Legal
The controller responsible for data processing on this website within the meaning of the GDPR is:
Felix Witte
Erbhof 9
44791 Bochum, Germany
Email: info@goraadv.com
No Data Protection Officer is required for this operation (fewer than 20 people regularly involved in processing; no systematic large-scale or special-category data processing).
We only process data that is technically necessary to provide the service or that you actively provide to us.
When you visit GoraAdv, our web server software — running on our own server at Hetzner (Section 3.1) — records for every request:
If a request fails, the same kind of data goes into an error log. Requests to addresses that carry a personal code — password reset, email confirmation, shared routes, group-ride invitations and newsletter links — are left out of the log.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in maintaining server security and diagnosing technical errors.
Retention: the log files are rotated daily and deleted automatically after at most eight days.
You may object to this processing under Art. 21 GDPR; however, doing so would make it impossible to serve the website to you.
Our own application additionally writes a technical log of errors, timings and navigation diagnostics (Sections 2A.5 and 2A.6). Since 16 September 2026 it contains no IP addresses, and it never contains account or contact data. It can contain a position where a calculation needed one. It is deleted automatically after at most eight days.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in finding and fixing technical errors.
The server's own system logs record, among other things, attempts to log in to the server
itself — with the IP address they came from — and what our firewall and intrusion
prevention blocked. They too are deleted automatically after at most eight days.
Legal basis: Art. 6(1)(f) GDPR — protecting the server against attacks.
If you create an account, we store:
If you sign in with Apple or Google instead of a password, we store the identifier that provider gives us for you, and no password.
Legal basis: Art. 6(1)(b) GDPR — necessary to perform the contract (providing the account-based features you signed up for).
Retention: Until you delete your account. You can delete it yourself
from your profile page, which removes the account and everything attached to it in one
step, or email support@goraadv.com.
If you save a route, we store:
Legal basis: Art. 6(1)(b) GDPR — necessary to provide the "save routes" feature you explicitly used.
Retention: Until you delete the route or your account.
The website and the app keep a few things on your device — in your browser's local storage, or in the app's own storage on your phone. None of it is used for tracking or advertising.
| What is stored | Purpose |
|---|---|
| Login data (token, user name, account number) | Keeps you signed in between visits |
| Settings you choose (units, ferries, fords, weather, map zoom and similar) | Remembers your choices |
| Planner state (your last route with its waypoints, access keys for tracks you uploaded) | Lets you continue where you left off |
| App only: navigation, recording and group-ride state, a ride or road-closure report not yet sent, routes saved on the phone, offline map packages you downloaded, and the app version of the last start | Keeps a ride or navigation going through a restart of the app or a gap in mobile signal, delivers what is waiting once you have signal again, and tells an interrupted navigation apart from an app update (Section 2A.6) |
| Display state (notices you have already seen, whether a menu or list was open, the page you came from) | Shows the website and app the way you left them |
Some of these entries contain locations — your last route, or a ride not yet sent. They stay on your device and reach us only when you use the function they belong to, for example when a finished ride is uploaded.
Legal basis: TDDDG §25(2) No. 2 — storing and reading this information is strictly
necessary for the functions you use; where personal data is involved, Art. 6(1)(b) GDPR.
Retention: until you sign out (login data), clear your browser's data for this site, or
uninstall the app. Entries for a finished task are removed once it is done — a ride once it has been
delivered, a closure report once it has been sent.
Cookies: ordinary visitors receive none — no tracking, advertising or analytics cookies. The only cookie we use marks the devices we test with, so that our own visits are not counted as users; it is set only when an internal link is opened.
If you subscribe to country launch notifications or the GoraAdv newsletter (via the countries page, the registration form opt-in checkbox, or any other sign-up form), we store:
Double opt-in. Typing an address into a form does not put it on the list. We send one email to that address asking for confirmation, and only the click in that email adds it — which is also our record that the owner of the mailbox agreed. If somebody enters your address by mistake or on purpose, doing nothing is enough: the address never receives a newsletter and is deleted 30 days after we asked. If you ticked the newsletter box while registering, the click in your account verification email confirms both at once; that email says so explicitly.
Legal basis: Art. 6(1)(a) GDPR — your consent, evidenced by the
confirmation click.
Retention: Until you unsubscribe, or 30 days after an unanswered
confirmation request. Every email we send contains a one-click unsubscribe link. You can
also email support@goraadv.com to be removed at any
time, and we will action it within 5 business days.
