Saddle Sense Privacy Policy
Data controller: VIRIDIAN LABS LTD, a company registered in England and Wales under company number 16619547.
Registered office: West Goods Entrance, Somerset House, Victoria Embankment, London WC2R 1LA, United Kingdom.
Contact: privacy@saddlesense.co
1. What This Policy Covers
This policy explains how Viridian Labs Ltd (“we”, “us”, “Viridian Labs”) collects, uses, stores, and shares your personal data when you use Saddle Sense, our air quality sensing app and platform. This includes the app, any Saddle Sense sensor, the pollution maps, and related services (together, the “Service”).
It applies to all users of the Service. You can use the Service with a Saddle Sense sensor or, where available, by subscription without a sensor, and this policy covers both. It also applies to participants in council-sponsored pilot programmes.
2. Data We Collect
2.1 Data You Provide
- Account information: name, email address, and password when you create an account.
- Profile information: any optional details you add, such as your borough, preferred cycling routes, or groups you are affiliated with.
2.2 Data Collected Automatically by the Sensor and App
What we collect automatically depends on how you use the Service.
When you ride with a Saddle Sense sensor connected, we collect:
- Location data: GPS coordinates and timestamps when you are measuring air quality or navigating. This is used to pair air quality readings with road segments, and to record your trips so you can track your exposure.
- Air quality measurements: real-time readings of PM1, PM2.5, and PM10 concentrations from your sensor.
- Atmospheric data: temperature, relative humidity, and atmospheric pressure.
- Ride metadata: start time, end time, duration, and distance.
- Device and app data: app version, device type, operating system, Bluetooth connection status, your sensor’s firmware version, and identifiers for your app installation and for your sensor. We use these for troubleshooting, compatibility, analytics, and to calibrate individual sensors.
If you use the Service without a sensor (for example, for route suggestions and the map), we collect your location and trip data to provide routing and to build your personal ride history and exposure estimates. We do not collect air quality or atmospheric measurements in this case, because there is no sensor, so you do not contribute air quality readings to the pollution map. We may also use your route and usage data in anonymised, aggregated form for analytics and reporting, as described in Section 3.4.
2.3 Data We Do Not Collect
We do not collect GPS data when your sensor is not connected and you are not navigating. We do not collect your contacts, photos, messages, or browsing history, or any data from other apps on your phone. We do not use your microphone or camera.
3. How We Use Your Data
We use your data for the purposes below. The table summarises the legal basis for each, and full details follow.
| Purpose | Section | Legal basis |
|---|---|---|
| Providing the Service (ride history, routing, sensor connection, calibration) | 3.1 | Contract |
| Building and improving pollution maps | 3.2 | Contract |
| Supporting council programmes (pollution maps and impact reporting) | 3.3 | Not applicable (anonymised data only) |
| Improving the Service, and producing anonymised usage and impact statistics | 3.4 | Legitimate interest |
| Essential service communications | 3.5 | Contract |
| Optional communications (ride summaries, product updates) | 3.5 | Consent |
3.1 To Provide the Service to You (Contractual Basis)
- Displaying your ride history, routes, and personal exposure summaries in the app.
- Providing pollution-aware route suggestions.
- Connecting your app to your sensor and ensuring it functions correctly.
- Monitoring sensor calibration accuracy to ensure data quality across the network.
- Comparing the pollution we predicted for routes against the readings actually observed, so that our routing and exposure estimates stay accurate and we can show you the exposure you have avoided.
3.2 To Build and Improve Our Pollution Maps (Contractual Basis)
Saddle Sense is a crowdsourced pollution mapping platform. If you use a Saddle Sense sensor, contributing your sensor data, which we anonymise and aggregate into our collective pollution map, is a core function of the Service. It is what makes real-time pollution maps, cleaner route suggestions, and exposure insights possible for all users. By using the Service with a sensor, you agree to this contribution as part of your contract with us.
Your air quality readings and location data are anonymised and aggregated with data from other users and sources to create real-time, street-level pollution maps.
“Anonymised” means we remove the link to your identity. “Aggregated” means individual readings are combined with others to produce modelled pollution estimates for road segments, not records of individual trips.
The process works by mapping GPS readings to road segments and combining them with data from other riders, reference monitoring stations, and modelling. Obscuring individual journeys is a deliberate part of how we build the maps: the published maps do not contain individual trip routes, and the anonymisation is built to prevent any specific user’s journey from being identified or reconstructed from the published data.
If you do not wish to contribute data to the pollution maps, you may stop using the sensor and request deletion of your personal data (see Section 8). Anonymised data that has already been incorporated into aggregated maps cannot be removed, as it is no longer personal data.
