HeadzUp · Off Road Xperience, LLC

HeadzUp Privacy Policy

Off Road Xperience, LLC
6330 Oak Valley Drive, Cumming, Georgia, United States
[email protected] · headzupoffroad.com

Version 2.0 · Effective August 29, 2026 · Supersedes the policy effective August 23, 2026


Table of contents

  1. Who this policy covers
  2. The short version
  3. Our role, and the park's role
  4. What we collect, and from where
  5. Data that never reaches us: the radio mesh
  6. What we do not collect
  7. Why we use it, and our legal basis
  8. Sensitive information: precise location
  9. Who we disclose it to
  10. Artificial intelligence features
  11. Event paperwork and demo days
  12. How long we keep it
  13. How we protect it
  14. International transfers
  15. Your rights and choices
  16. United States state privacy rights
  17. European Economic Area, United Kingdom and Switzerland
  18. Canada
  19. Children and minors
  20. Storage on your device, cookies and similar technologies
  21. Automated decision-making
  22. Features that are planned but not yet live
  23. Changes to this policy
  24. How to contact us

1. Who this policy covers

Off Road Xperience, LLC, a Georgia limited liability company ("ORX", "HeadzUp", "we", "us", "our"), builds HeadzUp — a rider-awareness system for off-road motor parks. This policy explains what personal information the HeadzUp system handles, why, who else sees it, how long it is kept, and what you can do about it.

It applies to every part of the HeadzUp system, whether that part is live today or is described in section 22 as planned:

SurfaceWhat it isStatus
HeadzUp rider appThe iOS and Android app riders use on the trail.Live
HeadzUp Rider Unit ("RU")The LoRa radio that pairs to the phone over Bluetooth.Live
The park meshThe LoRa radio network the Rider Units form among themselves.Live
Park ModeThe operator console built into the rider app, behind a separate staff login.Live
HeadzUp park dashboardThe browser dashboard park staff use to see riders on a live map and message them.Live
The message brokerThe MQTT server the app and dashboard exchange data through.Live
headzupoffroad.comThe public website, sign-up form and (when it launches) checkout.Live / partly planned
HeadzUp Trail MapperThe survey app park staff use to record trail geometry.Live
Provisioning toolsThe internal flashing tool, and the park-facing browser flasher.Live / partly planned
Public API and integrationsThe documented REST API and assistant integrations available to authorised accounts.Live
Support wiki and support emailRider and operator help material, and correspondence with us.Live
Pilot and demo programsTime-boxed validation events, including on-site check-in paperwork.Event-only

If a park you ride at gives you its own privacy notice, that notice governs what the park does with what it sees. This policy governs what we do.


2. The short version


3. Our role, and the park's role

Two separate businesses handle your information, for two different reasons.

ORX is the controller (the business that decides why and how information is used) for: your rider account, your subscription, the operation of the app and the broker, our own diagnostics and liability records, and our support correspondence with you.

Each park operator is an independent controller for what it sees on its own dashboard: where its riders are, what they message the office, what incidents they report, and — where the park has enabled it — the position history it retains for trail and heat mapping. A park decides its own retention, its own staff access, and its own use of that information within the limits of its agreement with us and the law. We are that park's service provider / processor for the dashboard software — we host it, we do not use its data for our own purposes.

Where a park operates the dashboard itself, on its own infrastructure, we may not hold the data at all. Ask the park.

Practical consequence: a request to delete data the park holds may need to go to the park. Send it to us anyway — we will route it and tell you where it went.


4. What we collect, and from where

"Collect" here means the information leaves your phone or your Rider Unit and reaches a HeadzUp server or a park dashboard. Radio-only traffic is section 5.

4.1 Account and subscription

DataDetailSourceRequired
Username3–32 characters, chosen by you. Visible to friends and to park staff.You, at sign-upYes
PasswordStored only as a salted scrypt hash. We never store or display the password itself.YouYes
Email addressUsed for account recovery, service notices, and — only if you tick the box — trail updates and offers.YouYes
Phone numberSecond recovery channel.YouYes
Marketing opt-inA single yes/no flag. Off unless you tick it.YouNo
Subscription status, plan and expiryWhether coverage is active, which plan, and until when.Our billing recordsYes, if you subscribe
Session tokensRandom opaque tokens that keep you signed in. Not derived from your password.Generated by usYes
Recovery intentsA record that a recovery was requested, holding a rider id — not the email or phone submitted.YouOnly if you use recovery

Rider accounts in a pilot program may instead be provisioned by us or by park staff, in which case the email address or phone number they entered is stored the same way and returned to the app so it can show you who is signed in.

