Privacy Policy
Last updated: September 20, 2026
This Privacy Policy explains how Camino.Today collects, uses, stores, shares, and protects your personal data when you use the Camino.Today mobile application (the "App"), the website at camino.today (the "Website"), and related services (together, the "Service"). Please read it together with our Terms of Use.
1. Who We Are (Data Controller)
The Service is operated by Arkadii Broun, an individual, …("we", "us", "our"). We are the data controller for the personal data described in this Policy.
For any privacy-related question or request, contact ….
We are established in Israel, a country recognised by the European Commission as providing an adequate level of data protection. We have not appointed a separate representative in the European Union; you can reach us directly at the email address above for all matters covered by the EU General Data Protection Regulation ("GDPR").
2. Scope and Age Requirement
This Policy applies to everyone who uses the App, visits the Website, subscribes to our mailing list, or contacts us. The Service is intended for adults aged 18 and older. By creating an account you confirm that you are at least 18. We do not knowingly collect personal data from anyone under 18.
3. Personal Data We Process
Depending on how you use the Service, we may process the following categories of personal data.
3.1 Account and profile data
- data received from your sign-in provider when you sign in with Apple or Google: name, email address (which may be an Apple "Hide My Email" relay address), profile photo (if provided), and a provider user identifier;
- your Camino.Today user identifier, display name, profile photo, and country as shown in the App;
- account settings and preferences (for example language, units, notification choices).
3.2 Location data
- your device's geographic coordinates, accuracy, and timestamps while the App is in use (foreground) and you are within about 2 km of your selected route;
- derived data such as your position on a route, the route stage you are on, and distance walked.
See Section 6 for details on how location data is used, stored, and who can see it.
3.3 Content you create
- messages you post in route-based group chats;
- direct messages you exchange with other users;
- problem reports and other feedback you submit about accommodation listings or the Service;
- reports you file about other users or content, and users you block.
3.4 Purchase and subscription data
- subscription status, product identifier, purchase and renewal dates, and transaction identifiers provided by Apple App Store or Google Play;
- promo codes you redeem and the resulting access period;
- records of voluntary donations made through in-app purchase.
We never receive or store your payment card details. Payments are processed entirely by Apple or Google.
3.5 Device, technical, and usage data
- device model, operating system version, App version, language, and time zone;
- IP address and approximate region derived from it;
- push notification tokens (Apple Push Notification service and Firebase Cloud Messaging);
- crash reports, error logs, and diagnostic data;
- App interaction events (for example screens opened and features used).
3.6 Website data
- if you leave your email on the Website (for example to receive a promo code or a launch notification): your email address, the date and time of sign-up, and your confirmation of the sign-up (double opt-in);
- Website analytics data collected through cookies and similar technologies, including pages viewed, clicks, referring page, and device and browser information (see Section 15).
3.7 Communications
- emails and support requests you send us, and our replies;
- service messages we send you in the App (for example a reply from support).
4. Where the Data Comes From
We receive data directly from you (when you sign in, create content, make purchases, or contact us), automatically from your device and the App (location, technical, and usage data), from Apple and Google (sign-in and purchase data), and from other users (for example when they report or message you).
5. Purposes and Legal Bases
We process personal data only where we have a legal basis to do so. Under the GDPR the relevant bases are:
- Performance of a contract (Article 6(1)(b)): creating and managing your account, providing routes, maps, accommodation listings, chats, direct messages, subscriptions, promo codes, and support.
- Consent (Article 6(1)(a)): accessing your device location, sending push notifications, sending marketing emails from the Website, and non-essential Website cookies. You can withdraw consent at any time as described in Section 12.
- Legitimate interests (Article 6(1)(f)): keeping the Service secure, preventing abuse and fraud, moderating content, handling reports, diagnosing errors, understanding how the Service is used, improving it, and defending legal claims. We balance these interests against your rights and do not rely on this basis where your interests override ours.
