Privacy Policy
Effective date: April 26, 2026
1. Introduction
This Privacy Policy explains how Camí de Cavalls ("we", "us", or "our") collects, uses, and protects your personal information when you use our mobile application (the "App"). We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and applicable Spanish data protection laws.
2. Data Controller
The data controller for this App is:
Stefano Russello
Menorca, Balearic Islands, Spain
Email: info@followtheflowai.com
Stefano Russello
Menorca, Balearic Islands, Spain
Email: info@followtheflowai.com
3. Data We Collect
The App collects the following types of personal data:
Account Information
What: Name, email address, and user ID.
How: Collected when you sign in using Google Sign-In or Apple Sign-In.
Why: To create and manage your account, enable features like GPS tracking and danger reporting.
Legal basis: Performance of contract (providing the service you requested).
Precise Location Data
What: GPS coordinates (latitude and longitude).
How: Collected only when you explicitly start a GPS tracking session or open the interactive map.
Why: To show your position on the trail map, record your hiking sessions, and enable danger report location tagging.
Legal basis: Your explicit consent (you grant location permission and actively start tracking).
Live Sharing Data (optional, opt-in)
What: Real-time GPS coordinates and tracking session metadata, made publicly accessible via a unique web link.
How: Only when you explicitly enable Live Sharing at the start of a hiking session. Live Sharing is off by default.
Why: To broadcast your live position via a public link that you choose to share with friends, family, or anyone you want to follow your hike in real time.
Public visibility: While Live Sharing is active, anyone who has the link can view your live position on a public web page. You can stop sharing at any time from the app, which immediately ends the public broadcast.
Legal basis: Your explicit consent (you actively enable Live Sharing per session).
Account Information
What: Name, email address, and user ID.
How: Collected when you sign in using Google Sign-In or Apple Sign-In.
Why: To create and manage your account, enable features like GPS tracking and danger reporting.
Legal basis: Performance of contract (providing the service you requested).
Precise Location Data
What: GPS coordinates (latitude and longitude).
How: Collected only when you explicitly start a GPS tracking session or open the interactive map.
Why: To show your position on the trail map, record your hiking sessions, and enable danger report location tagging.
Legal basis: Your explicit consent (you grant location permission and actively start tracking).
Live Sharing Data (optional, opt-in)
What: Real-time GPS coordinates and tracking session metadata, made publicly accessible via a unique web link.
How: Only when you explicitly enable Live Sharing at the start of a hiking session. Live Sharing is off by default.
Why: To broadcast your live position via a public link that you choose to share with friends, family, or anyone you want to follow your hike in real time.
Public visibility: While Live Sharing is active, anyone who has the link can view your live position on a public web page. You can stop sharing at any time from the app, which immediately ends the public broadcast.
Legal basis: Your explicit consent (you actively enable Live Sharing per session).
4. Data We Do NOT Collect
• We do not collect financial or payment information
• We do not collect health or fitness data
• We do not collect contacts, photos, or browsing history
• We do not use analytics or crash reporting SDKs
• We do not use advertising identifiers (IDFA)
• We do not track you across other apps or websites
• We do not collect health or fitness data
• We do not collect contacts, photos, or browsing history
• We do not use analytics or crash reporting SDKs
• We do not use advertising identifiers (IDFA)
• We do not track you across other apps or websites
5. How We Use Your Data
We use your data exclusively to provide and improve the App’s functionality:
• Authenticate you and manage your account
• Display your position on the trail map
• Record and save your hiking sessions
• Enable you to submit and view trail condition reports (danger reports)
• Display your profile name within the App
• Authenticate you and manage your account
• Display your position on the trail map
• Record and save your hiking sessions
• Enable you to submit and view trail condition reports (danger reports)
• Display your profile name within the App
6. Data Sharing and Third Parties
We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes.
Your data may be processed by:
• Google and Apple — solely for the purpose of authenticating your sign-in (OAuth). We receive only your name and email; we do not access your Google or Apple account data.
• Our hosting provider — our servers are located within the European Union.
Danger reports you submit (trail condition, location, optional photo) may be visible to other App users to help the hiking community.
Live Sharing — When you opt in to Live Sharing, your live GPS position is made publicly accessible via a unique web link for the duration of the session. Anyone who receives or finds the link can view your position until you stop the session. We do not share the link itself with any third parties — you alone control who you send it to. Live Sharing is off by default and is enabled only by your explicit per-session opt-in.
Your data may be processed by:
• Google and Apple — solely for the purpose of authenticating your sign-in (OAuth). We receive only your name and email; we do not access your Google or Apple account data.
• Our hosting provider — our servers are located within the European Union.
Danger reports you submit (trail condition, location, optional photo) may be visible to other App users to help the hiking community.
Live Sharing — When you opt in to Live Sharing, your live GPS position is made publicly accessible via a unique web link for the duration of the session. Anyone who receives or finds the link can view your position until you stop the session. We do not share the link itself with any third parties — you alone control who you send it to. Live Sharing is off by default and is enabled only by your explicit per-session opt-in.
7. Data Storage and Security
• Your data is stored on servers located in the European Union
• All data is transmitted over encrypted HTTPS connections
• Passwords are never stored — authentication is handled by Google and Apple via secure OAuth protocols
• GPS tracking data is stored locally on your device and synced to our servers only when you have an active internet connection
• All data is transmitted over encrypted HTTPS connections
• Passwords are never stored — authentication is handled by Google and Apple via secure OAuth protocols
• GPS tracking data is stored locally on your device and synced to our servers only when you have an active internet connection
8. Data Retention
We retain your personal data for as long as your account is active. If you request account deletion, we will permanently delete all your personal data, including hiking sessions and danger reports, within 30 days of your request.
Live Sharing sessions are subject to a shorter retention: the live tracking points and the public link associated with a Live Sharing session are automatically deleted 30 days after the session ends, regardless of account status. You can also end a live session at any time from the app, which immediately revokes the public link.
Live Sharing sessions are subject to a shorter retention: the live tracking points and the public link associated with a Live Sharing session are automatically deleted 30 days after the session ends, regardless of account status. You can also end a live session at any time from the app, which immediately revokes the public link.
9. Your Rights (GDPR)
Under the GDPR, you have the following rights regarding your personal data:
• Right of access — request a copy of the data we hold about you
• Right to rectification — request correction of inaccurate data
• Right to erasure — request deletion of your account and all associated data
• Right to data portability — receive your data in a structured, machine-readable format
• Right to withdraw consent — revoke location permissions at any time through your device settings
• Right to lodge a complaint — you may file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es
To exercise any of these rights, contact us at info@followtheflowai.com.
• Right of access — request a copy of the data we hold about you
• Right to rectification — request correction of inaccurate data
• Right to erasure — request deletion of your account and all associated data
• Right to data portability — receive your data in a structured, machine-readable format
• Right to withdraw consent — revoke location permissions at any time through your device settings
• Right to lodge a complaint — you may file a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es
To exercise any of these rights, contact us at info@followtheflowai.com.
10. Account Deletion
You can request the deletion of your account and all associated data at any time by contacting us at info@followtheflowai.com. Upon receiving your request, we will permanently delete all your personal data within 30 days. This includes your profile information, hiking sessions, and any danger reports you have submitted.
11. Children’s Privacy
The App is not directed at children under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated effective date. We encourage you to review this page periodically. Continued use of the App after changes constitutes your acceptance of the updated policy.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Email: info@followtheflowai.com
Email: info@followtheflowai.com