4.2 Location

DataDetail
Precise locationLatitude, longitude, speed, heading and accuracy, sampled while a ride is active.
Background locationThe same, while the app is in the background and the screen is off. On Android this runs in a foreground service with a persistent notification; on iOS it uses background location updates. Without it, alerts stop when the screen locks — which is most of a ride.
When it stopsWhen you end the ride, sign out, revoke the permission, or the app is force-stopped.
Where it goesTo the park you selected, over the broker. Also, subject to your settings, over the radio to nearby Rider Units.

Precise location is treated as sensitive personal information — see section 8.

4.3 Identifiers

4.4 Messages and rider-generated content

TypeWho receives itNotes
Message to the park officePark staffIncludes text, timestamp, severity and your identifiers.
Park-wide broadcastEvery rider at that park, and park staff
Group messageThe group's membersGroup membership is app-level, set by you.
Rider-to-rider direct messageThe addressed riderDropped at the dashboard's ingest — park staff are not shown it. It still transits the broker, which is why per-device broker credentials are on the roadmap (section 22). Treat it as private from staff, not as end-to-end encrypted.
SOS, accident, obstacle, hazard, medical, mechanical and other incident reportsPark staff and, for SOS and accident, every rider at the parkCarries the location the report was made from, a timestamp and any up/down votes.
Meetup pinsThe riders you shared them withFriends-only meetups are not surfaced to park staff.
Voice-dictated messagesSame as the message type you sentDictation happens on your phone; only the resulting text is sent. See section 6.

4.5 Device, radio and diagnostic data

4.6 Park operator and staff data

For park staff, club organisers and our own administrators: name or label on the account, email address, role (superadmin, admin, user), which parks the account is scoped to, invite state, password hash, session records, and any API keys issued. Actions taken in the dashboard — messages sent, incidents resolved, parks created — are attributable to the account that took them.

4.7 Position history, heat maps and trails

Where a park enables history, the backend retains rider position rows so it can draw heat maps and trail overlays. This is per-deployment configuration, not a global default. Trail surveys recorded with Trail Mapper are GPS traces driven by staff, with trail names and waypoints — they are about the park's terrain, but they are recorded by an identifiable staff member and are treated as personal information for that person.

4.8 Fleet and provisioning records

Our provisioning tools keep a registry of Rider Units: unit serial (derived from the radio's own node id), park assignment, firmware version, configuration snapshots, flashing history, and encrypted backups of the unit's keys. This is equipment data. It becomes personal information only where a unit is tied to a named rider — for example a rider who owns their unit outright.

4.9 Website

The public website serves the marketing pages, the sign-up form and (when it launches) checkout. It runs no analytics, sets no advertising cookies, and loads no third-party script by default. If bot protection is enabled for a deployment, a Cloudflare Turnstile challenge is loaded on the sign-up form only, and Cloudflare receives the data described in Appendix B. Park-entrance QR codes produce aggregate scan counts — how many scans, which park, which platform — with no identifier tying a scan to a person.

4.10 Support

If you email support, open a ticket, or talk to park staff who escalate to us, we keep the correspondence and whatever you chose to put in it.


5. Data that never reaches us: the radio mesh

Your Rider Unit broadcasts your position, heading and speed over LoRa radio so that other HeadzUp Rider Units in range can compute proximity and raise an alert. Those broadcasts:

There is no way to be visible to other riders' alerts and invisible to their radios at the same time. That is what the product is. If you do not want to be seen on the mesh, do not start a ride.

Two things reach our servers from the radio path only because the phone puts them there: the position your own phone publishes to the broker, and — if you have the bridge enabled — mesh traffic your phone heard and relayed. A rider with no cell signal publishes nothing.


6. What we do not collect

Verified against the shipped code, and mirrored in our app-store data-safety declarations:


Where the GDPR or UK GDPR applies, the legal basis is in the right-hand column. Where it does not, read the column as a plain statement of purpose.

