Privacy Policy

Last Updated: July 14, 2026  |  Effective Date: July 14, 2026

1. Introduction & Scope

Sandbox Synergy LLC (“Company,” “We,” “Us,” or “Our”), a New Mexico limited liability company, operates the SOSRoute API platform at sosroute.dev. This Privacy Policy describes how we collect, use, share, retain, and protect personal information when you access or use our API, developer dashboard, documentation, and related services (collectively, the “Services”).

This policy applies to all individuals who interact with the Services, including account holders, developers integrating our API, and visitors to our website. It is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and the California Online Privacy Protection Act (CalOPPA). We are committed to protecting your privacy and handling your personal information with transparency and care.

By creating an account, using our API, or otherwise interacting with the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use the Services. This Privacy Policy should be read in conjunction with our Terms of Service and Data Processing Agreement.

2. Information We Collect

2.1 Account Information

When you register for an account, we collect the following personal information: your full name, email address, company or organization name (if applicable), and job title (optional). This information is necessary to create and manage your account, issue API keys, and communicate with you about the Services. We may also collect your billing address if you subscribe to a paid plan.

2.2 API Usage Data

We automatically collect data about your use of the API, including: the endpoints you access, the number of API calls made, timestamps of requests, HTTP methods used, response status codes, response times, rate limit consumption, and error details. This usage data is collected to enforce rate limits, monitor service health, detect abuse, generate analytics dashboards, and improve the Services. API request and response bodies are not logged or retained except in transient memory during request processing.

2.3 Payment Information

All payment processing is handled by Stripe, Inc. When you subscribe to a paid plan, your credit card number, expiration date, and CVC are transmitted directly to Stripe via their secure payment form and are never stored on our servers. We retain only the Stripe customer identifier, subscription status, plan type, billing cycle dates, and invoice history. Stripe’s handling of your payment data is governed by Stripe’s Privacy Policy. Stripe is PCI DSS Level 1 certified.

2.4 Device & Browser Information

When you access the developer dashboard or website, we may automatically collect technical information including your browser type and version, operating system, device type, screen resolution, referring URL, and pages visited. This information is collected through standard server logs and is used for security monitoring, troubleshooting, and improving the user experience of our web interfaces.

2.5 Location Data

The SOSRoute API processes geographic coordinates (latitude and longitude) submitted by your application on behalf of your end users to provide location-relevant safety data, risk scores, and nearest-facility lookups. We do not store end-user location data beyond the transient processing of each API request. Location coordinates are used solely to resolve the relevant API response and are not logged, retained, or associated with identifiable individuals. Your application is responsible for obtaining appropriate consent from your end users before transmitting their location data to the API.

2.6 IP Addresses

We collect IP addresses of API requests and dashboard sessions for the purposes of rate limiting, security monitoring, abuse prevention, and geographic usage analytics. IP addresses in API logs are retained for ninety (90) days and then automatically purged. We do not use IP addresses to identify individual end users of your applications.

3. How We Use Information

We use the information we collect for the following purposes:

4. Legal Bases for Processing (GDPR)

For users located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process personal data based on the following legal grounds as required by the General Data Protection Regulation:

5. Data Sharing & Third-Party Processors

We share personal data with the following categories of third-party service providers, each of which is contractually bound to process data only on our instructions and to maintain appropriate security measures. We have executed Data Processing Agreements with each sub-processor.

We do not sell, rent, lease, or trade your personal information to any third party. We do not share personal data with data brokers, advertising networks, or any entity for purposes unrelated to providing the Services. We may disclose personal information if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Company, our users, or the public.

6. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are as follows:

7. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation with respect to your personal data:

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within thirty (30) days as required by the GDPR. We may need to verify your identity before processing your request. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

8. Your Rights Under CCPA

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with the following rights:

To submit a CCPA request, contact us at [email protected]. We will verify your identity by matching the information you provide with the information in our records. You may also designate an authorized agent to make a request on your behalf, provided the agent presents a valid power of attorney or you provide written authorization and verify your own identity. We will respond to verified requests within forty-five (45) days as required by law.

9. International Data Transfers

The Services are operated from the United States. Our primary infrastructure is hosted in DigitalOcean’s NYC region data centers. If you access the Services from outside the United States, your personal data will be transferred to, stored, and processed in the United States, which may have data protection laws that are different from those in your country of residence.

For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to the United States, we rely on the European Commission’s Standard Contractual Clauses (SCCs) as adopted under Commission Implementing Decision (EU) 2021/914. These SCCs are incorporated into our Data Processing Agreements with customers and with our sub-processors. We have conducted Transfer Impact Assessments and implemented supplementary measures, including encryption in transit and at rest, to ensure that transferred data receives an adequate level of protection.

We do not currently offer data localization (hosting data exclusively within the EU or other specific regions). If data localization is a requirement for your organization, please contact [email protected] to discuss Enterprise plan options.

10. Cookies & Tracking Technologies

We use a minimal number of cookies and similar technologies, strictly limited to those necessary for the operation and security of the Services. We do not use any third-party advertising cookies, retargeting pixels, or behavioral tracking technologies.

We perform analytics through server-side request logging only. We do not use client-side analytics scripts such as Google Analytics, Facebook Pixel, or similar tracking technologies. Your cookie preferences are respected, and you may disable cookies through your browser settings, though this may affect the functionality of the developer dashboard.

11. Data Security

We implement industry-standard technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security but commit to promptly addressing any security incidents that may occur.

12. Children’s Privacy

The Services are not directed at individuals under the age of sixteen (16). We do not knowingly collect, solicit, or maintain personal information from children under 16 years of age. If we learn that we have collected personal information from a child under 16, we will promptly delete such information from our systems. If you believe that we have inadvertently collected personal information from a child under 16, please contact us immediately at [email protected].

We comply with the Children’s Online Privacy Protection Act (COPPA) and do not knowingly collect personal information from children under 13 years of age in the United States. Parents and guardians who believe their child has provided personal information to us may contact us to request deletion.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. If we make material changes, we will notify you via email to the address associated with your account at least thirty (30) days before the changes take effect. We will also update the “Last Updated” date at the top of this page.

Material changes include, but are not limited to: new categories of personal data collected, new purposes for processing, new third-party data sharing arrangements, or changes to your rights. We encourage you to review this Privacy Policy periodically. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. Previous versions of this policy are available upon request by contacting [email protected].

14. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within seventy-two (72) hours of becoming aware of the breach, as required by GDPR Article 33. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals without undue delay, as required by GDPR Article 34.

Our breach notification will include: the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, the measures taken or proposed to address the breach and mitigate adverse effects, and the contact details of our data protection point of contact. We maintain a breach register documenting all personal data breaches, regardless of whether they meet the notification threshold, including facts, effects, and remedial actions taken.

For U.S. state breach notification requirements, we will comply with the applicable notification timelines and requirements of all relevant state laws, including providing notification to state attorneys general where required.

15. Contact Information & Data Protection

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

Sandbox Synergy LLC has designated a Data Protection Officer (DPO) who can be reached at [email protected] for all matters related to data protection and privacy. The DPO is responsible for overseeing our compliance with data protection laws, conducting data protection impact assessments, cooperating with supervisory authorities, and serving as the point of contact for data subjects exercising their rights.

For users in the European Economic Area, if you are unsatisfied with our handling of your privacy concerns, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU data protection authorities is available at edpb.europa.eu.