Scope
This policy explains how Transalpina Moto Map, its website, and its online services handle information. Most planning, navigation, downloaded-map, ride-journal, and visited-area features work without an account.
Who is responsible
Transalpina Moto Map is operated by its independent developer. The primary contact for privacy, safety, account-deletion, or data-access requests is info@transalpina.app.
Data that normally stays on your device
Downloaded maps and routing data, signed-out saved routes, planning and navigation preferences, signed-out visited-area coverage cells, signed-out ride-journal tracks, and privacy-limited app diagnostics are stored locally. Visited-area coverage stores map cells rather than raw GPS history. These items are not uploaded merely because you use navigation.
The local error log is bounded and excludes exception messages, routes, searches, account identifiers, request headers, and raw GPS. It leaves the device only if you deliberately copy and share it. Internal development builds may contain a separate sensitive diagnostics recorder, but that recorder is not included in the public App Store build.
Accounts and cloud features
If you create an account, the service processes your email address, password hash, confirmation/change/reset records, device sessions, chosen group-ride name, and account security records. Passwords are not stored in readable form. Signed-in route synchronization stores the routes you choose to save. If device data exists when you sign in, the app requires you to add the whole local library to the account, sign out and keep it unassigned, or delete it with two confirmations. Adding it synchronizes saved routes, completed ride tracks (including coordinates, timestamps, speed and elevation), and visited-area coverage cells. A public route share stores its route and a revocable random share token until you revoke the share or delete the route or account.
Group rides
A live group ride processes the shared route, membership status, public rider names, and accepted riders’ current positions. Joining and accepting a ride makes the rider’s name and current position visible to the other accepted participants while sharing is active.
Live positions are kept in server memory for the active session and are not stored as a location history. Location sharing stops when the rider leaves, blocks, is removed, or the session ends. The shared route is released from memory after a short idle period, and the session ends after the leader is absent for five minutes.
Anonymous riders receive a random public name. The app creates a random, app-scoped installation token in secure device storage. The server uses a one-way hash of it during the temporary session to reject an installation that a leader removed. It is not Apple’s advertising identifier or a hardware identifier, and reinstalling or modifying the app can replace it.
Reports, blocking, and safety
A report stores the report category, time, ride and temporary member references, the reported display name, and one-way participant hashes. It does not copy live location into the report. Reports are retained while reasonably needed to investigate abuse, enforce safety, and meet legal obligations, then deleted or anonymized. Blocking immediately separates the riders’ live location sharing in that session.
Navigation testing reports
During active guidance, you can explicitly report a navigation audio-output issue, mark a moment, report a road closure, or mark a road as unsuitable. A report stores your precise and snapped location, a sampled copy of the planned route, the affected route section, route progress, current and next maneuver context, and routing identifiers. Audio reports store the text and kind of navigation output from the preceding moments; they do not record microphone or speaker audio.
The app saves these reports locally first so road avoidance and later upload work without connectivity. Temporary closure avoidance expires after your selected duration. A road marked unsuitable remains avoided locally without an expiry. If you are signed in, pending reports are uploaded to your account’s selected Transalpina service for testing and investigation. Merely navigating does not upload your route or location; pressing a report action is the explicit submission.
Online services and service providers
Online place search sends the search text, app language, and optional exact map focus to the first-party Transalpina Places service. After you set or move a route point, the app also sends that point’s coordinate there to obtain a rough settlement name for the planner row. It may repeat that lookup if you change the app language while the row remains visible. The app may make one additional reverse request for each assigned point when you calculate with Do not cross borders. Rough country hints only explain a no-path result from the local routing graph and never reject a route the graph can calculate; missing hints are ignored. The app does not persist, cache, or reuse reverse-lookup results; when offline, it continues showing the coordinate. A result you select may be saved in the bounded recent-destination list on your device. Place requests carry no account token, cookie, or custom device identifier, and Transalpina does not log their search text or coordinates. Map and package downloads contact the configured hosting provider. Account email is delivered by the configured email provider. Infrastructure, hosting, and email providers process only the information needed to supply those services.
Like most internet services, these providers and the Transalpina API may process IP addresses, request times, device and app version information, and short-lived security logs to deliver requests, prevent abuse, and diagnose failures. Transalpina does not use third-party advertising or cross-app tracking SDKs in the public app.
The website
The public website is static and currently uses no account login, advertising tracker, behavioral analytics, or non-essential cookies. Its hosting provider may still process ordinary request information such as an IP address, browser user agent, requested page, and time for delivery, security, and short-lived operational logs.
Why data is processed
Data is used to provide features you request, secure accounts and sessions, prevent abuse, respond to reports, and meet legal duties. Where applicable, these purposes rely on performance of the service contract, legitimate safety and security interests, consent for optional device permissions, or legal obligations.
Retention
Account records, synchronized routes, completed ride tracks, and visited-area coverage remain while the account or content is active. Revoked sessions and short-lived confirmation or reset records expire or are removed when no longer needed. Live group locations are ephemeral as described above. Navigation testing reports, moderation reports, and security records are retained only as long as reasonably needed for testing, safety, abuse prevention, dispute handling, and legal obligations.
Your choices and deletion
Location permission can be denied or withdrawn in system settings. Visited-area collection and other optional features can be disabled in the app. Signed-in riders can change their email or password, export their server-held account data as portable JSON, and permanently delete their account in Account settings. Email changes require codes sent to both the current and new addresses. Password changes, data exports, and deletion require a code sent to the current account email.
Confirmed deletion immediately removes the live account, device sessions, synchronized routes and shares, completed ride tracks, visited-area coverage, signed-in navigation reports, associated group-report identifiers, and their AI-review suggestions. Encrypted backup snapshots are isolated from ordinary use and age out under the backup retention schedule. A completed logout removes the account's local route, ride, and coverage cache; signed-out unassigned data and downloads remain on the device. The export contains account and profile fields, authentication-method metadata, device sessions, synchronized routes, exact completed ride tracks, ride/route deletion sync records, current visited-area coverage, navigation reports, and relevant group-report and moderation records. It excludes passwords, authentication tokens, passkey credentials, private share-token hashes, internal staff notes, and unrelated riders' identifiers. You may also request access, correction, deletion, restriction, or export by contacting us.
Sharing, sale, and security
Transalpina does not sell personal data. Data is shared only with service providers needed to operate requested features, with riders you explicitly join or share with, or when legally required. Service providers may process data from infrastructure in another country, subject to the safeguards applicable to that service. We use encrypted transport, restricted credentials, hashed secrets, and access controls, but no system can promise absolute security.
Changes
Material changes will be dated here and, when appropriate, surfaced in the app. Questions are welcome at info@transalpina.app.