TRAVLR Back to app
On this page
  • 1. Data Controller
  • 2. What We Collect
  • 3. Legal Basis
  • 4. How We Use Your Data
  • 5. Sharing & Processors
  • 6. International Transfers
  • 7. Retention
  • 8. Your Rights
  • 9. Cookies
  • 10. Children
  • 11. Updates
  • 12. Contact & DPO
Legal

Privacy Policy

Last updated: 2 September 2026 GDPR compliant Version 1.0
The short version: We collect only what we need to run TRAVLR. We do not sell your data. We do not run advertising. We use a small number of reputable third-party services to operate the platform. You have full rights over your data under GDPR.

01 Data Controller

The data controller responsible for your personal data is:

TRAVLR
Legal entity: [TRAVLR Legal Entity Name]
Registered address: [Company Address]
Registration number: [Company Reg. No.]
Email: privacy@travlr.earth

Where this policy refers to "TRAVLR", "we", "us" or "our", it means the entity above.

02 What We Collect

2.1 Account data

When you create an account we collect your email address and a display name (username). We store a hashed password — we never store your password in plain text.

You can also sign in with Google or Apple instead of a password. If you do, that provider tells us your email address and confirms the sign-in; we do not receive your password, your contacts, or anything else from your account with them, and we do not post anything anywhere.

2.2 Usage and interaction data

We may log technical data needed to operate and debug the service:

  • Browser type, operating system, screen resolution
  • Pages and features accessed, timestamps
  • Error logs and crash reports
  • IP address (retained for security purposes, not linked to your profile)

2.3 Travel data you provide

TRAVLR is a mapping platform. Any routes, diary entries, saved locations, or trip data you create are stored on your behalf and under your control. This data is yours — see Section 8 for how to export or delete it.

2.4 Location

TRAVLR is a map, so knowing roughly where you are is most of what makes it useful. There are three levels, and they differ deliberately in what they ask of you. The first happens by itself because it cannot not happen; the other two are switches you turn on, and neither is needed to use TRAVLR.

  • Rough, automatically. Every request to any website carries your IP address, and an IP resolves to about a city. We use that to answer “what is near me” without asking you for anything — it needs no permission prompt because it reveals nothing your connection had not already revealed. It is accurate to tens of kilometres at best, and often far worse on a mobile network or a VPN. We do not store it: it draws the screen in front of you and is gone when you close the tab. Website only — the iOS and Android apps never make this call.
  • Precise, only if you turn it on. Your device’s own position (GPS, Wi-Fi and cell) is opt-in: your browser or phone asks you first, and declining is a perfectly normal way to use TRAVLR — the rough level above carries on working. We ask only where it is the point of the feature: finding places near you, recording a live track, and putting a stop where you actually are. Your browser or phone remembers that choice, not us, and you can change it there at any time.
  • In the background, only during a track you started. In the iOS and Android apps you can also allow location “all the time”. This exists for one reason: a recording made with the phone in your pocket. Without it the operating system suspends the app when the screen locks and your route comes back as a straight line. We ask for it separately, only after you have allowed the level above, and only when you start a track — on Android it runs as a foreground service with a permanent notification, so you can always see that your location is in use. It stops when the track stops. You can revoke it in your phone’s settings at any time.

Precise location is only stored when storing it is the thing you asked for — a stop you save to a trip, or a track you record and keep. That is your travel data under 2.3, and Section 8 covers exporting and deleting it. A position used to answer “what is near me” and nothing else is never written down.

