Back to near & here.

near & here.

Privacy Policy

Last updated: August 23, 2026

The short version

  • We never sell, rent, or share your personal information with anyone, for any reason.
  • No account, no ads, no ad-tracking, no advertising ID of any kind.
  • Your location is used live, on your device, to run the map and directions — we never store it on our servers.
  • Usage analytics are off by default. If you turn them on, they're anonymous, self-hosted by us, and auto-deleted after 400 days.
  • Saved places, search history, and your Passport stay on your phone. We never see them.
  • In-app announcements are the same for everyone. Which ones you've read stays on your phone — we never learn who read what.
  • Our servers are in Toronto, Ontario — run by us, not Google, Amazon, or Meta.

On this page

  1. Who we are
  2. Information we collect, and why
  3. What we don't do
  4. Our basis for processing information
  5. Who else may see limited information
  6. Where information is stored and processed
  7. How long we keep information
  8. Security
  9. Your choices and rights
  10. Children's privacy
  11. International data transfers
  12. Automated decision-making
  13. Changes to this policy
  14. Regional disclosures (EEA/UK, Canada & Quebec, California)
  15. Contact us

Who we are

near & here. society is a federally incorporated not-for-profit organization (under the Canada Not-for-profit Corporations Act), based in Toronto, Ontario, Canada. We build and operate near & here. (bundle identifier com.nearandhere.app), a free app that helps people find nearby places, transit, events, and community services around Toronto.

This policy describes how the near & here. app collects, uses, discloses, and protects information. It applies to the app itself — not to any other website. Questions, requests, or concerns about this policy can be sent to hi@nearandhere.ca at any time.

Information we collect, and why

Location

We ask for your location so the app can centre the map on you, find places and transit near you, and give you directions. This is used live, on your device, for the feature you're actively using — we do not write your location to disk on our servers.

During active turn-by-turn navigation only, the app can continue using your location while your screen is locked, so directions keep working. This does not need the "Always" location permission, and the app never asks for it — "while using the app" is enough. A session in progress is always visible while it runs: iOS shows a blue indicator in the status bar, and Android shows an ongoing notification. Outside of an active navigation session, the app only ever uses location while you have it open in the foreground.

Your coordinates are never included in analytics events. If you view content outside the Toronto area, the app records only that fact (e.g. "outside service area") — never the coordinates themselves.

Usage analytics — off by default

The app can optionally tell us which screens get opened, which categories get tapped, how long things take to load, and your answers to occasional short feedback prompts (a rating or a multiple-choice answer — never anything you type). This is opt-in and off until you say yes, in the same onboarding step where we explain it, and you can turn it off again at any time in Profile → Settings, with immediate effect.

This is enforced in the app's code, not just its settings screen: no analytics event of any kind can be created or sent while consent is off, and every event that is sent has the following stripped out first, before it ever leaves your device:

  • Your location, or anything that could reconstruct it (coordinates, postal codes, neighbourhood names)
  • Anything you type
  • Your name or email address
  • Whether you viewed a sensitive category of content — health, faith and religious services, 2SLGBTQ+ services, and similar support services are specifically excluded before an event is ever created, regardless of your consent setting

We run this analytics ourselves, on our own server in Toronto, using an open-source, self-hosted tool called Umami — not Google Analytics, and not any advertising or marketing platform. See How long we keep information for how long this data lasts.

Crash and error reports — same on/off switch as analytics

If something goes wrong, the app can optionally tell us what type of error occurred and roughly where in the app it happened, so we can fix it. This runs through the same consent-gated pipeline as analytics above (same redaction, same on/off switch) rather than a third-party crash-reporting SDK — deliberately, so that no persistent device identifier or full request details are collected the way a service like Crashlytics or Sentry would by default.

Information stored only on your device

The following never leaves your phone — not to our servers, not to analytics:

  • Saved / bookmarked places
  • Search history
  • Your Passport — a personal record of the places you've explored in the app, including an optional name you can give it
  • Which in-app notices you've read — see In-app notices and announcements above

This is kept in the app's local storage on your device. On Android, it's specifically excluded from automatic cloud backup, so it stays only on the device that created it. Uninstalling the app, or clearing its storage from your device's settings, permanently deletes all of it.

Calendar

If you tap "Add to calendar" on an event, the app hands that event to your device's own calendar app. We don't see, store, or otherwise access your calendar.

