Ridgeline - Find the dirt

Privacy Policy

Effective date: March 30, 2026 · Last updated: March 30, 2026

1. Introduction

Welcome to Ridgeline ("we", "our", or "us"). We operate the website and service available at ridgeline.rocks — an adventure motorcycle route generator that helps riders plan and export off-road routes.

This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have over your data. Please read it carefully. By using Ridgeline, you agree to the practices described here.

For questions or requests, contact us at [email protected].

2. Information We Collect

2.1 Information you provide directly

DataWhen collected
Email addressWhen you create an account or reset your password
Password (hashed, never stored in plain text)When you create an account
Saved routesWhen you save a generated route to your account
Route waypoints and preferencesWhen you configure and generate a route

2.2 Information collected automatically

DataSourcePurpose
IP addressWeb server logsSecurity, abuse prevention
Browser type, operating system, device typeUser-agent stringAnalytics, compatibility
Pages visited, time on site, referring URLGoogle Analytics (via Google Tag Manager)Understanding how people use Ridgeline
Clicks and interactionsGoogle AnalyticsProduct improvement
Approximate geographic location (city/country level)Google Analytics (derived from IP)Aggregate usage insights

2.3 Device location (geolocation)

If you choose to use the "locate me" feature, your browser will ask for permission to share your precise device location. We use this only to center the map on your current position. We do not store your device location on our servers.

3. How We Use Your Information

We use the information we collect to:

  • Provide and operate the service — generating routes, saving them to your account, and serving the application.
  • Authenticate you — verifying your identity when you log in and sending password-reset emails.
  • Improve the product — analysing aggregate usage data to understand which features are used and where the experience can be improved.
  • Ensure security — detecting and preventing abuse, fraud, or unauthorised access.
  • Communicate with you — sending transactional emails (e.g. password reset). We do not send marketing emails unless you explicitly opt in.

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

4. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data under the following legal bases:

Processing activityLegal basis
Account creation and managementContract (Art. 6(1)(b)) — necessary to provide the service you signed up for
Sending password-reset emailsContract (Art. 6(1)(b))
Analytics via Google AnalyticsLegitimate interests (Art. 6(1)(f)) — we have a legitimate interest in understanding how our service is used; you may opt out (see Section 7)
Security loggingLegitimate interests (Art. 6(1)(f))
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))

5. Cookies and Tracking Technologies

Ridgeline uses the following cookies and similar technologies:

Cookie / technologyProviderPurposeDuration
_ga, _ga_*Google AnalyticsDistinguishes unique users and sessions for analytics2 years
Google Tag Manager scriptsGoogleLoads and manages analytics tagsSession
Session cookieRidgelineKeeps you logged inSession / persistent (based on "remember me")

You can control cookies through your browser settings. Note that disabling cookies may affect your ability to stay logged in.

We do not use advertising or third-party tracking cookies beyond Google Analytics.

6. Data Sharing and Third Parties

We do not sell your personal data. We share data only with the following trusted service providers, and only to the extent necessary:

ProviderPurposeLocation
CloudflareDNS, CDN, DDoS protection, security headersUSA (global CDN)
Google Analytics / Tag ManagerUsage analyticsUSA
ResendTransactional email delivery (account validation, password reset)USA

We may also disclose information if required by law, court order, or to protect the rights and safety of our users or the public.

7. Your Rights

7.1 Rights for everyone

Regardless of where you live, you may:

  • Access the personal data we hold about you.
  • Correct inaccurate data by updating your account settings or contacting us.
  • Delete your account and associated data by contacting us at [email protected].
  • Opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on or using your browser's privacy settings.

7.2 Additional rights under GDPR (EEA/UK residents)

You also have the right to:

  • Data portability — request a copy of your data in a machine-readable format.
  • Restriction of processing — ask us to pause processing your data in certain circumstances.
  • Object to processing — object to processing based on legitimate interests.
  • Lodge a complaint with your local data protection authority. In the EU, you can find your authority at edpb.europa.eu.

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

7.3 Rights under CCPA (California residents)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, disclose, or sell.
  • Delete your personal information (subject to certain exceptions).
  • Opt out of the sale of personal information — we do not sell personal information.
  • Non-discrimination — we will not discriminate against you for exercising your rights.

To submit a CCPA request, contact us at [email protected] with the subject line "CCPA Request". We will respond within 45 days.

8. Data Retention

We retain your data for as long as your account is active or as needed to provide the service. Specifically:

  • Account data (email, hashed password): Retained until you delete your account.
  • Saved routes: Retained until you delete them or your account.
  • Server logs: Retained for up to 90 days for security purposes.
  • Analytics data: Retained per Google Analytics' default retention settings (up to 26 months).

When you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it by law.

9. Data Security

We take reasonable technical and organisational measures to protect your data, including:

  • Passwords are hashed before storage (never stored in plain text).
  • All data in transit is encrypted using TLS (HTTPS enforced via HSTS).
  • HTTP security headers (CSP, X-Frame-Options, X-Content-Type-Options, etc.) are in place.
  • Access to production systems is restricted to authorised personnel.

No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at [email protected].

10. International Data Transfers

Ridgeline's infrastructure involves service providers based in the United States (see Section 6). If you are located in the EEA or UK, your data may be transferred to and processed in the USA. Where this occurs, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework, as applicable to each provider.

11. Children's Privacy

Ridgeline is not directed at children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at [email protected] and we will delete it promptly.

12. Links to Third-Party Services

The Ridgeline interface displays map tiles sourced from OpenStreetMap and related providers. We are not responsible for the privacy practices of third-party websites or services linked from our application. We encourage you to review their privacy policies.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify you by email (if you have an account) or by a prominent notice on the site.

Your continued use of Ridgeline after a change is posted constitutes your acceptance of the revised policy.

14. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy, please contact us at:

Email: [email protected]
Website: ridgeline.rocks