English
Last updated: 14 September 2026
Definitions
For this Policy: Account means the optional account used to access account-based features; App means the Mountainmapper mobile application; operator, “we” and “us” mean Mountainmapper, operated from France; personal data means information relating to an identified or identifiable person; Service means the App and its related backend services; service provider means a person or organisation that processes data for us; usage data means technical data generated through use of the Service; and you means the person using the Service.
1. Data we process
- Account data: email address, password hash, account creation date, and any name you choose to provide. We never store your account password in plain text.
- Apple or Google sign-in data: provider user identifier, email address, email verification status, and name if the provider supplies it. Google ID tokens are used to verify sign-in and are not stored as your profile credential. When available, an Apple refresh token is encrypted and kept only so Apple authorization can be revoked when your account is deleted.
- Authentication and security data: hashed refresh tokens, session identifiers, expiry and revocation times, and basic rate-limit information. Access tokens expire after 15 minutes; active refresh tokens expire after 30 days of inactivity.
- Location and route data: precise coordinates, accuracy, heading and speed may be processed to plan routes, show navigation progress, detect deviation and announce guidance. Online planning creates a temporary route record containing route geometry and steps, normally expiring after approximately two hours. Position checks are processed for navigation but are not intended to create a permanent location history.
- Saved routes: if you sign in and choose to save a route, we store its name, ski area or pass scope, route request and associated account identifier until you remove it or delete your account.
- Purchases and subscriptions: the App Store or Google Play processes payment. We validate signed purchase records directly with Apple or Google and store the product, store, purchase environment, transaction identifier, renewal and expiry information needed to provide and restore Premium access. We do not receive or store your full payment-card details.
- Search data: ski-run and lift searches normally use an index stored on your device. On iOS, when you use Google Places, your query and a search area around the selected ski area are sent directly to Google. After selection, the App receives the place ID, name and coordinates; coordinates used for route planning are sent to our backend.
- Local app data: downloaded offline maps and routing data, map and language preferences, voice selections, cached routes, and an active navigation session may be stored on your device. Authentication tokens are stored in the operating system's secure storage.
- Technical data: our server and hosting provider may process IP address, user agent, request time, endpoint, status code and diagnostic logs for operation, security and troubleshooting.
2. How we use data
Navigation safety reports: when you explicitly submit a report, we store your account reference, report category and description, route/feature identifiers, data, graph, algorithm and notice versions, submission time and review decisions. We do not request a complete GPS track. Reports are accessible to authorized reviewers; public restrictions contain only affected feature identifiers and a public-safe reason. An offline report remains a local draft until you submit it again while connected. The device also stores one current navigation-notice acknowledgement (version, time, language and data versions), not a navigation history.
We use this data to create and secure optional accounts; authenticate and link login methods; provide maps, search, mixed walking/ski route planning, offline downloads and visual or spoken navigation; restore active sessions; prevent abuse; diagnose failures; and comply with legal obligations. We do not sell personal data and do not use it for targeted advertising.
3. Location and background navigation
Location permission is optional until you request location-based features. During an active navigation session, iOS may continue providing location while the phone is locked so spoken navigation can continue. Background route projection and speech are designed to run locally on the device. When the App is active and online, it may send position checks to our backend. You can stop navigation, disable location permission in system settings, or use offline planning where available.
Safety: Mountainmapper is a planning aid, not an emergency or avalanche-safety service. Always follow resort signs, closures, patrol instructions, weather and terrain conditions.
4. Legal bases
Where the GDPR or similar law applies, we process account and requested service data to perform our contract with you; precise location with your device permission and for the feature you request; security and limited technical logs for our legitimate interests in keeping the service safe and reliable; and data where necessary to meet legal obligations. You may withdraw device permission at any time, without affecting earlier lawful processing.
5. Service providers and disclosures
We disclose only the data needed to providers that support the service, including hosting and infrastructure providers, Apple for sign-in, system services and App Store purchases, and Google for sign-in, Google Places and Google Play purchases. We validate purchases directly with Apple and Google and do not send purchase data to a third-party subscription-management provider. Those providers process data under their own terms and privacy policies. Map and routing content may incorporate licensed or open data such as OpenStreetMap and IGN data; normal use is served through Mountainmapper where configured. We may disclose data if required by law, to protect users and the service, or as part of a business transfer subject to appropriate safeguards.
