Die schönsten Wanderwege
GermanDEEnglishEN

Privacy policy

This policy explains which data is processed when using the Wanderer app, for what purpose, on which legal basis, and what rights are attached to it. It applies to the app on iOS and Android, to the associated web services at wanderer-app.cc, and to the separate web administration area through which mountain huts, regions and partner businesses are maintained (see 3.17).

The German version of this document is the authoritative one; this translation is provided for convenience.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Controller
Die schönsten Wanderwege
Karin & Erwin Neuherz (GesbR)
Klam 87
4352 Klam
Austria
Karin Neuherz
+43 (0) 660 / 352 94 31
Erwin Neuherz
+43 (0) 680 / 405 54 47
Email
office@wanderwege.cc
Web
www.wanderwege.cc
Privacy enquiries
privacy@wanderer-app.cc

Privacy enquiries and requests to exercise data subject rights are to be addressed here.

No data protection officer has been appointed. Because the app processes location data, direct messages and community profiles, the criteria of Art. 37(1) GDPR were examined explicitly: we are not a public authority (point (a)), and the processing of special categories of personal data or of data relating to criminal offences is not a core activity (point (c)). Recording hikes does constitute systematic monitoring within the meaning of point (b); it takes place only after explicit permission has been granted, for the duration of the individual recording, and across a regionally limited number of accounts — the additional requirement of “large scale” is therefore not met at present. Austrian data protection law imposes no further obligation to appoint. This assessment will be repeated if the number of users grows substantially, together with the question of a data protection impact assessment under Art. 35 GDPR.

A representative in the Union under Art. 27 GDPR is not required, as the controller is established in Austria.

2. Principles

Using the app requires an account. Without signing in, only the loading screen and the sign-in screen are accessible; trails, mountain huts, regions, maps and community content become available once you have registered. Personal data therefore arises from the moment the account is created. What is processed beyond that depends on the features used — recording a hike, publishing content, sending messages.

Beyond what registration requires, we ask for nothing: the self-description and the profile picture are optional, access to location can be refused, and usage analytics is disabled by default.

The website at wanderer-app.cc, by contrast, is accessible without an account. Anyone opening a shared item there leaves behind only the data that arises when a page is served (see 3.18).

Data is stored on servers in Ireland and therefore within the European Union. Data is not processed for third-party advertising purposes, not sold, and not combined into advertising profiles.

3. Processing activities in detail

3.1 Account and sign-in

An account stores an email address and a password. The password is held solely as a cryptographic hash and cannot be read by us. Sign-in via Google or Apple is available as an alternative; in that case the email address and the identifier supplied by the respective provider are processed. With “Sign in with Apple”, the email address can be hidden behind Apple’s relay service.

The time of registration and the times of sign-ins are logged so that misuse of accounts can be traced.

Purpose
provision of the account, authentication, protection against misuse.
Legal basis
performance of the user agreement (Art. 6(1)(b) GDPR); for the logging, legitimate interest in secure operation (Art. 6(1)(f) GDPR).

3.2 Profile

The profile holds a first name, a last name, an optional self-description and an optional profile picture, plus the balance of hiking points earned from completed challenges. A profile can be set to “private” in the settings; content and connections are then visible only to approved followers.

First name, last name and profile picture become visible to other users as soon as posts are published, comments are written or connections are formed. Profile pictures are held in a publicly addressable storage area: anyone who knows a picture’s address can retrieve it without signing in.

Purpose
display of the profile, attribution of content and connections.
Legal basis
performance of the user agreement (Art. 6(1)(b) GDPR); optional details on the basis of consent (Art. 6(1)(a) GDPR).

3.3 Location data

The app accesses the device’s location once this has been permitted at operating-system level. Permission can be withdrawn in the system settings at any time; the app remains usable with a reduced feature set.

Location is used for three purposes:

  • Map display: the current position is shown on the map and used to find trails and huts nearby. This position data is processed on the device only and is not transmitted to our servers.
  • Emergency view: the current coordinates are displayed so that they can be passed on to rescue services in an emergency. There is no automatic transmission to emergency services or to us.
  • Hike recording: once a recording is started, the app continuously captures position, altitude and timestamp (see 3.4).

