Privacy Policy
How Refuge collects, uses, shares, and protects your personal data when you use our website and apps, and the rights you have under the GDPR.
Last updated: 28 June 2026
This Privacy Policy explains how Refuge ("Refuge", "we", "us") processes personal data when you use the Refuge website (refuge.camp) and mobile apps (together, the "Service"). It is written to comply with the EU General Data Protection Regulation (GDPR).
Data controller. The Service is operated by Refuge. The legal entity, registered address and registration number will be specified here before production launch. For any privacy question you can contact us at contact@refuge.camp.
1. What data we collect
We only collect data we need to run the Service. We do not sell your data.
Account data
When you create an account we store:
- your email address and a display name;
- optionally a first name, last name, username (public handle), bio and profile picture;
- your language preference;
- the answers to the optional onboarding questionnaire (main activity, experience level, frequency, preferred accommodation, how you discovered us);
- your subscription status (whether you have a premium plan and its expiry).
If you sign in with a third party (Apple or Google), we receive your email and name in order to create or link your account. We never receive your password from these providers.
Content you create
The Service is community-driven, so it stores the content you contribute and links it to your account:
- photos you upload for a refuge;
- comments and the people you @mention;
- field reports ("comptes-rendus de passage") about a refuge's condition;
- favorites, visited marks and any private notes you attach to a refuge;
- itineraries you draw or complete;
- the people you follow and who follow you;
- your search history (the query, the type of search and which result you opened), used to show your recent searches.
Technical and session data
When you sign in we record, for security and fraud-prevention purposes:
- your IP address and user-agent (browser/app identifier);
- your country, derived from your IP address at the network edge (we store only the two-letter country code, never a precise location);
- session tokens and timestamps.
We use the country and a web/mobile classification (derived from the user-agent) only in aggregate, to understand where and how the Service is used in our internal admin dashboard.
Analytics
The Service is built to support privacy-friendly product analytics (PostHog). Analytics are not enabled in our current production configuration. If we enable them, we will update this policy and, where required, ask for your consent first.
2. Why we use your data (legal bases)
| Purpose | Legal basis (GDPR Art. 6) | | --------------------------------------------------------- | ----------------------------- | | Creating and managing your account, providing the Service | Performance of a contract | | Hosting your photos, comments, reports and itineraries | Performance of a contract | | Securing accounts, preventing abuse and fraud | Legitimate interest | | Understanding usage in aggregate to improve the Service | Legitimate interest | | Processing premium subscriptions and payments | Performance of a contract | | Sending you service or, if you opt in, marketing emails | Consent / Legitimate interest |
You can object to processing based on legitimate interest at any time (see your rights below).
3. Who we share data with
We share data only with service providers ("sub-processors") that help us run the Service, under contracts that require them to protect it:
- Supabase — database hosting (servers in the EU, region eu-west-3);
- Cloudflare — application hosting (Workers) and media storage (R2);
- Resend — transactional and account emails;
- Mapbox — map display;
- RevenueCat — managing in-app subscriptions (mobile);
- Stripe — payment processing.
We may also disclose data where required by law, or to protect the rights and safety of our users and the Service.
4. International transfers
Our primary database is hosted in the European Union. Some sub-processors (for example Cloudflare, Stripe, RevenueCat, Mapbox) may process data outside the EU. Where that happens, transfers are protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
5. How long we keep your data
We keep your account data for as long as your account is active. Content you publish remains available until you delete it or your account. Session and technical logs are kept for a limited period for security purposes. When you delete your account, we delete or anonymise your personal data, except where we must retain certain records to comply with legal obligations.
6. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten");
- restrict or object to certain processing;
- data portability — receive your data in a portable format;
- withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, email contact@refuge.camp. You also have the right to lodge a complaint with your local data protection authority (in France, the CNIL — cnil.fr).
7. Security
We use encryption in transit, access controls and reputable infrastructure providers to protect your data. No system is perfectly secure, but we take reasonable measures to keep your information safe.
8. Children
The Service is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us so we can remove it.
9. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you.
10. Contact
For any question about this policy or your personal data, contact us at contact@refuge.camp.