Goggl is a ski app. To do what you installed it for — plan your route, record your day, find your friends on the mountain — we process personal data. This document sets out exactly what we process, why, where it is kept and what you can change about it.
No legal fog. If you read something you don’t understand, email us: contact@goggl.app.
In short
- Your recordings live on our server, but nobody else can get to them. Your full GPS track and your heart rate data are visible to you alone.
- Sharing with friends is on by default — but only with friends you have accepted, and only your day’s figures and a simplified route. You can turn it off at any time.
- Your live location on the map is off by default. You only share it once you switch it on yourself.
- No analytics, no crash tracking, no ads, no selling your data. To nobody, ever.
- Your data sits on servers in Ireland, within the European Union.
1. Who is responsible
The controller of your data is:
Maxim Janssens, trading as mixxamm Varenstraat 57, 2840 Rumst, Belgium Enterprise number BE 1023.684.154 contact@goggl.app
For anything to do with privacy — questions, requests, complaints — that email address is the right one.
2. What data we process, and why
Your account
When you create an account, we process your email address and, if you fill them in, a display name, a profile picture and your skiing ability.
Why: without an account we cannot link your recordings to you, and the social side does not work. Legal basis: performance of the contract (Article 6(1)(b) GDPR).
If you sign in with Apple or Google, we receive from them only the data needed to create your account. If you choose to hide your email address with Apple, we see Apple’s relay address and not your real one.
Your ski recordings
When you record a session, we process:
- your GPS track: the full sequence of positions, with altitude and timestamp
- your heart rate, if you give Goggl access to Apple Health
- derived data: distance, vertical metres, speeds, number of runs, lifts and breaks
- barometric altitude via your device’s pressure sensor, for more accurate altitude readings than GPS alone
Why: this is the app. No track, no map, no statistics, no logbook. Legal basis: performance of the contract (Article 6(1)(b) GDPR).
Your heart rate is health data and falls under a stricter regime (Article 9 GDPR). We process it solely on the basis of your explicit consent, which you give at the moment you grant Goggl access to Apple Health (Article 9(2)(a) GDPR). If you do not give that consent, the app works just fine — without heart rate. You can withdraw access at any time through the Health app or your device settings.
Your location
Goggl uses your location to show ski resorts near you, place your position on the map, navigate you, and — if you are recording a session — capture your route. During a recording this continues in the background, because otherwise the recording would stop the moment your screen turns off.
If you want to share your location live with friends, we store your last known position: coordinates, altitude, speed and whether you are skiing or riding a lift.
Legal basis: performance of the contract for the app itself; consent (Article 6(1)(a) GDPR) for live sharing with friends, which you can withdraw at any time by turning sharing off.
The social side
If you have friends in Goggl, we share the following with accepted friends by default:
- your day’s figures: resort, country, distance, vertical metres, number of runs and lifts, and when you started and stopped
- your top speed for that day
- a simplified route of your day, so a friend can look back at it on the map — reduced to one point every ten seconds, without heart rate and without per-point speed
- your reactions (high-fives) on other people’s days
Why: that is what the social side exists for. Legal basis: performance of the contract (Article 6(1)(b) GDPR).
This is on by default. We tell you so in the app too, in a screen you have to confirm before anything at all is shared. You can turn each part off separately in the privacy settings. Turn something off and it is immediately no longer visible to your friends — but it is not deleted. If you really want it gone, there is a separate button for that: Delete shared data.
What we do not share, not even with friends: your full GPS track and your heart rate. Those stay yours alone.
Your profile is visible to other users
Your display name, profile picture and skiing ability are visible to every signed-in Goggl user, not just to your friends. That is needed so people can find each other and send a friend request. So choose your display name and picture with that in mind.
Photos and reviews of places
If you upload a photo of a mountain hut, or write a review, they become publicly visible in the app once approved, linked to your display name. The same goes for corrections you suggest to a place’s details (opening hours, phone number, website).
Legal basis: performance of the contract. You decide for yourself whether to post something; by posting it, you make it public.
Everything is moderated in advance. We may refuse or remove contributions.
The waitlist on this website
If you join the waitlist, we keep your email address and which devices you ticked. We use that to let you know when Goggl is available, and to decide which platform to support first. Nothing else: no newsletter, no reselling.