Once started, a recording continues while the app is in the background or the screen is locked — otherwise the hike would be captured only in part. This applies solely for the duration of a recording: where the map is merely being viewed, location updates stop as soon as the app moves to the background. An ongoing recording is always identifiable — on iOS by the blue location indicator, on Android by a persistent system notification.

Purpose
map display, proximity search, determining position in an emergency, recording hikes.
Legal basis
consent, given by granting the operating-system permission and by starting a recording (Art. 6(1)(a) GDPR).

3.4 Recorded hikes

Recording and saving a hike creates a movement profile of the route covered. The following is stored: the route as a sequence of coordinates with altitude and timestamp, start and end time, duration, distance, ascent and descent, and average speed.

This data is linked to the account and serves the user’s own review. It is not published unless it is actively shared as a post. Individual recordings can be deleted in the app at any time.

A recording is first secured on the device and only then transmitted to our servers. If there is no connection when it is saved, it stays on the device and is transmitted as soon as one is available again; until then it is marked in the app as not yet uploaded and can also be discarded there. The same applies to a recording in progress that was interrupted by the app being terminated: it is preserved on the device and can be resumed or finished the next time the app starts. This safeguarding takes place solely on the device.

Routes can allow conclusions to be drawn about where someone lives or spends time. Before sharing a recording in the community, bear in mind that its start and end points become visible to others.

Purpose
recording, evaluation and management of a user’s own hikes, progress in challenges.
Legal basis
performance of the user agreement (Art. 6(1)(b) GDPR) and consent (Art. 6(1)(a) GDPR) respectively.

3.5 Community content

Posts, uploaded images, comments and likes are stored with a timestamp and a link to the account, and are visible to other users. The same applies to the social graph: who is followed and who follows. For private profiles this information is limited to approved followers; the corresponding check is performed server-side.

Anyone publishing content decides on its scope. Publishing special categories of personal data — health data, for instance — is inadvisable. Images showing other identifiable people should only be uploaded with their agreement.

Published content can be deleted in the app. Copies or screenshots already made by third parties are beyond our control.

Purpose
operation of the community features.
Legal basis
performance of the user agreement (Art. 6(1)(b) GDPR).

3.6 Reports and blocking

Posts, comments, profiles and messages can be reported. A report stores the reporting account, the account concerned, the selected reason, any explanatory text, the time, and the state of processing. It also records the reported text as it stood at the time of the report, so that the review remains traceable even if the content has since been deleted; where the report concerns an image in a message, the reference to the reported image file is recorded in its place. The identity of the reporting person is not disclosed to the reported person.

Every report is delivered to the mailbox info@wanderer-app.cc and reviewed there; delivery is handled by Resend (see section 4). Depending on the outcome, content is hidden or removed and accounts are suspended. Where several people independently report the same post or comment, it is provisionally hidden automatically until the review is complete. The person who wrote it continues to see their own content; the decision on final removal is always taken by a human.

In addition, individual accounts can be blocked. Who blocked whom is stored together with the time — this is the only way to keep both sides’ content apart. A block takes effect in both directions; the blocked person is not notified. Any existing follower connections between the two accounts are deleted in the process.

Purpose
review of reported content, enforcement of the terms of use, protection against harassment.
Legal basis
legal obligation as a hosting service, in particular the notice and action mechanism under Art. 16 of Regulation (EU) 2022/2065 on a Single Market for Digital Services (Art. 6(1)(c) GDPR), and legitimate interest in a safe community (Art. 6(1)(f) GDPR).

3.7 Direct messages

Messages exchanged via the chat feature are stored on our servers with content, sender and timestamp so that they are available on all devices of those involved. A message may also contain an image. It is chosen from the gallery or taken with the camera, scaled down on the device before it is uploaded, and stored separately from the text. Unlike images in posts, these images are held in a non-public storage area: they can only be retrieved from a signed-in session of the accounts taking part in the conversation, not via a generally accessible address. Access is technically restricted to the participants of the conversation concerned. There is no end-to-end encryption: access by us would be technically possible, but occurs only for cause — for example following a report under 3.6, upon reasonable suspicion of criminal conduct, or by order of a public authority.

