Privacy Policy
1.Overview
Crossroutes is an app for Android and iOS, also usable in the browser at web.crossroutes.de, that helps cyclists and runners organize and join group rides and runs organized through the app. This policy explains what personal data the app and its backend collect, why, who else ever sees it, and what choices you have. It's written to be read, not skimmed past - if anything is unclear, the contact details in section 14 reach a real person, not a support queue.
Crossroutes is operated by Lennard Zirks as a sole proprietorship (trading as "Software-Entwicklung Lennard Zirks"), one person. There is no advertising, no analytics SDK, and no sale of data to anyone, ever.
2.Who is responsible for your data
The controller responsible for processing under this policy is:
Lennard Zirks
Trading as: Software-Entwicklung Lennard Zirks
Hirtenweg 63A
26180 Rastede
Germany
Email: [email protected]
Crossroutes operates at a small, one-person scale. It does not meet any of the GDPR Article 37 thresholds that would require appointing a Data Protection Officer (no large-scale processing of special-category data, no large-scale systematic monitoring, no public-authority processing) - so requests and questions go directly to the address above, not to an intermediary.
3.Data we collect, and why
The table below lists every category of personal data the app or its backend handles.
| Category | What it includes | Why we collect it |
|---|---|---|
| Account data | Email address, username, display name, password (stored as a salted hash, never in plain text) or a Google sign-in token if you choose that option | Creating and securing your account, letting other riders find and recognize you |
| Profile content | Avatar photo, short bio (optional, up to 300 characters) | Shown to other riders/friends within the app; entirely your choice what to add |
| App preferences & settings | Notification delivery preferences, suggestion filters (search radius, max pace, max route distance, weekday availability, friends-only/all/none), unit system, theme, language, calendar app choice, and similar in-app toggles | Making the app behave the way you've configured it - none of this is shared with other users or any third party |
| Group ride/run & route data | Group rides and runs you create or join, their activity type, schedule, route waypoints, target distance/speed or pace, rest stops, cover images, GPX files you import | Making a group ride or run's route, schedule, and details usable and shareable - this is the app's core function |
| Social graph | Friend connections, friend requests, group ride/run invitations you send or receive | The friends and invite features you choose to use |
| Reports | The category and optional free-text description you provide when reporting a group ride/run, club, or user profile for review, plus both accounts' usernames | Trust & safety - lets you flag content or behavior that may violate our acceptable-use rules for the operator to review; see section 8 for retention |
| Participation history | Which group rides/runs you've joined or created, and when | Your own group rides/runs created/joined stats, and "ridden/run together" counts on friends' profiles |
| Referral program | Your personal referral code, how many people have signed up through it, whether a reward has already been granted | Powers the friend-referral reward (free Member time) - reachable both from the in-app "invite friends" share sheet and from the "Get the app" button on a shared group ride or run's public page; see also the Play Store "Install Referrer" processing in section 5 |
| Connected Strava account (optional) | OAuth access and refresh tokens, your Strava athlete id | Only if you explicitly connect Strava in Settings - to import one of your saved Strava routes, or export a completed ride to Strava; see section 5 |
| Payment & subscription data | Whether you have an active Member subscription, its trial/renewal status, and a Google-issued purchase token - never your card number or full payment details, which Google Play Billing collects and processes directly; Android only, since that's currently the only place Member is available | Providing Member features to the right account, and knowing when access should start or end - see the Terms of Use for the subscription itself |
| Device & notification data | A push-notification registration token, the platform ("Android", "iOS" or "Web"); in the web version, the "token" is your browser's push subscription instead (see section 12) | Delivering the notifications you've enabled - see section 5 for how this reaches Google's Firebase Cloud Messaging |
| Technical / server-log data | IP address and request metadata, recorded transiently by the server for every request | Rate-limiting abusive traffic and diagnosing faults - see section 7 and section 8 for retention |
One more feature never touches our server at all: the Play Store referral link you share with friends carries only your referral code, no other personal data.
