vertical
mobi
Change language: Português
Back to Vertical Way

Privacy Policy

Vertical Way · Last updated 26 August 2026

This policy explains what the Vertical Way app does with your data. It covers the version published on the App Store by VERTICAL MOBI LTDA.

In one line

Vertical Way works without an account: signed out, your records stay on your device alone. With an account, records sync across your devices or with a company you belong to, and attachments are held in Firebase Storage. Your location, when you allow it, only suggests the station you are at, and it is not stored. We do not sell your data, we do not hand it over, and we do not use it for advertising.

What data the app handles

Your account

The account is optional. Signed out, you can use records on the device; syncing, attachments, in-app contact and account or company screens ask for a session. When you do create an account, we store your email address, your name and a user identifier we generate.

You can sign in three ways: email and password, Sign in with Google or Sign in with Apple. Through Google, it tells us the email address and name on the account you pick. Through Apple, you may choose to hide your email address, in which case we receive a relay address from Apple rather than your real one.

Your password is never held by us in readable form: authentication is handled by Firebase Authentication, from Google.

What you record

Vehicles, fuel-ups, expenses, services, trips, odometer readings, reminders, income, your app preferences, and the metadata of any file you attach to a record.

Signed out, that data stays on your device alone, in the app’s private area, and nothing is sent to our infrastructure.

With an account, it is also synced to our infrastructure, so you find it again when you sign in to the same account on another device. It lives in Cloud Firestore, from Firebase, inside your personal fleet or the active company, in the vehicles, records, catalogues, reminders, attachments, members and settings sets. Your account profile is held separately under your identifier. Syncing ships turned on, and we can turn it off remotely, with no new version in the store, if we have to.

If the device already held records when you signed in for the first time, they are taken into the account, and the app asks first when both sides hold something.

The app works offline: you record with no signal, and syncing happens when the connection comes back.

Company and member data

An account can use its personal fleet and also belong to companies. A company administrator can store the company’s name, tax document, address, contact email and phone number. For each person invited, they can store first and last name, email, phone, admin or driver role, assigned vehicles and, for a driver, licence number, category and expiry date.

Company data belongs to that shared space. Active administrators can manage all vehicles and records. Active drivers see and change only data for vehicles assigned to them. Removing a person revokes their access but preserves the member history and the records they created for the company.

Attachments: the files live in Firebase Storage

You must sign in to attach a file. The file is uploaded to Firebase Storage, from Google, under the fleet and record it belongs to. In Cloud Firestore we also store its reference, name, type, size, vehicle, author and the dates needed to sync it and account for the storage used.

Access follows the same fleet boundary: an active administrator can reach company attachments; an active driver can reach only attachments for assigned vehicles. With no active membership, Firebase rules refuse reads and writes.

When you open an attachment, the file is downloaded and kept on your device for 7 days, so reopening the same record needs no second download. After that, the local copy is swept. Deleting an attachment inside the record deletes the matching Firebase Storage object and marks its reference as deleted.

Location: the station suggestion

When you log a fuel-up, the app can suggest the station you are at and list the stations around you. That is the only thing it does with your location.

The permission is asked for there alone, in the fuel-up form, and before the system’s own prompt the app shows a sheet explaining what it is for. The reading is of a single position, at the moment you open a new fuel-up or tap the Station field, with the app open in front of you. There is no background reading, no trip recording, and the app does not follow where you go.

That position is sent to Google’s Places API, which answers with the fuel stations around it. What leaves the device in that request is the point, the search radius, the kind of place being looked for and the language: nothing that identifies you, your account or your records. The answer stays in the app’s memory while it is open, and is gone when it closes.

We do not store your location. It does not go into the record, it does not reach our infrastructure, and it is not used for anything else.

What may be stored is the station, not you: if you pick a station that is not in “My stations” yet, the app creates the entry with its name, its address, its Google place identifier and the coordinates of the station. With an account, that entry syncs along with the rest of your catalogues.

Refusing the permission takes nothing away: the Station field is still picked or typed by you, the way it always was. And the automatic suggestion can be turned off under More › Settings › Records › Nearby station suggestion.

Technical data from the provider

The app uses Firebase Remote Config, from Google, to turn features on and off without shipping a new version to the store. To work, that service sends Google an app installation identifier along with technical data about the device, such as model, operating system, language and app version.

That identifier belongs to the installed app and not to you: it carries no name, no email address and none of your records, and it is discarded when you uninstall the app.

What we do not collect

We do not ask for a phone number or a government id. We do not measure your behaviour inside the app: the app carries an internal event recorder, and the only destination wired into it writes to the device’s own debug console, sending nothing out. There is no advertising. We do not track you across other apps or websites, and we hand no data to any form of profiling.

