Privacy Policy

Last updated: 29 June 2026

This Privacy Policy explains how the Santiago Walk mobile application ("the App", "we", "us") collects, uses, and protects the personal information of its users ("you", "the pilgrim"). The App is developed and operated by Juan José Pereira Salinas as an individual developer based in Spain. We comply with the EU General Data Protection Regulation (GDPR) and Spanish data protection law (LOPDGDD).

On this page

  1. Data we collect
  2. How we use your data
  3. Legal basis (GDPR)
  4. Third-party services
  5. Advertising
  6. Crash reports
  7. Data retention & deletion
  8. Your rights
  9. Security
  10. Minors
  11. International transfers
  12. Changes to this policy
  13. Contact

1. Data we collect

1.1 Account data

1.2 Pilgrimage data

1.3 Location data

The App requests access to your device location only while in use, exclusively to display your position on the route map. Your location is not stored, not transmitted, and not shared with any third party. It only lives in memory while you have the map screen open.

1.4 Photos

If you choose to upload a profile picture or add a photo to a community post, the App requests access to your camera and/or gallery. The selected photo is uploaded to our storage (Supabase) and associated with your account or post. You can delete photos at any time from inside the App; the file is removed from storage immediately.

1.5 Crash diagnostics

If the App crashes unexpectedly, an anonymous diagnostic report is sent to our crash reporting provider (Sentry, see section 6). The report contains the stack trace, the type of device, and the version of the App. It does not contain your email, your diary content, your photos, your location, or your authentication token — those values are actively scrubbed before the report leaves the device.

1.6 Advertising ID

The App displays an occasional interstitial advert (one between Camino stages) served by Google AdMob. AdMob may access your device's Advertising ID for ad selection and frequency capping. You can reset or delete this ID at any time from your Android system settings (Settings → Google → Ads). See section 5 for details.

2. How we use your data

DataPurpose
EmailAuthentication, password recovery
Display name, alias, pictureShow authorship of community posts
Completed stages, diaryPersonal tracking, sync between your own devices
Posts, alerts, likesShow in the Community feed to other authenticated users
LocationReal-time map positioning, never stored
Crash diagnosticsDetect and fix bugs (anonymized)
Advertising IDFrequency capping for interstitial adverts

4. Third-party services

To operate the App we rely on the following service providers (data processors under GDPR Art. 28). Each one only receives the minimum data required for its function:

5. Advertising

The free tier of Santiago Walk shows a single interstitial advert when you complete a stage. Adverts are served by Google AdMob. AdMob may collect and process:

The App does not share your email, diary content, photos, posts, or precise GPS location with AdMob. You can opt out of personalized ads at any time from Settings → Google → Ads → Reset advertising ID on your Android device. You can also disable adverts entirely by upgrading to the planned Premium tier.

6. Crash reports

To detect and fix bugs we use Sentry. When the App crashes, an event is sent containing: stack trace, device model, OS version, App version, and a short list of UI breadcrumbs (e.g. "user opened map", "user opened profile"). The following data is explicitly scrubbed before the event leaves the device:

Crash reports are retained by Sentry for 90 days and then permanently deleted.

7. Data retention & deletion

8. Your rights (GDPR)

You may exercise the following rights at any time by writing to hello@santiagowalk.com:

9. Security

All traffic between the App and our servers is encrypted in transit via HTTPS/TLS. Passwords are never stored in plaintext; we use the secure hashing provided by Supabase Auth. Database tables holding personal data are protected with Row-Level Security policies that restrict each row to its owner. Cascading foreign keys ensure that when you delete your account every related row is removed atomically.

10. Minors

The App is not directed to children under 14 years old. We do not knowingly collect data from minors. If you are a parent or guardian and believe your child has provided personal data, contact us to delete it.

11. International transfers

Our primary data processor (Supabase) operates infrastructure in the EU (Frankfurt). When data must be transferred outside the EEA (e.g. Stadia Maps tile requests, Sentry events, AdMob), we rely on the European Commission's Standard Contractual Clauses (SCC) or equivalent safeguards.

12. Changes to this policy

We may update this policy from time to time. We will notify you in-app or by email of substantial changes. The "Last updated" date at the top of this document indicates the latest revision.

13. Contact

Data Controller: Juan José Pereira Salinas
Email: hello@santiagowalk.com
Website: https://santiagowalk.com

← Back to Santiago Walk