Datenschutzerklärung
Gilt für die App alps.ride und die Website alps-ride.app · Stand: 1. September 2026
Kurzfassung: alps.ride braucht kein Konto und keine Registrierung. Wir setzen keine Werbe- oder Tracking-Dienste ein, verwenden keine Cookies, erstellen keine Nutzerprofile und verkaufen keine Daten. Dein Standort verlässt das Gerät nur als Koordinatenpaar, um Haltestellen und Verbindungen abzufragen, und wird bei uns nicht dauerhaft gespeichert. Alles Weitere – Fehlerberichte, geteilte Verbindungen – passiert nur, wenn du es aktiv auslöst.
1. Verantwortlicher
Simon Schnabl
Grantenplatzl 1, 6413 Wildermieming, Österreich
Matthias Komar
Schlossweg 2, 39035 Welsberg (BZ), Italien
E-Mail: info@alps-ride.app
Beide Betreiber entscheiden gemeinsam über Zwecke und Mittel der Verarbeitung und sind daher gemeinsam Verantwortliche. Der wesentliche Inhalt unserer Vereinbarung (Art. 26 Abs. 2 DSGVO): Wir erfüllen die Informationspflichten gemeinsam über diese Erklärung, und du kannst alle deine Rechte gegenüber jedem von uns geltend machen — am einfachsten über die gemeinsame E-Mail-Adresse unten, die wir beide lesen. Eine Anfrage an einen von uns gilt als Anfrage an beide.
Ein Datenschutzbeauftragter ist gesetzlich nicht erforderlich und wurde nicht bestellt. Für alle Anliegen zum Datenschutz erreichst du uns unter der oben genannten E-Mail-Adresse.
2. Wo die Daten verarbeitet werden
Die App spricht ausschließlich mit unserem eigenen Server unter api.alps-ride.app. Dieser läuft auf einer virtuellen Maschine von Oracle Cloud Infrastructure in der Region Frankfurt am Main, Deutschland (EU). Dort laufen auch die Adresssuche (Photon/Nominatim), die Verbindungsauskunft (OpenTripPlanner) und die Kartenkacheln – all das wird von uns selbst betrieben. Die App bindet keine Karten-, Schrift- oder Analysedienste Dritter ein: es gibt keine Google-Maps-, Mapbox-, Firebase- oder Google-Fonts-Aufrufe.
Die Website alps-ride.app wird bei IONOS SE, Montabaur, Deutschland gehostet. Auch sie lädt keine externen Schriften, keine Analyse-Skripte und setzt keine Cookies.
3. Welche Daten wir verarbeiten
3.1 Standortdaten
Was: Geografische Koordinaten (Breiten- und Längengrad) deines Geräts.
Wann: Nur, wenn du die Standortberechtigung erteilt hast, und nur während du die App aktiv verwendest. alps.ride fordert bewusst keinen Hintergrundstandort an und verfolgt deine Bewegungen nicht.
Wozu: Um Haltestellen in deiner Nähe anzuzeigen, dich auf der Karte zu verorten und eine Verbindung ab deinem aktuellen Standort zu planen.
Wohin: Die Koordinaten werden an unseren Server geschickt, um die passenden Haltestellen bzw. Verbindungen zu berechnen. Sie werden dort nicht gespeichert und keinem Nutzer zugeordnet – die Abfrage wird beantwortet und die Koordinaten verworfen. Auf deinem Gerät wird die zuletzt ermittelte Position lokal zwischengespeichert, damit die App und die Homescreen-Widgets nach einem Neustart sofort etwas anzeigen können.
Rechtsgrundlage: Einwilligung, Art. 6 Abs. 1 lit. a DSGVO (erteilt über den Berechtigungsdialog des Betriebssystems). Du kannst sie jederzeit in den Systemeinstellungen widerrufen; die App bleibt danach nutzbar, du musst Haltestellen dann selbst auswählen.
3.2 Such- und Fahrplanabfragen
Wenn du nach einer Haltestelle oder Adresse suchst oder eine Verbindung planst, werden der Suchbegriff bzw. Start- und Zielkoordinaten an unseren Server übermittelt und dort beantwortet. Diese Abfragen werden nicht zu einem Verlauf verknüpft und keinem Nutzer zugeordnet.
