Privacy Policy
Last updated: May 2026
Your Rights at a Glance
Under GDPR:
- Access your data
- Request correction
- Request deletion
- Export your data
- Request restriction of processing
Exercise your rights in Settings or contact privacy@crospath.app
1. Introduction
CrosPath ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website (collectively, the "Service").
CrosPath is operated as a micro-entreprise registered in France. We process personal data in compliance with the General Data Protection Regulation (GDPR/RGPD) and the French "Informatique et Libertés" law.
Data Controller: CrosPath, contact: legal@crospath.app
2. Legal Basis for Processing
We process your personal data based on the following legal grounds:
| Data Type | Legal Basis | Purpose |
|---|---|---|
| Account data (email, name) | Contract | Service provision |
| Profile photos | Consent | Profile display |
| Location data | Consent | Nearby matching |
| Messages | Contract | Communication |
| Analytics | Legitimate Interest | Service improvement |
3. Information We Collect
Personal Data
We collect information that you voluntarily provide when registering and using the Service:
- Name, username, and email address
- Phone number (optional)
- Date of birth and gender
- Nationality and spoken languages
- Countries visited
- Relationship status
- Bio / free-text description
- Profile photos
- Travel preferences and interests
- Current location and travel plans
User-Generated Content
- Chat messages including text, images, files, and location messages
- Voice messages and audio recordings
- Video content (shots, stories)
- Feed posts and comments
- User reviews and ratings
- Connection/friend requests
Identity Verification Data
For identity verification purposes, we may collect:
- Selfie photos for facial verification
- Government-issued ID document images (passport, ID card)
Important — biometric data: for identity verification, these images are sent to Amazon Rekognition (AWS, EU-Ireland region) which extracts temporary facial features to compare the selfie against the ID document. AWS does NOT retain those images or facial vectors after processing (we do not use their persistent collections). The result (match true/false + confidence score) is then stored on your user record in Supabase. You may decline this verification — you'll keep a "basic" account without the trust badge. The GDPR legal basis is your explicit consent (art. 9 §2 a), revocable at any time by deleting your account.
Trusted / Emergency Contacts
You may choose to provide trusted contact information (name, email, phone number of non-users) for safety purposes. This information is stored solely to send emergency alerts on your behalf.
Location Data
With your explicit consent, we collect location data to connect you with nearby travelers and activities. You can disable location services at any time through your device settings or in-app privacy controls.
Automatically Collected Data
We use privacy-focused analytics (Plausible) that do not track individuals or use cookies. We collect aggregate, anonymized data about usage patterns to improve the service. Additionally, we may automatically collect:
- Push notification device tokens
- Profile view tracking (who viewed your profile)
- Screenshot detection data in ephemeral content
- Online presence and last active status
- EXIF metadata extracted from photos (GPS coordinates, timestamps)
4. How We Use Your Information
We use the information we collect to:
- Create and manage your account
- Match you with compatible travelers
- Show relevant activities in your area
- Enable messaging between users
- Send important updates about the Service (transactional emails only)
- Improve and personalize your experience
- Ensure the safety and security of our community
5. Data Sharing & International Transfers
We do not sell your personal information. We may share your information with:
- Other users (as part of your public profile)
- Service providers who assist our operations (listed below)
- Law enforcement when required by law
Service Providers
| Provider | Country | Service | Data Received |
|---|---|---|---|
| Supabase | Singapore | Database and authentication | All user data |
| Hostinger | Cyprus/EU | Web hosting | Service traffic |
| Cloudflare | USA | CDN and security | Service traffic, stored files |
| Resend | USA | Transactional emails | Email address, email content |
| Plausible | UE | Privacy-focused analytics | Anonymized browsing data |
| Mapbox | USA | Map rendering | GPS coordinates |
| Sentry | USA | Error tracking | User ID, email, device info |
| Expo Push Service | USA | Push notifications | Device tokens, notification content |
| RevenueCat | USA | In-app purchases / subscriptions | User identity, purchase data |
| Deezer | France | Music search for posts/stories | Search queries |
| Nominatim / OpenStreetMap | Germany | Reverse geocoding | GPS coordinates |
| Open-Meteo | Germany | Weather data | GPS coordinates |
| USA | OAuth authentication | Account ID, email, name | |
| Apple | USA | OAuth authentication | Account ID, email, name |
| Amazon Rekognition (AWS) | Ireland (eu-west-1) | Face comparison for identity verification (selfie ↔ ID document) | Selfie photo + ID document photo, processed in real-time and not retained by AWS |
| Stripe | USA / Ireland | Web payments (promo codes and partner subscriptions only — in-app purchases go through Apple/Google via RevenueCat) | Email, name, last 4 card digits, billing country |
For transfers outside the EU/EEA, we ensure adequate protection through Standard Contractual Clauses (SCCs) or adequacy decisions.
