near & here.
Last updated: August 23, 2026
near & here. society is a federally incorporated not-for-profit organization (under the Canada Not-for-profit Corporations Act), based in Toronto, Ontario, Canada. We build and operate near & here. (bundle identifier com.nearandhere.app), a free app that helps people find nearby places, transit, events, and community services around Toronto.
This policy describes how the near & here. app collects, uses, discloses, and protects information. It applies to the app itself — not to any other website. Questions, requests, or concerns about this policy can be sent to hi@nearandhere.ca at any time.
We ask for your location so the app can centre the map on you, find places and transit near you, and give you directions. This is used live, on your device, for the feature you're actively using — we do not write your location to disk on our servers.
During active turn-by-turn navigation only, the app can continue using your location while your screen is locked, so directions keep working. This does not need the "Always" location permission, and the app never asks for it — "while using the app" is enough. A session in progress is always visible while it runs: iOS shows a blue indicator in the status bar, and Android shows an ongoing notification. Outside of an active navigation session, the app only ever uses location while you have it open in the foreground.
Your coordinates are never included in analytics events. If you view content outside the Toronto area, the app records only that fact (e.g. "outside service area") — never the coordinates themselves.
The app can optionally tell us which screens get opened, which categories get tapped, how long things take to load, and your answers to occasional short feedback prompts (a rating or a multiple-choice answer — never anything you type). This is opt-in and off until you say yes, in the same onboarding step where we explain it, and you can turn it off again at any time in Profile → Settings, with immediate effect.
This is enforced in the app's code, not just its settings screen: no analytics event of any kind can be created or sent while consent is off, and every event that is sent has the following stripped out first, before it ever leaves your device:
We run this analytics ourselves, on our own server in Toronto, using an open-source, self-hosted tool called Umami — not Google Analytics, and not any advertising or marketing platform. See How long we keep information for how long this data lasts.
If something goes wrong, the app can optionally tell us what type of error occurred and roughly where in the app it happened, so we can fix it. This runs through the same consent-gated pipeline as analytics above (same redaction, same on/off switch) rather than a third-party crash-reporting SDK — deliberately, so that no persistent device identifier or full request details are collected the way a service like Crashlytics or Sentry would by default.
The following never leaves your phone — not to our servers, not to analytics:
This is kept in the app's local storage on your device. On Android, it's specifically excluded from automatic cloud backup, so it stays only on the device that created it. Uninstalling the app, or clearing its storage from your device's settings, permanently deletes all of it.
If you tap "Add to calendar" on an event, the app hands that event to your device's own calendar app. We don't see, store, or otherwise access your calendar.
The app uses a local notification to show you're in an active turn-by-turn navigation session (so you know it's still running with your screen locked). We don't use push notifications at all — not for marketing, not for re-engagement, not for anything. The app has no push token, and we've deliberately kept it that way: a push token is a permanent identifier for your specific device, and we'd rather not have one.
The app has a notices area (the bell on the map) where we post occasional announcements, planned-maintenance warnings, and service-status updates. These appear only inside the app, when you open it.
Everyone gets the same list. We publish one set of notices and your device fetches it exactly as it fetches map content — anonymously, with nothing about you attached. We don't send your platform, your app version, your city, or any identifier with that request.
Some notices are meant for a subset of people — for example "Android only", or "only versions older than X". Those checks happen on your phone, not on our servers. Your device downloads the whole list and decides locally what applies to it. We deliberately built it this way rather than the usual approach of telling the server about your device and letting it choose, because that would mean sending us a per-request description of your device that we don't want and don't need.
Which notices you've read is stored only on your device, and is never sent anywhere. There is no read receipt. We can see how many notices we've published; we cannot see who has read them.
If usage analytics are switched on, opening the notices area and reading a notice count as ordinary app activity and are recorded the same way as any other screen — which notice, and what type it was, never its contents alongside anything about you. With analytics off, nothing is recorded at all. This is the same single on/off switch described above.
Two related details, for completeness:
nearandhere.ca to see whether we've posted anything about the outage. That request reveals your IP address to our website host in the same way visiting any web page does, and it happens only when something is already failing — never during normal use.You can report a problem with a listing or a route, or send us a support message, from inside the app or from our website's support page. When you do, we receive the reason you pick, anything you choose to type, and — for a report about a specific place, event, stop, or station — which listing it was, along with basic technical context (the app version, your platform, and the major version of your operating system, e.g. "iOS 18"). We use this only to find and fix the thing you're telling us about.
A report is not linked to your identity. We don't attach your name, your analytics session, any device identifier, or your location to it — so a report about a sensitive listing, such as a health or faith service, does not tell us who sent it. A report about a route records only its rough shape (the travel mode and a coarse duration and distance) — never your start point, your destination, or the path between them.
Asking us to cover somewhere new. If you point at a place outside the area we cover, the app offers to pass on a request for it. What we receive is the name of the city, town, or area — the one you tap, or the one you type — plus anything else you choose to add. We do not keep the point on the map you touched: to save you typing, the app asks our own geocoding service which municipality that point falls in — the same lookup it already makes whenever you drop a pin anywhere else — and the request we store records only the place name you confirmed before sending. Where you ask for is never attached to an analytics event, so it stays unconnected to anything else about your use of the app. We count these requests to decide where to go next.
Giving us your email is optional, separate, and only offered on our website's support page — the app itself never asks for or collects an email address for a report. On the website, you provide it only if you'd like a reply, and only alongside a clearly-unchecked box confirming we may contact you about that report. When you do, it's stored apart from the report itself, used solely to reply to you about that report, and never for anything else — and you can have it deleted at any time by emailing hi@nearandhere.ca. We ask you not to include personal or sensitive information in the free-text part of a report.
