Privacy Policy

Last updated: September 8, 2026

This Privacy Policy explains what personal data Good Experience s.r.o. collects, why we collect it, and what rights you have. It applies when you use Climbing Place or Hike Place.

Who we are

The controller is Good Experience s.r.o., Heinemannova 2695/6, Dejvice, Praha 6, 160 00, Czechia (the Company, we, us).

Contact: contact@climbing.place, or the contact form.

The supervisory authority in Czechia is the Úřad pro ochranu osobních údajů (Office for Personal Data Protection).

What this policy covers

The Service includes:

  • the websites climbing.place and hike.place;
  • the Android apps that open those sites (Trusted Web Activities, packages place.climbing.app and place.hike.app);
  • the Climbing Place watch apps for Garmin, Amazfit (Zepp) and Wear OS;
  • pairing those watches with a climbing.place account and uploading sessions to your logbook.

Using the Service is voluntary. Some features (an account, a public listing, a paired watch, payments) need extra data; you can still browse public content without creating an account.

Personal data we collect

Account and profile

When you register or sign in we may collect:

  • e-mail address and password (stored as a hash);
  • name;
  • optional biography and profile picture;
  • preferences: language, unit system, grade system, whether your profile and logbook are public, e-mail and push notification settings;
  • if you sign in with Google or Facebook: the identifier those providers give us, plus the e-mail and name they share with your consent.

Logbook, contributions and public content

If you use logged-in features we store what you create, for example:

  • outdoor and gym ascents (place, grade, style, date, comments);
  • training log entries;
  • bookmarks;
  • hike posts, photos, notes and GPX tracks;
  • route / gym / topo suggestions and uploaded images (including topos);
  • partner-finder posts;
  • chat and direct messages;
  • guide bookings and inquiry messages;
  • watch sessions imported into your logbook (see Watch apps).

Content you mark as public (a public profile, a listing, a contribution, a partner post) can be seen by other users and by search engines. Private logbook items stay on your account unless you make the profile public.

Photos and camera

You may upload photos (routes, hikes, topos, a profile picture, a guide listing). If a photo contains GPS EXIF data, we may read coordinates, altitude and the capture time so we can place it on a map or a street-view walk. The browser or phone camera is used when you scan a watch pairing QR code or take a photo in the app; images are processed only after you choose to upload them.

Location

  • Approximate location: we may look up your IP address in a MaxMind GeoLite2 database on our servers to set a default map view. That lookup stays on our servers.
  • Precise location: only when you use “Near me”, grant geolocation in the browser or Android app, or enable GPS on a watch (typically via ferrata). We use it to show nearby places and, on a watch, to record a track.
  • Photo GPS: as above, from EXIF if present.
  • Last map position: stored in a first-party cookie (lastMapPosition) so the map can reopen where you left it.

We do not track your location in the background on the websites. Watch GPS runs only during a session when that mode and the GPS setting are on.

Watch apps (Garmin, Amazfit, Wear OS)

The watch app records a climbing session on the device. While a session runs it may read:

  • heart rate;
  • barometric altitude (ascent, indoor route detection);
  • calories reported by the watch;
  • time, laps and grades you enter;
  • GPS track and distance, when GPS is enabled (via ferrata and similar modes);
  • device name / model sent with an upload.

Sessions stay on the watch until you save or discard them. A normal Garmin activity is also written as a FIT file in Garmin Connect; that copy is Garmin’s, not ours.

Pairing is optional. Without a climbing.place account the watch still records; nothing is sent to us. If you pair:

  • you generate a code on the website (My logbook → Watch) or show a QR from the watch;
  • we store only a hash of the code, not the code itself;
  • finished sessions are sent over HTTPS to https://climbing.place/api/watch/session (via Garmin Connect Mobile, the Zepp phone app, or the Wear OS app) with that token;
  • we then store the summary in your logbook: mode, times, duration, ascent/descent, distance, grades, laps, average/max heart rate, calories, device, and an optional GPX track.

Heart rate and related activity metrics are health data (GDPR Article 9). We process them only to provide your logbook, and only if you pair the watch and upload a session — that is your explicit consent. You can stop uploads by clearing the pairing code in the watch/phone settings. You can ask us to delete stored sessions (see Your rights).

We do not sell watch data, use it for advertising, or share heart rate, GPS or session data with advertisers.

Guide listings and payments

If you publish a guide listing we store the listing (display name, photo, bio, services, location text, languages, certifications, website, phone) and billing status. Paid listings go through Stripe. Stripe processes the payment; we store Stripe customer and subscription identifiers and whether the listing is paid. We do not store full card numbers.

Messages we send you

We send e-mail for things you asked for (password reset, contact-form confirmation) and, if you leave e-mail notifications on, for product messages such as chat. Push notifications use the Web Push protocol and a subscription stored against your account; you can turn them off in settings or in the browser.

We do not run SMS or phone marketing. We do not send newsletters beyond those notification settings.

Contact form

Name, e-mail, subject and message. We e-mail a copy to ourselves and a short confirmation to you.