Permissions the app asks for

The app asks for a permission only at the moment it is needed, and none of them is mandatory: refuse, and the matching feature stays available by typing.

Permission What for If you refuse
Camera Photograph a receipt and attach it to a record The record is saved without the attachment
Photos Pick an image from your library to attach The record is saved without the attachment
Location (while in use) Suggest the station you are at and list the ones around you, in the fuel-up form You pick or type the station, as always
Notifications Warn you about a service, insurance or oil-change reminder Reminders stay in the list, without the alert

Reminders are worked out and fired on your device. We do not send you notifications.

Who we share it with

Nobody, in the sense of selling, renting or handing over. There is no advertising, measurement or profiling partner in the app.

We use Google Firebase for authentication, Cloud Firestore syncing, Firebase Storage attachments, Remote Config and server functions.

A second Google service, the Places API, receives the device’s position alone, and only when you have allowed location and are logging a fuel-up. That request is made to bring back the stations around you and nothing else: it carries no account, no name and none of your records, and the position sent is not stored by us.

When an administrator invites someone or you send a message through the Contact screen, our email service, Resend, receives what is needed to deliver it: recipient, names and company data for an invitation; or the text you wrote, reply address, account and submission identifiers, language, platform, app version and technical device identifier for a contact message.

Separately, and on its own account, the Firebase components send Google a technical identifier for the installed build, along with device data such as country, language, time zone and system version. That collection is Google’s, for Google’s own product decisions, and does not pass through us. It carries none of your records, your name or your email address. Google’s own handling is described in the Google Privacy Policy.

You can also export your timeline and send it wherever you want, through any app on the device. That way out is your action, and the destination is your choice.

Some taps also take you out of the app: opening an attachment opens an address served by Firebase Storage, the About and Settings screens open our website, our Instagram profile and these legal pages, and More › Rate the app opens the app’s App Store page. From there the destination’s own policy applies, not ours.

How long the data stays

As long as your account or the company that holds the data exists. Deleting a record takes the data out of the app on every device; in Cloud Firestore the matching document is marked as deleted, because that mark carries the deletion to other devices. Removing a member ends their access, but their historical member entry and the records they created remain with the company.

Deleting an attachment in its record deletes the file from Firebase Storage. Account deletion removes the active fleet’s Cloud Firestore documents, the authentication profile and the local copy, but the current flow does not automatically delete attachment objects already in Firebase Storage. Delete attachments from their records before deleting the account, or write to contato@verticalmobi.com to ask us to locate and erase remaining objects. Downloaded device copies are swept within 7 days, or at once if you uninstall.

Uninstalling the app removes the local copy but does not delete your account: the data is still there if you sign in again. To erase everything, use the account deletion described below.

Your rights

You can confirm what we process, access it, correct it, take it elsewhere and have it erased, and you can withdraw consent.

You exercise those rights inside the app:

  • Access and correct: any record opens and edits from the list itself.
  • Take it elsewhere: exporting your timeline is free, in CSV, with no paywall and nothing asked in return. Reports export as PDF.
  • Erase: delete the record or attachment in the app, or delete the account under More › My account › Delete account. Deletion asks you to type DELETE; in a company with other members, the phrase is DELETE COMPANY. The operation is permanent. As described above, any remaining attachment objects must be removed first or requested by email.
  • Revoke access: signing out ends the session on the device without deleting data. An administrator can remove a company member, revoking that person’s access to the shared space.

If you would still rather talk to us about personal data, write to contato@verticalmobi.com. We answer within 15 days.

Children

Vertical Way is rated 4+ and is not directed at children. We do not knowingly collect data from minors. If you know of an account created by a child, write to contato@verticalmobi.com and we will remove it.

Security

Traffic between the app and our infrastructure is encrypted. On the device, data sits in the app’s private area, which other apps cannot read, and its protection follows the protection of the device itself: use a passcode, biometrics and your system’s encrypted backup. Session credentials are kept in the operating system’s secure storage.

Access to server data is scoped to the active fleet. Firestore rules require an active membership: administrators can reach all fleet data, and drivers only records and reminders for vehicles assigned to them. The personal profile under an account identifier can be read and written only by that account.

In Firebase Storage, each object sits under the fleet and record it belongs to. The rules require an active membership: administrators can reach the fleet, and drivers only the vehicles assigned to them.

Who is responsible

VERTICAL MOBI LTDA · contato@verticalmobi.com

Changes to this policy

When this policy changes, the date at the top of the page changes with it. Material changes will be announced inside the app.