← TrailPassport

Privacy Policy

Last updated 29 July 2026 · Version 1.1

1. What this covers

This Privacy Policy explains what personal data TrailPassport ("we", "us", or "our") collects, why, and how it is handled. It is a separate document from our Terms of Service to ensure clear, dedicated transparency regarding your personal data and your privacy rights under applicable data protection laws (including the GDPR and CCPA).

2. Data Controller & How to Contact Us

TrailPassport acts as the Data Controller for your personal data. If you have any questions about this Privacy Policy, wish to exercise your legal data protection rights, or need assistance, you can reach us through either of the following channels:

  • Direct Email: info@trailpassport.net
  • In-App: Profile Settings → Feedback Form (Category: General Inquiry / Privacy)

3. Data we collect

  • Account data: Email address, and any optional details you choose to add — full name, display name, avatar image, club/group association, country, and timezone.
  • Activity data: The Trail Items, Lists, and Challenges you complete, completion timestamps, and the points, flags, badges, and status tiers derived from them.
  • Content you submit: Feedback form submissions, customer support messages, and diagnostic screenshots you attach.
  • Technical data: Authentication session cookies (via Supabase Auth) necessary to keep you securely signed in, device type, and transient IP addresses recorded during server communications. We do not use third-party advertising or commercial analytics trackers.

4. Why we process it & Legal Bases (GDPR Art. 6)

We process your personal data under the following legal grounds:

  • Performance of a Contract (Art. 6(1)(b)): To authenticate your identity, record your completions, compute your points and Travel Status, display your history, and provide core application functionality.
  • Legitimate Interests (Art. 6(1)(f)): To operate our Feedback system, protect the platform against rate-limit violations or unauthorized access, and optimize system stability.
  • Legal Obligations (Art. 6(1)(c)): To meet accounting, regulatory, or legal compliance demands.
  • Consent (Art. 6(1)(a)): Where you voluntarily provide optional profile details (such as avatar uploads or group affiliations).

5. Who we share it with

We do not sell, rent, or trade your personal data with anyone, nor do we share it with third-party advertisers. We rely on trusted third-party infrastructure providers to run TrailPassport:

  • Supabase: Handles user authentication, database management, and file storage under strict encryption and row-level security policies.
  • Vercel: Provides web application hosting and edge deployment.
  • OpenFreeMap & AWS Terrarium: Powers our Interactive Map and terrain feature. Loading map tiles transmits your IP address to tile servers as part of standard web protocol.

6. How long we keep it

We retain your account and activity data for as long as your account is active. If you delete your account (Profile Settings → Security & Privacy → Delete Account), we permanently purge your profile records and associated uploaded files, subject to standard automated backup clearing cycles (up to 30 days).

7. Your rights

Depending on your place of residence, you possess specific data protection rights under laws such as the GDPR or CCPA:

  • Access & Export: Request a machine-readable export of your data via Profile Settings → Data Export.
  • Correction: Review and amend inaccurate account details directly in Profile Settings.
  • Erasure: Delete your account and associated records at any time in-app or by emailing info@trailpassport.net.
  • Restriction & Objection: Object to data processing based on legitimate interests by contacting us via email.
  • Supervisory Authority: You have the right to lodge a complaint with your local Data Protection Authority if you believe your rights have been violated.

8. Security

We implement industry-standard technical measures (TLS-encrypted connections, cryptographically hashed credentials via Supabase Auth, and PostgreSQL Row-Level Security) to protect your information. No system can be guaranteed 100% secure, and we cannot warrant absolute security.

9. Children

TrailPassport is not directed at children and is not intended for use by anyone below the age of digital consent in their jurisdiction (e.g., under 13 in the US or under 16 in the EEA/UK). We do not knowingly collect personal data from minors.

10. Changes to this policy

When material changes are made to this policy, the effective date and version number at the top of this page will update, and registered Wayfarers will be prompted to review and re-accept the updated terms upon logging in before continuing to use the Service.