What we deliberately do not collect: advertising identifiers, behavioural analytics, cross-app tracking of any kind, or your precise device location on our servers, with one narrow exception described in section 7 - setting a club's home location via a one-time GPS shortcut. Location is the one we get asked about most, so it has its own section.
4.Legal bases for processing
- Performance of a contract (Art. 6(1)(b) GDPR): account data, group ride/run and route data, participation history, and - if you subscribe - Member billing/subscription status - the app (or the subscription itself) can't function without these. This includes rendering the background map (our own map-tile service, see section 5) and road-snapping a route while you draw or edit it (BRouter) - both are how the core route/map functionality is delivered, not a separate purpose.
- Consent (Art. 6(1)(a) GDPR): signing in with Google is an action you actively choose; push notifications additionally require your OS's own system permission prompt, and every notification category can be switched off individually in Settings. The same applies to the Strava connection (only after you sign in to Strava yourself via their own OAuth page, disconnectable at any time in Settings). Weather Windows notifications (Settings) work the same way, for the same reason: unlike every other notification category, turning this on for the first time shows its own explanation first - your device's approximate location gets sent to a third party (MET Norway) roughly once an hour while it's on - and only takes effect once you confirm, rather than applying the moment you tap the switch.
- Legitimate interest (Art. 6(1)(f) GDPR): rate-limiting and short-lived request logging (including limiting how many new map tiles a connection or account can have fetched or generated, using a daily-changing pseudonym of the IP address and of the account that is held in memory for at most one day), to keep the service available and secure for everyone; checking that a sign-up email address is a real, permanent inbox rather than a disposable/throwaway one, to keep the service usable for everyone; checking for a newer app version on launch (Google Play); recognizing a referral code right after install (Google Play "Install Referrer"); reviewing reports filed about a group ride/run, club, or user - including data about the person or content being reported, who didn't file the report themselves and isn't separately notified, since doing so would undermine our ability to review reports honestly; and, if you've turned them on in Settings, showing a route's elevation profile and fetching a weather forecast for a route you're viewing or have joined (BRouter, MET Norway - route data only, never your own device location; see the Consent paragraph above for the separate Weather Windows feature, which also uses MET Norway but for a different purpose and with your own location instead). Those last two are enabled by default, so the Settings toggle is a preference control, not a GDPR consent mechanism - we rely on legitimate interest for them, not consent. Balancing-test records for these are available on request.
5.Who else sees your data
Crossroutes' backend runs on infrastructure located in Germany that the developer personally owns and operates - it is not hosted by a cloud provider. All requests to reach it (and to reach this website) pass through Cloudflare first, a reverse-proxy/content-delivery layer sitting in front of that infrastructure - this changes how requests get to our server, not where your data is ultimately stored or processed. The one exception is the map: map data is delivered and stored by our own map-tile service, which runs on Cloudflare's platform itself (see the table below). The following external services are used for specific, narrow purposes:
| Processor | Purpose | Data it receives |
|---|---|---|
| Cloudflare, Inc. (USA) | Reverse proxy and content-delivery network in front of both this website and Crossroutes' backend - handles every request's connection, DDoS protection, and TLS/HTTPS termination | Your device's IP address, and technically the content of every request to our backend or this website (including anything you send the app, the same way any website or API behind a CDN works) - Cloudflare relays this to reach our server and doesn't use it for its own purposes under our agreement with them |
| Cloudflare, Inc. (USA) - R2 object storage | Storing uploaded ride cover photos, GPX route files, and club tag icons, in an EU-region bucket | The uploaded file itself - no other personal data. Same Cloudflare agreement/DPA as the reverse-proxy row above; a distinct product, not a separate company |
| Cloudflare, Inc. (USA) - Workers, Containers and R2 (map tiles) | Delivering the background map: our own map-tile service delivers map data from OpenStreetMap (vector tiles plus the map's fonts and symbols; your device draws the map itself) and keeps each tile in an EU-region storage bucket once it has been requested. Older app versions (Android up to 1.7.4) still receive finished map images, which the service renders from the same data; this ends on 31 December 2026 at the latest | Your device's IP address and the map area you're viewing, which any map-tile request inherently reveals - processed only to deliver the tile and not logged by us - plus a map access token that identifies your account by a pseudonym (not your name or ID). To prevent abuse, a daily-changing pseudonym of the IP address and the account pseudonym are counted in memory in the EU for at most one day. The stored tiles and images contain no personal data. The map data itself comes from OpenFreeMap, which is only ever contacted by our service, never by your device, and receives no data about you. Same Cloudflare agreement/DPA as the rows above |
