Safentura

Privacy at Safentura

Privacy that follows the trail with you.

This Privacy Policy explains how Safentura processes personal data through the mobile application, website and connected services. It describes which information we collect or receive, why we use it, how long it may be kept, which providers may process it, what happens when an account is deleted and which rights you have under applicable data-protection law.

Effective: 26 August 2026Last updated: 26 August 2026
Safentura does not sell personal data.
Precise location is used only for functions that require it, such as route monitoring and location-based trail reports.
Private routes are deleted when the account is deleted, while deliberately shared Public Routes may remain as community content.
You may exercise applicable rights including access, correction, deletion, restriction, objection and data portability.

Data controller

Sphawn · Safentura

Safentura is operated by Sphawn, a Dutch sole proprietorship registered with the Netherlands Chamber of Commerce. Sphawn determines the purposes and means of the personal-data processing described in this Privacy Policy.

privacy@safentura.comKVK 97594148Heerlen, The Netherlands
01

Scope of this Privacy Policy

This Privacy Policy applies to safentura.com, the Safentura mobile application, connected account services, administrative systems used to operate the service and direct privacy-related communications with Safentura.

It does not govern independent websites, app stores, map providers, public authorities or other external services that you access separately. Those organisations process information according to their own privacy notices.

02

Who is responsible for your data

Sphawn is the data controller for personal data processed for the operation of Safentura where Sphawn determines why and how that information is used.

Some external providers may act as processors on behalf of Sphawn, while others may act as independent controllers for their own services, such as app-store purchases or authentication services.

  • Privacy contact: privacy@safentura.com.
  • Service operator: Sphawn · Safentura.
  • Location: Heerlen, The Netherlands.
  • KVK: 97594148.
03

Account and profile data

When you create or use a Safentura account, we may process information required to identify and operate that account.

Authentication may be handled using Firebase Authentication and supported sign-in methods, including Google sign-in where available. Safentura does not store readable account passwords.

Profile information may be displayed inside your account and may be used to personalise the Safentura experience.

  • Firebase user identifier.
  • Email address.
  • Display name or username.
  • Profile photograph where provided.
  • Account creation and update timestamps.
  • Selected application language.
  • Home region and selected activity preferences where configured.
  • Preferred navigation application where configured.
  • Membership or subscription status.
  • Community statistics such as reports, confirmations and routes.
04

Authentication and Google sign-in

Safentura may use Firebase Authentication and Google authentication services to allow users to create or access their accounts.

When Google sign-in is used, Safentura may receive account information made available through the authentication process, such as a unique identifier, email address, display name and profile image.

Google processes authentication information according to its own terms and privacy documentation.

  • Safentura does not receive your Google password.
  • Authentication identifiers are used to associate Safentura data with the correct account.
  • Security information may be processed to prevent unauthorised access and abuse.
05

Device information and active-device management

Safentura may process limited device information to manage account access, security and simultaneous-device limits.

Under the current service structure, a Standard account may use one active mobile device at a time and a Premium account may use up to two active mobile devices.

When you log out from the application, Safentura may mark that device as inactive so that the corresponding active-device slot becomes available.

  • Device identifier used by Safentura for account-access management.
  • Device name or technical label where available.
  • Last activity time.
  • Active or inactive device status.
  • Application or operating-system information where required for technical operation.
06

Precise location and route monitoring

Safentura uses precise device location when you activate a function that depends on location, including route monitoring, displaying your position, checking nearby reports, determining proximity to route information or creating a report at the place where a condition is observed.

When route monitoring is active and the required permission has been granted, location processing may continue while the application is running in the background.

Safentura does not require continuous background location when route monitoring is not active.

Location accuracy depends on your device and environmental conditions and may not be exact.

  • Current latitude and longitude.
  • Location accuracy provided by the device.
  • Location timestamps where needed for the feature.
  • Location used to compare your position with a monitored route.
  • Location used to determine proximity to relevant reports or warnings.
  • Location is not sold or used to build an advertising profile.
07

Route-monitoring data

When you start monitoring a route, Safentura may process your location in relation to that route and nearby information.

