RouteMapBack to RouteMap

Privacy Policy

Last updated 5 September 2026

1. About this policy

RouteMap ("we", "us", "our") is operated by Jason Reeve, based inAustralia. This Privacy Policy explains how we collect, use, store and share your information when you use the RouteMap mobile application ("the App").

We handle personal information in accordance with the Australian Privacy Act 1988and the Australian Privacy Principles. This policy also addresses the requirements of the EU and UK General Data Protection Regulation (GDPR) and theCalifornia Consumer Privacy Act (CCPA) where they apply.

By using the App, you agree to the practices described in this policy.

2. Information we collect

2.1 Account information

When you create an account, we may collect:

Passwords are stored on our servers as bcrypt hashes. We never store plain-text passwords.

2.2 Strava activity data

When you connect Strava, we access your activities with read-only scope (activity:read_all). We retrieve the activity metadata needed to draw routes on the map: name, type, distance, dates and the encoded route polyline. We store Strava OAuth tokens on our servers, encrypted, so we can sync on your behalf and refresh them when they expire.

We do not post to Strava or modify your Strava data.

Strava also notifies our server when you create, change or delete an activity, or when you revoke RouteMap's access, so the map stays current without polling. Cached activity data is also stored on your device for offline viewing and faster loading.

2.3 Location data

When you grant location permission, the App uses your device's position to:

Location is processed on your device for map display. We do not store your live position on our servers.

2.4 Photos and media

When you grant photo library permission, the App may:

We do not upload your photos to our servers. Profile images from Strava or Google are referenced by URL and not re-hosted by us.

2.5 Usage and error data

The App may send anonymous crash reports and error logs to Sentry (sentry.io) to help us fix bugs. A report can include device type, OS version, app version and a stack trace. Personal identifiers and tokens are scrubbed before anything is sent.

2.6 Purchase information

VIP purchases are processed by the Apple App Store or Google Play. We use RevenueCat to verify entitlements. RevenueCat receives a device identifier and purchase receipt, not your payment card details.

2.7 Map and search data

The App draws its map with Apple Maps on iOS and Google Mapson Android. When a map is displayed, those providers may collect data under their own privacy policies. Place search sends the text you type to OpenStreetMap's Nominatim service to find matching places.

2.8 Advertising

Free users may see an in-app RouteMap message before certain actions such as export. We do not use third-party ad networks. VIP users do not see these messages.

3. How we use your information

PurposeLegal basis (GDPR)
Create and manage your accountContract performance
Sync and display Strava activitiesContract performance, consent
Save exports to your deviceConsent
Process in-app purchasesContract performance
Diagnose crashesLegitimate interest
Prevent abuse of our APIsLegitimate interest

4. Data sharing and third parties

We do not sell your personal information. We share limited data only with:

ServicePurposePrivacy policy
Strava, Inc.OAuth and activity API (you authorise this)strava.com/legal/privacy
Apple Inc.Maps on iOS, Sign in with Apple, payment processingapple.com/legal/privacy
Google LLCMaps on Android, optional Google sign-in, payment processingpolicies.google.com/privacy
OpenStreetMap FoundationPlace search (Nominatim)osmfoundation.org
RevenueCat Inc.Purchase and subscription managementrevenuecat.com/privacy
SentryCrash reportingsentry.io/privacy

Our backend is hosted on Railway in the United States. Account, token and session data live in a database we configure there.

5. Data storage and security

6. International data transfers

Data may be processed in the United States (hosting, RevenueCat, Sentry, Google). We rely on provider compliance and applicable transfer mechanisms where required.

7. Data retention

DataRetention
Account and Strava tokensUntil you delete your account or disconnect Strava
Device cacheUntil you log out, delete the account or uninstall
SessionsUntil expiry or logout
Crash reports (Sentry)Up to 90 days
Purchase records (RevenueCat)Per RevenueCat and store policies

8. Your rights

Depending on where you live, you may have the right to:

Australia: OAIC.EU and UK: your local Data Protection Authority.California: we do not sell personal information.

To exercise any of these rights, contact us by email at support@mandooist.com.

9. Children's privacy

The App is not directed at children under 13 (or 16 in the EU). We do not knowingly collect data from children. Contact us to request deletion if you believe a child has provided data.

10. Changes to this policy

We may update this policy. The "Last updated" date at the top will change. Continued use after an update constitutes acceptance of the revised policy.

11. Contact us

Jason Reeve, Mandooist.

You can reach us by email at support@mandooist.com.

Help and frequently asked questions are on theSupport page.

RouteMap (package app.routemap) on the Apple App Store and Google Play.

Back to RouteMap