Privacy Policy
DRAFT — legal review pending1. Who we are
Camino GO ("the App", "we", "us") is operated by:
- Operator: DANSHAN CO., LTD. (丹山有限公司), incorporated in Taiwan, Unified Business No. 62050237
- Registered address: 11F., No. 14, Aly. 4, Ln. 284, Zhongzheng Rd., Xindian Dist., New Taipei City 231009, Taiwan (R.O.C.)
- Contact (privacy): [email protected]
- Contact (general support): [email protected]
EU Representative (Art. 27 GDPR): Data Protection Representative Limited (trading as DataRep), 77 Camden Street Lower, Dublin, D02 XE80, Ireland. You can contact DataRep about our processing of your personal data by email at [email protected] (please quote “CaminoGO” in the subject line), through the form at www.datarep.com/data-request, or by post to the DataRep location most convenient for you. Letters must be addressed to “DataRep”, not to CaminoGO, or they may not reach them.
UK Representative (Art. 27 UK GDPR): Data Protection Representative Limited (trading as DataRep), 107-111 Fleet Street, London, EC4A 2AB, United Kingdom, reachable in the same ways.
DataRep postal addresses in the EU/EEA and the UK
- Austria: DataRep, City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria
- Belgium: DataRep, Rue des Colonies 11, Brussels, 1000
- Bulgaria: DataRep, 25 Vitosha blvd. Fl. 2, office 4, 1000, Sofia, Bulgaria
- Croatia: DataRep, Ground & 9th Floor, Hoto Tower, Savska cesta 32, Zagreb, 10000, Croatia
- Cyprus: DataRep, Victory House, 205 Archbishop Makarios Avenue, Limassol, 3030, Cyprus
- Czech Republic: DataRep, Platan Office, 28. Října 205/45, Floor 3&4, Ostrava, 70200, Czech Republic
- Denmark: DataRep, Lautruphøj 1-3, Ballerup, 2750, Denmark
- Estonia: DataRep, 2nd Floor, Tornimae 5, Tallinn, 10145, Estonia
- Finland: DataRep, Luna House, 5.krs, Mannerheimintie 12 B, Helsinki, 00100, Finland
- France: DataRep, 72 rue de Lessard, Rouen, 76100, France
- Germany: DataRep, 3rd and 4th floor, Altmarkt 10 B/D, Dresden, 01067, Germany
- Greece: DataRep, Ippodamias Sq. 8, 4th floor, Piraeus, Attica, Greece
- Hungary: DataRep, 1054 Honved street, 8 1/2, Budapest, Hungary
- Iceland: DataRep, Laugavegur 13, 101 Reykjavik, Iceland
- Ireland: DataRep, 77 Camden Street Lower, Dublin, D02 XE80, Ireland
- Italy: DataRep, Viale Giorgio Ribotta 11, Piano 1, Rome, Lazio, 00144, Italy
- Latvia: DataRep, 4th & 5th floors, 14 Terbatas Street, Riga, LV-1011, Latvia
- Liechtenstein: DataRep, City Tower, Brückenkopfgasse 1/6. Stock, Graz, 8020, Austria
- Lithuania: DataRep, 44A Gedimino Avenue, 01110 Vilnius, Lithuania
- Luxembourg: DataRep, BPM 335368, Banzelt 4 A, 6921, Roodt-sur-Syre, Luxembourg
- Malta: DataRep, Tower Business Centre, 2nd floor, Tower Street, Swatar, BKR4013, Malta
- Netherlands: DataRep, De Nieuwe Erven 3 Unit – 15162, 5431 NV Cuijk, Netherlands
- Norway: DataRep, C.J. Hambros Plass 2c, Oslo, 0164, Norway
- Poland: DataRep, Budynek Fronton ul Kamienna 21, Krakow, 31-403, Poland
- Portugal: DataRep, Torre de Monsanto, Rua Afonso Praça 30, 7th floor, Algès, Lisbon, 1495-061, Portugal
- Romania: DataRep, 15 Piaţa Charles de Gaulle, nr. 1-T, Bucureşti, Sectorul 1, 011857, Romania
- Slovakia: DataRep, Apollo Business Centre II, Block E / 9th floor, 4D Prievozska, Bratislava, 821 09, Slovakia
- Slovenia: DataRep, Trg. Republike 3, Floor 3, Ljubljana, 1000, Slovenia
- Spain: DataRep, Calle de Manzanares 4, Madrid, 28005, Spain
- Sweden: DataRep, S:t Johannesgatan 2, 4th floor, Malmo, SE - 211 46, Sweden
- United Kingdom: DataRep, 107-111 Fleet Street, London, EC4A 2AB, United Kingdom
For questions about the App or your account, please contact us directly at [email protected].
