← Back to home

Privacy Policy

Last updated: 18 September 2026

This is an English translation provided for convenience. The Croatian version is the authoritative text and prevails in the event of any discrepancy.


1. Data controller

The controller of personal data is:

BInspired, obrt za usluge
Owner: Marina Grandić
Glavinićeva 7, 51000 Rijeka, Republic of Croatia
Business register number (MBS): 97921742
E-mail for data protection questions: binspired.obrt@gmail.com

This Privacy Policy applies to the BajsRoute mobile application (the "App") and to the associated website (the "Website"). Together they are referred to as the "Service".


2. What personal data we collect and why

2.1. User account data

DataSourcePurposeLegal basis
Name and surname (Google profile)Google Sign-InIdentifying the user within the systemPerformance of a contract (Article 6(1)(b) GDPR)
E-mail address (Google profile)Google Sign-InCommunication, account identificationPerformance of a contract (Article 6(1)(b) GDPR)
Unique user identifier (UID)Firebase AuthenticationTechnically linking data to a user accountPerformance of a contract (Article 6(1)(b) GDPR)
Anonymous user identifier (UID) and daily number of routing requestsFirebase Authentication (assigned automatically to users who are not signed in as well); the routing backend functionProtecting the routing service from abuse (limiting the number of requests per user)Legitimate interest (Article 6(1)(f) GDPR)
Sign-in restore key (the public part of the key and its identifier)The App on your device, after sign-in (Android Restore Credentials)Automatic sign-in after the App is transferred to a new device, without re-entering sign-in detailsPerformance of a contract (Article 6(1)(b) GDPR)

2.2. Location data

DataSourcePurposeLegal basis
Current device location (GPS)The device operating system, with the user's permissionGenerating a cycling route and showing the user's position on the mapConsent (Article 6(1)(a) GDPR)

Note: the App accesses your location only while in use (while the app is active on screen). Your location is not tracked continuously, is not stored on a server and is not used for profiling. The coordinates of your start and destination are passed to the GraphHopper service through the App's backend function (Google Cloud Functions, servers in the EU) solely to calculate the route, and are neither stored nor written to logs.

2.3. User-generated content (UGC)

DataSourcePurposeLegal basis
Rating of a bike path section (1–5)User input in the AppCalculating the average rating of a section; improving routingLegitimate interest (Article 6(1)(f) GDPR)
Problem report (problem type, comment, location, severity and, if you attach one, a photo)User input in the AppRecording infrastructure defects; passing them on to the responsible authoritiesLegitimate interest (Article 6(1)(f) GDPR)

User content is publicly visible in the App. Alongside the average rating of a section, any user can open the list of that section's individual ratings – the number of stars, the comment attached to it, and the date. Individual problem reports (type, comment, date) are equally visible to every user on that section. That content is shown with the author's nickname from their profile; the nickname is chosen by the user and can be changed at any time, while the e-mail address and the rest of the account details are never published. Once a user account is deleted, the content carries only a deleted-account marker. Because the comment is public, please do not enter personal data into it.

A photo attached to a problem report is not publicly available: it is seen only by authorised persons with access to the admin interface, and may be passed on to the responsible authorities in order to resolve the problem. Before sending, the App downsizes the photo and strips its metadata (for example, the location where it was taken). Please do not photograph people or vehicle registration plates.

The controller's legitimate interest in collecting user content is based on the public interest in improving the City of Zagreb's cycling infrastructure, which is also the purpose of the App. You may exercise your right to object at any time in accordance with Article 21 GDPR (see section 7).

2.4. Aggregated (anonymous) data

On the basis of individual ratings and problem reports, the system automatically calculates aggregated statistics per path section (average rating, number of ratings, number of open problems). The system also keeps daily statistics on use of the routing service (number of requests and credits spent), without location data and without user identifiers. This data contains no personal data and cannot be linked to individual users. Aggregated data is publicly available through the map view in the App.

2.5. Technical data (website)

When you visit the Website, the server automatically records technical data such as your IP address, browser type, operating system, and the date and time of access. This data is processed on the basis of legitimate interest (Article 6(1)(f) GDPR) to ensure the security and stability of the system, and is not used to identify visitors. For more on cookies, see the Cookie Policy.


