Privacy policy
Last updated 10 October 2026. This policy explains what personal data the PolkuPiste app and website handle, why, and what rights you have under the EU General Data Protection Regulation (GDPR).
1. Who is responsible
The controller of your personal data is [Company name], business ID (Y-tunnus) [1234567-8], [street address, postcode, city, Finland]. Email: privacy@polkupiste.fi
2. What we collect
| Data | What it is | Why |
|---|---|---|
| Account | Email address, password (stored only as a secure hash by our sign-in provider), name, account type (walker or shop owner), referral code, the code you signed up with | To create and secure your account and to pay referral rewards |
| Profile (optional) | Username, profile photo, short bio, town, phone number | To show your profile; the phone number is used to pay referral rewards with MobilePay |
| Walks | Start time, duration, distance, estimated steps, coins earned, the offer you walked to, the point where the walk ended, and whether a fake (mock) location was detected | To calculate coins, check that you arrived at the shop, keep rewards fair and show your history |
| Coins and vouchers | Coin transactions, offers you unlocked, when vouchers were claimed and used | To run the reward system and let shops verify vouchers |
| Shops | Store name, category, address and map position, phone, description, photo, offers, subscription and payment status, MobilePay number for subscription payments | To show your shop and offers to walkers and to manage your subscription |
| Invites, jackpot and ads | Friends who joined with your code, jackpot spins, video ads watched | To pay invite rewards and limit spins and ads per day |
| Admin security | For admin accounts: two-step login (authenticator app) details | To protect admin tools |
| Technical | Network address and basic request data, kept briefly by our providers; a short log of password reset checks per network address | Security and preventing abuse |
Location
The app asks for location permission only to show where you are on the walking map and to measure your walk. Your position is used on your phone while you walk. Your full route is not sent to our servers: when you finish a walk, only the distance, the duration and the end point are saved, so the server can check that you reached the shop. When you plan a route or search for a place, the start and destination points or the search text are sent to the map services listed below.
Camera and photos
Shop owners use the camera to scan voucher QR codes; the images are processed on the phone and not stored. Photos you choose for your profile or store are uploaded and shown in the app.
3. Legal bases
- Contract (GDPR art. 6(1)(b)): your account, walks, coins, vouchers, shop and subscription.
- Legitimate interest (art. 6(1)(f)): security, preventing fraud such as fake GPS and code guessing, and improving the service.
- Legal obligation (art. 6(1)(c)): accounting records of payments.
- Consent (art. 6(1)(a)): location and camera permissions on your phone, and push notifications. You can withdraw consent at any time in your phone's settings.
4. Who processes data for us
| Provider | Purpose |
|---|---|
| Supabase | Database, sign-in and file storage [confirm the project region, e.g. EU (Stockholm or Frankfurt)] |
| Brevo | Sending emails such as password reset codes |
| Cloudflare | Hosting this website and, if enabled, the "I am human" check at sign-up and sign-in (Turnstile) |
| OpenStreetMap Foundation | Map images shown in the app |
| FOSSGIS e.V. (routing.openstreetmap.de) | Walking routes (start and destination points) |
| komoot (Photon) | Place and address search (search text and map points) |
| Vipps MobilePay | Payments of shop subscriptions and referral rewards |
| Apple and Google | App distribution and, if enabled, push notifications |
If we add new providers, for example for advertising or analytics, we update this policy first. Where data is transferred outside the EU/EEA, it is protected with the European Commission's standard contractual clauses or an adequacy decision.
Shops see only what they need to give you an offer: the offer you unlocked, your first name and the initial of your last name, and when the voucher was claimed and used. Shops never see your email or phone number.
5. How long we keep data
- Account data, walks, coins and vouchers: as long as you have an account.
- When you delete your account, its data is deleted right away. Accounting records of payments are kept as long as Finnish accounting law requires (generally 6 years).
- Password reset check logs: at most one day.
6. Your rights
You have the right to access your data, to have it corrected or deleted, to restrict or object to its processing and to receive it in a portable format. You can correct your profile and delete your account yourself in the app. For other requests, email privacy@polkupiste.fi; we answer within one month.
You can also complain to the Finnish Data Protection Ombudsman (tietosuoja.fi).
7. Children
PolkuPiste is meant for people aged 13 and over. If you are younger, please do not create an account.
8. Security
Data is sent encrypted (HTTPS). Coins, vouchers and rewards are checked on our server, each voucher QR code is signed, and your sign-in is stored in your phone's secure storage (Keychain or Keystore).
9. Changes
We update this policy when the app changes. The date at the top shows the latest version; for important changes we tell you in the app.