We act as the data controller for the personal data described in this policy.
2. Scope
This policy covers the Camino GO mobile application, related backend services, and the caminogo.app website. It does not cover third-party websites or services we link to (e.g., an accommodation's own booking page).
Users in the United Kingdom. The UK GDPR and the Data Protection Act 2018 apply to personal data of users in the UK. For those users, references in this policy to the GDPR, the EU/EEA, supervisory authorities, adequacy decisions and transfer safeguards also mean their UK equivalents, such as UK adequacy regulations, the UK Extension to the EU–US Data Privacy Framework and the UK International Data Transfer Addendum to the Standard Contractual Clauses.
3. What data we collect
3.1 Account data
- Email address, display name, profile photo (optional)
- Authentication identifiers from your sign-in provider (Apple, Google, or email) via Firebase Authentication
- Account settings (language, preferences)
3.2 Location and activity data
- Precise location (GPS) — when you enable location features: live map position, route tracking, daily route briefing, weather for your position, and location context for AI questions. Active walk tracking may continue in the background when you grant the necessary permission. You can stop tracking or revoke permission in your device settings.
- Walking records — daily distance, step counts, elevation gain, and recorded track points for trips you track. Step counts are read from your device's motion sensors (Core Motion on iOS, the step counter sensor on Android), with your operating-system permission. We do not access HealthKit or Google Fit.
- Track history is stored so you can review your journey; see §7 for retention and §8 for deletion.
3.3 AI questions, photos, search and voice
- Text, photos and relevant conversation context you submit to Camino AI, including translation and photo questions. Route assistance can include your location, nearby places and trip context when that feature uses them.
- General food preferences: optional choices such as vegetarian or avoiding pork are saved on your device and sent with a menu-analysis request when selected. They are not a medical or allergy profile. Menu explanations and recommendations cannot determine allergy safety.
- When you explicitly request AI-assisted map search, the search text is sent for interpretation. Ordinary name matching and category filtering do not require an AI request. A place name or other personal information you type may be included in the text.
- Cloud speech recognition: recordings you submit are sent through our server to OpenAI for transcription. Audio is handled for the transcription request and is not stored as a permanent recording by our application server. The resulting text can be sent to an AI provider when you submit your question.
- Read aloud: when you tap read aloud on a Camino AI answer or translation, that text and its language are sent through our server to Google Cloud Text-to-Speech to generate audio. Our server keeps the generated audio in memory for up to about 30 minutes to avoid repeat requests, and your device keeps a limited cache of recent audio.
- Face-to-face translation: speech recognition is handled by your phone's operating-system speech service; Camino sends the recognized text for translation. System speech processing is subject to Apple or Google's settings and terms and is not necessarily entirely on-device.
- AI session data on our server, copies in your device's history and copies processed by AI providers have different retention rules; see §5 and §7.
3.4 User-generated content (UGC)
- Chat messages, announcements/forum posts, diary entries, photos you upload, accommodation/POI reports and community data edits.
- Diary entries are private in the current App — they are stored on our servers to sync across your devices and are not shown to other users through the current diary feature.
- Family groups: you can create or join a family group by invitation or join request. Members see each other's display name, profile photo and status, and can chat in the group. Family groups do not share members' locations.
- Trip sharing and companions: you can create a link that shares a snapshot of your trip plan; anyone with the link can view and copy the plan. You can also invite companions to a shared trip plan; its members see the plan and each other's display names.
3.5 Purchases
Purchase entitlements (Trip Pass validity, AI-use balances and cloud speech allowances), platform transaction identifiers and purchase history. We use RevenueCat to validate and restore purchases and manage entitlements; its SDK associates purchase information with your Camino account identifier and receives relevant app/device information. Payment is processed entirely by Apple App Store / Google Play; we never receive your card details.
