Pumpy / Privacy
Privacy Policy
Your data, explained plainly.
Pumpy is operated by LilyBit. This policy explains what we collect, why we collect it, and what you can do about it. We aim to collect as little as possible and to use it only to run the service you ask for.
Last updated: 24 June 2026
Contact: hello@pumpy.uk
---
1. Who is responsible for your data?
For the purposes of UK data protection law, LilyBit is the data controller for personal data processed through Pumpy (the website at [app.pumpy.uk](https://app.pumpy.uk) and the Android app).
If you have questions about this policy or your data, email hello@pumpy.uk.
---
2. What we collect and why
| What | Why | Legal basis (UK GDPR) |
|------|-----|------------------------|
| Email address, display username, account settings | To create and run your account, sync favourites and preferences across devices | Contract (providing the service you signed up for) |
| Location (when you request it) | To show nearby fuel stations and to check price confirmations (see sections 3 and 4) | Contract / legitimate interest (delivering core app functionality) |
| Price confirmations (signed-in users) | To show community verification on station prices and maintain trust scores | Contract / legitimate interest (service improvement) |
| Push notification tokens (Firebase Cloud Messaging, Web Push) | To deliver price alerts you opt into | Consent (you enable alerts and notifications) |
| Email address (for alert emails) | To deliver price alert emails you opt into | Consent |
| Price alerts you create | To monitor stations and notify you when prices change | Contract |
| App activity and performance data (Google Analytics) | To understand how Pumpy is used and to fix bugs, improve speed, and improve features | Legitimate interest (improving the service) |
| Price discrepancy reports (signed-in users) | To correct station data and investigate reported issues | Legitimate interest / contract (service improvement) |
| IP address and User-Agent (via Firebase Authentication) | Security, fraud prevention, and abuse detection (collected automatically by Firebase when you sign in) | Legitimate interest (keeping accounts secure) |
| Subscription status (Pumpy Pro) | To provide paid features such as unlimited price alert stations | Contract |
We do not sell your personal data to third parties.
---
3. Location data
Pumpy uses location only when you ask it to.
- User-initiated only: We only read your device's location when you take a specific action, such as tapping the location icon in the search bar, searching for a place or postcode (which resolves to map coordinates), or submitting a price confirmation (see section 4).
- No background tracking: We do not track your location in the background.
- No location or search history: We do not keep a history of your locations or place searches on our servers. Coordinates are used for the request you made (for example, to load nearby stations or to check you are near a forecourt when confirming a price), then discarded. We do not build a trail of where you have been.
- No selling location data: We do not sell or share your location with advertisers. We do not retain location data for that purpose; it is used only for the immediate feature you requested and is not kept afterwards.
---
4. Price confirmations
Signed-in users can confirm that a fuel price shown in Pumpy matches what they saw at the forecourt.
- What you submit: The station, fuel type, and price you are confirming. We also receive your coordinates at the moment you submit, so we can check you are reasonably close to that station. Those coordinates are used for that check only and are not stored as a separate location history.
- What we store: Your account is linked to the confirmation so we can show a community count on the price and list confirming users by display username (see section 5). This helps other drivers see that a price has been checked recently.
- Trust scores: Confirmations may affect an internal trust score used to reduce abuse. We may flag or limit suspicious confirmation patterns.
---
5. Accounts and authentication
Optional accounts are provided through Firebase Authentication (Email/Password and Google Sign-In).
- Data we store: Your email address, display username, encrypted authentication credentials (managed by Firebase), synced preferences (such as fuel grade, search radius, and map display options), saved favourites, and price alerts you create.
- Display username: When you first sign up, we assign a unique default display name such as 'Driver_47332' (the word "Driver_" plus a random number). You can change it at any time at [app.pumpy.uk/account](https://app.pumpy.uk/account). Display names must be unique across Pumpy. Your display name may be visible to other users, for example when you confirm a fuel price (see section 4).
- Firebase security data: Firebase may automatically collect technical data such as your IP address and User-Agent string when you sign in. This is used by Firebase for security, abuse prevention, and service reliability. We do not use this data for advertising.
- Cloud favourites: Saved stations are stored in our secure cloud database so they are available when you sign in on another device.
- Guest use: If you do not create an account, most settings stay on your device and we do not build a personal profile on our servers.
---
6. Analytics
We use Google Analytics on both the web app and the Android app to collect app activity and performance information (for example, which screens are used, session duration, and crash-related performance signals).
