Back to Home

🛡️ PRIVACY POLICY

Last updated: January 2026

Welcome to Trodbox. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our travel platform for routes, events, and community features. By using Trodbox, you agree to the practices described in this policy. If you disagree, please discontinue use of the service. Note: This policy is currently under legal review. The final version may include adjustments.

1. Data Controller

The data controller for this website is Michele Carpenzano, NIF Y2282929D, La Línea de la Concepción (Cádiz), Spain. For full contact details, please see our Legal Notice.
Aviso Legal

2. Information We Collect

We collect the following types of information: • Account information: email address, full name, password (encrypted) • Profile information: profile picture, vehicle preferences, language preference • Location data: city, country, region, GPS coordinates (when you opt in) • Content: routes, photos, events, chat messages, comments • Usage data: pages visited, features used, interaction patterns • Technical data: IP address, browser type, device type, operating system • Payment data: handled by Stripe (we do NOT store credit card details)

3. How We Use Your Information

We use your information to: • Provide the Trodbox service (routes, events, community features) • Process payments and subscriptions • Personalize your experience (match content to your vehicles) • Communicate important updates • Improve our service and develop new features • Comply with legal obligations • Prevent fraud and abuse • Automatically screen public content (display names, full names, route/event titles and descriptions) for offensive language, to keep the community safe — analysis is automated, moderation decisions are made by a human • Send marketing communications (only with your consent)

4. Legal Basis for Processing (GDPR)

Under GDPR, we process your data based on: • Consent: for marketing emails, cookies, location services • Contract performance: to provide the service you signed up for • Legitimate interests: for security, fraud prevention, service improvement • Legal obligations: tax records, regulatory compliance

5. Data Sharing & Third Parties

We share data only with: • Supabase (database hosting, EU-based) • Stripe (payment processing, certified PCI-DSS) • ImageKit (image storage and CDN) • Vercel (web hosting) • Nominatim/OpenStreetMap (geocoding services) • Google AdSense (advertising, optional) • Anthropic (AI-based automated screening of public profile/content text for offensive language) We do NOT sell your personal data to anyone. All third parties are GDPR-compliant.

6. Data Retention

We retain your data for: • Active accounts: as long as your account is active • Deleted accounts: 30 days for backup recovery, then permanently deleted • Financial records: 7 years (legal requirement) • Analytics: anonymized after 14 months • Chat messages: deleted with the related event/conversation You can request immediate deletion at any time.

7. Your Rights (GDPR)

You have the right to: • Access: request a copy of your data • Rectification: correct inaccurate data • Erasure: request deletion ("right to be forgotten") • Portability: receive your data in machine-readable format • Object: opt out of certain processing • Restrict: limit how we use your data • Withdraw consent: at any time • Lodge a complaint with your local data protection authority To exercise these rights, email: trodbox@gmail.com (response within 30 days)

8. Cookies & Tracking

We use cookies for: • Essential: authentication, session management (always active) • Functional: language preferences, UI state • Analytics: anonymous usage statistics (with your consent) • Marketing: ad personalization (with your consent) You can manage cookie preferences via the Cookie Banner shown on first visit, or your browser settings.

9. Data Security

We protect your data with: • HTTPS/SSL encryption for all data transmission • Encrypted password storage (industry standard hashing) • Database access controls and Row-Level Security • Regular security audits • Stripe PCI-DSS compliance for payments • Limited access to authorized personnel only Despite our efforts, no system is 100% secure. We will notify users within 72 hours of any data breach affecting personal data.

10. International Data Transfers

Your data may be transferred outside the EU/EEA, but only to providers with adequate protection (Standard Contractual Clauses or Adequacy Decisions). Main data centers: EU (Frankfurt) for Supabase, US (Stripe processing). All transfers comply with GDPR Chapter V.

11. Children's Privacy

Trodbox is intended for users 18 years and older. We do not knowingly collect data from minors. If we discover a minor has registered, we will delete the account immediately. Parents/guardians can contact us at trodbox@gmail.com.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification. Continued use after changes implies acceptance. The "Last updated" date at the top reflects the current version.

13. Disclaimer & Policy Updates

This Privacy Policy may be updated periodically based on: • Legal counsel review • User feedback • Regulatory changes • Service feature additions We encourage users to review this policy periodically. Major changes will be notified via email.

📧 CONTACT US

For any privacy-related questions, requests, or concerns, contact us at:

Contact