- Legal obligation (Article 6(1)(c)): complying with laws that apply to us, including tax, accounting, and responding to lawful requests from authorities.
Where the laws of your country require a different or additional basis (for example the Israeli Protection of Privacy Law), we rely on the closest equivalent basis under that law.
6. Location Data (Important)
Location is central to the Service. The App uses your device location only in the foreground, that is while you are actively using the App. We do not track your location in the background or when the App is closed.
We use location data to:
- show your position on the map and along the route;
- calculate progress, distances, and the stage you are on;
- show you weather for your current position and upcoming stages;
- show accommodation and points of interest near you;
- show your progress along the route you have selected;
- investigate abuse, safety incidents, and technical problems.
Storage. Location updates are sent to and stored on our servers, together with a timestamp, only while you are within about 2 km of the route you have selected. When you are further away from the route, your location is used on your device only and is not sent to or stored by us, even if the App is open. Stored location history is kept until you delete your account, at which point it is deleted together with the account (see Section 13).
Who can see it. Your position history is visible only to the operator of the Service for the purposes listed above. It is not shared with other users. Other users cannot see your location or your movement history. Route chats are not tied to your location: being a member of a route's chat does not mean you are on that route.
The App requires location permission to function. If you deny or revoke it in your device settings, most features will not work, but you can continue to use the App in a limited way.
7. Chats, Direct Messages, and Moderation
Each route has a group chat. When you select a route in the App you are automatically added to that route's chat, and you can also join the chat of any other route. Messages in group chats are visible to all members of that chat, together with your display name, profile photo, and country flag. Direct messages are visible to you and the recipient. Messages are stored on our servers so they can be delivered and displayed on your devices.
Messages are not end-to-end encrypted. We may access message content when it is reported by a user, when we detect a likely violation of the Terms, when required by law, or when necessary to protect the safety of users. We may also use automated tools to filter spam and prohibited content.
The operator may send you service messages inside the App (for example a reply to a support request or a safety notice). These are not marketing messages.
8. Push Notifications
With your permission, we send push notifications about new chat and direct messages, weather alerts, support replies, and important service information. Notifications are delivered through Apple Push Notification service and Firebase Cloud Messaging. You can turn notifications off at any time in your device settings.
9. Sharing Features
When you share an accommodation page from the App, the link you share may include your display name and profile photo so that the recipient can see who sent it. Anyone who receives or opens that link can see this information. Share links only with people you trust.
10. Service Providers and Other Recipients
We share personal data only with providers that help us operate the Service, and only to the extent needed. They act on our instructions under data processing agreements, or as independent controllers where noted.
- Amazon Web Services (AWS), EU (Frankfurt) region: hosting of our servers and databases, and storage of accommodation photos.
- Google / Firebase: sign-in with Google, Firebase Authentication, storage of profile photos, Firebase Cloud Messaging, and Cloud Functions. Google is an independent controller for your Google account.
- Apple: Sign in with Apple, App Store purchases and subscriptions, and Apple Push Notification service. Apple is an independent controller for your Apple ID and purchases.
- Mapbox: map rendering. When the map loads, your device requests map tiles from Mapbox, which receives your IP address and the map area being viewed.
- Microsoft (Azure Maps Weather): weather forecasts. Coordinates of the location for which a forecast is requested are sent to Microsoft.
- Sentry: crash reporting and error diagnostics (device and App information, error context, and a pseudonymous user identifier).
- Yandex Metrika: Website analytics (see Section 15). Not used inside the App.
- Mailjet: Website email sign-up and sending of promo codes and launch notifications.
We may also disclose personal data:
- to other users, to the extent you choose to share it (profile, messages, share links);
- to comply with a law, regulation, court order, or lawful request from a public authority;
- to enforce our Terms, protect our rights, or protect the safety of any person;
- to a successor in the event the Service or its assets are transferred to another operator, who will be bound by this Policy.
We do not sell personal data and we do not share it with advertising networks.
