providers may process technical request data such as IP address under their own policies. When Save map offline is on, copies of tiles you view may also be kept on your device as described above.

How we use data

  • Create and secure your account and sessions
  • Show the map, search, and location summaries to signed-in and signed-out visitors (including an approximate map centre from precise device location when allowed, or from IP as a fallback)
  • Resolve address text from coordinates when you or operators look up or refresh an address
  • Show full location details (including access codes), ratings, and contribution tools to signed-in users
  • Show the map offline when you have opted in and previously synced toilets / viewed map tiles on this device
  • Open Google Maps directions when you choose Directions on a toilet
  • Publish and moderate community toilet data and reviews
  • Review toilet problem reports you submit (stored on your account and optionally triaged via Sentry)
  • Read optional Send feedback from Account (message plus account name and email), which we may triage via Sentry
  • Enforce roles, bans, and Service integrity
  • Diagnose and fix production errors
  • Measure product usage and improve reliability and usability of the Service (including via PostHog, with cookies only if you accept analytics)

We do not sell your personal data. We do not run third-party advertising trackers in the app today.

Legal bases (where GDPR/UK GDPR applies)

We process personal data where needed to:

  • Perform the contract — provide the account, map, and contribution features you request
  • Legitimate interests — secure the Service, prevent abuse, understand production failures, measure product usage with cookieless analytics when you decline analytics cookies (PostHog), and centre the map using approximate IP-based location when device location is unavailable
  • Consent — for optional device GPS geolocation and similar device permissions you control, and for PostHog analytics cookies when you choose Accept analytics
  • Comply with law when we must respond to lawful requests

Sharing

We share data only as needed to run the Service, including:

  • Hosting and database providers that store account and contribution data under our control
  • Authentication providers such as Apple and Google when you choose “Continue with Apple” or “Continue with Google” (including native Sign-In SDKs in the iOS app; the Android app uses the web sign-in flows inside Chrome).
  • Email delivery (Resend) when you choose “Continue with email” — we send your email address to Resend so it can deliver a one-time sign-in link — and when operators email Android beta waitlist invite links to the address you joined with
  • Sentry for production error monitoring, operator triage of voluntary toilet problem reports, and optional Send feedback from Account
  • PostHog for product analytics, usage events, and optional client-side exception capture — with cookies and optional account linking when you accept analytics, or cookieless anonymous counting when you choose Essential only
  • Map tile providers (OpenFreeMap) when the map loads
  • Geocoding (Photon / Komoot) when coordinates are sent to look up or refresh an address, or when you search for a place and the typed query (with optional map-bias coordinates) is sent to Photon
  • Google Maps — if you choose Directions, we open the Google Maps app when available (otherwise Google Maps in the browser) with the toilet as the walking destination. If you have already shared your location with Looqate, we may include it as the route start. Routing after that handoff is handled by Google Maps under its own policies.
  • Other users — contributions you publish (for example approved toilet locations including who-can-use types when set or community-suggested, attribute suggestions such as access codes and costs, and review scores including accuracy checks on attributes) are visible to other signed-in users, but without your name or email. Pending toilet suggestions you submit are not shown to other users until an admin approves them. Signed-out visitors can see public map locations, costs, and whether an access code exists, but not the code itself or ratings. Operators (admins) may see account identifiers when moderating reports, pending toilet suggestions, or managing users.
  • Authorities if required by applicable law

Cookies and similar technologies

We use a small number of cookies and similar on-device storage to run the Service. We do not use advertising cookies or third-party marketing trackers.