Monitoring information may be used to determine whether you approach a Community Report, relevant external warning, route endpoint or another supported geographic condition.

The exact amount of monitoring data retained depends on the functionality being used. Temporary location checks do not necessarily become a permanent movement history unless a feature specifically requires route-history storage.

  • Selected route identifier.
  • Route geometry required for monitoring.
  • Current or recent location during active monitoring.
  • Proximity calculations.
  • Monitoring start and stop status.
  • Technical timestamps necessary to operate the feature.
08

Personal Route Heatmap

Eligible Premium users may use a Personal Route Heatmap that creates a visual history from route-monitoring activity recorded after the relevant Premium functionality becomes active.

Heatmap information is associated with the user's account and may include geographic route-history data needed to create the visual Heatmap.

Access to the Heatmap may be available only while the user has an active eligible Premium entitlement.

When Premium expires, Heatmap access may be disabled while historical Heatmap information may remain stored for a limited period or until deletion according to the retention rules described in this Policy.

  • Heatmap information is not public by default.
  • Heatmap information is not intended as a legally precise location history.
  • Heatmap information is not sold for advertising.
  • Heatmap access depends on Premium entitlement status.
09

GPX routes and route data

When you import a GPX route, Safentura may process route coordinates, route name, distance and technical route information required to store, display and monitor the route.

Safentura may simplify, segment or otherwise technically transform a GPX route for performance and storage.

You choose whether supported routes are Public or Private.

A Public Route is deliberately shared with the Safentura community. A Private Route is intended to remain accessible only to its owner and authorised Safentura personnel where access is necessary for operation, support, security, abuse investigation or legal compliance.

  • Public Routes may be visible to other Safentura users.
  • Public Routes may be downloadable as GPX where that function is available.
  • Private Routes are not intended as community content.
  • A GPX file may reveal sensitive locations such as a home or workplace, so users should review route data before upload.
10

Community Reports

When you create a Community Report, Safentura processes information necessary to display, manage and moderate that report.

Community Reports are intended to inform other users about conditions observed on or near a route.

A report may remain associated with your account while the account exists so that Safentura can prevent misuse, enforce report rules, display your contribution history and manage report ownership.

  • Report type or category.
  • Severity or passability information.
  • Description where provided.
  • Precise report location.
  • Timestamp.
  • Report status.
  • Reporter account identifier.
  • Confirmation and resolved-response counts.
  • Associated photograph where required or provided.
11

Report confirmations and resolved responses

Safentura may record when an authenticated user confirms that a Community Report is still relevant or indicates that the condition appears resolved.

These records help reduce manipulation, prevent duplicate responses and determine whether report status should change under the applicable community rules.

Confirmation activity may be associated with the responding user's account for integrity and abuse-prevention purposes.

  • User identifier of the responding account.
  • Report identifier.
  • Response type.
  • Timestamp.
  • Technical data necessary to enforce response limits.
12

Report photographs and metadata

Safentura may require or allow a photograph to accompany a Community Report.

Photographs may be resized, compressed or otherwise technically processed before or after upload.

Where implemented, Safentura may remove EXIF metadata before the photograph is stored or made available through the service.

Photographs associated with active reports may be visible to other Safentura users in the context of that report.

  • Do not upload unnecessary personal data about third parties.
  • Avoid identifiable faces, vehicle plates, private addresses and documents where they are not needed.
  • Photographs may be reviewed by authorised administrators for moderation, safety, privacy complaints or abuse investigation.
13

Offline report data

Safentura may allow a report to be prepared when no internet connection is available.

In that situation, report information, location and an associated photograph may be stored temporarily on the user's device until the report can be transmitted.

Temporary offline report information may be deleted automatically if it cannot be successfully transmitted within the applicable storage period.

The current implementation may retain pending offline report data locally for up to approximately 24 hours.

14

Push notifications and in-app notifications

Safentura may process information necessary to deliver device notifications and maintain an in-app notification centre.

If push notifications are enabled, Safentura or its providers may process a push-notification token associated with the device.

