Privacy Policy
1. Controller
Faviroute UG (haftungsbeschränkt)
represented by its Managing Director Thomas Hoffmann
Lindengasse 11
55120 Mainz
Germany
Phone: +49 178 2368172
Email: info@faviroute.com
2. Hosting
This website is hosted by:
Mittwald CM Service GmbH & Co. KG
Königsberger Straße 4–6
32339 Espelkamp
Germany
The hosting provider processes personal data on our behalf for the purpose of providing this website.
3. Server Log Files
When you visit this website, the hosting provider automatically collects and stores information in server log files. This may include your IP address, date and time of access, requested page or file, amount of data transferred, browser type and version, operating system, referrer URL, hostname, HTTP status code, and user agent.
This processing is carried out to ensure the secure, stable, and technically correct operation of the website.
Legal basis: Art. 6(1)(f) GDPR.
Legitimate interest: secure and reliable provision of the website, system security, and prevention of misuse.
According to the hosting provider’s published information, access logs are stored in anonymized form for up to 60 days. Error logs are deleted after 7 days. A different storage period may apply where retention is required for security or evidentiary reasons.
4. Contact by Email or Phone
If you contact us by email or phone, we process the personal data you provide in order to handle your request. This may include your name, email address, phone number, message content, and any other information you provide voluntarily.
Legal basis:
Art. 6(1)(b) GDPR, if your inquiry relates to the initiation or performance of a contract.
Art. 6(1)(f) GDPR for other general inquiries.
Legitimate interest: efficient handling of inquiries and communication with interested parties.
We delete this data once your request has been fully processed, unless statutory retention obligations require longer storage.
5. Cookies and Similar Technologies
This website does not use cookies or similar technologies for analytics, tracking, marketing, or profiling purposes.
This does not exclude technically necessary requests to map, routing or geocoding services, or technically necessary browser caching and storage processes required to display maps, load map tiles, maintain route planner sessions or provide route planning functions requested by you.
6. Route Planner, Stored Travel Plans and Passcodes
As part of our web-based Route Planner, we process the data that is generated when the tool is used or entered by you. This may include, in particular, technically generated travel plan data, selected places, accommodation, travel dates, the order of stops, technical status values of the travel plan, as well as a randomly generated identifier (“token”) under which a travel plan can be stored, accessed again or unlocked.
Purposes of Processing
Processing takes place in order to technically provide the Route Planner, generate travel plans, keep them up to date during use, make stored travel plans accessible again, manage acquired access rights (“passes” / passcodes), and prevent misuse, errors and disruptions of the service.
Legal Bases
Where processing is necessary for the provision of the Route Planner requested by you, for the storage of travel plans, for unlocking by means of passcodes, or for carrying out an order or payment process, it is carried out on the basis of Art. 6(1)(b) GDPR.
Where we process data for IT security, error analysis, prevention of misuse or the technical stability of our offering, this is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and economically viable provision of our online offering.
Tokens, Stored Travel Plans and Access Protection
Stored travel plans can be accessed via a technically generated, random identifier (“token”). In addition, active access rights via a pass / passcode may be required for certain functions or content.
Please note: Anyone who has a token link or a valid passcode can — subject to further technical restrictions — access the relevant travel plan. You should therefore treat token links and passcodes as confidential and only share them with persons to whom you wish to grant access.
Which Data Is Stored on the Server Side
When a travel plan is saved, updated, purchased, accessed again or unlocked by means of a pass, we may process or store, in particular, the following data:
- technical travel plan data and status values;
- the token identifier of the travel plan;
- times of creation, updating, unlocking and expiry;
- status information, e.g. “saved”, “temporarily saved”, “pass-protected”;
- where applicable, assignment to a purchased pass or an order;
- technical log and security data.
Where travel plans are linked to an order or a pass, assignment to order and payment data may take place to the extent necessary for provision, unlocking, administration or troubleshooting.
Passes / Passcodes
When you purchase a pass, we process the data required for the order and payment process as well as for issuing, activating and managing the pass. This includes, in particular:
- order number;
- email address;
- purchased pass type / term;
- time of purchase;
- expiry date of the pass;
- generated passcode;
- status of the pass, e.g. active / inactive / expired;
- where applicable, links to one or more travel plans.
Processing is carried out for the performance of a contract pursuant to Art. 6(1)(b) GDPR.
Payment Processing
For payment processing, we work with external payment service providers. The data required as part of the payment process is transmitted to the payment service provider selected by you. The respective payment service provider’s own privacy policy applies to the data processing carried out by that provider.
Payment service providers used:
Paypal
Sending Emails in Connection with Passes
When you purchase a pass or request that a passcode be sent to you, we use your order email address or the email address provided by you to send you pass- and order-related messages, in particular:
- order confirmations;
- information about your pass;
- sending of the passcode;
- technically necessary notices regarding your access.
Processing is carried out for the performance of a contract pursuant to Art. 6(1)(b) GDPR.
Storage Period
We store travel plan, order and pass data only for as long as this is necessary for the respective purposes, in particular for providing the service, enforcing acquired access rights, troubleshooting, preventing misuse and fulfilling statutory retention obligations.
Travel plans may be deleted or anonymized once their technical or contractual relevance has expired.
Order and billing-related data is stored within the scope of statutory retention obligations.
Specific periods / deletion logic:
- 1-Month-Pass: Valid for 7 days, starting at purchase time
- 6-Month-Pass: Valid for 186 days, starting at purchase time
- 1-Year-Pass: Valid for 365 days, starting at purchase time
All passes are deleted within 14 days after end of their respective validity.
