RS

Privacy

Privacy Policy

This policy explains the personal data RouteStudio uses to provide accounts, save projects, secure access, produce exports, and operate future subscriptions.

Effective July 27, 2026

1. Data we collect

Account data includes your email address, optional display name, authentication events, legal acceptance timestamps, MFA enrollment status, and internal user identifier. Passwords and authenticator secrets are handled by Supabase Auth and are not stored in RouteStudio’s public application tables.

Project data includes waypoints, routes, styling, map settings, highlights, Studio clips, tracks, camera keyframes, thumbnails, recovery revisions, video and PNG export usage, and support tickets or feedback you submit. Technical records may include IP address, device/browser information, request logs, security events, and error diagnostics.

2. Why we use it

Data is used to authenticate users, provide and autosave projects, enforce plan limits, render requested exports, prevent abuse, diagnose failures, maintain security, comply with legal obligations, and support users. Data is not sold.

3. Service providers

Supabase provides authentication and database infrastructure; Mapbox provides maps, geocoding, directions, and related geographic services; Cloudflare Turnstile may process security signals to distinguish people from abusive automation. Polar acts as merchant of record for subscription checkout, payments, tax handling, receipts, and its customer portal. Each provider processes data under its own terms and privacy commitments.

4. Retention and deletion

Active account and project data is retained while needed to provide the service. Deleted projects may remain in recovery snapshots or backups for a limited period. You can download an account archive or permanently delete your account from Profile & security. Security, transaction, backup, and legal records may remain for a limited period where reasonably necessary or legally required.

5. Security

The service uses scoped database access, Row Level Security, cookie-based sessions, password hashing managed by Supabase, optional TOTP MFA, CAPTCHA, signed webhooks, and server-only credentials. No system is perfectly secure, so users should use a unique password and enable MFA.

6. International processing

Infrastructure providers may process data in countries other than your own. Appropriate contractual and technical safeguards will be used where required by applicable data-protection law.

7. Your choices and rights

You can update profile and security settings, revoke sessions, download your account data, and permanently delete your account from Profile & security. Depending on your location, you may also have rights to access, correct, restrict, object to processing, or complain to a supervisory authority.

8. Children and changes

The service is not directed to children under the minimum digital-consent age applicable in their country. Material policy changes will be posted with a new effective date and additional notice when legally required. Privacy questions or rights requests should use the official support contact published with the deployed application.