1. Controller
The controller for processing personal data in the TapRun app and on this website is:
Waldemar Friesenhandelnd unter e12.media
Eichweg 12
71254 Ditzingen
Deutschland
Email: legal@e12.media
2. In short
- TapRun does not require a user account.
- TapRun contains no advertising and uses no advertising or hardware identifier.
- We use location data only to build routes, render the map and navigate, not for profiling, tracking or advertising.
- Routing, elevation data and maps come from services we operate ourselves.
- Run history, settings and downloaded maps stay on your device.
3. Location data
To build routes, render the map, navigate with turn prompts and detect deviations, TapRun processes your precise location on the device. The app needs background location only while a navigation is running; the purpose is explained in the operating system’s permission prompt.
The legal basis is Art. 6(1)(b) GDPR (providing the app function you use) together with the permission you grant in the operating system. You can withdraw it at any time in the system settings; building routes at your current location is then no longer possible.
4. Routing and elevation services
For the route search the app sends coordinates (start point and waypoints) and elevation requests via routing.taprun.app to the routing and elevation services we operate. They run on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, in the Helsinki data center (Finland, EU). Hetzner processes the data as a processor.
The web servers’ access logs use a reduced format without IP address, URL, query, referrer or user agent. What remains is time, HTTP method, status code, response size and request and processing duration. Technically required error and security logs may contain additional connection data when an error occurs. Logs rotate daily and are kept for 14 rotations.
The legal basis is Art. 6(1)(b) GDPR; for security and error logs, Art. 6(1)(f) GDPR (secure and stable operation of the services).
5. Maps
The visible base map and the tiles needed for route calculation are loaded by the app from tiles.taprun.app, also from our servers at Hetzner in Finland. The requested tile identifiers reveal an approximate region. The app does not fetch map tiles from OpenStreetMap; OpenStreetMap is a data source, not a recipient of map or location requests.
When you explicitly start a route, TapRun downloads the map area of the route for both themes into local storage so you can use the route without signal. This storage is not transferred to cloud backups or new devices. Map data © OpenStreetMap contributors, map design based on OpenMapTiles.
6. Data on your device
Run history, settings and downloaded map and elevation data stay on the device. You remove them by deleting the app.
7. Diagnostics (optional)
Detailed diagnostics are off by default. You switch them on deliberately only for an agreed test. A package with precise GPS, navigation, error and performance data and a random installation code is then created locally for each run. Nothing is uploaded automatically. You decide whether and to whom you send the package using the operating system’s share function.
The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by switching diagnostics off.
8. Report a problem (optional)
If you send a problem report from a test version, we receive your description, a screenshot of the original app view, the available precise location, routing and navigation state, app, build and device data and existing diagnostic events only after you deliberately press “Send”. Drafts stay on the device. TapRun does not record audio.
The recipient is a service we operate at Hetzner in Finland. Reports are removed from the server after 30 days at most. You can delete individual reports and withdraw your consent; existing reports are then deleted. After losing a device, legal@e12.media helps you on a verified request.
The legal basis is your consent (Art. 6(1)(a) GDPR).
9. This website
This website is served as a static site via Appwrite Sites (Appwrite Code Ltd.; project in the Frankfurt region). On every request Appwrite processes technically required connection data, in particular IP address, date and time, path, status code and browser information, and keeps access logs for seven days on the Pro plan. The legal basis is Art. 6(1)(f) GDPR; Appwrite acts as a processor. More information: Appwrite’s privacy policy.
The website sets no cookies, runs no analytics, uses no marketing trackers and loads no external fonts. The language follows from the requested URL and is not stored.
If you email us, we process your address and message to handle your request (Art. 6(1)(b) or (f) GDPR). Our email runs through Microsoft 365 (Microsoft Ireland Operations Limited, Dublin, Ireland) as a processor. We delete requests once they are resolved and no statutory retention duty applies.
10. Your rights
Under the statutory conditions you have the right of access, rectification, erasure, restriction of processing, data portability and the right to object to processing under Art. 6(1)(f) GDPR. You can withdraw consent with effect for the future. Write to legal@e12.media. You may also lodge a complaint with a data protection authority, in particular at your place of residence, work or the place of the alleged infringement.
We use no automated decision-making and no profiling.
11. Changes
If the app, the services we use or legal requirements change, we will update this policy, in particular before in-app purchases are introduced. The version published here applies.