Traza is built for riders. We collect what we need to draw your route on a map and let you share it with the people you ride with — nothing more.
1. Who we are
Traza is operated by Alexandre Llagostera, trading as Traza, based in Barcelona, Spain.
- General contact: hello@gettraza.com
- Privacy contact: privacy@gettraza.com
- Spanish supervisory authority: AEPD
2. What we collect
Account data
- Email — to identify your account and let you sign in.
- Display name — what other riders see.
- Profile photo (optional) — only if you upload one.
- Sign-in identifier — when you use Apple or Google sign-in.
Location — only during active routes
- GPS coordinates, speed, altitude, heading, accuracy — sampled while a route recording is running.
- Background location so the recording continues with the phone in your pocket or on a vibration-isolated handlebar mount.
- We do not track your location passively, in the background outside of active routes, or when the app is closed and no route is recording.
Route content
The route line, session timestamps, telemetry derived from GPS (top speed, distance, elevation), names you give to routes, and any photos or notes you attach. Plus garage entries (vehicles you add to your profile).
Device data
Device model, iOS version, app version, language, timezone, and a Traza-generated install identifier — to debug crashes and ship updates that work on your device.
Aggregate usage data
Counts of events like "route started", "route saved", "route shared". Used in aggregate. Not tied to your identity in our analytics tooling.
3. What we don't collect
- No passive location tracking. Location only flows while you have a route running.
- No data sales. Ever.
- No third-party advertising trackers. No Facebook SDK, no ad networks.
- No microphone, no health/fitness data, no contacts, unless and until we add a feature that requires it and ask you for permission.
- No crash reporting service is wired up at this time. If we add one (e.g. Sentry, Apple Crashlytics) we will update this policy and notify users.
- No data from anyone under 16.
4. Why we collect it (legal basis)
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Email, name, sign-in ID | Operate your account | Contract — 6(1)(b) |
| Profile photo (optional) | Show on your profile | Consent — 6(1)(a) |
| Location during active routes | Record the route you asked us to record | Contract — 6(1)(b) |
| Background location during active routes | Keep recording with phone in pocket / on bike | Contract — 6(1)(b) |
| Route content, garage | Store and display what you create | Contract — 6(1)(b) |
| Device data | Operate the service, ship working updates | Legitimate interest — 6(1)(f) |
| Aggregate usage | Understand which features get used | Legitimate interest — 6(1)(f) |
You can object to any processing based on legitimate interest — see §8.
5. Who we share it with
We share data with a small number of vendors, only because we need them to run the service. Each is bound by a Data Processing Agreement.
| Processor | What they do | Region |
|---|---|---|
| Supabase | Database, auth, file storage | EU |
| Mapbox | Map tiles and geocoding | Global CDN |
| Apple | Sign in with Apple, push, TestFlight | Global |
| Sign in with Google | Global | |
| Vercel | Landing page and admin dashboard hosting | EU/Global |
We do not share data with advertisers, data brokers, or anyone else.
International transfers
Where data leaves the EEA, transfers are covered by the European Commission's Standard Contractual Clauses (SCCs) or an equivalent valid mechanism.
6. How long we keep it
| Data | Retention |
|---|---|
| Account data | While your account exists. Deleted within 30 days of deletion. |
| Route content & garage | While your account exists. Deleted within 30 days (or immediately when you delete a route). |
| Aggregate usage | Up to 24 months in aggregated form. |
| Backups | Encrypted backups retained up to 30 days after deletion, then purged. |
7. How we protect it
- All connections use TLS 1.2+.
- Passwords are never stored — sign-in goes through Apple, Google, or hashed credentials at our identity provider.
- Database access is restricted by row-level security: you can only ever read or write your own data.
If a breach occurs that affects your data, we will tell you within 72 hours, as required by Art. 33 GDPR.
8. Your rights
Under the GDPR / RGPD you have the right to access, correct, export, delete, object, restrict, and withdraw consent.
To exercise any of these, email privacy@gettraza.com from the address on your account. We respond within 30 days.
If you're not satisfied with our response, you can file a complaint with the Agencia Española de Protección de Datos (AEPD).
9. Children
Traza is not designed for or marketed to people under 16. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, email privacy@gettraza.com and we will delete it.
10. Changes
When we make material changes, we'll update the date above, notify active users in-app before the change takes effect, and keep prior versions available on request.
11. Contact
- Privacy: privacy@gettraza.com
- Everything else: hello@gettraza.com
- Postal: Alexandre Llagostera (Traza), Barcelona, Spain