3.6 Technical data
- Device model, OS version, app version, language
- Push notification token (if you enable notifications)
- Server logs (IP address, request metadata, error logs) for security and reliability
- Optional diagnostic reports: local diagnostic logs are uploaded when you choose to send a report. Reports may include device/app details, error information and precise route or location details relevant to the problem. These reports are not an automatic upload of all your local logs.
- Automatic crash and error reports: when the App or our servers encounter an error, a technical report is sent to Sentry (EU data region, Germany). It contains the error type and message, stack trace, app and operating-system versions, device model and release information. We configure Sentry not to receive your account identifier, request contents, screenshots, activity breadcrumbs or session replays, and not to store IP addresses. An error message can occasionally contain a fragment of the data being processed when the error occurred.
3.7 Website visitors (caminogo.app)
- Launch notification list — if you submit your email address on our website, we store the address, signup time and verification status, solely to send you one launch announcement. You can withdraw at any time by emailing [email protected].
- Privacy-first analytics (no cookies) — the website uses Cloudflare Web Analytics, a cookieless tool that sets no cookies and does no cross-site tracking or fingerprinting. It records aggregate, non-identifying statistics (page views, referrers, country, device/browser type) via a lightweight beacon; no individual profile is created and we cannot identify you from it.
- Search performance — we use Google Search Console, a Google webmaster tool that reports how our pages appear in Google Search results. It does not run code, set cookies, or track visitors on our website; the data comes from Google's own search infrastructure.
- Standard CDN server logs (Cloudflare) for security and abuse prevention. Our signup endpoint also temporarily stores a hash derived from the IP address to limit repeated submissions, with a two-hour expiry. Where an anti-bot challenge is enabled, Cloudflare processes the challenge response and request information for verification.
4. Why we process it (purposes and legal bases)
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Provide the App (account, maps, planner, tracking) | 3.1, 3.2, 3.6 | Art. 6(1)(b) contract |
| AI features you invoke (photo questions, translation, speech recognition, read aloud, search interpretation and briefings) | 3.2, 3.3 | Art. 6(1)(b) contract |
| Weather for your route | Approximate location | Art. 6(1)(b) contract |
| Community and sharing features (chat, forum, community edits, family groups, trip sharing and companions) | 3.2, 3.4 | Art. 6(1)(b) contract |
| Public-content/profile moderation and AI safety screening | 3.1, 3.3, 3.4 | Art. 6(1)(f) legitimate interest (keeping the community safe) |
| Purchases and entitlements | 3.5 | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation (accounting) |
| Security, abuse prevention, rate limiting | 3.6 | Art. 6(1)(f) legitimate interest |
| Detect and fix crashes and errors (automatic error reports) | 3.6 | Art. 6(1)(f) legitimate interest in keeping the App stable and secure |
| Investigate a diagnostic report you choose to send | 3.2, 3.6 | Art. 6(1)(f) legitimate interest in resolving reported faults |
| Service announcements | 3.1 | Art. 6(1)(b) contract |
| Launch notification list (website) | 3.7 | Art. 6(1)(a) consent |
| Aggregate, cookieless website analytics | 3.7 | Art. 6(1)(f) legitimate interest (understanding site usage without tracking individuals) |
| Website hosting, security & CDN server logs | 3.7 | Art. 6(1)(f) legitimate interest |
| Marketing communications (if any) | 3.1 | Art. 6(1)(a) consent — opt-in only |
We do not sell personal data or use it for third-party advertising. An operating-system permission controls access to a device feature; it is not blanket consent to every form of processing. This release does not offer personalized allergy or intolerance analysis and does not ask you to enter those details in a dedicated field. Menu assistance uses general food preferences and cannot assess whether food is safe for a medical condition. Please do not submit unnecessary health or other sensitive information in free-text questions, photos or voice recordings. If you include such information yourself, it may be present in the content sent to AI providers and in their responses, subject to the AI history, temporary-context and provider rules below. You can disable AI in Settings and clear local AI history. Contact [email protected] for data-rights requests.
