⚑ ← Back to ScootNav
πŸ‡¬πŸ‡§ English πŸ‡©πŸ‡ͺ Deutsch πŸ“‹ Impressum

Privacy Policy

ScootNav β€” GPS navigation PWA
Last updated: 7 August 2026 Β· Version 1.2 Β· Applies to boostfit.online

1. Controller Art. 4(7) GDPR

This application is operated by Sofiane (the "controller"), contactable at advice@onpremise.cloud. Because the app is a non-commercial personal-use navigation tool and stores no account or identity data server-side, no dedicated Data Protection Officer is required (Art. 37 GDPR does not apply to this processing). You can exercise any of the rights below by using the in-app ☰ β†’ Delete my data function or by contacting the operator directly via email.

2. What we process Art. 13 GDPR

DataWhyWhereRetention
Device GPS position, speed, headingCore navigation function (map, distance, ETA)Your device onlyNot stored
Live position + optional name (if you ride)Multi-rider feature β€” showing nearby riders to other riders on the same destinationServer RAM onlyAuto-deleted after 25 seconds (PEER_TTL_MS)
Rider ID, name, cruise speedSession identity, UI preferencesYour browser localStorageUntil you clear site data or use Delete my data
Address typed in the "From" fieldGeocoding your start pointSent to OSM Nominatim, not storedNot stored
Email address + consent (optional)Only if you subscribe to the newsletterServer data/subscribers.jsonUntil you unsubscribe / request deletion
Anonymous usage & affiliate stats (pseudonymous ID, event type, affiliate product/query)Aggregate reporting β€” how many riders, which destinations and which affiliate items are clicked. No GPS coordinates or identityServer data/analytics.jsonl (aggregated)Aggregate counters; raw rows capped (ring buffer) and usable for status, breakdown reports

The navigation core sets no cookies, no advertising identifiers, no fingerprinting, and never reads your contacts, photos or messages. Because the app is used over HTTPS, we also cannot re-read your location once you leave. We run a privacy-by-design setup: the only directly identifying personal data we ever store is your email β€” and only if you voluntarily subscribe to the newsletter. Like almost any website, this server keeps short technical access logs (IP, time, requested file) to protect against abuse; these are not linked to your identity in the app and are not used to profile you.

3. Legal basis Art. 6 GDPR

4. Third-party processors Art. 13(1)(e) GDPR

To function, the app makes client-side requests to free OpenStreetMap-based services. No personal data beyond the immediate query (coordinates / address) is transferred, and none is stored by us:

These are privacy-respecting, non-tracking services. For affiliate transactions (Amazon Associates), we act purely as an advertising intermediary and never see, store, or receive your payment or account data.

We do not sell data. ScootNav does not sell, rent, or trade personal data to anyone, and does not sell personal data for money or any other consideration to any third party. Any revenue would come only from consent-based advertising and affiliate commissions paid by click-through/qualifying purchase on Amazon.de β€” neither of which involves selling your data.

5. Consent & sharing Art. 7 GDPR

6. Storage & retention Art. 5(1)(e) GDPR

6b. Newsletter Art. 6(1)(a) GDPR

If you subscribe, we store your email address and the date/time of your explicit consent to send occasional update and tip emails. Subscribing is entirely optional. You can unsubscribe at any time β€” every message includes an unsubscribe link, or email advice@onpremise.cloud. On request we delete your email immediately (see rights below).

7. Your rights Arts. 15–22 GDPR

Because of the in-browser, ephemeral architecture, most rights are already exercised by design β€” there is no server-side account to lock or export.

8. Advertising & affiliate program Art. 6(1)(a), TTDSG Β§25

ScootNav is free to use. It displays consent-based advertising and participates in the Amazon Associates affiliate program, which may earn a commission if you make a qualifying purchase. It is explicitly not a sale of your data:

8b. Your rights shield Arts. 15–22, 77 GDPR

German and EU law give you a protective shield over your personal data. You can invoke all of these rights at any time, free of charge:

We will honour any request within 30 days (Art. 12 GDPR). Because the app is designed with data minimization β€œby default and by design” (Art. 25 GDPR), most of your rights are already satisfied: there is no account system, and no data beyond what is described in Β§2 exists to be exported or locked.

9. California Consumer Privacy Act (CCPA)

California residents have the right to opt out of the "sale" or "sharing" of personal data.

10. Security Art. 32 GDPR

11. Changes to this policy Art. 13(3) GDPR

If processing changes materially, this page is updated with a new version date, and the app banner reflects it. Continued use after a change implies acceptance of the updated policy.

12. Contact

Questions, erasure requests, or audits: contact the operator Sofiane at advice@onpremise.cloud. Please allow 30 days for a response, as required by GDPR.