The controller for the processing described here is SCAI GmbH, Quettinger Straße 143a, 51381 Leverkusen, Germany, phone +49 2171 776960-0, e-mail admin@frelestray.com. All further details about the provider are given in the legal notice under "Legal".
The service may see the data it needs to answer; it does not keep it. Routes and locations can point to a person even without an account: anyone whose loop always starts at their own front door reveals where they live. We therefore treat them as personal data, whether or not there is an account behind them. There is no advertising, no tracking, no third-party analytics and no sharing for advertising purposes. We do not sell data. All connections between your device and our server are encrypted with TLS (HTTPS).
Route search, planning, editing: your starting point, waypoints and settings are sent to our server and processed for the response. They are not stored and not linked to your IP address. Legal basis: Art. 6(1)(b) GDPR (provision of the requested service).
On-the-way mode (app): When you start navigation and when you use "Back to route", your current position is sent to our server so it can compute the way to the route. It is discarded after the response: we do not store your position and we do not keep a sequence of your positions. Progress along the route is kept only on your device. Legal basis: Art. 6(1)(b) GDPR.
Location on the device: The position itself comes from your device's location service. On devices with Google Play services this is, for navigation, their service, which combines satellites, Wi-Fi, mobile cells and motion sensors; without Play services it is the system's own location. How that service determines the position and which data it transmits to Google is decided by Google on its own responsibility; you set this in your device's location settings. We transmit nothing to it.
Place search and addresses: search terms and coordinates go to our own Nominatim instance on our server. No third party is involved.
Map: map tiles are delivered by our own server. The access log only records that tiles were requested (the path class “/kacheln/*”), not which ones. Which map section you are looking at therefore does not appear next to your IP address (see section 5).
Route names: to suggest a name for a route, the following is sent to Amazon Web Services (Amazon Bedrock service, model by Anthropic; processing takes place in data centres in the EU, Frankfurt region and other EU regions): names from the route's surroundings (waters, forests, viewpoints, towns and districts — including the place of the starting point) and share values of the route such as “71 % of the route quiet”. Coordinates, length, your IP address, your account and your current position are not sent. Amazon Web Services is a processor under Art. 28 GDPR (AWS Data Processing Addendum, which includes the EU Commission's standard contractual clauses for any transfer to third countries). Legal basis: Art. 6(1)(f) GDPR (our interest in understandable route names).
For the account we store: your e-mail address, a hash of your password (if set), hashes of your session tokens, your language choice, the time of creation, your saved tours (route, starting point, settings, name) and your confirmations of the Terms of Use and of the route notice (time, checksum of the confirmed version, language read). Legal basis: Art. 6(1)(b) GDPR; for the confirmations additionally Art. 6(1)(f) GDPR (proof).
In addition we count your GPX exports: one number per account and day, nothing else — no route, no coordinate, no timestamp. The counter enforces the limit from section 3 of the Terms of Use, which we derive from the licence terms of the map data (Art. 6(1)(f) GDPR). It is deleted by the day after next at the latest.
If you share a saved tour, the service creates a link with a random identifier that has no connection to your account. Whoever opens the link does not see your saved tour but an obscured view: the loop starts at a different point, and the stretch within at least 300 metres of your real starting point is missing — also in the GPX file a recipient downloads. The gap applies to the whole line, not only to individual points. How much more is missing at each edge of the gap is random for each tour. This makes it harder to calculate your starting point back from the edges of the gap; we cannot rule it out entirely. If you share several tours from the same starting point, a recipient can infer the area from the gaps. Your saved tour itself stays unchanged. You can revoke the links to a tour at any time; deleting the tour or the account invalidates them. GPX downloads via a shared link are counted per link and day (one number, nothing else). Legal basis: Art. 6(1)(b) GDPR.
If you request access under Art. 15, we store the timestamps of that request (requested, compiled, notified, downloaded) and, until you download it or for at most 30 days, the compiled file itself. The timestamps remain as evidence that we complied with the request (Art. 5(2) GDPR); they are deleted together with the account.