Usage data

Servers automatically log IP address, browser and device type, pages requested, date and time, and similar diagnostic data. This is needed to run and secure the Service.

If you allow tracking cookies, Google Analytics 4 (Google Ireland Limited, measurement ID G-EVMHMZJJX0) measures traffic. You can refuse tracking in Cookie preferences.

Cookies and similar storage

We use first-party cookies and local storage:

  • Strictly necessary: session / login cookies so the site works; cookie-consent choice (cookie_consent_level).
  • Functionality: last map position; colour theme in local storage (bsTheme).
  • Tracking (optional): Google Analytics cookies, only after you accept tracking.
  • Targeting (optional): we do not show third-party ads. This banner category only controls Google’s ads-related consent signals used by Analytics if you grant it. You can leave it off.

You can change this at any time via Cookie preferences in the footer.

How we use the data (legal bases)

  • Contract (GDPR Art. 6(1)(b)): creating and running your account, logbook, uploads, watch pairing and uploads, guide listings, bookings and chat.
  • Consent (Art. 6(1)(a), and Art. 9(2)(a) for health data): analytics cookies; precise geolocation in the browser; uploading heart-rate and GPS sessions from a watch; optional notifications.
  • Legitimate interests (Art. 6(1)(f)): security, abuse prevention, GeoIP map defaults, aggregated statistics, improving the Service. You may object.
  • Legal obligation (Art. 6(1)(c)): accounting records for paid listings, and other duties under Czech or EU law.

Who we share data with

We do not sell personal data. We share it only as follows:

  • Google Ireland Limited — Analytics (if you consent); reCAPTCHA on sign-up, sign-in, password reset and the contact form; Google sign-in if you choose it.
  • Meta Platforms Ireland Limited — Facebook Login if you choose it.
  • Stripe — payments for guide listings.
  • OpenStreetMap Foundation — map tiles. Your IP address and the map area you view are sent to OSM when a map loads.
  • Nominatim (OpenStreetMap) and Photon (Komoot) — reverse geocoding when we turn coordinates into a place name (for example after reading photo GPS).
  • Garmin / Zepp (Amazfit) — if you use their watch and phone apps, those companies process the activity according to their own policies. We receive a session only when you have paired and the phone uploads it to us.
  • Browser push services (for example Google FCM, Mozilla, Apple) — to deliver a push you enabled.
  • CDNs we sometimes load scripts or map extras from (for example cdnjs / Cloudflare, unpkg) — they see your IP the same way any website asset would.
  • Other users — what you publish or send to them (public profile, listings, partner posts, chat, bookings).
  • Authorities — if the law requires it.

reCAPTCHA may collect device and interaction data. It loads on pages that need spam protection (contact, sign-in, sign-up, forgotten password), not on every page.

MaxMind GeoLite2 runs on our servers; we do not send your IP to MaxMind for that lookup.

Where data is processed

We process data in the EU (Czechia). Some processors above are in the EU (Google Ireland, Meta Ireland) or may transfer data to the United States. Where a transfer outside the EEA is needed, it relies on an adequacy decision or Standard Contractual Clauses.

How long we keep data

  • Account, logbook, uploads, watch sessions, chat: for as long as the account exists, then until you ask us to delete them or they are no longer needed.
  • Contact-form messages: as long as needed to answer you and keep a basic record of the request.
  • Payment / listing billing: as required by Czech tax and accounting rules.
  • Server logs: a short period for security and operations, unless a log is needed longer to investigate abuse.
  • Analytics: according to our Google Analytics retention setting; stops for new hits if you withdraw cookie consent.
  • Pairing-code hashes: until you revoke the code or we delete the account.

Usage data used only for security or debugging is kept shorter than account content.

Your rights

You can request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests. Where we rely on consent, you can withdraw it at any time (cookie banner; watch pairing; notification switches; browser location permission) without affecting earlier processing.

In your account settings you can edit your profile and download a JSON export of core account data (profile, ascents, training log, bookmarks, partner posts, suggestions). That export is not a complete dump of every table; for watch sessions, chat, photos or a full erasure, contact us.

We do not currently offer a one-click account deletion button. To delete your account and the personal data we hold, e-mail contact@climbing.place or use the contact form. We will delete or anonymise what we can; we may keep what the law requires (for example invoices) or what must stay as part of a public contribution you asked us to publish, unless you ask us to remove that too.

You may lodge a complaint with the Úřad pro ochranu osobních údajů or with the authority in your EU country of residence.

Children

The Service is not directed at children under 15 (the age of digital consent in Czechia). We do not knowingly collect personal data from anyone under 15. If you believe a child has registered, contact us and we will delete the account.

Security

We use HTTPS, hashed passwords, hashed watch pairing codes, and ordinary access controls. No transmission or storage on the internet is completely secure.

Links to other sites

The Service links to third-party sites (maps, social login, stores, external topos). Their privacy practices are their own. Garmin Connect, Zepp and Google Play have separate policies for their platforms.

Changes

We may update this policy. The new version is posted on this page with a new “Last updated” date. For material changes we will also show a notice on the Service or e-mail account holders when that is reasonable.

Contact