Legal basis: consent (Article 6(1)(a) GDPR). One email to contact@goggl.app and you are off the list again.
3. What never leaves your device
Some things Goggl processes purely locally. They are never uploaded:
- Photos from your photo library. Goggl reads them to show them in the right place on your map. They stay on your device.
- The detection of lifts, runs and breaks. That runs on a model that works entirely on your device. Not a single piece of data goes to a server to compute this.
- Maps you download for offline use, and the route calculation performed on them.
- Your local database with sessions, routes and settings.
4. Where your data is kept
Our database and file storage run at Supabase, on servers in Ireland — within the European Union. Your data is stored there and does not leave the EU for the storage itself.
Supabase Inc. is a US company and acts as a processor for us. To the extent that data may flow to the United States in that capacity, this is covered by the European Commission’s standard contractual clauses.
5. Who we share data with
We sell your data to nobody. We share it with the following parties, and only for what is set out below.
| Party | What they receive | When |
|---|---|---|
| Supabase (EU servers) | All data from section 2 that is held on our server | Always — this is our database |
| Mapbox and OpenFreeMap | Your IP address and which piece of map you request. Not your track, not your account | When you view an online map |
| Strava (United States) | Your full GPS track and heart rate data for the session you upload | Only when you press upload yourself. Never automatically |
| Garmin | Navigation steps, and the names and positions of friends who share with you — to your own watch | When you pair a Garmin watch |
| Apple Health | Your recording, with route and heart rate, if you switch that on | Stays on your device; Apple receives nothing from us |
| Webcam and ski resort websites | Your IP address, because you open their site | When you tap such a link |
The Strava connection is a transfer to the United States, a country outside the EU. It happens solely at your explicit request, session by session. What Strava does with your data afterwards is governed by Strava’s privacy policy.
6. What we don’t do
This section is short, but it is the section we are proudest of.
- No analytics. No Google Analytics, no Firebase, not a single tracker that records what you do in the app.
- No crash reporting to third parties.
- No ads, no advertising SDKs, no advertising ID.
- No profiling and no automated decision-making.
- No selling or renting out of your data. To nobody.
- No cookies on this website. We don’t set any, so you don’t get a cookie banner either.
7. How long we keep it
We keep your recordings and your account for as long as your account exists. That is deliberate: your ski logbook is something you want to be able to look back on years later. If you delete your account, we delete everything.
We do not store your live location as history. We keep only your last known position, which is overwritten with every update. Turn sharing off and that position is immediately no longer visible; delete your account and it is gone.
We keep your waitlist sign-up until Goggl has launched, or until you ask to be removed.
Public photos and reviews stay up until you delete them or we delete them.
8. Your rights
Under the GDPR you have the right to:
- access your data — to request a copy of everything we hold about you
- have it corrected if something is wrong
- have it deleted — see Delete account
- take it with you to another service, in a usable format. You can already export your sessions yourself as GPX or TCX from within the app
- object to a processing activity, or have it restricted
- withdraw your consent, for everything that relies on consent (heart rate, live location, waitlist). That takes effect from that moment on; it does not make what happened before unlawful
Email us at contact@goggl.app. We respond within one month. You don’t have to give a reason and it costs you nothing.
If you think we are treating you wrongly, you may lodge a complaint with the supervisory authority:
Gegevensbeschermingsautoriteit Drukpersstraat 35, 1000 Brussel https://www.gegevensbeschermingsautoriteit.be
9. Security
Your connection to our server is encrypted. Who is allowed to see which data is enforced by the database itself, not by the app — even if someone were to tamper with the app, they could not get at anyone else’s recordings. Your login credentials are kept on your device in the operating system’s secure storage.
No system is unbreakable. If something goes wrong despite everything and that carries a risk for you, we report it to the supervisory authority within 72 hours, and to you if the risk is high.
10. Children
Goggl is not intended for children under 16 and we do not create accounts for them. If we discover that an account belongs to someone younger, we delete it and all associated data. If you are a parent or guardian and you think your child has an account, email us.
11. Changes to this policy
If something material changes about what we do with your data, we update this document and change the date at the top. For significant changes we let you know in the app or by email. We do not apply any change retroactively to data we already hold.