In-app notifications may contain information relating to reports, route monitoring, warnings, account events or Safentura updates.

A device push notification and an in-app notification may be generated and stored through separate technical mechanisms.

  • Push or device notification token.
  • Notification category.
  • Notification title and message.
  • Associated report or service identifier where relevant.
  • Creation timestamp.
  • Read or unread status for in-app notifications.
15

Safentura Premium and subscription data

Safentura processes limited subscription information to determine whether an account is entitled to Premium features.

Premium purchases made through the Android application are processed by Google Play. Safentura does not receive or store the full payment-card details used for those purchases.

RevenueCat may be used to receive and manage technical subscription-entitlement information between Google Play and Safentura.

  • Subscription or entitlement status.
  • Product or subscription identifier.
  • Purchase or entitlement timestamps.
  • Expiry information.
  • Renewal or cancellation status where available.
  • Store or platform information.
  • Technical transaction identifiers where required for entitlement validation.
16

Google Play and payment information

Google Play processes payment methods, billing information, purchase authorisation and other transaction information required to complete an Android subscription purchase.

Safentura generally receives only the information required to recognise whether the corresponding Safentura account has an active Premium entitlement.

Google processes payment information under its own privacy terms and legal responsibilities.

17

RevenueCat

Safentura may use RevenueCat to manage technical subscription entitlement information.

RevenueCat may process information such as application-user identifiers, subscription product identifiers, purchase status, entitlement status, renewal or expiration information and related technical events.

This information is used to synchronise Premium access and subscription state between the application store and Safentura.

18

Community statistics, ranks and digital achievements

Safentura may process contribution statistics to provide community ranks, points, badges, souvenirs or other digital achievements.

This information is derived from actions such as submitting reports, confirming reports or other supported community activity.

Safentura may correct or recalculate achievement information when necessary to address errors, fraud or manipulation.

  • Report counts.
  • Confirmation counts.
  • Community participation points.
  • Rank or level.
  • Earned digital souvenirs or achievements.
19

Technical, network and security data

Safentura and its service providers may process technical information required to operate, protect and diagnose the service.

Technical logs may be used for security, fraud prevention, troubleshooting, performance analysis and protection against unauthorised access.

The exact technical information available depends on the device, platform and provider.

  • IP address.
  • Application version.
  • Operating system.
  • Device type.
  • Language.
  • Network requests.
  • Request timestamps.
  • Error and diagnostic information.
  • Security events and authentication events.
20

Website data

When you visit the Safentura website, hosting and network providers may process technical information required to deliver and secure the site.

If you sign in to the Safentura website, authentication and account data may be processed so that account functionality can be provided.

Safentura does not currently use personal data for targeted advertising.

Information about cookies and similar technologies is provided through the applicable cookie information and consent controls.

21

External and official data sources

Safentura may display external or official information such as satellite heat detections, weather warnings, flood warnings or hunting restrictions.

These external datasets generally describe geographic conditions rather than individual Safentura users.

When the service requests, caches or displays those datasets, technical network information may be processed by the relevant external infrastructure.

Safentura may link to the original data source so users can consult authoritative information directly.

22

Why we process personal data

Safentura processes personal data only for defined purposes connected with providing, securing, improving and administering the service.

Different categories of personal data may be used for more than one compatible purpose where permitted by applicable law.

  • Create and maintain Safentura accounts.
  • Authenticate users.
  • Store and display user profiles.
  • Import, store and monitor routes.
  • Create, display and manage Community Reports.
  • Process confirmations and resolved responses.
  • Deliver proximity and account notifications.
  • Provide the Personal Route Heatmap.
  • Determine Premium entitlement.
  • Manage device-access limits.
  • Prevent fraud, spam, manipulation and abuse.
  • Moderate content.
  • Maintain service security.
  • Diagnose technical problems.
  • Comply with legal obligations.
  • Respond to privacy, support or legal requests.
24

Legitimate interests

Where Safentura relies on legitimate interests, we consider the necessity of the processing and balance those interests against the rights and freedoms of users.

