Who we are
HikeLevel ("we", "us", "our") provides a gamified hike and trail-run tracking experience. We operate from the European Union and process personal data in accordance with the EU General Data Protection Regulation (GDPR). The data controller is the operator of HikeLevel, reachable at support@hikelevel.app.
What data we collect
- Email address (account identifier and account-related communication)
- Authentication information (hashed password or third-party sign-in identifier)
- Activities you log: mode (hike or trail run), distance, elevation gain, duration, difficulty, optional notes, and date
- Derived gamification data: XP progression, ranks, badges, streaks, quest progress
- Payment status (whether you hold a HikeLevel Lifetime entitlement; we do not store card numbers)
- Limited technical and analytics data (e.g. anonymous usage events) needed to operate and improve the service
Why we collect it and the legal basis
- Provide the service (contract, Art. 6(1)(b) GDPR): account creation, sign-in, logging activities, computing XP, ranks, and badges.
- Process payments (contract, Art. 6(1)(b)): granting and verifying Lifetime access.
- Security and abuse prevention (legitimate interest, Art. 6(1)(f)): rate-limiting, fraud detection, paywall enforcement.
- Service improvement (legitimate interest, Art. 6(1)(f)): aggregated, anonymous usage analytics.
- Legal obligations (Art. 6(1)(c)): tax records for completed purchases.
How we use your data
Your activities power your personal progression: XP, ranks, badges, streaks, seasonal quests, and shareable achievement cards you choose to generate. We do not sell your data, we do not run third-party advertising, and we do not profile you for marketing purposes.
How long we keep it
- Account, activities, XP, ranks, badges: kept while your account is active.
- Account deletion request: data is removed within 30 days, except records we must retain by law.
- Payment and invoicing records: retained for the period required by applicable tax law (typically up to 10 years in the EU).
- Anonymous analytics: retained in aggregated form without persistent identifiers.
Service providers (sub-processors)
We use a small set of trusted providers to operate HikeLevel:
- Supabase — authentication and database hosting for your account and activity data.
- Stripe — payment processing for Lifetime purchases. Card data is handled directly by Stripe; we never see it.
- Clerk — additional authentication features, if enabled in your deployment.
- PostHog — privacy-respecting product analytics, if enabled. Activated only after consent.
- Resend — transactional email delivery (e.g. contact-form replies), if enabled.
Where these providers are located outside the EU, transfers rely on appropriate safeguards such as the EU Standard Contractual Clauses.
Your rights under GDPR
As a user located in the EU/EEA, you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten") of your account and personal data.
- Data portability: receive your activities and progression in a structured, commonly used, machine-readable format.
- Object to processing based on legitimate interest, and to restrict processing in certain cases.
- Lodge a complaint with your local supervisory authority.
To exercise any of these rights, email support@hikelevel.app. We respond within 30 days.
Account deletion
You can permanently delete your account at any time from Profile → Settings → Delete Account. Deletion removes your profile, activities, XP progression, badges, streaks, and quest progress. This action cannot be undone. Payment records may be retained where required by law.
Cookies and analytics
HikeLevel uses strictly necessary cookies and local storage to keep you signed in and to remember your preferences. Optional analytics and non-essential cookies are only enabled after you give consent, and can be withdrawn at any time.
Security
We use encryption in transit (HTTPS), encrypted database storage, role-based access, and server-side validation of every entitlement and XP calculation. No system is perfectly secure, but we work to limit data we hold and protect what we do hold.
Children
HikeLevel is not directed to children under 16. We do not knowingly collect personal data from children. Contact us if you believe a child has provided personal data.
Changes to this policy
We may update this policy as the service evolves. Material changes will be announced in the app or by email before they take effect.
Contact
Questions or requests about your data? support@hikelevel.app