English (TraceHero · Google Maps) | 中文版(寻踪侠 · 高德地图)
TraceHero Privacy Policy
Welcome to TraceHero (the “App”). The App is operated by Nanjing Ruichuangte Information Technology Co., Ltd. (“we”, “us”, or “our”).
We take your privacy seriously. This Privacy Policy explains how we process information to provide TraceHero features. Core business data in the App—such as device locations, track history, geofences, profiles, and device bindings—is processed on your device. We do not upload that business data to our own servers. No account registration is required to use the App.
Please read this policy carefully before using the App. By using the App, you acknowledge that you have read and understood this Privacy Policy.
1. Information We Collect and How We Use It
We follow a minimum-necessary approach and request system permissions only when needed for App features. Data handled directly by our App logic is processed primarily on your device.
1.1 Information Processed Directly by the App
For App functionality, we may process the following information locally on your device:
-
Location information
- Your GPS location (to show “My Location” on the map and calculate distance and direction to tracked devices)
- Location coordinates (latitude/longitude) received from Bluetooth broadcasts of trackers, mobile relays, beacons, and other RCT hardware
-
Device and UI information
- Platform type (iOS/Android) and OS version
- Status bar height and screen size (for layout adaptation)
-
Sensor information
- Device heading (compass direction, 0–360°) to orient the “My Location” marker on the map
- Sensor capabilities reported by the system (e.g. GPS, accelerometer) for location, map, and Bluetooth features only—not for advertising or profiling
-
Bluetooth device information
- Scanned BLE device names, device IDs, and signal strength (RSSI)
- Location and other data in device broadcasts (for map display, alerts, and parsing)
- Data sent over Bluetooth when configuring devices or performing over-the-air (OTA) firmware updates
- On supported helmet/card devices: device identifiers such as IMEI read over Bluetooth for display and configuration (not uploaded to our servers)
-
Helmet Wi‑Fi configuration (when you use that feature)
- Wi‑Fi SSID and password you enter, or read from a connected device over Bluetooth, to send configuration to the device
- Used only for Bluetooth parameter transfer; we do not upload Wi‑Fi credentials to our servers. Avoid configuring sensitive networks on untrusted devices
-
Camera and QR scanning
- When you use “Scan to bind device”, the camera reads a device QR code; the parsed device ID is used locally for binding. We do not upload scan images or photo library content
-
Information you voluntarily enter in profiles
- In Profile Management you may enter names, notes, emergency contacts, phone numbers, and other optional fields for livestock, team members, or tour participants
- This content is stored only in the on-device database for map and list display
-
Locally stored data (on device only)
- SQLite database
rct_app.db: track history, geofences, alerts, device aliases, scene settings, profiles and bindings, missions, OTA records, and related data - App settings: privacy consent status, data retention days, permission guidance records, etc.
- OTA firmware cache (downloaded to the device only when you use network-based OTA)
- Import/export backup files (created or restored by you)
- SQLite database
Note: Third-party SDKs (especially Google Maps Platform) may process device identifiers, location, and network information on the device or with their service providers, as described in Section 1.5. That is separate from us collecting and storing your business data.
1.1.1 Network features (device OTA)
The App is local-first by default. When you open Device OTA or related network features, the App may contact location.rctiot.com, for example:
GET /v1/user/getDevOtaMapFileList?devtype=…— firmware list for a device typeGET /v1/user/getDevOtaLatestMapFileList— latest firmware map (Bluetooth page)GET /v1/ota/{filename}— firmware package download
Requests mainly include device-type and firmware metadata needed for upgrades. They do not include your tracks, geofences, profiles, or other business data. Device IDs shown on the OTA screen are used locally for Bluetooth transfer and local OTA logs; they are not uploaded to the firmware server. Downloaded firmware is stored on the device and transferred to hardware over Bluetooth.
1.1.2 DCloud uni-app framework
The App is built with DCloud uni-app (5+ App).
Current build configuration:
- uni Statistics (
uniStatistics) is disabled—we do not use it for analytics - IDFA is disabled; we do not show the iOS “Allow App to Track” prompt for advertising
Framework components may still be used for runtime and UI rendering. For DCloud’s general compliance information, see https://dcloud.io/license/appprivacy.html
1.1.3 uni-app runtime components
The packaged App may include default framework components (e.g. for nvue rendering and images), such as:
- Weex engine — nvue page rendering
- Fresco / Glide — image loading
- fastjson — JSON parsing
These support UI and basic capabilities. We do not use them for ad tracking, and we do not upload your business data to our servers through them.
