Privacy Policy
This Privacy Policy explains how PATHS Navigation ("we", "us") collects and uses personal data when you use the PATHS Navigation website at pathsnav.com and the PATHS Navigation app. It is written to satisfy the transparency requirements of the EU General Data Protection Regulation (GDPR) and Swedish data protection law.
Last updated: July 18, 2026
1.Data controller
PATHS Navigation, Stockholm, Sweden, is the controller for the personal data processed through PATHS Navigation. You can reach us at privacy@pathsnav.com.
2.What data we collect and why
- Account data — email, display name and sign-in identifiers when you create an app account. Purpose: create and secure your account. Legal basis: performance of a contract (Art. 6(1)(b)).
- Location data — your device's position while you actively use navigation, and the start/end points and routes you search for. Purpose: calculate accessible routes and give turn-by-turn guidance. Location is processed to provide the service you request; it is not used for advertising and never sold. Legal basis: contract; where required by your platform, your device-level permission.
- Accessibility profile — the mobility preferences you optionally set (for example avoiding steep slopes, stairs or high kerbs). Because these settings can indirectly reveal information about disability, we treat them with extra care: they are used solely to calculate routes that work for you. Legal basis: your explicit consent (Art. 9(2)(a) GDPR), which you can withdraw by clearing your profile.
- Community reports — the route conditions you report, with the location of the report and the time. Shown to other users without your name. Legal basis: contract; our legitimate interest in keeping accessibility data accurate (Art. 6(1)(f)).
- Contact messages — what you send us by email or the contact form. Legal basis: legitimate interest in answering you.
- Technical & security logs — IP address, user agent, request timestamps, error reports. Purpose: keep the service running, prevent abuse, debug issues. Legal basis: legitimate interest in security and reliability.
We do not sell personal data. We do not use your data for advertising. We do not knowingly collect data from children under 16.
3.Subprocessors and third-party recipients
We rely on a small set of vetted service providers that process personal data on our behalf under written data processing agreements:
- Supabase / Lovable Cloud — application hosting, authentication and database (EU region).
- Map, elevation and transit data providers — receive the route queries needed to compute your route; they do not receive your name or account details.
Where providers are located outside the EEA, transfers are protected by the EU Standard Contractual Clauses and supplementary measures such as encryption in transit and at rest.
4.How long we keep your data
- Account data: while your account is active, and until you delete it.
- Location traces used for live navigation: not retained after your session beyond what is needed to operate the service; saved routes and favourites remain until you delete them.
- Community reports: retained as long as they are useful for the community; the link to your account is removed if you delete your account.
- Security and error logs: typically up to 90 days, then deleted or anonymised.
- Backups age out on the normal backup rotation (max 30 days).
5.Your rights under the GDPR
You have the right to:
- access the personal data we hold about you;
- have inaccurate data rectified;
- have your data erased;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- lodge a complaint with Integritetsskyddsmyndigheten (IMY, imy.se) or your local supervisory authority.
To exercise any of these rights, email privacy@pathsnav.com. We respond within 30 days as required by the GDPR.
6.Security
All traffic is encrypted in transit using TLS. Data at rest is encrypted by our infrastructure providers. Access to production systems is restricted and requires strong authentication. Row-level security in our database scopes reads and writes to the signed-in user.
7.Cookies
See our Cookie Policy for a description of the cookies and similar storage we use.
8.Changes to this policy
We may update this Privacy Policy. The "Last updated" date at the top always reflects the current version. Material changes will be communicated by email or an in-app notice.
9.Contact
PATHS Navigation, Stockholm, Sweden — privacy@pathsnav.com.
Questions about this page? Email privacy@pathsnav.com.