Take the Scenic Route (TTSR) — Last updated: 4 July 2026
Take the Scenic Route ("TTSR") is a travel journal and trip planning application developed and operated by:
| Data Controller | Pomme Bleue |
| Contact Email | privacy@ttsr.net |
| Registered Address | [Pomme Bleue Registered Address] |
Pomme Bleue is the data controller for the purposes of the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR).
If you are located in the European Economic Area (EEA), you may contact our EU representative at: [Pomme Bleue EU Representative Address — to be confirmed].
We have appointed a Data Protection Officer who can be contacted at privacy@ttsr.net for all matters relating to data protection.
This privacy policy explains how Pomme Bleue collects, uses, shares, and protects your personal data when you use:
It applies to all users of TTSR, whether you are based in the United Kingdom, the European Economic Area (EEA), or elsewhere.
We collect and process the following categories of personal data. For each category, we explain the lawful basis we rely on under Article 6 of the UK GDPR and EU GDPR.
| Data Type | Specific Data | Lawful Basis |
|---|---|---|
| Authentication | Email address, password (hashed via Supabase Auth) | Contract (necessary to create and maintain your account) |
| Profile Information | Full name, avatar URL (photo), language preference | Contract (necessary to provide profile features) |
| Home Location | Home country, home city, home latitude/longitude | Contract (necessary for the trip planning features) |
| Vehicle/Rig Details | Outfit type, make, model, year, dimensions, weight, trailer information | Consent (optional data you choose to provide) |
| Pet Details | Pet name, type (dog/cat/ferret), microchip number (ISO 11784/11785) | Consent (optional data you choose to provide) |
| Privacy Consent | IP address (captured at signup via the ipify API — api.ipify.org) | Consent (you actively tick a checkbox accepting this Privacy Policy; your IP address is recorded as part of that consent to create a verifiable audit trail of your acceptance) |
Note on Privacy Consent Audit Trail: When you sign up and accept this Privacy Policy, we record your IP address in a dedicated privacy_consents table. This creates a tamper-resistant audit trail of when and from which IP address you provided your consent, as required under Articles 7(1) and 5(2) of the UK GDPR and EU GDPR (accountability principle). No further IP address tracking occurs beyond this one-time capture at signup.
| Data Type | Specific Data | Lawful Basis |
|---|---|---|
| Trip Details | Title, description, dates, destinations, countries, border crossings, accommodations | Contract (core functionality of the service) |
| Activities | Activity type, title, description, timeslot, location, cost, booking info, accessibility needs, party composition | Contract (core functionality of the service) |
| Journal Postcards | Notes, photos/images, location, latitude/longitude, weather data, altitude, distance from home, music selections (song title, artist), AI-generated haikus | Contract (core functionality of the service) |
| Widget Data | Structured JSON data attached to postcards (weather, altitude, music, haiku) | Contract (optional enhancement to the journal feature) |
| Data Type | Specific Data | Lawful Basis |
|---|---|---|
| GPS Location | Precise latitude/longitude from your device (captured when creating postcards) | Consent (device permission requested via expo-location; you may deny at any time) |
| Geocoding Searches | Search queries (place names, addresses) you enter for location lookup | Contract (necessary to search and select locations) |
| Trip Destinations | Destination cities, countries, and coordinates you add to your trips | Contract (core trip planning functionality) |
| Data Type | Specific Data | Lawful Basis |
|---|---|---|
| Uploaded Photos | Images you upload to postcards, stored in our Supabase Storage bucket | Consent (you choose which photos to upload) |
| AI Haiku Photos | Photos you optionally submit to our AI haiku generation feature (sent to OpenRouter for processing; not stored server-side) | Consent (opt-in feature; photo is processed transiently) |
| Data Type | Specific Data | Lawful Basis |
|---|---|---|
| Feedback/Support | Subject, message, app version, device OS, device model | Legitimate interests (improving our service and responding to user enquiries) |
| Transactional Emails | Email address, email content (via Resend; used for account notifications and optional marketing) | Contract (service communications) / Consent (marketing emails) |
| Data Type | Specific Data | Lawful Basis |
|---|---|---|
| Usage Analytics (Web) | Page views, clicks, session recordings, web vitals, browser/device info (via PostHog) | Consent (via cookie consent banner) / Legitimate interests (service improvement and error detection) |
| Error Reports | Error messages, stack traces, device ID, OS platform, app version (captured via PostHog and custom error capture) | Legitimate interests (maintaining service stability and fixing bugs) |
We collect personal data through the following methods:
We do not sell your personal data. We share your data only with trusted service providers (data processors) who help us deliver the TTSR service. All processors are contractually bound to process your data only on our instructions and to implement appropriate technical and organisational security measures.