Purpose
transmission and display of messages between users.
Legal basis
performance of the user agreement (Art. 6(1)(b) GDPR).

3.8 Challenges, hiking points, rewards and giveaways

Every account takes part in challenges automatically; there is no separate opt-in. How a completion is established depends on the type of challenge.

Challenges evaluated from existing data: Depending on the task, this draws on recorded hikes (distance, elevation gain, duration, number, date as well as the assigned trail and its region) or on the number of your own posts, comments, reactions and follow connections. None of this data is created for challenges — it is stored for the purposes set out elsewhere in this policy and is additionally used here for the evaluation. The evaluation runs on our servers and is recalculated on every display; no separate progress figure is kept permanently.

Photo challenges: Anyone completing a photo task uploads an image, which our team reviews and either confirms or rejects. We store the image, any comment added by the user, the time of submission, the processing status, the team member who reviewed it, the time of review and any reason given for a rejection. To help assess the submission, we additionally record whether the image was taken directly with the camera or chosen from the gallery, whether a hike was recorded on the same day and — where the location has been released — the distance to the challenge target in metres. The location coordinates themselves are not stored. Releasing the location is voluntary; a submission is possible without it. On request, the image can at the same time become a post in the feed — that post is independent of the review and is processed in accordance with section 3.5.

Challenges requiring a place: Where a hike is recorded, we compare its route with the challenge target on our servers. Alternatively, presence can be confirmed on site; the current position is transmitted to our server, compared with the target and not stored — only whether the target was reached is recorded.

Challenges with a code: We store the fact that the code was redeemed, not the code itself per person.

Hiking points: An account is kept for hiking points. Every credit and every debit is recorded with the amount, the reason, a reference to the relevant challenge or reward, and the time. This serves to make the points balance traceable — both for users, who can view the history in the app, and for us in the event of queries. Points are only credited once they are collected in the app. Where a badge is attached to a challenge, its award is recorded together with the time.

Redeeming a reward. Redeeming reduces the points balance by the cost of the reward and records the entry in the points account. In addition, a record of the redemption itself is created: which reward, at what cost, how it is handed over, the time and the processing status. The title and cost are recorded as they stood at the time of redemption. Where a voucher code is assigned from a pool or the code of a partner business is taken over, it is stored in the record; it is the proof of redemption and can be viewed in the app at any time. For a voucher shown on site, the time at which it was redeemed there is also recorded.

Delivery address. Only for rewards that are sent by post do we ask for name, street, postcode, town and country. These details are stored with the individual order only, not with the account. They are used for the delivery and deleted afterwards (period in section 6); on cancellation they are removed immediately.

No data is transmitted to partner businesses in the process — fulfilment is always handled by us.

For giveaways, participation, the time of entry and any accompanying entry comment are stored. Where an entry is excluded from the draw, we additionally record the reason, the time and the team member who decided.

The draw itself is recorded: the person drawn, their name at the time of the draw, the number of valid entries, the time and the team member who triggered it. Where a draw is voided, the reason is added. The record serves as evidence of a proper procedure and is visible only to our team; in the app, only who won is shown.

In the event of a win we notify the person drawn twice: with a notification in the app and with an email to the account’s address, sent via Resend. The time of the notification and the text sent are recorded with the draw. Any further details required for settlement are announced separately and deleted once the matter is settled, unless a retention obligation applies.

Purpose
operation of challenges, keeping the points account, reviewing submitted photos, the reward programme and giveaways.
Legal basis
performance of the user agreement or pre-contractual measures (Art. 6(1)(b) GDPR); for the review of submitted photos and the traceability of the points account, additionally our legitimate interest in an abuse-free process (Art. 6(1)(f) GDPR); in the event of a win, additionally legal obligations (Art. 6(1)(c) GDPR).

3.8a “Hiker of the week”

This contest is decided by the response of the community: per person, the post of a calendar week with the most likes is judged. No new data is collected for this — what is evaluated are the posts and likes that are stored under section 3.5 in any case; the evaluation takes place on our servers and is recalculated each time it is displayed.