See Google's Privacy Policy and Apple's Privacy Policy.
Legal disclosures and business transfers
We may disclose personal data in response to a valid request from a court, public authority or law-enforcement body, or where we believe in good faith that disclosure is necessary to comply with a legal obligation, protect the rights or property of Mountainmapper, investigate possible wrongdoing connected with the Service, protect the safety of users or the public, or protect against legal liability.
If Mountainmapper is involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be transferred as part of that transaction. We will provide notice before transferred personal data becomes subject to a materially different privacy policy where required.
6. Retention
Account, linked identity and Premium entitlement records are kept while your account exists and as needed for purchase restoration, disputes, tax, fraud prevention and legal compliance. Authentication session records are kept with the account for security and are deleted when the account is deleted; active refresh tokens expire after 30 days without use. Temporary server route sessions normally expire after approximately two hours. Operational logs are kept only as long as reasonably needed for security, reliability and legal compliance. Local maps, routes and preferences remain on your device until you remove them, clear app data or uninstall the App; logging out or deleting an online account does not automatically remove these local files.
7. Account deletion, choices and rights
Safety reports and review records are retained for investigation, correction verification and justified incident follow-up. Account deletion removes account links from these records, but does not automatically erase report text or review decisions. Do not include personal information in report text; contact us to request review or removal of unnecessary personal data. Local report drafts and acknowledgement records remain until removed, replaced, or app data is cleared. Ending navigation clears the active navigation session and stops navigation speech and location; using “My location” again enables foreground map location.
You may use core map and planning features as a guest. You can change location permission, background location, language, voice and offline data through the App or system settings. Account settings allow you to restore purchases, manage an auto-renewing subscription, sign out and request account deletion after re-authentication. Deleting the Mountainmapper account does not itself cancel an App Store or Google Play subscription; cancellation is managed in the applicable store. Account deletion removes the account, linked identities and server authentication sessions and revokes the stored Apple authorization where applicable.
Depending on your location, you may request access, correction, deletion, restriction, objection or portability, and may complain to your local data-protection authority. Email ottozhangdev@gmail.com. We may need to verify your identity before fulfilling a request.
8. International transfers and security
Providers may process data in countries other than yours. Where required, we rely on appropriate transfer safeguards. We use measures such as password hashing, encrypted provider tokens, short-lived access tokens, access controls and secure device storage. No method of internet transmission or electronic storage is completely secure, so we cannot guarantee absolute security.
9. Children’s privacy and safety
The Service is not directed to children under 13, and we do not knowingly collect their personal data without verified parental or guardian consent. Where local law sets a higher age for valid consent, the applicable higher age applies. A parent or guardian who believes a child has provided personal data may contact us to request review and deletion.
Mountainmapper does not provide a public social feed, private messaging or user-to-user media sharing. We have zero tolerance for child sexual abuse and exploitation (“CSAE”) and child sexual abuse material (“CSAM”). Such content or conduct is prohibited in all information submitted through the Service, including navigation safety report text.
If we become aware of apparent CSAM or CSAE, we may remove the material or associated access, preserve information where lawful, report it to the National Center for Missing & Exploited Children or other competent authorities where required, and cooperate with lawful investigations. Child-safety concerns may be reported to our designated contact, Otto Zhang, at ottozhangdev@gmail.com.
10. Links to other websites
The Service or this website may link to sites operated by others. Their privacy practices are governed by their own policies. We do not control and are not responsible for third-party sites or services; review their policies before providing personal data.
11. Changes to this Policy
We may update this Policy as the App changes. We will update the “Last updated” date and, for material changes, provide notice in the App or by another appropriate method before the change takes effect where required.
12. Contact us
The operator and data controller is Mountainmapper. The privacy and child-safety contact is Otto Zhang, France. Email ottozhangdev@gmail.com or visit www.ottozhang.com. We may need to verify your identity before acting on a data-rights request.