PurposeData usedLegal basis (GDPR / UK GDPR)
Signing you in and keeping your accountAccount data, session tokensPerformance of a contract
Showing you on the park's live mapLocation, identifiers, statusPerformance of a contract
Computing and delivering proximity alertsLocation, identifiersPerformance of a contract
Delivering messages, broadcasts, meetupsMessage content, identifiersPerformance of a contract
Handling SOS, accident and medical reportsIncident content, location, identifiersVital interests of you or another person; performance of a contract
Managing your subscriptionAccount and billing statusPerformance of a contract
Keeping the service working and secure — rate limiting, abuse prevention, fault diagnosisDiagnostics, IP address, identifiersLegitimate interests in a secure, functioning service
Reconstructing what the app knew after an incident (the black box)Alert-path recordsLegitimate interests in defending legal claims and improving safety-critical behaviour
Improving radio and app reliability during a pilotPilot telemetryConsent (it is opt-out in the app; where required, it is opt-in)
Trail and heat mappingPosition history, trail surveysLegitimate interests of the park in operating its site; performance of a contract
Sending trail updates and offersEmail addressConsent
Complying with law, responding to lawful requests, enforcing our termsWhatever is in scopeLegal obligation; legitimate interests; establishment or defence of legal claims

Where we rely on legitimate interests, we have weighed those interests against your rights. You can object — see section 15.


8. Sensitive information: precise location

Under the California Consumer Privacy Act as amended (CCPA/CPRA) and several other state laws, precise geolocation is sensitive personal information.

We collect it, and we use and disclose it only for the purposes permitted without a further right to limit: providing the service you asked for (proximity awareness, the park's live map, incident location), securing and debugging the service, and short-term operational use. We do not use precise location to infer characteristics about you, we do not use it for advertising or profiling, and we do not sell or share it.

Because of that, no "Limit the Use of My Sensitive Personal Information" right is triggered. You can still switch it off outright: revoke the location permission, or stop riding. The app will tell you that a ride cannot run without it, because it cannot.


9. Who we disclose it to

RecipientWhat they receiveOn what footing
The park you selected — its operators and staff, via the park dashboard and Park ModeYour live position and heading, rider and Rider Unit ids, battery and radio health, messages you send to the office or to all riders, SOS and incident reports, meetup pins you made public, and — where the park enables it — retained position history used for trail and heat mapsIndependent controller. Bound by its agreement with us and by its own obligations to you
Other ridersYour position relative to them over the radio; park-wide broadcasts you send; your presence and, if you are friends, your name/handle on the map; SOS and accident alerts you raisePeer-to-peer, and via the park's mesh
Service providers and subprocessorsOnly what each needs. Listed in Appendix BContractually bound to process only on our instructions, not for their own purposes
A park's own integrationsWhere a park issues an API key or connects an integration, that integration sees data within that key's park scopeThe park's choice, under its agreement with us
Professional advisers, insurers, auditorsAs needed, usually in connection with an incidentConfidentiality obligations
Law enforcement, courts, regulatorsWhere legally required, or where we believe in good faith that disclosure is necessary to prevent death or serious injuryLegal obligation; vital interests
An acquirerIn a merger, acquisition, financing or sale of assets, subject to this policy continuing to applyLegitimate interests; we will give notice

We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by California and other US state privacy laws. We have not done so in the preceding twelve months.

We do not disclose private rider-to-rider messages or friends-only meetups to park staff.


10. Artificial intelligence features

The park dashboard includes an optional Park Assistant that lets park staff ask questions about their own park in natural language. When a park has it enabled and a staff member uses it:

We do not use your personal information to train any model of our own.


11. Event paperwork and demo days

At a controlled demonstration or validation event, check-in may ask you to complete paperwork on your own phone: your name, email, phone, a short survey, photographs of your photo ID (front and back), a photograph of your face, and your signature on the event's liability waiver, media release and confidentiality agreement.

None of it is stored. Specifically, by design and enforced in code:

The resulting email, and the signed agreements inside it, are then held by ORX as event records under ordinary business retention. The agreements you sign at an event are separate contracts and say so on their face.


12. How long we keep it

Summarised here; the full table with the configured values is Appendix C.


