CropseyWorks LLC
Privacy Policy
Effective July 19, 2026. BikeSignal is an Android home-screen widget application that shows bike-share station availability for saved places and the phone's current location. This policy explains what is processed, where it comes from, and the choices available to you.
1. What BikeSignal processes
Data stored on your device
BikeSignal stores app settings and widget data in Android private storage. This can include saved addresses and coordinates, location nicknames, station selections, widget configuration, recent location fixes, entitlement state, and an app-generated random install identifier. It may also store a bounded queue of up to 300 analytics events and up to 50 recent supported bike-share notification records. Android cloud backup and device transfer are disabled for BikeSignal app storage.
If a Google Play subscription becomes inactive while synchronization is unavailable, Android may temporarily retain its purchase token in private app storage until the inactive state is synchronized successfully.
Location
BikeSignal uses foreground precise or approximate location for Current Location, nearby-station searches, live-location tracking, widget refreshes, and related diagnostics. Opt-in Updates While Moving runs as a foreground service and displays a persistent Android notification for Current Location and Automatic View Switching. Automatic widgets continue monitoring location while showing My Stations so BikeSignal can detect when you leave a saved area. Active location updates pause while the screen is off. BikeSignal does not request Android background-location permission.
Notification Access, location access, and Live Tracking are optional. Saved-station setup and widgets continue working without them. The configuration screen shows each disabled feature-access breaker until you opt in and moves enabled breakers to Advanced Configuration. Revoking location prevents or limits Current Location, nearby search, location-based refresh, and related behavior. Location coordinates may be included in widget, analytics, diagnostic, and ride-learning events sent to BikeSignal's backend while location access is enabled.
Data from supported bike-share notifications
When you grant Android Notification Access, BikeSignal examines notifications produced by supported third-party applications for recognized bike-share ride-start or ride-completion signals. Notifications from a shared general-purpose Lyft application must also contain positive bike-share evidence in their text or notification channel. Notifications without that evidence are discarded without being stored or uploaded. For a recognized ride notification, BikeSignal may retain the source application, notification key hash, channel, title, text, expanded text, subtext, text lines, posted and captured timestamps, lifecycle, parsed ride type and station, and parsing confidence. It may also attach the best available precise location.
Raw notification fields and captured ride information may be stored locally for ride learning and related product behavior. They are uploaded to BikeSignal's Cloudflare backend only while Analytics is enabled. You can use the Notification Access breaker to open Android settings and revoke access, which stops future notification access and ride learning while saved-station widgets continue working. Turning Analytics off stops future raw notification uploads and removes queued uploads, but does not delete data already sent or disable local ride learning.
App, widget, diagnostic, and support data
When Analytics is enabled, optional app and widget analytics may include saved addresses and nicknames, resolved coordinates, selected networks and stations, widget configuration, station names and availability counts, taps, searches, public-feed source and fallback information, refresh results, app/widget usage events, permission state, and backend status.
Optional device and app diagnostics can include manufacturer, brand, model, Android version, app version and code, install and update timestamps, installer or install source, entitlement state, permission state, and backend or error status. This information is used to monitor application performance, diagnose crashes and failures, and improve BikeSignal. BikeSignal uses an app-generated anonymous install identifier; Firebase may use Firebase installation or app-instance identifiers.
Operational backend requests needed for features such as subscription verification, entitlements, referrals, promos, abuse prevention, and service security are not controlled by the Analytics switch.
Feedback sent through the app includes your message, a contact email currently required by the form, diagnostics, and any image you choose to attach. The app converts an attached image to JPEG for upload; the backend accepts validated JPEG, PNG, or WebP image data.
Remote messages and push registration
To deliver enabled Public Safety & Emergency Alerts, Service Alerts, BikeSignal Updates, and Offers & Promotions, BikeSignal processes a Firebase Cloud Messaging registration token associated with the app-generated anonymous installation ID, platform, app version/environment, message preferences, token update time, and operational delivery/open/dismiss acknowledgments. The Service Alerts preference controls the first three categories together; Offers & Promotions is controlled separately. Optional engagement analytics follows the Analytics setting. Message bodies, codes, and QR payloads are not included in analytics. An FCM token is not Google's Advertising ID, and BikeSignal does not use Google's Advertising ID for advertising, analytics, messaging, attribution, or personalization.