Notifications

The app uses a local notification to show you're in an active turn-by-turn navigation session (so you know it's still running with your screen locked). We don't use push notifications at all — not for marketing, not for re-engagement, not for anything. The app has no push token, and we've deliberately kept it that way: a push token is a permanent identifier for your specific device, and we'd rather not have one.

In-app notices and announcements

The app has a notices area (the bell on the map) where we post occasional announcements, planned-maintenance warnings, and service-status updates. These appear only inside the app, when you open it.

Everyone gets the same list. We publish one set of notices and your device fetches it exactly as it fetches map content — anonymously, with nothing about you attached. We don't send your platform, your app version, your city, or any identifier with that request.

Some notices are meant for a subset of people — for example "Android only", or "only versions older than X". Those checks happen on your phone, not on our servers. Your device downloads the whole list and decides locally what applies to it. We deliberately built it this way rather than the usual approach of telling the server about your device and letting it choose, because that would mean sending us a per-request description of your device that we don't want and don't need.

Which notices you've read is stored only on your device, and is never sent anywhere. There is no read receipt. We can see how many notices we've published; we cannot see who has read them.

If usage analytics are switched on, opening the notices area and reading a notice count as ordinary app activity and are recorded the same way as any other screen — which notice, and what type it was, never its contents alongside anything about you. With analytics off, nothing is recorded at all. This is the same single on/off switch described above.

Two related details, for completeness:

  • If the app can't reach our data server, it explains that to you on the spot — that message is written by the app itself, on your device, and needs no network at all. It will also check a small status file on nearandhere.ca to see whether we've posted anything about the outage. That request reveals your IP address to our website host in the same way visiting any web page does, and it happens only when something is already failing — never during normal use.
  • Very rarely, an update may be required. If a version of the app can no longer work correctly with our data, it will ask you to update before continuing. This is a functional safeguard, not a data-collection mechanism: the decision is made on your device by comparing your app's version number against a number we publish, and nothing about you is sent to us in the process.

Reports, support messages, and other things you send us

You can report a problem with a listing or a route, or send us a support message, from inside the app or from our website's support page. When you do, we receive the reason you pick, anything you choose to type, and — for a report about a specific place, event, stop, or station — which listing it was, along with basic technical context (the app version, your platform, and the major version of your operating system, e.g. "iOS 18"). We use this only to find and fix the thing you're telling us about.

A report is not linked to your identity. We don't attach your name, your analytics session, any device identifier, or your location to it — so a report about a sensitive listing, such as a health or faith service, does not tell us who sent it. A report about a route records only its rough shape (the travel mode and a coarse duration and distance) — never your start point, your destination, or the path between them.

Asking us to cover somewhere new. If you point at a place outside the area we cover, the app offers to pass on a request for it. What we receive is the name of the city, town, or area — the one you tap, or the one you type — plus anything else you choose to add. We do not keep the point on the map you touched: to save you typing, the app asks our own geocoding service which municipality that point falls in — the same lookup it already makes whenever you drop a pin anywhere else — and the request we store records only the place name you confirmed before sending. Where you ask for is never attached to an analytics event, so it stays unconnected to anything else about your use of the app. We count these requests to decide where to go next.

Giving us your email is optional, separate, and only offered on our website's support page — the app itself never asks for or collects an email address for a report. On the website, you provide it only if you'd like a reply, and only alongside a clearly-unchecked box confirming we may contact you about that report. When you do, it's stored apart from the report itself, used solely to reply to you about that report, and never for anything else — and you can have it deleted at any time by emailing hi@nearandhere.ca. We ask you not to include personal or sensitive information in the free-text part of a report.

If you email hi@nearandhere.ca directly instead, we receive whatever you choose to include in that message, and use it only to respond to you.

What we don't do

We do not, under any circumstance:

  • Sell, rent, or otherwise disclose your personal information to any other company for their own marketing or commercial purposes
  • Show ads, or share information with any advertising network or data broker
  • Use advertising identifiers (like Apple's IDFA) or any cross-app/cross-site tracking technology
  • Build an advertising or marketing profile of you
  • Require an account to use the app

Our basis for processing information

Where your location and other information are needed to directly provide a feature you've asked for — showing the map, finding nearby content, giving directions — we process it because it's necessary to provide that specific feature, for the moment you're using it.

