HikeTracker records where you walk. That is the most sensitive kind of data an app can hold, so this page says plainly what is collected, why it exists, and who else sees it. It describes what the app actually does, not what we might do later.
HikeTracker is operated by an individual developer in South Africa. For any privacy question, or to have your data deleted, email mbastenie@gmail.com.
Location is recorded only while a hike is running, including when your screen is off — which is why Android shows a permanent notification the whole time. Ending the hike stops it. The app has no reason to know where you are between hikes and does not look.
Positions the server judges impossible — wildly inaccurate, or implying a speed no walker reaches — are kept and marked as rejected rather than deleted. They are excluded from your distance, and they are the evidence if a distance ever looks wrong to you.
The name and email address or phone number of the contacts you add. This is information about somebody else, and you are the one deciding to give it to us — please only add people who would expect to hear from you.
If you raise an alarm, or your phone goes quiet during a hike, or you are overdue, your contacts are emailed. Those emails include your name, when we last heard from your phone, and your last known position with a map link. That is the entire purpose of nominating them.
A tracking link is a secret URL: whoever has it can open it, with no account and no password. It shows your display name, your route, your current position, how long you have been out, your distance, and any open alarm. It shows nothing else — not your email, not your phone number, not your contacts, and not your other hikes.
You can revoke a link at any time, which kills the URL immediately, or rotate it to issue a new one. Revoking is never blocked by billing.
Hazards and points of interest you report are shared with other people walking the same area — that is what makes the warnings work. They are published without your name or identity attached, and without any link to which of your hikes produced them.
We do not sell your data, and we do not share it for advertising.
South Africa's POPIA and the EU GDPR both give you rights over your personal information, including access, correction and deletion. The list above is how to use them here.
Traffic between the app and our server is encrypted with TLS. Passwords are stored only as hashes. Password reset codes, sign-in refresh tokens and email confirmation codes are stored as one-way fingerprints, so a copy of our database is not a set of usable credentials.
No system is perfectly secure, and we would rather say so than imply otherwise.
HikeTracker is not intended for children under 13, and we do not knowingly collect their information.
If this policy changes in a way that affects what is collected or who sees it, we will say so in the app rather than quietly editing this page.