| Geoapify (Mering, Germany) - phase-out | Background map in older app versions only (Android up to 1.7.1) until the app is updated; this service ends by 31 October 2026 at the latest | Your device's IP address and the map area you're viewing, which any map-tile request inherently reveals. Geoapify is a German company with EU data centers, so no international transfer takes place; see Geoapify's Data Processing Agreement |
| Google Ireland Ltd. (Firebase Cloud Messaging) | Delivering push notifications to your device | Your device's push registration token, plus opaque IDs and a group ride or run's own public title (e.g. "Saturday Hunte Loop") - never your email, real name, bio, or photo |
| Google Ireland Ltd. (Sign in with Google) | Optional sign-in method | Google is the one receiving your sign-in action, not us - the app never reads your Google profile directly; it only forwards the sign-in confirmation token Google issues to our own server for verification |
| Google (sent via a Gmail account) | Sending the handful of account and moderation emails this app ever sends: account verification, password reset, letting you know when a report you filed has been reviewed, notifying you (with the reason) if your account is ever restricted for violating our acceptable-use rules, and alerting you if repeated failed sign-in attempts are seen on your account | Your email address and the content of that specific email - no newsletter, no marketing |
| Google Ireland Ltd. / Google LLC (Google Play Billing) | Processing Member subscription payments (Android only) | Your card and payment details go directly to Google - we only receive your subscription/purchase status and a Google-issued purchase token, never your card number or billing address |
| BRouter (brouter.de, a public community routing service) | Snapping a hand-drawn route to real roads when creating/editing a group ride or run; separately, if enabled in Settings, showing a route's elevation profile and accounting for hills in weather timing for any group ride or run you're viewing | Only the route waypoints involved - either the ones you're drawing/editing, or, for the elevation feature, the already-public route of whichever group ride or run you're currently viewing, sent directly from your device the same way the MET Norway route-forecast row below works - never your device's own location |
| MET Norway (Norwegian Meteorological Institute, api.met.no) - route forecast | Showing a weather forecast for a group ride or run you've joined, if you've enabled this in Settings | Called directly from your device, not through our server (in the web version, through our server instead - see section 12). Only a handful of approximate coordinates sampled along that ride's already-public route are sent - not personal data about you specifically. The only personal element in this case is that MET Norway's servers see your device's IP address, an unavoidable part of any direct connection to any server (the same as for the map-tile row above) - never used by us or shared with anyone else |
| MET Norway (Norwegian Meteorological Institute, api.met.no) - Weather Windows | Checking for upcoming good-weather windows nearby, unrelated to any specific ride, if you've enabled "Weather Windows" notifications in Settings | Called directly from your device, not through our server (in the web version, through our server instead - see section 12). This is the only purpose for which your device's own real (approximate, rounded to roughly 10m) location is sent anywhere outside the app - checked roughly once an hour while this setting is on. MET Norway's servers also see your device's IP address, an unavoidable part of any direct connection to any server - never used by us or shared with anyone else |
| Strava, Inc. (USA) | Only if you explicitly connect your Strava account in Settings: importing one of your saved routes, or exporting a ride you've completed as a new Strava activity | On connecting: you approve access on Strava's own sign-in page in your browser (we never see your Strava password) - Strava then redirects back through our own server with a one-time authorization code, which we exchange for the access/refresh tokens listed above. On export: the name, date, distance, duration, and GPX route of that ride. We deliberately request only the narrowest possible permission ("read" and "activity:write") - never your full Strava activity history or profile |
| Google Play (Play Store "Install Referrer") | Recognizing a referral code after install, when the app wasn't yet installed at the moment a referral link was tapped | Only the one short string we ourselves appended to the Play Store link (your referral code) - no other Install Referrer fields Google also makes available (e.g. timestamps) are read; Android only, read once right after install |
| Google Play (In-app update check) | Checking on every app launch whether a newer version of the app is published, so we can prompt you to update | Your app's package name and installed version, read via the Play Store app already on your device - no other data |
Komoot or Strava links you may add to a group ride or run are just that - links. Tapping one opens your browser or the Komoot/Strava app; we never send it any data. The same applies to links you add to your own profile or a club's page (to Instagram, Strava, Komoot, or any other site) - you choose what to add, we don't verify it belongs to you, and opening one never sends that site anything of ours. The app shows every one of these links in full before you tap it, and warns you before opening one that isn't from a platform it recognizes.