Rechtsgrundlage: Art. 6 Abs. 1 lit. b DSGVO – Erbringung der von dir angeforderten Funktion.
3.3 Server-Protokolle
Unser Webserver protokolliert jeden Aufruf. Die IP-Adresse wird dabei bereits vor dem Schreiben gekürzt (bei IPv4 wird das letzte Oktett auf 0 gesetzt, bei IPv6 entsprechend gekürzt), sodass keine vollständige IP-Adresse gespeichert wird. Protokolliert werden Zeitpunkt, angefragter Pfad, HTTP-Statuscode, übertragene Bytes, App-Version bzw. User-Agent und Antwortzeit.
Wozu: Betriebssicherheit, Fehlersuche und Abwehr von Missbrauch.
Speicherdauer: 7 Tage, danach automatische Löschung.
Zur Begrenzung der Anfragezahl (Rate-Limiting) verarbeitet der Server die vollständige IP-Adresse kurzzeitig nur im Arbeitsspeicher. Sie wird nicht auf die Festplatte geschrieben und ist nach einem Neustart des Dienstes verschwunden.
Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO – berechtigtes Interesse am sicheren und stabilen Betrieb.
3.4 Fehlerberichte und Feature-Wünsche
Wenn du in der App einen Fehler meldest oder eine Idee einschickst, übermitteln wir die von dir eingegebenen Inhalte – Titel, Beschreibung, Kategorie, Schritte zur Reproduktion und optional bis zu fünf Screenshots – an unseren Server. Von dort wird daraus automatisch ein Eintrag (Issue) in unserem Projekt-Repository bei GitHub erstellt; Screenshots werden in ein separates, nicht-öffentliches Repository hochgeladen und im Eintrag verlinkt.
Wichtig: Wir bitten dich, in Text und Screenshots keine personenbezogenen Daten anzugeben – weder deine noch die anderer Personen. Beachte, dass ein Screenshot deinen Standort, deine Heimathaltestelle oder Inhalte anderer Apps sichtbar machen kann. Es werden keine Geräte-, Konto- oder Standortdaten automatisch mitgesendet.
Empfänger und Drittlandtransfer: GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. Die Übermittlung in die USA erfolgt auf Grundlage der Standardvertragsklauseln der EU-Kommission bzw. der Zertifizierung nach dem EU-US Data Privacy Framework. Es besteht dabei das Restrisiko eines Zugriffs durch US-Behörden.
Speicherdauer: Bis der gemeldete Punkt erledigt ist; Einträge werden anschließend geschlossen und können auf Wunsch gelöscht werden.
Rechtsgrundlage: Einwilligung, Art. 6 Abs. 1 lit. a DSGVO – die Meldung ist freiwillig und wird erst durch dein Absenden ausgelöst.
3.5 Geteilte Verbindungen (Share-Links)
Wenn du eine geplante Verbindung teilst, speichern wir die Verbindung selbst sowie Start- und Zielkoordinaten samt Ortsbezeichnungen unter einer zufällig erzeugten, nicht erratbaren Adresse auf unserem Server, damit die Empfängerin oder der Empfänger sie im Browser ansehen kann.
Bitte beachte: Wer den Link hat, sieht diese Angaben – bei einer Adresssuche kann das eine genaue Adresse sein, etwa deine Wohnadresse. Teile den Link deshalb nur mit Personen, denen du diese Information anvertrauen möchtest. Die App weist dich vor dem ersten Teilen darauf hin.
Speicherdauer: Automatische Löschung 7 Tage nach dem Ende der geteilten Fahrt. Auf Zuruf löschen wir einen Link jederzeit früher.
Rechtsgrundlage: Einwilligung, Art. 6 Abs. 1 lit. a DSGVO.
3.6 Daten auf deinem Gerät
Folgendes bleibt lokal auf deinem Gerät und wird nicht an uns übertragen: Heimathaltestelle, Sprach- und Designeinstellungen, Anzeigeoptionen, zwischengespeicherte Haltestellennamen und die zuletzt ermittelte Position. Diese Daten werden mit der Deinstallation der App gelöscht.
3.7 Kontaktaufnahme
Wenn du uns per E-Mail schreibst, verarbeiten wir deine Nachricht und deine Adressdaten, um sie zu beantworten (Art. 6 Abs. 1 lit. b bzw. lit. f DSGVO). Wir bewahren solche Nachrichten nur so lange auf, wie es für die Bearbeitung nötig ist.
