Privacy Policy — Backcountry Beta Web Map
Last updated: July 12, 2026
Delete your account — how to delete your Backcountry Beta account and what happens to your data.
This policy describes how Backcountry Beta ("we", "us") collects and uses personal data on the Backcountry Beta website and web map at backcountry-beta.app. Separate policies cover the iOS app and the Android app.
Contact (data controller): Backcountry Beta — david@backcountry-beta.app
Summary
- You can browse the map without an account. If you create one, we collect account information (email, name, username).
- With your permission, we use your browser's location to center the map and to attach a location to observations you submit.
- The web map does not currently include any third-party analytics or advertising trackers, and we do not use tracking cookies.
- Our backend runs on Back4App (Parse) and Cloudflare; photos you upload are stored on Cloudflare R2.
- Content you choose to share — observations, trip reports, photos, public profile — is visible to other users.
- We do not sell your personal data, and we do not show ads.
Data we collect
Account data. When you sign up we collect your email address, a username and password (stored hashed), and optionally a display name. If you sign in with Google or Facebook, we receive your name, email address, and account identifier from that provider.
Location. With your permission, the web map uses your browser's geolocation to center the map on your position and to fill in the location of a field observation you are submitting (latitude, longitude, and elevation). Coordinates are stored on our backend only when you save an observation or other content that includes them. Tours you save or import (GPX files) contain a track of locations and are stored with your account.
Photos. Photos you attach to observations or trip reports are uploaded from your device. Photo metadata (capture date and GPS location embedded in the photo) may be read and stored with the photo so it can be placed on the map. Uploaded photos are stored on Cloudflare R2 at unlisted public URLs.
Content you create. Field observations, trip reports and notes, saved tours and GPX files you import, saved forecast points, custom zones, Condition Check questions and answers, and feedback you submit.
Usage data and identifiers. The web map stores functional state in your browser (localStorage), such as map position, layer settings, and saved filters, plus a randomly generated installation identifier used for sync and abuse prevention. We do not use tracking cookies and do not currently run any third-party analytics on the web map. When you submit feedback, your browser's user-agent string is included so we can reproduce problems. Our servers keep standard technical logs (IP address, request timestamps).
Payment data. Pro subscriptions purchased on the web use RevenueCat's hosted checkout, embedded from pay.rev.cat. Your payment details are entered on and processed by RevenueCat and its payment processor; we never see your card number. We receive subscription status (for example: trial, active, expired) linked to your account.
Third-party services we use
- Back4App (Parse Server) — hosts our database and backend (accounts, tours, observations, saved content). United States.
- Cloudflare — photo storage (R2), map-tile workers, and related infrastructure.
- RevenueCat — subscription management and hosted web checkout. RevenueCat receives an account identifier and purchase/subscription state; its checkout collects your payment details directly.
- Google Sign-In, Facebook Login — optional sign-in providers, used only to sign you in; each shares your name, email, and account identifier with us when you choose to use it, and loads that provider's sign-in script in your browser. We do not send usage or analytics information to these providers.
- OpenAI — powers AI features (Condition Check answers and zone summaries). Your question text and the relevant forecast/weather context are sent to OpenAI to generate the answer; we do not send your name or account details with these requests.
- Map, weather, and avalanche data providers — your browser requests data directly from third-party services as you use the map: map tiles from OpenStreetMap, USGS/The National Map, and Esri; slope and topo tiles from our Cloudflare services (Mapbox-derived); weather from the National Weather Service (weather.gov), USDA SNOTEL, and CoCoRaHS; avalanche data from avalanche.org, Avalanche Canada, CAIC, and other avalanche centers; elevation from USGS; place search from Photon (Komoot); and summit data from the Overpass API. These requests include your IP address and the map coordinates being viewed or searched. Open-source libraries are loaded from the unpkg and jsDelivr CDNs, which receive your IP address when the page loads.
We share personal data with these processors only as needed to run the Services. We do not sell personal data and do not share it with data brokers or advertising networks.
Content you share publicly
If you mark an observation or trip report as shared, it — including its location, photos, and text — is visible to other users, attributed to your public display name. Your public profile (display name, username, home state) is visible to other users. Uploaded photos are served from unlisted public URLs, which anyone with the link can open. You can unshare or delete your content at any time.
How we use data
To provide and sync the Services across your devices; to show your content on the map; to answer your Condition Check questions; to operate subscriptions and Pro features; to respond to feedback and provide support; to prevent abuse and enforce our terms; and to comply with legal obligations.
Legal bases (GDPR): performance of our contract with you (providing the Services), your consent (browser location, analytics where required), our legitimate interests (product improvement, abuse prevention, security), and compliance with legal obligations.
Where data is processed
Our backend providers process data in the United States. If you use the Services from outside the United States, your data is transferred to and processed in the United States.
Retention
Account data and content you save are kept until you delete them or delete your account. Server logs are retained for shorter operational periods. When you delete your account, your tours, observations, photos, saved content, sessions, and profile are deleted from our backend; residual copies in backups and logs are purged on their normal cycle. Functional browser storage stays on your device until you clear it.
Your rights and choices
- Location. Browser location access is optional and controlled by your browser; the map works without it.
- Access, correction, deletion, portability. You can access and edit your content on the web map. You can delete your account and its data from within the mobile apps or from the web map (click your user name and choose Delete account). You may also request a copy of your data. See Delete your account for step-by-step instructions.
- EU/UK users have the rights provided by the GDPR, including objection, restriction, withdrawal of consent, and complaint to your data protection authority. California residents have the rights provided by the CCPA/CPRA; we do not sell or share personal information as defined by that law.
Requests: email david@backcountry-beta.app. We respond within the time required by applicable law (at most one month for GDPR requests).
Children
The Services are not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided us personal data, contact us and we will delete it.
Changes to this policy
We will post any changes on this page and update the date above. If we add analytics to the web map in the future, we will update this policy first. Where required, we will ask for your consent.
(This policy supersedes the previous iubenda-hosted policy dated January 13, 2020.)