5. AI processing — what you should know
- Google Gemini and OpenAI: the configured provider processes the text, images and relevant context needed for the AI feature you request. The current setup uses Gemini for general assistance and OpenAI for AI-assisted search interpretation and cloud transcription; OpenAI can also serve assistant features when configured.
- Safety screening: public content and profile information, including display names and avatars, may be screened using OpenAI's moderation API. AI requests are also subject to the AI provider's own safety checks and our assistant safety instructions. Content may be blocked or restricted. Contact [email protected] to contest a decision and request human review.
- Model training: we do not use your submissions to train our own AI models. OpenAI's API does not use API content to train its models by default. Google's paid Gemini API terms do not use prompts or responses to improve its general models. Safety processing is separate: Google may use logged content for models specifically used to enforce its policies. See OpenAI API data controls and Gemini API terms.
- Provider retention: our short-lived server session does not determine how long a provider retains data. OpenAI generally retains abuse-monitoring logs for up to 30 days, subject to applicable exceptions; its published endpoint table lists no abuse-monitoring or application-state retention for the moderation and audio-transcription endpoints. Gemini's published abuse-monitoring policy describes 55-day retention of prompts, context and outputs and possible authorized human review. These are provider policies, not a claim that our account has Zero Data Retention.
- Global processing: the current AI connections use global services. We do not promise that AI input, output or service metadata remains within the EU/EEA. See §6.
- You can use ordinary map browsing and name/category search without submitting an AI question. Microphone permission can be revoked independently. AI output may be inaccurate; see the Terms of Service.
6. Service providers and international transfers
The following providers receive data for the services described. Provider contracts and service configurations determine the precise processing locations; a European application server does not make all downstream processing European.
| Provider | Purpose / data | Processing locations and documentation |
|---|---|---|
| Hetzner Online GmbH | Application hosting and database | Nuremberg, Germany (application, database and routing servers). Database backups are stored in Cloudflare R2 buckets set to EU jurisdiction. Hetzner acts under a GDPR Article 28 data processing agreement that limits processing to the EU/EEA. |
| Cloudflare | Secure connection routing for all App and website traffic to our servers (IP addresses and request contents pass through Cloudflare's network), protection against attacks, sign-in for our remote administration, images, map delivery, encrypted database backups, website, launch-list storage and website analytics | Global network; requests are usually handled at a Cloudflare data centre near the user. R2 buckets holding database backups are set to EU jurisdiction; this applies to those buckets only and does not make the network, Workers, Pages, KV or analytics EU-only. Cloudflare acts under its Data Processing Addendum, which includes the Standard Contractual Clauses, and is certified under the EU–US Data Privacy Framework. Cloudflare DPA · R2 location documentation. |
| Google — Firebase | Authentication identifiers, account sign-in and push notifications | International processing, including the US, depending on service. The Firebase Data Processing and Security Terms apply; Google relies on the EU–US Data Privacy Framework and Standard Contractual Clauses. Firebase privacy information. |
| Google — Gemini API | AI prompts, photos, responses and relevant context | Global API; no EU-only processing commitment in the current setup. As a paid-tier customer, prompts and responses are processed under Google's Data Processing Addendum for Products Where Google is a Data Processor. Service and data terms. |
| Google — Cloud Text-to-Speech | Text of answers or translations you ask to hear read aloud, and its language | Google Cloud global service, covered by the Cloud Data Processing Addendum, which we have accepted with the Standard Contractual Clauses that apply to customers subject to the GDPR. |
| OpenAI OpCo, LLC | AI search interpretation, transcription, configured assistant features and moderation | Global API; processing may take place in the US and other countries. OpenAI's Data Processing Addendum applies; under it, data subject to EU/EEA or Swiss law is processed by OpenAI Ireland Ltd., with Standard Contractual Clauses for onward transfers. Our organisation settings do not share API inputs or outputs with OpenAI for model training. Subprocessors. |
| RevenueCat, Inc. | Account identifier, purchase transactions, entitlements and related SDK metadata | US (Amazon Web Services, Snowflake) and applicable subprocessors. RevenueCat's Data Processing Addendum applies, with EU Standard Contractual Clauses. |
| WeatherAPI.com | Forecasts for the centre of an approximately 5 km grid cell around the map centre or your location. The request is sent from our server without any account or device identifier. | We do not consider these requests to contain personal data. See the provider privacy policy. |
| Infomaniak Network SA | Email hosting for [email protected] and our team's mailboxes: messages you send us, their attachments and our replies | Switzerland (Infomaniak's own data centres). The European Commission recognises Switzerland as providing adequate protection. Infomaniak acts under a data processing agreement based on Article 28 GDPR and the Swiss Federal Act on Data Protection. Infomaniak GDPR information. |
| Functional Software, Inc. (Sentry) | Automatic crash and error reports (see §3.6) | EU data storage region selected for our organisation; storage of IP addresses is disabled. Sentry is certified under the EU–US Data Privacy Framework. Sentry's Data Processing Addendum and subprocessors. |
| Apple / Google | Store payments and system speech services | International processing under the relevant platform terms; they act independently for their own services. |
Data may be processed outside the EEA, including in the United States and by the operator in Taiwan. Where GDPR transfer rules apply, transfers require an applicable adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses, with any required transfer assessment and supplementary measures. The EU–US Data Privacy Framework applies only where the receiving entity and transfer are actually covered by a valid certification.
