Privacy Policy
1. Controller Art. 4(7) GDPR
This application is operated by Sofiane Ould Hammou (the "controller"), contactable at advice@onpremise.cloud. Because the app is a non-commercial personal-use navigation tool and stores no account or identity data server-side, no dedicated Data Protection Officer is required (Art. 37 GDPR does not apply to this processing). You can exercise any of the rights below by using the in-app β° β Delete my data function or by contacting the operator directly via email.
2. What we process Art. 13 GDPR
| Data | Why | Where | Retention |
|---|---|---|---|
| Device GPS position, speed, heading | Core navigation function (map, distance, ETA) | Your device only | Not stored |
| Live position + optional name (if you ride) | Multi-rider feature β showing nearby riders to other riders on the same destination | Server RAM only | Auto-deleted after 25 seconds (PEER_TTL_MS) |
| Rider ID, name, cruise speed | Session identity, UI preferences | Your browser localStorage | Until you clear site data or use Delete my data |
| Address typed in the "From" field | Geocoding your start point | Sent to OSM Nominatim, not stored | Not stored |
We process no cookies, no advertising identifiers, no analytics, no fingerprinting, and no email addresses. The app runs entirely in your browser with no account system.
3. Legal basis Art. 6 GDPR
- Art. 6(1)(b) β performance of a contract / pre-contractual steps: processing your location is strictly necessary to provide the navigation service you requested by pressing "Start navigation".
- Art. 6(1)(a) β consent: sharing your live position and name with other riders, and storing preferences in your browser, happen only after you explicitly accept the consent prompt.
- Art. 6(1)(f) β legitimate interest: transient in-memory routing of your request to OSM services (map tiles, routing, geocoding). This is minimal, ephemeral, and does not override your rights.
4. Third-party processors Art. 13(1)(e) GDPR
To function, the app makes client-side requests to free OpenStreetMap-based services. No personal data beyond the immediate query (coordinates / address) is transferred, and none is stored by us:
- CARTO basemaps (
basemaps.cartocdn.com) β map tiles. Server logs standard HTTP request data per their policy. - OSM routing (
routing.openstreetmap.de) β route geometry for your current originβdestination pair. - Nominatim (
nominatim.openstreetmap.org) β geocoding the address you type. Subject to their usage policy. - Overpass API (
overpass-api.de) β loading public charging-station points; sends only map coordinates. - This server (
/api/destinations) β the built-in list of Amazon fulfillment-center addresses worldwide (public location data). No personal data is involved.
These are privacy-respecting, non-tracking services operated by the OpenStreetMap community. We do not sell, rent, or share your data with any commercial third party.
5. Consent & sharing Art. 7 GDPR
- On first launch you are shown a clear consent prompt. The app only starts GPS tracking and rider-sharing after you accept.
- If you decline, the app runs in privacy mode: no location sharing with other riders, no persistent identity. Navigation using the on-map/address start point still works.
- Consent can be revoked at any time via β° β Delete my data. The browser's own location permission can also be revoked in the OS settings.
- Riders are only identifiable by a randomly generated ID and (optionally) the name you enter yourself. There is no sign-up and no way for other users to contact or profile you.
6. Storage & retention Art. 5(1)(e) GDPR
- Server side: live rider positions exist only in RAM, expire automatically after 25 seconds with no new report, and are purged on process restart. There is no database, no log of locations, and no backup of this data.
- Client side: preferences (name, cruise speed, rider ID, consent choice) live in your browser's
localStorageon your own device and never leave it except when you actively ride (the current name + position for 25s). - Deleting the app / clearing site data removes all client-side storage immediately.
7. Your rights Arts. 15β22 GDPR
- Access (Art. 15) β a copy of any personal data we hold about you.
- Rectification (Art. 16) β fix your rider name/identity.
- Erasure (Art. 17) β use β° β Delete my data; server-side live data self-deletes within 25s.
- Restriction (Art. 18) & Objection (Art. 21) β stop sharing or processing.
- Data portability (Art. 20) β your data is already fully under your control in your browser.
- Right to withdraw consent (Art. 7(3)) β at any time, with the same ease as giving it.
- Complaint (Art. 77) β you may lodge a complaint with your local supervisory authority (in Germany, e.g. the LDI NRW).
Because of the in-browser, ephemeral architecture, most rights are already exercised by design β there is no server-side account to lock or export.
8. Advertising Art. 6(1)(a), TTDSG Β§25
ScootNav is free to use and may be funded by non-intrusive display advertising. Ads are governed by the following principles:
- Consent-gated: no ad network script is loaded before you accept the consent prompt. If you choose privacy mode, no ads are shown and no ad network is contacted.
- Never during navigation: for your safety, advertising slots are only rendered on the pre-ride setup screen and the post-ride arrival summary. During active navigation all ad slots are removed from the layout.
- Offline-safe: if your device is offline, no ad request is made; a local sponsor card may be shown instead.
- Networks: if configured, Google AdSense may set cookies / use similar technologies to serve personalized ads. You may opt out of personalized advertising at adssettings.google.com. Referrer affiliate links for commuter gear are marked
rel="sponsored". - No rider data: ad delivery never receives your GPS position, rider name, or destination.
9. California Consumer Privacy Act (CCPA)
California residents have the right to opt out of the "sale" or "sharing" of personal data.
- ScootNav does not sell personal identity information.
- Anonymized ad telemetry served through third-party networks can be managed through the Network Advertising Initiative Opt-Out Portal.
10. Security Art. 32 GDPR
- Transport is fully encrypted (HTTPS / TLS 1.2+ via Let's Encrypt) and the app is a secure context, which is also required for GPS access.
- Server-side input is strictly validated (coordinates, speed, payload size capped at 4 KB) and the static-file server is path-traversal protected.
- The peer relay holds only minimal, ephemeral, pseudo-anonymous data with a hard memory cap.
- The service worker caches app assets locally for offline use; no personal data is written to the cache. Ad-network responses are never cached.
11. Changes to this policy Art. 13(3) GDPR
If processing changes materially, this page is updated with a new version date, and the app banner reflects it. Continued use after a change implies acceptance of the updated policy.
12. Contact
Questions, erasure requests, or audits: contact the operator Sofiane Ould Hammou at advice@onpremise.cloud. Please allow 30 days for a response, as required by GDPR.