RoadTripPark is committed to protecting your privacy. This policy describes
the data we collect, how we use it, and your rights.
1. Data Controller
The data controller is:
Hichame EL GHAOUTI, sole proprietor (entrepreneur individuel, EI), trading as ARQDEV STUDIO (hereinafter “ARQDEV”)
SIRET: 103 552 063 00010
Address: Allée Cervantès, 13009 Marseille, France
Publication director: Hichame EL GHAOUTI
Email: contact@roadtrippark.com
2. Data Collected
We collect the following data:
- Account information: email address, display name, profile photo
- User content: photos, journal entries, road trip itineraries. Published photos are automatically analysed by AWS Rekognition to detect inappropriate content (moderation).
- Photo geolocation: photos you add to the gallery may carry the precise GPS coordinates of where they were taken. These precise coordinates are stored but remain strictly private: only the photo's owner can view them. For other users allowed to see the photo, only the city and country (derived from those coordinates) are shown — never the exact position.
- Badges and progress: the badges and trophies you unlock, along with your progress in challenges (validated stages, completed road trips), are recorded and linked to your account.
- Technical data: device type, app version, language, crash reports (Firebase Crashlytics)
- Usage data: app interactions, screens viewed, session duration — collected via Firebase Analytics to improve the service, linked to your account identifier. Disabled by default for new installations and can be turned off at any time from Settings → Advanced → "Usage analytics"
- Device identifiers: Firebase Analytics collects the Android advertising ID (AD_ID) and an app identifier, solely for usage statistics — RoadTripPark displays no advertising and never shares these identifiers with advertisers
- Push notifications: device token (if you enable notifications)
- Geolocation data: collected only when a road trip is active. If you grant the (optional) background location permission, trace recording continues with the screen off or the app in the background, with a permanently visible notification. Two distinct processes:
- Stage validation (one-shot): when you tap "Complete this stage", your current GPS position (latitude, longitude) is sent to the server to verify you are within 20 km of the expected point (anti-cheat). This point is not stored after verification.
- Road trip trace (breadcrumb): while a road trip is active, your position is recorded every 30 seconds as points (latitude, longitude, timestamp, heading, speed), up to 50,000 points maximum per road trip. These points form the yellow trace displayed on your map.
- Social data: friends list, friend requests, published comments, likes. This data is visible to other users according to the app's social features.
- Published travel journal: you may choose to publish the journal of a completed road trip. A published journal (photos, texts, stage names, trip statistics, along with your display name and profile picture) becomes visible to all signed-in users of the app — not only your friends. The exact GPS coordinates of your photos and your GPS trace are never exposed (see "Photo geolocation" above). Publishing is optional and reversible: you can unpublish your journal at any time from the app, and it immediately becomes private again.
- Reports and moderation: when you report a piece of content (photo, journal, comment) or a user, we record the reference of the reported content, the report category, and your account identifier. This information is never visible to other users — the author of the reported content is not told who reported it — and is used exclusively for moderation. Content reported by several users is automatically hidden as a precaution pending review; any final decision (removal, reinstatement, account suspension — see our Terms) is made after human review.
- Purchase data: type of access purchased (single road trip or Roadtrip Pack). Payments are handled entirely by Google Play — we never have access to your payment details
- Biometric authentication: if you enable Face ID, Touch ID, or fingerprint, this verification is performed locally on your device. No biometric data is collected or transmitted to our servers
Background geolocation: only during an active road trip, with a visible notification. To record your trace even with the phone in your pocket while driving, the app uses the Android ACCESS_FINE_LOCATION, ACCESS_BACKGROUND_LOCATION and FOREGROUND_SERVICE_LOCATION permissions. Background recording only starts if you start a road trip yourself and explicitly grant the "Allow all the time" permission; it is accompanied by a permanent, visible notification in the status bar ("Trajet en cours — RoadtripPark enregistre votre roadtrip") and stops as soon as the road trip is completed or abandoned. This permission is optional: if you decline it, the road trip starts normally and the trace is only recorded while you are using the app. On iOS, the "Always" authorization is requested in the same way when a road trip starts, and the app reverts to "While Using" when the trip ends. You can disable GPS tracking entirely from Settings → Privacy → "GPS trip tracking", or revoke the permission at any time from your phone settings: map and stage-validation features will be disabled, but the rest of the app continues to work.
GPS data is never shared with advertisers, analytics services, friends or third parties. It is exchanged only between the app and our servers.
2bis. Roadtrip Catalogue Data Sources
RoadTripPark includes an editorial catalogue of 27 road trips covering
France, Spain, Portugal, Italy, Germany, Denmark and Norway. This catalogue contains
approximately 94 stages, 240 parking spots (motorhome areas,
campsites, car parks) and over 630 points of interest. All data in
this catalogue is compiled from public and lawful sources, verified by our
editorial team:
- OpenStreetMap — community mapping database under the
ODbL licence (commercial use permitted with attribution
"© OpenStreetMap contributors"). The stop suggestions
of the PreTrip feature come from a database derived from OpenStreetMap,
© OpenStreetMap contributors, under the ODbL licence.