4. Was wir nicht tun
- Keine Benutzerkonten, keine Registrierung, keine Passwörter.
- Keine Cookies und kein vergleichbares Tracking – weder in der App noch auf der Website.
- Keine Werbung, keine Werbe-IDs, keine Weitergabe an Werbenetzwerke.
- Keine Analyse- oder Statistikdienste (kein Google Analytics, kein Firebase, kein Matomo).
- Keine Absturzberichte an Dritte. Die App enthält eine Schnittstelle für Fehlerberichterstattung, diese ist jedoch nicht aktiviert. Sollte sich das ändern, aktualisieren wir zuvor diese Erklärung.
- Kein Profiling und keine automatisierte Entscheidungsfindung im Sinne des Art. 22 DSGVO.
- Kein Verkauf und keine Vermietung von Daten.
5. Empfänger im Überblick
| Empfänger | Zweck | Ort |
|---|---|---|
| Oracle Cloud Infrastructure | Betrieb unseres Servers (Auftragsverarbeiter) | Frankfurt, Deutschland (EU) |
| IONOS SE | Betrieb der Website | Deutschland (EU) |
| GitHub, Inc. | Nur bei freiwilligen Fehlerberichten | USA (Drittland) |
| Google LLC / Apple Inc. | Verteilung der App über die App-Stores | USA (Drittland) |
Die Verkehrsunternehmen und Datenplattformen, aus denen die Fahrplandaten stammen (IVB, VVT, ÖBB, STA/NOI Open Data Hub), erhalten keine Daten über dich: Diese Daten werden von unserem Server abgeholt, nicht von deinem Gerät.
Der Bezug der App erfolgt über Google Play bzw. den App Store. Google und Apple verarbeiten dabei eigenverantwortlich Daten nach ihren eigenen Datenschutzbestimmungen, auf die wir keinen Einfluss haben.
6. Deine Rechte
Dir stehen gegenüber uns folgende Rechte zu: Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20) und Widerspruch gegen Verarbeitungen auf Basis berechtigter Interessen (Art. 21). Erteilte Einwilligungen kannst du jederzeit mit Wirkung für die Zukunft widerrufen.
Da wir keine Konten führen und keine Kennungen speichern, können wir dich in der Regel nicht identifizieren (Art. 11 DSGVO). Bei geteilten Verbindungen genügt uns der Link, um den Eintrag zu löschen; bei Fehlerberichten die Nummer des Eintrags.
Du hast außerdem das Recht, dich bei einer Aufsichtsbehörde zu beschweren — nach Art. 77 DSGVO bei der Behörde deines Aufenthaltsorts, deines Arbeitsplatzes oder des mutmaßlichen Verstoßes. Für uns zuständig ist:
Barichgasse 40–42, 1030 Wien
Telefon: +43 1 52 152-0
E-Mail: dsb@dsb.gv.at · dsb.gv.at
Da einer der Verantwortlichen in Italien ansässig ist, kommt ebenso der italienische Garante per la protezione dei dati personali in Betracht (Piazza Venezia 11, 00187 Roma).
7. Kinder
alps.ride richtet sich nicht gezielt an Kinder und erhebt wissentlich keine Daten von Kindern. Die App ist ohne Angabe personenbezogener Daten nutzbar.
8. Änderungen dieser Erklärung
Wir passen diese Erklärung an, wenn sich die App oder die Rechtslage ändert. Maßgeblich ist die jeweils hier veröffentlichte Fassung; das Datum oben zeigt den aktuellen Stand. Bei wesentlichen Änderungen weisen wir in der App darauf hin.
Privacy Policy
Applies to the alps.ride app and the alps-ride.app website · Last updated: 1 September 2026
In short: alps.ride needs no account and no sign-up. We use no advertising or tracking services, no cookies, build no user profiles and sell no data. Your location leaves the device only as a pair of coordinates, in order to look up stops and connections, and is not stored on our side. Everything else — bug reports, shared journeys — happens only when you actively trigger it.
