We respect your privacy. This policy explains what personal data we process in the RoamRise app and website, why we process it, who we may share it with, and what rights you have. RoamRise is an app for discovering, recording and sharing your favourite routes — from humans to humans. We only collect what we genuinely need.
1. Data controller
The controller of your personal data is the operator of RoamRise:
registered office: Pardubice, Czech Republic
Company ID (IČO): 09546766
registered in the Commercial Register kept by the Regional Court in Hradec Králové, Section C, Insert 46446
E-mail: [email protected]
You can contact us about any privacy matter at the e-mail address above.
2. What data we process
Depending on how you use RoamRise, we process the following categories:
- Account data — e-mail address, secured (hashed) password, display name and an optional profile photo.
- Location data — GPS coordinates, the recorded route, speed, distance, duration and G-force values. This data is created only when you start recording a route yourself, and is used to record, score and share routes.
- Content you create — saved routes, points of interest, notes and photos you add to routes.
- Technical and diagnostic data — device type and model, operating system version, language, identifiers needed for operation, and anonymised crash and error reports.
- Website data — if you sign up for our newsletter or early access, we process your e-mail address.
- Analytics data — anonymous usage statistics that help us improve the app and website.
We do not process payment data or card details — any payments are handled solely through the App Store or Google Play.
3. Purposes and legal basis
We process personal data in accordance with the GDPR (Art. 6) on the following legal bases:
- Performance of a contract — operating the app, managing your account, recording, storing and sharing routes, and showing community content.
- Consent — access to your device location, sending notifications, and newsletter sign-up on the website. You can withdraw consent at any time.
- Legitimate interests — securing the service, preventing abuse and spam, fixing bugs and improving the app.
- Legal obligations — where required by law.
4. Who we share data with
We do not sell your data and do not share it with third parties for their marketing. To run the service we use the processors below, who process data only on our instructions:
- Supabase — database, authentication and photo storage.
- Google Maps — map tiles and route display.
- PostHog — anonymous usage analytics.
- Apple App Store and Google Play — app distribution and any payments.
Routes, points of interest and a profile you choose to share publicly may be visible to other RoamRise users. You decide what you share.
5. Transfers outside the EU/EEA
Some processors may process data outside the European Economic Area. In that case the transfer is protected by appropriate GDPR safeguards, in particular the European Commission's Standard Contractual Clauses.
6. Data retention
We keep account data and the content you create for as long as your account exists. After you delete your account we erase the data within 30 days at the latest, except where we are legally required to keep it. A newsletter e-mail address is processed until you withdraw consent.
7. Your rights
Regarding your personal data, the GDPR gives you the following rights:
- the right of access and to a copy of your data,
- the right to rectification of inaccurate data,
- the right to erasure (“right to be forgotten”),
- the right to restriction of processing,
- the right to data portability,
- the right to object to processing,
- the right to withdraw consent at any time.
You can exercise most of these rights directly in the app — you can manage and delete your account and data in settings. Otherwise, contact us at [email protected]. You also have the right to lodge a complaint with the supervisory authority, the Office for Personal Data Protection (Pplk. Sochora 27, 170 00 Prague 7, Czech Republic).
8. Security
We protect your data with technical and organisational measures — encrypted transfer (HTTPS/TLS), row-level security (RLS) for database access, and hashed password storage. No transmission of data over the internet is entirely without risk, however, and we cannot guarantee absolute security.
9. Children
RoamRise is intended for users aged 15 and over. We do not knowingly process data of children under 15. If we discover we have collected such data, we will delete it.
10. Cookies and tracking on the website
The RoamRise marketing website uses PostHog for anonymous analytics (in a mode without persistent cookies) and Google reCAPTCHA to protect the sign-up form from abuse. We do not use third-party advertising or tracking cookies to run the website.
11. Changes to this policy
We may update this policy from time to time. We will inform you of any material changes in the app or on the website and state the new effective date.
12. Contact
For any privacy question, reach us at [email protected].