Caravanios Camping App
Privacy Notice
What personal data Caravanios processes when you use the iOS or Android app, plan routes and
trips, share a camping group, keep a trip budget, buy Pro or visit app.caravanios.com.
Last updated: 6 September 2026
1. Controller
The controller under the EU General Data Protection Regulation (GDPR) and the Austrian Data
Protection Act (DSG) is:
Philip Ullmann
Bürgerstrasse 22
4300 St. Valentin
Austria
Email for privacy requests:
kontakt@caravanios.com
Website: https://app.caravanios.com
No data protection officer is appointed, because the statutory conditions for that are not
met. Send requests to the address above or use the
privacy-request form.
2. The short version
This notice covers the Caravanios apps for iOS and Android, the app API, invitation and trip
links, the support and privacy forms, and the public pages at app.caravanios.com.
- We do not sell personal data and we do not sell personal advertising profiles.
- The apps contain no third-party crash, analytics or advertising SDK, no advertising identifier and no cross-device tracking. The single exception for measuring installation source: the Android app reads the Google Play Install Referrer once per installation — section 3 says what that involves.
- Location and route data are processed only when you enter, select or use them for a feature. There is no permanent background positioning and no live tracking of your movements.
- The public website loads Google Tag Manager and Google Analytics 4 only after your consent. The apps do not send app usage to Google Analytics 4.
- Firebase is used for sign-in and for delivering notifications.
- A public trip link shows only the published snapshot — no private notes, no budget data, no camping-group member email addresses.
- The app is not meant for special-category data, such as health information or details about children that trip planning does not need.
- If we ever introduce an AI feature that sends trip content, images or support text to an AI provider, we will say so separately before that processing starts.
3. What we process, why and on which legal basis
Depending on the features you use, the following data arises. Each block names the data, the
purpose and the legal basis.
Do you have to provide this data? An account needs an email address and
a password, or a sign-in through Apple, Google or Firebase — without those there is no
account. Everything else is voluntary: the route finder and a route draft work without an
account at all, and without location permission, images, a camping group, a trip budget
or push notifications you can keep using the app — only that particular feature is then
unavailable.
Account and sign-in
Data: name, email address, sign-in provider and provider identifier,
password hash, verification and reset codes, deletion codes, authentication tokens,
sessions, app version, platform, language and technical request headers. Sign in with
Apple, Google sign-in and Firebase Auth add the identity data needed for sign-in; we
do not receive payment details or full store-account information.
Purpose: registration, sign-in, account protection, email
verification, password reset, account deletion, abuse prevention.
Legal basis: Article 6(1)(b) GDPR; for security logs and rate limits
Article 6(1)(f) GDPR.
Camping groups and members
Data: group name, purpose, currency, description, group image, home
base as an approximate starting point with text and coordinates, members and roles,
real travellers listed in the group, with or without their own account,
invitations and invitation tokens.
Purpose: shared planning, roles and access, invitations,
synchronisation between authorised members.
Legal basis: Article 6(1)(b) GDPR; for abuse prevention
Article 6(1)(f) GDPR.
Vehicles, inventory and checklists
Data: vehicle details and images, equipment items, categories,
quantities, status, notes, checklist items, recurring tasks, departure checks and
timestamps.
Purpose: managing the camping vehicle, equipment, packing lists and
departure checks.
Legal basis: Article 6(1)(b) GDPR.
Trips, stops and on-the-road use
Data: trip name, dates, status, image, route and distance, stops with
order, coordinates, assigned campsite, costs and notes, trip members and invitations,
on-the-road notes, moments with image and free text, completed trip checks and
locally cached data for use with limited connectivity.
Purpose: planning a trip, working on it together, using it on the
road, the recap and reusing it later.
Legal basis: Article 6(1)(b) GDPR.
Trip budget, expenses and Budget FX
Data: budget people and trip participation, expense title, category,
amount, currency, payer, split, optional stop assignment, balances, manually recorded
settlements, notes, status, versions, correction and reversal details, timestamps.
