BorderETA
Privacy Policy
BorderETA · Last updated: August 2, 2026
BorderETA is a border wait time intelligence app for crossings between the United States and Mexico. We collect only what we need to provide accurate crossing information and to improve our wait-time estimates over time. We do not sell your personal data.
This policy describes what we collect, how we use it, who we share it with, and the choices you have.
1. Who We Are
BorderETA ("we," "our," or "us") is operated by Jonathan Kim (sole proprietor) doing business as BorderETA. You can contact us at support@bordereta.live.
2. Information We Collect
2.1 Information You Provide Directly
- Account information. Email address and password when you create an account. Passwords are stored hashed by our authentication provider; we never see them in plaintext. You may instead create or access your account using Sign in with Apple or Sign in with Google; in that case we receive from the provider the email address for your account (for Apple, this may be a private relay address if you choose to hide your email) and a provider account identifier used to recognize you when you return. Apple's prompt may ask whether to share your name; we do not store your name.
- Community reports. Wait times, lane conditions, and optional notes you submit through the app.
2.2 Information Collected Automatically
- Device location (GPS). Location access is optional — the app is fully functional on the official crossing feed without it. When you grant location permission, we use it in two ways. While the app is open, we use your foreground location to calculate drive time to a bridge; to limit repeated calls to our drive-time provider, we cache an approximate location key (rounded to roughly 100 meters) per user per bridge per day, associated with your account and deleted when you delete your account. If you also enable background ("Always") location, the app registers two geofence rings around each bridge. An inner ring of approximately 500 meters wakes the app on enter and on exit, and is what writes the crossing record described above. An outer ring of approximately 1200 meters wakes the app on enter only, and is used to enable in-app features like the "are you in line?" prompt. The outer ring does not write any record to our servers. We do not continuously track your location or record your movements between crossings. You can revoke location permission at any time in your device settings. If you confirm you are in line while using in-app navigation, we record how far you are from the crossing zone (a distance, not your location) to improve our wait-time accuracy.
- Active in-app navigation. When you start navigation to a bridge, the app reads your device location continuously while the navigation screen is open. This is used to draw your live position on the map, follow the route, grey out the segments you've already driven, and prompt you if you appear to be stationary near the bridge. The live stream stops the moment you leave the navigation screen or background the app. None of the coordinates from this stream are written to our servers; they live only in app memory for the duration of the trip.
- Crossing dwell time. When background location is enabled, entering and leaving a crossing produces a crossing record: the time you appear to enter and exit the queue (the difference is your dwell time), the port of entry, and the lane (you may be asked to confirm which lane you used). These records are saved to your account so you can view them in your crossing history in the Activity tab in the app. They are also used, in anonymized form, to improve our wait-time prediction model over time. Your crossing data is not shown to other users. To stop this collection, revoke location permission in your device settings.
- Usage data. Which ports and lanes you view, app version, language preference, and basic interaction events (such as opening a bridge's details or switching crossing direction). We collect this through PostHog, a product analytics service, so we can understand which features users find useful and where the app needs improvement. Events are associated with an anonymous device identifier until you sign in, at which point they are linked to your account. We never send your password to PostHog. After you sign in, we send PostHog your account ID so we can tie events to your account, and your email address as a separate property so we can reach you about account issues. Before sign-in, events are recorded against an anonymous device ID with no email attached. The app also automatically collects crash and error diagnostic data — including the error type, stack trace, and device and OS context — through PostHog, our analytics provider, so we can identify and fix bugs. This diagnostic data is not used for advertising.
- Push notification tokens. When you opt into notifications, your device-issued push token is provided to OneSignal so we can deliver wait-time alerts you configure and ask you to confirm the lane of a recent crossing. You can disable notifications at any time in your device settings or in-app.
- IP address. Collected automatically when you use the service. We use it for rate-limiting, abuse prevention, and security; for rate-limiting it is stored in hashed form, and it may also appear in our server logs.
2.3 Information We Do Not Collect
- We do not continuously track your location. Background location wakes the app only when you enter or leave a border crossing — it does not record where you go between crossings or build a continuous location trail.
- We do not access your contacts, photos, microphone, or camera.
- We do not build advertising profiles or sell your data to advertisers.
- We do not track you across other apps or websites.
3. How We Use Your Information
- To display real-time and predicted border wait times.
- To calculate drive time from your current location to a crossing, when you grant location permission.
- To send push notifications for wait-time alerts you configure.
- To improve our machine learning prediction model using crossing dwell time data and community reports.
- To diagnose problems and improve app performance.
- To communicate with you about your account (password resets, email verification, security notifications, and material changes to our terms or privacy practices).
