Legal
Privacy Policy
Last updated: 17 August 2026
1. Controller and contact
Corsin Curtins / SwissTrails, Gottfried-Kellerstrasse 22, 8192 Glattfelden, Zürich, Switzerland, is responsible for the personal data described here. Privacy and data-rights requests can be sent to hello@swiss-trails.com.
This policy applies to swiss-trails.com and app.swiss-trails.com.
2. Data we process and why
Account data includes your email address, optional name and avatar, authentication session, purchase status and account timestamps. We use it to authenticate you, deliver purchased access, provide support and secure the service.
Product data includes saved location identifiers. Trip plans, visited places, map preference and some reactions are stored locally in your browser and are not automatically transferred to Swiss Trails.
Technical requests may include IP address, device/browser information, requested pages, timestamps and security logs. These are used to deliver, protect and troubleshoot the service. Swiss Trails does not currently run advertising trackers or behavioural analytics in this codebase.
3. Service providers
Supabase provides account authentication and database hosting. Stripe processes checkout, payment and refunds; Swiss Trails does not receive your full card number. Vercel hosts and delivers the websites.
Mapbox supplies map tiles and driving-route requests. Open-Meteo supplies weather requests. Wikimedia Commons and, on the marketing hero, Unsplash deliver credited imagery. Requests to these services can disclose your IP address and the resource or coordinates requested to that provider.
Providers may process data outside Switzerland. Their contractual and legal safeguards apply alongside Swiss data-protection requirements and, where applicable, European data-protection law.
4. Cookies and device storage
Supabase uses essential session storage or cookies to keep you signed in securely. Swiss Trails uses browser storage for favourites, trips, visited-place history, reactions and preferences. These are functional features, not advertising cookies.
You can clear browser-stored data through your browser settings. Blocking essential session storage prevents signed-in features from working.
5. Retention and security
Account data is kept while the account is active. On a valid deletion request, personal account data is deleted or anonymised unless a limited record must be retained for payment, accounting, fraud prevention or another legal obligation.
We use HTTPS, server-only secret keys, account-level database rules and restricted administrator access. No online service can promise absolute security; confirmed incidents affecting personal data are handled under applicable law.
6. Your choices and rights
You can download a structured copy of server-held account data from Account & Privacy inside the app. You may also request access, correction, deletion, restriction or another right available under applicable law by emailing us from your account address.
If you believe a request was not handled appropriately, you may contact the competent data-protection authority, including the Swiss Federal Data Protection and Information Commissioner where applicable.
7. Changes
We update this policy when the product or its providers change. The date above identifies the current version; material changes will be communicated through the service where appropriate.