For multi-currency trips also the reference conversion, rate date, source, rounding
values and conversion snapshots.
Purpose: the shared trip budget within the authorised trip group,
with traceable corrections and settlements. The payment itself happens outside the
app; Caravanios only records it.
Legal basis: Article 6(1)(b) GDPR; for evidence and disputes
Article 6(1)(f) GDPR.
Route finder and route drafts
Data: start, destination, waypoints, search corridor, route
geometry, distance, result count, selected campsites, draft status, route signature,
expiry and the conversion into a trip.
Purpose: calculating the route, finding campsites along it, ordering
results, turning a draft into a trip.
Legal basis: Article 6(1)(b) GDPR; for caching, stability and abuse
prevention Article 6(1)(f) GDPR.
Route search without an account
Data: an anonymous device identifier that reaches the database only
as a hash, plus route points, search corridor, result limit, language and technical
metadata.
Purpose: a fair limit for searches without an account. If you create
an account later, your guest searches can be assigned to it — pseudonymous data then
becomes personal data.
Legal basis: Article 6(1)(f) GDPR, and Article 6(1)(b) GDPR once an account exists.
Campsite feedback
Data: user and campsite identifier, affected field, problem type,
current and proposed value, proposed coordinates, comment, source screen, app
version, route context, review status.
Purpose: checking and improving campsite data quality.
Legal basis: Article 6(1)(f) GDPR.
Invitations and public trip links
Data: invitation tokens, roles and status. A public link stores a
snapshot of trip title, route, dates, distance, stop count and stops with title,
type, date and coordinates. Access runs through a secret link; the tokens are stored
hashed and additionally encrypted.
Purpose: bringing someone into a group or trip, and showing a trip.
Legal basis: Article 6(1)(b) GDPR; for delivery and abuse prevention
Article 6(1)(f) GDPR.
Push notifications
Data: push token, platform, device type, app version, notification
preferences, quiet hours, category, destination screen, delivery state, open time and
technical provider identifiers.
Purpose: reminders, notices for the group, budget activity in shared
trips, trip preparation, delivery control. Budget notifications avoid exact amounts,
balances and splits.
Legal basis: Article 6(1)(b) GDPR for feature-related notices,
Article 6(1)(a) GDPR for optional categories. The device permission is granted and
withdrawn separately in iOS or Android.
Pro and stores
Data: product identifier, plan, store platform, transaction and
subscription references, status, periods, recheck times, the App Store app-account
token and the obfuscated Google Play account identifier. Full payment details stay
with Apple or Google, not with us.
Purpose: verifying a purchase, establishing and restoring the
entitlement, managing limits, helping with store problems.
Legal basis: Article 6(1)(b) GDPR, Article 6(1)(c) GDPR for
statutory records, Article 6(1)(f) GDPR for abuse prevention.
Product events and technical logs
Data: event name, event identifier, time, user identifier, source,
platform, app version, entity type and identifier, and restricted properties such as
screen, trigger, result count or Pro context. The permitted properties are limited to
a fixed list that contains no coordinates, free text, names or email addresses. Added
to this are IP address, user agent, requested URI, error details, delivery records
and rate-limit data.
Purpose: seeing whether core flows work, where errors occur and
whether limits apply correctly; operation and security.
Legal basis: Article 6(1)(f) GDPR.
Installation source on Android
Data: the campaign values (source, medium, campaign name) that the
Android app reads once per installation from the Google Play Install
Referrer.
Purpose: understanding how an installation came about — for example
through a link from our blog. If the link carried a route, the same value opens that
route after installation.
Legal basis: Article 6(1)(f) GDPR. No advertising identifier, no
cross-device identifier and no advertising profile is created; this processing does
not exist on iOS.
4. Location, routes and maps
Your location is processed only at the moment you ask for it: as a start, destination,
waypoint, home base or stop. There is no location history and no background service. Without
location permission you can use the same features by typing the place instead.
