Trazo is a bike-route planning service operated by Arkalogy LLC ("we," "our," or "us"). This policy explains what information Trazo collects, how we use it, and the choices you have. We've tried to keep it plain and honest.
Information we collect
- Pseudonymous device identifier. When you use the app, our server sets a random identifier (the
trazo_idcookie, HTTP-only). It is not linked to your name (unless you create an account), but because it persists and we attach usage events to it, the data is pseudonymous rather than fully anonymous. It is used to associate your saved routes and submissions with your browser, and to distinguish returning from new sessions in aggregate. - Saved routes. If you save a route, we store the route's parameters (the start, destination, and any stops or preferences you entered) linked to your device identifier.
- Reports, suggestions, reviews & feedback. When you report a condition or hazard, suggest a place, leave a review, or send feedback, we store what you submit — the type or rating, any free-text note or message you write, the precise map location you select, and, if you choose to include it, your email address — linked to your device identifier or account. Approved reports, suggestions, and reviews are shown publicly on the map to other riders.
- Photos you submit. If you attach a photo to a report or suggestion, we store it. Location metadata (EXIF/GPS) is stripped in your browser before upload. Once a moderator approves it, the photo may be shown publicly on the map and in shared-link previews. You can ask us to remove a photo you submitted — see Your choices and rights.
- Waitlist email. If you submit your email on our landing page, we store that email so we can notify you about new features or cities.
- Account information. Trazo offers optional accounts so your saved routes and submissions can follow you across devices. You can sign in with Apple, Google, an email magic link, or an email and password. If you create an account, we store your email address and, depending on how you sign in, basic profile information from your sign-in provider (e.g., name). Accounts remain optional; when you first sign in, data tied to your browser identifier is migrated to your account.
- Device location ("Use my location"). Only if you tap "Use my location," your browser shares your device's GPS location with the app to place a point on the map and plan a route. This happens in your browser; we do not continuously track you and we do not store your device's GPS location on our servers. Precise location is sensitive information under California law. Note that this is separate from the map coordinate you deliberately select when you submit a report, suggestion, or review — that coordinate is stored with your submission and, once approved, shown publicly, as described above and under "Data retention."
- Usage & product analytics (aggregate, pseudonymous). To understand how the product is used and to support local advertising, we record events as you use the app — for example: a route was planned (with its distance, comfort level, and general area/corridor), a facility category was tapped, a search happened (and whether it resolved), and which features were used. We deliberately do not send your exact start/end coordinates, your full route, or your search text to our analytics tools — those are stripped before any event leaves your browser. This data is aggregated and tied to the pseudonymous identifier, not to your name. We use Google Analytics (high-level traffic) and Mixpanel (product usage) for this. We do not enable session recording.
- Approximate region. Our hosting provider tells our server the general region a request comes from (e.g., country/state). We use it only to gauge, in aggregate, whether riders in a market are local or visiting. We do not store your IP address as part of analytics.
- Technical data. Like most websites, our hosting provider automatically logs standard technical information (such as IP address and browser type) for security and reliability.
How we use information
- To provide core features — saving and reloading your routes, and showing community condition reports.
- To operate, maintain, secure, and improve the service.
- To understand product usage in aggregate — which routes, areas, and features riders use — so we can improve Trazo and decide where to expand.
- To support local advertising — we may share aggregate, de-identified insights with sponsors (e.g., "riders planned routes near your area"), never a profile of an individual rider and never a claim that a specific person visited.
- To contact you if you joined the waitlist.
- To comply with legal obligations.
Cookies and similar technologies
We use a minimal set of cookies:
- Functional: the
trazo_iddevice identifier described above, which makes saved routes and submissions possible. - Analytics: Google Analytics and Mixpanel cookies/identifiers to measure aggregate product usage.
We do not use cross-site behavioral advertising networks, and we do not record your screen. Our advertising support is based on aggregate usage, not individual ad-profiles.
Service providers
We do not sell, rent, or trade your information. We share it only with the providers that run the service, each under their own terms:
- Cloudflare — website hosting, content delivery, edge functions, and Cloudflare Web Analytics (a cookieless, no-PII measure of visits and referrers).
