Legal and privacy
Privacy policy
This draft privacy policy maps the information used by the current storefront, account, checkout, monitoring, and trip workspace features.
Draft updated: July 23, 2026
1. Who controls your personal data
The controller is Martin Zbořil, Smrková 194/3, Strašín, 251 01 Říčany, Czech Republic, Czech business ID (IČO): 07520301; not registered for VAT.. For privacy questions or requests, email support@rovefold.com.
If a data protection officer or EU representative is appointed, their verified contact details must be added here before publication.
2. Categories and sources of data
- Account: name, email, verification state, password credential held by the server, and account status.
- Social sign-in: provider, provider account identifier, and profile details you approve, such as name, email, and avatar.
- Preferences: language, origin or citizenship selection, and workspace display choices.
- Orders: selected product, price and currency, order code, ownership, and transaction or accounting data returned by the Store service.
- Trip content: routes, dates, travelers, logistics, accommodation, notes, activities, checklists, reviews, attachments, and sharing settings you add.
- Support: messages, identifiers, screenshots, and other information you choose to provide when asking for help or exercising a right.
- Security and diagnostics: IP and request metadata processed by the server, device and browser information, error details, page or operation context, timestamps, and internal account ID used by error monitoring.
Most data comes directly from you or your device. Social sign-in providers supply the basic data you authorize. Product and trip data may also come from the Rovefold Store service or content already included in a purchased template.
3. Why we process data
| Purpose | Typical data | Legal basis |
|---|---|---|
| Create and secure an account; sign you in | Account, session, social sign-in, security data | Contract; legitimate interest in account security |
| Supply a purchase and trip workspace | Order, ownership, preferences, trip content | Contract |
| Save, export, and share a trip at your request | Trip content, attachments, sharing token | Contract; actions you request |
| Provide support and handle requests | Account, order, support communication | Contract; legal obligation; legitimate interest |
| Keep accounting and legal records | Order, transaction, invoice, complaint data | Legal obligation; legal claims |
| Detect errors, abuse, and security events | Diagnostics, request context, internal account ID | Legitimate interest in a reliable and secure service |
| Non-essential analytics or marketing, if introduced | Only data described at the time | Consent where required |
Providing account and order data is necessary to create an account, complete an order, and supply the workspace. Without it, those features cannot be provided. Optional profile, preference, and trip details can be omitted unless a specific feature needs them.
The current frontend does not describe automated decisions that produce legal or similarly significant effects. If that changes, this notice must explain the logic and consequences.
5. Public sharing links and third-party links
Trip workspaces are account-restricted by default. When you enable sharing, anyone with the generated link may be able to view the read-only trip snapshot, map, and export. Do not place confidential information, unnecessary personal data, identity documents, or private booking codes in content you share. You can disable sharing from the workspace.
Links to maps, accommodation, transport, attractions, or other websites take you to independent controllers. Review their privacy information before giving them data.
6. How long data is kept
Rovefold should keep data only for as long as needed for the purpose described. The final retention schedule must be verified before publication. The current draft uses these criteria:
- account and active workspace data: while the account and service relationship continue;
- browser cart and preferences: until cleared, replaced, or browser storage is removed;
- short-lived confirmation and support-session state: for the browser session or stated workflow;
- diagnostic events: for a limited operational and security period set in the monitoring service;
- support and complaint records: while the request is handled and for a justified claims period;
- purchase, invoice, and accounting records: for periods required by tax and accounting law;
- deleted data: until deletion propagates through protected backups under the backup schedule.
7. Your data protection rights
Depending on the processing and applicable law, you may request access, correction, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing.
Email support@rovefold.com. We may need proportionate information to verify identity. We normally respond without undue delay and within one month, subject to any lawful extension.
You may also complain to your competent supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů), uoou.gov.cz .
For account deletion steps, see Data deletion .
8. Security and browser storage
Current safeguards include encrypted transport, server-managed sessions, CSRF protection, access controls, email verification for important actions, optional social authentication, sanitized error monitoring, and restrictions on support impersonation. No online system is risk-free.
Rovefold uses essential cookies and browser storage for security and requested product functions. The Cookies & local storage notice lists the known categories and explains when consent would be required.
9. Changes to this notice
We may update this notice when the service, providers, or legal requirements change. We will show a new effective date and provide additional notice where a change materially affects users or a new consent is required.