Log in

Privacy & cookies

Privacy and cookie notice

Last updated 4 September 2026

PaddleScout stores some of the most sensitive data a paddling app can hold: where you paddle, when, and where you launch from. This notice explains what we keep, why we keep it, who else touches it, and how you stay in control.

The short version: we collect what the service needs to work and nothing else. We count page views with a cookie-free counter that cannot identify you; beyond that there are no trackers, no advertising, and we sell nothing about you to anyone.

1Who we are

PaddleScout is run by Andrew Franklin, a sole trader based in the United Kingdom, who is the data controller for the personal data described here.

For anything in this notice, or any question about your data, email privacy@paddlescout.co.uk.

2What we hold and why

Each row below names the purpose, the legal basis we rely on under UK GDPR, and how long the data lives. Unless a row says otherwise, deleting your account removes the data with it.

WhatDetailsLegal basisKept for
Your accountName, email, password (stored hashed, we cannot read it), display name, timezone, alert preferencesContractUntil you delete your account
Trips & placesRoute tracks, start point & place name, the original GPX/FIT file, map thumbnails, pins, saved spots, and the named lists you save spots intoContractUntil you delete your account — a listed spot stays; see Directory content
PhotosRe-encoded copies of your images; we strip GPS and embedded metadata on uploadContractUntil you delete your account
Device detailsManufacturer & product from a FIT file; heart rate, calories & serial number are discarded on uploadContractUntil you delete your account
Friends & sharingFriendships, trip tags (a tag stands only once accepted), comments & questions on spots, boardsContractUntil you delete your account
Directory contentSpots you list, and photos and notes you submit to listed location pagesConsentApproved content stays published after deletion, with your name removed; a one-way email fingerprint is kept 2 years
Emails we sendFor condition alerts: address, subject & body, to diagnose delivery; security email logged without contentLegitimate interest90 days, then pruned
Sign-in sessionsThe IP address & browser identifier of each active sessionLegitimate interestWhile the session is active; removed on deletion
BillingName, email & subscription state, held with Paddle; card details go to Paddle, never to usContractLegal obligationSubscription records until deletion; transaction records 6 years (UK tax law)
Safety & moderationReports you make, and records of moderation action on content or accountsLegitimate interest2 years after the account involved is deleted
Near-me locationIf you tap "Use my location" on the near-me search, your device location — rounded on your device — used once to find nearby spots, never sent to any other serviceConsentNot stored — used for that one search, then gone
Your data exportThe archive you request from Settings → Your dataContractUntil its download link expires, then deleted
BackupsA daily safety copy of your account, trip and spot records so accidental loss or corruption is recoverable. Your uploaded track files and photos are stored separately and are not part of this copyLegitimate interestRolls off after 30 days — deleting your account does not remove a backup already made until it ages out

Nothing on PaddleScout makes automated decisions about you. The trip planner summarises a weather forecast for a place; it judges nothing about you, and your personal data plays no part in it.

3Your location data

A public trip that starts at your slipway tells a stranger where you live.

Trips are precise location history, so this data gets the strictest handling in the app:

  • Every trip has a visibility setting — Private, Unlisted, or Public. Our servers decide what each viewer sees, before anything leaves us.
  • Original track files and photos live on private storage, reachable at no public address, and an unlisted link stops working the moment you switch a trip to private.
  • Photos are stripped of GPS on upload, so a shared photo can't leak where it was taken.
  • A saved spot's coordinates stay yours — published only if you offer it to the directory, tick the consent box, and a moderator approves it.

If you launch from home, consider starting your recording a little way from your door, or trimming the start of the track before sharing.

4Sharing and other people

Private trips are yours alone; unlisted trips are visible to anyone holding the share link; public trips are visible to anyone, including search engines. When a friend tags you, the tag waits for your acceptance. Listing a spot, or contributing a photo or note, starts with a consent box and ends with a moderator's review. Contributed photos appear without your name, marked only "Added by a paddler".