A small amount of information is kept in the app's own storage on your device because the feature you asked for cannot work without it — which notices you've already read, so we don't show you the same announcement twice, and your saved places and preferences. This is stored on your device only, is never transmitted, and is not used to recognise or track you across apps, sites, or sessions.

Where information is not necessary for the app's core functioning — analytics and crash reports — we rely on your freely given, specific, informed consent, which you can withdraw at any time with immediate effect and no consequence to any other part of the app.

When you send us a report or support message, we process what you include in order to handle the request you've made. If you add a contact email on our website's support page, we use it to reply to you on the basis of the consent you give by ticking that box. And we process a small amount of technical information — such as a short-lived record of IP addresses — where it's necessary for our legitimate interest in keeping the service secure and free from automated abuse.

Who else may see limited information

We operate almost everything ourselves. A short, complete list of everyone else involved, and why:

  • Cloudflare — sits in front of our own server for domain name service, encryption, and protection against automated abuse. Cloudflare may process connection-level information (like your IP address) as part of that role. On our website's report form we also use Cloudflare Turnstile, a privacy-preserving check that confirms a submission comes from a person rather than a bot, without tracking cookies or building an advertising profile. Cloudflare also fronts nearandhere.ca, which is where the app looks for a service-status file if it cannot reach our data server — so in that situation Cloudflare sees that connection too. Governed by Cloudflare's own privacy policy.
  • Mapillary — when you open a street-level photo in the app, our own server fetches that image from Mapillary on your behalf. Mapillary sees a request from our server, not from your device directly.
  • Open-Meteo and Environment and Climate Change Canada (ECCC) — the weather and air-quality panels call these public, free data services directly from your device. This exposes your device's IP address and the general map area you're currently viewing (not your precise GPS coordinates) to these providers. Open-Meteo is a non-commercial weather-data project; ECCC is the Government of Canada.
  • Toronto Transit Commission (TTC) — live vehicle and arrival predictions are fetched directly from the TTC's own public real-time feeds. No personal information is included in these requests.
  • Open data sources — OpenStreetMap, Overture Maps, City of Toronto Open Data, Bike Share Toronto, Ticketmaster, Wikimedia and Wikipedia. These are one-way: they supply public content that the app displays. We do not send them any information about you. Full attribution and licences for every source are listed in-app under Data & Map Attributions.

None of the above are paid for access to your information, and none of them receive it for their own marketing use.

Where information is stored and processed

Everything we control runs on infrastructure we operate ourselves: a single server located in Toronto, Ontario, Canada (Oracle Cloud Infrastructure, ca-toronto-1 region). We do not route app data through Google Firebase, AWS, or a similar big-tech backend. To protect the service from automated abuse — for example, spam submitted to our report form — our server briefly records the IP address a request comes from, keeps it for about 7 days, uses it only for that security purpose, and then deletes it automatically. We keep no other persistent log of visitor IP addresses, and an IP recorded this way is never linked to a report's contents or to anything else about you.

How long we keep information

  • Location: not retained at all beyond the moment it's used — never written to disk on our servers.
  • Analytics and crash/error events: kept for 400 days, then automatically and permanently deleted by a scheduled process built specifically to enforce this window.
  • Information stored on your device (saved places, search history, Passport, which notices you've read): kept until you remove it yourself by uninstalling the app or clearing its storage in your device settings. Read-notice records are also pruned automatically by the app as older announcements expire. There is currently no in-app "clear my data" button as a separate option — we're working on adding one.
  • Reports, support messages, and requests to cover a new area: kept for up to 180 days and then permanently deleted by the same kind of scheduled, enforced process as our analytics window. A report we've marked resolved is deleted sooner — about 90 days after we resolve it — and anything identified as spam is removed within about 30 days. A contact email you attached to a report on our website's support page is deleted together with that report, or sooner if you ask.
  • IP addresses logged to prevent abuse: kept about 7 days, then automatically deleted (see Where information is stored and processed).
  • A message you email us directly: kept as long as reasonably needed to address it, then deleted.

Security

All connections between the app and our servers use HTTPS/TLS encryption. Our infrastructure is self-hosted rather than shared with, or resold through, a third-party data or advertising platform, and access to it is restricted to the small team operating near & here. society.

