Privacy Policy

Take the Scenic Route (TTSR) — Last updated: 4 July 2026

1. Who We Are

Take the Scenic Route ("TTSR") is a travel journal and trip planning application developed and operated by:

Data ControllerPomme Bleue
Contact Emailprivacy@ttsr.net
Registered Address[Pomme Bleue Registered Address]

Pomme Bleue is the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR).

EU Representative

If you are located in the European Economic Area (EEA), you may contact our EU representative at: [Pomme Bleue EU Representative Address — to be confirmed].

Data Protection Officer (DPO)

We have appointed a Data Protection Officer who can be contacted at privacy@ttsr.net for all matters relating to data protection.


2. How This Policy Applies

This privacy policy explains how Pomme Bleue collects, uses, shares, and protects your personal data when you use:

  • The TTSR mobile app (iOS and Android)
  • The TTSR web application (Next.js)
  • Any related services, features, or communications

It applies to all users of TTSR, whether you are based in the United Kingdom, the European Economic Area (EEA), or elsewhere.


3. What Personal Data We Collect and Why

We collect and process the following categories of personal data. For each category, we explain the lawful basis we rely on under Article 6 of the UK GDPR and EU GDPR.

3.1 Account and Profile Data

Data TypeSpecific DataLawful Basis
AuthenticationEmail address, password (hashed via Supabase Auth)Contract (necessary to create and maintain your account)
Profile InformationFull name, avatar URL (photo), language preferenceContract (necessary to provide profile features)
Home LocationHome country, home city, home latitude/longitudeContract (necessary for the trip planning features)
Vehicle/Rig DetailsOutfit type, make, model, year, dimensions, weight, trailer informationConsent (optional data you choose to provide)
Pet DetailsPet name, type (dog/cat/ferret), microchip number (ISO 11784/11785)Consent (optional data you choose to provide)
Privacy ConsentIP address (captured at signup via the ipify API — api.ipify.org)Consent (you actively tick a checkbox accepting this Privacy Policy; your IP address is recorded as part of that consent to create a verifiable audit trail of your acceptance)

Note on Privacy Consent Audit Trail: When you sign up and accept this Privacy Policy, we record your IP address in a dedicated privacy_consents table. This creates a tamper-resistant audit trail of when and from which IP address you provided your consent, as required under Articles 7(1) and 5(2) of the UK GDPR and EU GDPR (accountability principle). No further IP address tracking occurs beyond this one-time capture at signup.

3.2 Trip and Journal Data

Data TypeSpecific DataLawful Basis
Trip DetailsTitle, description, dates, destinations, countries, border crossings, accommodationsContract (core functionality of the service)
ActivitiesActivity type, title, description, timeslot, location, cost, booking info, accessibility needs, party compositionContract (core functionality of the service)
Journal PostcardsNotes, photos/images, location, latitude/longitude, weather data, altitude, distance from home, music selections (song title, artist), AI-generated haikusContract (core functionality of the service)
Widget DataStructured JSON data attached to postcards (weather, altitude, music, haiku)Contract (optional enhancement to the journal feature)

3.3 Location Data

Data TypeSpecific DataLawful Basis
GPS LocationPrecise latitude/longitude from your device (captured when creating postcards)Consent (device permission requested via expo-location; you may deny at any time)
Geocoding SearchesSearch queries (place names, addresses) you enter for location lookupContract (necessary to search and select locations)
Trip DestinationsDestination cities, countries, and coordinates you add to your tripsContract (core trip planning functionality)

3.4 Photos and Media

Data TypeSpecific DataLawful Basis
Uploaded PhotosImages you upload to postcards, stored in our Supabase Storage bucketConsent (you choose which photos to upload)
AI Haiku PhotosPhotos you optionally submit to our AI haiku generation feature (sent to OpenRouter for processing; not stored server-side)Consent (opt-in feature; photo is processed transiently)

3.5 Communications and Feedback

Data TypeSpecific DataLawful Basis
Feedback/SupportSubject, message, app version, device OS, device modelLegitimate interests (improving our service and responding to user enquiries)
Transactional EmailsEmail address, email content (via Resend; used for account notifications and optional marketing)Contract (service communications) / Consent (marketing emails)

3.6 Analytics and Error Monitoring

Data TypeSpecific DataLawful Basis
Usage Analytics (Web)Page views, clicks, session recordings, web vitals, browser/device info (via PostHog)Consent (via cookie consent banner) / Legitimate interests (service improvement and error detection)
Error ReportsError messages, stack traces, device ID, OS platform, app version (captured via PostHog and custom error capture)Legitimate interests (maintaining service stability and fixing bugs)

4. How We Collect Your Data

We collect personal data through the following methods:

  • Direct input: Information you provide when creating an account, setting up your profile, planning trips, writing journal entries, or submitting feedback.
  • Automatic collection: Device information, app version, and error data collected through PostHog analytics and our error capture system.
  • Device permissions: With your consent, we access your device's GPS for location-based features and your photo library for uploading images. You can manage these permissions at any time through your device settings.
  • We do not purchase personal data from third parties.

