Privacy Policy
Last Updated: July 14, 2026 | Effective Date: July 14, 2026
1. Introduction & Scope
Sandbox Synergy LLC (“Company,” “We,” “Us,” or “Our”), a New Mexico limited liability company, operates the SOSRoute API platform at sosroute.dev. This Privacy Policy describes how we collect, use, share, retain, and protect personal information when you access or use our API, developer dashboard, documentation, and related services (collectively, the “Services”).
This policy applies to all individuals who interact with the Services, including account holders, developers integrating our API, and visitors to our website. It is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the California Online Privacy Protection Act (CalOPPA). We are committed to protecting your privacy and handling your personal information with transparency and care.
By creating an account, using our API, or otherwise interacting with the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use the Services. This Privacy Policy should be read in conjunction with our Terms of Service and Data Processing Agreement.
2. Information We Collect
2.1 Account Information
When you register for an account, we collect the following personal information: your full name, email address, company or organization name (if applicable), and job title (optional). This information is necessary to create and manage your account, issue API keys, and communicate with you about the Services. We may also collect your billing address if you subscribe to a paid plan.
2.2 API Usage Data
We automatically collect data about your use of the API, including: the endpoints you access, the number of API calls made, timestamps of requests, HTTP methods used, response status codes, response times, rate limit consumption, and error details. This usage data is collected to enforce rate limits, monitor service health, detect abuse, generate analytics dashboards, and improve the Services. API request and response bodies are not logged or retained except in transient memory during request processing.
2.3 Payment Information
All payment processing is handled by Stripe, Inc. When you subscribe to a paid plan, your credit card number, expiration date, and CVC are transmitted directly to Stripe via their secure payment form and are never stored on our servers. We retain only the Stripe customer identifier, subscription status, plan type, billing cycle dates, and invoice history. Stripe’s handling of your payment data is governed by Stripe’s Privacy Policy. Stripe is PCI DSS Level 1 certified.
2.4 Device & Browser Information
When you access the developer dashboard or website, we may automatically collect technical information including your browser type and version, operating system, device type, screen resolution, referring URL, and pages visited. This information is collected through standard server logs and is used for security monitoring, troubleshooting, and improving the user experience of our web interfaces.
2.5 Location Data
The SOSRoute API processes geographic coordinates (latitude and longitude) submitted by your application on behalf of your end users to provide location-relevant safety data, risk scores, and nearest-facility lookups. We do not store end-user location data beyond the transient processing of each API request. Location coordinates are used solely to resolve the relevant API response and are not logged, retained, or associated with identifiable individuals. Your application is responsible for obtaining appropriate consent from your end users before transmitting their location data to the API.
2.6 IP Addresses
We collect IP addresses of API requests and dashboard sessions for the purposes of rate limiting, security monitoring, abuse prevention, and geographic usage analytics. IP addresses in API logs are retained for ninety (90) days and then automatically purged. We do not use IP addresses to identify individual end users of your applications.
3. How We Use Information
We use the information we collect for the following purposes:
- Service Provision: To provide, maintain, and improve the SOSRoute API and related Services, including processing API requests, delivering webhook notifications, and operating the developer dashboard.
- Billing & Account Management: To process payments, manage subscriptions, issue invoices, and handle billing inquiries through our payment processor Stripe.
- Customer Support: To respond to your support requests, troubleshoot issues, and provide technical assistance via email at [email protected].
- Analytics & Improvement: To analyze usage patterns, monitor API performance, identify areas for improvement, and develop new features. Analytics are generated from aggregated and anonymized data wherever possible.
- Security & Fraud Prevention: To detect, prevent, and respond to security incidents, unauthorized access, abuse of the Services, and fraudulent activity. This includes monitoring API usage patterns for anomalies and enforcing rate limits.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, and governmental requests, including tax reporting obligations and responding to lawful data access requests.
- Communications: To send you transactional emails related to your account, including API key issuance, billing confirmations, usage alerts, security notifications, and service announcements. Transactional emails are sent through Twilio SendGrid. We do not send marketing emails unless you have explicitly opted in, and you may opt out at any time.
4. Legal Bases for Processing (GDPR)
For users located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process personal data based on the following legal grounds as required by the General Data Protection Regulation:
- Performance of a Contract (Article 6(1)(b)): Processing is necessary to perform our obligations under the Terms of Service, including providing the API, managing your account, processing payments, and delivering support.
- Legitimate Interests (Article 6(1)(f)): Processing is necessary for our legitimate interests, including securing and improving the Services, analyzing usage patterns, preventing fraud and abuse, and enforcing our Terms. We have balanced these interests against your rights and have determined that our processing does not unduly impact your privacy.
