Traverse is a free app for the mountains of Kosovo and the region: a terrain map, trip recording, a community, and safety features (trip plans and SOS). This policy explains what we store about you, why, who can see it and how to remove it. It applies to the Traverse apps for iPhone and Android, to traverse-3d.com and to the Traverse console for organizations.
1. The short version
- We store what the app needs to work: your account, what you record and share, and the data behind trip plans and SOS.
- Your data is stored in the European Union (Supabase, Frankfurt, Germany).
- We do not sell your data, show ads or use advertising trackers.
- Your position is used in the background only while you record a trip or have an open trip plan.
- If you press SOS, or a trip plan you shared with a rescue organization escalates, rescue responders see your position and the details they need to find you.
- You can delete your account in the app at any time: Profile → Delete account. See Delete your account.
2. Who is responsible
The controller of your personal data is [Legal entity name], [Registered address, Kosovo], registration number [Business registration number] (“Traverse”, “we”). For anything about your data, write to privacy@traverse-3d.com.
Lawyer to confirmFill in the legal entity, address and registration number. Confirm whether a data protection officer must be appointed, and whether an EU representative is needed under GDPR Article 27 (Traverse is not established in the EU but is offered to people there).3. What we store and why
The table lists everything the app stores on our servers. “Legal basis” refers to the General Data Protection Regulation (GDPR) Article 6 and the matching grounds in Kosovo’s Law No. 06/L-082 on Protection of Personal Data.
Lawyer to confirmConfirm the legal bases below and the matching articles of Law No. 06/L-082 (Kosovo) and of Albania’s personal data protection law.| Data | What it is used for | Legal basis |
|---|---|---|
| Account: email address, or the identifier Apple or Google gives us when you sign in with them (and the name they share, if any) | Signing you in with 6-digit email codes or Apple/Google sign-in; contacting you about your account | Contract |
| Profile: username, display name, photo, bio, home region, language, units, private-profile setting | Showing who you are to other people in Traverse | Contract |
| Private profile: emergency contact name and phone number; your own phone number if you add one | Pre-filling trip plans; texting your contact when a trip plan is overdue or you press SOS; letting responders call | Contract; vital interests in an emergency |
| Trips: GPS track (position, elevation and time of each point), start and end, distance, ascent, moving time, steps (from the phone’s step counter, or estimated from distance), sport, title, notes, people you tag, summits matched from your track | Your trip history, statistics, the feed, and your year in review | Contract |
| Trip plans: route, start and check-in time, party size, notes, emergency contact, which rescue organization you share it with, your last known position, and every step of the plan (created, extended, overdue, contact alerted, escalated, checked in) | Checking that you are back, and raising the alarm if you are not | Contract; vital interests once it escalates |
| SOS: position, accuracy, elevation, battery level, optional message, time, whether it went over data or SMS, and its status (prepared, sent, acknowledged, resolved, cancelled) | Getting help to you | Vital interests |
| Field reports: category (conditions, hazard, avalanche observation), text, photos, location, elevation, time observed; your “still there” / “gone” votes on others’ reports; which reports you were shown | Telling other people about conditions; expiring outdated reports; showing authors how many people saw their report | Contract; legitimate interest (accurate, current reports) |
| Routes and places you draw or add; routes you save (and whether you saved them offline) | The map, route planning, and warning you about official notices along routes you saved | Contract |
| Community: people you follow and block, groups, events you join (and, for clean-ups, attendance and bags collected), posts, comments, thanks, notifications, and content you report to us | The community features; keeping them free of abuse | Contract; legitimate interest (moderation) |
| Photos you add to trips, routes, reports or posts, with their location if you attach one | Showing them in Traverse | Contract |
| GPX files you import or export | Importing and exporting tracks | Contract |
| Device: push notification token and platform (iOS/Android) | Sending you notifications you asked for, including safety alerts | Contract; consent (you allow notifications on your phone) |
| App sessions: when you opened and closed the app, and for how long | Time-in-the-mountains figures in your year in review | Contract |
| Error reports: platform, app version, error message and technical trace, and your account ID | Finding and fixing crashes | Legitimate interest (a working, reliable app) |
| Organization staff: your membership and role, notices and events you publish, and what you do in the console (acknowledging an SOS, notes on a trip plan, verifying reports) | Running official notices and rescue coordination; a record of who did what | Contract; legitimate interest (accountability in emergencies) |
| Server logs kept by our hosting provider: IP address, time and type of request | Security and troubleshooting | Legitimate interest (security) |
We do not ask for health information. If you write any into a trip plan note or an SOS message, we use it only to help you in an emergency.
Lawyer to confirmConfirm the treatment of health data a person may type into notes or SOS messages (GDPR Article 9(2)(c), vital interests).4. Location and phone permissions
- Location while using the app: to show you on the map and to record trips.
- Location in the background: only while you record a trip or have an open trip plan, so the track keeps recording with the screen off and your last known position is available if you need help. It stops when the recording or trip plan ends.
- Motion (step counter): to count steps during recorded trips.
- Camera and photos: only when you choose to add a photo.
- Notifications: for trip-plan check-ins, official notices in your area and community activity.
5. Who can see your data
Everyone, including people without an account
Your username, display name, profile photo, bio and home region. Routes you publish, field reports (with your name), photos you add, and trips and posts you set to “public”. Photos are stored at web addresses that anyone who has the link can open, even if the trip they belong to is private.