2.5 Data we do NOT collect

  • Your location when you have not turned it on — the switch is held by your browser or your phone, not by us, and we never follow your position outside a track you started
  • Payment or financial data (we do not currently charge for anything)
  • Biometric data
  • Your contacts, friend list, or anything else from a social account you sign in with
  • Third-party advertising or analytics trackers — there are none in the app. Clicks on sponsored cards are counted on our own servers; following one takes you to the partner’s own website, where their terms apply

03 Legal Basis for Processing (GDPR Art. 6)

Processing activity Legal basis
Creating and managing your account Art. 6(1)(b) — Performance of a contract
Delivering the TRAVLR service Art. 6(1)(b) — Performance of a contract
Security monitoring and fraud prevention Art. 6(1)(f) — Legitimate interest
Service improvement and analytics Art. 6(1)(f) — Legitimate interest
Optional analytics cookies Art. 6(1)(a) — Consent (revocable)
Legal compliance (e.g. law enforcement requests) Art. 6(1)(c) — Legal obligation
Transactional emails (password reset, account notices) Art. 6(1)(b) — Performance of a contract

04 How We Use Your Data

We use the data described above to:

  • Create and authenticate your account
  • Deliver the TRAVLR map, Explore, Diary and related features
  • Respond to your support requests
  • Send essential service communications (account security, policy updates)
  • Detect, investigate and prevent abuse, fraud and security incidents
  • Improve the platform through aggregated, de-identified analytics
  • Comply with legal obligations
We do not use your data to serve personalised advertisements, build advertising profiles, or sell your data to any third party — ever.

05 Sharing & Third-Party Processors

We share your data only with the following sub-processors, each bound by data processing agreements and appropriate safeguards:

Processor Purpose Location Data shared
Supabase, Inc. Database, authentication, storage, edge functions USA (AWS) Account data, travel data, usage logs
Cloudflare, Inc. Serves every map asset — imagery, vector map data, elevation, fonts and country outlines — from our own tile server running on their network Global edge network Your IP address and the map tiles your device requests, which indicate the area of the map you are viewing. No account data, and nothing is written to a profile
OpenFreeMap Source of the vector map data (OpenStreetMap), served to you through our own infrastructure Public tile service Nothing. Map tiles are fetched by our servers and cached there, so your browser never contacts OpenFreeMap and they never see your IP address or which part of the map you are looking at
AWS Open Data (Mapzen Terrain Tiles) Source of the elevation data behind hillshading and 3D Terrain (SRTM, NASA/USGS), served to you through our own infrastructure Public dataset Nothing. Elevation tiles are fetched by our servers and cached there, so your browser never contacts Amazon Web Services for them
wheretheiss.at Real-time ISS position API Unknown — public API, no account data sent Your IP address only (anonymous API call)
ipwho.is / GeoJS Turns your IP address into an approximate city, which is how the website works out roughly where you are without asking for location access (see 2.4). Used wherever a rough position is enough — showing what is near you, and drawing your position on the developer-console world map. If you grant precise location, your device’s own position is used for those features instead. Website only — the iOS and Android apps never make this call. Unknown — public API, no account data sent Your IP address only (anonymous API call; the result is never stored and never sent to us)
Travelpayouts Travel affiliate network. It does two things for us. First, the sponsored cards you see beside a place are search links to travel partners (hotels, flights) carrying our affiliate id, so that if you book something we are credited — the link is built in your browser and is not a request to anyone until you click it. Second, on the website only, a Travelpayouts script (tpembars.com) runs on the page and turns qualifying outbound travel links into affiliate links the same way. Website only — the iOS and Android apps never load that script. We are paid a commission on bookings; you are never charged more because of it, and a card is labelled “Sponsored” wherever one appears. Cyprus / EU, with partner redirect servers globally Nothing from your account. When you click a sponsored card or an affiliate link, the destination site and Travelpayouts see your IP address, your browser details and which offer you clicked. No name, email, travel data or location from your TRAVLR account is passed to them
Map data is served through us, not by third parties. The map's vector data and elevation come from open datasets, but your browser does not fetch them from those providers. Our own tile server requests them, caches them, and serves them to you — so the organisations behind the map data never see your IP address or which part of the world you are looking at. The trade-off is stated honestly above: our tile server runs on Cloudflare's network, so Cloudflare handles those requests instead.

We may also disclose your data if required to do so by law, court order, or a binding request from a public authority, and only to the extent legally required.

