Privacy Statement

🗺️ HK Utility Map

Privacy Statement

"HK Utility Map" is a free public tool. There is no account, no login, and we never ask for your name, phone number or email address. This page sets out, item by item, what stays on your device, what reaches our server, what is passed to third parties, and how to remove it.

Last updated: 2026-09-15. This statement also covers the network features of the Android app "Hop In 車埋我", in its own section below.

1. What stays on your device

All of the following is kept in your browser’s localStorage. None of it is transmitted to us or to anyone else, and clearing your browser data removes it immediately.

KeyWhat it is for
hkum_langinterface language
hkum_layers2 · hkum_recent_layers · hkum_layers_seenwhich layers you switched on, and the ones you used most recently
hkum_last_loc · hkum_last_nearbythe last point you looked up and its results (kept 24 hours), so the next visit shows something immediately instead of waiting for location
hkum_saved_locslocations you saved yourself (up to 30)
hkum_saved_spotsfacilities you starred (up to 50)
hkum_transit_pinsthe departures you pinned
hkum_open · hkum_taxitype · hkum_evspeed · hkum_routetab · hkum_recyclemat · hkum_leftfilter and interface choices (including whether you collapsed the left panel)
hkum_onboarded · hkum_coach_seen · hkum_od_hint_seenwhich one-off hints you have already seen
hkum_pushwhether you turned weather alerts on

2. Your location

We receive your coordinates only when you tap "use my location" or allow your browser to share it. They go to our server to find nearby facilities and to compute routes and fares. They are not written to any database and are not linked to any identity. You can skip location entirely — typing an address or landmark works just as well.

To be straightforward about one thing: like every website, our host (Google Cloud Run) and Cloudflare keep standard server logs. Those include the request URL — and therefore the coordinates you looked up — along with your IP address, timestamp and browser type. They are retained for the providers’ default periods and we do not use them to analyse individual users.

3. Analytics (Google Analytics)

We use Google Analytics 4 to see aggregate usage — which layers get switched on, which pages get read. Event names come from a fixed list and never carry free text. Before anything is sent, these parameters are stripped from the page URL: lat, lng, q, name, a, b, pin — so your coordinates, your search text, place names and route endpoints never reach Google Analytics. Google sets its own cookies for analytics; browser settings or a content blocker will stop them.

4. The little we do store

Apart from the open data itself, our database holds only these four kinds of record:

  • Facility reports — only what you submit when you tap "report": the facility name and coordinates, the issue type, your optional note, the interface language, your browser user-agent, the reCAPTCHA score, and a daily-rotating hash of your IP address used to stop abuse, not to identify you. The raw IP is not stored.
  • Route-choice measurement — when you pick one of the suggested routes we record the date, time band, weekday/weekend, which position you chose, the mode, how many minutes slower it was than the fastest, and a daily-rotating IP hash. Origin, destination, your search text and any string returned by Google are deliberately never recorded. The journey itself is represented only by a one-way hash, computed from the government stop ids along it — or, where no stop resolves, from a roughly 110 m coordinate cell. The hash cannot be turned back into an address.
  • Layer usage counts — plain counters of how many times each layer was switched on, with no identifier attached, used to decide the order of the categories in the interface.
  • Weather alert subscriptions — if you turn on severe-weather alerts, your browser generates a push endpoint and two encryption keys, stored with your language setting. Delivery goes through your browser vendor2019s push service (Google for Chrome, Mozilla for Firefox), so that service knows a notification was sent to your device. Turning the alerts off deletes the subscription.

5. Third parties

Opening this site makes your browser connect directly to the hosts below. "Directly" means each of them sees your IP address and browser details, whether or not we send them anything ourselves:

  • Google Maps (maps.googleapis.com, maps.gstatic.com) — map tiles and place search, governed by Google’s privacy policy.
  • Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — the Chinese interface typeface. Fonts are part of rendering the page, so there is no switch to turn this off; blocking it needs a browser extension.
  • jsDelivr (cdn.jsdelivr.net) — the seven-segment font for the taxi meter display, loaded only if you open the taxi panel.
  • Google Analytics (googletagmanager.com, google-analytics.com) — see the previous section.
  • reCAPTCHA (google.com/recaptcha) — loaded only when you open the report form, to tell people from bots.
  • Cloudflare — content delivery and protection; every request passes through it.