Itineraries that are not saved will be deleted within 7 days of their creation.
Itineraries that have been saved will be deleted within 7 days after the end of the validity of the pass which was last used to save the respective itinerary.
Technically Necessary Storage on Your Device
For the operation of the Route Planner, maintaining a session, unlocking travel plans, using passcodes and carrying out checkout and security functions, technically necessary information may be stored on or read from your device, such as session IDs or comparable technical storage. Such storage takes place exclusively to the extent necessary for the use of our service expressly requested by you.
Note on Use of the Route Planner
Please do not enter any sensitive personal data or other content into the Route Planner whose processing or disclosure would pose a particular risk to you, unless this is strictly necessary for the intended use.
7. Map, Geocoding and Routing Services: Mapbox and OpenStreetMap
Our Route Planner uses external map, geocoding, routing and/or map display services in order to display maps, calculate routes, search for places and provide location-based route planning functions.
For this purpose, requests may be transmitted to the following providers:
Mapbox
Provider: Mapbox, Inc., USA.
When the Route Planner is used, your browser or our server may send requests to Mapbox services. In this context, Mapbox may receive technical and location-related data, in particular:
IP address;
date and time of the request;
browser and device information;
operating system;
user agent;
referrer URL;
Mapbox access token or comparable technical identifiers;
contents of API requests, such as map view, coordinates, route points, search terms, addresses, place names, selected destinations or route-related parameters;
where applicable, approximate or precise location data if you actively use location-based functions or permit access to your location.
Mapbox processes such data in order to provide, secure, maintain, bill, analyse and improve its map and location services. According to Mapbox, IP addresses are generally retained for 30 days, unless a longer retention period is required for security, anti-fraud, misuse investigation or legal reasons.
Further information can be found in Mapbox’s privacy information and product privacy policy.
OpenStreetMap / OpenStreetMap Foundation
We may also use services or data from the OpenStreetMap project. Where requests are made directly to services operated by the OpenStreetMap Foundation, the following provider may receive data:
OpenStreetMap Foundation
St John’s Innovation Centre
Cowley Road
Cambridge CB4 0WS
United Kingdom
When OpenStreetMap services are accessed, technical access data may be transmitted, in particular:
IP address;
browser and device type;
operating system;
referring website;
date and time of access;
requested map tiles, API resources, search queries or other accessed services.
OpenStreetMap may use such data for the operation, security, technical administration, abuse prevention and improvement of its services. Map tiles may be delivered through a global network of cache servers.
Please do not enter sensitive personal data into map search fields, route points, place names or other route planning inputs unless this is necessary for using the Route Planner.
Purposes of processing
We use these services to provide the Route Planner, display maps, search for locations, calculate routes, process selected stops and destinations, improve technical reliability, prevent misuse and troubleshoot errors.
Legal basis
Where the processing is necessary to provide the Route Planner or route planning functions requested by you, the legal basis is Art. 6(1)(b) GDPR.
Where processing is necessary for the secure, stable and technically reliable operation of our Route Planner, the legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the provision of a functional, secure and user-friendly map-based route planning service.
Where your browser or device asks for permission to access your current location, location access only takes place if you grant that permission. You can revoke or prevent location access at any time in your browser or device settings.
8. Recipients of Personal Data
We only share personal data with recipients where this is necessary for the operation of the website or for handling communications. Recipients of your data may include, in particular:
- our hosting provider;
- technical service providers for operation, maintenance and email delivery;
- payment service providers;
- Mapbox, Inc., where Mapbox map, geocoding, routing or location services are used;
- OpenStreetMap Foundation, where services operated by the OpenStreetMap Foundation are accessed directly;
- where applicable, further processors or independent providers insofar as they are used for the operation of our offering.
Where required, we conclude data processing agreements with processors pursuant to Art. 28 GDPR. Some external providers may also process certain data as independent controllers under their own privacy policies.
We do not sell your personal data.
9. International Data Transfers
In connection with the Route Planner, personal data may be transferred to or accessed from countries outside the European Union or the European Economic Area.
This applies in particular to Mapbox, Inc., USA. Mapbox states that its products and services are hosted in AWS in the United States and that content may be cached and served from different regions for performance reasons. Mapbox states that it relies on safeguards such as the EU-U.S. Data Privacy Framework and, where required, Standard Contractual Clauses or other approved transfer mechanisms.
Where OpenStreetMap Foundation services are accessed directly, data may be processed in the United Kingdom and, for map tile delivery, through a global network of cache servers. The specific server accessed may depend on the content delivery network used at the time of the request.
For transfers to third countries, we take the measures required under Art. 44 et seq. GDPR, in particular by relying on adequacy decisions, Standard Contractual Clauses, Data Privacy Framework certifications or other legally recognized safeguards where applicable.
10. Retention Period
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, unless longer retention is required by law.
In particular, server log data is retained only for a limited period as described above, and inquiry data is retained until the inquiry has been resolved, unless statutory retention obligations apply.
11. Your Rights
Under the GDPR, you have the following rights, subject to the applicable legal requirements: the right of access, the right to rectification, the right to erasure, the right to restriction of processing, the right to data portability, and the right to object to processing based on Art. 6(1)(f) GDPR.
If you believe that the processing of your personal data violates data protection law, you also have the right to lodge a complaint with a supervisory authority.
12. Competent Supervisory Authority
The State Commissioner for Data Protection and Freedom of Information Rhineland-Palatinate
Hintere Bleiche 34
55116 Mainz
Germany
https://www.datenschutz.rlp.de/
13. No Automated Decision-Making
We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time, for example if legal requirements change or if we add new services to this website.