1. Controller
Simon Schnabl
Grantenplatzl 1, 6413 Wildermieming, Austria
Matthias Komar
Schlossweg 2, 39035 Welsberg (BZ), Italy
Email: info@alps-ride.app
Both operators decide jointly on the purposes and means of processing and are therefore joint controllers. The essence of our arrangement (Art. 26(2) GDPR): we meet the information duties jointly through this policy, and you may exercise all of your rights against either of us — most easily via the shared email address above, which we both read. A request to one of us counts as a request to both.
A data protection officer is not legally required and has not been appointed. For any privacy matter, reach us at the email address above.
2. Where processing happens
The app talks only to our own server at api.alps-ride.app. It runs on an Oracle Cloud Infrastructure virtual machine in the Frankfurt am Main, Germany region (EU). Address search (Photon/Nominatim), journey planning (OpenTripPlanner) and the map tiles all run there as well — we operate all of them ourselves. The app embeds no third-party map, font or analytics services: there are no calls to Google Maps, Mapbox, Firebase or Google Fonts.
The alps-ride.app website is hosted with IONOS SE, Montabaur, Germany. It too loads no external fonts, runs no analytics scripts and sets no cookies.
3. What we process
3.1 Location data
What: Your device's geographic coordinates (latitude and longitude).
When: Only if you have granted the location permission, and only while you are actively using the app. alps.ride deliberately requests no background location and does not track your movements.
Why: To show stops near you, place you on the map, and plan a journey from where you are.
Where to: The coordinates are sent to our server to work out the matching stops or connections. They are not stored there and are not linked to any user — the request is answered and the coordinates are discarded. On your device, the most recent position is cached locally so that the app and the home-screen widgets can show something immediately after a restart.
Legal basis: Consent, Art. 6(1)(a) GDPR (given through your operating system's permission dialog). You can withdraw it at any time in the system settings; the app remains usable, you then pick stops manually.
3.2 Search and timetable requests
When you search for a stop or address, or plan a journey, the search term or the origin and destination coordinates are sent to our server and answered there. These requests are not linked into a history and are not attributed to any user.
Legal basis: Art. 6(1)(b) GDPR — providing the function you requested.
3.3 Server logs
Our web server logs every request. The IP address is truncated before it is written (for IPv4 the last octet is set to 0, IPv6 is shortened accordingly), so no complete IP address is ever stored. What is logged: timestamp, requested path, HTTP status code, bytes transferred, app version / user agent, and response time.
Why: Operational security, troubleshooting and abuse prevention.
Retention: 7 days, then deleted automatically.
For rate limiting, the server briefly processes the full IP address in memory only. It is never written to disk and is gone when the service restarts.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in secure, stable operation.
3.4 Bug reports and feature requests
If you report a bug or send an idea from within the app, we transmit what you entered — title, description, category, steps to reproduce and optionally up to five screenshots — to our server. From there an issue is created automatically in our project repository on GitHub; screenshots are uploaded to a separate, non-public repository and linked from the issue.
Important: Please do not include personal data in the text or screenshots — neither yours nor anyone else's. Note that a screenshot may reveal your location, your home stop, or content from other apps. No device, account or location data is attached automatically.
Recipient and third-country transfer: GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. The transfer to the USA is based on the EU Commission's Standard Contractual Clauses and/or certification under the EU-US Data Privacy Framework. A residual risk of access by US authorities remains.
Retention: Until the reported issue is resolved; issues are then closed and can be deleted on request.
Legal basis: Consent, Art. 6(1)(a) GDPR — reporting is voluntary and only happens when you submit.
3.5 Shared journeys (share links)
When you share a planned journey, we store the journey itself along with the origin and destination coordinates and their place names under a randomly generated, unguessable address on our server, so the recipient can view it in a browser.
Please note: Anyone holding the link can see this information — for an address search that may be a precise address, such as where you live. Only share the link with people you are willing to give that information to. The app points this out before you share for the first time.
Retention: Deleted automatically 7 days after the shared journey ends. We will delete a link sooner on request at any time.
Legal basis: Consent, Art. 6(1)(a) GDPR.
3.6 Data on your device
The following stays local to your device and is never transmitted to us: home stop, language and theme settings, display options, cached stop names and the most recent position. This data is removed when you uninstall the app.
3.7 Contacting us
If you email us, we process your message and contact details in order to reply (Art. 6(1)(b) or (f) GDPR). We keep such messages only as long as needed to deal with the matter.
4. What we do not do
- No user accounts, no sign-up, no passwords.