- Consent (Article 6(1)(a)): Where we send marketing communications or use non-essential cookies, we rely on your explicit, freely-given consent. You may withdraw your consent at any time without affecting the lawfulness of processing performed prior to withdrawal.
- Legal Obligation (Article 6(1)(c)): Processing is necessary to comply with legal obligations, including tax record-keeping, responding to valid law enforcement requests, and meeting regulatory requirements.
5. Data Sharing & Third-Party Processors
We share personal data with the following categories of third-party service providers, each of which is contractually bound to process data only on our instructions and to maintain appropriate security measures. We have executed Data Processing Agreements with each sub-processor.
- Stripe, Inc. (San Francisco, CA, USA) — Payment processing. Receives billing information to process subscriptions and payments. PCI DSS Level 1 certified.
- Twilio SendGrid (San Francisco, CA, USA) — Transactional email delivery. Receives email addresses to deliver account notifications, billing receipts, usage alerts, and security notifications. We do not use SendGrid for marketing emails without explicit opt-in consent.
- DigitalOcean, LLC (New York, NY, USA) — Cloud infrastructure hosting. Our application servers, load balancers, and networking infrastructure are hosted in DigitalOcean’s NYC region data centers. DigitalOcean is SOC 2 Type II and ISO 27001 certified.
- Neon, Inc. (USA) — Managed PostgreSQL database hosting. Stores account information, subscription data, API usage records, and webhook configurations.
- Upstash, Inc. (USA) — Managed Redis caching and rate limiting infrastructure. Processes API keys (hashed) and rate limit counters. Data is ephemeral and automatically expires.
- Cloudflare, Inc. (San Francisco, CA, USA) — Content delivery network (CDN), DNS management, and DDoS protection. Processes IP addresses and request metadata for security filtering and performance optimization.
We do not sell, rent, lease, or trade your personal information to any third party. We do not share personal data with data brokers, advertising networks, or any entity for purposes unrelated to providing the Services. We may disclose personal information if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Company, our users, or the public.
6. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are as follows:
- Account Data: Retained for the duration of your active account plus ninety (90) days following account closure or deletion request to allow for reactivation or data export.
- API Usage Logs: Retained for ninety (90) days on a rolling basis. Logs older than 90 days are automatically and permanently deleted.
- Billing & Financial Records: Retained for seven (7) years to comply with tax reporting obligations and financial record-keeping requirements under applicable law.
- Anonymized Analytics: Aggregated, de-identified analytics data that cannot be linked to any individual may be retained indefinitely for statistical analysis and service improvement purposes.
- Account Deletion: Upon receiving a valid deletion request, we will permanently purge your personal data from our active systems within thirty (30) days. Data in encrypted backups will be purged as part of the normal backup rotation cycle, typically within ninety (90) days.
7. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation with respect to your personal data:
- Right of Access (Article 15): You have the right to request a copy of the personal data we hold about you, along with information about how it is processed.
- Right to Rectification (Article 16): You have the right to request that we correct any inaccurate personal data or complete any incomplete personal data.
- Right to Erasure (Article 17): You have the right to request the deletion of your personal data, subject to exceptions for legal obligations, exercise of legal claims, or public interest.
- Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.
- Right to Restriction (Article 18): You have the right to request that we restrict processing of your personal data under certain circumstances, such as when you contest the accuracy of the data.
- Right to Object (Article 21): You have the right to object to processing of your personal data based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.
- Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing performed prior to withdrawal.
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within thirty (30) days as required by the GDPR. We may need to verify your identity before processing your request. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.
8. Your Rights Under CCPA
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with the following rights:
- Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share your personal information.
- Right to Delete: You have the right to request that we delete the personal information we have collected from you, subject to certain exceptions permitted by law (such as legal compliance and completing transactions).
- Right to Opt-Out of Sale: We do not sell personal information as defined by the CCPA. We do not share personal information for cross-context behavioral advertising. Therefore, there is no need to opt out. However, if our practices change, we will provide a “Do Not Sell or Share My Personal Information” link on our website.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights. We will not deny you services, charge different prices, provide a different level of quality, or suggest any of these actions as a consequence of exercising your rights.
To submit a CCPA request, contact us at [email protected]. We will verify your identity by matching the information you provide with the information in our records. You may also designate an authorized agent to make a request on your behalf, provided the agent presents a valid power of attorney or you provide written authorization and verify your own identity. We will respond to verified requests within forty-five (45) days as required by law.
9. International Data Transfers
The Services are operated from the United States. Our primary infrastructure is hosted in DigitalOcean’s NYC region data centers. If you access the Services from outside the United States, your personal data will be transferred to, stored, and processed in the United States, which may have data protection laws that are different from those in your country of residence.