5Who else processes your data

Seven services help run PaddleScout. Six operate in the UK or the European Economic Area. The seventh, Cloudflare, is based in the United States; it runs the bot check on the sign-in, sign-up, and password pages and a cookie-free page-view count on every page. That transfer is covered by Cloudflare's data protection agreement and the UK's international transfer terms.

ServiceWhat it receivesWhere
Paddle paymentsYour name, email & payment details when you subscribe. Merchant of record — your card never reaches us. Its checkout script sees your IP on the billing page.UK / EU
Amazon Web Services email & storageThe recipient and content of each email we send (SES), plus your uploaded track files and photos. All in AWS's London region.UK
Zoho Mail our inboxEmail between you and us at our support, privacy, or hello addresses: your address and whatever the messages contain. The app’s own email, like password resets and alerts, goes out through AWS.Netherlands
Open-Meteo weatherThe coordinates a forecast is for, and place names you type into search. No name or account identifier attached.Germany
OpenStreetMap mapsCoordinates we turn into place names (from our servers, no identity). Map tiles load in your browser, so OSM sees your IP and the area you view.UK / EU
New Relic performance monitoringTechnical diagnostics about how the app runs on our server: response times, and error reports naming which page was hit by its route pattern, never the full web address, so a share or reset link is never included. We attach no name or account identifier. If a request fails, the error detail can include a coordinate our server was looking up. We also send our server's operational logs for the same diagnostics, but scrub every line first: we strip out share and reset links, coordinates, email addresses, file paths and IP addresses before a log leaves our server. Runs only on our server, nothing in your browser.EU
Cloudflare bot check & analyticsYour IP address and signals about your browser: on the sign-in, sign-up, and password pages to tell a real visitor from an automated one, and on every page to count a view. The count sets no cookie and stores nothing that ties a visit back to your account; no name or account identifier reaches Cloudflare.United States

We host our own fonts. Three third-party scripts run on the site: Paddle's checkout on the billing page, the Cloudflare bot check on the sign-in, sign-up, and password pages, and Cloudflare's cookie-free page-view counter everywhere. No advertising script runs anywhere.

6Cookies

PaddleScout sets only the cookies it needs to sign you in and remember small preferences. This is the full list:

CookieWhat it doesLifetime
paddlescout_sessionKeeps you signed in while you browse2 hours from last request
XSRF-TOKENStops another website submitting forms as you2 hours from last request
remember_web_*Keeps you signed in between visits when you tick "Remember me"Until you sign out, or 400 days
sidebar:stateRemembers whether the sidebar is open or collapsed7 days
cookie_notice_dismissedRemembers that you dismissed the one-time cookie note12 months

There are no advertising or tracking cookies. The page-view counter described above sets no cookie either, which is why you see no consent pop-up: UK law (PECR) requires consent only for cookies beyond what the service strictly needs, and we set none. A small one-time note points new visitors here; dismissing it blocks nothing.

No tracking cookies, no ads

7Your rights

UK GDPR gives you rights over your data. Here is each one and how to use it:

  • See and take your data. Request an export from Settings → Your data — a ZIP of your track files, a spreadsheet of your trips, and a file describing your boards, pins, tags, spots, saved lists, and captions. We email you when it's ready.
  • Correct your data. Edit your name, email, and profile at Settings → Profile.
  • Delete your data. Delete your account from Settings → Profile. Three things outlast deletion: transaction records (6 years, UK tax law), moderation records (2 years), and directory content you chose to keep public, which stays without your name.
  • Stop alert emails. Every alert email carries an unsubscribe link, and the same switches live in your settings.
  • Restrict or object. Where the controls above don't cover it, email privacy@paddlescout.co.uk and we respond within a month.
  • Complain. You can complain to the Information Commissioner's Office at ico.org.uk. We'd welcome the chance to put things right first.

8Children

PaddleScout is for people aged 18 and over. We do not knowingly hold data about anyone younger. If you believe a child has an account, email privacy@paddlescout.co.uk and we will remove it.

9Changes to this notice

When this notice changes, we update the date at the top. If a change affects what we collect or who we share it with, we will tell you by email or a notice in the app before it takes effect.