ROUTEART / PRIVACY POLICY
Effective 22 July 2026 · routeart is operated by Westmidlanders LLC, a Wyoming (USA) limited liability company.
The short version
A GPS route is precise location history, and we treat it that way. Your uploaded file is processed in memory and never stored. What we keep is the rendered poster and its statistics, and those delete themselves after 30 days, or immediately if you ask. No accounts, no advertising, no analytics, no cookies, and we never sell data.
What we process, and why
- Your GPS file (GPX). Read in memory to compute the route trace, elevation profile, and statistics. The raw file is discarded when rendering finishes and is never written to storage.
- Rendered artifacts. The poster (SVG/PNG), its computed statistics, and your chosen settings are stored under an unguessable content-derived identifier so you can preview and download. The rendered trace still depicts where you went, so we treat it as location data.
- Server logs. Standard request logs (IP address, request time and path, render timings) for operating and securing the service.
- Account data. If you create an account, we process your email address to sign you in and to keep your credit balance. We have no passwords to store: sign-in works by emailed link.
- Purchase records. If you buy credits, we keep a ledger of credits bought and spent. Card details go directly to Stripe; we never see or store them.
Retention and deletion
Rendered artifacts and job records are automatically deleted 30 days after creation, with one exception: posters you have exported with a credit are kept so your re-downloads stay free. You can delete any poster immediately, at any time, using the delete action for its job. You do not need an account or a request form. Account and purchase records are kept while your account exists and for as long as tax law requires afterwards. Server logs are retained per our hosting provider's standard rotation.
Service providers
- Hosting: Render (render.com), where the service and its short-lived storage run.
- Terrain data: when terrain contours are enabled, the service requests public elevation tiles from the AWS Open Data Registry. Only map tile coordinates for the poster's area are sent. Your file and the traced route never leave our server.
- Error reporting: if enabled, exception reports go to Sentry; these do not include your route data.
- Accounts: Supabase provides sign-in and stores your email address for that purpose.
- Payments: Stripe processes card payments. Your payment details go to Stripe directly and are governed by Stripe's privacy policy.
We do not sell or share personal information for advertising. We disclose data only if legally compelled.
Your rights
Wherever you are, you can delete your data as described above. If you are in the EEA/UK, the legal bases for processing are performance of the service you request (Art. 6(1)(b) GDPR) and our legitimate interest in operating it securely (Art. 6(1)(f)); you additionally have rights of access, rectification, erasure, restriction, and portability, and the right to lodge a complaint with your supervisory authority. California residents have analogous rights under the CCPA/CPRA; we do not "sell" or "share" personal information as those terms are defined there.
A practical note on route privacy
Routes often begin and end at home. Consider trimming the start and end of an activity in your tracking app before exporting a GPX you plan to turn into a poster you will display.
Children
The service is not directed at children under 13 and we do not knowingly process their data.
Changes and contact
If payments or accounts are added, this policy will be updated before those features launch, with the effective date above revised. Questions or deletion requests: westmidlanderstech@gmail.com.
← back to routeart