06 International Transfers

Our primary infrastructure provider, Supabase, stores data on Amazon Web Services servers in the United States. This constitutes a transfer of personal data from the European Economic Area (EEA) to a third country.

This transfer is covered by Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914), which Supabase has incorporated into their Data Processing Agreement. A copy of the applicable SCCs is available on request.

Our map assets are served from Cloudflare's global edge network, which means a request from your device is answered by whichever of their locations is nearest to you — inside or outside the EEA. What Cloudflare handles is limited to the map request itself: an IP address and a tile coordinate, with no account data attached.

Cloudflare's Data Processing Addendum incorporates the same Standard Contractual Clauses approved by the European Commission (Decision 2021/914). For transfers to the United States, Cloudflare is additionally certified under the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework, and the UK Extension to the EU-U.S. DPF, and states that it falls back to the Standard Contractual Clauses should those certifications lapse. A copy of the applicable terms is available on request.

We do not transfer your data to any country that is not covered by an adequacy decision, SCCs, or another lawful transfer mechanism under GDPR Chapter V.

07 Data Retention

Data type Retention period Reason
Account & profile data Until account deletion + 30 days Account operation; 30-day recovery window
Travel data (routes, diary) Until deleted by you or account deletion User-controlled content
Security / access logs 90 days Abuse detection & incident response
Aggregated analytics 24 months (no personal identifiers) Product improvement
Legal hold data Duration of legal obligation Compliance with applicable law

When retention periods expire, data is permanently deleted or irreversibly anonymised.

08 Your Rights Under GDPR

If you are located in the EEA, UK, or Switzerland, you have the following rights. We will respond to all requests within 30 days.

Right of Access (Art. 15)
Request a copy of all personal data we hold about you.
Right to Rectification (Art. 16)
Correct inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
Request deletion of your account and all associated data.
Right to Restriction (Art. 18)
Restrict how we process your data while a dispute is resolved.
Right to Portability (Art. 20)
Receive your data in a structured, machine-readable format (JSON/CSV).
Right to Object (Art. 21)
Object to processing based on legitimate interest.
Withdraw Consent (Art. 7)
Revoke consent for optional processing (e.g. analytics cookies) at any time.
Right to Lodge a Complaint
Complain to your national supervisory authority (e.g. ICO in the UK, BfDI in Germany).

To exercise any of these rights, contact us at privacy@travlr.earth. We may need to verify your identity before processing the request.

09 Cookies & Local Storage

We use a minimal number of cookies and browser storage. See our Cookie Policy for the full list. In summary:

  • Strictly necessary: Authentication session, user preferences (sidebar state, theme). These cannot be disabled as they are essential to the service.
  • Analytics: Aggregated usage statistics to improve TRAVLR. Only set with your consent.
  • No advertising cookies are used on TRAVLR.

You can manage your cookie preferences at any time via the cookie banner (click "Cookie settings" in the app footer).

10 Children's Privacy

TRAVLR is not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data without parental consent, please contact us at privacy@travlr.earth and we will delete it promptly.

11 Updates to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:

  • Displaying a prominent notice in the TRAVLR app, and/or
  • Sending an email to the address associated with your account

The "Last updated" date at the top of this page will always reflect when the policy was last changed. Continued use of TRAVLR after a policy update constitutes acceptance of the revised policy, to the extent permitted by applicable law.

Previous versions of this policy are available on request.

12 Contact & Data Protection Officer

For any privacy-related questions, data subject requests, or concerns, please contact us:

Privacy & Data Requests
Email: privacy@travlr.earth
Response time: within 30 days (GDPR Art. 12(3))

If you are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority:

  • EU: Your country's national DPA — find your authority
  • UK: Information Commissioner's Office (ICO) — ico.org.uk
  • Germany: Bundesbeauftragte für den Datenschutz (BfDI)
© 2026 TRAVLR. All rights reserved.
Privacy Policy Terms of Service Cookie Policy Contact