Privacy Policy – Pocket Traveler
March 24, 2025
1. Who are we?
Pocket Traveler is a digital service for AI-powered GPS walking tours. We are the data controller under GDPR. Questions? Email privacy@pockettraveler.app.
2. Data we process
Via the waitlist we process: email address (required), city/destination (optional), trip type (optional), marketing consent, UTM parameters, hashed IP (SHA-256 + salt, never readable), and user-agent string.
3. Legal basis
Consent (Art. 6(1)(a) GDPR) for waitlist sign-up and optional marketing. Legitimate interest (Art. 6(1)(f) GDPR) for fraud prevention via IP hash and user-agent.
4. Retention
Waitlist data is kept until you unsubscribe or the service launches and your account is migrated. Unused records are deleted within 12 months of the waitlist closing.
5. Third parties
We never sell or rent your data. We use Supabase (EU data storage, GDPR-compliant) as our sole processor. No other recipients.
6. Cookies & tracking
No tracking cookies. No third-party analytics scripts (no Google Analytics, no Meta Pixel). Only strictly necessary functional cookies are used.
7. Your rights
You have the right of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Send requests to privacy@pockettraveler.app. We respond within 30 days. You may also lodge a complaint with your national supervisory authority.
8. Security
We apply appropriate measures: TLS encryption, hashed IP addresses, database access controls, and server-side-only API keys.
9. Changes
We will notify you by email of material changes. The date at the top reflects the latest version.
10. Contact
Questions or requests: privacy@pockettraveler.app.