Once a week has ended, our team reviews the result and closes the week. In doing so, the place, the name at that time, the number of likes, the reference to the post, the time and the team member closing it are recorded. These details do not change afterwards — not even where likes are withdrawn or the post is deleted. That is the purpose: an award whose basis shifts after the fact could not be verified.

Where a post is excluded from the judging, we additionally record the reason, the time and the team member deciding — the evidence that the exclusion took place before the week was closed and for an objective reason.

Whoever is on the podium is named in the app with their first and last name, profile picture and the post concerned, and remains so after the week has ended. Posts from accounts with a private profile do not take part in the judging; nobody is therefore named whose content is not public in any case.

Those placed are notified with a message in the app. Where a week carries a goodie, an email additionally goes to our team — it contains place, name and the number of likes and is the prompt to arrange despatch. It is sent via Resend (see section 4).

For despatch we get in touch with the person placed: with a message in the app and an email to the address of the account, likewise via Resend. We record the time and the text with the week. The details needed for despatch, in particular the address, are to be provided to us in reply; they then sit in our email inbox and are deleted once the matter is settled, unless a retention obligation applies. No address is created with the account or with an order — unlike when a reward is redeemed (section 3.8).

Purpose
Running the contest, making the result verifiable, and handling any prize.
Legal basis
Performance of the user agreement (Art. 6(1)(b) GDPR); for recording the result and any exclusion, additionally our legitimate interest in a manipulation-free and verifiable process (Art. 6(1)(f) GDPR).

3.9 Support requests

Where a support request is submitted through the app, the category, subject, message text and account reference are stored. In the course of handling it, the processing status, an internal urgency rating, the team member responsible, our reply and any internal notes are added to the request. The same applies to details submitted when contacting us by email.

Conversely, our team may approach an account on its own initiative — about a report, a reward redemption or a maintenance arrangement, for instance. This happens by one of two routes. As a message in the app, an ordinary conversation is created between the team member’s account and the account addressed; it is stored like any other direct message (see 3.7), and a reply travels back the same way. As an email to the account’s address, the text is transmitted to our email service provider (see section 4) and additionally created as an entry in the app’s notification area, so that it remains traceable there as well; replies go to info@wanderer-app.cc. We keep no separate log of these contacts — what remains is the conversation, or the entry in the notification area.

Purpose
handling the request, keeping a record of the exchange, contacting accounts about matters concerning them.
Legal basis
performance of the user agreement (Art. 6(1)(b) GDPR) and legitimate interest in orderly handling (Art. 6(1)(f) GDPR).

3.10 Notifications

Push notifications are only sent once permission has been granted at operating-system level. For delivery, a device identifier (push token) is obtained from Firebase Cloud Messaging and stored against the account together with the device platform. Identifiers that have become invalid are removed automatically.

Every notification also creates an entry in the app’s notification area so that it remains accessible afterwards. Triggers include new followers, reactions to a user’s own posts, messages, completed challenges and messages from our team about matters concerning the account. Permission can be withdrawn in the system settings at any time.

Under “Settings → Notifications” you can additionally choose which triggers are delivered to your device — either altogether or per category. This choice is stored against the account so that it is retained on further devices and after a reinstallation. It concerns delivery only: the entry in the app’s notification area is still created, so that the account keeps a record of what happened.

Purpose
delivery and display of notifications.
Legal basis
consent, given by granting the operating-system permission (Art. 6(1)(a) GDPR).

3.11 Usage analytics

The app can collect usage statistics via Google Analytics for Firebase. What is currently recorded: the areas of the app opened, sign-ins together with the method used (email, Google or Apple), and the start and completion of a recording — on completion, additionally the distance, duration and ascent of the hike. What is transmitted: the account identifier in the form of the internal user ID, an instance identifier assigned by the SDK, device type, operating-system version, app version, and the approximate location at country level. Names, email addresses and recorded routes are not transmitted.

These statistics are pseudonymised, not anonymised. The events carry neither a name nor an email address, but remain attributable to an account and an app installation via the user and instance identifiers. They therefore continue to constitute personal data, and the rights set out in section 8 extend to them.

Collection is disabled by default and takes place only after explicit consent. Consent is requested at first sign-in and can be withdrawn at any time with effect for the future under “Settings → Privacy & analytics” in the app. After withdrawal the SDK sends no further events and discards locally cached data. The choice made is stored against the account so that it persists across further devices and after a reinstallation.