A group ride or run's public share link (crossroutes.de/p/…, created via the app's "Share" action, and its calendar-invite/.ics download) is reachable by anyone who has the URL, without an account or the app - it shows that group ride or run's name, description, schedule, distance/pace, activity type, cover image, and the creator's display name, plus how many people have joined (a count only, never other participants' names or photos). This applies the same way to Friends-only group rides/runs as to Public ones, since the link itself controls access, not your account's friend list - don't share a Friends-only group ride or run's link anywhere you wouldn't want a stranger to see it.
A user's or club's own public share link (crossroutes.de/u/…, crossroutes.de/c/…, created via the "Share" action on your own profile or a club page) works the same way - reachable by anyone who has the link, without an account or the app. It shows the display name (and, for a user, their own chosen username - already part of the link itself) or the club's name and tag; never a photo, bio, ride history, or friend list. Opening either link doesn't do anything on its own - sending a friend request or joining a club still requires opening the app and taking that action deliberately.
6.International transfers
Cloudflare, Inc. is based in the United States; the transfer relies primarily on Cloudflare's certification under the EU-U.S. Data Privacy Framework (also the Swiss-U.S. and UK-extension frameworks), which the European Commission has recognized as providing adequate protection (Art. 45 GDPR) - meaning this transfer isn't a "restricted" one in the first place. As a fallback should that certification ever lapse, Cloudflare's own Data Processing Addendum separately incorporates the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914). This same agreement also covers Cloudflare's R2 object storage (used for uploaded photos, GPX files, and tag icons) - the bucket itself is hosted in an EU region, but Cloudflare, Inc. as the company remains US-based, so the same safeguards apply as for the reverse-proxy use above. Google Ireland Ltd. is an EU entity; Google's own data processing terms and standard contractual clauses govern any transfer to its US parent. The map-tile service runs on Cloudflare under the same agreement and transfer basis as described above; the map image storage is in the EU, and the abuse-protection counters are held in Cloudflare's EU jurisdiction only. Strava, Inc. is based in the United States; any transfer relies on Strava's own API Agreement (which incorporates standard contractual clauses) or comparable safeguards under Art. 44 et seq. GDPR. In every case, only the narrow data described in section 5 - never your account or profile data - is exposed to these services, and a Strava transfer only ever happens because you actively chose to connect it. In the web version, notifications travel through your browser maker's push service, which may be located outside the EU; their contents are end-to-end encrypted to your browser, so only the encrypted message and its delivery metadata pass through it (see section 12).
7.Location data, specifically
Your device's GPS location is used only on your device, for two things: centering the map on where you are, and working out which suggested group rides/runs count as "nearby" for you. Neither of these sends your coordinates to our server - the app downloads the public location of nearby group rides/runs (which their creators chose to share, the same way a group ride or run's start point is shown to everyone) and does the distance comparison itself, locally.
The one place your device does contact our server in connection with a group ride or run's location is when you create one or draw/import a route yourself - because that route's start point and path are the group ride or run's own public information, shown to everyone who might want to join, not a passive record of your movements.
If you create or manage a club, tapping "use my current location" reads a single, one-time GPS position from your device and sends it to our server, where it's stored as that club's home location - used only to work out which clubs count as "nearby" for other people browsing clubs. It's never shown to anyone as your own location, and once stored it's indistinguishable from a location you could have picked by tapping a point on the map instead.