After downloading a GPX file you may send a share invite to up to 10 friends. When you submit the share form we receive: your chosen sender name (display name for the invite), an optional personal note (max 200 characters), and the recipient email addresses.
Recipient email addresses are not stored. We use them solely to send the one-time invite email and then discard them from memory once the send is complete. They are not written to the database, not added to any mailing list, and not used for any purpose other than the single invite.
We keep only the following, in aggregate:
Recipients open the share link without logging in; we do not set any identifying cookies on their browser and do not track who downloaded which file. A per-token counter simply enforces the 50-download cap.
Legal basis:
Art. 6(1)(b) GDPR for processing the buyer's data (providing the sharing feature you used);
Art. 6(1)(a) GDPR for sending the invite to the recipient (you confirm via the consent checkbox that the recipient has agreed to receive the invite — the recipient's legal basis is the consent you obtained from them).
Retention: The share link and aggregate consent log are retained until the buyer deletes the share (from their account) or deletes their account. Recipient email addresses: not stored at all.
If you upload a track file to edit it in the planner, the file is parsed on our server and the resulting track (coordinates, elevation, track names) is stored so the editing tools can work on it. The original file itself is not kept.
Legal basis: Art. 6(1)(b) GDPR — necessary to provide the editing
feature you used.
Retention: 24 hours without an account, 30
days with an account, then deleted automatically. Access is limited to the
device that uploaded the file (via a capability token stored in that browser) or, if you
were signed in, to your account.
We count page views using Umami, analytics software we run on our own server. No data is sent to any third party, no cookies are set, and nothing is read from your device.
What is recorded per page view: the page URL, the referring page, your browser and operating system, screen size, and the country derived from your IP address. To tell one visit apart from another, Umami calculates a short identifier from your IP address and browser details; the IP address itself is not stored. There is no profile, no cross-site tracking and no advertising use.
Besides page views, Umami counts a few actions — on the website and in the app — with no further identifier: a route was calculated (its length, its offroad share and the names of its start and end place; where no place name is found, coordinates rounded to about 1 km), a GPX file was downloaded, a route was shared (number of recipients) or saved, a POI category was opened, an account was registered.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in
understanding which parts of the site are used, in order to develop it. Because no
information is stored on or read from your device, the consent requirement of § 25
TDDDG does not apply. You may object under Art. 21 GDPR at
info@goraadv.com, or send a Do Not Track signal,
which we honour.
Retention: aggregated statistics are kept indefinitely; they contain no
identifying information.
To stop automated abuse we count recent requests per visitor for a handful of actions: GPX downloads, sign-in attempts, registration attempts, newsletter sign-ups, feedback messages, invitations to share a route, weather checks in the app, and the daily route limit for visitors without an account. Each counter row holds an identifier for the requester, the action, and a timestamp — nothing about the content of the request.
The identifier is a salted hash of your IP address, never the address itself, for every one of these counters. Re-sending the confirmation e-mail is also limited per account (five a day); that counter uses a salted hash of the account number instead. Neither hash can be turned back into an address or an account, and both are used for nothing but comparing one request against another.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in protecting
the service against automated abuse and password guessing.
Retention: these rows are deleted automatically after one day (the daily
route counter for visitors without an account after two days); they are of no use once
the time window they measure has passed.
If you send us feedback from the feedback page, we store the title, the text you wrote, the time it arrived, and — only if you filled that field in — the email address you gave us for an answer. We deliberately store nothing about where it came from: no IP address, no account, no page, no route. Leave the email field empty and we have no way of knowing who wrote.
A copy of your message is also placed in our own support mailbox, so that a reply is one click away. If you gave an address, that copy carries it as the reply address; otherwise there is nothing to reply to. Because that copy sits in the support mailbox, it is read when we go through our correspondence — including with the help of an AI assistant, as described in Section 3.9.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in improving
the service; where you gave an address, Art. 6(1)(a) GDPR — your consent, given by
typing it in, which you can withdraw at any time by asking us to delete it.
Retention: until the point it raises has been dealt with.
If you write to support@goraadv.com, info@goraadv.com or business@goraadv.com, your message arrives in a mailbox on the mail server of our hosting provider (Section 3.1). What we hold is what any email contains: your address, the name your mail program sends, the subject, the text, and anything you attach.
Once a day our own server sends us a short list of what has arrived and what is still unanswered, so that nothing sits forgotten. That list is built on our own machines and is not passed to anyone. Messages that are clearly automatic — delivery failures, newsletters, notifications from services we use — are recognised by a simple rule and only counted.
