Privacy Policy
Last updated: 2 May 2026
1. Who we are
RouteWeather (routeweather.cc) is operated by Tobiasz Waszak Dev, Topolowa 1a, 62-800 Kalisz, Poland (EU). VAT ID: PL6182109667. Contact: tobiaszwaszak@gmail.com.
As the operator of this website, Tobiasz Waszak Dev is the data controller within the meaning of the EU General Data Protection Regulation (GDPR) and Polish data protection law.
2. What data we collect and why
a) Account data
When you create an account we store your email address and a bcrypt-hashed password. This data is necessary to provide the account features (favourites, ride history, settings) — legal basis: performance of a contract (GDPR Art. 6(1)(b)).
b) Session data
When you sign in we store your IP address and browser user-agent in the sessions table for security purposes (detecting compromised sessions). Legal basis: legitimate interest (GDPR Art. 6(1)(f)). Sessions are automatically deleted after 90 days of inactivity.
c) Route and activity data
Routes you submit (GPX files, Strava/RideWithGPS URLs) are stored alongside metadata such as GPS coordinates, elevation and distance. Your route view history and favourites are linked to your account so you can access them later. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
d) Feedback
If you submit feedback you may optionally provide your email address. We use it only to reply to your message. Legal basis: consent (GDPR Art. 6(1)(a)).
e) Analytics (Umami)
With your consent, we use Umami Analytics to understand how the site is used (page views, clicks). Umami does not use cookies and does not track you across other websites. If you are a signed-in user, an anonymised identifier may be sent to help us understand returning visits. Legal basis: consent (GDPR Art. 6(1)(a)). You can withdraw consent at any time via the cookie banner.
f) Error monitoring (Sentry)
We use Sentry (Functional Software Inc., US) to capture application errors in production. We have configured Sentry not to send personally identifiable information (IP addresses, cookies or request headers). A Data Processing Agreement is in place with Sentry.
3. Third-party services
- Open-Meteo — weather forecasts fetched server-side; your IP is not forwarded.
- Strava / RideWithGPS — route data fetched via their APIs when you provide a URL. Their own privacy policies apply to your Strava/RideWithGPS accounts.
- Umami Analytics — see §2e above.
- Sentry — see §2f above.
All fonts, maps and scripts are served from our own origin; we do not load resources from Google Fonts, CDNs or other third parties.
4. International transfers
Sentry is based in the United States. Personal data sent to Sentry (limited to error stack traces — no PII) is protected by Standard Contractual Clauses (SCCs) under GDPR Art. 46(2)(c).
5. Your rights
Under GDPR you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate data via your account settings.
- Erasure — delete your account and all associated data via Settings → Delete account.
- Portability — download your data (routes, history, favourites) via Settings → Download my data.
- Restriction / Objection — restrict or object to processing based on legitimate interests.
- Withdraw consent — withdraw analytics consent via the cookie banner at any time.
To exercise any right, email tobiaszwaszak@gmail.com. You also have the right to lodge a complaint with your national data-protection authority.
6. Data retention
- Account data: retained until you delete your account.
- Sessions: automatically purged after 90 days of inactivity.
- Feedback: retained indefinitely unless you request deletion.
7. Cookies
We set a single first-party session cookie (session_id) that is
strictly necessary for authentication. It is HttpOnly and SameSite=Lax.
No third-party tracking cookies are set without your consent.
8. Minimum age
This service is intended for users aged 16 or older. If you are under 16 please do not create an account.
9. Changes to this policy
We may update this policy. The "Last updated" date at the top will reflect any changes. Significant changes will be notified via a notice on the site.