Privacy Policy

This Privacy Policy explains how Hikify (“we”, “us”) processes personal data when you use the Hikify website at hikify.eu, the Hikify application at app.hikify.eu, and the Hikify iOS / Apple Watch apps (together, the “Service”).

Controller

The data controller for Hikify is the operator of hikify.eu. For privacy requests, contact privacy@hikify.eu. General support: support@hikify.eu or our Support page.

What we collect

  • Account data: email address, display name, community username, hashed password (email sign-up), and Apple Sign In identifiers when you use Sign in with Apple.
  • Library content: hike names, notes, collections/folders, GPX files you upload or edit, version history metadata (distance, timestamps, etc.), parking notes, and photos you attach to hikes.
  • Community content: public hike listings, descriptions, community photos, likes, and your public profile (username, display name, avatar) when you publish.
  • Location (iOS / Watch): precise location while you use map, “nearest” sorting, live tracking, or navigation features — processed on-device and only uploaded if you include it in a hike (for example GPX track points) or choose related features.
  • Health (Apple Watch): heart rate and related workout metrics from HealthKit during an active hike session on Watch, used to show live metrics in the companion experience. We do not sell health data.
  • Moderation: content reports and block lists you submit so we can keep Community safe.
  • Technical data: IP address and basic request metadata (for security, rate limiting, and abuse prevention), processed by our hosting provider Cloudflare.

We do not sell your personal data. We do not use advertising trackers in the Service.

Why we process data (legal bases)

  • Contract: to create your account, store your GPX library, sync across devices, and provide the features you request (GDPR Art. 6(1)(b)).
  • Legitimate interests: to keep the Service secure, prevent abuse, moderate Community content, and maintain reliable infrastructure (GDPR Art. 6(1)(f)).
  • Consent: where required for optional device permissions (location, HealthKit, photo library) that you can revoke in system settings (GDPR Art. 6(1)(a)).
  • Legal obligation: where we must retain or disclose data to comply with applicable law (GDPR Art. 6(1)(c)).

Where data is stored

The Service is hosted on Cloudflare (Workers, D1, R2). Data may be processed in the EU and other regions where Cloudflare operates. Cloudflare acts as a processor under appropriate safeguards.

Retention

We keep your account and library data for as long as your account exists. Community reports may be retained for a limited period to investigate abuse. If you delete your account, we permanently remove your account profile, hikes, photos, GPX objects, and related tokens from our systems (subject to short-lived backups or logs that expire automatically).

Your rights

Under the GDPR (and similar laws), you may have the right to:

  • access your personal data;
  • rectify inaccurate data;
  • erase your data (including via in-app / on-site account deletion);
  • restrict or object to certain processing;
  • data portability of data you provided;
  • lodge a complaint with your local supervisory authority.

To exercise these rights, email privacy@hikify.eu or use Delete account in Settings (web or iOS).

Children

Hikify is not directed at children under 16. If you believe a child has created an account, contact us and we will delete it.

Changes

We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the Service after an update constitutes acceptance of the revised policy where permitted by law.

See also our Terms of Service and Support. The application lives at app.hikify.eu.