For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to the United States, we rely on the European Commission’s Standard Contractual Clauses (SCCs) as adopted under Commission Implementing Decision (EU) 2021/914. These SCCs are incorporated into our Data Processing Agreements with customers and with our sub-processors. We have conducted Transfer Impact Assessments and implemented supplementary measures, including encryption in transit and at rest, to ensure that transferred data receives an adequate level of protection.
We do not currently offer data localization (hosting data exclusively within the EU or other specific regions). If data localization is a requirement for your organization, please contact [email protected] to discuss Enterprise plan options.
10. Cookies & Tracking Technologies
We use a minimal number of cookies and similar technologies, strictly limited to those necessary for the operation and security of the Services. We do not use any third-party advertising cookies, retargeting pixels, or behavioral tracking technologies.
- Session Cookies: Temporary cookies used to maintain your authenticated session on the developer dashboard. These cookies expire when you close your browser or after a period of inactivity.
- CSRF Protection Cookies: Security cookies used to prevent Cross-Site Request Forgery attacks on form submissions and API key management actions.
- Preference Cookies: Optional cookies that store your dashboard preferences, such as theme selection and default dashboard view.
We perform analytics through server-side request logging only. We do not use client-side analytics scripts such as Google Analytics, Facebook Pixel, or similar tracking technologies. Your cookie preferences are respected, and you may disable cookies through your browser settings, though this may affect the functionality of the developer dashboard.
11. Data Security
We implement industry-standard technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption in Transit: All communications between your applications and the SOSRoute API are encrypted using TLS 1.3. We enforce HTTPS on all endpoints and do not support unencrypted HTTP connections.
- Encryption at Rest: Data stored in our databases is encrypted at rest using AES-256 encryption. Database backups are also encrypted.
- API Key Security: API keys are stored as salted cryptographic hashes using bcrypt. We never store API keys in plaintext. API keys are displayed to you only once at the time of generation.
- Access Controls: We implement role-based access controls (RBAC) for all internal systems. Access to production infrastructure requires multi-factor authentication (MFA) and is restricted to authorized personnel on a need-to-know basis.
- Security Audits: We conduct regular internal security reviews and vulnerability assessments. Our infrastructure providers (DigitalOcean, Neon, Upstash) maintain SOC 2 Type II certifications.
- Incident Response: We maintain a documented incident response plan with defined roles, escalation procedures, and communication protocols for security events.
While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security but commit to promptly addressing any security incidents that may occur.
12. Children’s Privacy
The Services are not directed at individuals under the age of sixteen (16). We do not knowingly collect, solicit, or maintain personal information from children under 16 years of age. If we learn that we have collected personal information from a child under 16, we will promptly delete such information from our systems. If you believe that we have inadvertently collected personal information from a child under 16, please contact us immediately at [email protected].
We comply with the Children’s Online Privacy Protection Act (COPPA) and do not knowingly collect personal information from children under 13 years of age in the United States. Parents and guardians who believe their child has provided personal information to us may contact us to request deletion.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. If we make material changes, we will notify you via email to the address associated with your account at least thirty (30) days before the changes take effect. We will also update the “Last Updated” date at the top of this page.
Material changes include, but are not limited to: new categories of personal data collected, new purposes for processing, new third-party data sharing arrangements, or changes to your rights. We encourage you to review this Privacy Policy periodically. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. Previous versions of this policy are available upon request by contacting [email protected].
14. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within seventy-two (72) hours of becoming aware of the breach, as required by GDPR Article 33. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals without undue delay, as required by GDPR Article 34.
Our breach notification will include: the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, the measures taken or proposed to address the breach and mitigate adverse effects, and the contact details of our data protection point of contact. We maintain a breach register documenting all personal data breaches, regardless of whether they meet the notification threshold, including facts, effects, and remedial actions taken.
For U.S. state breach notification requirements, we will comply with the applicable notification timelines and requirements of all relevant state laws, including providing notification to state attorneys general where required.
15. Contact Information & Data Protection
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
- Privacy & Legal Inquiries: [email protected]
- Developer Support: [email protected]
- Company: Sandbox Synergy LLC, 6300 Riverside Plaza Ln., NW Ste 118, PMB 360597, Albuquerque, New Mexico 87120
- Website: sandboxsynergy.org
Sandbox Synergy LLC has designated a Data Protection Officer (DPO) who can be reached at [email protected] for all matters related to data protection and privacy. The DPO is responsible for overseeing our compliance with data protection laws, conducting data protection impact assessments, cooperating with supervisory authorities, and serving as the point of contact for data subjects exercising their rights.
For users in the European Economic Area, if you are unsatisfied with our handling of your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU data protection authorities is available at edpb.europa.eu.