Legitimate interests may include protecting accounts, detecting abuse, maintaining community-information integrity, preventing fraudulent Premium access, moderating harmful content, maintaining technical security and defending legal claims.

25

Information visible to other users

Some Safentura information is intentionally shared as part of the community service.

Public Routes and active Community Reports may be visible to other users depending on the applicable feature.

Safentura does not intend to expose a user's email address as public profile information.

Private Routes and Personal Route Heatmap information are not intended as public community content.

  • Public route geometry and route information.
  • Report location.
  • Report type and severity.
  • Report photograph.
  • Report date or age.
  • Confirmation or resolved status.
  • Other information deliberately made public through the relevant feature.
26

Administrative access

Authorised Safentura administrators may access personal data where reasonably necessary to operate, secure, moderate or support the service.

Administrative access may be used to investigate abuse, remove illegal or inappropriate content, respond to user requests, manage routes, investigate technical problems or comply with legal obligations.

Administrative access is not intended for unrelated personal use.

27

Service providers and recipients

Safentura uses specialised service providers to operate the application and website.

Depending on the service used, providers may process personal data on behalf of Sphawn or as independent controllers for their own activities.

  • Google Firebase — authentication, database, cloud functions, storage and related infrastructure.
  • Google — supported sign-in and Android platform services.
  • Google Play — Android application distribution and subscription payments.
  • RevenueCat — subscription-entitlement management.
  • Expo — mobile application infrastructure and notification-related services where used.
  • Vercel — website hosting and delivery.
  • Map and geographic-data providers — map display and geographic information.
  • Other technical providers where reasonably necessary to operate Safentura.
28

When personal data may be shared

Safentura does not sell personal data and does not provide personal data to data brokers.

Personal data may be disclosed only where reasonably necessary for operation of the service, where required by law or where another valid legal basis exists.

  • With processors and infrastructure providers required to operate Safentura.
  • With authorities where disclosure is legally required.
  • To protect Safentura, users or third parties against serious fraud, abuse, security threats or unlawful activity where legally permitted.
  • In connection with a lawful business transfer, restructuring or acquisition, subject to applicable data-protection requirements.
  • With another party where you have expressly authorised the disclosure.
29

International data transfers

Some Safentura service providers operate internationally. Personal data may therefore be processed outside the Netherlands or European Economic Area.

Where the GDPR requires safeguards for an international transfer, Safentura relies on appropriate mechanisms made available under applicable law, which may include adequacy decisions, Standard Contractual Clauses approved by the European Commission and supplementary security measures.

Provider-specific transfer information may be available through the official privacy documentation of the relevant provider.

30

How long personal data is kept

Safentura does not intend to retain personal data longer than reasonably necessary for the purpose for which it is processed, subject to legal, security and technical requirements.

Retention periods can differ depending on the data category and feature.

Technical backups may temporarily contain data after deletion until the applicable secure backup-rotation period is completed.

  • Account and profile data: generally while the account exists.
  • Private Routes: until deleted by the user or until account deletion.
  • Public Routes: may remain as Safentura community content after account deletion where they were intentionally shared publicly.
  • Community Reports: may remain after account deletion in anonymised form.
  • Report photographs: may remain with a retained Community Report or until the report is removed under applicable service rules.
  • Push tokens: while required and valid for enabled notification functionality.
  • Device-access records: while necessary to manage account access, security and applicable device limits.
  • Subscription information: while required to administer Premium and as necessary for accounting, fraud prevention or legal obligations.
  • Heatmap data: while required for the Premium Heatmap function and according to account or service-retention rules.
  • Temporary offline reports: generally up to approximately 24 hours on the device unless successfully transmitted sooner.
  • Technical and security logs: for limited periods appropriate to security, troubleshooting, fraud prevention and legal needs.
31

What happens when you delete your account

When you complete the Safentura account-deletion process, Safentura removes the personal account and associated personal profile data, subject to limited data that must or may lawfully be retained for security, fraud prevention, dispute handling, legal obligations or technical backup rotation.

Private Routes associated with the deleted account are deleted.

Community Reports created by the user may remain available in anonymised form. The report will no longer identify the deleted account as its reporter.