13. How we protect it

An honest limitation. Today, park-level broker credentials are shared per park. Dashboard-level privacy for rider-to-rider messages is enforced at ingest and works, but a party holding a park's broker credential could subscribe to more topics than the dashboard shows. Per-device broker credentials and tighter access lists are a committed roadmap item (section 22). We would rather tell you this than let you assume otherwise.

No system is perfectly secure, and we do not claim ours is.


14. International transfers

We operate from the United States and our infrastructure is hosted in the United States. If you use HeadzUp from outside the US, your information is transferred to and processed in the US, which may not provide the same level of protection as your home country.

Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss addendum, as applicable, together with supplementary technical measures (encryption in transit, access scoping, minimisation). A copy of the clauses we use is available on request at [email protected].


15. Your rights and choices

These apply to everyone, regardless of where you live. Some jurisdictions add to them — see sections 16 to 18.

In the app and on the site

By writing to us at [email protected], from the address on your account:

How we verify you. We match the request against the email or phone on the account and, where a request is high-risk, ask you to confirm from the app while signed in. We do not ask for more identifying information than the request requires, and we do not keep verification material.

Cost. Free, unless a request is manifestly unfounded or excessive, in which case we will say so before charging anything.

Appeal. If we refuse a request, our response will tell you why and how to appeal. Appeals go to [email protected] with "Appeal" in the subject line; we respond within the period your state's law allows and, if we again refuse, tell you how to complain to your regulator.


16. United States state privacy rights

This section supplements the rest of the policy for residents of states with comprehensive privacy laws — including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia — and for any state whose law comes into force after this date.

Notice at collection. The categories in section 4, collected for the purposes in section 7, retained per Appendix C, disclosed to the recipients in section 9. Sensitive personal information is limited to precise geolocation and, at an event only, the identification documents described in section 11 — used only for the purposes described there.

Statutory categories collected in the last twelve months (using the CCPA's vocabulary): identifiers; personal information under Cal. Civ. Code §1798.80(e) (name, phone, email); commercial information (subscription); internet or network activity (app interaction, diagnostics); precise geolocation; audio-adjacent only in the sense that dictation is converted on-device and never transmitted; professional information for park staff accounts; and inferences — none, we draw no profiles.

Sale and sharing. We have not sold personal information and have not shared it for cross-context behavioural advertising in the preceding twelve months, including that of anyone we know to be under 16. We have no financial incentive programs.

Your rights — to know, access, correct, delete, obtain a portable copy, opt out of sale/sharing and of profiling with legal effects (we do none), limit the use of sensitive personal information (see section 8), appeal a refusal, and not be discriminated against for exercising any of them. Exercise them as described in section 15.

Opt-out preference signals. Our website honours the Global Privacy Control signal. Since we neither sell nor share, the signal has nothing to switch off — but it is recorded and respected.

Shine the Light (Cal. Civ. Code §1798.83): we do not disclose personal information to third parties for their own direct marketing.

Nevada (NRS 603A): we do not sell covered information. Requests to [email protected].

Washington My Health My Data / Nevada SB370: we do not collect consumer health data. Location data is not used to infer health status, and is not shared with any party who could.

Minors: see section 19.


17. European Economic Area, United Kingdom and Switzerland

If the GDPR or UK GDPR applies to you:


18. Canada

If PIPEDA or a substantially similar provincial law (Quebec's Law 25, Alberta's or BC's PIPA) applies:


19. Children and minors

HeadzUp accounts are for adults. You must be at least 18 to create a HeadzUp account, hold a subscription, or accept our terms.

A rider under 18 may use HeadzUp under an account held and accepted by their parent or legal guardian, who is responsible for that use. Where a park issues a loaner Rider Unit to a minor, the park's own check-in and waiver process governs, and the adult who signed for the minor is the account holder for our purposes.

We do not knowingly collect personal information from a child under 13. If you believe a child under 13 has given us information, write to [email protected] and we will delete it. We do not sell or share the personal information of anyone under 16, and we do not knowingly process a minor's data for targeted advertising or profiling.

If a guardian asks us to delete a minor's data, we will — subject to the same legal and incident-record exceptions in section 15.


20. Storage on your device, cookies and similar technologies

The app stores data locally on your phone: your settings, your sign-in token (in secure storage), your friends list, recent messages, cached node information, and the unsent portion of the black-box buffer. This is device storage for the app to work, not tracking. Uninstalling the app removes it. The Android build opts out of the OS's cloud backup, so this data is not copied off your device by the system.