If you email hi@nearandhere.ca directly instead, we receive whatever you choose to include in that message, and use it only to respond to you.
We do not, under any circumstance:
Where your location and other information are needed to directly provide a feature you've asked for — showing the map, finding nearby content, giving directions — we process it because it's necessary to provide that specific feature, for the moment you're using it.
A small amount of information is kept in the app's own storage on your device because the feature you asked for cannot work without it — which notices you've already read, so we don't show you the same announcement twice, and your saved places and preferences. This is stored on your device only, is never transmitted, and is not used to recognise or track you across apps, sites, or sessions.
Where information is not necessary for the app's core functioning — analytics and crash reports — we rely on your freely given, specific, informed consent, which you can withdraw at any time with immediate effect and no consequence to any other part of the app.
When you send us a report or support message, we process what you include in order to handle the request you've made. If you add a contact email on our website's support page, we use it to reply to you on the basis of the consent you give by ticking that box. And we process a small amount of technical information — such as a short-lived record of IP addresses — where it's necessary for our legitimate interest in keeping the service secure and free from automated abuse.
We operate almost everything ourselves. A short, complete list of everyone else involved, and why:
nearandhere.ca, which is where the app looks for a service-status file if it cannot reach our data server — so in that situation Cloudflare sees that connection too. Governed by Cloudflare's own privacy policy.None of the above are paid for access to your information, and none of them receive it for their own marketing use.
Everything we control runs on infrastructure we operate ourselves: a single server located in Toronto, Ontario, Canada (Oracle Cloud Infrastructure, ca-toronto-1 region). We do not route app data through Google Firebase, AWS, or a similar big-tech backend. To protect the service from automated abuse — for example, spam submitted to our report form — our server briefly records the IP address a request comes from, keeps it for about 7 days, uses it only for that security purpose, and then deletes it automatically. We keep no other persistent log of visitor IP addresses, and an IP recorded this way is never linked to a report's contents or to anything else about you.
All connections between the app and our servers use HTTPS/TLS encryption. Our infrastructure is self-hosted rather than shared with, or resold through, a third-party data or advertising platform, and access to it is restricted to the small team operating near & here. society.
Regardless of where you live, you can:
near & here. is not directed at children, and we do not knowingly collect personal information from children. The app requires no account and no age-identifying information, so we have no way to knowingly identify a child user. If a parent or guardian believes a child has used the app and has a concern, please contact hi@nearandhere.ca.
Everything we control is stored and processed in Ontario, Canada. Quebec's Law 25 treats a transfer of personal information outside Quebec — including to another Canadian province — as something that needs assessment. Ontario is subject to the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and comparable protections to Quebec's own law, and we do not transfer personal information to any jurisdiction with materially weaker protection than that.
Cloudflare, our network and security provider, operates a global network, so connection-level information (like your IP address) may transit or be processed outside Canada as a standard part of that service — see Cloudflare's privacy policy for details.
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you. Route and search results are computed from what you ask for and public map/transit data — not from a profile built about you.
If we make a material change — for example, introducing accounts, or a new category of data collection — we'll update the "Last updated" date above and, where appropriate, call it out in the app itself.
The sections above apply to everyone. The notes below map our practices to the specific rules of a few regions — they don't add new practices, they point at the ones above using each region's own terms.
near & here. is a Toronto-focused civic app and does not direct itself at, or market to, people in the EEA or UK. If you use the app from there anyway, we extend the same rights described in Your choices and rights to you: the right to access, correct, delete, or restrict use of your information, to object to processing, to data portability, and to withdraw consent at any time. Our basis for processing is set out in Our basis for processing information. You can lodge a complaint with your national Data Protection Authority, or with the UK Information Commissioner's Office if you're in the UK.
We handle personal information according to PIPEDA's ten fair-information principles — accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and the ability to challenge our compliance. Our privacy contact is Vladislav Grigorev, President, reachable at hi@nearandhere.ca, and you can complain to the Office of the Privacy Commissioner of Canada at any time.
For people in Quebec specifically: under Law 25, the person responsible for the protection of personal information is, by default, the person with the highest authority in the organization — for near & here. society, that's Vladislav Grigorev, President, reachable at the same address, hi@nearandhere.ca. As described in Your choices and rights, you can deactivate location use at any time from your device settings. You may lodge a complaint with the Commission d'accès à l'information du Québec (CAI).
near & here. society is a Canadian non-profit and does not meet the CCPA's applicability thresholds for a covered business (revenue, or volume of California consumers' data) — but we extend the substance of these rights to everyone regardless of legal threshold. In the categories the CCPA defines: we collect geolocation data (used live, never stored — see Information we collect, and why); only with your opt-in consent, internet/device activity information (the analytics described above); and identifiers only in two narrow forms — an email address, if you choose to give one to receive a reply, and a short-lived record of your IP address kept solely to block automated abuse. We do not sell or share personal information as those terms are defined by the CCPA/CPRA. Precise geolocation is processed only to the extent necessary to provide the feature you asked for in the moment. You have the right to know, access, correct, and delete your information, to limit use of sensitive personal information, and to be free from discrimination for exercising any of these rights — contact hi@nearandhere.ca to exercise any of them.
near & here. society
Toronto, Ontario, Canada
Vladislav Grigorev, President — hi@nearandhere.ca
Responsible for the protection of personal information under applicable Canadian privacy law.