- Official websites of local authorities, tourist offices,
campsite operators and motorhome areas (publicly accessible information)
- Open government data published on data.gouv.fr and
opendatasoft.com (Etalab 2.0 licence)
- On-site verification carried out by the ARQDEV editorial
team (in-person visits and checks)
- Google Maps consulted on an ad hoc basis to verify
public postal addresses and GPS coordinates (manual reading only,
no automated extraction)
Our catalogue contains no personal data about third
parties: no individual's name (operator, manager, owner), no personal email
address, no private phone number. Any names in the catalogue refer
exclusively to company names or trading names (e.g. "Camping Municipal de
Quimper"). GPS coordinates are rounded to 4 decimal places (approximately
11 metres accuracy), which does not allow identification of a private
address.
This data is provided for information purposes only and is continuously
updated. ARQDEV cannot be held liable for information that has become
outdated between updates. To report a location error or a closed spot:
contact@roadtrippark.com.
3. Legal Basis for Processing
In accordance with Article 6 of the GDPR, your data is processed on the following bases:
- Performance of contract: providing the RoadTripPark service (account, road trips, gallery, social sharing, geolocation required for road trip functionality)
- Consent: sending push notifications
- Legitimate interest: service security, content moderation, app improvement
3bis. Purposes and Legal Basis for Geolocation
GPS data collected is used exclusively for the following purposes, all based on the performance of contract (Article 6.1.b of the GDPR) — these processes are necessary for the app to fulfil its road-trip function:
- Road trip trace: building the visual journal of your trip (yellow breadcrumb on the map).
- Stage validation: checking that you are actually on site before validating a stage (anti-cheat for badges and progression).
- Multi-device sync: retrieving your trace on another device signed into the same account.
4. Use of Data
Your data is used to:
- Provide and improve the RoadTripPark service
- Display your road trips and shared content
- Send push notifications (if enabled)
- Ensure the security of your account
- Moderate published content (automatic detection of inappropriate content)
5. Storage and Security
- Authentication: managed by Firebase Authentication (Google)
- Database: MongoDB Atlas hosted on AWS Paris (eu-west-3), European Union, with encryption at rest
- GPS traces (breadcrumbs): stored in MongoDB Atlas AWS Paris (eu-west-3), European Union, encrypted at rest
- Photos: stored on Amazon S3, distributed via CloudFront (CDN)
- Password: never stored in plain text, managed by Firebase
6. Data Sharing and Processors
We never sell your personal data. Your data is only shared with
the technical services necessary for the app to function:
- Firebase (Google): authentication, push notifications, crash reports (Crashlytics), usage analytics (Analytics), device integrity attestation (App Check / Play Integrity)
- Google ("Sign in with Google"): optional authentication provider. When you choose "Sign in with Google", Google sends us your email address, your name and your profile photo, in order to create or find your account. Google LLC is based in the United States.
- Apple ("Sign in with Apple"): optional authentication provider, offered primarily on iOS. When you choose "Sign in with Apple", Apple sends us your email address (real or a private "…@privaterelay.appleid.com" relay) and, on first sign-in, your name, in order to create or retrieve your account. Apple, Inc. is based in the United States.
- Amazon Web Services: photo storage (S3), distribution (CloudFront), MongoDB Atlas database (eu-west-3, Paris)
- AWS Rekognition: automatic photo content moderation
- Railway: hosting of the app's server. The data processed by this server is hosted in the EU (Netherlands) by Railway Corporation (United States).
- Mapbox: map display and routing (the SDK may transmit technical telemetry data to Mapbox). The place names the map shows on screen are not kept. Mapbox, Inc. is based in the United States.
- OpenStreetMap Foundation — Nominatim (United Kingdom): to name the city of a photo you upload, or to find a place you search for as a stage, our server queries the Nominatim geocoding service of the OpenStreetMap Foundation (United Kingdom, a country recognised by the European Commission as providing adequate protection). Only coordinates rounded to about one kilometre, or the text of your search, are sent — never your exact position, your IP address, or any identifier of your account. The app's map is still provided by Mapbox; the place names it shows on screen are not kept.
- Google Maps and Waze: the app offers a link to open an address or a route in Google Maps or Waze. It is a plain external link: no data is sent to these services unless you tap it, and they then open in their own app, under their own terms.
- RevenueCat: in-app purchase management (receives only a technical account identifier and your purchase history — never your email address or name)
- MET Norway — Norwegian Meteorological Institute (Norway): weather display on the home screen and on the map. The app sends the
api.met.no API approximate coordinates (rounded to ~1 km — never your exact position), with no account identifier. The request is sent directly from your device, so the service receives its IP address, as with any internet request. The request carries a header identifying the app and our contact address, required by their terms of service; that header contains no data about you. Norway is part of the European Economic Area and applies the GDPR. Data under the CC BY 4.0 licence, credited in the app.