If you've enabled weather forecasts (Settings), your device separately contacts MET Norway directly to fetch a forecast for a group ride or run you've joined - sending only a handful of approximate coordinates sampled along that ride's already-public route, never your own device location. This isn't personal data about you specifically, and never goes through our server (the web version is the one exception - see section 12). If you've separately enabled Weather Windows notifications (Settings) - a background check for upcoming good-weather windows nearby, unrelated to any specific ride - your device contacts MET Norway directly, roughly once an hour while that setting is on. This is the only purpose for which your device's real (approximate, rounded to roughly 10m) location is sent anywhere outside the app - also never through our server, except in the web version, where it is relayed through our server without being logged (section 12). See section 5.
If you've enabled the height-profile chart or elevation-aware weather timing (Settings), your device also contacts BRouter directly to fetch elevation for a group ride or run's route while you're viewing it - not just when you personally draw or edit a route (see above) - sending that route's own already-public waypoints, never through our server. See section 5.
8.How long we keep data
- Account data: until you delete your account, which you can do yourself in Settings at any time.
- Group ride/run participation history (which ones you've joined/created, and when) is kept indefinitely while your account exists, so your own stats and friends' "ridden/run together" counts stay accurate - deleting your account removes it, including your participation in other people's group rides/runs.
- Route GPS data for a specific group ride or run is removed automatically 7 days after its last occurrence, unless you're a Member and bookmark it.
- Your Strava connection (access/refresh tokens, athlete id) stays stored until you disconnect it in Settings or delete your account - either immediately revokes the connection, on Strava's side too.
- Payment & subscription status is kept only as long as your account exists, the same as account data - we don't separately retain historical billing records ourselves; Google Play retains your purchase history under its own policies.
- Reports you file, or that are filed about you, are kept while relevant to an open review and for a limited period afterward, then deleted.
- Server access logs (IP addresses, request metadata) and rate-limit counters (which briefly track your IP address to enforce the limits described in section 3) are both short-lived - neither is a permanent database.
- Backups: routine encrypted backups of the whole database are kept for disaster-recovery purposes on the developer's own infrastructure, for a limited rolling window - not indefinitely, and never used for any purpose other than restoring service after a failure.
9.Your rights
Under the GDPR, you can ask to: access the personal data we hold about you, have inaccurate data corrected, have your data erased, restrict or object to processing, and receive your data in a portable format. Most of this - editing your profile, deleting your account, disconnecting Strava, exporting a group ride or run's GPX file - you can already do yourself in the app. For anything else, write to [email protected]; we'll respond within 30 days. You can also lodge a complaint with your local data protection authority - for the controller's own location, that's the Landesbeauftragte für den Datenschutz Niedersachsen(external link, opens in a new tab).
10.Age requirement
Crossroutes is not directed at children. You must be at least 16 years old to create an account, in line with the age of consent for information-society services under German and EU data protection law.
11.Security
Passwords are stored as salted hashes, never in plain text. Your session token is stored on-device using your OS's own encrypted storage APIs (Android or iOS); in the web version, it is kept in your browser's storage for crossroutes.de instead, protected by a strict Content Security Policy that allows no third-party scripts on the page, and removed when you sign out. All traffic between the app and our server is encrypted in transit (HTTPS/TLS). Access to the administrative backend is restricted to the developer alone.
12.The web version (web.crossroutes.de)
Crossroutes also runs in your browser at web.crossroutes.de. It is the same app - same account, same backend, same features - so everything in this policy applies to it as well. The differences below are purely technical, and all come from running in a browser instead of as an installed app:
- Adding it to your home screen: on a phone you can add the web version to your home screen (your browser's “Add to Home Screen” or “Install app”). It then opens without the browser bar; it is the same website with the same data processing - nothing extra is sent or stored, apart from remembering that you closed the hint about it (see the cookie policy).