This helps us understand whether features work, where users get stuck, and what to improve. We do not use Google Analytics to sell your data or to build advertising profiles inside Pumpy.
You can limit analytics on your device through your browser or OS privacy settings where available. On Android, Google may also provide device-level advertising/analytics controls separate from Pumpy.
---
7. Notifications (push and email)
You can opt in to fuel price alerts for stations you choose.
- Push notifications (Android): If you enable alerts with push notifications on Android, we collect and store a device push token via Firebase Cloud Messaging. We use this only to send alerts you requested.
- Web push notifications: On the web app, if you enable push alerts, we use your browser's Push API (a Web Push subscription created with your permission through the browser and our service worker). We store the subscription details needed to send alerts to that browser. We use this only for price alerts you requested.
- Email alerts: If you enable email alerts, we use your email address and our own backend mailer to send those messages.
- Opt out any time: You can turn off push notifications in your device or browser settings, or in Pumpy's alert preferences. You can turn off email alerts in the app or via the unsubscribe link in any alert email.
We do not use your alert contact details for unrelated marketing.
---
8. Price discrepancy reports
If you spot incorrect station data in Pumpy, signed-in users can submit a discrepancy report from the station page (for example, a price that does not match the forecourt board or an outdated facility).
Reports are sent to our servers and linked to your signed-in account so we can follow up if needed and reduce spam. We use the report details (station, issue type, prices or description you provide, and when you observed the issue) to investigate and improve our data.
---
9. Pumpy Pro subscriptions
If you subscribe to Pumpy Pro, payment and billing are handled by a third-party provider, not by Pumpy directly:
- Web: payments are processed by Stripe.
- Android: payments are processed by Google Play.
We receive subscription status, renewal dates, and related billing identifiers from that provider so we can unlock Pro features on your account. We never have access to or store your sensitive payment information, such as card details, on our servers.
---
10. How long we keep data
- Account data: Kept while your account is active.
- After deletion: When you delete your account (see section 11), we permanently remove your profile, settings, favourites, price alerts, and related data from our active databases, and we delete your Firebase authentication record.
- Analytics: Google Analytics retention is configured within Google's systems according to their policies and our configuration.
- Backups: Residual copies in encrypted backups may persist for a limited period before being overwritten.
---
11. Account deletion
You can delete your account at any time, with or without the app installed:
- In the app: Account settings → delete account.
- On the web: [https://app.pumpy.uk/account](https://app.pumpy.uk/account) (sign in, then use delete account).
Account deletion is permanent and irreversible. It removes your profile, settings, favourites, price alerts, and all other associated personal data we hold for your account, followed by removal of your authentication credentials from Firebase.
---
12. Security
We maintain robust technical and organisational safeguards to protect your data, including:
- Encryption in transit: Data is transmitted between your device and our servers over secure encrypted connections (HTTPS/TLS).
- Secure infrastructure: Data is stored on modern cloud infrastructure with access controls appropriate to the sensitivity of the data.
No method of transmission or storage is 100% secure, but we work to protect your information and to respond to incidents responsibly.
---
13. Your rights under UK GDPR
In the UK, you have rights including:
- Access: Request a copy of personal data we hold about you.
- Rectification: Ask us to correct inaccurate data.
- Erasure: Ask us to delete your data (account deletion in the app or on the web is the primary way to do this, however you may also contact us for assistance).
- Restriction: Ask us to limit how we use your data in certain circumstances.
- Objection: Object to processing based on legitimate interests (including analytics where applicable).
- Data portability: Request a copy of certain data in a portable format where technically feasible.
- Withdraw consent: Where we rely on consent (for example alert notifications), you can withdraw it at any time without affecting the lawfulness of earlier processing.
To exercise these rights, contact hello@pumpy.uk. You also have the right to complain to the Information Commissioner's Office (ICO) in the UK if you believe we have handled your data unlawfully.
---
14. International transfers
Some service providers (including Google/Firebase and Stripe) may process data outside the UK. Where this happens, we rely on appropriate safeguards recognised under UK law (such as standard contractual clauses or UK extension mechanisms) as provided by those vendors.
---
15. Children
Pumpy is intended for adult motorists. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will take steps to delete it.
---
16. Changes to this policy
We may update this policy from time to time. The current version will always be available in the app and on our website, with the "Last updated" date shown.
---
17. Contact
hello@pumpy.uk
---
Last updated: 24 June 2026