Registration involves a confirmation procedure: your e-mail address is held in our process engine for at most 72 hours: you have 48 hours to confirm the link, and after 72 hours the procedure ends in any case. It is then deleted within seven days. Confirmation and login links are sent by e-mail via Amazon Web Services (Amazon SES service, processing in the Frankfurt region); the same route carries the message that a report under Art. 15 is ready to collect. What is transmitted is your e-mail address and the content of exactly these messages — no routes, no starting points, no coordinates. Amazon Web Services is a processor under Art. 28 GDPR (AWS Data Processing Addendum, which includes the EU Commission's standard contractual clauses for any transfer to third countries). Legal basis: Art. 6(1)(b) GDPR for the account e-mails, Art. 6(1)(c) GDPR for the notification about the report.
Retention: until you delete the account. "Delete account" removes all account data immediately. Backups are deleted within 30 days at the latest. We use backups solely to restore operation. If we have to restore a backup, we immediately afterwards delete again those accounts and tours whose deletion you have already requested; for that we keep the identifier of the deleted entry and the time until the 30 days have elapsed, and nothing else (Art. 6(1)(c) GDPR). We protect and delete this note in the same way as the backups themselves.
The web interface stores your settings, language choice, session and confirmations in the browser (localStorage). The app stores the same on the device, plus the current tour for navigation without a network. This storage is necessary for the service (Section 25(2) TDDDG); there are no cookies for tracking purposes.
The app uses your location for two features only: "Loop from here" and navigation. You start navigation yourself; it then keeps running even while the screen is off or you are using another app — for as long as it runs, a notification shows that it is running. "End" stops location use. Without a running navigation, the app does not access your location. Where the position comes from is described in section 2. Notifications serve only the running navigation.
For every request our servers log your IP address, the time, the kind of request, the response status and the duration. The kind of request is the method and a path class, such as “map tiles” or “route search”: without tile coordinates, without the identifiers of individual tours or shared links and without the contents of the request. In the case of technical errors, your IP address may appear in an error log together with the error message and the failed request, including its path. The same retention period applies to that log. The purpose is preventing abuse and troubleshooting (Art. 6(1)(f) GDPR). We delete these logs at the latest 14 days after the entry, including all copies; they are not part of our backups.
Hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany — server and backups are located in Falkenstein, Germany, no transfer to third countries. Processor under a contract pursuant to Art. 28 GDPR. E-mail delivery: Amazon Web Services EMEA SARL, Luxembourg (Amazon SES, processing in the Frankfurt region), processor (see section 3). Language model for route names: Amazon Web Services EMEA SARL, Luxembourg (Amazon Bedrock, processing in EU regions), processor (see section 2).
Public authorities receive data only where we are legally obliged to disclose it.
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on Art. 6(1)(f) (Art. 21). You delete your account and tours yourself in the interface; you export tours as GPX. You request access under Art. 15 while signed in, in the "Account" area: you receive a file with all data stored for your account, for download in the interface; an e-mail tells you when it is ready. For anything else, write to the e-mail address given above. You may lodge a complaint with a data protection supervisory authority, for example the one responsible for your place of residence. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, www.ldi.nrw.de). Our data protection officer is IITR Datenschutz GmbH, Marienplatz 2, 80331 Munich, Germany, phone +49 89 1891 7360; you may also contact them directly.
If you suspect a personal data breach, you can report it in the interface under “Legal” — also without an account. If you voluntarily provide an e-mail address for follow-up questions, it is stored only within this case and deleted at the latest seven days after the case is closed; the case itself ends after 90 days at the latest; without an address we can neither ask back nor reply. If you report while signed in, we reply to your account's address. We review every report under Art. 33 and 34 GDPR; the permanent documentation of an incident contains no details about the reporting person. Legal basis: Art. 6(1)(c) GDPR (Art. 33), for the voluntary contact detail point (a).
There is no automated decision-making within the meaning of Art. 22 GDPR. Only persons aged 16 or over may create an account.