5. How We Share Your Data

We do not sell your personal data. We share your data only with trusted service providers (data processors) who help us deliver the TTSR service. All processors are contractually bound to process your data only on our instructions and to implement appropriate technical and organisational security measures.

Third-Party Data Processors

ProcessorPurposeData ProcessedLocationSafeguards
SupabaseDatabase, Authentication, File Storage, Serverless FunctionsAll user data (profile, trips, postcards, photos, settings), authentication credentialsUnited States (multi-region)Standard Contractual Clauses (SCCs) — covered by Supabase's standard Data Processing Agreement
PostHogProduct analytics, error tracking, session replayPage views, user interactions, errors, device info, user ID and email (for identified users), session recordingsUnited StatesStandard Contractual Clauses (SCCs) — accepted via account settings
ResendTransactional and marketing email deliveryEmail addresses, email content, subject linesUnited StatesStandard Contractual Clauses (SCCs) — covered by Resend's standard terms
DeepSeekAI-powered activity suggestionsActivity preferences, location data, weather context, free-text notes (prompt-injection sanitised)ChinaData minimisation, no persistent storage, encryption in transit. SCCs used where available.
OpenRouterAI haiku generation from photosBase64-encoded photo images, mood, location description, weather context, language preference (processed transiently)United States / Global (multi-region)Data minimisation and transient processing (images not stored server-side)
OpenWeatherMapWeather forecast dataLatitude, longitude, language preferenceUnited StatesReliance on data minimisation — only minimal location data sent
GeoapifyForward and reverse geocoding (address lookup)Search queries (place names), latitude, longitudeGlobal (multi-region)Reliance on data minimisation — search queries are transient
Open-ElevationAltitude/elevation dataLatitude, longitudeUnited StatesReliance on data minimisation — only coordinates sent
iTunes Search APIMusic search for postcard listening-to widgetFree-text song/artist search queriesUnited StatesReliance on data minimisation — search queries are transient
DeepLTranslation of app UI text and country dataApp UI text strings, country names (no personal data is translated)European Union (Germany)Adequate under EU GDPR — no personal data is translated
Apple Maps (iOS)Map tile rendering within the mobile appDevice IP address, map tile requests (processed by Apple's standard map service)Apple's serversApple's privacy framework
Google Maps (Android)Map tile rendering within the mobile appDevice IP address, map tile requests (processed by Google's standard map service)Google's serversGoogle's privacy framework
OpenStreetMap (Web)Map tile rendering on the web applicationBrowser IP address (standard HTTP request for tile images)Global (community-operated infrastructure)OpenStreetMap privacy policy

6. International Data Transfers

Your personal data may be transferred to and processed in countries outside the United Kingdom and the European Economic Area (EEA), including:

  • United States (Supabase, PostHog, Resend, OpenWeatherMap, Geoapify, Open-Elevation, iTunes Search API)
  • China (DeepSeek)
  • Global (OpenRouter, OpenStreetMap)

When we transfer your data to countries that the UK Government and the European Commission have not deemed to provide an adequate level of data protection, we apply the following safeguard measures depending on the provider and the nature of the data:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission and the UK International Data Transfer Agreement (IDTA). Used for major providers (Supabase, PostHog, Resend) through their standard Data Processing Agreements.
  • Data minimisation and transient processing for services where formal SCCs are not commercially available (free-tier APIs, open data services). Only the minimum data needed for the feature is sent, and it is not stored by the provider beyond the immediate request.
  • Encryption in transit using TLS 1.2+ for all API communications.

You can request a copy of the relevant safeguards by contacting us at privacy@ttsr.net.


7. Cookies, Local Storage, and Similar Technologies

We use cookies and similar local storage technologies to provide and improve our service. Below is a summary of the technologies we use:

7.1 Essential Cookies and Storage

These are necessary for the service to function and cannot be disabled:

TechnologyPurposeDuration
Supabase Auth Cookies (sb-*-auth-token)Authentication session management (web)Session
NEXT_LOCALELanguage preference (web)1 year
admin_last_activeAdmin inactivity timeout (web)1 hour
AsyncStorage (Mobile)Supabase auth session persistence (mobile)Until sign-out
SQLite Database (ttsr-cache-v2.db)Local offline data mirror (mobile)Until deleted or app uninstalled

7.2 Analytics Storage

TechnologyPurposeDuration
PostHog Cookies / localStorageAnonymous usage analytics, session recording, feature tracking1 year

7.3 Cache Storage

TechnologyPurposeDuration
localStorage (elevation_cache_*)Cached elevation data (web)24 hours
In-memory cacheWeather data, AI request caching5 minutes – 30 minutes

7.4 Managing Cookies and Local Storage

You can control and manage cookies through your browser settings. On mobile, you can clear app data through your device settings. Note that disabling essential cookies/storage may prevent the service from functioning properly.