Purpose
analysis of usage in order to develop the app further.
Legal basis
consent (Art. 6(1)(a) GDPR).

3.12 Map display

Map material is retrieved at runtime from MapTiler, a service of MapTiler AG, established in Switzerland. When map tiles are loaded, the device’s IP address is transmitted to their servers; without this transmission the map cannot technically be displayed. The access key of our account is also sent along, by which the provider attributes and bills the request to us. Neither account nor position data is transmitted in the process, and no cookies or recognition features are used. The map data is based on OpenStreetMap.

The provider determines the processing of this connection data as a controller in its own right; there is accordingly no data processing agreement under Art. 28 GDPR. According to its privacy statement, it processes IP addresses to secure its services on the basis of a legitimate interest and retains them for that purpose for up to two months. Delivery is handled via the Cloudflare content delivery network, which normally serves from the nearest location; delivery from a location outside the European Union can therefore not be ruled out. The provider’s privacy statement is available at maptiler.com/privacy-policy.

Purpose
display of the map.
Legal basis
legitimate interest in a functioning map display (Art. 6(1)(f) GDPR).

3.13 Weather data

Weather forecasts for trails, huts and regions are retrieved server-side at regular intervals and cached. The retrieval is performed per location, not per user; no personal reference arises.

3.14 Partner content and advertising space

The app displays references to partner businesses and offers. This content is served from our own servers; third-party advertising networks, tracking pixels and identifiers used for advertising purposes are not employed. Content is not selected on the basis of personal interests.

3.15 App store rating

The app may prompt users to leave a rating in the App Store or on Google Play. The rating dialogue is provided by the operating system; we do not learn whether or what was rated. Any further processing is the responsibility of the respective store operator.

3.16 Saved trails and huts

Trails and huts can be marked as favourites. This stores the entry marked, the link to the account, and the time. This list is not visible to other users; a marking can be removed again in the app at any time.

Purpose
finding selected trails and huts again.
Legal basis
performance of the user agreement (Art. 6(1)(b) GDPR).

3.17 Maintenance of huts, regions and partner businesses

Mountain huts, regions and partner businesses can be maintained by the businesses responsible for them. To that end we invite the responsible person by email. The invitation stores the email address, the hut, region or partner business concerned, the team member issuing the invitation, and the time.

Where the invited person signs in with an account carrying that same email address, the invitation is redeemed automatically: an assignment between the account and the business is created, recorded with the time and the inviting team member, and the invitation is marked as accepted. That assignment alone determines which content may be edited; it does not create a separate type of account — it remains an ordinary user account that can use the app as before. The account is additionally marked as maintaining a business. That marker follows from the assignments, lapses with the last of them, and serves only to give an overview within our administration: it is not visible in the app, and it confers no further rights. The maintenance itself takes place not in the app but in a separate web administration area.

An invitation can be revoked, and an existing assignment removed again. Invitations that were not accepted, and revoked ones, are deleted automatically twelve months afterwards. Accepted invitations and the assignments themselves remain for as long as the arrangement lasts — they evidence who granted a permission and who exercises it.

Purpose
maintenance of content by the businesses responsible, traceability of the permissions granted.
Legal basis
performance of, or steps prior to entering into, the maintenance arrangement (Art. 6(1)(b) GDPR); legitimate interest in traceable permissions (Art. 6(1)(f) GDPR).

3.18 Sharing content

Posts, the signpost of the day, hikes, mountain huts, regions and giveaways can be passed on using the operating system’s share function — to a messenger, by email, or to a social network. What is passed on is an address of the form wanderer-app.cc/s/… Anyone opening it who has the app installed lands directly in the app; everyone else sees a page on our website that displays the shared item and offers the app. For the signpost of the day, the image is attached as a file as well, because there the image is the content.

Whoever shares makes the item accessible to every person who receives the link — including people without an account. For posts, one restriction applies and is enforced server-side: they are only displayed on that page if the profile of the person who wrote them is public. Posts from private profiles, as well as hidden or deleted posts, are not displayed; the link then leads to a notice without content. The pages carry a search engine exclusion and will therefore not appear in search results.

