1. Who we are (controller)
The data controller for personal data processed through the Service is Byeoo, sole proprietorship. Contact: post@byeoo.com.
2. What we process and why
| Category | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Location data (GPS) and chosen origin/destination | Calculate and display navigation routes; show weather at start/end | Consent & performance of a contract |
| Mobility profile and preferences (e.g. wheelchair, stroller, dog walk, My Profile sliders) | Personalize routing and scoring | Consent |
| Device/diagnostic data (anonymous app logs) | Detect bugs, improve reliability | Legitimate interest |
| Optional analytics & usage events | Understand feature usage | Consent (cookie banner) |
| Account data (if you create one) | Cloud sync of preferences and history | Performance of a contract |
3. Location data
Location is requested only when needed (e.g. to start a route from your current position or for turn-by-turn navigation). Location is processed on your device and transmitted to map, routing and weather providers only as required to compute the result. You can revoke location permission at any time in your device settings.
4. Third-party processors and data sharing
We share only the minimum data needed for each function, and we never sell your personal data. The recipients are:
| Recipient | What it receives | Location |
|---|---|---|
| Lovable Cloud / Supabase (hosting, database, authentication, email) | Account e-mail, profile, subscription status, feedback, contact messages, analytics events | EU / USA |
| Stripe (payments) | E-mail, payment and subscription data (card data goes directly to Stripe, never to us) | EU / USA |
| OpenRouteService / HeiGIT (routing) | Start and end coordinates, mobility profile | Germany (EU) |
| OSRM (fallback routing) | Start and end coordinates | EU |
| OpenStreetMap Nominatim (address search) and OSM tile servers (maps) | Search text, coordinates, IP address | EU |
| Open-Meteo (weather and elevation) | Coordinates | Germany (EU) |
These requests carry location data but no account identifier: the providers cannot link a coordinate to your Byeoo account. Where a recipient processes data outside the EEA we rely on adequacy decisions or the EU Standard Contractual Clauses.
4a. What we do not store
Byeoo does not store your GPS trace, your searched addresses or your calculated routes on our servers. They are computed for the request and kept only in your browser.
5. Cookies and local storage
See our Cookie & Tracking Policy. We use essential local storage to remember your consent and preferences. Analytics, personalization and marketing storage are only set if you opt in.
6. Retention
Profile and preference data are kept until you delete your account or clear local storage. Diagnostic logs are retained for up to 90 days. Consent records are retained as long as required to evidence compliance.
7. Your rights (GDPR Articles 15–22)
- Right of access, rectification, erasure, restriction, portability, objection.
- Right to withdraw consent at any time (without affecting prior lawful processing).
- Right to lodge a complaint with your supervisory authority.
To exercise these rights see Account Deletion & Data Removal or contact post@byeoo.com.
8. Children
The Service is not directed at children under 16. Do not use it if you are under that age.
9. Security
We apply reasonable technical and organizational measures (encryption in transit, minimal data collection, scoped access). No system is 100% secure; please use a strong device passcode.
10. Self-service controls
Signed-in users can download a machine-readable copy of all stored personal data, and can permanently delete their account and personal data, directly on the Account page. Deletion is immediate and irreversible.
11. Regional rights
- United Kingdom. UK GDPR applies; you may complain to the ICO.
- United States (California, Colorado, Virginia and similar). You may request access, deletion and correction, and opt out of targeted advertising or any sharing. Byeoo does not sell or share personal information for advertising, so no “Do Not Sell or Share” mechanism is required; requests go to post@byeoo.com. We do not discriminate against you for exercising these rights.
- Canada (PIPEDA, Québec Law 25). Personal data may be stored or processed outside Canada, including in the EU and the USA, and is therefore subject to the laws of those jurisdictions.
- Brazil (LGPD). You have the rights in Art. 18 LGPD; our privacy contact also acts as the data-protection point of contact.
- Australia (Privacy Act / APPs). We disclose personal information to overseas recipients as listed in section 4.
- Japan (APPI) and South Korea (PIPA). Cross-border transfer of personal data to the recipients listed in section 4 takes place with your consent, given when you accept this Policy.
- India (DPDP Act). You may withdraw consent at any time and request erasure through the Account page or our privacy contact.
- Mainland China. Byeoo is not offered in mainland China and is not designed to comply with PIPL data-localisation requirements.
12. Privacy contact
For any privacy request, including access, deletion, objection or a complaint, contact post@byeoo.com. We answer within 30 days. We have not appointed a statutory Data Protection Officer, as our processing does not meet the threshold of GDPR Art. 37.
13. Changes to this Policy
We may update this Policy. Material changes trigger a new acceptance flow inside the app.
