Muevono
Privacy Policy
This Privacy Policy explains how the Muevono mobile application
("Muevono", "we", "us", "our") collects, uses, stores, and shares
information when you use our iOS and Android apps and the related
backend services at muevono.com.
Muevono is operated by Chris Hutton, a sole trader based in the United Kingdom, trading as Muevono. You can contact us at huttswickandallenby@outlook.com for any privacy-related questions or requests.
1. Summary
- You sign in with Google, Apple, or Spotify — or continue as a guest. Depending on the provider we receive an account identifier and, where available, your name and email; from Spotify we also receive your display name and profile image.
- We use your device location, only while the app is open, to surface music history nearby and to award badges when you visit specific places on a trail.
- We record anonymised analytics (search and view events with coarse coordinates) to improve the app.
- We do not sell your personal data, and we do not use third-party advertising or tracking SDKs.
- You can request access to or deletion of your data at any time by emailing us.
2. Information We Collect
2.1 Account information (sign-in)
You can sign in with Google, Apple, or Spotify, or continue as a guest. We create a Muevono account identified by an internal ID, and depending on how you sign in we receive:
- Google: your Google account ID and email address (from a Google ID token we verify).
- Apple: your Apple account ID and, on first sign-in, your email (which may be a private-relay address) and name. Apple only shares your name once, at the first authorisation.
- Spotify: your Spotify user ID, display name, email, and profile image URLs.
- Guest: no personal identifier — a random, device-stored token represents you until you sign in.
When you sign in with Google or Apple, our backend issues a short-lived Muevono session token that identifies you to our API. If you sign in with Spotify (or later link Spotify to your Google/Apple account), we also receive OAuth access and refresh tokens which let the app play music through Spotify's player and create or modify playlists you authorise. These tokens are stored on your device in the iOS Keychain or Android Keystore (encrypted by the operating system); we do not persist your Spotify tokens on our servers.
The Spotify scopes we request are: user-read-email,
user-read-private, streaming,
app-remote-control,
playlist-modify-public, playlist-modify-private,
user-read-playback-state, and
user-modify-playback-state.
2.2 Location data
With your permission, the app accesses your device's precise location (GPS) only while the app is in use. We do not access location in the background. We use location to:
- Centre the map on your area and surface music history nearby.
- Detect when you reach a waypoint on a trail (geofence) so that audio narration plays and digital badges can be awarded.
- Confirm presence at partner shops or venues when redeeming physical pin badges.
When location is sent to our analytics store, coordinates are rounded to four decimal places (approximately 11 metres) and not joined to your user ID. Your real-time precise location is processed on your device and is not stored long-term on our servers.
2.3 Trail and badge activity
To make the app work, we store the trails you have started or completed, the waypoints you have reached, and the digital and physical badges you have claimed. This information is associated with your Muevono user account.
2.4 Purchase information
If you buy a trail, city pack, or subscription through the app, Apple (App Store) or Google (Play Store) processes the payment. We never see your card details. We receive a transaction receipt from Apple or Google which we validate server-side; we then store the transaction ID, product purchased, and purchase date so that we can unlock the relevant content for your account and handle refunds and restores.
2.5 Analytics events
We log non-identifying usage events such as searches, area views and item views with rounded coordinates and aggregate counts. These events are not linked to your user ID. We do not use Firebase, Google Analytics, Sentry, Mixpanel, or any other third-party analytics or advertising SDK.
2.6 Push notifications
With your permission, we may send push notifications about trails, festivals, and your account (for example, when a badge becomes available). These are delivered through Firebase Cloud Messaging (Google). You can turn notifications off at any time in your device settings.
2.7 Device permissions and information we do not collect
Muevono does not request access to your camera, microphone, contacts, photos, calendar, or health data. We do not use the iOS IDFA or the Android Advertising ID, and we do not use any third-party advertising or tracking SDKs.
3. How We Use Your Information
- To authenticate you and keep you signed in.
- To play music through Spotify and create playlists you ask us to create.
- To show you music history, venues, studios, and gigs near your location.
- To trigger trail narration and award badges when you reach a waypoint.
- To validate purchases and unlock content you have bought.
- To improve the app through anonymised, aggregated analytics.
- To detect, prevent, and respond to fraud, abuse, or security incidents.
- To comply with our legal obligations.
3.1 Legal bases (UK-GDPR and EU-GDPR)
- Contract — to provide the app, its core features and any purchases you make.
- Legitimate interests — to keep the service secure, prevent fraud, and improve the product through anonymised analytics.
- Consent — for access to your device location, which you can grant or revoke at any time in your operating system settings.
- Legal obligation — to retain financial records of purchases for the period required by tax law.