3.3 To Support Council Air Quality Programmes
If you participate in a council-sponsored pilot programme (for example, the London Borough of Barnet pilot), the anonymised, aggregated pollution maps described in Section 3.2 are shared with the sponsoring council for air quality reporting, transport planning, public health analysis, and identifying pollution sources and hotspots.
We also share anonymised, aggregated statistics about how the Service is used in the area, such as route and demand patterns and the exposure reductions achieved through our routing, so the council can see the impact of the programme it funds.
This is anonymised, aggregated data: road-segment-level pollution estimates, coverage and usage statistics, and trend analysis. We do not share your personal data, trip history, or identity with any council.
3.4 To Improve the Service (Legitimate Interest)
- Analysing usage patterns to improve the app and data quality.
- Developing new features based on aggregated usage trends.
- Producing anonymised, aggregated statistics about how the Service is used and the exposure reductions it achieves, for analytics, research, and to measure and demonstrate the impact and value of the Service, including to partners such as councils and mobility companies, and in public communications.
3.5 To Communicate With You (Consent or Contractual)
- Sending you essential service communications (for example, sensor firmware updates and account security).
- With your consent, sending you optional communications such as ride summaries, air quality insights, or product updates. You can opt out at any time.
4. How We Anonymise and Aggregate Your Data
This section explains the process in more detail, because we know location data is sensitive and we want to be transparent about how we handle it.
Step 1: Map to road segments. Your raw GPS coordinates are mapped onto the nearest road segment in our network. We do not store or publish raw GPS coordinates in any shared dataset.
Step 2: Combine with other readings. Your reading for a road segment is combined with readings from other users, with data from reference monitoring stations, and with road features to estimate pollution levels. No single user’s reading is individually visible in the output.
Step 3: Publish as modelled estimates. The resulting map shows estimated pollution levels per road segment, not individual contributions. Because each segment shows a modelled estimate blended from many readings and sources, you cannot tell from the map which readings came from any individual user. The more users contribute on a given segment, the more accurate the estimate.
Step 4: Near-real-time updates. Recent readings may be reflected in the map shortly after they are recorded, so that other users can avoid pollution hotspots. The same process applies: readings are mapped to road segments and blended with modelling and other sources. A near-real-time update to a segment estimate is not intended to reveal which user contributed a reading, their route, or when they passed through.
In any dataset we keep beyond the short-term personal data described in Section 7, or share outside Viridian Labs, we apply the same protections: no user or trip identifiers and no raw GPS coordinates; location resolved to road segments or area cells rather than precise points; readings grouped into time buckets rather than exact timestamps; and a segment or cell retained or shared only once it combines readings from a minimum number of contributors. The map you see shows modelled estimates blended from many sources, not any individual’s raw readings. This is what we mean by anonymised.
Your personal data (trip history, exposure summaries, routes) is stored separately and is never included in the anonymised or aggregated dataset. See Section 5 for how we protect it.
5. How We Store and Protect Your Data
- All data is stored on Google Cloud Platform servers located in the United Kingdom or the European Economic Area.
- Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
- Access to personal data is restricted to authorised Viridian Labs personnel on a need-to-know basis.
- We review our security practices regularly and keep them under ongoing review as the Service grows.
6. Who We Share Your Data With
Anything we make available outside Viridian Labs, to councils, commercial customers, or the public, is anonymised, aggregated data, never your personal data. We share personal data only with the processors who run the Service for us, under data processing agreements, and in the limited legal and business-transfer situations described in Section 6.2.
6.1 Anonymised and Aggregated Data (Not Personal Data)
We make our anonymised, aggregated pollution maps available to:
- Council and government partners: for air quality action planning, transport policy, public health analysis, identifying pollution sources and hotspots, and reporting on the impact of programmes they fund, such as exposure reductions.
- Academic and research institutions: for air quality and public health research.
- Commercial customers: third parties who access our pollution map and routing data, for example via our API, for use in their own products and services (such as navigation apps, urban planning tools, and health applications).
- The public: we may publish pollution maps, impact statistics, or summaries on our website or through partner channels.
This data is anonymised and aggregated. It does not contain personal data, trip routes, or any information that could identify you.
6.2 Personal Data
We do not sell your personal data.
We share personal data only in the following limited circumstances:
- Service providers: we use third-party providers for cloud hosting (Google Cloud Platform), analytics and app infrastructure (Firebase), and email delivery. During beta testing, the app may be distributed via Apple TestFlight, which is subject to Apple’s own privacy policy. These providers process data on our behalf under data processing agreements and are contractually bound to protect your data.
