Privacy Policy

Last updated: 12 May 2026

By creating an account, registering, or using the ClimbPath application (hereinafter "the App"), you confirm that you have read this Privacy Policy and agree to its terms. If you do not agree, please do not use the App.

The data controller is the operator of this independent project, which develops and manages the App as a standalone initiative. Personal data processing is carried out in accordance with GDPR and related legal regulations.

1. What data we process

Category Data Purpose and legal basis
Registration data Email, username, password (hashed). Contract performance – account creation and management.
Profile data (optional) Instagram, location, bio. User consent – profile display and personalization.
GPS and activity Location, routes, elevation profile. User consent – tracking and route recommendation features.
Technical information IP address, device type. Legitimate interest – security and abuse prevention.
Analytics data App usage statistics, error reports. Legitimate interest – improving features and stability.

2. Data retention period

We store personal data only for as long as necessary to fulfill its purpose or as required by law. You can delete your account and related data at any time in the App settings.

3. Data sharing and security

We do not sell or share personal data with third parties. We only use verified service providers contractually bound to protect and keep data confidential.

Data transmission is secured using encrypted connections (HTTPS/TLS). However, no online system can guarantee absolute security.

4. Changes to the policy

This policy may be updated. Users will be informed of significant changes within the App. Continued use of the App indicates acceptance of the current version.

5. Your GDPR rights

  • Right of access
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to object
  • Right to lodge a complaint with a supervisory authority

6. Cookies and analytics

The App may use essential cookies for functionality and optionally anonymized analytics tools to improve performance and user experience.

If analytics tools are used, data is processed in anonymized or pseudonymized form.

7. Data processors and recipients

Personal data may be processed by third parties providing technical infrastructure (e.g., hosting, databases, email services, analytics). All providers are GDPR-compliant.

8. International data transfers

In some cases, data may be processed outside the EU. In such cases, protection is ensured via Standard Contractual Clauses (SCC) or equivalent GDPR mechanisms.

9. Automated decision-making

We do not use automated decision-making or profiling that produces legal or similarly significant effects.

10. How to exercise your rights

You can exercise your GDPR rights by contacting the controller via email. We typically respond within 30 days.

You also have the right to withdraw consent at any time, where consent is the legal basis.

Contact

For privacy-related questions, contact us:

kontakt@vosoone.cz