People you choose
Trips and posts set to “followers” are visible to people you accepted as followers (this is the default for trips). “Private” is visible only to you and to people you tag on that trip. Group posts are visible to the group’s members, or to everyone for public groups. People you block cannot see your content.
Your emergency contact
Receives an SMS when a trip plan is 30 minutes overdue (your name, the trip’s title, when you were due back and your last known position), an SMS with your name and coordinates when you press SOS with data, and an “all clear” message if you check in after they were alerted. Please tell the person before you add them.
Rescue responders
Responders are staff of a rescue organization that Traverse has verified. They are separate organizations, not Traverse.
- When you press SOS, responders of every verified rescue organization see your position, accuracy, elevation, battery level, message, name, your emergency contact (and your own phone number if you added one), and your open trip plan with its planned route, party size and notes.
- A trip plan you shared with a verified rescue organization becomes visible to that organization’s staff only if it escalates (90 minutes after your check-in time, without a check-in). They then see the plan, your last known position, planned route, contact and its history.
- They keep seeing these records in the console for 24 hours after they are closed.
Organizations in general
Staff of verified organizations can publish official notices, verify, resolve or hide field reports, and see the members of their organization.
Traverse administrators
A small number of Traverse staff can verify organizations, review content people report, hide content that breaks the terms, and read error reports.
Service providers
These companies process data for us, only to provide their service:
| Provider | What for | Data | Where |
|---|---|---|---|
| Supabase | Database, sign-in, file storage, server functions | Everything above | EU (Frankfurt) |
| Expo (650 Industries) | Delivering push notifications | Push token, notification text | USA |
| Twilio | SMS to emergency contacts | Contact’s phone number, message text (your name, position) | USA |
| Mapbox | Map tiles in the app (usage telemetry is switched off) | IP address, the map area requested | USA |
| Apple, Google | Sign in with Apple / Google, if you use it; app distribution | Sign-in identifier, name and email they share | USA / EU |
| [Email provider] | Sending sign-in codes | Email address | [Region] |
| Namecheap | Hosting traverse-3d.com | IP address, pages requested (server logs) | [Region] |
| Google Analytics | Website statistics, only if you accept them | Pages visited, device and browser, approximate location, cookie ID | EU / US |
Authorities
We disclose data to authorities only when the law requires it, or to emergency services when someone’s life may be at risk.
We never sell your data, and we do not share it with advertisers.
6. Where your data is
Our database and files are stored in the European Union (Frankfurt, Germany). Some providers listed above are in the United States. Transfers to them rely on the EU–US Data Privacy Framework where the provider is certified, or on the European Commission’s standard contractual clauses.
Lawyer to confirmConfirm the transfer mechanism for each US provider, and the rules for transfers from Kosovo and Albania (both outside the EU) under their national laws.7. How long we keep it
- Your account and everything tied to it (profile, trips, trip plans, SOS records, photos, posts and the rest): until you delete it, or delete your account.
- Field reports leave the map after 7 days unless people confirm them, but stay stored. When you delete your account, field reports, routes and places you added stay on the map without your name, because other people rely on them for their safety.
- Error reports: when you delete your account they are kept without your account ID.
- Backups: deleted data can remain in encrypted backups for up to [7] days before they are overwritten.
- Server logs: kept by the hosting provider for [1–7] days.
- Deletion requests by email: we keep the date and email address of the request as proof that we handled it.
8. Your rights
You have the right to:
- access your data and get a copy of it, in a machine-readable format (JSON, and GPX for tracks);
- correct it (most of it you can edit in the app);
- delete it: single trips, reports, posts and photos in the app, or your whole account (how);
- restrict or object to processing based on legitimate interest;
- withdraw consent, for example by turning off location or notifications in your phone’s settings;
- complain to a supervisory authority: in Kosovo the Information and Privacy Agency (Agjencia për Informim dhe Privatësi); in Albania the Commissioner for the Right to Information and Personal Data Protection; in the EU the data protection authority of your country.
Write to privacy@traverse-3d.com from the email address of your account. We answer within one month. We may ask you to confirm a code we send to that address, so that nobody else can get your data.
9. Children
Traverse is not meant for children under 16. If you believe a child under 16 has an account, write to us and we will delete it.
Lawyer to confirmConfirm the minimum age under Kosovo and Albanian law and for EU countries that set a lower age (13–15).10. Security
All traffic is encrypted (HTTPS). Every table in our database has row-level access rules, so the app can only read what you are allowed to see; safety data reaches responders only in the cases described above. Sign-in uses one-time codes, so there is no password to steal. No system is perfectly secure; if a breach affects your data we will tell you and the supervisory authority as the law requires.
11. This website
traverse-3d.com uses Google Analytics 4 to count visits and see which pages are useful, but only if you accept it in the banner. Until you do, no analytics script loads and no analytics cookie is set; if you decline, we remember that choice in your browser and ask no more. If you accept, Google sets cookies (_ga, _ga_*) and receives the pages you visit, your device and browser type and an approximate location derived from your IP address. Google does not store the full IP address. Google signals and ad personalisation are switched off, and we do not use the data for advertising. You can change your choice at any time with “Analytics settings” at the bottom of every page.
Fonts are served from our own site, and no advertising trackers are used. If you sign in to the console, your session is stored in your browser’s local storage until you sign out. The console map loads map tiles from OpenTopoMap, which sees your IP address.
12. Changes to this policy
If we change this policy in a way that matters, we will tell you in the app before the change applies. The date at the top shows the latest version.
13. Contact
Privacy: privacy@traverse-3d.com. Everything else: support@traverse-3d.com.