Last updated: 8 July 2026 · Deutsche Version
This Privacy Policy explains how AlpRoute collects, uses, and protects your personal data when you use our website and application at alproute.com (the “Service”). It is written to comply with the EU General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law No. 6698 (KVKK).
The data controller — the party that decides why and how your personal data is processed — is:
Sema Volkan (sole proprietor, operating as AlpRoute)
Çiğdem Mah., Karagözsırtı Cad. No:22/2, 34800 Beykoz, İstanbul, Türkiye
Email: contact@alproute.com · Phone: +90 532 336 91 66
The third-party services listed in Section 6 act as our data processors (they process data on our behalf, under our instructions), except our payment provider, which acts as an independent seller/controller for the payment transaction as described below.
| Category | Examples |
|---|---|
| Account data | Email address, password (stored hashed by our authentication provider), account status, Pro membership status. |
| Location data | Your device location when you use “My location”, and a coarse (~250 m) area tag when you post in “Nearby travellers”. We never share your precise location with other users. |
| User content | Photos you upload, comments and price reports, “Nearby travellers” posts and replies, journals, saved and shared routes, favourites and visited places. |
| Usage & technical data | Device/browser type, approximate region, log data, and information needed to keep your session secure (e.g. active device sessions). |
To keep the community safe, text and photos submitted to the Service may be automatically screened (including by an automated moderation service) and may be reviewed following user reports. Content that breaches our Terms may be hidden or removed. See our Terms of Use for the community rules.
We use trusted third-party providers to run the Service. They process data on our behalf, only as needed to provide their function:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication and file/photo storage |
| Vercel | Website hosting and serverless functions |
| MapTiler | Map and satellite imagery tiles |
| Mapillary | Street-level / location imagery |
| OpenRouteService | Route calculation |
| MyMemory | Translation of user content |
| Resend | Sending account and transactional emails |
| OpenAI | Automated content moderation (text and images) |
| Paddle | Payment processing for Pro membership (Merchant of Record — see below) |
Payments: Pro membership is sold through Paddle (Paddle.com Market Limited, United Kingdom), which acts as the Merchant of Record. This means Paddle is the seller for the transaction, processes your payment, and handles applicable EU VAT. We do not receive or store your full card details. Paddle processes your payment data under its own privacy policy.
Some providers store or process data on servers located inside and outside the European Economic Area and Türkiye. Countries where your data may be processed include Türkiye, EU/EEA member states, the United Kingdom and the United States. Where data is transferred internationally, it is protected by appropriate safeguards such as Standard Contractual Clauses or adequacy mechanisms, and — where required under KVKK — on the basis of your explicit consent.
For users in Switzerland, this Policy also serves as the information notice required by the Swiss Federal Act on Data Protection (revFADP / revDSG). The controller is Sema Volkan (contact details in Section 1). Your data may be processed in the countries listed in Section 7; for transfers abroad we rely on safeguards such as Standard Contractual Clauses. You have the rights described in Section 9 and may also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) with any concerns.
Depending on your location, you have the right to:
To exercise any right, contact contact@alproute.com. We aim to respond within 30 days.
We use only functional storage needed to run the app — for example to keep you signed in, remember your preferences and blocked users, and cache map data for offline use. We do not use advertising or third-party tracking cookies.
The Service is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a minor has provided us data, contact us and we will delete it.
We use industry-standard measures (encryption in transit, access controls, session limits) to protect your data. No method of transmission or storage is completely secure, but we work to protect your information and to address any incident promptly.
We may update this Policy from time to time. Material changes will be indicated by updating the “Last updated” date at the top of this page.
Questions about this Policy or your data: contact@alproute.com.