Privacy Policy
Last updated: 18 September 2026
This is an English translation provided for convenience. The Croatian version is the authoritative text and prevails in the event of any discrepancy.
1. Data controller
The controller of personal data is:
BInspired, obrt za uslugeOwner: Marina Grandić
Glavinićeva 7, 51000 Rijeka, Republic of Croatia
Business register number (MBS): 97921742
E-mail for data protection questions: binspired.obrt@gmail.com
This Privacy Policy applies to the BajsRoute mobile application (the "App") and to the associated website (the "Website"). Together they are referred to as the "Service".
2. What personal data we collect and why
2.1. User account data
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Name and surname (Google profile) | Google Sign-In | Identifying the user within the system | Performance of a contract (Article 6(1)(b) GDPR) |
| E-mail address (Google profile) | Google Sign-In | Communication, account identification | Performance of a contract (Article 6(1)(b) GDPR) |
| Unique user identifier (UID) | Firebase Authentication | Technically linking data to a user account | Performance of a contract (Article 6(1)(b) GDPR) |
| Anonymous user identifier (UID) and daily number of routing requests | Firebase Authentication (assigned automatically to users who are not signed in as well); the routing backend function | Protecting the routing service from abuse (limiting the number of requests per user) | Legitimate interest (Article 6(1)(f) GDPR) |
| Sign-in restore key (the public part of the key and its identifier) | The App on your device, after sign-in (Android Restore Credentials) | Automatic sign-in after the App is transferred to a new device, without re-entering sign-in details | Performance of a contract (Article 6(1)(b) GDPR) |
2.2. Location data
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Current device location (GPS) | The device operating system, with the user's permission | Generating a cycling route and showing the user's position on the map | Consent (Article 6(1)(a) GDPR) |
Note: the App accesses your location only while in use (while the app is active on screen). Your location is not tracked continuously, is not stored on a server and is not used for profiling. The coordinates of your start and destination are passed to the GraphHopper service through the App's backend function (Google Cloud Functions, servers in the EU) solely to calculate the route, and are neither stored nor written to logs.
2.3. User-generated content (UGC)
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Rating of a bike path section (1–5) | User input in the App | Calculating the average rating of a section; improving routing | Legitimate interest (Article 6(1)(f) GDPR) |
| Problem report (problem type, comment, location, severity and, if you attach one, a photo) | User input in the App | Recording infrastructure defects; passing them on to the responsible authorities | Legitimate interest (Article 6(1)(f) GDPR) |
User content is publicly visible in the App. Alongside the average rating of a section, any user can open the list of that section's individual ratings – the number of stars, the comment attached to it, and the date. Individual problem reports (type, comment, date) are equally visible to every user on that section. That content is shown with the author's nickname from their profile; the nickname is chosen by the user and can be changed at any time, while the e-mail address and the rest of the account details are never published. Once a user account is deleted, the content carries only a deleted-account marker. Because the comment is public, please do not enter personal data into it.
A photo attached to a problem report is not publicly available: it is seen only by authorised persons with access to the admin interface, and may be passed on to the responsible authorities in order to resolve the problem. Before sending, the App downsizes the photo and strips its metadata (for example, the location where it was taken). Please do not photograph people or vehicle registration plates.
The controller's legitimate interest in collecting user content is based on the public interest in improving the City of Zagreb's cycling infrastructure, which is also the purpose of the App. You may exercise your right to object at any time in accordance with Article 21 GDPR (see section 7).
2.4. Aggregated (anonymous) data
On the basis of individual ratings and problem reports, the system automatically calculates aggregated statistics per path section (average rating, number of ratings, number of open problems). The system also keeps daily statistics on use of the routing service (number of requests and credits spent), without location data and without user identifiers. This data contains no personal data and cannot be linked to individual users. Aggregated data is publicly available through the map view in the App.
2.5. Technical data (website)
When you visit the Website, the server automatically records technical data such as your IP address, browser type, operating system, and the date and time of access. This data is processed on the basis of legitimate interest (Article 6(1)(f) GDPR) to ensure the security and stability of the system, and is not used to identify visitors. For more on cookies, see the Cookie Policy.