1.2 System permissions and purposes
To provide core features, the App and integrated map services may request the permissions below. Prompts generally appear when you first use the related feature.
When permissions are requested (summary):
- Location — first use of map or positioning
- Network — loading online maps, opening policy pages, or when you use device OTA
- Bluetooth — first scan or connection to a device
- Camera — first use of scan-to-bind
- Orientation sensor — map heading display
- System settings, Wi‑Fi state (Android only) — network and location environment
- Foreground service (Android only) — stable Bluetooth connection during OTA and similar tasks
Note: Our Android manifest explicitly excludes several sensitive permissions
(e.g. contacts, phone calls, microphone, READ_PHONE_STATE, broad external storage
read/write). Merged dependencies may still declare additional permissions; refer to your
device’s Settings → Apps → TraceHero → Permissions for the installed build.
Location (GPS)
- Purpose: Show your position on the map, compute distance/direction to devices; when enabled, refresh “My Location” about every 3 minutes in the background of active use
- Processing: “My Location” is used for display and map math; we do not upload it as standalone business data. Bluetooth device locations may be stored locally for history (Section 1.4)
- If denied: The map cannot show your position; core tracking features are severely limited
Network (Internet)
- Purpose: Load Google Maps tiles and services; access the OTA firmware server when you use OTA; open our website and this policy from About
- Processing: Used for map/firmware services and displaying policy pages. We do not store your IP address on our servers for these requests
- If denied: Online maps and network OTA will not work; local Bluetooth and stored data features may still work
Bluetooth (scan and connect)
- Purpose: Scan RCT hardware (relays, badge/helmet trackers, beacons); receive broadcast data; configure devices and perform OTA over BLE
- Processing: Parsed locally for maps and alerts; location-related data stored per Section 1.4. Scan results are not uploaded to our servers
- If denied: Scanning and connection are unavailable; most App features cannot be used
Camera (QR codes)
- Purpose: Read device QR codes to bind devices to profiles
- Processing: Device ID parsed locally; images are not uploaded
- If denied: Scan binding is unavailable; manual device ID entry still works
Orientation sensor
- Purpose: Compass heading for the “My Location” marker
- Processing: Real-time local use only; not persisted or uploaded
- If denied: Heading is not shown; other features remain usable
Write system settings (Android only)
- Purpose: Adjust system settings related to App operation when needed for location/Bluetooth stability
- If denied: Some edge cases may be less stable; core features usually remain available
Wi‑Fi state (Android only)
- Purpose: Detect network connectivity to assist map loading
- Processing: Connectivity checks only; Wi‑Fi passwords are not collected
Storage permissions
Our Android main configuration excludes broad external storage read/write. OTA firmware, the SQLite database, and backups are stored in app-specific directories. If your installed package still lists storage-related permissions, they may come from merged libraries; we do not use them to read unrelated photos or videos.
Camera vs. photo library
Device binding uses the camera for QR scanning only (uni.scanCode). We do not
access your photo library for this feature. Settings may label “Camera/Album” for clarity on
some devices; album access is not required for core binding flows.
Background location and notifications (if present in your build)
Map or system components may declare background location or notification permissions. Our product focus is foreground map use and Bluetooth scanning. Background location may occur only when you use related features and the OS allows it. You can revoke permissions in system settings.
1.3 System information
For UI layout we read platform (iOS/Android), OS version, status bar height, and screen size. This is not uploaded to our servers.
1.4 Local storage
Business data is stored primarily in SQLite at _doc/rct_app.db. Upgrades from
older versions may have migrated legacy keys (e.g. histrackdata,
saved_fences_list) into the database once.
| Data type | Storage | Purpose | Retention |
|---|---|---|---|
| Track history | device_track_points |
History screen | Auto-deleted per Storage settings (default 3 days; options 1/3/7/14 days) |
| Geofences | geo_fences |
Geofence configuration | Until you delete or uninstall |
| Alerts (geofence, offline, etc.) | alert_records |
Alert list | Expired records cleaned per retention policy |
| Device aliases | device_aliases |
Custom display names | Until uninstall |
| Profiles and bindings | object_profiles, device_bindings |
Profiles and device links | Until you delete or uninstall |
| Scenes and alert settings | scenes, app_settings |
Scene mode, retention, privacy consent, etc. | Until uninstall |
| Missions / activities | missions |
Hiking or tour group activities | Until you delete or uninstall |
| Last seen (device status) | device_last_seen |
Last location, battery, RSSI | Cleaned per retention policy |
| OTA records | ota_records |
Upgrade history and status | Until you delete or uninstall |
| Device config summary | device_config_summary |
Bluetooth configuration summary (when used) | Until you delete or uninstall |
| Permission guidance | app_settings, _permissionStatus, etc. |
Avoid repeated permission prompts | Until uninstall |
| Backup files | JSON you export or save via share | Backup and restore (all 12 business tables) | Managed by you |
Online maps: The current version uses Google Maps Platform for online map tiles. There is no in-app offline map pack download (unlike legacy Amap-based builds). Without network access, map tiles may not load; local Bluetooth and stored data features may still work.
