TrailyMap

Privacy Policy

Version 2026-07-29 · Effective 29 July 2026 · TrailyMap

This policy explains what personal data the TrailyMap mobile application and the trailymap.lat website collect, why, how long it is kept, and what you can do about it. We have tried to describe only what the service actually does — if something is not listed here, we do not do it.

1. Who is responsible

Your personal data is processed by the operator of TrailyMap (“we”, “us”). Our servers are located in France. For all data matters contact info@trailymap.lat.

For any question about this policy or your data, write to info@trailymap.lat.

2. What we collect

2.1 Account data

DataWhyRequired?
Email addressIdentifies your account, password recovery, service noticesYes
PasswordAuthentication. Stored only as a salted hash — we cannot read itYes
Display nameShown in the appNo
Language, unitsApp preferencesNo
Profile photoShown in the app. Location metadata (EXIF) is stripped on uploadNo

2.2 Location

We treat location in two clearly separate ways.

Finding routes near you. When you search for routes nearby, your device sends its position to us so we can return matching routes. This position is used for that request and is not stored. It is never written to our database and never used for advertising.

Advertising and audience measurement. Only if you switch on personalised advertising, we store an approximate location: before saving, we round the coordinates to roughly one kilometre and keep the nearest known city and country. We deliberately do not keep a precise position, and we do not keep a history of your movements at street level.

2.3 Records of your consent

When you accept this policy or change your advertising preference, we record the fact, the time, the document version, your IP address, your device’s user-agent string and (on iOS) the tracking-permission status reported by the system. We keep this so we can show, if asked, that a choice was actually made — including your choice to say no.

2.4 Push notifications

If you enable notifications, we store the push token issued by Apple or Google, the platform, app version and device language. Removing the app or signing out removes the token.

2.5 Technical data

Our servers keep short-lived request logs (IP address, time, requested address, response code, user-agent) for security and troubleshooting. These are not used to build a profile of you.

2.6 What we do not collect

3. Why we use it

PurposeData used
Providing the service — account, routes, favourites, settingsAccount data, transient location
Security, abuse prevention, rate limitingTechnical data
Service messages (email confirmation, password reset)Email address
Personalised advertising and audience measurementApproximate location, city, country — only with consent
Push notifications you asked forPush token, preferences
Demonstrating that consent was given or withdrawnConsent records

Where the law requires a legal basis, we rely on performance of our contract with you for the service itself, on your consent for advertising and notifications, and on our legitimate interest in keeping the service secure.

4. Who else sees your data

We do not sell your personal data. We share it only with parties that help us run the service:

Route descriptions, tracks and photos in the catalogue are aggregated from publicly available open sources and third-party content published on the internet (map data includes © OpenStreetMap contributors). Browsing the catalogue does not send your identity to those sources.

5. Where your data is processed

Our servers are located in France (European Union), so your data is processed under the EU General Data Protection Regulation (GDPR). If you use the app from another country, your data will be transferred to the EU. We apply the protections described in this policy regardless of where you are.

6. How long we keep it

DataRetention
Account and profileUntil you delete your account
Approximate location90 days, then deleted automatically
Consent recordsWhile the account exists, then deleted with it
Push tokensUntil you sign out or disable notifications
Server request logs (incl. IP)Up to 90 days, for security purposes

After an account is permanently deleted, residual copies may persist in our encrypted backups for up to 30 days before those backups are rotated out.

7. Your choices

These are the controls the app really provides today:

Because your data is processed in the EU, you additionally have the GDPR rights of access, rectification, erasure, restriction of processing, data portability and objection (Articles 15–21), and the right to withdraw consent at any time without affecting prior processing. To exercise any of them, write to info@trailymap.lat — we will respond within a reasonable period. You also have the right to lodge a complaint with a supervisory authority; for our processing that is the French CNIL (cnil.fr), or the authority of your own country of residence.

8. Children

The service is not directed to children and we do not knowingly collect their data. If you believe a child has provided us with personal data, contact us and we will delete it.

9. Security

Traffic between the app and our servers is encrypted with TLS. Passwords are stored only as salted hashes. Access to production systems is restricted. Location data is deliberately stored at reduced precision, so that even in the worst case it cannot reveal where exactly you were.

No system is perfectly secure, and we cannot guarantee absolute security.

10. Changes

If we change this policy in a way that affects you, we will publish the new version here with a new version number and, where the change is significant, ask you to review it in the app. Continuing to use the service after a change means you accept the updated policy.

11. Contact

info@trailymap.lat