Sharing is not limited to the person who wrote a post: anyone who can see it in the app can share it. A link that has been passed on cannot be recalled; if the post is deleted or the profile is set to private, however, the page stops displaying the content within fifteen minutes at the latest. Copies that recipients have already made are beyond our influence — the same applies within the app (see 3.5).

When such a page is requested, we process the IP address, the time, the address requested and the browser’s details, in order to serve the page and to detect faults. These logs arise at Firebase Hosting and Cloud Functions (see section 4); the page itself is generated in a data centre in Belgium.

Purpose
passing content on outside the app, operation and security of the page required for it.
Legal basis
performance of the contract of use towards the person sharing (Art. 6(1)(b) GDPR); legitimate interest in fault-free and secure operation (Art. 6(1)(f) GDPR).

3.19 Newsletter

Anyone who consents when creating their account, or later in the settings, receives a few emails a year with pointers to new trails, huts, regions and giveaways. For this we process the account's email address and first name, together with the time and the place of consent — whether it was given when the account was created or in the settings. The first name serves only as a form of address.

Without consent no such email is sent. Consent is not preselected and is not required in order to use the app. It can be withdrawn at any time with effect for the future: with one tap on the unsubscribe link at the foot of every such email — no sign-in required — or in the app under Settings → Notifications. After withdrawal no further mailing is delivered, not even one that was already prepared at that point.

For every mailing we record which address it was delivered to and whether delivery succeeded. This is necessary in order to prevent duplicate delivery and to be able to follow up a complaint. No measurement of whether an email was opened or a link in it clicked takes place — the mailings contain no tracking pixels and no rewritten links.

The time and place of every consent and every withdrawal are logged separately. Without such evidence, consent is deemed not to have been given under Art. 7(1) GDPR; the log serves that purpose alone and is deleted together with the account.

Delivery runs via Resend (see section 4), the same service used for the emails about your account.

Purpose
Sending pointers to content and activities in the app; demonstrating consent; avoiding duplicate delivery.
Legal basis
Consent (Art. 6(1)(a) GDPR, § 107(2) Austrian Telecommunications Act 2021); for the record of consent, the legal obligation arising from Art. 7(1) GDPR (Art. 6(1)(c) GDPR).

4. Recipients and processors

The following services are used to operate the app. Supabase, Resend and the Firebase services process personal data on our instructions and solely for the purposes stated; data processing agreements pursuant to Art. 28 GDPR are in place with them. Where sign-in via Google or Apple is used, and where map tiles are retrieved, the respective provider determines the processing that occurs there as a controller in its own right; that provider’s privacy terms apply in this respect.

ServicePurposeProvider
SupabaseHosting, database, authentication, file storageSupabase Inc., United States, with a data centre in Ireland
ResendDelivery of system emails (confirmation, password), of reports to our mailbox, of notifications to giveaway winners and of the newsletterPlus Five Five, Inc., trading as Resend, United States
Firebase Cloud MessagingDelivery of push notificationsGoogle Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
Firebase Hosting and Cloud FunctionsServing the website and the pages for shared items (see 3.18)Google Ireland Limited, Dublin, Ireland
Google Analytics for FirebaseUsage analytics, subject to consent onlyGoogle Ireland Limited, Dublin, Ireland
Google Sign-InSign-in with a Google accountGoogle Ireland Limited, Dublin, Ireland
Sign in with AppleSign-in with an Apple accountApple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland
MapTilerMap tilesMapTiler AG, Zugerstrasse 22, 6314 Unterägeri, Switzerland

Partner businesses currently receive no personal data from the app: redeeming a reward happens solely via the points balance held in the account. Should a prize or a reward be settled through a partner business in future, disclosure will be limited to the details required for that purpose. Data is not passed on for advertising purposes.

Beyond this, data is disclosed where there is a legal obligation to do so, or where disclosure is necessary to establish, exercise or defend legal claims.