On iOS, Apple Maps draws the map and answers the place search. On Android, address search
uses the operating system's geocoding service, which on many devices comes from Google. If
you start navigation from Caravanios, it runs in the map or navigation app you open and under
that provider's privacy terms.
On Android the app draws the map itself and loads map tiles directly from the tile servers of
the OpenStreetMap project. Those requests do not go through our backend;
they leave from your device. The operator of those servers therefore receives your IP address
and the requested map area and zoom level — but not your account identifier and no trip,
route or stop data.
Route geometry is calculated in our backend with limited coordinate precision and cached
temporarily for stability and abuse prevention. If a route cannot be answered from the cache,
the necessary coordinates go to an external routing provider: primarily to an
OSRM-compatible routing service based on OpenStreetMap data, and only if that is unavailable
to the Directions API of Mapbox (Mapbox, Inc., USA). In normal operation
Mapbox receives nothing.
Only the coordinates and technical request data are sent — no account identifier, no
name, no trip data. Because the request comes from our backend and not from your app, the
provider does not see your IP address but our server's.
5. What stays on your device
- iOS stores access tokens in the Keychain, Android stores access tokens in encrypted SharedPreferences.
- Both platforms keep an offline cache for groups, trips, route plans and pending changes including images.
- Added to this are push tokens, pending invitation tokens, the anonymous guest device identifier, a guest route draft and functional settings.
- The Android backup rules exclude the sensitive files
secure_prefs.xml, push_token_store.xml and invite_store.xml from cloud backup and device transfer; on iOS the protected offline store is excluded from iCloud backup.
- Images, image capture and file selection also pass through the operating system, the system camera or apps you choose.
You can remove local data by signing out, through app settings or by deleting the app.
Server-side data does not disappear with it — account deletion and the privacy request exist
for that.
6. App permissions
- Internet and network state: required for the API, sign-in, synchronisation, routes, campsite data, notifications and the Pro check.
- Location: optional, for using your current position as a start, destination or stop.
- Images: for group, vehicle, trip and stop images Caravanios requests no photo, camera or file permission. You pick an image in your device's system picker, in the system camera or in an app you choose; the app receives only the image you selected.
- Notifications: optional, for reminders and group notices; on Android through POST_NOTIFICATIONS.
- Billing (Android only): technically required so that Google Play Billing can check a Pro entitlement.
You can withdraw permissions in your device settings; individual features are then limited.
7. Website, cookies and consent
Purely informational pages need no session. Forms such as the deletion request set
essential cookies and tokens for CSRF protection, session state and abuse prevention.
Google Tag Manager and Google Analytics 4 load only if you expressly consent. Your choice is
kept in your browser's local storage under caravanios.consent.v1. Without
consent, analytics_storage, ad_storage, ad_user_data and ad_personalization stay denied. We
do not use remarketing or personalised advertising; if that ever changes we will say so
separately beforehand and obtain the necessary consent.
After consent, Google Analytics cookies such as _ga or a container-specific
_ga_* cookie may be set. If you decline or withdraw, the website tries to remove
known analytics cookies where your browser permits it. Global Privacy Control is honoured
as long as no choice of your own is stored. Change your choice under
Cookie and Analytics Settings.
Legal basis: Article 6(1)(f) GDPR for essential operation; for non-essential
storage of and access to your device Article 6(1)(a) GDPR together with section 165 TKG 2021.
8. Support, deletion requests and former Android feedback
When you contact support we process what you send: name, email address, account email,
platform, app version, device details, description, screenshots and message text. Please do
not send passwords or full payment details.
The deletion form processes name, account email, optional contact email, platform, request
scope, message and the two confirmations shown on the form. Analytics is switched off on that
page. The request is emailed to the privacy or support address and handled as an internal
case; the free message text is not copied into event data. Once the case is complete we
remove the identity fields and the free text; non-personal status information and timestamps
remain as evidence.
