← rastros

Privacy policy

Effective: 2026-06-27

Who we are

Rastros is operated by GBS Tecnologia LTDA, a Brazilian limited liability company (sociedade empresária limitada) registered in Brazil. This privacy policy explains what personal data we collect when you use Rastros at https://rastros.app, why we collect it, how long we keep it, and the rights you have over it under the General Data Protection Regulation (GDPR) in the EU/UK, the Lei Geral de Proteção de Dados (LGPD) in Brazil, and the California Consumer Privacy Act (CCPA/CPRA) in California — among other state laws in the US.

If you have any question about this policy or want to exercise your rights, contact us at [email protected].

What we collect and why

WhatWhyLegal basis (GDPR / LGPD)
Email and name from Google sign-inTo create and identify your accountContract performance
Content you upload — albums, routes (GPX/FIT files and the GPS points inside them), memories (text, photos, videos, audio)To provide the service you signed up forContract performance
Subscription identifiers (Stripe customer ID, subscription ID, invoice metadata)To bill, generate receipts, and apply feature limitsContract performance
Product analytics events from your browser (page views, feature interactions), tied to a pseudonymous identifier set in your browserTo understand how Rastros is used and improve itConsent (you can opt in or out at any time via the Cookies link in the footer)
Server-side operational signals tied to your account id — consent decisions (so we can audit that you accepted or refused) and feature-flag evaluations (so we can stage paid features safely). For feature-flag evaluation the id is hashed before leaving our server.Comply with consent-audit obligations and operate the service safelyLegal obligation (consent records); legitimate interest (feature-flag evaluation)
Server logs (IP address, request path, timestamp) for a short retention windowTo debug, prevent abuse, and meet legal logging obligationsLegitimate interest

We do not sell your personal data. We do not share it with third parties for marketing.

Where your data lives

DataProviderRegion
Account, content, billing identifiers (database)SQL-like databaseEU and Brazil
Photos, videos, audio uploadsS3-like object storageEU and Brazil
AuthenticationGoogle OAuth (Google LLC)Global
Payment processingStripe, Inc.US (with EU-standard contractual clauses)
Product analytics, consent-decision audit, and feature-flag evaluationPostHog Inc.EU (eu.i.posthog.com)
Error monitoring, performance traces, and session replaySentry (Functional Software, Inc.)EU (ingest.de.sentry.io)
Map tilesMapbox, Inc.Global

These providers act as sub-processors on our behalf. We have data-processing agreements where applicable, and they are restricted to what they need to perform their function.

What we send to PostHog

Two distinct kinds of data go to PostHog:

What we send to Sentry

Sentry helps us catch and diagnose application errors. Three kinds of data may go to Sentry:

How long we keep things

DataRetention
Account data (email, name)While your account is active. After account deletion, removed within 30 days; backups expire within 30 days more
Content you uploadedSame as account data
Subscription / billing records5 years after the last transaction (legal/tax obligation)
Browser analytics events (PostHog)12 months unless you opt out earlier
Feature-flag evaluation entries (PostHog)12 months. Tied to a hashed identifier for rollout bucketing
Sentry error events90 days
Sentry session replays30 days. Only present if you opted into analytics
Sentry performance traces30 days
Server logs30 days
Consent records (audit of accept/reject)3 years after the last decision (LGPD demonstrability)

When you delete your account, we erase or anonymize the data above within the windows shown. We may keep aggregate, fully-anonymized data indefinitely for product improvement.

Cookies and similar technologies

Cookie / storagePurposeStrictly necessary?
better-auth.session_token (cookie)Keep you logged inYes
PARAGLIDE_LOCALE (cookie)Remember your language choiceFunctional — required for the language switcher
ph_*_posthog (cookie + localStorage)Pseudonymous product analyticsNo — opt-in only
sentry* (sessionStorage)Continues a session-replay recording across page loadsNo — only set when analytics consent is granted
__stripe_* (cookies, on the checkout flow only)Stripe fraud prevention during paymentConditional — set only when you start a checkout

You can change your choice at any time via the Cookies link in the footer. The link doubles as our California "Do Not Sell or Share My Personal Information" entry point.

If your browser sends a Do Not Track signal, we treat it as an opt-out and skip the cookie banner entirely.

Your rights

Under GDPR (EU/UK), LGPD (Brazil), CCPA/CPRA (California), and similar laws elsewhere, you have rights to:

To exercise any of these, email [email protected]. We respond within 30 days.

Children

Rastros is not directed at children. We do not knowingly collect data from anyone under 16 (EU) or under 13 (most other jurisdictions). If you believe a child has provided us with personal data, contact us and we will delete it.

International transfers

When data leaves the EU or Brazil (for example, to Stripe in the US), we rely on the European Commission's Standard Contractual Clauses for transfers from the EU, and on equivalent contractual safeguards under LGPD Art. 33 for transfers from Brazil. Sub-processors are contractually obliged to provide equivalent protection.

Changes to this policy

When we make material changes — for example, adding a new sub-processor or changing a retention period — we update the Effective date at the top of this page and re-prompt your cookie consent. Minor edits (typos, wording) do not trigger a re-prompt.

Contact

For any privacy or data-protection question:

GBS Tecnologia LTDA [email protected]