- Legal requirements: we may disclose personal data if required by law, regulation, or legal process.
- Business transfers: if Viridian Labs is acquired or merged, or sells substantially all of its assets, your data may be transferred to the successor entity. We would notify you before your data becomes subject to a different privacy policy.
7. How Long We Keep Your Data
We hold data in two categories. Personal data is kept only as long as we need it to deliver and improve the Service, then deleted or turned into anonymised data, and you can ask us to delete it at any time. Anonymised data (identity stripped, location generalised to road segments or area cells, time-binned, and combined across a minimum number of contributors, as described in Section 4) is no longer personal data and is retained indefinitely.
Personal data (held temporarily, deletable on request)
| Data type | Retention period | Notes |
|---|---|---|
| Account information | Until you delete your account, plus 90 days as backups are overwritten | |
| Trip history, routes, and personal exposure summaries | Until you delete your account or delete specific trips | Visible only to you in the app |
| Raw, GPS-linked and precise-time sensor readings | Up to 12 months, then deleted or turned into anonymised aggregates | Used to deliver and improve the Service (calibration, model retraining, seasonal analysis). Deletable on request. |
| Internal sensor-to-user link | Until you delete your account | See Section 2.2. Severing it leaves the calibration records unlinked. |
| App usage and diagnostics | 12 months rolling |
Anonymised data (not personal data, retained indefinitely)
| Data type | Retention period | Notes |
|---|---|---|
| Anonymised, granular readings (road segment or area cell, time-binned, combined across a minimum number of contributors, no identifiers or raw GPS) | Retained indefinitely | Not personal data. Used internally for model retraining and historical analysis. |
| Anonymised, aggregated map data | Retained indefinitely | Not personal data. Published via API, dashboard, and partner channels. |
| Anonymised, aggregated usage and impact statistics (route and demand patterns, exposure reductions) | Retained indefinitely | Not personal data. Used for analytics, research, impact reporting, and public communications. |
8. Your Rights
Under UK GDPR, you have the following rights:
- Access: you can request a copy of the personal data we hold about you.
- Correction: you can ask us to correct inaccurate personal data.
- Deletion: you can ask us to delete your personal data. When you do, we delete the personal data we hold about you: your account information, trip history, routes and exposure summaries, your raw and precise-time sensor readings, the internal sensor-to-user link, and any identifiers in our operational logs, unless we have a legal obligation to retain something. This does not reach data that has already been genuinely anonymised (identity stripped, location generalised, time-binned, and combined across a minimum number of contributors, as described in Section 4), because that data is no longer personal and can no longer be connected to you.
- Objection: you can object to processing based on legitimate interest (Section 3.4). This does not apply to processing that is necessary for our contract with you (Sections 3.1 and 3.2), or to the anonymised data we share for council programmes (Section 3.3), which is not personal data. If you do not wish to contribute data to the pollution maps, you may stop using the sensor and request deletion of your personal data.
- Restriction: you can ask us to restrict processing of your personal data while we address a concern.
- Portability: you can request your personal data in a structured, machine-readable format.
- Withdraw consent: where we process data based on your consent (for example, optional communications), you can withdraw it at any time.
To exercise any of these rights, contact us at privacy@saddlesense.co. We will respond within one month.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
9. Children
The Service is intended for adults and is not directed at anyone under 18. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has provided us with personal data, please contact us and we will delete it.
10. International Transfers
Your data is stored on servers located in the United Kingdom and the European Economic Area. In the course of operating the Service, authorised Viridian Labs personnel based outside the UK and EEA, including in the United States, may access personal data remotely for purposes such as analysis, model development, and technical support. Data is accessed remotely and is not stored outside the UK and EEA.
Where personal data is accessed from outside the UK and EEA, we put appropriate safeguards in place, such as the ICO’s International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, to protect your data.
11. Cookies and Tracking
The Saddle Sense app does not use cookies or third-party advertising trackers. We use Firebase for basic in-app analytics and stability monitoring, as described in Section 6.2, which may involve app or device identifiers. We do not track you across other apps or websites. If this changes, we will update this policy and notify you before introducing any new tracking technologies.
12. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will notify you through the app or by email at least 30 days before the changes take effect. The “last updated” date at the top of this policy shows when it was most recently revised.
13. Contact Us
If you have any questions about this policy or how we handle your data:
Viridian Labs Ltd
West Goods Entrance, Somerset House, Victoria Embankment, London WC2R 1LA, United Kingdom
privacy@saddlesense.co