3. Retention periods

Data categoryRetention period
User account data (name, e-mail, UID)Until the user deletes the account + 30 days for technical clean-up
Section ratings (and the comments attached to them)No limit. When a user account is deleted the rating and comment stay on record, but the link to the account is severed – the name is no longer shown, only a deleted-account marker. We delete ratings and comments at the user's request.
Problem reportsUntil the problem is resolved and for 2 (two) years from resolution, in order to track infrastructure maintenance trends. After that period the report is anonymised (the link to the user account is removed) or deleted. An attached photo is deleted together with the report. When a user account is deleted the report stays on record, because it may already have been passed on to the responsible city service, but it is no longer shown next to a user name. We delete reports at the user's request.
Location dataNot stored – used only in working memory to calculate a route
Routing request counter (UID, credits spent that day)The counter resets every day, and the record is deleted automatically within a few days of the last routing request, or when the user account is deleted
Sign-in restore key (public part of the key)Until the user account is deleted. The key can no longer be used if the account's sessions are revoked (for example by a password change). The private part of the key never leaves the device except inside an encrypted backup or a transfer to a new device, and is deleted on sign-out or when the App is uninstalled.
Aggregated data (segmentAgg)No limit – contains no personal data
Website technical logs (IP, user agent)Maximum 90 days

4. Recipients and processors

We do not sell, rent out or pass your personal data to third parties for marketing purposes. To provide the Service we use the following processors:

ProcessorPlace of establishmentPurposeApplicable safeguard
Google LLC (Firebase Authentication, Cloud Firestore, Cloud Storage for Firebase, Cloud Functions, Firebase Hosting)USAUser authentication, storage of data and files (for example photos attached to problem reports), running backend functions, serving the websiteEU-U.S. Data Privacy Framework (DPF); Standard Contractual Clauses (SCC)
GraphHopper GmbHGermany (EU)Calculating the cycling route from the start and destination coordinatesProcessing within the EU/EEA
OpenStreetMap Foundation (Nominatim)United KingdomGeocoding (turning addresses into coordinates and vice versa)Publicly available API; only geocoding queries are sent, without user identifiers

Transfers outside the EU/EEA: Firebase services run on Google LLC's infrastructure. Google is certified under the EU-U.S. Data Privacy Framework. In addition, Standard Contractual Clauses (SCC) approved by the European Commission apply to data transfers. More information: Google Cloud Privacy Notice.


5. Cookies and similar technologies

The Website uses a limited number of technical cookies necessary for it to function. The details are set out in a separate Cookie Policy.

The mobile app does not use cookies. Firebase Authentication in the App uses a locally stored token to keep your session – that token is deleted automatically when you sign out or clear the App's data. If you are signed in, the App also creates a sign-in restore key on your device, which Android may include in an encrypted backup or in a transfer to a new device; the key is deleted when you sign out.


6. Data security

We take appropriate technical and organisational measures to protect your personal data from unauthorised access, loss, destruction or alteration, including:


7. Your rights as a data subject

Under the General Data Protection Regulation (GDPR) you have the following rights in relation to your personal data:

Right of access (Article 15) – You have the right to ask for confirmation of whether your personal data is being processed and, if it is, to obtain access to that data and information about the processing.

Right to rectification (Article 16) – You have the right to ask for inaccurate personal data concerning you to be corrected.

Right to erasure ("right to be forgotten") (Article 17) – You have the right to ask for your personal data to be deleted, under the conditions laid down by the GDPR. You can request deletion of your user account by writing to binspired.obrt@gmail.com.

Right to restriction of processing (Article 18) – You have the right to ask for the processing of your data to be restricted in certain circumstances, for example if you contest the accuracy of the data.

Right to data portability (Article 20) – You have the right to receive your personal data in a structured, commonly used and machine-readable format and to transmit it to another controller.

Right to object (Article 21) – You have the right to object to processing of your personal data based on the controller's legitimate interest. In that case we will stop processing your data unless we demonstrate compelling legitimate grounds for the processing which override your interests.

Right to lodge a complaint with a supervisory authority – If you believe that the processing of your personal data does not comply with the GDPR, you have the right to lodge a complaint with the competent supervisory authority. In the Republic of Croatia this is:

Agencija za zaštitu osobnih podataka (AZOP) – the Croatian Personal Data Protection Agency
Selska cesta 136, 10000 Zagreb
www.azop.hr
azop@azop.hr

8. Requests concerning personal data

You can send any request to exercise your rights to:

E-mail: binspired.obrt@gmail.com
Subject line: "Request – personal data protection"

We will respond to your request without undue delay and within 30 days of receiving it at the latest. If the request is complex, or if a large number of requests is received, that period may be extended by a further 60 days, of which we will notify you.

To protect your privacy, we may ask for additional identification before acting on a request.


9. Special provisions for minors

The Service is intended for people over 16. We do not knowingly collect personal data of people under 16. If we learn that we have collected personal data of a person under 16 without valid consent from a parent or guardian, we will take reasonable steps to delete that data.


10. Automated decision-making

The App does not carry out automated decision-making or profiling within the meaning of Article 22 GDPR. The aggregated calculation of average ratings for path sections is a statistical operation that produces no legal effects and does not similarly significantly affect individuals.


11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the Service or in applicable regulations. We will notify you of significant changes through a notice in the App or on the Website. The date of the last update is shown at the top of this document. By continuing to use the Service after changes are published, you will be deemed to be aware of the updated Policy.


12. Governing law

This Privacy Policy is governed by the law of the Republic of Croatia and by the General Data Protection Regulation (Regulation (EU) 2016/679).