  • Session cookies. When you sign in, we set first-party cookies (via our auth stack) so we can keep you signed in, secure your session, and recognise you on later requests. These are needed to provide the signed-in Service you ask for.
  • Last sign-in method cookie. After you sign in, we may set a first-party cookie that remembers which method you used last (for example Apple, Google, or email) so we can highlight it on the sign-in screen. It does not identify you by name or email. You can clear it by clearing site cookies.
  • Local storage — theme. Your appearance preference (system, light, or dark) is stored in the browser’s local storage so the UI stays consistent between visits.
  • Local storage — offline map. Whether Save map offline is on or off is stored in local storage. When on, toilet snapshots and viewed map tiles may be stored in IndexedDB and Cache Storage as described under What we collect.
  • Local storage — your locations map. When you are signed in, whether the “Your locations” map filter is on or off is stored in local storage so the map can show only toilets you added or suggested.
  • Local storage — admin unpublished map. If your account has the admin role, whether the Unpublished map filter is on or off is stored in local storage so pending or rejected toilet pins can appear on your map when you opt in.
  • Local storage — map filters. When you are signed in, your map filter choices are also stored in local storage on this device (keyed to your account) so they work offline. Guests do not get a local filter store.
  • Local storage — location prompt. We may store a local flag that you previously allowed device location, so we can avoid repeatedly prompting you. This is not your GPS coordinates.
  • Analytics (PostHog). If you Accept analytics, PostHog may store a first-party analytics id and related session data in cookies and/or local storage. If you choose Essential only, PostHog does not set those analytics cookies or local analytics ids (cookieless mode). We store your Accept analytics / Essential only choice in local storage (looqate-analytics-consent). Clearing site data removes that choice and any PostHog cookies; signing out also resets an identified PostHog profile when you had accepted analytics.

Third-party map, geocoding, analytics, and error-monitoring services may process technical request data (such as IP address) when your browser or the app contacts them; they may also set their own cookies under their policies. See Sharing above. You can clear cookies and site data in your browser or device settings; signing out ends the current session cookie.

We use first-party storage that is needed to provide the Service (sessions, theme, map preferences). For PostHog we show an in-app prompt: Accept analytics enables analytics cookies; Essential only keeps cookieless anonymous stats only. If we add advertising cookies or other non-essential tracking that requires a different consent flow, we will update this policy.

Retention

We keep account and contribution data while your account exists and as needed to operate the Service. Sessions expire according to auth settings. Error reports, problem-report feedback copies, and Account Send feedback submissions are retained according to our Sentry project settings. Product analytics events are retained according to our PostHog project settings. Operators may permanently delete toilet locations (and related attributes and ratings) from the Service. You may also permanently delete your own pending toilet suggestion before it is approved, and permanently delete a rejected suggestion that remains visible only to you. You can delete your account from Account & data in the app, or request deletion on the delete account page. Deletion removes your profile, sessions, linked sign-in providers, ratings (including problem reports), and saved filters. Public map contributions (toilets and attribute suggestions) are retained on the Service without your identity so the map stays useful for others. For other retention questions, email [email protected].

Your choices and rights

  • Update your display name in Account
  • See which sign-in providers are linked to your account in Account & data
  • Turn Save map offline on or off, and Clear offline cache, from Your data
  • Export a copy of your account data from Your data
  • Delete your account from Account, or request deletion on the delete account page (public map contributions stay anonymised as described above)
  • Revoke device GPS geolocation in your browser or device settings
  • Block or clear site data / use network controls if you do not want your browser to contact geocoding or map tile providers used by the Service
  • Sign out to end the current session
  • Clear cookies / local storage / site data in your browser
  • Request correction, restriction, or other privacy rights where applicable law gives you those rights

For privacy rights that are not available in the app, or if you need help with export or deletion, email [email protected].

Children

The Service is not directed at children under 16. If you believe a child has created an account, contact us so we can delete it.

International transfers

Depending on where we host the app, database, Sentry, PostHog, map tiles, IP geolocation, or geocoding providers, data may be processed in the UK, EEA, United States, or other countries. Where required, we rely on appropriate safeguards offered by those providers.

Changes

We may update this policy when the product or our practices change. The “Last updated” date at the top will change when we do. Continued use after an update means you accept the revised policy.

Related

Use of the Service is also governed by our Terms of Service. Cookie and local-storage details are in Cookies and similar technologies above.