Ridgeflow — Privacy Policy

Last updated: August 4, 2026

Overview

Ridgeflow is a wilderness route-planning app for hiking and trail running, covering trails worldwide. We are committed to protecting your privacy. This policy explains what data the app accesses, how it is used, and your rights.

What is on your device, and what reaches us

Accounts are live. Signing in creates an account with us, and from that point the sections below describe exactly what we hold. Before you sign in, nothing you do in the app is sent to us at all — the map, the trail data and the topo sheet need no account and report nothing.

Most of what you make still lives only on your device. Downloaded offline maps never leave it — they are gigabytes of terrain held in your own browser or app storage, and we keep no copy. Clearing your browser data or uninstalling the app deletes them permanently and we cannot restore them. Saved routes, favourites, recorded trips and preferences are held on your device and, when you are signed in, synced to your account so they survive a lost phone.

This page was updated on 8 August 2026, the day sign-in was switched on. The previous version said this release had no accounts; that was true when it was written and is no longer.

Data We Collect

When sign-in is enabled you will create an account with a username and password only — we do not ask for or store an email address. The following account data would then be stored on our behalf by Supabase (our authentication and database provider):

Payment for a subscription is processed by Stripe (on the web) or the Apple App Store / Google Play (in-app purchase). We store only your subscription status and, for web payments, a Stripe customer reference — never your card details.

We do not sell or share account data with anyone. You can delete your account and all associated cloud data at any time from the app (Account → Delete account) or by emailing [email protected].

Location Data

The app requests access to your device's GPS location to:

Your live GPS location is processed entirely on your device. It is never sent to our servers and is not stored beyond the current session. The one deliberate exception is the home base address you choose to save: because you asked for it to sync across your devices, that single saved address is stored with your account (see "Data We Collect"). The app functions without location access — you can deny the permission and use the map manually.

Device Sensors

The app may access device motion sensors (accelerometer, gyroscope, compass) for the trip dashboard's heading and compass features. This sensor data is processed on-device only and is not stored or transmitted.

Data Stored on Your Device

The app stores the following locally on your device using browser storage (localStorage, IndexedDB, Cache API):

You can clear all locally stored data at any time by clearing your browser's site data for this app.

Third-Party Services

The app makes direct requests from your browser to these third-party services:

Track, hut and campsite data from the Department of Conservation (CC-BY 4.0) and OpenStreetMap (ODbL) is bundled with the app as a static dataset — the app makes no runtime calls to DOC for it.

These services may log your IP address and the coordinates/queries you request. We have no control over their data practices — please review their policies.

Cookies & Tracking

Ridgeflow does not use analytics, advertising, or any tracking technologies. We do not use Google Analytics, Facebook Pixel, or any similar services. If you sign in, Supabase stores an authentication token in your browser solely to keep you signed in.

Children's Privacy

The app is not directed at children under 13 and does not knowingly collect data from children.

Your Rights (GDPR / CCPA)

You may request access to, correction of, or deletion of your account data (username, saved routes, favourites, home base, preferences, usage and subscription status) at any time — from the app (Account → Delete account) or by emailing [email protected]. Deletion removes your account and all associated cloud data.

Changes to This Policy

We may update this policy from time to time. The "last updated" date at the top will reflect any changes.

Contact

For questions about this privacy policy, contact us at: [email protected]