| Processor | Purpose | Data Processed | Location | Safeguards |
|---|---|---|---|---|
| Supabase | Database, Authentication, File Storage, Serverless Functions | All user data (profile, trips, postcards, photos, settings), authentication credentials | United States (multi-region) | Standard Contractual Clauses (SCCs) — covered by Supabase's standard Data Processing Agreement |
| PostHog | Product analytics, error tracking, session replay | Page views, user interactions, errors, device info, user ID and email (for identified users), session recordings | United States | Standard Contractual Clauses (SCCs) — accepted via account settings |
| Resend | Transactional and marketing email delivery | Email addresses, email content, subject lines | United States | Standard Contractual Clauses (SCCs) — covered by Resend's standard terms |
| DeepSeek | AI-powered activity suggestions | Activity preferences, location data, weather context, free-text notes (prompt-injection sanitised) | China | Data minimisation, no persistent storage, encryption in transit. SCCs used where available. |
| OpenRouter | AI haiku generation from photos | Base64-encoded photo images, mood, location description, weather context, language preference (processed transiently) | United States / Global (multi-region) | Data minimisation and transient processing (images not stored server-side) |
| OpenWeatherMap | Weather forecast data | Latitude, longitude, language preference | United States | Reliance on data minimisation — only minimal location data sent |
| Geoapify | Forward and reverse geocoding (address lookup) | Search queries (place names), latitude, longitude | Global (multi-region) | Reliance on data minimisation — search queries are transient |
| Open-Elevation | Altitude/elevation data | Latitude, longitude | United States | Reliance on data minimisation — only coordinates sent |
| iTunes Search API | Music search for postcard listening-to widget | Free-text song/artist search queries | United States | Reliance on data minimisation — search queries are transient |
| DeepL | Translation of app UI text and country data | App UI text strings, country names (no personal data is translated) | European Union (Germany) | Adequate under EU GDPR — no personal data is translated |
| Apple Maps (iOS) | Map tile rendering within the mobile app | Device IP address, map tile requests (processed by Apple's standard map service) | Apple's servers | Apple's privacy framework |
| Google Maps (Android) | Map tile rendering within the mobile app | Device IP address, map tile requests (processed by Google's standard map service) | Google's servers | Google's privacy framework |
| OpenStreetMap (Web) | Map tile rendering on the web application | Browser IP address (standard HTTP request for tile images) | Global (community-operated infrastructure) | OpenStreetMap privacy policy |
Your personal data may be transferred to and processed in countries outside the United Kingdom and the European Economic Area (EEA), including:
When we transfer your data to countries that the UK Government and the European Commission have not deemed to provide an adequate level of data protection, we apply the following safeguard measures depending on the provider and the nature of the data:
You can request a copy of the relevant safeguards by contacting us at privacy@ttsr.net.