- Sentry: error tracking and performance monitoring (backend)
- Resend: transactional email service (Resend, Inc., United States), used for two distinct purposes. First, the emails we send to you: confirmation of your email address at sign-up and password reset. Your email address is then passed to Resend for delivery only, together with the signed single-use link; no other content from your account is included. Second, the internal moderation alerts triggered when content is reported by several users: these are sent to our own administration address and contain only the reference of the reported content, the category and the report count — no user identifier, neither reporter nor reported. Resend processes our sending in the European Union (Ireland).
7. Transfers Outside the European Union
Some of our processors (Firebase/Google, Amazon Web Services, Mapbox, MongoDB, Railway, Resend, RevenueCat, Sentry, Apple) are
based in the United States. For MongoDB Atlas, your data stays hosted in Paris; only occasional access by the support teams of MongoDB, Inc. (United States) is possible. These transfers are governed by:
- The EU-U.S. Data Privacy Framework
- Standard contractual clauses approved by the European Commission
8. Data Retention
- Account data: retained as long as your account is active
- User content: retained as long as your account is active, deleted upon account deletion
- GPS traces (breadcrumbs): retained as long as the corresponding road trip exists in your account. Permanently deleted when you delete the road trip or your account.
- Technical data and crash reports: 12 months maximum
- Transaction data (single road trip and Roadtrip-Pack purchases): retained for 10 years in accordance with legal accounting obligations
- Notification tokens: deleted when notifications are disabled or the account is deleted
- Notification history: retained for 90 days, then automatically deleted
- Reports: retained for a maximum of 12 months (automatic deletion), and removed earlier if you delete your account: the reports you filed and those concerning you are then deleted, along with the related internal moderation alerts.
- Server technical logs: 14 days (30 days for error logs), with no email addresses — only technical identifiers appear in them.
After account deletion, all your personal data is deleted immediately from our active servers, except for transaction data retained in dissociated form under our accounting obligations (see above). Encrypted backups are purged within 90 days maximum.
9. Your Rights
Under the GDPR, you have the following rights:
- Access: view your data from your profile
- Rectification: modify your information at any time
- Deletion: delete your account and all your data from the Settings screen ("Delete account" button at the bottom of the screen), or request it on the web: roadtrippark.com/delete-account-en. Deletion is irreversible: your personal data is deleted immediately from our active servers and encrypted backups are purged within 90 days maximum (see section 8). Two exceptions apply, required by law or by our providers: (a) purchase transaction data is retained for 10 years, dissociated from your profile, under our accounting obligations (see section 8); (b) our purchase-management provider (RevenueCat) may retain the technical identifier linked to your purchases according to its own retention policy.
- Portability: download a complete copy of your data in JSON format directly from the app (Settings → Privacy → Export my data) — see section 11ter below
- Objection: object to the processing of your data
- Restriction: request restriction of processing
- Withdrawal of consent: withdraw your consent at any time for push notifications. For geolocation (processed on the basis of performance of contract), you can revoke the Android permission at any time: road-trip features will be disabled, but the rest of the app remains usable.
To exercise these rights, contact us at
contact@roadtrippark.com.
You may also file a complaint with the
CNIL (French Data Protection Authority) or your local supervisory authority.
10. Cookies
The mobile app does not use cookies. The website roadtrippark.com
only uses technical cookies necessary for its operation (Firebase).
11. Children
RoadTripPark is not intended for children under 16. We do not knowingly
collect personal data from minors under 16.
If you are a parent and believe your child has provided us with data,
contact us so we can delete it.
11bis. Crash Reports (Crashlytics)
The app uses Firebase Crashlytics (Google) to collect anonymised crash reports.
These reports contain technical information such as device model, Android version,
app version, and the error stack trace. Your Firebase identifier (anonymous) is
attached to each report to enable per-user aggregation — no personally identifiable
data (name, email, GPS) is included.
Opt-out: you can disable crash reporting at any time from
Settings → Privacy → Crash reporting.
This setting takes effect immediately and is persisted across sessions.
11ter. Data Portability (GDPR Art. 20)
Under Article 20 of the GDPR, you can at any time export all your personal data
in a structured, machine-readable format (JSON).
How to exercise this right: open the app, go to
Settings → Privacy → Export my data.
A JSON file is generated and can be shared directly from your device
(email, cloud storage, etc.).
The export includes: profile, road trips, photos, albums, comments, likes,
friends, blocked users, reports, notifications, purchases,
and GPS traces (capped at 50,000 points for the most recent data).
This operation is limited to 5 exports per 24 hours. If you encounter any
difficulty, you may also submit a request by email to
contact@roadtrippark.com.
12. Changes
This policy may be updated. In case of significant changes,
we will notify you through the app. The last update date is
shown at the top of this page.