This Privacy Policy explains how GoExploring handles personal data when you use the GoExploring website, mobile application, and related services (together, GoExploring or the Service).
The data controller is Javier Iglesias Garcia, operating GoExploring personally in Spain. You can contact us at [email protected].
1. Who this policy applies to
This policy applies to GoExploring users and website visitors worldwide. You must be at least 16 years old to use the Service. We do not knowingly offer the Service to or collect account data from anyone under 16. If you believe a person under 16 has provided personal data, contact us so we can investigate and delete it where appropriate.
2. Data we handle
We handle only the categories below when you use the relevant feature.
Account and authentication data
When you sign in with Apple or Google, we receive a provider account identifier, name, email address, and, where made available by Google, profile image URL. Apple may provide a relay email address instead of your personal email. We also create internal user and session identifiers and store sign-in and account update times.
Authentication tokens supplied during sign-in are used to verify your identity. GoExploring stores hashed session refresh tokens. Where needed to support provider-token revocation during account deletion, an Apple refresh token is stored in encrypted form. The app stores the active GoExploring session and basic profile details on your device.
Exploration and progress data
We store the expeditions you create, including titles, selected missions, optional planned dates, status, and related timestamps. We also store completed mission identifiers, completion times, and whether a completion was recorded automatically or manually.
Location data
If you grant location permission, the app uses precise device location to show your position, request the relevant map area, check proximity to missions, support optional background mission tracking, and record eligible completions. Proximity checks and geofence monitoring are performed on your device. GoExploring does not send or store a history of your raw precise location coordinates on its server.
Map-area requests disclose the geographic bounds being viewed, which may be based on your current position. As with any internet request, the server and network providers also receive technical connection information such as your IP address.
The app stores your last selected map viewport, nearby mission data, revealed missions, and tracking preferences locally on your device so these features can work between sessions.
Content reports and communications
If you report incorrect mission content, we store your account identifier, the mission, selected reasons, any optional details you write, the report status, and timestamps. If you contact us by email, we receive your email address and the content of your message.
Waitlist data
If you join the website waitlist, we store your email address and the time you joined.
Notifications and device settings
If you enable notifications, the app may deliver local notifications about mission completions. These notifications are scheduled on your device. We do not currently use a GoExploring server to send remote push notifications or store an Apple push-notification token.
The app also stores preferences such as selected language, map filters, and whether automatic tracking is enabled on your device.
Technical data
When you connect to the Service, our server, reverse proxy, and infrastructure providers may process standard request information such as IP address, request time, requested path, response status, and device or browser headers for delivery, reliability, and security.
On the public website, OneDollarStats processes page paths, referring URLs, UTM campaign parameters, visit times and durations, country, device type, operating system, and browser so we can understand aggregate website use. It derives a short-lived session identifier from the IP address, user-agent header, and the start of the current hour. We do not send your GoExploring account identity, email address, or precise location to OneDollarStats, and this integration does not use advertising cookies or track you across third-party websites.
3. Why we use data and our legal bases
Where the EU General Data Protection Regulation (GDPR) applies, we rely on these legal bases:
- Performing our contract: to create and authenticate your account, provide maps and missions, synchronize expeditions and progress, and handle account deletion.
- Your consent: to access device location, monitor eligible missions in the background, send local notifications, and add your email to the waitlist. You can withdraw device permissions in system settings and withdraw waitlist consent by contacting us.
- Legitimate interests: to secure, maintain, troubleshoot, and improve the Service; prevent misuse; respond to support requests; and review content reports. We balance these interests against your rights and expectations.
- Legal obligations: to comply with applicable law, enforce valid legal requests, and establish or defend legal claims where necessary.
We do not use your personal data for automated decision-making that produces legal or similarly significant effects.
4. Services that receive data
We use service providers only where needed to operate a feature:
- Apple or Google processes authentication data when you choose its sign-in service. Its own privacy terms also apply.
- Cloudflare proxies website and API traffic and processes technical connection and security data.
- OneDollarStats provides aggregate analytics for the public website and processes the technical and usage data described above. Its service infrastructure is hosted in Finland.
- Our server and PostgreSQL database infrastructure host the Service and its stored data.
- Viator receives mission-related search terms when GoExploring requests relevant third-party activities. GoExploring does not include your account identity in that search request. If you open or book an offer, Viator and the relevant provider handle that interaction under their own policies.
- Apple Maps processes map and place-search requests made through Apple's mapping services. If you choose an external Google Maps link, Google handles the request after you open it.
We may also disclose data if required by law, to protect legal rights or safety, or as part of a future business reorganization. We do not sell personal data. We do not share personal data for cross-context behavioural advertising.
5. International transfers
Some providers may process data outside Spain or the European Economic Area. Where GDPR requires it, transfers must use a valid legal mechanism, such as an adequacy decision or approved contractual safeguards. Provider privacy notices explain their locations and transfer arrangements.
6. Retention
We keep account, expedition, completion, and content-report data while your account remains active. Deleting your account through the app deletes your GoExploring account, identities, sessions, expeditions, completion records, and content reports from the active database. The app also clears its locally stored account data.
Expired or revoked session records may remain until routine database cleanup. Temporary sign-up details are removed when account creation completes or is cancelled, and may otherwise remain until operational cleanup. Waitlist email addresses remain until the waitlist purpose ends or you ask us to remove yours.
Support emails, limited security or server logs, and aggregate website analytics are retained only for as long as reasonably needed for the relevant communication, security, troubleshooting, service-improvement, or legal purpose. OneDollarStats derives website sessions within one-hour windows rather than assigning a persistent visitor identity. Residual copies may remain temporarily in backups until those backups rotate. We may retain limited information longer where required by law or reasonably needed to establish or defend legal claims.
7. Security
We use measures designed to protect personal data, including encrypted network connections, restricted database access, hashed session refresh tokens, and encryption for stored provider refresh tokens where used. No system can guarantee absolute security.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to our handling of your personal data, receive a portable copy, and withdraw consent. Withdrawing consent does not make earlier processing unlawful.
You can:
- delete your account and associated active GoExploring data from the app;
- change location and notification permissions in device settings;
- stop background mission tracking in the app; and
- ask to access, correct, export, or delete other data by emailing us.
We may need to verify your identity before completing a request. If GDPR applies and you are dissatisfied with our response, you may complain to the Spanish Data Protection Agency (AEPD) or your local data-protection authority.
9. Third-party links
The Service contains links to third-party maps, activity providers, sources, and other websites. Their privacy practices are controlled by them, not by this policy. Review their policies before providing information or completing a transaction.
10. Changes to this policy
We may update this policy when the Service or legal requirements change. We will publish the revised policy here and change the date below. Where required, we will provide additional notice before a material change takes effect.
11. Contact
For privacy questions or requests, email [email protected].
Data controller: Javier Iglesias Garcia, Spain
Last updated: 3 September 2026