Public Routes deliberately shared with the Safentura community may remain available as community content after account deletion.

Where Public Routes remain, Safentura removes or separates account-identifying information to the extent reasonably necessary and consistent with the purpose of retaining the public community route.

  • Personal profile: deleted.
  • Private Routes: deleted.
  • Public Routes: may remain as community content.
  • Community Reports: may remain anonymously.
  • Personal authentication account: deleted.
  • Certain legally or technically necessary records may remain temporarily.
32

Security measures

Safentura uses technical and organisational measures intended to protect personal data against unauthorised access, loss, alteration or misuse.

Measures may include authentication controls, Firestore and storage access rules, restricted administrator access, encrypted network connections, provider security controls and separation between public and private data.

No internet-based service can guarantee absolute security.

  • Protect your account credentials.
  • Use a unique password where password authentication is used.
  • Protect physical access to your device.
  • Notify privacy@safentura.com if you believe your account or personal data may have been compromised.
33

Personal-data breaches

Safentura investigates suspected personal-data breaches and takes measures appropriate to the circumstances.

Where applicable law requires notification to a supervisory authority or affected individuals, Safentura will take the required steps within the applicable legal framework.

34

Automated processing and community status rules

Safentura uses certain automated processes to operate the service.

These may include duplicate-report detection, proximity calculations, report expiry, report-status updates, subscription-entitlement checks and account-device-limit enforcement.

These functions are operational rules and are not intended to make decisions producing legal or similarly significant effects about individuals within the meaning of Article 22 GDPR.

35

Your data-protection rights

Depending on the circumstances and applicable law, you may exercise rights concerning personal data processed by Safentura.

Some rights are subject to legal conditions or exceptions. Safentura may request reasonable information to verify the identity of the person making a request.

  • Right of access.
  • Right to correction of inaccurate data.
  • Right to deletion where applicable.
  • Right to restriction of processing.
  • Right to object to processing based on legitimate interests.
  • Right to data portability for eligible data.
  • Right to withdraw consent where consent is the legal basis.
  • Right to lodge a complaint with a competent supervisory authority.
36

How to exercise your rights

Privacy requests may be sent to privacy@safentura.com.

Please provide enough information for Safentura to understand the request and, where necessary, verify that you are the account holder or otherwise authorised to make the request.

Safentura will respond within the period required by applicable law. Under the GDPR this is generally one month, subject to permitted extensions in appropriate circumstances.

37

Complaints and supervisory authorities

You may contact Safentura first if you have a question or concern about personal-data processing.

You also have the right to lodge a complaint with the competent data-protection authority.

For Safentura's establishment in the Netherlands, the relevant supervisory authority is the Autoriteit Persoonsgegevens. Depending on your circumstances, you may also be entitled to contact the supervisory authority in the EU or EEA country where you live or work.

38

Children

Safentura is not directed to children under 16 years of age for independent account creation.

If you believe that a child has provided personal data to Safentura without valid authorisation, contact privacy@safentura.com so the situation can be investigated and appropriate action taken.

39

Cookies and similar technologies

The Safentura website may use cookies, local storage or similar technologies where necessary for website functionality, account access, security or user preferences.

Strictly necessary technologies may be used where they are required to provide a service requested by the user or maintain website security.

Non-essential cookies or similar technologies that require consent will not be activated before the user has been provided with the legally required choice.

More detailed information about website cookies and available choices may be provided through a dedicated cookie notice and consent interface.

41

Changes to this Privacy Policy

Safentura may update this Privacy Policy when features, processing activities, providers or legal requirements change.

Material changes will be communicated in an appropriate manner and the date shown at the top of this Policy will be updated.

Where a new processing activity requires consent, consent will be requested where legally required before that processing begins.

Official sources

Privacy law, authorities and infrastructure

These official resources provide information about European data-protection law, supervisory authorities and privacy documentation for important Safentura service providers.

Privacy request or question?

Contact Safentura regarding access, correction, deletion, restriction, portability, objection, consent, a suspected privacy issue or any question about this Privacy Policy.

privacy@safentura.com