Your choices and rights

Regardless of where you live, you can:

  • Turn analytics off at any time in Profile → Settings. This takes effect immediately; nothing further is sent afterward.
  • Turn off location access at any time in your device settings (iOS: Settings → Privacy & Security → Location Services → near & here.; Android: Settings → Apps → near & here. → Permissions). The app keeps working — map centring, nearby search, and turn-by-turn directions simply won't use your device's location anymore.
  • Delete everything stored on your device by uninstalling the app, or by clearing its storage from your device's settings.
  • Ask what we hold, correct it, or ask us to delete it — because there's no account and analytics isn't linked to your identity, in practice this mostly concerns any direct correspondence you've had with us, or a contact email you chose to leave with a report. Email hi@nearandhere.ca and we'll respond within 30 days.
  • Lodge a complaint with your local privacy regulator — see Regional disclosures below for how to reach the one that covers you.

Children's privacy

near & here. is not directed at children, and we do not knowingly collect personal information from children. The app requires no account and no age-identifying information, so we have no way to knowingly identify a child user. If a parent or guardian believes a child has used the app and has a concern, please contact hi@nearandhere.ca.

International data transfers

Everything we control is stored and processed in Ontario, Canada. Quebec's Law 25 treats a transfer of personal information outside Quebec — including to another Canadian province — as something that needs assessment. Ontario is subject to the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and comparable protections to Quebec's own law, and we do not transfer personal information to any jurisdiction with materially weaker protection than that.

Cloudflare, our network and security provider, operates a global network, so connection-level information (like your IP address) may transit or be processed outside Canada as a standard part of that service — see Cloudflare's privacy policy for details.

Automated decision-making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on you. Route and search results are computed from what you ask for and public map/transit data — not from a profile built about you.

Changes to this policy

If we make a material change — for example, introducing accounts, or a new category of data collection — we'll update the "Last updated" date above and, where appropriate, call it out in the app itself.

Regional disclosures

The sections above apply to everyone. The notes below map our practices to the specific rules of a few regions — they don't add new practices, they point at the ones above using each region's own terms.

European Economic Area & United Kingdom (GDPR / UK GDPR)

near & here. is a Toronto-focused civic app and does not direct itself at, or market to, people in the EEA or UK. If you use the app from there anyway, we extend the same rights described in Your choices and rights to you: the right to access, correct, delete, or restrict use of your information, to object to processing, to data portability, and to withdraw consent at any time. Our basis for processing is set out in Our basis for processing information. You can lodge a complaint with your national Data Protection Authority, or with the UK Information Commissioner's Office if you're in the UK.

Canada (PIPEDA) and Quebec (Law 25)

We handle personal information according to PIPEDA's ten fair-information principles — accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and the ability to challenge our compliance. Our privacy contact is Vladislav Grigorev, President, reachable at hi@nearandhere.ca, and you can complain to the Office of the Privacy Commissioner of Canada at any time.

For people in Quebec specifically: under Law 25, the person responsible for the protection of personal information is, by default, the person with the highest authority in the organization — for near & here. society, that's Vladislav Grigorev, President, reachable at the same address, hi@nearandhere.ca. As described in Your choices and rights, you can deactivate location use at any time from your device settings. You may lodge a complaint with the Commission d'accès à l'information du Québec (CAI).

California (CCPA / CPRA)

near & here. society is a Canadian non-profit and does not meet the CCPA's applicability thresholds for a covered business (revenue, or volume of California consumers' data) — but we extend the substance of these rights to everyone regardless of legal threshold. In the categories the CCPA defines: we collect geolocation data (used live, never stored — see Information we collect, and why); only with your opt-in consent, internet/device activity information (the analytics described above); and identifiers only in two narrow forms — an email address, if you choose to give one to receive a reply, and a short-lived record of your IP address kept solely to block automated abuse. We do not sell or share personal information as those terms are defined by the CCPA/CPRA. Precise geolocation is processed only to the extent necessary to provide the feature you asked for in the moment. You have the right to know, access, correct, and delete your information, to limit use of sensitive personal information, and to be free from discrimination for exercising any of these rights — contact hi@nearandhere.ca to exercise any of them.

Contact us

near & here. society
Toronto, Ontario, Canada

Vladislav Grigorev, President — hi@nearandhere.ca
Responsible for the protection of personal information under applicable Canadian privacy law.