Back to Strollo

Privacy Notice

Last updated: July 2026

This Privacy Notice explains how Strollo ("Strollo", "we", "us") collects, uses, shares, and protects your personal data when you use our self-guided walking tour service (the "Service"). Strollo is the data controller for the personal data described below.

1. Categories of personal data we collect

  • Account data — email address, authentication identifiers, password hash.
  • Approximate location — collected only when you tap the locate button or start a walk, to suggest nearby points of interest.
  • Walk preferences — vibe, available time, favorites, weather context. Stored locally on your device and synced to your account.
  • Walk history — routes you have generated, saved, or completed.
  • Billing data — collected and processed by Stripe (see Section 4). We receive only limited metadata (subscription status, country, last four digits of the card).
  • Support messages — anything you send us by email.
  • Device and usage data — IP address, browser/device identifiers, and aggregated feature usage.

2. Purposes and legal bases (GDPR Article 6)

  • Providing the Service (account, routes, walk history) — Article 6(1)(b), performance of a contract.
  • Processing payments and subscriptions — Article 6(1)(b), performance of a contract, and Article 6(1)(c), legal obligation (tax and invoicing).
  • Security, fraud prevention, and abuse monitoring — Article 6(1)(f), legitimate interests in keeping the Service safe.
  • Product improvement and analytics (aggregated) — Article 6(1)(f), legitimate interests in improving the Service.
  • Customer support — Article 6(1)(b) and 6(1)(f).
  • Marketing emails (if any) — Article 6(1)(a), consent, which you can withdraw at any time.

3. How long we keep your data

  • Account and walk history — for as long as your account is active, then deleted within 30 days of account closure.
  • Billing records — retained by Stripe and by us for up to 7 years, as required by tax law.
  • Support messages — up to 24 months after the last correspondence.
  • Server and security logs — up to 90 days.
  • Anonymized analytics — retained indefinitely, as it can no longer identify you.

4. Sharing your data (recipients)

  • Stripe Payments Europe, Ltd. — our payment processor and Merchant of Record. Stripe handles all payments, invoicing, tax compliance, subscription management, and refund requests. Stripe's privacy notice: stripe.com/privacy.
  • Hosting and infrastructure — Lovable Cloud (backend, database, authentication) and Cloudflare (edge delivery).
  • Google Maps Platform — to render maps and suggest places. Google may receive your IP address and approximate location.
  • Email delivery — transactional emails are sent via our email infrastructure provider.
  • Professional advisers — accountants and legal counsel, where necessary.
  • Authorities — where required by law, court order, or to protect our rights.

5. International transfers

Some recipients may process your data outside the UK/EEA. Where this happens, we rely on Standard Contractual Clauses (SCCs) or adequacy decisions to safeguard your data.

6. Your rights

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data (rectification).
  • Request deletion of your data (erasure / "right to be forgotten").
  • Restrict or object to certain processing.
  • Receive your data in a portable format (data portability).
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with your local data protection supervisory authority.

To exercise any of these rights, email us at support@strollo.app. We respond within one month.

7. Security measures

We apply appropriate technical and organizational measures to protect your data, including: encryption in transit (TLS 1.2+), encryption at rest for our database, hashed passwords, role-based access controls, row-level security policies, least-privilege service credentials, audit logging, regular dependency updates, and restricted administrative access. No system is perfectly secure, but we take reasonable steps to keep your data safe.

8. Cookies

We use only essential cookies and local storage needed for authentication, preferences, and offline functionality. We do not use advertising cookies.

9. Contact

Privacy questions, requests, or complaints: support@strollo.app.