Several further kinds of call do not expose your IP, because our server makes them on your behalf:

  • Google Directions / Places — routes are looked up by coordinates; place names and the address check by the text you typed (the address check asks Google only when the government ALS is unsure). Google receives that text or those coordinates, but not your IP address.
  • Hong Kong Government Address Lookup Service (ALS, als.gov.hk) — when you type an address to search, or use the address check, the text you typed (for the address check, after we tidy it: unit and floor removed, abbreviations expanded) is sent to the government’s address service to be turned into coordinates and a canonical address. It is a Hong Kong Government service, but it is still a third party, so it is named here. Hop In route planning uses the same path when given an address rather than coordinates.
  • Government and operator sources — toilets, fares, weather and live departures are fetched by our server, on a schedule or on demand, with none of your data involved.

We do not sell, rent or trade any data, we show no advertising, and we build no user profiles.

6. Where the data is held, and for how long

The service runs on Google Cloud Run and Cloud SQL in asia-southeast1 (Singapore), which means the records described above and the server logs are processed and stored outside Hong Kong. Cloudflare additionally caches public pages at edge locations worldwide; those caches hold no personal data.

  • Facility reports — kept indefinitely, because they are what we check the data against; you can ask for one to be deleted.
  • Route choices and layer counts — statistics by construction, with no identity attached; the IP hash rotates daily, so yesterday’s cannot be matched to today’s.
  • Hop In live shares — the link expires after 12 hours and the record is purged within 2 days of creation.
  • Hop In trip records — kept indefinitely; deletable on request using your install id.
  • Server logs — retained for Google’s and Cloudflare’s default periods, which we do not control.

This site is also an installable web app (PWA). A service worker caches pages and your last result on your device so it still works offline. That cache lives on your device and is removed when you clear site data or uninstall.

7. Hop In 車埋我 (Android app)

"Hop In 車埋我" is a taxi-meter simulator. By default everything stays on your phone — trips, routes and fare calculations are all handled locally and nothing is uploaded. Only these three features use the network: you switch the first two on yourself, and the third runs only when you ask it to plan a route:

7.1 Sharing trip data (opt-in)

With it on, one record is sent when a trip ends: a randomly generated install id (a UUID unrelated to you, replaced if you reinstall), the app version, the phone model, the tariff used, start and end times, distance, waiting time, total fare, the number of GPS points, and start and end coordinates rounded to three decimal places (about 100 m).

Please note in particular: if you choose in the app to include the route, this record also carries the actual GPS trail you drove (up to 3000 points, and not rounded the way the start and end points are). A trail shows where you went and which roads you took. Turn that option off in the app if you do not want it uploaded; anything already uploaded can be deleted on request using your install id.

These records are read only in aggregate; no individual trip is published.

7.2 Live meter sharing (opt-in)

Tapping "share" creates a link that anyone you send it to can open in a browser to watch the meter run. While it is live, the phone uploads the meter state (fare, distance, waiting time, status) every 5 seconds, optionally with the recent trail. The share token is stored only as a sha256 hash, so not even we can read it back. You can end the share at any time; the link expires automatically after 12 hours, and the record is purged within 2 days of being created. Note that the link has no password — anyone who has it can watch while it is live.

7.3 Route planning

When you enter a start and end point in the app to estimate a fare, those two places — coordinates, or the address text you typed — are sent to our server: an address goes through the government ALS to become coordinates, then we ask Google Directions for the drive on your behalf and return the distance, duration, tolled tunnels and a simplified route line. None of this is written to the database; it is held in the server’s memory for 30 minutes to avoid paying for the same lookup twice, and is gone on restart.

As with the website, the request URL — and therefore those two places — appears in our host’s server logs. If you would rather it did not, use the meter in the app without route planning.

Switching any of these off stops further data being sent. To delete trip records already sent, contact us using the details below with the install id shown on the app’s About screen, and we will delete every record carrying it.

8. Your rights

Under the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) you have the right to request access to, and correction of, personal data we hold about you. Because this site collects no name, email or account, we normally hold nothing that can be matched to you. The Hop In install id is the one exception, and you can use it to request deletion.

9. Children

This tool is not designed for children and we do not knowingly collect data from them.

10. Contact and changes

For any privacy question, or to ask us to delete Hop In records, use the "report" button on any facility on the map and write your request in the note. If this statement changes, the date at the top changes with it; anything substantive will be announced on the site.

香港地圖 Map of Hong Kong © OpenStreetMap contributors