11. International Data Transfers
Our servers are located in the European Union. We, the operator, access data from Israel, which benefits from a European Commission adequacy decision. Some providers listed above process data in the United States or other countries. Where this involves data of users in the European Economic Area, the United Kingdom, or Switzerland, we rely on the provider's certification under the EU-US Data Privacy Framework or on Standard Contractual Clauses approved by the European Commission, together with additional technical and organisational safeguards.
12. Your Rights and Choices
Subject to applicable law, you have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate or incomplete data;
- delete your data ("right to be forgotten");
- restrict or object to processing, including processing based on legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting processing carried out before withdrawal;
- not be subject to a decision based solely on automated processing that has legal or similar effects;
- lodge a complaint with a data protection authority, in particular in the EU/EEA member state of your residence or workplace, or with the Israeli Privacy Protection Authority.
How to exercise these rights:
- location and notifications: change the App's permissions in your device settings;
- profile data: edit it in the App;
- account deletion: use the delete-account option in the App settings, or email us;
- marketing emails: use the unsubscribe link in any email;
- all other requests: email ….
We respond to requests within 30 calendar days. We may ask you to verify your identity before acting on a request. We do not discriminate against you for exercising your rights.
13. Data Retention
We keep personal data only as long as necessary for the purposes described above:
- account and profile data: until you delete your account;
- location history (while near your route): until you delete your account;
- group chat messages and direct messages: until you delete your account;
- problem reports and abuse reports: until resolved, then up to 12 months for audit purposes;
- purchase and subscription records: as long as required by tax and accounting law (typically 7 years);
- crash reports and technical logs: up to 90 days;
- usage analytics: up to 24 months, in aggregated or pseudonymised form where possible;
- Website mailing list: until you unsubscribe or 24 months after the last interaction;
- support correspondence: up to 24 months after the request is closed.
When you delete your account, everything linked to it is deleted: your profile and photo, location history, group chat and direct messages, reports, and identifiers. The only exceptions are records we are legally required to keep (for example purchase records held for tax purposes, which contain no location or message content) and records needed to enforce a ban or to handle an ongoing dispute.
14. Data Security
We apply technical and organisational measures appropriate to the risk, including encrypted connections (TLS), access controls, authentication of all administrative access, logging, and hosting with certified providers. No method of storage or transmission is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that is likely to result in a high risk to you, we will notify you and the competent authority as required by law.
15. Website Cookies and Analytics
The Website uses Yandex Metrika to understand how visitors use it. Yandex Metrika sets cookies and collects pages viewed, clicks, referring page, and device and browser information. We do not use session recording. We use this data in aggregate to improve the Website. You can block analytics cookies in your browser settings or with a browser extension; the Website works without them. Analytics is not used inside the App.
The Website may also use strictly necessary cookies and local storage needed for it to function. Third parties such as the App Store badge or embedded forms may set their own cookies under their own policies.
When you save a place to sleep with the heart on a lodging card, or switch a filter on the lodgings list, the Website stores that choice in your browser’s local storage. It stays on your device, it is not sent to us, and it is not linked to any account — clearing your browser data removes it. Saved places on the Website are separate from the ones you save in the App.
16. Children
The Service is not directed to children, and we do not knowingly process personal data of anyone under 18. Accounts found to belong to a person under 18 may be terminated.
17. Public Content and Safety
Anything you post in a group chat can be seen by everyone in that chat, and messages can be copied or forwarded by their recipients. Please do not share sensitive information (such as your exact accommodation, travel plans, health details, identity documents, or financial information) in chats or with people you do not know. Use the report and block features if someone makes you uncomfortable.
18. Changes to This Policy
We may update this Policy from time to time. The current version is always available at camino.today/privacy and takes effect on the "Last updated" date shown above. If a change materially reduces your rights or introduces a new purpose, we will notify you in the App or by email before it takes effect and, where required, ask for your consent.
19. Contact
For privacy questions, requests, or complaints, contact … or write to Arkadii Broun, ….