The Android feedback forms from the former test phase process name, Caravanios email, Google
Play email, test commitment, email consent, status, language, feedback, tested flows, unclear
points, errors, suggestions, rating and the optional permission to follow up.
Legal basis: Article 6(1)(b) GDPR for handling your request,
Article 6(1)(a) GDPR for beta emails and the optional follow-up, Article 6(1)(c) GDPR for
data protection duties, and Article 6(1)(f) GDPR for evidence and abuse prevention.
9. Who receives your data
We pass data on only where a feature needs it, a legal duty applies, you have consented or a
legitimate interest prevails.
- hosting, server, database, storage, backup and security providers for operation and maintenance;
- email providers for confirmations, password resets, support and operational messages;
- Apple for Sign in with Apple, the App Store, StoreKit, server notifications, APNs and Apple Maps;
- Google and Firebase for Firebase Auth, Firebase Cloud Messaging, Google Sign-In, Google Play, Android services, Google Tag Manager, Google Analytics 4 and Google Search Console;
- an OSRM-compatible routing service based on OpenStreetMap data, and Mapbox, Inc. (USA) only as fallback;
- the tile servers of the OpenStreetMap project when you use the map in the Android app; those requests leave directly from your device;
- the rating dialogue of the respective store if you want to rate the app: iOS calls the StoreKit system dialogue, Android the Google Play in-app review. We do not learn whether or how you rated;
- operating-system, map and navigation providers when you use location, maps, address search or external navigation;
- other authorised group and trip members, and the recipients of a public trip link you create;
- advisers, legal representatives, authorities or courts where required to pursue or defend claims or to meet legal duties.
Where a provider acts as a processor we conclude the agreements required by Article 28 GDPR.
Store, operating-system, map and identity providers can also be independent controllers for
their own processing.
10. Transfers outside the EEA
Some providers — in particular Apple, Google and Firebase, Mapbox and the app stores —
process data outside the European Economic Area, mainly in the United States.
Where required, such transfers rely on an adequacy decision, in particular for providers
certified under the EU-US Data Privacy Framework, or on the European Commission's standard
contractual clauses with supplementary measures. For Mapbox as fallback provider its
data-processing addendum applies; only coordinates and technical request data are sent.
Hosting, database, backup and mail delivery are located in the EEA.
11. How long we keep data
We keep personal data for as long as it is needed for the purpose, as long as you keep it in
the app, or as long as legal duties and legitimate evidence interests require. These criteria
apply:
- account, group, vehicle, inventory, checklist, trip and budget data remain while your account and the related content exist. There is no fixed period for trip content — it stays until you delete it or the account goes. Dormant accounts are not deleted automatically.
- Account deletion is final. It removes your account and the trip, group, budget and image data attached to it; there is no recycle bin and no restore.
- Three things deliberately survive account deletion: the record of email consent without an account reference (Article 7(1) and Article 17(3)(e) GDPR), a suppression list for mailboxes that rejected messages, and campsite statistics that never had any personal reference.
- budget people, expenses, splits, balances and settlements in shared trips can still be needed by other authorised members. In those cases we remove or separate the account reference instead of deleting the shared budget history.
- verification, password-reset and deletion codes are short-lived and expire after their function.
- route drafts, guest-search counters, route caches, unused push devices, raw event and delivery records, error logs and rate-limit data are cleaned up under the applicable system or provider configuration.
- aggregated statistics without any personal reference can be kept longer.
- public trip snapshots remain reachable until you disable the link, the trip is deleted or an applicable deletion request is carried out. A public trip link also expires on its own: 90 days after it was created or after the snapshot was last refreshed.
- Pro and purchase records remain while needed for entitlements, support, abuse prevention or tax and legal evidence.
- support and privacy requests remain while handling, evidence and follow-up questions require it.
- backups are overwritten through the usual backup cycles; removing a single record from every existing backup at once is usually not technically possible.