- Supabase — the database that stores saved routes, submissions, and waitlist emails, and that powers account sign-in.
- Resend — delivery of our emails (waitlist, submission acknowledgements, moderation notices, and account sign-in/verification emails); it receives the recipient's email address.
- Google and Apple — sign-in providers, if you choose to create an account with them.
- Google Analytics — high-level traffic analytics.
- Mixpanel — aggregate product-usage analytics (the events described above; session recording is disabled).
- Sentry — error monitoring (technical diagnostic data when something breaks, so we can fix it). Configured to minimize personal data; we do not route submission content, email addresses, or precise coordinates to it.
- OpenStreetMap, OpenFreeMap, and Photon (komoot) — map data, map tiles, and address search. When you pan the map, OpenFreeMap receives the corresponding tile request. Address search and reverse lookups are routed through our own server, which queries the Photon (komoot) geocoder on your behalf — so the geocoder receives the search text, not your device's IP address.
Data retention
We keep the information you submit for as long as it remains useful to the service, which may be indefinitely. You can delete your saved routes in the app at any time, and you can unsubscribe from or ask us to remove your waitlist email. Because anonymous data is tied to your browser's device identifier, clearing your cookies or switching browsers/devices will disconnect you from previously saved data.
- Submissions and the map coordinates attached to them (reports, hazard reports, place suggestions, reviews, and any note, email, or photo you attach): retained indefinitely so the community map stays useful — unless you request removal (see below).
- Aggregate, pseudonymous usage analytics (route/area/feature counts, with no precise location): retained on an ongoing basis as historical product data, since it does not identify individuals.
- Account data: retained while your account is active; you can request deletion of your account and its data.
Requesting removal. You can ask us to remove content you submitted (a report, suggestion, review, feedback, or photo), or to delete your account and its data, by emailing [email protected]. We review requests through our moderation process and honor verifiable requests as required by applicable law; we don't guarantee a specific turnaround. We may retain information where we have a legitimate need — for example, to operate or secure the service, resolve disputes, enforce our Terms, or comply with legal obligations.
Your choices and rights
Depending on where you live (including under laws such as the Colorado Privacy Act, GDPR, and CCPA), you may have rights to access, correct, or delete your personal information, or to opt out of certain processing. You can delete saved routes in the app, decline location access in your browser, and clear cookies at any time. For waitlist data or other requests, contact us at [email protected] and we'll help. Note that most app data is anonymous and tied to a device identifier rather than to an identifiable person.
Your California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, to access or delete it, to correct it, and to not be discriminated against for exercising these rights. The categories we collect are described above (pseudonymous identifiers, device/region data, aggregate usage, any saved routes/submissions you create, and — only if you provide it — your email and any precise location you choose to use).
Do Not Sell or Share My Personal Information. We do not sell your personal information for money. Because we use aggregate usage to support local advertising and analytics, some of this activity may be considered "sharing" or "sale" under California law. You can opt out of this analytics/advertising use at any time by enabling your browser's Global Privacy Control (GPC) signal, which we honor, or by emailing [email protected] with "Do Not Sell or Share." When you opt out, we stop sending your usage events to our analytics tools. (Insights we have already combined into aggregate, de-identified statistics — which cannot be traced back to any individual — are not personal information under California law and are not part of this opt-out.)
Limit the Use of My Sensitive Personal Information. Precise geolocation is "sensitive personal information." We do not store your device's GPS location from "Use my location" on our servers, and we never sell it. The one place we retain a precise coordinate is one you deliberately select when you submit a report, suggestion, or review — which is stored with that submission and, once approved, shown publicly (that is the purpose of a community map). To ask us to remove a coordinate or submission you provided, email [email protected] with "Limit Sensitive Information."
To make any request, contact [email protected]. We will not discriminate against you for exercising your rights.
Children
Trazo is not directed to children under 13, and we do not knowingly collect personal information from them.
Security
We use reasonable technical measures to protect information, including keeping database credentials server-side and locking direct database access. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Governing law
Arkalogy LLC is organized under the laws of the State of Colorado, USA, and this policy is governed by Colorado law.
Changes to this policy
We may update this policy from time to time. Changes will be posted here with a new "Last updated" date.
Contact
Questions about privacy? Email [email protected].