When a person then works through the mailboxes, an AI assistant helps with reading and drafting, and the messages being reviewed are transmitted at that point — see Section 3.9 below. Nothing is ever sent back to you automatically: a person writes and sends every reply.
Feedback sent through the feedback page arrives in the same support mailbox, so the same applies to it (Section 2.10).
Legal basis: Art. 6(1)(b) GDPR where your message concerns your account
or a service you asked for, otherwise Art. 6(1)(f) GDPR — legitimate interest in answering
people who write to us.
Retention: until the matter is settled and no longer needed as a record of
what was agreed. We do not delete mailboxes on a fixed schedule; you can ask us to delete
your correspondence at any time (Section 4).
For every route and round trip we calculate, we keep a short statistical record: the start and end point rounded to about 1 km, the kind of route (for example A→B or round trip), the riding mode (offroad or road), the distance, the share of each surface type, the estimated riding time, the elevation gain and loss, how long the calculation took, the time of day, and a random visit number that exists only while the page is open. The record is not linked to your account, your IP address or your name.
New routes calculated during navigation and partial routes — for example when a fuel stop is inserted — are not recorded. Records made before 21 September 2026 were rounded in the same way on that day.
We use these records to see which regions and kinds of routes are used and how long riders wait for a result, in order to improve routing.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in understanding
and improving the service.
Retention: kept indefinitely; the rounded records contain no identifying
information.
If a route or round trip cannot be calculated — because there is no connection between the points, a time limit was reached, something failed on our side, or you cancelled — we keep that request so that we can reproduce and fix the problem. It holds the points exactly as they were sent, what the planner's fields showed at that moment (a search result, map coordinates or the name of a point of interest), the settings (ferries, areas to avoid, direction of travel), the kind of route, the requested length, the reason for the failure, how long it took, whether it came from the website or the app (with the app version), and the random visit number from Section 2.12, which shows whether several attempts belong to one visit.
It contains no IP address, no account and no name. In the app this includes a recalculation during navigation that failed, together with the position at that moment (Section 2A.1). When we look into such a failure, we may use the AI assistant described in Section 3.9.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in finding and
fixing errors in route calculation.
Retention: deleted automatically after 90 days.
Everything above applies to the app as well, because it talks to the same server. The app can additionally access your location, and this section says exactly when and what leaves your phone.
The app asks your phone's operating system for permission before it uses your location, and you can withdraw that permission at any time in your device settings. Location is used for three things:
Background location. While you are navigating or a recording is running, the app keeps receiving your position with the screen off and the app in the background — otherwise guidance would stop and the recording would have a hole in it every time you pocket the phone. Your phone shows this permission separately and asks for it explicitly. Background location is used for nothing else: no advertising, no profiling, no sharing, and it is never collected when you are not recording or navigating.
Legal basis: Art. 6(1)(a) GDPR — your consent, given through the operating system's permission dialog and withdrawable there at any time.
If you record a ride and then choose to save it, the recorded track — the sequence of positions with times and elevations — is stored on our server under your account, so it is there on your other devices. A recorded track shows where you were at what time. We do not analyse it, share it, or use it for anything except showing it back to you, exporting it as a file, and reopening it in the planner.
Legal basis: Art. 6(1)(b) GDPR — necessary to provide the recording
feature you used.
Retention: until you delete the ride or your account. If your account
already holds 1,000 recorded rides, saving a new one removes the oldest; its date and
figures (distances, climb, heights — no location, no track) stay for your level and
personal bests until you delete your account. A recording you
do not save never leaves the phone.
If you join a group ride, your position, speed and direction are sent to our server every few seconds and shown to the other members of that group — that is the entire point of the feature. The same is true of theirs, shown to you. Nobody outside the group can see any of it.
A group ride also carries an alarm: if you press the help button, your position at that moment is sent to the group.
Legal basis: Art. 6(1)(a) GDPR — your consent, given by joining a
group with a code you were handed.
Retention: positions are kept only as long as the group ride is live
and are deleted with it, at the latest 24 hours after it was created.
You can leave a group at any time, which stops the sharing immediately.
From the app you can report that a track is blocked; reporting needs an account. The report holds the coordinates of the spot, whether it looked temporary or permanent, the time you observed it, an optional note you write, and your account as the reporter (reports sent without an account before 9 October 2026 carry a salted hash of the IP address instead). The reporter is stored so that a series of wrong reports can be reversed together; it is never shown to anyone.
