Privacy Policy
Draft — not yet reviewed by a lawyer. Last edited 2026-08-26.
This describes what Rudy Route Picker ("the App") collects and why. We are the data controller: iNovaLynx (KvK 42145387), whose full registered details are at the foot of this page.
1. What we collect, and why
| Data | Purpose | Where it lives |
|---|---|---|
| GPS location | Route planning, turn-by-turn navigation, ride tracking | On your device. Sent to our routing/geocoding proxy only to calculate a route; not stored server-side. |
| Motion/orientation (tilt and vibration) | Lean-angle estimation during a ride, and road-roughness measurement | On your device. It leaves your phone only if you switch on ride contribution, which is off by default — Section 4 sets out exactly what is sent and what is stripped first. |
| Ride history, saved routes, preferences | So your rides and settings persist between sessions | On your device (local storage), unless you use route sharing, which stores that one route's geometry server-side behind a link you choose to create. |
| Road closure reports | Warning other riders that a road is shut, and routing them around it | Our server database: the coordinates, the time, and which account reported it. The account link is what lets a report be traced or withdrawn if it is wrong, and stops one person shutting a road repeatedly on their own say-so. Reports expire by themselves — see Section 7. |
| Published community routes | Sharing a route with other riders, when you choose to publish it | Our server database, with your display name attached, and visible to other riders nearby. Only routes you explicitly publish; nothing is published automatically. |
| Friend connections and ride statistics | Showing friends each other's ride totals | Our server database. Feeds carry figures — distance, duration, lean — not the route you rode or where you were. |
| Bug reports, including any screenshot you attach | Diagnosing a problem you have reported | Our server database, with your account and app version, so we can reply and reproduce it. A screenshot is only ever sent if you attach one — check it does not show anything you would rather keep private before you do. |
| Google account (name, email, account ID) | Sign-in and subscription management | Our server database, to link your subscription status to your account. |
| Payment details | Subscription billing | Never seen by us. Card details are entered with and held by Stripe, our payment processor; we only ever receive your subscription status and a Stripe customer reference. |
2. Third parties we send requests through
To calculate and display a route, your query is relayed (never stored by us beyond what's needed to answer it) to:
- Routing — a server we run ourselves, so route requests for the Netherlands, Belgium, Luxembourg and Germany do not leave our own infrastructure. Routes beyond that area fall back to Stadia Maps.
- Address search — mostly answered on your device from a place-name dataset shipped inside the App, so most searches reach no one at all. Dutch street addresses are looked up with PDOK, the Dutch government's own address service.
- Weather and daylight — Open-Meteo for the forecast along a route. Sunrise and sunset are calculated on your device and sent nowhere.
- Road closures — the national roadworks feeds of the Netherlands, Belgium and Germany, requested by our server rather than by your phone.
- Map tiles — OpenFreeMap, using OpenStreetMap data.
- Routing — routes inside the Netherlands, Belgium, Luxembourg and Germany are planned on our own server, so the places you plan to ride do not leave it. A destination outside those four countries is planned by Geoapify, which means the start, end and any stops of that particular route are sent to them. Everything else stays with us.
- Address search — Photon, an OpenStreetMap search service run by komoot.
- Speed cameras & points of interest — OpenStreetMap, via Overpass, cached on our server so this is asked rarely rather than per request.
3. What we don't do
- We don't sell or share data that identifies you.
- We don't track you across other apps or websites.
- We don't build advertising profiles.
- We don't upload anything that identifies you without your say-so. On the free tier, finished rides contribute anonymous road measurements as a term of the tier — no account link, no route — and nothing beyond that is uploaded. On Pro, ride contribution is yours to switch on or off (see section 4).
4. Contributing ride data
What this depends on is which tier you are on. On the free tier, contributing road measurements is part of the service and is not optional — the routes the free tier suggests are built out of them. On Pro, it is optional and can be switched off at any time.
The difference that makes this fair, and lawful, is what is actually stored. A free-tier contribution is anonymous: it carries no link to your account, and no record of the route you rode. What is kept is individual readings tied to places on the road — a corner was taken at this speed and lean, this stretch of surface was this rough — which cannot be traced back to you or reassembled into a ride. Because that data is not personal data, there is nothing here for you to consent to and nothing to withdraw; there is also, for the same reason, nothing we could find and delete if you asked.
A Pro contribution stays linked to your account, which is what lets you delete everything you have contributed on request — and what lets you switch it off entirely.
Sharing road data onward to other organisations is a separate question and remains a genuine choice on every tier, free included. It is never a condition of using the App.
Rudy can learn which roads are genuinely good to ride from how people actually ride them. If you switch this on, finished rides contribute corner data — position of the corner, its angle, the speed and lean angle through it — which is combined across many riders to improve route suggestions for everyone.
This is off unless you turn it on. You will find it under Settings → Your ride data, as two separate switches: one to help improve routing, and a second, independent one to allow your contribution to be included in road-quality data shared with or licensed to other organisations. You can decline either, or both, and still use every part of the App. Turning the first switch off stops future uploads and marks everything you have already contributed for deletion; there is also a button to delete it all immediately.
Before anything leaves your phone we remove the first and last 500 metres of every ride. This happens on your device, so we never receive them — it is what stops a contributed ride pointing at your home or workplace. Rides too short to survive that trimming are not uploaded at all. Times are rounded to the hour, and contributed road data carries no name or email address. It is linked internally to your account, and only internally: that link is what lets you delete everything you have contributed, which would be impossible if the data were fully anonymous. It is removed before anything is aggregated, shared or licensed onward.
Anything shared with or licensed to others is aggregated across multiple riders, never an individual ride. Your own ride history stays complete and private to you inside the App — contributing changes only what is sent, not what you can see.
We record each choice you make here, and the version of this wording it was made against, so that we can show what you agreed to and when. If we change what this section permits, we will ask again rather than relying on your earlier answer.
5. Device permissions
Location and motion-sensor access are granted to the App by your browser or device, not by signing in — an account cannot grant or restore these. Installing the App to your home screen (Add to Home Screen / Install) is what keeps a permission grant from being asked again on every visit, since it runs as a persistent installed app rather than a fresh browser tab each time.
6. Your rights (EU/UK GDPR)
You can request access to, correction of, or deletion of the account data we hold (email, Google account ID, subscription status) at any time by contacting [email protected]. Data stored only on your device (ride history, saved routes) is deleted by clearing it in the App or uninstalling it — we never have a copy to delete on our end.
7. Retention
Account and subscription records are kept for as long as your account is active, plus what tax law requires afterward. Shared-route links expire automatically after 30 days.
Road closure reports delete themselves. A closure reported by one rider stops being used after seven days. If a second rider independently reports the same spot, the report is treated as confirmed and kept for twenty-eight days from that confirmation, and each further confirmation extends it again — so genuine roadworks stay up while they last, and a mistaken report disappears on its own without anyone having to clear it.
Bug reports and any screenshot attached to them are kept until the problem is resolved and then deleted. Contributed data from a Pro rider is kept until they withdraw consent or delete it, both available under Settings → Your ride data. Anonymous free-tier road measurements are kept indefinitely, because there is no person attached to them to keep them for — and, for the same reason, no way to find and remove an individual rider's.
8. Changes
We'll update this page if what we collect changes, and update the date above.
Company details
iNovaLynx — sole proprietorship (eenmanszaak), Netherlands.
Chamber of Commerce (KvK): 42145387
VAT identification number (BTW-id): NL005532797B44
Registered address: Vlasbemt 27, 5993 HV Maasbree, Netherlands
Contact: [email protected]