Privacy Policy
Last updated: May 10, 2026
1. Introduction
Trail Pathfinder ("we," "our," or "us") operates the trailpathfinder.com website and related services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our platform or use our services.
By using Trail Pathfinder, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use our services.
2. Information We Collect
2.1 Account Information
When you register, we collect:
- Display name
- Email address
- Password (stored securely using bcrypt hashing)
- Profile photo (optional)
2.2 Location Data
With your explicit permission, we collect GPS location data when you:
- Track an activity (hiking, biking, off-road, RC crawling, etc.)
- Use the "Find My Location" feature on the map
- Enable live beacon tracking to share your position
Location data is used solely to provide trail navigation, activity tracking, and mapping features. You can disable location access at any time through your browser or device settings.
2.3 User-Generated Content
We store content you voluntarily submit, including:
- Trail submissions (name, description, GPX data, photos)
- Activity recordings and waypoints
- Comments, ratings, and reviews
- Event listings
- Group/community posts
- Chat messages in the Trailer Lounge
- Vehicle/rig garage entries and photos
- Feedback and bug reports
2.4 Automatically Collected Data
When you visit our site, we may automatically collect:
- IP address
- Browser type and version
- Pages visited and time spent
- Referring URL
- Device type and operating system
3. How We Use Your Information
We use collected information to:
- Provide and maintain our trail mapping and activity tracking services
- Display trails, activities, and events on the map
- Enable community features (groups, chat, events)
- Process trail submissions and moderate content
- Generate activity statistics and badge achievements
- Improve our platform and user experience
- Communicate service updates (no marketing spam)
- Detect and prevent abuse or security threats
4. Data Sharing
We do not sell your personal data to third parties.
Your information may be shared in the following limited circumstances:
- Public content: Trail submissions, activity summaries, event listings, and group posts are visible to other users as part of the community platform.
- Live beacon: When you activate live tracking, your real-time location is accessible to anyone with the beacon link. You control when to start and stop sharing.
- Analytics: We use Google Analytics (GA4) to understand site usage. Google may collect anonymized usage data per its own privacy policy.
- Legal requirements: We may disclose information if required by law or to protect the rights, safety, or property of our users or the public.
5. Third-Party Services
Our platform integrates with the following third-party services:
- OpenStreetMap / Leaflet: Map tiles and geographic data
- OSRM: Route calculation for the route builder
- Nominatim: Address/location geocoding
- Google Analytics: Anonymous usage analytics
Each service has its own privacy policy. We recommend reviewing them for details on their data practices.
6. Cookies and Local Storage
We use:
- Session cookies: To keep you logged in and maintain your session
- CSRF tokens: To protect against cross-site request forgery attacks
- Local storage: To remember your theme preference (dark/light mode) and PWA settings
We do not use advertising or third-party tracking cookies.
7. Data Security
We implement industry-standard security measures to protect your data:
- Passwords are hashed using bcrypt (never stored in plain text)
- CSRF protection on all form submissions
- Input validation and output escaping to prevent injection attacks
- API authentication via session cookies or Bearer tokens
- HTTPS encryption in transit
While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
8. Data Retention
We retain your data for as long as your account is active. If you delete your account:
- Your profile information is removed
- Your API tokens are revoked
- Trail submissions that have been approved may remain as community content with authorship anonymized
- Chat messages and comments may be retained in anonymized form
9. Your Rights
You have the right to:
- Access your personal data through your dashboard and profile settings
- Update your profile information at any time
- Delete your account and associated data
- Withdraw consent for location tracking by disabling browser permissions
- Export your activity data (GPX format)
10. Children's Privacy
Trail Pathfinder is not intended for children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us so we can remove it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the platform after changes constitutes acceptance of the revised policy.
12. Contact Us
If you have questions about this Privacy Policy or your data, please contact us:
- Via the in-app Feedback widget (available to logged-in users)
- Through our Facebook page