An accepted report changes routing for everybody: we route around that spot, and permanent ones are built into our map data at the next rebuild. Other riders never see who reported it, and reports are shown to month precision only.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in not sending
other riders down a track that is closed.
Retention: a temporary report expires by itself after 180
days. A permanent one stays until it is rejected, because it describes a fact
about the terrain rather than about you.
After each navigation, the app sends us a short technical log of the decisions it made along the way — for example that you were 72 m off the route, that a new route was calculated, or that a calculation failed and why. Each entry holds the time of day, the app version and platform, the kind of event, the distance to the route, and your speed, direction and GPS accuracy at that moment. It contains no destination and, with one exception to Section 2A.1, no position: if a new route could not be calculated, that one entry holds your position rounded to about 100 m, so that we can find the spot and calculate the route again. The log is sent without your sign-in: a random number only keeps the entries of one ride together. If you are offline, the log waits on your phone and is sent the next time the app has a connection.
We use it for one purpose: finding out why navigation went wrong — including the cases where a request never reached our server, which we could not see otherwise.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in finding and
fixing navigation errors.
Retention: the entries are stored in our technical log (Section 2.1) and
deleted with it, after at most eight days.
If the app runs into a program error, it sends us a short report: the error message, where in our code it happened, the app version, the platform (iPhone or Android) and which screen was open. If navigation was cut off last time — for example because the phone ended the app — it reports that once at the next start. A report contains no position, no route and no account, and it is sent without your sign-in. The app sends at most five reports per session and each error only once.
We use them for one purpose: finding errors that happen on the phone and never reach our server otherwise.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in finding and
fixing errors in the app.
Retention: the reports are stored in our technical log (Section 2.1) and
deleted with it, after at most eight days.
Our server is rented from Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, and runs in Hetzner's data centre near Helsinki, Finland. Everything we store lies on that server — your account, saved routes and recorded rides, the log files (Section 2.1) and our backup copies — and Hetzner also keeps the occasional snapshots of the whole server (Section 7). Hetzner therefore processes all of it on our behalf as a data processor under Art. 28 GDPR; its Finnish subsidiary Hetzner Finland Oy (Tuusula) provides the data centre building and on-site technical support as a sub-processor. A data processing agreement with Hetzner is in place. The server and the data on it remain within the EU. Hetzner's privacy policy: hetzner.com/legal/privacy-policy
Place name searches and the names of points on the map use Nominatim, the OpenStreetMap Foundation's (OSMF) geocoding service. Suggestions while you type are fetched by our server: OSMF receives the search text and, so that nearby places come first, the centre of the map you are looking at, rounded to about 50 km — but not your IP address. Our server keeps the text, that rounded centre and the suggestions for up to 90 days so that the same search is not sent twice, without any link to you. Names of places are looked up by our server as well — when you place or move a point on the map, and when the app names a recorded ride or an uploaded track: OSMF receives the coordinates but not your IP address, and our server keeps the place name for that spot (to about 110 m) so it is not looked up twice, without any link to you. The OSMF tile CDN (tile.openstreetmap.org) is also contacted in two cases: as a fallback if our default map style fails to load, and on the page that shows a shared route. In those cases your IP address is transmitted to OSMF to fetch the map images. OSMF is based in the UK (adequacy decision applies). OSMF privacy policy: osmfoundation.org/wiki/Privacy_Policy
The "Support GoraAdv" button is a plain external link to ko-fi.com. No Ko-fi scripts or trackers are loaded on GoraAdv. When you click the link and visit Ko-fi, their own privacy policy applies: more.ko-fi.com/privacy
We send account-related emails (verification links, password reset, share invites) through an SMTP relay operated by our hosting provider. Your email address and the message content are transmitted to the SMTP server to deliver the message. No email contents are stored beyond the time required to deliver them. For friend-share invites specifically, see Section 2.6 — recipient addresses are not retained after sending.
The default map you see in the planner and while navigating is served by OpenFreeMap (tiles.openfreemap.org), a free map tile service. Every time the map loads or you pan and zoom, your IP address and the coordinates of the map section you are looking at are transmitted to OpenFreeMap in order to fetch the tiles. We do not send your route, your account, or any identifier along with it. OpenFreeMap's privacy information: openfreemap.org
If you switch the map to the satellite or topographic layer, those images are served by Esri (server.arcgisonline.com). As with any map service, your IP address and the coordinates of the section you are viewing are transmitted in order to fetch the images. While navigation is running and one of these layers is active, this happens continuously as the map follows you. Esri is based in the United States, so this transfer leaves the EU; it takes place only while you have chosen one of these layers. Esri's privacy policy: esri.com/en-us/privacy/overview
The standard map layer (Section 3.5) does not involve Esri. Switching back to it stops these requests.