We have reviewed or concluded the data-processing terms of the providers listed above, including Hetzner, Firebase, the Gemini API, Google Cloud, OpenAI, RevenueCat, Sentry and Infomaniak.
Access from Taiwan. Our application servers and database are hosted in Germany. Our team in Taiwan administers the service remotely, for example for maintenance, support and troubleshooting, and may view personal data where a task requires it. Taiwan is not covered by an EU adequacy decision. We are directly subject to the GDPR for this processing (Article 3(2)) and apply its obligations to this access. Our safeguards include:
- Our servers accept no inbound connections from the internet; the App and website reach our service only through encrypted (TLS) connections via Cloudflare.
- Remote administration goes through Cloudflare Access and SSH keys. SSH password and root logins are disabled.
- Our servers communicate with each other over a private network, and database connections use certificate-verified TLS.
- Our hosting, Cloudflare and code-hosting accounts use two-factor authentication.
- Access is limited to what the task requires.
You can contact [email protected] for more information about these safeguards and how to obtain a copy of the relevant terms, subject to legitimate redactions.
7. Retention
These rules distinguish our application storage from provider processing. We may retain specific records where required by law or necessary for a documented dispute; retention is limited to the relevant purpose.
| Data | Retention / deletion |
|---|---|
| Account, synced walking records, tracks and private diaries | Until you delete the relevant data or your account, subject to the limited exceptions below. |
| AI photos and context in our server session | Default session lifetime of approximately 30 minutes. This does not delete device history or provider-held copies. |
| Cloud audio on our application server | Processed for the transcription request; no permanent recording is kept by the application server. |
| Read-aloud audio | Kept in our server's memory for up to about 30 minutes to avoid repeat synthesis. Your device keeps a limited cache of recent audio (up to 200 items), which is replaced as new audio is added or cleared when app data is removed. |
| Camino AI history on your device | According to your history setting: the latest 10, 30 or 100 entries, or retained until you clear it. It can include text and compressed photos. Signing out preserves this account-separated history; account deletion or removal of app data clears it. |
| Unsynced walking recovery data on your device | May be retained for up to 30 days after sign-out so the same account can recover it. It is cleared before another account uses it, on account deletion, or when the app next checks expired recovery data. |
| Uploaded diagnostic reports | Eligible for automatic cleanup after 30 days; cleanup runs periodically. Account deletion also removes associated reports. |
| Automatic crash and error reports (Sentry) | Retained by Sentry for 30 days under our current plan (never more than 90 days), then deleted. |
| Public content and messages | Until deleted, with the account-deletion treatment described in §8. Moderation and abuse records are separate from public display. |
| Reports about content or users | Kept while the accounts involved exist, so we can handle appeals and repeated abuse. Deleted automatically 90 days after the reporting or reported account is deleted. |
| Server logs | Our servers record technical details of each request, such as IP address, time, requested address and result, for security, abuse prevention and troubleshooting. These logs are deleted automatically within 35 days. |
| Records of administrative actions | Kept so moderation and administrative decisions can be accounted for. The IP address and browser details recorded with our staff's sign-ins and actions are removed after 90 days. |
| Database backups | Encrypted daily backups are stored in the EU (Cloudflare R2, EU jurisdiction). Each backup is locked against deletion for 30 days and deleted automatically after 45 days, so data you delete, including a deleted account, can remain in backups for up to 45 days. Backups are used only to restore the service after a failure. |
| Purchase and point-transaction records | Kept while your account exists. After account deletion they are linked only to an internal ID and kept for accounting, tax, refunds and fraud prevention for the periods required by Taiwan's Business Entity Accounting Act: supporting records at least 5 years and accounting books at least 10 years after the annual accounts are closed. Apple, Google and RevenueCat keep their own purchase records under their own terms. |