- What's stored in your browser: instead of your phone's app storage, the web version keeps your session token, your settings, and - only if you accept it in the consent banner - an offline copy of your data in your browser's own storage for crossroutes.de (local storage, IndexedDB). Without that consent the copy lives in memory for the open tab only; you can change or withdraw your choice any time via "Cookie settings" at the bottom of the sidebar (on a phone: Settings → Legal) (legal basis for the offline copy: your consent, Art. 6 (1) (a) GDPR and § 25 (1) TDDDG). It sets no cookies. Details are in the Cookie & Local Storage Policy.
- Weather forecasts go through our server: MET Norway's terms require every request to identify the app making it, which a browser can't do - so the web version fetches forecasts through our own server instead of directly. Our server receives only the coordinates the Android app would otherwise send MET Norway itself (a handful of points along a group ride or run's route, or - only if you've turned on Weather Windows - your approximate location) and forwards just those coordinates. MET Norway therefore sees our server's IP address, never yours. These requests are deliberately not written to our server logs, and forecasts are cached only briefly (until MET Norway's own expiry time, plus at most 6 hours), stored under the coordinates alone - never under who asked. In the browser, Weather Windows checks only run while a Crossroutes tab is open.
- Push notifications: only if you allow notifications for crossroutes.de in your browser. Your browser then creates a push subscription with its maker's push service (for example Google for Chrome, Mozilla for Firefox, or Apple for Safari - which one is decided by your browser, not by us), and we store that subscription - a web address at that push service plus encryption keys - the same way we store an app's push token. Notification contents are end-to-end encrypted to your browser, so the push service can't read them; it only sees that a message was delivered, when, and how large it was. You can switch notifications off per category in Settings, or entirely in your browser's site settings.
- Notices while the page is open: weather windows, disruptions on your routes and route-reversal and tailwind notices are worked out by the web version itself while a Crossroutes tab is open, and shown as a browser notification if you've allowed notifications for web.crossroutes.de. No push service is involved; the data they need is fetched as described above.
- Location: your browser asks you before the site can use your location at all; how the browser works out that location (for example by asking a location service run by your browser's maker) is up to the browser. What Crossroutes does with it is exactly what section 7 describes - it stays on your device.
- Sign in with Google: opens Google's own sign-in page in a separate window; no Google script is ever loaded into the web version itself. Afterwards, as in the app, only the sign-in confirmation token Google issues is forwarded to our server.
- Not part of the web version: everything that exists only through Google Play - buying a Member subscription (Play Billing), the in-app update check, and the Install Referrer. A Member subscription you already have belongs to your account, so it's recognized in the browser too.
- Loading the web version: its program files (the app code, fonts, texts and icons) are delivered by Cloudflare from its data centre nearest to you (Cloudflare Workers, see section 5), not by our own server. As with any web request, Cloudflare processes your IP address to deliver them, as our processor; we keep no access logs of these requests ourselves. All fonts are served from web.crossroutes.de itself. The map comes from our own map-tile service (tiles.crossroutes.de, see section 5) - as map data (vector tiles plus the map's fonts and symbols), just like the app; your browser draws the map itself, and the same data is processed as described there; route-snapping/elevation (BRouter) is contacted directly from your browser, exactly as the app contacts it directly from your phone (see section 5).
- Opening a route in other apps and services ("Open route"): instead of the app's "open with" chooser, the web version offers a group ride or run's GPX file as a download or through your device's share sheet (where your browser supports sharing files), and links to the import pages of Komoot, Garmin Connect and RideWithGPS and to directions in Google Maps or Apple Maps. We send nothing to any of these services. Only when you click one of them does your browser open that service's own website in a new tab - the Maps links carry the ride's already-public start point in the address, and, like any website you visit, the opened service sees your IP address. What happens there is governed by that service's own privacy policy.
- Search: the web version's search only looks through data already loaded in your browser (your own group rides/runs, public ones shown on the map, your friends and clubs). Search terms are never sent anywhere.
13.Changes to this policy
If this policy changes in a way that meaningfully affects how your data is handled, we'll surface that in the app rather than silently updating this page. The "last updated" date at the top always reflects the current version.
14.Contact
Questions, requests, or concerns about your data: [email protected].