- No cookies or comparable tracking — neither in the app nor on the website.
- No advertising, no advertising IDs, no sharing with ad networks.
- No analytics or statistics services (no Google Analytics, no Firebase, no Matomo).
- No crash reports to third parties. The app contains an interface for error reporting, but it is not enabled. Should that change, we will update this policy first.
- No profiling and no automated decision-making within the meaning of Art. 22 GDPR.
- No selling or renting of data.
5. Recipients at a glance
| Recipient | Purpose | Location |
|---|---|---|
| Oracle Cloud Infrastructure | Running our server (processor) | Frankfurt, Germany (EU) |
| IONOS SE | Running the website | Germany (EU) |
| GitHub, Inc. | Only for voluntary bug reports | USA (third country) |
| Google LLC / Apple Inc. | App distribution through the app stores | USA (third country) |
The transit operators and data platforms the timetable data comes from (IVB, VVT, ÖBB, STA/NOI Open Data Hub) receive no data about you: that data is fetched by our server, not by your device.
The app is distributed through Google Play and the App Store. Google and Apple process data as controllers in their own right under their own privacy policies, over which we have no influence.
6. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Any consent given can be withdrawn at any time with effect for the future.
Because we keep no accounts and store no identifiers, we generally cannot identify you (Art. 11 GDPR). For a shared journey, the link is enough for us to delete the entry; for a bug report, the issue number.
You also have the right to lodge a complaint with a supervisory authority — under Art. 77 GDPR, with the authority in your country of residence, place of work, or of the alleged infringement. Ours is:
Barichgasse 40–42, 1030 Vienna, Austria
Phone: +43 1 52 152-0
Email: dsb@dsb.gv.at · dsb.gv.at
As one of the controllers is resident in Italy, the Italian Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome) is equally available.
7. Children
alps.ride is not directed at children and does not knowingly collect data from children. The app can be used without providing any personal data.
8. Changes to this policy
We update this policy when the app or the legal situation changes. The version published here applies; the date at the top shows its status. We will point out substantial changes in the app.
Informativa sulla privacy
Si applica all'app alps.ride e al sito alps-ride.app · Ultimo aggiornamento: 1° settembre 2026
In breve: alps.ride non richiede alcun account né registrazione. Non utilizziamo servizi pubblicitari o di tracciamento, non usiamo cookie, non creiamo profili utente e non vendiamo dati. La tua posizione lascia il dispositivo solo come coppia di coordinate, per cercare fermate e collegamenti, e non viene conservata da noi. Tutto il resto — segnalazioni di errori, viaggi condivisi — avviene solo se lo avvii tu.
1. Titolare del trattamento
Simon Schnabl
Grantenplatzl 1, 6413 Wildermieming, Austria
Matthias Komar
Schlossweg 2, 39035 Welsberg (BZ), Italia
E-mail: info@alps-ride.app
Entrambi i gestori decidono congiuntamente finalità e mezzi del trattamento e sono quindi contitolari. Il contenuto essenziale del nostro accordo (art. 26, par. 2, GDPR): adempiamo congiuntamente agli obblighi informativi tramite questa informativa e puoi esercitare tutti i tuoi diritti nei confronti di ciascuno di noi — più semplicemente tramite l'indirizzo e-mail comune indicato sopra, che leggiamo entrambi. Una richiesta a uno di noi vale come richiesta a entrambi.
Un responsabile della protezione dei dati non è richiesto per legge e non è stato nominato. Per qualsiasi questione relativa alla privacy puoi scriverci all'indirizzo e-mail indicato sopra.
2. Dove avviene il trattamento
L'app comunica esclusivamente con il nostro server all'indirizzo api.alps-ride.app, ospitato su una macchina virtuale di Oracle Cloud Infrastructure nella regione di Francoforte sul Meno, Germania (UE). Anche la ricerca di indirizzi (Photon/Nominatim), il calcolo dei percorsi (OpenTripPlanner) e le tile cartografiche funzionano lì e sono gestiti interamente da noi. L'app non integra alcun servizio di terzi per mappe, caratteri tipografici o analisi: non vengono effettuate chiamate a Google Maps, Mapbox, Firebase o Google Fonts.
Il sito alps-ride.app è ospitato presso IONOS SE, Montabaur, Germania. Anche il sito non carica caratteri esterni, non esegue script di analisi e non utilizza cookie.