8. Data Retention

We retain your personal data only for as long as necessary to provide the service:

Data CategoryRetention Period
Account data (profile, settings)Until account deletion
Trip and journal dataUntil account deletion
Uploaded photosUntil account deletion (or earlier if you delete individual postcards)
Cache data (weather, elevation, AI)Automatically expires after TTL (5 minutes – 24 hours)
Analytics and error logs13 months (PostHog) / 90 days (in-house error logs)
Feedback submissionsUntil resolved and archived (typically 6 months)
Email communicationsUntil you unsubscribe or request deletion

When you delete your account, all your personal data is permanently deleted through a cascading delete process. Cache entries and local SQLite data on your device will persist until cleared through the app or device settings.


9. Your Rights Under UK GDPR and EU GDPR

You have the following rights regarding your personal data. These rights are available to all users under the UK GDPR and EU GDPR, regardless of where you are based:

Right to Access (Art. 15)

You have the right to request a copy of the personal data we hold about you, along with information about how we process it.

Right to Rectification (Art. 16)

You have the right to correct any inaccurate or incomplete personal data. You can update most of your data directly through your profile and account settings.

Right to Erasure (Art. 17) — "Right to be Forgotten"

You have the right to request the deletion of your personal data. You can delete individual postcards, trips, or your entire account through the app. We will process your request without undue delay.

Right to Restrict Processing (Art. 18)

You have the right to request that we restrict the processing of your personal data in certain circumstances (e.g., while a correction request is being verified).

Right to Data Portability (Art. 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON), and to transmit that data to another controller without hindrance.

Right to Object (Art. 21)

You have the right to object to the processing of your personal data where we rely on legitimate interests as our lawful basis. We will comply unless we have compelling legitimate grounds that override your interests.

Rights Related to Automated Decision-Making (Art. 22)

You have the right not to be subject to a decision based solely on automated processing. Our AI features (activity suggestions and haiku generation) are optional tools that require your active input and are not used for automated decision-making that produces legal effects.

How to Exercise Your Rights

To exercise any of these rights, please contact us at privacy@ttsr.net. We will respond to your request within one month (extendable by two months for complex or multiple requests). We may ask you to verify your identity before processing your request.


10. Security Measures

We implement appropriate technical and organisational security measures to protect your personal data, including:

  • Row-Level Security (RLS) on all database tables — users can only access their own data
  • JWT authentication with PKCE flow (mobile) and HTTP-only cookies (web)
  • Password hashing managed by Supabase Auth (bcrypt-based)
  • SQL injection prevention through column allowlists and parameterised queries
  • Prompt injection sanitisation on all AI features to prevent misuse
  • Admin multi-factor authentication (TOTP-based MFA for admin accounts)
  • Rate limiting on admin routes (60 requests/minute per IP)
  • HTTPS/TLS encryption for all data in transit
  • Content Security Policy (CSP) headers on web routes

11. Children's Privacy

TTSR is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@ttsr.net and we will take steps to delete such information.

Note: The UK GDPR sets the digital age of consent at 13, while EU member states may set it between 13 and 16. We apply the highest standard (16) across all jurisdictions.


12. Changes to This Privacy Policy

We may update this privacy policy from time to time. We will notify you of any material changes by:

  • Displaying a notice within the app and/or website
  • Sending an email notification (if we have your email address)
  • Updating the "Last updated" date at the top of this policy

We encourage you to review this policy periodically. Material changes will take effect30 days after notification.


13. Contact Us

If you have any questions, concerns, or requests regarding this privacy policy or our data practices, please contact our Data Protection Officer:

Emailprivacy@ttsr.net
Data ControllerPomme Bleue
Registered Address[Pomme Bleue Registered Address]

14. Right to Complain

If you are unsatisfied with how we handle your personal data, you have the right to lodge a complaint with your local data protection supervisory authority:

In the United Kingdom

Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113

In the European Union

You may lodge a complaint with the local data protection authority in the EU member state of your habitual residence, place of work, or the place of the alleged infringement. Contact details for all EU data protection authorities are available at edpb.europa.eu.

We would appreciate the opportunity to address your concerns before you approach a supervisory authority. Please contact us first at privacy@ttsr.net.


15. Legal Framework

This privacy policy is designed to comply with:

  • The UK General Data Protection Regulation (UK GDPR) — as retained in UK law post-Brexit
  • The EU General Data Protection Regulation (EU GDPR 2016/679)
  • The Privacy and Electronic Communications Regulations (PECR) — UK
  • The ePrivacy Directive (2002/58/EC) — EU

Disclaimer

This privacy policy is for informational purposes only and does not constitute legal advice. Laws vary by jurisdiction, and you should consult with a qualified legal professional to ensure compliance with applicable data protection regulations.

This document was generated for Take the Scenic Route (TTSR) and reflects current UK and EU data protection requirements as of 4 July 2026.

Take the Scenic Route