The dashboard sets a session cookie or holds a session token so staff stay signed in. It is strictly necessary, first-party, and expires with the session.

The website sets no cookies for analytics, advertising, or profiling, and loads no third-party script by default. Where bot protection is enabled, Cloudflare Turnstile is loaded on the sign-up form only and sets what is necessary to run the challenge.

Map tiles on the dashboard are requested from a third-party basemap provider (see Appendix B). That provider necessarily sees the requesting IP address and which tiles were requested, which implies the map area being viewed. Rider positions themselves are drawn locally and are never sent to the tile provider.

We do not use pixels, beacons, fingerprinting, or any cross-site tracking technology.


21. Automated decision-making

The proximity alert is automated: the app computes distance, closing geometry, speed and heading, and raises an alert when its thresholds are met. It decides about a moment, not about a person — it produces no legal or similarly significant effect about you, no score, no profile, and no consequence outside the alert itself. It is deliberately biased toward alerting: where a value is unknown, the system does not treat it as safe.

We do not use profiling to make decisions about your account, your subscription or your access.


22. Features that are planned but not yet live

Listed so that this policy covers the system we are building, not only the one shipped today. Each will operate as described here; where one materially changes what we collect or who sees it, we will update this policy and tell you before it launches.

PlannedPrivacy effect
Website checkout and subscriptions (Stripe)The payment processor collects your card details directly on its own infrastructure. We receive a customer/subscription reference, plan, status and the last four digits — never the full card number. Payments never happen inside the app.
Per-device broker credentials and tightened access listsStrictly a privacy improvement. Closes the limitation described in section 13.
In-app sign-up and in-app account deletionAdds an account-deletion entry point inside the app, as the app stores require. Same 30-day commitment.
NFC pairing stickersA pairing identifier written to a sticker inside the Rider Unit's case. Equipment data; no additional personal information.
Message delivery receiptsAdds a delivered/read state to messages you send, visible to you and to the recipient's side of the conversation.
Trail-aware alert suppression and the park map editorUses trail geometry from Trail Mapper to suppress alerts where trails cannot actually converge. Uses terrain data, not additional personal data.
Learning modeTuning alert behaviour from aggregate ride data. Aggregate and de-identified; if it ever needs identifiable data, it will be opt-in.
Partner data paths and third-party integrationsA park may connect an integration under an API key scoped to that park. The park decides; we publish what each integration can see.
Park-facing browser flasherLets park admins update and verify their own units. Handles equipment data and encrypted key backups, behind park-admin authentication.
Watch / wearable companionWould receive alerts and, if it has its own GPS, could become a position source. Same categories, same purposes.
Vehicle-bus (CAN) Rider Unit variantWould read vehicle telemetry — speed, and possibly other bus values — from the vehicle rather than the phone. Vehicle data associated with your account. Not before this policy is updated.
Multi-site cloud dashboardConsolidated hosting for operators with several parks. Same data, same scoping rules.
Extended firmware workIf we ship our own Rider Unit firmware, this policy will state what that firmware records, if anything.

23. Changes to this policy

We will post any change at headzupoffroad.com/privacy and update the version and effective date at the top. Material changes — a new category of data, a new category of recipient, or a new purpose that is not compatible with the original one — will be announced in the app and, where the law requires it, will not apply to information already collected until you have been given notice and, where required, have consented.

Superseded versions are archived and available on request.


24. How to contact us

Off Road Xperience, LLC
6330 Oak Valley Drive
Cumming, Georgia, United States

Write "Privacy Request" in the subject line and tell us which right you are exercising and which email or phone is on your account. If you would rather ask the park you ride at to pass it on, that works too.