3. Quali dati trattiamo
3.1 Dati di posizione
Cosa: le coordinate geografiche (latitudine e longitudine) del tuo dispositivo.
Quando: solo se hai concesso l'autorizzazione alla posizione e solo mentre utilizzi attivamente l'app. alps.ride non richiede deliberatamente alcuna posizione in background e non traccia i tuoi spostamenti.
Perché: per mostrare le fermate vicine a te, posizionarti sulla mappa e pianificare un viaggio a partire dal punto in cui ti trovi.
Dove: le coordinate vengono inviate al nostro server per calcolare le fermate o i collegamenti corrispondenti. Non vengono conservate e non sono associate ad alcun utente: la richiesta viene evasa e le coordinate scartate. Sul dispositivo l'ultima posizione rilevata viene memorizzata localmente, così l'app e i widget della schermata home possono mostrare subito qualcosa dopo un riavvio.
Base giuridica: consenso, art. 6, par. 1, lett. a) GDPR (prestato tramite la finestra di autorizzazione del sistema operativo). Puoi revocarlo in qualsiasi momento nelle impostazioni di sistema; l'app resta utilizzabile, dovrai selezionare le fermate manualmente.
3.2 Richieste di ricerca e di orario
Quando cerchi una fermata o un indirizzo, oppure pianifichi un viaggio, il termine di ricerca o le coordinate di partenza e destinazione vengono inviati al nostro server ed elaborati lì. Queste richieste non vengono collegate in una cronologia né attribuite ad alcun utente.
Base giuridica: art. 6, par. 1, lett. b) GDPR — erogazione della funzione da te richiesta.
3.3 Log del server
Il nostro server registra ogni richiesta. L'indirizzo IP viene troncato prima della scrittura (per IPv4 l'ultimo ottetto viene posto a 0, per IPv6 viene abbreviato di conseguenza), perciò non viene mai memorizzato un indirizzo IP completo. Vengono registrati: data e ora, percorso richiesto, codice di stato HTTP, byte trasmessi, versione dell'app o user agent e tempo di risposta.
Perché: sicurezza operativa, ricerca di errori e prevenzione degli abusi.
Conservazione: 7 giorni, poi cancellazione automatica.
Per la limitazione delle richieste (rate limiting) il server elabora brevemente l'indirizzo IP completo solo in memoria. Non viene mai scritto su disco e scompare al riavvio del servizio.
Base giuridica: art. 6, par. 1, lett. f) GDPR — legittimo interesse a un funzionamento sicuro e stabile.
3.4 Segnalazioni di errori e richieste di funzionalità
Se segnali un errore o invii un'idea dall'app, trasmettiamo al nostro server quanto hai inserito — titolo, descrizione, categoria, passaggi per riprodurre l'errore e, facoltativamente, fino a cinque screenshot. Da lì viene creata automaticamente una segnalazione (issue) nel nostro repository di progetto su GitHub; gli screenshot vengono caricati in un repository separato non pubblico e collegati alla segnalazione.
Importante: ti chiediamo di non inserire dati personali nel testo e negli screenshot, né tuoi né di altre persone. Tieni presente che uno screenshot può rivelare la tua posizione, la tua fermata preferita o contenuti di altre app. Non vengono allegati automaticamente dati del dispositivo, dell'account o di posizione.
Destinatario e trasferimento extra-UE: GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. Il trasferimento negli Stati Uniti avviene sulla base delle clausole contrattuali tipo della Commissione UE e/o della certificazione secondo l'EU-US Data Privacy Framework. Permane un rischio residuo di accesso da parte delle autorità statunitensi.
Conservazione: fino alla risoluzione del problema segnalato; le segnalazioni vengono poi chiuse e possono essere cancellate su richiesta.
Base giuridica: consenso, art. 6, par. 1, lett. a) GDPR — la segnalazione è volontaria e avviene solo con il tuo invio.
3.5 Viaggi condivisi (link di condivisione)
Quando condividi un viaggio pianificato, memorizziamo sul nostro server il viaggio stesso insieme alle coordinate di partenza e destinazione e ai relativi nomi dei luoghi, sotto un indirizzo generato casualmente e non indovinabile, affinché il destinatario possa visualizzarlo nel browser.