12. Security
We protect personal data with encrypted transport, access and role checks, password hashing,
hashing of guest device identifiers, hashing and encryption of public trip tokens, rate
limits, CSRF protection and security headers.
No system is absolutely secure. Use strong passwords, keep your devices up to date and report
suspected misuse to kontakt@caravanios.com.
13. Shared camping groups and public links
Caravanios is built for planning together. Members of a camping group or trip see the data
belonging to the shared feature: group information, vehicles, inventory, checklists, trips,
stops, notes, budget data with expenses, payers, splits, balances and settlements, and the
related notifications.
Treat invitation links as confidential. If a link reaches the wrong person, unwanted access
can follow — delete or renew the invitation in that case.
A public trip link is deliberately reachable by anyone holding it. Budget data, settlements,
private notes, camping-group member email addresses, checklists and inventory are not part of
that snapshot. Disable the link when the trip should no longer be public.
14. Automated decisions
Caravanios makes no automated decisions within the meaning of Article 22 GDPR that produce
legal effects concerning you or similarly significantly affect you. Rankings, route-fit
scores, readiness prompts, suggestions and Pro or guest limits are assistance features or
technical access controls; they do not decide rights outside the app.
15. Children and family use
Caravanios is aimed at adults and travelling households. A minor should not create an account
without the approval of their legal representative. For consent to information society
services, Austria sets the age at the completed 14th year (section 4(4) DSG).
Where families record details about children in trips, notes, images or checklists, only
necessary and non-sensitive details should be entered.
16. Your rights
Under the GDPR and Austrian data protection law you have, in particular, these rights:
- access to the personal data processed about you (Article 15 GDPR);
- correction of inaccurate data (Article 16 GDPR);
- erasure (Article 17 GDPR);
- restriction of processing (Article 18 GDPR);
- data portability where the conditions are met (Article 20 GDPR);
- objection to processing based on legitimate interests (Article 21 GDPR);
- withdrawal of consent with effect for the future (Article 7(3) GDPR);
- complaint to a supervisory authority (Article 77 GDPR).
For Austria, the Data Protection Authority is the competent national supervisory authority:
Barichgasse 40–42, 1030 Vienna,
dsb.gv.at. You may also
contact any other authority competent for your case.
Before we disclose or erase data we have to verify your identity appropriately. In a shared
group or trip, erasure can affect the rights of other members; we then check what has to be
erased, anonymised, separated or kept.
17. Settings and withdrawal
- Website analytics: Cookie and Analytics Settings.
- Push notifications: in the app and in your device settings.
- Location and notification permissions: in iOS or Android settings.
- Public trip links: disable them in the trip.
- Account, group, vehicle, inventory, checklist, trip and budget data: edit or delete them in the app.
- Account deletion: in the app under Delete account, or through Data Deletion and Privacy Requests.
18. Where the data comes from
Most of it comes directly from you. Data can also come from: Apple, Google or Firebase when
you sign in; the App Store or Google Play when a Pro entitlement is checked; APNs or Firebase
Cloud Messaging for notification tokens and delivery; other group or trip members who invite
you or edit shared content; your device or browser
(IP address, user agent, platform, app version, language, device model, timestamps); and
public or shared campsite and location data.
19. United Kingdom and Switzerland
If you use Caravanios in the United Kingdom, the UK GDPR and the Data Protection Act 2018
apply to you as well; the supervisory authority is the Information Commissioner's Office
(ICO, ico.org.uk). In
Switzerland the revised Federal Act on Data Protection (revDSG) applies as well; the
supervisory authority is the Federal Data Protection and Information Commissioner
(FDPIC, edoeb.admin.ch).
In both cases you can send the rights in section 16 to the same address.
We update this notice when app or website functions, providers, legal bases or technical
processing change materially. The current English version is available at
/en/privacy.
For access, correction, erasure, restriction, portability, objection or withdrawal of
consent, email kontakt@caravanios.com or use the
privacy-request form.