We use cookies and similar local storage technologies to provide and improve our service. Below is a summary of the technologies we use:
These are necessary for the service to function and cannot be disabled:
| Technology | Purpose | Duration |
|---|---|---|
| Supabase Auth Cookies (sb-*-auth-token) | Authentication session management (web) | Session |
| NEXT_LOCALE | Language preference (web) | 1 year |
| admin_last_active | Admin inactivity timeout (web) | 1 hour |
| AsyncStorage (Mobile) | Supabase auth session persistence (mobile) | Until sign-out |
| SQLite Database (ttsr-cache-v2.db) | Local offline data mirror (mobile) | Until deleted or app uninstalled |
| Technology | Purpose | Duration |
|---|---|---|
| PostHog Cookies / localStorage | Anonymous usage analytics, session recording, feature tracking | 1 year |
| Technology | Purpose | Duration |
|---|---|---|
| localStorage (elevation_cache_*) | Cached elevation data (web) | 24 hours |
| In-memory cache | Weather data, AI request caching | 5 minutes – 30 minutes |
You can control and manage cookies through your browser settings. On mobile, you can clear app data through your device settings. Note that disabling essential cookies/storage may prevent the service from functioning properly.
We retain your personal data only for as long as necessary to provide the service:
| Data Category | Retention Period |
|---|---|
| Account data (profile, settings) | Until account deletion |
| Trip and journal data | Until account deletion |
| Uploaded photos | Until account deletion (or earlier if you delete individual postcards) |
| Cache data (weather, elevation, AI) | Automatically expires after TTL (5 minutes – 24 hours) |
| Analytics and error logs | 13 months (PostHog) / 90 days (in-house error logs) |
| Feedback submissions | Until resolved and archived (typically 6 months) |
| Email communications | Until you unsubscribe or request deletion |
When you delete your account, all your personal data is permanently deleted through a cascading delete process. Cache entries and local SQLite data on your device will persist until cleared through the app or device settings.
You have the following rights regarding your personal data. These rights are available to all users under the UK GDPR and EU GDPR, regardless of where you are based:
You have the right to request a copy of the personal data we hold about you, along with information about how we process it.
You have the right to correct any inaccurate or incomplete personal data. You can update most of your data directly through your profile and account settings.
You have the right to request the deletion of your personal data. You can delete individual postcards, trips, or your entire account through the app. We will process your request without undue delay.
You have the right to request that we restrict the processing of your personal data in certain circumstances (e.g., while a correction request is being verified).
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON), and to transmit that data to another controller without hindrance.
You have the right to object to the processing of your personal data where we rely on legitimate interests as our lawful basis. We will comply unless we have compelling legitimate grounds that override your interests.
You have the right not to be subject to a decision based solely on automated processing. Our AI features (activity suggestions and haiku generation) are optional tools that require your active input and are not used for automated decision-making that produces legal effects.
To exercise any of these rights, please contact us at privacy@ttsr.net. We will respond to your request within one month (extendable by two months for complex or multiple requests). We may ask you to verify your identity before processing your request.
We implement appropriate technical and organisational security measures to protect your personal data, including:
TTSR is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at privacy@ttsr.net and we will take steps to delete such information.
Note: The UK GDPR sets the digital age of consent at 13, while EU member states may set it between 13 and 16. We apply the highest standard (16) across all jurisdictions.
We may update this privacy policy from time to time. We will notify you of any material changes by:
We encourage you to review this policy periodically. Material changes will take effect30 days after notification.
If you have any questions, concerns, or requests regarding this privacy policy or our data practices, please contact our Data Protection Officer:
| privacy@ttsr.net | |
| Data Controller | Pomme Bleue |
| Registered Address | [Pomme Bleue Registered Address] |
If you are unsatisfied with how we handle your personal data, you have the right to lodge a complaint with your local data protection supervisory authority:
Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113
You may lodge a complaint with the local data protection authority in the EU member state of your habitual residence, place of work, or the place of the alleged infringement. Contact details for all EU data protection authorities are available at edpb.europa.eu.
We would appreciate the opportunity to address your concerns before you approach a supervisory authority. Please contact us first at privacy@ttsr.net.
This privacy policy is designed to comply with:
This privacy policy is for informational purposes only and does not constitute legal advice. Laws vary by jurisdiction, and you should consult with a qualified legal professional to ensure compliance with applicable data protection regulations.
This document was generated for Take the Scenic Route (TTSR) and reflects current UK and EU data protection requirements as of 4 July 2026.