Attenzione: chiunque disponga del link può vedere queste informazioni — nel caso di una ricerca per indirizzo può trattarsi di un indirizzo preciso, ad esempio quello della tua abitazione. Condividi il link solo con persone a cui vuoi affidare questa informazione. L'app te lo ricorda prima della prima condivisione.
Conservazione: cancellazione automatica 7 giorni dopo la fine del viaggio condiviso. Su richiesta cancelliamo un link anche prima, in qualsiasi momento.
Base giuridica: consenso, art. 6, par. 1, lett. a) GDPR.
3.6 Dati sul tuo dispositivo
Quanto segue resta in locale sul tuo dispositivo e non ci viene mai trasmesso: fermata preferita, impostazioni di lingua e tema, opzioni di visualizzazione, nomi delle fermate memorizzati nella cache e ultima posizione rilevata. Questi dati vengono eliminati disinstallando l'app.
3.7 Contatti
Se ci scrivi un'e-mail, trattiamo il tuo messaggio e i tuoi dati di contatto per poterti rispondere (art. 6, par. 1, lett. b) o f) GDPR). Conserviamo tali messaggi solo per il tempo necessario a gestire la richiesta.
4. Cosa non facciamo
- Nessun account utente, nessuna registrazione, nessuna password.
- Nessun cookie né tracciamento equivalente, né nell'app né sul sito.
- Nessuna pubblicità, nessun ID pubblicitario, nessuna condivisione con reti pubblicitarie.
- Nessun servizio di analisi o statistica (niente Google Analytics, Firebase o Matomo).
- Nessun rapporto di crash a terzi. L'app contiene un'interfaccia per la segnalazione degli errori, ma non è attiva. Se dovesse cambiare, aggiorneremo prima questa informativa.
- Nessuna profilazione e nessun processo decisionale automatizzato ai sensi dell'art. 22 GDPR.
- Nessuna vendita o cessione di dati.
5. Destinatari in sintesi
| Destinatario | Finalità | Luogo |
|---|---|---|
| Oracle Cloud Infrastructure | Gestione del nostro server (responsabile del trattamento) | Francoforte, Germania (UE) |
| IONOS SE | Gestione del sito web | Germania (UE) |
| GitHub, Inc. | Solo per segnalazioni volontarie | USA (paese terzo) |
| Google LLC / Apple Inc. | Distribuzione dell'app tramite gli store | USA (paese terzo) |
Le aziende di trasporto e le piattaforme da cui provengono i dati sugli orari (IVB, VVT, ÖBB, STA/NOI Open Data Hub) non ricevono alcun dato su di te: tali dati vengono recuperati dal nostro server, non dal tuo dispositivo.
L'app viene distribuita tramite Google Play e l'App Store. Google e Apple trattano i dati in qualità di titolari autonomi secondo le proprie informative, sulle quali non abbiamo alcuna influenza.
6. I tuoi diritti
Hai diritto di accesso (art. 15), rettifica (art. 16), cancellazione (art. 17), limitazione del trattamento (art. 18), portabilità dei dati (art. 20) e di opposizione ai trattamenti fondati sul legittimo interesse (art. 21). Ogni consenso prestato può essere revocato in qualsiasi momento con effetto per il futuro.
Poiché non gestiamo account e non memorizziamo identificativi, di norma non siamo in grado di identificarti (art. 11 GDPR). Per un viaggio condiviso ci basta il link per cancellare la voce; per una segnalazione, il numero della issue.
Hai inoltre il diritto di proporre reclamo a un'autorità di controllo — ai sensi dell'art. 77 GDPR presso l'autorità del tuo luogo di residenza, di lavoro o della presunta violazione. La nostra è:
Barichgasse 40–42, 1030 Vienna, Austria
Telefono: +43 1 52 152-0
E-mail: dsb@dsb.gv.at · dsb.gv.at
Poiché uno dei titolari risiede in Italia, è ugualmente competente il Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Roma).
7. Minori
alps.ride non si rivolge specificamente ai minori e non raccoglie consapevolmente dati di minori. L'app è utilizzabile senza fornire alcun dato personale.
8. Modifiche a questa informativa
Aggiorniamo questa informativa quando cambiano l'app o il quadro normativo. Fa fede la versione qui pubblicata; la data in alto ne indica lo stato. In caso di modifiche sostanziali lo segnaleremo nell'app.