TowWithin Privacy Policy
The short version
TowWithin does most of its work on your device. Your saved vehicle and trailer setups never leave your phone. We do not ask for your name, email, address, or account.
We do collect some data, and we want to be specific about it: the app shows ads (which use an
advertising identifier), processes purchases, and looks up vehicle specifications from our
server. Details below. This policy applies to the TowWithin Android app
(com.quasslabs.towwithin), not to QuassLabs' website or other products.
What we collect, and why
1. Advertising data — collected by Google AdMob
The free version of TowWithin displays ads served by Google AdMob. To do that, the Google Mobile Ads SDK collects:
- your device's Advertising ID (a resettable identifier, not a hardware ID)
- device and app information (model, OS version, app version, coarse locale)
- IP address
- ad interaction events (impressions, clicks)
This is used to serve and measure ads, including personalized ads where you have consented and where local law allows. Google acts as an independent controller of this data, not merely our processor. Google's handling is governed by their own policies: Advertising and Privacy Policy.
You can limit this. Android lets you reset or delete your Advertising ID in Settings → Privacy → Ads. Purchasing the premium unlock removes ads entirely, after which the ad SDK no longer requests them.
2. Purchase data — processed by RevenueCat
If you buy the premium unlock or redeem a promotional code, we use RevenueCat to validate and manage that entitlement. RevenueCat receives:
- a randomly generated anonymous app user ID (created by the SDK; not linked to your name, email, or Google account by us)
- purchase and entitlement records (what was bought, when, whether it is active)
- device and platform metadata
We never receive or store your payment card details. Payment is handled entirely by Google Play. RevenueCat acts as our service provider under our instructions. See RevenueCat's privacy policy.
3. Vehicle lookups — our own server
When you search for a vehicle, the app queries our API (AWS, US East region). That request includes the search terms and, in standard web server logs, your IP address. Access logs are retained 14 days and are used for debugging, abuse prevention, and service reliability.
If a vehicle is missing from our dataset, the app may record the make, model, and year you searched for so we can add it. That record contains no identifier for you.
4. Promotional code redemption
If you redeem a promo code, we store the code and the anonymous RevenueCat app user ID that redeemed it, plus a timestamp. This is how we prevent one code from being used more times than the business that bought it paid for.
To limit brute-force guessing of codes, we temporarily store salted hashes of the anonymous user ID and the source IP address with failure counters. These records expire automatically within 24 hours. We do not store raw IP addresses in this system.
5. Install links (QR codes)
Scanning a TowWithin QR code sends you through get.quasslabs.com, which redirects
to the correct app store. Those requests are logged with IP address, user agent, and any
campaign tag in the link. Retained 90 days, used to understand which partners
and locations drive installs.
6. Camera — VIN scanning
If you use VIN scanning, the app requests camera access. Images are processed on your device and are not uploaded to us or to any third party. We do not store photographs.
7. What stays on your device only
- saved vehicle and trailer setups
- calculation history and results
- app preferences and the free-tier usage counters
These live in a local database on your phone and are never transmitted to us. Uninstalling the app, or using Settings → Clear All Data, deletes them. We cannot recover them for you.
What we do not collect
We do not collect your name, email address, phone number, postal address, precise location, contacts, photos, messages, calendar, health data, financial account details, or biometric data. We do not sell personal information. We do not knowingly collect data from children under 13.
Legal bases (EEA and UK users)
Where GDPR applies: vehicle lookups, purchase validation, and abuse prevention rest on legitimate interests and, for purchases, performance of a contract. Personalized advertising rests on consent, gathered through the Google UMP consent prompt shown on first launch where required.
Your choices and rights
- Reset or delete your Advertising ID — Android Settings → Privacy → Ads.
- Remove ads entirely — purchase the premium unlock.
- Delete local data — use Settings → Clear All Data in the app, uninstall the app, or clear app storage. Step-by-step instructions are on the data deletion page.
- Request deletion of server-side data — email us at the address below. We will delete associated promotional and diagnostic records. Our records are keyed to a random anonymous identifier rather than to you personally, so please tell us the approximate date and any promotional code you redeemed, and we will locate and delete what we can. Records we cannot link to you are already effectively anonymous.
- Access, correction, and portability — available on request where applicable law provides them.
- Advertising — the free version uses Google AdMob for personalized advertising. Depending on where you live, this may be treated as "sharing" for cross-context behavioural advertising. You can limit it by resetting or deleting your Advertising ID in Android settings, by declining personalized ads in the consent prompt where one is shown, or by purchasing the premium unlock, which removes ads entirely.
Requests are answered within the period required by applicable law (45 days under CCPA, 30 days under GDPR).
Retention
| Data | Retained |
|---|---|
| API access logs (IP, path) | 14 days |
| Install-link (QR) logs | 90 days |
| Promo redemption records | Life of the code, then archived for accounting |
| Promo abuse counters | 24 hours maximum (auto-expiring) |
| Purchase and entitlement records (RevenueCat) | Life of the entitlement — lifetime unlocks persist |
| On-device data | Until you delete it or delete the app |
Third parties who receive data
| Party | What they get | Role |
|---|---|---|
| Google AdMob | Advertising ID, device info, IP, ad events | Independent controller |
| Google Play | Purchase transactions | Independent controller |
| RevenueCat | Anonymous app user ID, entitlement records | Our processor |
| Amazon Web Services | Hosting for our API and logs (US East) | Our processor |
Security
Traffic between the app and our servers uses HTTPS/TLS. Server data is stored in AWS with access restricted to credentialed maintainers. No system is perfectly secure, and we cannot guarantee absolute security.
Children
TowWithin is intended for licensed drivers and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us data, contact us and we will delete it.
Changes
Material changes will be reflected here with a new effective date, and — where the change expands what we collect — surfaced in the app before it takes effect.
Contact
QuassLabs, Inc.
Email: taylor@quass.org
Postal address: 27 N 340 W, Orem, UT 84057-6627, USA