Legal

Privacy Policy

We believe in plain English, not legalese. Here is exactly how we handle your data, keeping it safe and private.

Last updated: August 16, 2026

1. What We Collect

The Short Version

We only collect what we need: your email, your maps, and basic usage stats.

  • —Account Info: Email address and name.
  • —Project Data: Your GPX files, pins, and stories.
  • —Usage Data: Basic product usage, like view counts on stories you publish, and product analytics events (e.g. which steps of story creation you complete) to help us improve the product — never your email or GPS coordinates.
  • —Payment Data: Handled securely by Paddle, our Merchant of Record (we never see your full card number).

2. How We Use It

The Short Version

We use your data to make RouteTale work. We NEVER sell it.

  • —Operating the Service: Saving your routes and rendering maps.
  • —Communication: Sending essential account and billing emails.
  • —Improvement: Fixing bugs and building better features.

3. Data Sharing

The Short Version

We only share data with essential services (like hosting or payments).

  • —Sub-processors: cloud object storage (S3-compatible) for your files, Paddle (payments), Resend (emails), MapTiler (map tiles), Sentry (error monitoring), PostHog (product analytics) — no email or location data included in either.
  • —Third-party Integrations: If you connect Google or Strava to import a route, that service processes only the data you authorize.
  • —Google API Limited Use: RouteTale's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
  • —Legal Compliance: Only if required by a valid legal request.
  • —Public Stories: If you publish a story, it becomes public. Do not share sensitive locations.

4. Data Security

The Short Version

Sensitive data — connected-account credentials and your files — is encrypted, both in transit and at rest.

  • —Encryption in transit: all traffic between your browser and RouteTale is sent over HTTPS/TLS.
  • —Encryption at rest: OAuth credentials for connected accounts (Google, Strava) are encrypted at the field level before being stored in our database — never stored as plain text.
  • —Your files: GPX routes, photos, and other project data are stored in encrypted cloud object storage.
  • —Access control: API requests are authenticated, and every request is scoped to your account — we never return another user's data.
  • —Google Photos: photos you select via the Google Photos Picker are fetched only for the items you pick in that session. RouteTale never lists or accesses your full Google Photos library.

5. Your Rights

The Short Version

It's your data. You can ask us to export or delete it anytime.

  • —Self-service export and account deletion from Settings are not available yet — email us at support@routetale.app and we'll handle the request for you.
  • —Once a deletion request is processed, your data is permanently removed within 30 days.
  • —Email support for any GDPR or privacy request — access, correction, deletion, or portability.

6. Cookies & Local Storage

The Short Version

No advertising cookies. Product analytics only run if you accept the cookie banner.

  • —We store your login session (access and refresh tokens) in your browser's local storage so you stay signed in.
  • —Product analytics (PostHog) sets its own cookies/local storage to track usage, but only after you click Accept on the cookie banner — it stays off by default and you can decline at any time.
  • —We don't use third-party advertising or ad-tracking cookies.
  • —Clearing your browser storage will sign you out and reset your cookie preference.