- Destination search and crossing ranking. When you type a destination into the picker, the destination text is sent to our geocoding provider, optionally with your current location as a proximity hint to bias nearby results. When you ask the app to rank the five bridges by total travel time, your starting location, destination, lane, and direction are sent to our crossing-ranking service, which uses them to compute drive times to each bridge and pick the fastest.
4. Legal Basis for Processing (GDPR and Applicable Law)
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with similar laws, we rely on the following legal bases:
- Contract performance — for account data and providing the service you signed up for.
- Legitimate interests — for app improvement, fraud prevention, and aggregate analytics that do not identify you.
- Consent — for location access (including background location used to improve our wait-time estimates), push notifications, and any other permissions you grant. You may withdraw consent at any time by revoking the relevant permission in your device settings.
5. Service Providers and Sub-Processors
We share data only with the service providers listed below, solely to operate BorderETA. These providers act under contract and may not use your data for their own purposes.
We also retrieve public data from the U.S. Customs and Border Protection wait time feed (bwt.cbp.gov) and publicly available southbound wait-time sources. These are read-only, public data sources; we do not share user information with them.
We do not share your personal information with any other third parties. We do not sell your data.
6. Community Reports and Crossing Data
Community reports you submit (wait times, conditions, optional notes) are visible to other app users. Your account identity is not displayed publicly — reports appear without your name or email attached.
Crossing dwell time records are anonymized and used to train our wait-time prediction model, improving its accuracy over time. They are not displayed to other users.
We may publish or license aggregated, anonymized insights derived from this data — for example, average wait times by hour, day of week, or season — including to commercial partners as part of our business offering. These aggregated datasets contain no personally identifiable information.
We do not attempt to re-identify individuals from aggregated or de-identified data, and we do not sell or license any data that is linked to an individual user. Any commercial data offering is limited to aggregated, de-identified statistics.
7. Data Retention
- Account data is retained for the life of your account and deleted within 30 days of account deletion.
- Community reports are automatically deleted 90 days after they are submitted.
- Crossing dwell time records linked to your account are retained for as long as your account is active and are deleted when you delete your account. Aggregated, anonymized data already derived from crossing records — used in model training or in licensed aggregate insights — is not linked to your identity and may be retained after account deletion.
- Push notification tokens are deleted when you uninstall the app or revoke notification permission.
- Webhook event records and other operational logs are retained for up to 12 months for security and audit purposes. Drive-time request logs include the requesting account's user ID in plain text for debugging. These logs are retained on a rolling 30-day window and are not used for analytics or shared externally.
- Queue calibration records. Distance-only measurements (no raw coordinates) describing how far past the bridge geofence ring you were when you confirmed you were in line. Retained for model calibration until you delete your account.
8. Your Rights and Choices
You have the following rights with respect to your personal data:
- Access and portability. You may request a copy of your personal data by emailing support@bordereta.live.
- Correction. You may update your account email at any time in Settings.
- Deletion. You may delete your account in the app: go to the Account tab, tap your profile at the top, then tap Delete account. This permanently removes your account, your reports, your alert configurations, and your crossing history.
- Location permissions. Revoke at any time via iOS Settings → BorderETA → Location, or Android Settings → Apps → BorderETA → Permissions. Setting location to "While Using" (instead of "Always") keeps drive-time calculations while stopping background crossing detection; revoking location entirely stops both, along with crossing dwell time collection used to improve our estimates.
- Push notifications. Disable at any time via your device's notification settings or in-app under Alerts.
If you are located in the EEA or UK, you also have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights have been violated.
To exercise any right, email us at support@bordereta.live. We will respond within 30 days.
9. California Residents (CCPA / CPRA)
If you are a California resident, you have the right to know what personal information we collect, to request deletion of your information, to correct inaccurate information, and to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. The aggregated insights we may license to commercial partners are de-identified and contain no personal information. To exercise your rights, email us at support@bordereta.live.
10. Children's Privacy
BorderETA is not directed to children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal information, contact us at support@bordereta.live and we will delete it promptly.
11. Data Security
We use industry-standard security measures including TLS encryption in transit, encryption at rest for sensitive data, row-level security in our database, and strict access controls on our internal systems. Passwords are hashed and never stored in plaintext. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
12. International Users
BorderETA is operated from the United States. If you use the app from Mexico or another country, your information will be transferred to and processed in the United States, where data protection laws may differ from your home country. By using the app, you consent to this transfer.
13. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will notify you via in-app banner, push notification, or email before the changes take effect. The "Last updated" date at the top of this policy reflects the most recent revision. Continued use of BorderETA after the effective date of an updated policy constitutes acceptance of the changes.
14. Contact Us
Questions about this policy or your data: