Last updated: 3 September 2026 · Deutsche Version
This Privacy Policy explains how AlpRoute collects, uses, and protects your personal data when you use our website and application at alproute.com (the “Service”). It is written to comply with the EU General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law No. 6698 (KVKK).
The data controller — the party that decides why and how your personal data is processed — is:
ZP İnternet ve Yazılım Hizmetleri Limited Şirketi (a limited liability company under Turkish law, operating as AlpRoute)
Çiğdem Mah. Karagözsırtı Cad. No: 22 İç Kapı No: 2, 34800 Beykoz, İstanbul, Türkiye
Email: contact@alproute.com
Data Protection Representative in the EU/EEA, the UK and Switzerland
Because we are established outside the European Union, we have appointed Data Protection Representative Limited (trading as DataRep), Dublin, Ireland, as our representative under Article 27 GDPR (EU/EEA), Article 27 UK GDPR (United Kingdom) and Article 14 of the Swiss Federal Act on Data Protection (Switzerland). If you are located in one of these regions, you may direct any question about this Policy or any request to exercise your data-protection rights to DataRep, who will forward it to us:
When writing by post, please address your letter to “DataRep” (not “AlpRoute”) and refer clearly to AlpRoute, otherwise it may not reach us. DataRep acts only as our representative for data-protection matters; for questions about the app, your account or Pro membership, please contact us directly at contact@alproute.com.

The third-party services listed in Section 6 act as our data processors (they process data on our behalf, under our instructions), except our payment provider, which acts as an independent seller/controller for the payment transaction as described below.
| Category | Examples |
|---|---|
| Account data | Email address, password (stored hashed by our authentication provider), account status, Pro membership status. |
| Location data | Your device location when you use “My location”, and a coarse (~250 m) area tag when you post in “Nearby travellers”. We never share your precise location with other users. |
| User content | Photos you upload, comments and price reports, “Nearby travellers” posts and replies, journals, saved and shared routes, favourites and visited places. |
| Usage & technical data | Device/browser type, approximate region, log data, and information needed to keep your session secure (e.g. active device sessions). |
To keep the community safe, text and photos submitted to the Service may be automatically screened (including by an automated moderation service) and may be reviewed following user reports. Content that breaches our Terms may be hidden or removed. See our Terms of Use for the community rules.
We use trusted third-party providers to run the Service. They process data on our behalf, only as needed to provide their function:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication and file/photo storage |
| Vercel | Website hosting and serverless functions |
| MapTiler | Map and satellite imagery tiles |
| Mapillary | Street-level / location imagery |
| OpenRouteService | Route calculation |
| MyMemory | Translation of user content |
| Resend | Sending account and transactional emails |
| OpenAI | Automated content moderation (text and images) |
| Paddle | Payment processing for Pro membership (Merchant of Record — see below) |
Payments: Pro membership is sold through Paddle (Paddle.com Market Limited, United Kingdom), which acts as the Merchant of Record. This means Paddle is the seller for the transaction, processes your payment, and handles applicable EU VAT. We do not receive or store your full card details. Paddle processes your payment data under its own privacy policy.
Some providers store or process data on servers located inside and outside the European Economic Area and Türkiye. Countries where your data may be processed include Türkiye, EU/EEA member states, the United Kingdom and the United States. Where data is transferred internationally, it is protected by appropriate safeguards such as Standard Contractual Clauses or adequacy mechanisms, and — where required under KVKK — on the basis of your explicit consent.
For users in Switzerland, this Policy also serves as the information notice required by the Swiss Federal Act on Data Protection (revFADP / revDSG). The controller is ZP İnternet ve Yazılım Hizmetleri Limited Şirketi (contact details in Section 1). Our representative in Switzerland under Article 14 FADP is Data Protection Representative Limited (trading as DataRep); contact details are given in Section 1. Your data may be processed in the countries listed in Section 7; for transfers abroad we rely on safeguards such as Standard Contractual Clauses. You have the rights described in Section 9 and may also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) with any concerns.
Depending on your location, you have the right to:
To exercise any right, contact contact@alproute.com or, if you are in the EU/EEA, the UK or Switzerland, our representative DataRep (Section 1). We aim to respond within 30 days.
We use only functional storage needed to run the app — for example to keep you signed in, remember your preferences and blocked users, and cache map data for offline use. We do not use advertising or third-party tracking cookies.
The Service is intended for users aged 18 and over. We do not knowingly collect personal data from children. If you believe a minor has provided us data, contact us and we will delete it.
We use industry-standard measures (encryption in transit, access controls, session limits) to protect your data. No method of transmission or storage is completely secure, but we work to protect your information and to address any incident promptly.
We may update this Policy from time to time. Material changes will be indicated by updating the “Last updated” date at the top of this page.
Questions about this Policy or your data: contact@alproute.com.