# London Cycle Finder — Privacy Policy _Last updated: 14 June 2026_ London Cycle Finder is a Garmin watch app that shows the nearest Santander Cycles docking stations to your current location, with live bike and dock counts and the direction to each. This policy explains exactly what data the app handles and what it does not. In short: the app sends your current GPS position to its backend so it can work out which docking stations are closest to you. That position is used only to answer that one request and is never stored, logged, or shared. ## Who is responsible This app and its backend are operated by an independent developer ("we", "us"). It is an unofficial app and is **not** affiliated with, endorsed by, or operated by Transport for London (TfL), Santander, or Garmin. ## What the app processes When you open the app and your watch has a GPS fix, it sends your current **latitude and longitude** to the backend at `https://london-cycle-finder.labs.0x6a74.dev`. The backend uses those coordinates to rank nearby docking stations by distance and returns the closest few, along with their publicly available bike and dock counts. That GPS position is the **only** piece of personal information the app transmits. ## What the app does NOT collect The app does not collect, request, or transmit any of the following: - Your name or email address, as the app has no login and no account functionality - Cookies or any tracking or analytics identifiers - Contacts, messages, photos, or files - Health, fitness, or activity data - Any history of where you have been Your watch sends nothing but the latitude and longitude of your current position, and only while the app is open. ## How your location is used and retained Your coordinates are used **solely** to compute the docking stations nearest to you for the request you just made. They are held in memory only for the moment it takes to answer that request and are then discarded. Your coordinates are **not** written to any database, **not** written to any log, and **not** retained after the response is sent. Because nothing is stored, there is no location history associated with you or your device. ## Your location is not shared with TfL Live bike and dock availability comes from TfL's public Santander Cycles ("BikePoint") data feed. The backend fetches the full public list of docking stations from TfL and works out which are closest to you **itself** — your coordinates are never sent to TfL or to any other third party. ## Infrastructure and network providers - **Amazon Web Services (AWS):** the backend runs on AWS (API Gateway and Lambda) in the London (`eu-west-2`) region. Your request passes through AWS in order to reach the backend. The application does not store or log your coordinates; see the [AWS Privacy Notice](https://aws.amazon.com/privacy/). - **Garmin:** network requests from the watch are delivered via your paired phone and Garmin's Connect IQ networking. Their handling of that traffic is governed by the [Garmin Privacy Policy](https://www.garmin.com/privacy/). ## IP address As with any request over the internet, the backend's network layer receives the IP address of the connecting device. This is an unavoidable part of how HTTP works. The application does not log, store, or use that IP address to identify or track you. ## User agent The backend logs the "user agent" string sent with each request — basic technical information about the app and device making the request. It is kept for diagnostics and is not used to identify or track you. ## Data security All communication between the watch and the backend uses HTTPS (TLS 1.2 or later). ## Your rights This policy is provided with UK and EU data protection law in mind. Because the app does not store any personal data, there is no stored location data to access, correct, export, or erase. ## Children The app is not directed at children and does not knowingly process data from children. ## Changes to this policy If this policy changes, the updated version will be published at this same address with a new "Last updated" date. ## Contact Questions about this policy or the app's data handling: `contact@0x6a74.dev`