Privacy Policy

Last updated: June 28, 2026

This Policy describes what personal data RouteLab (the “Service”, “we”) collects, why we use it, whom we share it with and what rights you have regarding this data. By using the Service you confirm that you have read and understood this Policy.

1. Data controller

The data controller (in GDPR terms) is the RouteLab team. For any questions about personal data, contact us at privacy@routelab.app.

2. Data we collect

2.1. Sign-up and profile

2.2. Content you create

2.3. Technical data

3. Why we use this data

4. Legal basis for processing (GDPR Art. 6)

5. Who we share data with (Sub-processors)

We do not sell your data to third parties. To run the Service we use the following sub-processors, which may receive data to the extent needed to provide their services:

6. Public content

A route “published to the feed” is publicly visible to all users, including logged-out visitors. A route “via link” is accessible to anyone with the direct link. A “draft” is visible only to you. Your name, username, avatar and public routes appear on your public profile at /u/<username>.

7. Retention

We keep your data while your account exists. When you delete your account (available in profile settings), all your data is irreversibly removed from our database. Supabase backups may retain deleted data for up to 7 days.

8. Your rights

Under GDPR (Articles 15–22) you have the following rights:

Send rights requests to privacy@routelab.app. We respond within 30 days.

9. Data security

We use industry practices: encryption in transit (TLS), Row Level Security in the database (only you can access your data, and only via an authorized session), password hashing. However, no online service can guarantee 100% security — use unique passwords and never share your credentials.

10. Children

The Service is not intended for anyone under 16. If we learn we collected data of a child under 16 without a parent's or guardian's consent, we will delete it promptly.

11. International data transfers

Our sub-processors' servers may be located outside the European Economic Area (EEA). Transfers rely on Standard Contractual Clauses (SCC) approved by the European Commission, or other legal mechanisms ensuring an adequate level of protection.

12. Changes to this policy

We may update this Policy. We will notify you of material changes by email or through the Service. The last-updated date is shown at the top.

13. Contact

For any questions about your data, contact privacy@routelab.app.