5. Transfers to third countries

Account data, recordings and community content are stored in a data centre in Ireland. Two of the services used are, however, established in the United States; access from the respective parent company in the course of operation and maintenance can therefore not be ruled out. The map service is established in Switzerland. With Google and Apple, our contracting parties are the Irish entities, but onward disclosure to the US parent company is likewise possible. The safeguards, per provider, are as follows:

  • Supabase Inc. (United States): the basis is not an adequacy decision but the European Commission’s Standard Contractual Clauses, which apply as an annex to the data processing agreement (together with an addendum for the United Kingdom). The provider’s transfer impact assessment is additionally on file. Storage in the Irish data centre, encryption in transit throughout, and encryption at rest serve as technical measures.
  • Plus Five Five, Inc. / Resend (United States): the provider has certified to the US Department of Commerce that it adheres to the principles of the EU-US Data Privacy Framework; the transfer is therefore based on the European Commission’s adequacy decision. The data processing agreement additionally stipulates the Standard Contractual Clauses, which take effect should the certification lapse. A separate transfer impact assessment is not envisaged for transfers based on an adequacy decision and is accordingly not on file. Only the recipient address and the content of the email in question are transmitted — for a newsletter additionally the first name, as a form of address. No location, recording or community data.
  • Google and Apple: for disclosure to their US parent companies, both groups rely on the adequacy decision on the EU-US Data Privacy Framework, supplemented by the Standard Contractual Clauses. The details are set out in their respective data protection terms.
  • MapTiler AG (Switzerland): the European Commission has found the level of data protection in Switzerland to be adequate; the transfer relies on that adequacy decision, and no further safeguards are required alongside it. Only the connection data of the tile request is transmitted — no account, location or community data. On the content delivery network used, see 3.12 as well.

The underlying agreements, certifications and evidence are documented on our side with the date of retrieval.

6. Retention periods

Data is deleted as soon as the purpose of its processing ceases to apply and no statutory retention obligation stands in the way.

  • Account, profile and activity data: until the account is deleted.
  • Community content and messages: until deleted by their author, and at the latest when the account is deleted. Images sent in messages are removed together with the account they came from — on the other side of the conversation as well.
  • Reports: up to three years after the review is concluded, in order to identify repeat violations and to evidence how a report was handled.
  • Blocks: until lifted by the blocking person, and at the latest when one of the accounts involved is deleted.
  • Push identifiers: until permission is withdrawn, until sign-out, or until Firebase reports the identifier as invalid.
  • Notifications in the app’s notification area: until the account is deleted.
  • Notification settings: until the account is deleted.
  • Saved trails and huts: until the marking is removed, and at the latest when the account is deleted.
  • Photos submitted for challenges: together with the review record, until the account is deleted. This also applies to rejected submissions, so that repeated attempts remain identifiable.
  • Points entries and badges: until the account is deleted.
  • Results of “Hiker of the week”: permanently, at most until the account is deleted. They are the record of an award that was made; a podium from which individual weeks disappear would no longer be evidence. With the account, the link is removed; the recorded place, along with name and number, remains as a record.
  • Reward redemptions: until the account is deleted. They are the receipt for a points entry; a point history from which individual redemptions vanish would no longer be traceable.
  • Delivery addresses for rewards: six months after delivery, after which name and address are removed from the order. On cancellation they are deleted immediately. What was ordered and what it cost remains.
  • Support requests: up to three years after the request has been dealt with, to observe limitation periods.
  • Maintenance invitations: invitations not accepted, and revoked ones, twelve months after revocation or after they were sent; accepted invitations and the assignment between account and business until the arrangement ends, and at the latest when the account is deleted.
  • Logs of the pages for shared items: 30 days, in line with the Google Cloud Logging default.
  • The record of newsletter consent and the delivery notes of a mailing: until the account is deleted. Keeping them longer would serve no purpose — without an account there is no consent whose granting would need to be demonstrated.
  • Analytics data: two months, in line with the retention period configured in Firebase.
  • Accounting records: seven years pursuant to Section 132 of the Austrian Federal Fiscal Code.

The periods for reports, support requests, invitations and delivery addresses are enforced by an automatic daily deletion run; for each run, the number of entries deleted is recorded so that compliance remains demonstrable. The remaining items are deleted together with the account or by the users themselves.