In the app you can hand a point over to an external navigation app (for example Google Maps or Waze) from a point of interest. This only happens when you tap that button, and it transmits the coordinates of that single point to the app you chose. Their own privacy policy applies from that moment. We do not send anything to those services unless you tap the button.
While you navigate in the app, it checks the weather on the rest of your route: when navigation starts, again about 20 km before each further warning, and when you tap the weather button. For this the app sends the remaining route, starting at your current position, and the average speed used to estimate your arrival times to our server. Our server works out the forecast and the rainfall of the last two days itself, from weather model data of the Deutscher Wetterdienst (DWD) that it downloads regularly in the form prepared by Open-Meteo. Your route is not passed on to anyone — neither to the DWD nor to Open-Meteo. We do not store the route or the answer. If you switch weather off in the app settings, nothing is sent.
We use Claude, an AI assistant made by Anthropic, when we develop and maintain GoraAdv. For that it works with our program code, our server configuration and technical figures such as memory use or how many requests arrived on a given day — figures that do not relate to anyone.
We may also use it in two situations where information about you can be involved:
None of this happens automatically: a person starts every step and decides what the assistant gets to see.
Our contractual partner is Anthropic Ireland, Limited. Anthropic transfers data to the United States on the basis of standard contractual clauses, so this processing can leave the EU. The account we use has model training switched off, which means the content is not used to train their models and is deleted within 30 days, except where they are legally required to keep it or where their usage policy was broken. Anthropic's privacy information: anthropic.com/legal/privacy
When we work away from our own machine, the same session is also stored on Anthropic's servers so that it stays in sync between our devices, under the same terms.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest in keeping the service working, fixing its errors and answering the people who write to us. You may object under Art. 21 GDPR at info@goraadv.com.
If you would rather we did not use this help on your correspondence, write to us by post at the address in our imprint, or say so in your message — we will handle the rest of that exchange by hand. Please understand that a message already sitting in the mailbox may have been read with this help before we got to your request.
For most countries we look up fuel stations, places to stay and other points of interest in
our own database. For places it does not cover, our server asks one of the public
Overpass servers of the OpenStreetMap community (overpass-api.de,
overpass.kumi.systems, overpass.osm.ch). Only the coordinates of the
area being searched are sent — not your IP address, your account or your route as a whole.
Nothing is stored there on our behalf.
Elevation profiles come from our own elevation data. Only if it has a gap does our server ask
OpenTopoData (api.opentopodata.org) for the elevation of the
affected route points. Only those coordinates are sent — not your IP address and no account
information.
Under the GDPR you have the following rights regarding your personal data:
To exercise any of these rights, email info@goraadv.com. We will respond within 30 days.
You have the right to lodge a complaint with the data protection supervisory authority responsible for your place of residence, or with the authority responsible for us:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW)
Kavalleriestraße 2–4, 40213 Düsseldorf
ldi.nrw.de
A list of all German supervisory authorities is available at bfdi.bund.de.
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
This website is served exclusively over HTTPS (TLS encryption). Passwords are stored as bcrypt hashes, and password-reset tokens are stored hashed as well. There is no payment of any kind on GoraAdv, so we neither transmit nor store any payment data.
Backups. So that accounts, saved routes and recorded rides survive a hardware
failure, we back up the database once a day. Every backup is encrypted (OpenPGP) as soon as it
is made, and the key needed to open it is not kept on the server. Encrypted backups are kept on
our server for 30 days, and a second encrypted copy is kept on our own computer, whose disk is
encrypted as well, also for 30 days. In addition, our hosting provider (Section 3.1) stores
occasional snapshots of the whole server on our instruction; we keep these for no longer than
two months. If you delete your account or ask us to erase your data, it is removed from the
live database straight away; copies in backups are not used and disappear when those backups
expire. Should we ever have to restore a backup, we delete such data again before the restored
database goes back into use.
Legal basis: Art. 6(1)(f) and Art. 32 GDPR — protecting your data against
loss.
We may update this privacy policy when we add new features or third-party services. The date at the top of this page reflects the last update. Significant changes will be noted in the app.