Privacy Policy
This policy explains what personal data the TrailyMap mobile application and
the trailymap.lat website collect, why, how long it is kept, and
what you can do about it. We have tried to describe only what the service
actually does — if something is not listed here, we do not do it.
1. Who is responsible
Your personal data is processed by the operator of TrailyMap (“we”, “us”). Our servers are located in France. For all data matters contact info@trailymap.lat.
For any question about this policy or your data, write to info@trailymap.lat.
2. What we collect
2.1 Account data
| Data | Why | Required? |
|---|---|---|
| Email address | Identifies your account, password recovery, service notices | Yes |
| Password | Authentication. Stored only as a salted hash — we cannot read it | Yes |
| Display name | Shown in the app | No |
| Language, units | App preferences | No |
| Profile photo | Shown in the app. Location metadata (EXIF) is stripped on upload | No |
2.2 Location
We treat location in two clearly separate ways.
Finding routes near you. When you search for routes nearby, your device sends its position to us so we can return matching routes. This position is used for that request and is not stored. It is never written to our database and never used for advertising.
Advertising and audience measurement. Only if you switch on personalised advertising, we store an approximate location: before saving, we round the coordinates to roughly one kilometre and keep the nearest known city and country. We deliberately do not keep a precise position, and we do not keep a history of your movements at street level.
- Turned off by default. Nothing is stored until you agree.
- On iOS, this is additionally governed by Apple’s App Tracking Transparency prompt. If you decline there, we do not collect it, even if a setting inside the app says otherwise.
- Kept for 90 days, then deleted automatically.
- You can erase all of it at any moment: Settings → Privacy → “Delete my location data”.
2.3 Records of your consent
When you accept this policy or change your advertising preference, we record the fact, the time, the document version, your IP address, your device’s user-agent string and (on iOS) the tracking-permission status reported by the system. We keep this so we can show, if asked, that a choice was actually made — including your choice to say no.
2.4 Push notifications
If you enable notifications, we store the push token issued by Apple or Google, the platform, app version and device language. Removing the app or signing out removes the token.
2.5 Technical data
Our servers keep short-lived request logs (IP address, time, requested address, response code, user-agent) for security and troubleshooting. These are not used to build a profile of you.
2.6 What we do not collect
- We do not ask for or store payment card details. Purchases are handled entirely by Apple or Google — we only learn whether a subscription is active.
- We do not collect your contacts, calendar, photos library, microphone or health data.
- We do not use third-party advertising SDKs that read your advertising identifier (IDFA). If that ever changes, this policy will be updated before it happens.
- We do not knowingly collect data from children (see §8).
3. Why we use it
| Purpose | Data used |
|---|---|
| Providing the service — account, routes, favourites, settings | Account data, transient location |
| Security, abuse prevention, rate limiting | Technical data |
| Service messages (email confirmation, password reset) | Email address |
| Personalised advertising and audience measurement | Approximate location, city, country — only with consent |
| Push notifications you asked for | Push token, preferences |
| Demonstrating that consent was given or withdrawn | Consent records |
Where the law requires a legal basis, we rely on performance of our contract with you for the service itself, on your consent for advertising and notifications, and on our legitimate interest in keeping the service secure.
4. Who else sees your data
We do not sell your personal data. We share it only with parties that help us run the service:
- Hosting provider — stores our database and files.
- Apple / Google — sign-in, subscriptions and push delivery. They act under their own privacy policies.
- Email delivery provider — sends confirmation and password reset messages.
- Authorities — only where we are legally obliged, and only to the extent required.
Route descriptions, tracks and photos in the catalogue are aggregated from publicly available open sources and third-party content published on the internet (map data includes © OpenStreetMap contributors). Browsing the catalogue does not send your identity to those sources.
5. Where your data is processed
Our servers are located in France (European Union), so your data is processed under the EU General Data Protection Regulation (GDPR). If you use the app from another country, your data will be transferred to the EU. We apply the protections described in this policy regardless of where you are.
6. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account |
| Approximate location | 90 days, then deleted automatically |
| Consent records | While the account exists, then deleted with it |
| Push tokens | Until you sign out or disable notifications |
| Server request logs (incl. IP) | Up to 90 days, for security purposes |
After an account is permanently deleted, residual copies may persist in our encrypted backups for up to 30 days before those backups are rotated out.
7. Your choices
These are the controls the app really provides today:
- Turn off personalised advertising — Settings → Privacy. Switching it off also erases the approximate location data already collected, not just future collection.
- Delete your location data — Settings → Privacy, at any time, without deleting your account.
- See what is stored — Settings → Privacy shows the number of stored records, their precision and the retention period, read directly from our servers.
- Correct your details — name, language and units are editable in the app.
- Delete your account — Settings → Delete account. Your advertising location data is erased immediately. The account can be restored for 14 days by simply signing in again; after that it and its data are permanently deleted.
- Turn off notifications — in the app or in your device settings.
Because your data is processed in the EU, you additionally have the GDPR
rights of access, rectification, erasure, restriction of processing, data
portability and objection (Articles 15–21), and the right to withdraw consent
at any time without affecting prior processing. To exercise any of them, write
to info@trailymap.lat — we will respond within a reasonable
period. You also have the right to lodge a complaint with a supervisory
authority; for our processing that is the French CNIL
(cnil.fr), or the authority of your own country of
residence.
8. Children
The service is not directed to children and we do not knowingly collect their data. If you believe a child has provided us with personal data, contact us and we will delete it.
9. Security
Traffic between the app and our servers is encrypted with TLS. Passwords are stored only as salted hashes. Access to production systems is restricted. Location data is deliberately stored at reduced precision, so that even in the worst case it cannot reveal where exactly you were.
No system is perfectly secure, and we cannot guarantee absolute security.
10. Changes
If we change this policy in a way that affects you, we will publish the new version here with a new version number and, where the change is significant, ask you to review it in the app. Continuing to use the service after a change means you accept the updated policy.
11. Contact
info@trailymap.lat