Independently of this, the app keeps the content it loaded most recently on the device, so that screens appear without a wait and remain readable on a poor connection. This covers trails, huts, regions and partner businesses as well as your own profile, your own tours, notifications and the posts in the feed, together with the associated images. These copies do not leave the device and are not transmitted to us. Account-related entries are deleted when you sign out; all others at the latest 30 days after they were last accessed, when the app is uninstalled, and whenever the operating system clears the cache itself to free up space.

Recordings that have not yet been uploaded are also held on the device, but for a different reason: an interrupted recording in progress, and finished hikes for which there was no connection at the time of saving. These are not copies of data already transmitted but the only version there is. They are therefore not deleted when you sign out; they remain assigned to the account under which they were created and are inaccessible to other accounts on the same device. They are deleted once the upload has succeeded, when discarded in the app, and at the latest 30 days after the recording — as well as when the account is deleted and when the app is uninstalled.

7. Deleting the account

The account can be deleted by the user under “Settings → Account” in the app. This removes the profile and profile picture, recordings, completed challenges including the points account, badges and submitted photos, posts and their images, comments, messages sent including any images shared in them, reactions, saved lists, follower connections, chat participations, prize-draw entries, blocked accounts, stored device identifiers, notifications, notification settings and any maintenance assignments — and finally the sign-in account itself. On the device, any interrupted recording and any hikes not yet uploaded are removed as well. The process cannot be reversed.

Some things remain. Reports made by this account are deleted with it; reports about this account are retained without any link to the deleted account, so that their handling remains traceable. Support requests and accepted maintenance invitations are retained without an account link for the same reason. In all three cases the periods set out in section 6 then apply. Data subject to a statutory retention obligation is likewise unaffected, as is other users’ content that refers to deleted content.

Alternatively, an informal message to privacy@wanderer-app.cc is sufficient.

8. Data subject rights

The following rights exist vis-à-vis the controller:

  • Access: to the data processed and a copy thereof (Art. 15 GDPR)
  • Rectification: of inaccurate data and completion of incomplete data (Art. 16 GDPR)
  • Erasure: (Art. 17 GDPR)
  • Restriction of processing: (Art. 18 GDPR)
  • Data portability: in a structured, commonly used and machine-readable format (Art. 20 GDPR)
  • Objection: to processing based on a legitimate interest (Art. 21 GDPR)
  • Withdrawal of consent: with effect for the future (Art. 7(3) GDPR)

A message to privacy@wanderer-app.cc is sufficient to exercise these rights. Proof of identity may be requested as a safeguard against unauthorised disclosure.

Automated decision-making, including profiling, within the meaning of Art. 22 GDPR does not take place.

9. Right to lodge a complaint

Without prejudice to any other remedy, there is a right to lodge a complaint with a supervisory authority. Under Art. 77 GDPR, a complaint may be lodged with the authority of the place of habitual residence, the place of work, or the place of the alleged infringement — where the app is used outside Austria, therefore also with the supervisory authority of the member state concerned. The European Data Protection Board maintains a list of the supervisory authorities in the European Economic Area at edpb.europa.eu.

The authority competent for us as controller is:

Supervisory authority
Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Vienna, Austria
dsb@dsb.gv.at
www.dsb.gv.at

10. Data security

Transmission between the app and our servers is encrypted throughout (TLS). Access to data is restricted at database level by authorisation rules that check, for every query, whether the requesting account is entitled to access. Access to individual fields is restricted in addition: details an app session does not need — the email address of other accounts, for instance — cannot be retrieved by it even where the rest of the record is visible. Passwords are stored as hashes only. Despite these measures, complete protection cannot be guaranteed for transmission over the internet.

11. Minimum age

The app is not directed at children. An account may only be created independently from the age of 16; below that age, the consent of a parent or guardian is required (Art. 8 GDPR). Where we become aware that an account has been created contrary to this rule, it will be deleted.

12. Changes to this policy

This policy is amended whenever the underlying processing changes — for instance through new features or a change of service provider. The version available in the app and at wanderer-app.cc at the given time applies. Substantial changes are notified in the app.

Last updated: September 2026

Die schönsten Wanderwege

© 2026 Die schönsten Wanderwege

Legal

  • Legal notice
  • Privacy policy
  • Terms and conditions & terms of use