6. User-to-User Data Sharing
When you use CrosPath, certain information is visible to other users:
- Profile: Name, photos, tribe, nationality, interests, bio, verification level, current city
- Online status: Online presence and last active (configurable in privacy settings)
- Activity participation: Activities you join are visible to other participants
- Reviews: Reviews written about you are visible to other users
- Profile view tracking: Premium users can see who viewed their profile
- Location: Approximate location shown on map; exact location only shared with trusted contacts for safety
7. Your Rights (GDPR/RGPD)
Under GDPR/RGPD, you have the following rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restriction of Processing: Request restriction of processing your data in certain circumstances (GDPR Article 18)
- Right to Data Portability: Export your data in a machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
- Right to Lodge a Complaint: File a complaint with a supervisory authority
How to Exercise Your Rights:
- Export your data: Settings → Your Data → Export My Data
- Delete your account: Settings → Danger Zone → Delete Account
- Email: privacy@crospath.app
- French supervisory authority: CNIL
8. Data Retention
We retain your personal information for as long as your account is active. When you delete your account:
- Your data is anonymized immediately
- A 30-day recovery window is provided
- After 30 days, all personal data is permanently deleted
- Anonymized, aggregate data may be retained for analytics
Specific Retention Periods
| Data Type | Retention Period |
|---|---|
| Chat messages | Retained until account deletion |
| Stories | Auto-expire after 24 hours, deleted from storage within 48 hours |
| Shots (ephemeral photos/videos) | Deleted after viewed or after expiry period |
| Verification documents (selfie, ID) | Retained for the duration of the account for re-verification purposes |
| Location data | Current location updated on each app use; historical location not retained beyond session |
| Profile view history | Retained for 90 days |
| Push tokens | Retained until device token becomes invalid or account deleted |
| Trusted contacts | Retained until removed by user or account deleted |
9. Ephemeral Content
CrosPath offers several types of ephemeral content designed to automatically disappear:
- Shots: Ephemeral photos and videos that disappear after viewing or expiry. If the recipient takes a screenshot, the sender is notified.
- Stories: Content visible for 24 hours then automatically deleted from our servers.
- View-once messages: Messages auto-destroyed after the first view by the recipient.
10. Device Permissions
The CrosPath mobile app may request the following permissions on your device. Each permission is optional and can be managed through your device settings:
| Permission | Purpose |
|---|---|
| Camera | Profile photos, verification selfies, shots, stories, chat photos |
| Microphone | Voice messages in chat, video recording with audio |
| Photo library | Selecting photos for profile, posts, stories, shots |
| Location (foreground only) | Nearby activities, nearby travelers, map features |
| Biometrics (optional) | Secure app access |
| Notifications | Activity updates, messages, safety alerts |
11. Safety Features
CrosPath includes safety features designed to protect travelers. Using these features involves the processing of certain data:
- Emergency alerts: In case of emergency, notifications are sent to your trusted contacts, including your current location and alert details.
- Safety check-ins: During activities, you can perform safety check-ins to confirm you are okay. If a check-in is missed, your trusted contacts may be notified.
- Travel plan sharing: You can share your travel itineraries with trusted contacts so they know where you are.
- Real-time location sharing: You can initiate temporary real-time location sharing with specific contacts. This sharing is time-limited and stops automatically.
12. Automated Decision-Making & Profiling
In accordance with GDPR Article 22, we inform you that CrosPath uses automated processes to enhance your experience:
- Path crossings: Algorithmic matching based on travel routes, shared interests, and tribes. This system identifies travelers whose paths cross with yours.
- Activity suggestions: Recommendations based on your location, preferences, and interests.
These processes do not have significant legal effects on you. You can opt out of path crossing profiling via the app's privacy settings.
13. Premium / Subscription Data
Payment data for subscriptions and in-app purchases is processed by RevenueCat and the associated payment platforms (Apple App Store, Google Play Store). CrosPath does not store your payment card details. We only receive confirmation of your subscription status, plan type, and renewal dates to activate premium features.
14. Security
We implement appropriate technical and organizational measures to protect your data:
- All data encrypted in transit (TLS 1.3) and at rest
- Row Level Security (RLS) for database access control
- Regular security audits and updates
- Access logging and monitoring
15. Age Restriction
CrosPath is intended for users aged 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe we have collected data from a minor, please contact us immediately.
16. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we may also send you an email notification.
17. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights:
💡 Before contacting us:
You can export or delete your data directly from the app: Settings → Your Data. Email requests are processed within 30 days in accordance with GDPR.