Appendix A — Data map by surface

SurfacePersonal data handledReaches ORX servers?Reaches the park?
Rider app (foreground)Account, precise location, identifiers, messages, incidents, meetups, friends, diagnostics, settingsYesYes, for the selected park
Rider app (background)Precise location, identifiers, statusYesYes
Rider app — Solo Ride (no park selected)Location stays on the device and on the radio; nothing is published to a parkNo park publishingNo
Rider Unit ↔ Rider Unit (LoRa)Position, heading, speed, node id, display nameNoNo
Phone ↔ Rider Unit (Bluetooth)The same, plus device configurationNoNo
Message brokerEverything the app publishes and subscribes toYesYes, within park scope
Park dashboardLive rider state, messages (office/broadcast only), incidents, meetups, device health, history and heat maps where enabledHosted by us or by the parkYes
Park Mode (in app)Same as the dashboard, within the staff account's scopeYesYes
Park AssistantQuestions and the in-scope park data needed to answer themYes, plus the AI providerYes
Trail MapperGPS traces, trail names, waypoints, the surveying staff accountYesYes
WebsiteSign-up form fields; aggregate QR scan counts; (planned) checkout via the payment processorYesNo
Internal provisioning toolUnit serials, configuration, encrypted key backups, flash historyYesNo
Park-facing flasher (planned)The same, for that park's units, behind park-admin authYesYes, for its own units
Public API / integrationsWhatever the issuing account's park scope allowsYesPark's choice
Black-box channelAlert-path recordsYes, internal onlyNo — never
Pilot telemetryDevice, radio and app-event diagnostics; no names, no message textYes, internal onlyNo
Event check-in (CVD)Name, email, phone, photo ID, face photo, signatureNot stored — emailed and discardedEvent staff named on the form

Appendix B — Subprocessors and service providers

Current at the effective date. We update this list when it changes; a current copy is always available at [email protected].

ProviderFunctionData it can seeLocation
DigitalOceanCloud hosting for the rider service, broker, dashboard and websiteAnything stored or transiting the serviceUnited States
CloudflareDNS, TLS termination, tunnels, and (where enabled) bot protection on the sign-up formConnection metadata, IP address, request data in transitGlobal edge
ForwardEmailTransactional email relay, including event paperwork deliveryMessage contents we send through itUnited States / EU
AppleApp distribution, TestFlight, push and platform services; on-device speech services on some devicesDistribution and platform telemetry under Apple's own policyGlobal
GoogleApp distribution via Google Play; platform servicesDistribution telemetry under Google's own policyGlobal
Anthropic / OpenAI / Google (whichever a deployment configures)Park Assistant language modelThe staff question and the in-scope park data needed to answer it. No training on itUnited States
CARTO (basemap tiles)Dashboard and app map backgroundsRequesting IP and which tiles were requestedGlobal CDN
Esri / ArcGIS (alternate basemap)Satellite basemap optionThe sameGlobal CDN
OpenStreetMap contributorsMap data attribution for the aboveNone directlyn/a
Stripe (planned)Payment processing for website checkoutYour payment details, collected by Stripe directlyUnited States

Where a park self-hosts the dashboard, that park — not this list — determines who else touches its data.


Appendix C — Retention schedule

RecordKept forNotes
Live rider state (in memory)Until you go quiet, then evicted; a hard ceiling of 6 hours appliesWorking memory for the map
"Currently offline" presence markers on the brokerCleared after 7 daysPrevents stale presence lingering forever
Rider session token30 days, sliding — an active session does not expireRevoked immediately on log out
Operator dashboard session12 hoursShorter on purpose
Position history and heat mapsPer park, where enabled, for that park's operational and trail-mapping needsAsk your park for its retention period
Messages (office, broadcast, group)While the park needs them for its records
Incident and SOS reportsVisible to riders for 3 days, then expired; retained by the park for its records
Meetup pinsUntil they expire or you delete them
Friends listUntil you remove the friend or delete your account
Account recordWhile the account exists; deleted or anonymised within 30 days of a verified deletion requestMinus what law or a park's incident records require
Pilot telemetryThe duration of the pilot program, then deleted or anonymisedOpt-out in Settings
Black-box records on your phonePurged automatically after the configured retention windowNever displayed, never shared with a park
Black-box records on our serversAs long as needed to investigate and defend claims from an incidentInternal only
Fleet/provisioning registryFor the service life of the unitEquipment data
Event check-in paperworkNot retained in the capture path; the resulting email is kept as an event recordSection 11
Support correspondenceUp to 3 years from the last message
Server and security logsUp to 90 days, longer only where an incident is under investigation
BackupsRoll off on their own scheduleA deletion propagates as backups cycle

HeadzUp is a rider-awareness product. It does not prevent collisions and it is not a safety system. Ride aware, ride together.