3. Retention periods
| Data category | Retention period |
|---|---|
| User account data (name, e-mail, UID) | Until the user deletes the account + 30 days for technical clean-up |
| Section ratings (and the comments attached to them) | No limit. When a user account is deleted the rating and comment stay on record, but the link to the account is severed – the name is no longer shown, only a deleted-account marker. We delete ratings and comments at the user's request. |
| Problem reports | Until the problem is resolved and for 2 (two) years from resolution, in order to track infrastructure maintenance trends. After that period the report is anonymised (the link to the user account is removed) or deleted. An attached photo is deleted together with the report. When a user account is deleted the report stays on record, because it may already have been passed on to the responsible city service, but it is no longer shown next to a user name. We delete reports at the user's request. |
| Location data | Not stored – used only in working memory to calculate a route |
| Routing request counter (UID, credits spent that day) | The counter resets every day, and the record is deleted automatically within a few days of the last routing request, or when the user account is deleted |
| Sign-in restore key (public part of the key) | Until the user account is deleted. The key can no longer be used if the account's sessions are revoked (for example by a password change). The private part of the key never leaves the device except inside an encrypted backup or a transfer to a new device, and is deleted on sign-out or when the App is uninstalled. |
| Aggregated data (segmentAgg) | No limit – contains no personal data |
| Website technical logs (IP, user agent) | Maximum 90 days |
4. Recipients and processors
We do not sell, rent out or pass your personal data to third parties for marketing purposes. To provide the Service we use the following processors:
| Processor | Place of establishment | Purpose | Applicable safeguard |
|---|---|---|---|
| Google LLC (Firebase Authentication, Cloud Firestore, Cloud Storage for Firebase, Cloud Functions, Firebase Hosting) | USA | User authentication, storage of data and files (for example photos attached to problem reports), running backend functions, serving the website | EU-U.S. Data Privacy Framework (DPF); Standard Contractual Clauses (SCC) |
| GraphHopper GmbH | Germany (EU) | Calculating the cycling route from the start and destination coordinates | Processing within the EU/EEA |
| OpenStreetMap Foundation (Nominatim) | United Kingdom | Geocoding (turning addresses into coordinates and vice versa) | Publicly available API; only geocoding queries are sent, without user identifiers |
Transfers outside the EU/EEA: Firebase services run on Google LLC's infrastructure. Google is certified under the EU-U.S. Data Privacy Framework. In addition, Standard Contractual Clauses (SCC) approved by the European Commission apply to data transfers. More information: Google Cloud Privacy Notice.
5. Cookies and similar technologies
The Website uses a limited number of technical cookies necessary for it to function. The details are set out in a separate Cookie Policy.
The mobile app does not use cookies. Firebase Authentication in the App uses a locally stored token to keep your session – that token is deleted automatically when you sign out or clear the App's data. If you are signed in, the App also creates a sign-in restore key on your device, which Android may include in an encrypted backup or in a transfer to a new device; the key is deleted when you sign out.
6. Data security
We take appropriate technical and organisational measures to protect your personal data from unauthorised access, loss, destruction or alteration, including:
- data between the App and the server is transmitted over encrypted channels (TLS/HTTPS);
- access to data in the database is restricted by access rules (Firestore Security Rules) – the data of your user account can be accessed only by you, while section ratings, problem reports and aggregated data are publicly available for reading only and can be changed only by you or by an authorised administrator;
- administrative access to data (reviewing problem reports, moderation) is restricted to authorised persons with a verified administrator role;
- personal data processed on the server side (Cloud Functions) is not written to logs except in anonymised form.
7. Your rights as a data subject
Under the General Data Protection Regulation (GDPR) you have the following rights in relation to your personal data:
Right of access (Article 15) – You have the right to ask for confirmation of whether your personal data is being processed and, if it is, to obtain access to that data and information about the processing.
Right to rectification (Article 16) – You have the right to ask for inaccurate personal data concerning you to be corrected.
Right to erasure ("right to be forgotten") (Article 17) – You have the right to ask for your personal data to be deleted, under the conditions laid down by the GDPR. You can request deletion of your user account by writing to binspired.obrt@gmail.com.
Right to restriction of processing (Article 18) – You have the right to ask for the processing of your data to be restricted in certain circumstances, for example if you contest the accuracy of the data.
Right to data portability (Article 20) – You have the right to receive your personal data in a structured, commonly used and machine-readable format and to transmit it to another controller.
Right to object (Article 21) – You have the right to object to processing of your personal data based on the controller's legitimate interest. In that case we will stop processing your data unless we demonstrate compelling legitimate grounds for the processing which override your interests.
Right to lodge a complaint with a supervisory authority – If you believe that the processing of your personal data does not comply with the GDPR, you have the right to lodge a complaint with the competent supervisory authority. In the Republic of Croatia this is:
Agencija za zaštitu osobnih podataka (AZOP) – the Croatian Personal Data Protection AgencySelska cesta 136, 10000 Zagreb
www.azop.hr
azop@azop.hr
8. Requests concerning personal data
You can send any request to exercise your rights to:
E-mail: binspired.obrt@gmail.com
Subject line: "Request – personal data protection"
We will respond to your request without undue delay and within 30 days of receiving it at the latest. If the request is complex, or if a large number of requests is received, that period may be extended by a further 60 days, of which we will notify you.
To protect your privacy, we may ask for additional identification before acting on a request.
9. Special provisions for minors
The Service is intended for people over 16. We do not knowingly collect personal data of people under 16. If we learn that we have collected personal data of a person under 16 without valid consent from a parent or guardian, we will take reasonable steps to delete that data.
10. Automated decision-making
The App does not carry out automated decision-making or profiling within the meaning of Article 22 GDPR. The aggregated calculation of average ratings for path sections is a statistical operation that produces no legal effects and does not similarly significantly affect individuals.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the Service or in applicable regulations. We will notify you of significant changes through a notice in the App or on the Website. The date of the last update is shown at the top of this document. By continuing to use the Service after changes are published, you will be deemed to be aware of the updated Policy.
12. Governing law
This Privacy Policy is governed by the law of the Republic of Croatia and by the General Data Protection Regulation (Regulation (EU) 2016/679).