Privacy Policy
Effective Date: January 30, 2026
SubwaySync (“we”, “our”, “us”) respects your privacy and is
committed to protecting your information. This policy explains exactly
how we access, use, store, and share data obtained from you.
1. Data We Access
We access:
- Google Email Address – used as an internal account identifier.
- Secondary Google Calendar ID – used to manage a separate Google calendar for subway service changes.
We can not see information in any other calendars.
- Google Account Refresh Token – we securely store a refresh token. This allows the app to update your calendar. We do not store your password nor have access to your other calendars.
2. How We Use Your Data We
use the Google data solely to:
- Create and manage a secondary Google
Calendar containing subway service alerts.
- Ensure calendar events reflect your selected subway lines and preferred time
ranges.
- Contact you regarding important updates, including privacy
policy changes.
- We do not use your Google data for advertising or share
it with third parties for marketing purposes.
- Google API Disclosure: Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. Consent
We process personal data based on:
- Your consent when you authorize Google access.
- The necessity of processing to provide the SubwaySync service.
- You may withdraw consent at any time by disconnecting your Google account.
4. Data Storage and Sharing
Service Providers
We use third-party infrastructure providers to operate, including:
- Supabase for secure data storage.
- Render for application hosting and deployment.
5. User Rights
- You can update your preferences at any
time.
- You can request access or correction of your data.
- You can disconnect your Google account or delete your account to remove all data.
- When you request account deletion, your personal data is removed from our active databases within a reasonable operational timeframe. For security and disaster recovery purposes, encrypted fragments of your data may persist in our immutable backups for up to 30 days before being completely overwritten.