Purchases
Google Play processes purchases and payment information. BikeSignal does not directly collect or store payment-card numbers or security codes. Subscription product and status information is processed for access control. The Android app sends a subscription purchase token to the BikeSignal Cloudflare Worker, which sends it to the Google Play Developer API for verification. The server stores a hash of the purchase token rather than the raw token.
Website and network data
The BikeSignal website is a static site and does not contain BikeSignal advertising or targeted-advertising code. The repository does not implement website accounts, shopping carts, or employment-data collection. When you visit the website or the app contacts online services, network providers including Cloudflare may process IP addresses, request metadata, and operational or security logs.
2. Why this data is used
BikeSignal processes data to provide and refresh widgets; find nearby stations; support live location and ride learning; diagnose failures; understand app and widget use; improve feeds and product behavior; manage subscriptions, entitlements, referrals, and promos; respond to feedback; prevent abuse; and operate and secure the service.
3. Who processes data
- BikeSignal / CropseyWorks LLC and Cloudflare: backend requests, analytics and ride-learning events, storage, entitlement status, referrals and promos, feedback, rate limiting, administrative tools, and operational data.
- Google / Firebase: Firebase Analytics, Crashlytics crash and diagnostic processing, Firebase Cloud Messaging transport and registration tokens, and associated installation/app-instance identifiers.
- Google Play: purchases, payment information, subscription processing, and purchase-token verification through the Google Play Developer API.
- Public bike-share feed operators: station-feed requests needed to obtain public availability data. Network providers may see normal request metadata such as IP address.
BikeSignal does not sell personal information. Advertising ID collection and Firebase ad-personalization signals are disabled. Advertising ID and AdServices identifier permissions are removed from the final merged Android manifest.
4. Retention and deletion
Local app data remains until removed by app behavior, clearing app storage, or uninstalling. The analytics queue is capped at 300 events and recent notification storage at 50 records.
BikeSignal's Cloudflare configuration sets a default 90-day retention period for raw analytics events and event-search indexes. Retention cleanup is operational and should not be understood as a guarantee that every other record is automatically deleted after 90 days. Derived rollups and entitlement, referral, promo, feedback, abuse-prevention, administrative, or operational records may remain longer according to their purpose. Firebase/Google and network-provider logs follow those providers' applicable settings and retention practices.
Remote-message registrations remain while active and are disabled after Firebase reports an invalid token; canonical test messages and acknowledgments require bounded operational cleanup. Reset/deletion requests include associated push-registration and acknowledgment records where they can be linked to the installation.
To request access to or deletion of data held by BikeSignal, email support@bikesignal.app. Because BikeSignal has no named user account and primarily associates records with an anonymous install ID, include the install ID or the diagnostic/install-ID prefix shown by the app, plus any contact email used for feedback. We may ask for enough information to locate the correct records and avoid deleting another installation's data. We may retain information when reasonably necessary for security, fraud prevention, legal obligations, or transaction and entitlement records. Revoking an Android permission does not delete previously uploaded data.
5. Security and international processing
BikeSignal uses HTTPS for reviewed app/backend communications, private Android app storage, bounded local queues, and access controls for administrative backend functions. No system can guarantee absolute security.
Cloudflare, Google, Firebase, public feed providers, and their subprocessors may process information in the United States and other countries where they operate. Those countries may have different data-protection laws from your location.
6. Your choices
Analytics is enabled by default. You can turn it off at any time under Permissions & Privacy to stop future Cloudflare app/widget analytics—including raw supported bike-share notification uploads—plus Firebase Analytics and Firebase Crashlytics collection. Turning Analytics off removes queued analytics but does not delete data already sent, disable operational backend requests, or stop local ride learning while Notification Access remains enabled.
You choose whether to grant Android permissions and special access. Refusing or revoking Notification Access, location, or Live Tracking limits only the related features described above; saved-station setup and widgets continue working. Feedback, image attachment, and purchases are optional.
Each remote-message category can be turned off installation-wide under Permissions & Privacy. Android separately controls phone notification permission and notification channels. Denying phone notifications does not enable a workaround; an enabled category may still appear on an eligible widget when the message explicitly permits widget presentation.
7. Children's privacy
BikeSignal is not directed to children under 13, and CropseyWorks LLC does not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us so we can review and delete it where appropriate.
8. Changes and contact
We may update this policy as BikeSignal changes. Material changes will be reflected by a new effective date and, when appropriate, an additional notice.
BikeSignal is operated by CropseyWorks LLC. For privacy questions, access or deletion requests, or support, email support@bikesignal.app.