4. Sharing and Third Parties
We share information only with the service providers we need to operate the app. We do not sell your personal data and we do not share it with advertisers.
| Provider | Information shared | Purpose | Privacy policy |
|---|---|---|---|
| Spotify AB | OAuth tokens, profile data you authorised, playback commands, playlists you create | Authentication and music playback | spotify.com |
| Apple Inc. (Sign in with Apple, App Store / In-App Purchase) | Sign-in verification, account identifier + email; purchase receipts | Authentication and receipt validation / refunds (iOS) | apple.com |
| Google LLC (Google sign-in, Play Billing, Firebase Cloud Messaging) | Sign-in verification, account identifier + email; purchase receipts; device push token | Authentication, receipt validation / refunds (Android), and push notifications | policies.google.com |
| Mapbox, Inc. | Map viewport coordinates and zoom level | Rendering the in-app map | mapbox.com |
| Ticketmaster (Live Nation) | Search-area coordinates only (no user identifiers) | Looking up gigs near a location | ticketmaster.co.uk |
| MetaBrainz Foundation (MusicBrainz) | Anonymous read-only queries | Looking up bands, releases, and venues | metabrainz.org |
| OpenStreetMap Foundation (Nominatim) | Anonymous geocoding queries | Converting place names to coordinates | osmfoundation.org |
| Wikimedia Foundation (Wikidata, Wikimedia Commons) | Anonymous read-only queries | Enriching artist, venue, and image data | wikimedia.org |
| Render Services, Inc. | All backend data (hosting) | Hosting our backend, database, and cache | render.com |
Anthropic (Claude) and OpenAI (text-to-speech) are used by our internal admin team to generate trail content and narration before publication. End-user data is not sent to these providers.
We may also disclose information when required by law, court order, or other legal process, or to protect the rights, property, or safety of Muevono, our users, or others.
5. Storage, Transfers, and Security
Backend data is stored in PostgreSQL and Redis instances operated by Render in the Frankfurt, Germany (EU) region, so your personal data is held within the European Economic Area. Some of our sub-processors (for example Spotify, Google, and Apple) may process limited data outside the EEA under their own appropriate safeguards, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.
All traffic between the app and our backend uses HTTPS. OAuth tokens on your device are stored in the iOS Keychain or the Android Keystore, both of which are encrypted by the operating system. Passwords for our backend admin tools are hashed with bcrypt; we never store plaintext passwords. We do not store payment card details — Apple and Google handle payment processing.
6. Data Retention
- Account data — kept while your account is active. When you delete your account we mark it as deleted and remove personally identifying fields within 30 days; aggregated, de-identified records may be retained for analytics.
- OAuth tokens — refreshed regularly; expired tokens are discarded.
- Trail and badge progress — kept for the lifetime of your account so you do not lose your history.
- Purchase records — retained for at least six years to meet UK tax and accounting obligations.
- Analytics events — retained for up to 24 months in aggregated form.
7. Your Rights
Depending on where you live, you have rights over your personal data. These include:
- The right to access a copy of the personal data we hold about you.
- The right to correct inaccurate or incomplete data.
- The right to deletion ("right to be forgotten").
- The right to restrict or object to certain processing.
- The right to data portability.
- The right to withdraw consent (for example by revoking location permission in your OS settings, or by signing out of Spotify).
- The right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO).
To exercise any of these rights, email huttswickandallenby@outlook.com. We will respond within 30 days.
Deleting your account. You can delete your account directly in the app at any time: go to Settings → Account → Delete account. This immediately removes your personally-identifying details (name, email, provider identifiers, and profile image) from your account record and marks the account as deleted; associated data is removed within 30 days, except records we must keep for legal reasons (such as purchase records for tax). You can also request deletion by email, or via muevono.com/account/delete. Note that purchases are tied to your App Store or Google Play account and can be restored on a new account, but badges and trail progress are permanently lost when an account is deleted.
7.1 Notice for California residents (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect, the right to delete it, the right to correct it, and the right to opt out of any "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under the CCPA, and we do not use the data we collect for cross-context behavioural advertising. To exercise your California rights, email us at huttswickandallenby@outlook.com.
8. Children
Muevono is not directed at children under 13, and we do not knowingly collect personal data from anyone under 13. Spotify's own Terms of Service require users to be at least 13 (and older in some jurisdictions). If you believe a child under 13 has provided us with personal information, please contact us and we will delete it.
9. Changes to This Policy
We may update this policy from time to time. When we make material changes we will update the "Last updated" date at the top of this page and, where appropriate, notify you in the app. Your continued use of Muevono after a change indicates your acceptance of the updated policy.
10. Contact
Chris Hutton (sole trader), trading as Muevono
United Kingdom
Email: huttswickandallenby@outlook.com