| Website launch notification list | Kept until we send the launch announcement, then deleted within 90 days. You can ask us to remove your address earlier at any time. |
| Support and privacy-request emails | Kept for up to 2 years after the matter is closed, so we can handle follow-up questions and show how a request was handled, then deleted. |
| Previously recorded allergy-analysis consent receipts, if any | This release does not create new receipts for the retired feature. Existing receipts contain only account ID, disclosure version, language and server timestamp, not allergy text. They remain subject to daily cleanup after 365 days, or immediate removal as part of account deletion. |
| Moderation notification queue | Drafts, the final delivered text and delivery references support manual notification. Completed or unreachable notices are removed by the daily cleanup after 180 days; pending notices remain until handled. Queue entries for a deleted account are erased during account deletion. Separate underlying report or email records follow their applicable retention rules. |
| AI provider records | Separate provider retention rules apply; see §5. Clearing Camino history does not itself delete a provider's security records. |
8. Your rights
Under the GDPR and the UK GDPR (and, where applicable, Taiwan's PDPA and other local laws) you have the right to: access, rectify, erase, port, restrict, and object to processing of your personal data, and to withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of processing before withdrawal. These rights apply subject to their statutory conditions.
- Account deletion is available directly in the App (Settings → Delete account) and by emailing [email protected]. Deletion permanently removes your profile, avatar, diaries, trips, GPS tracks, direct messages, and friendships through the account-deletion process. External authentication and image-storage cleanup may finish asynchronously and is retried if it fails. Limited accounting, security and legal records may remain as described in §7.
- Account deletion removes the content of your forum topics and discussion comments, including topic titles, bodies, attached images, location details, and poll options. Only deleted-content placeholders remain so replies written by other people stay readable. Other public contributions, such as town bulletins, events and point-of-interest or accommodation information and photographs, may remain attributed to a deleted user; you can request removal at [email protected].
- Your map messages are deleted. Numeric point-of-interest and accommodation star ratings remain and continue to contribute to rating counts and averages. Your review text and associated moderation notes are erased, and the written review is no longer displayed.
- Camino Guide daily usage counters and request/retry records are deleted. Point-transaction and purchase records are retained separately for the accounting and refund purposes described in §7.
- A deleted-account record and its internal identifier remain linked to retained records and discussion relationships. These links are not fully severed; account deletion does not mean that all retained records become anonymous.
- We respond to rights requests within the applicable legal deadlines, normally one month under GDPR; if a permitted extension is necessary, we explain it within that period. You may lodge a complaint with your local supervisory authority; in the UK, this is the Information Commissioner's Office (ico.org.uk). You can also contact our EU and UK representative, DataRep (see §1).
9. Security
Data in transit is encrypted (TLS). Access to production systems is restricted and logged. AI photo sessions are short-lived by design. No system is perfectly secure; we will notify affected users and authorities of personal data breaches as required by Art. 33/34 GDPR.
10. Children
Camino GO is not directed at children. You must be at least 16 years old (or the digital consent age in your country, if higher) to create an account.
11. Offline data
Route data, maps and settings may be cached on your device for offline use. AI history and unsynced walking recovery records follow the distinct rules in §7; signing out does not erase every local record. Local diagnostic and account-specific location caches are cleared on sign-out or account deletion. Device backups and their restore behavior are controlled by your operating system and backup settings.
12. Changes
We will notify you of material changes in-app before they take effect. Where a change requires consent, we will request it separately. Continuing to use the App is not a substitute for any consent required by law.
13. Contact
Privacy requests: [email protected]
General support: [email protected]
EU and UK representative: DataRep, [email protected] — see §1