Trust & Security
This page is maintained by PATHS Navigation to answer common security and privacy questions about the PATHS Navigation website and app. It describes controls that are currently enabled. It is not an independent certification or audit. For the formal policies, see the Privacy Policy, Terms, Cookie Policy, and Accessibility Statement.
Last updated: July 18, 2026
Authentication & access
App accounts are protected by modern authentication. Each user can only see and modify their own data — every read and write is scoped to the signed-in user through row-level security policies in our backend. Admin tooling is gated behind a separate role grant and verified server-side on every request.
Encryption
All traffic between your browser or device and our backend is served over HTTPS/TLS. Data at rest is encrypted by our infrastructure providers. Authentication tokens are managed by our backend provider's client SDK and never embedded in page source.
What we store
PATHS Navigation stores the data you give it: your account email, the accessibility preferences you set, saved routes and favourites, and the route condition reports you submit. We collect the minimum needed to run the service — see the Privacy Policy for the full inventory, legal bases and retention periods.
Location data
Your position is processed while you actively navigate, to compute accessible routes and give guidance. Live location traces are not retained after your session beyond what is needed to operate the service. Location is never used for advertising and never sold.
Accessibility profile
Mobility preferences (for example avoiding steep slopes or high kerbs) can indirectly reveal information about disability, so we treat them as sensitive: they are collected with your explicit consent, used solely for route calculation, and you can clear them at any time.
Community reports
Route condition reports are shown to other users without your name. If you delete your account, the link between you and your past reports is removed.
Your data is yours — export & deletion
You can request a copy of your data, or deletion of your account and associated data, by emailing privacy@pathsnav.com. We remove account data from active systems; residual copies in encrypted backups age out on the normal backup rotation.
Cookies & analytics
The PATHS Navigation website uses only strictly necessary storage (language and theme preferences, sign-in session). No analytics, no marketing trackers, no data sales. Details in the Cookie Policy.
Subprocessors
We rely on a small set of vetted providers, under written agreements:
- Supabase / Lovable Cloud — managed hosting, authentication, database, and file storage (EU region).
- Map, elevation and transit data providers — receive the route queries needed to compute routes; they do not receive your name or account details.
Where providers operate outside the EEA, transfers are protected by appropriate safeguards (EU Standard Contractual Clauses).
GDPR rights
If you are in the EEA or the UK you can request access, rectification, erasure, restriction, objection, and data portability. Full details and contact instructions are in the Privacy Policy.
Accessibility
PATHS Navigation targets WCAG 2.1 AA on this website and in the app. Known limitations and the feedback channel are listed in the Accessibility Statement.
Reporting a security issue
If you believe you have found a security vulnerability, please email security@pathsnav.com before sharing details publicly so we can investigate and respond.
Contact
Privacy questions or GDPR requests: privacy@pathsnav.com · Security questions or vulnerability reports: security@pathsnav.com · Anything else: hello@pathsnav.com.
PATHS Navigation · Stockholm, Sweden
PATHS Navigation is responsible for the practices described on this page. Platform capabilities provided by our infrastructure vendors are described factually and are not a PATHS Navigation certification.
Questions about this page? Email security@pathsnav.com.