Privacy Policy – Pocket Traveler

March 24, 2025

1. Who are we?

Pocket Traveler is a digital service for AI-powered GPS walking tours. We are the data controller under GDPR. Questions? Email privacy@pockettraveler.app.

2. Data we process

Via the waitlist we process: email address (required), city/destination (optional), trip type (optional), marketing consent, UTM parameters, hashed IP (SHA-256 + salt, never readable), and user-agent string.

3. Legal basis

Consent (Art. 6(1)(a) GDPR) for waitlist sign-up and optional marketing. Legitimate interest (Art. 6(1)(f) GDPR) for fraud prevention via IP hash and user-agent.

4. Retention

Waitlist data is kept until you unsubscribe or the service launches and your account is migrated. Unused records are deleted within 12 months of the waitlist closing.

5. Third parties

We never sell or rent your data. We use Supabase (EU data storage, GDPR-compliant) as our sole processor. No other recipients.

6. Cookies & tracking

No tracking cookies. No third-party analytics scripts (no Google Analytics, no Meta Pixel). Only strictly necessary functional cookies are used.

7. Your rights

You have the right of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Send requests to privacy@pockettraveler.app. We respond within 30 days. You may also lodge a complaint with your national supervisory authority.

8. Security

We apply appropriate measures: TLS encryption, hashed IP addresses, database access controls, and server-side-only API keys.

9. Changes

We will notify you by email of material changes. The date at the top reflects the latest version.

10. Contact

Questions or requests: privacy@pockettraveler.app.