All business data above stays on your device. We do not read or upload it to our servers. Uninstalling the App removes data in the app directories.
1.5 Third-party SDKs
The App integrates third-party SDKs for maps, firmware transfer, and framework/runtime support. They may process data under their own policies.
| SDK | Provider | Types of information | Purpose | Privacy policy |
|---|---|---|---|---|
| Google Maps Platform | Google LLC | Location; device and network information (model, OS, IP, connectivity—see Google’s policy) | Map display, tiles, positioning | Google Privacy Policy Maps Terms |
| Nordic DFU | Nordic Semiconductor (via embedded library) | Bluetooth connection data during Secure DFU | BLE firmware upgrade to supported devices | nordicsemi.com (library terms apply to the embedded component) |
| DCloud uni-app runtime | DCloud | Device and runtime information as needed for the framework | App runtime and UI | DCloud App Privacy |
Notes specific to this App:
- iOS builds disable IDFA;
NSUserTrackingUsageDescriptionis not used for cross-app ad tracking - Android main configuration excludes
READ_PHONE_STATEand similar sensitive permissions - Google Maps requests may be processed on Google’s infrastructure, which may involve cross-border data transfer depending on your region. See Google’s policies for details
- System share sheets (export backup) let you send files to apps you choose; we do not control those destinations
2. Storage and Security
Runtime data: Live map display and Bluetooth parsing are handled mainly in memory while the App runs.
Persistent data: See Section 1.4; stored in SQLite or app-specific folders on device.
Security measures:
- Local data resides in app-protected storage
- OTA and policy pages are accessed over HTTPS where supported
- We do not maintain a cloud copy of your business data on our servers
No security measure can guarantee absolute protection.
3. Sharing, Transfer, and Disclosure
We do not sell or share your local business data (tracks, geofences, alerts, profiles, etc.) with third parties for their marketing.
Exceptions include:
- Third-party SDKs processing data as needed for their services (e.g. Google map tile requests)
- Import/export or system share when you choose where to save or send backup files
- OTA when you request firmware by device type from our firmware host (no business data upload)
- Legal requirements or valid requests from authorities
4. Your Rights and Choices
- Access: View tracks in History, geofences and alerts in their screens, and profiles in Profile Management
- Correction: Edit geofences, device display names, and profile fields in the App
-
Deletion:
- Delete individual geofences in the geofence screen
- Track history and some alerts: automatic cleanup by retention days, or manual cleanup in Storage
- Profiles and bindings: delete in the relevant screens
- All local data: uninstall the App
- Backup and restore: Use Import/Export to export or restore on-device data; you are responsible for backup files you create
- Withdraw consent: Revoke location, Bluetooth, camera, etc. in system settings (Android: Settings → Apps → TraceHero → Permissions; iOS: Settings → Privacy & Security → Location Services / Bluetooth / Camera → TraceHero)
- Account deletion: There is no account system; uninstalling the App stops use and removes local business data from app storage
5. Sensitive and Voluntary Information
You may optionally enter emergency contacts, phone numbers, blood type, or similar fields in profiles. This is voluntary and stored locally. Exported backups include these fields if present. Please store backups securely and avoid entering information you do not wish to keep on device or in backup files.
6. Children
We do not knowingly target children. If you are a minor, use the App only with a parent or guardian’s consent and supervision. If you believe we have processed a minor’s information without appropriate consent, contact us and we will address it as required by law.
7. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through in-app notice or announcements on our website. Continued use after an update means you accept the revised policy.
Online versions:
- English (Google Maps · Google Play): https://www.rctiot.com/app/privacy-en.html
- Chinese (Amap · domestic build): https://www.rctiot.com/app/privacy.html
8. Contact Us
If you have questions, comments, or requests regarding this policy, contact us:
- Email: support@ruichuangte.com
- Website: www.rctiot.com
We aim to respond within 15 business days of receiving your message.