Privacy Policy

Last updated: May 19, 2026

This Policy describes how AlpinToilet (hereinafter "the Application" or "We" or "Owner") manages the data collected. Our philosophy is based on data minimization: we collect only what is strictly necessary to operate the service securely and anonymously.

1. Data Controller and Point of Contact

The data controller is the development team of AlpinToilet. For any privacy-related request, exercise of rights or communications you can contact us at support@alpintoilet.it, which constitutes the point of contact. Communications are accepted in Italian and English.

2. Data Collected

The app is designed for use without registration and collects the following categories of data:

2.1 Device ID

A randomly generated UUID code saved locally on the device. It is used to:

Associate ratings with the device (without identifying the individual).

Ensure system integrity (limit of 1 rating per device per refuge).

Allow users to manage or delete their ratings independently.

2.2 Ratings

When you submit a rating, we save the technical parameters (cleanliness, hot water, etc.) and facility characteristics. This data is processed exclusively in aggregate form: your individual rating will never be publicly visible, but will contribute to the formation of the refuge's "Statistical Average."

2.3 Refuges

When you add a new refuge, we save the identifying data (name, location, coordinates). Users commit to not entering personal data of third parties in these fields, but only what is necessary and publicly available for the identification of the Refuge.

2.4 Geolocation

The device's GPS position is used exclusively to center the map when adding a refuge. The position is not saved or transmitted.

2.5 Age Verification

On first access, the app asks you to confirm you are at least 14 years old. This preference is saved only locally (localStorage) and is not transmitted.

2.6 IP Address

When you submit a rating (or add a new refuge) we record the public IP address from which the request originates. The IP address is used exclusively for anti-fraud purposes (detection of automated attacks, multiple voting, coordinated rating manipulation) and for security incident resolution. This data is stored exclusively in the server-side database in non-public form, is never shown to other users, is not aggregated into profiles, is not shared with third parties, and is not used for marketing or profiling purposes. The only exception is disclosure upon a duly motivated request from judicial or public security Authorities with jurisdiction.

3. Legal Basis for Processing

  • Legitimate interest: this is the primary legal basis for processing. It covers the technical functioning of the app, database security, prevention of abuse or multiple voting (Anti-Spam) and the ability to cooperate with competent Authorities through IP address logging.
  • Legal obligation: for the retention and possible disclosure of the IP address following legitimate requests from Authorities.
  • Consent: limited to GPS geolocation access. Such consent is explicitly requested by the device's operating system (iOS / Android) through the native authorization dialog, in compliance with Apple App Store and Google Play policies, which in turn condition the installation and use of applications on a minimum age declared by the device account holder. The user may deny or revoke this consent at any time from device settings, without prejudice to the usability of the app's main functions.

4. Third-Party Services

The app uses the following external services:

  • Lovable Cloud / Supabase — database and API hosting.
  • OpenStreetMap / Leaflet — map display. Tiles are loaded from OpenStreetMap servers.
  • Nominatim (OpenStreetMap) — reverse geocoding to obtain location names from refuge coordinates.
  • Open Elevation API — to automatically determine refuge altitude from coordinates.
  • api.country.is (IP geolocation) — when a rating is submitted, the request's IP address may be transmitted to this free third-party service for the sole purpose of deriving the country code (ISO 3166-1 alpha-2) associated with the event, where the network infrastructure has not already provided it via HTTP headers. The call is performed server-side, is limited to a single lookup per rating and does not transmit any other data (no Device ID, no rating content). The resulting country code is used exclusively for anti-fraud statistical purposes, as described in section 5.

5. Data Retention

Ratings and the associated refuge data are not automatically deleted based on their age and are retained indefinitely for statistical transparency and Refuge historical-record purposes. Their weight in the published average does decay over time (full weight up to 48 months, reduced to 0.1 between 48 and 72 months, zero beyond 72 months: see section 4 of the Terms of Service).

IP address and security logs — two-phase retention policy. In line with the principles of data minimization and storage limitation and with the Owner of Alpintoilet's need for legal defense, we apply the following policy:

  • From 0 to 24 months from rating submission or moderation incident logging: the IP address is stored in clear in the server-side database, in non-public form, together with the country code (ISO 3166-1 alpha-2) derived from the IP.
  • From 24 months to 10 years: the IP address is definitively and irreversibly removed from both the ratings table and the moderation incident log (`moderation_incidents`). Only the country code, event date, type (e.g. blocked voting attempt, neutralized coordinated attack) and the anonymous technical device identifier are retained, exclusively as statistical and evidentiary record of professional diligence for any legal action or defense.
  • Beyond 120 months (10 years): moderation incident logs are deleted in full automatically.

Generic device technical events (`device_events`, e.g. app open, rating submitted) follow a shorter retention and are deleted in full after 24 months, with no anonymization phase, as they have no anti-fraud evidentiary value.

Users may also delete their ratings at any time via the "Manage my ratings" section in the app menu: deletion is immediate, permanent and also removes the associated IP address; refuges left without any ratings are then automatically removed as well.

6. User Rights

You have the right to:

  • Access: view ratings associated with your device via the app menu.
  • Deletion: delete individual ratings or all ratings from the "Manage my ratings" menu.
  • Portability: rating data can be viewed directly in the app.
  • Objection: you may stop using the app at any time.

7. Cookies and Similar Technologies

The app does not use profiling cookies or advertising trackers. Data saved locally (localStorage) includes only:

  • The anonymous Device ID.
  • The age verification confirmation.

8. Security

We adopt technical and organizational measures to protect data, including encrypted communications (HTTPS) and database access policies (Row Level Security).

9. Changes to the Privacy Policy

This privacy notice may be updated periodically. Changes will be published on this page with the update date. We invite you to consult it periodically within the application.