Privacy Policy

Last updated: 27 July 2026

Data controller

Plot is operated by Alexander Jakub Moravčík
Registered address: Pionierska 338/20, Šaľa, 92701, Slovakia
Registration: Private individual — not registered as a business; no IČO. This operator is the data controller under Regulation (EU) 2016/679 (GDPR). Contact: privacy@acronym.sk

Age requirement

Plot is intended for users aged 16 and over. By creating an account you confirm you meet this requirement. If you become aware that a person under 16 has registered, contact privacy@acronym.sk and we will review and delete the account where required.

What we collect, why, and the legal basis

Name and email address — to create and identify your account, authenticate you and support recovery-code based password reset. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Agreement records — the date and published version of the Terms you accepted and the Privacy Policy shown when you created an account, opened a demo, joined as a guest or converted a guest session. We keep this with the account to administer the agreement and demonstrate what notice was presented. Legal basis: performance of a contract and legitimate interests (Art. 6(1)(b) and (f) GDPR).

Marketing preference — whether you separately ticked the optional box for occasional trip tips or product updates, together with the time and signup surface where that choice was recorded. Unticked is the default. Legal basis: consent (Art. 6(1)(a) GDPR); you may withdraw it at any time.

Trip data (spots, expenses, notes, lists, polls, documents, photos and member activity) — to provide the collaborative trip service. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).

Operational request and error records — request ID, route, method, response status, timing, account ID when authenticated, and technical error details. We use these to secure, diagnose and maintain Plot. Persistent error records are retained for up to 90 days; deployment process logs follow the hosting environment's log-rotation policy. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).

Limited product-usage events — for example, whether the landing page, invite or recap route opened; broad referral source; selected calls to action; and completion of core steps such as demo start, signup, trip creation, invite join or recap sharing. A random page-session identifier is kept only in memory. When you are signed in, an event may also be associated with your account ID on Plot's server. Events exclude passwords, recovery codes, document contents, expense line items and precise live-location coordinates. Raw product events are retained for up to 180 days and used to find broken journeys and improve the service, not for advertising or cross-site profiling. Legal basis: legitimate interests (Art. 6(1)(f) GDPR).

Live location (only if you enable sharing) — your latest coordinates are shown to members of the active trip. Plot also stores a breadcrumb at most once every five minutes for proximity nudges and derived recap insights. Off by default. Legal basis: consent (Art. 6(1)(a) GDPR).

Push subscription details (only if you enable notifications) — the browser push endpoint and encryption keys needed to deliver requested notifications. Legal basis: consent (Art. 6(1)(a) GDPR).

We do not collect advertising identifiers or sell activity data.

How your data is stored

Account and trip data are stored in PostgreSQL. Uploaded documents and photos may be stored in configured S3-compatible object storage. Passwords and recovery codes are hashed and are not stored in plain text. Browser sessions use a signed token in an HttpOnly cookie, so the token is unavailable to page JavaScript.

Place search, weather, maps and live location

Place search and weather are powered by Google Maps Platform and proxied through Plot's server. Google receives Plot's server request, the search term or coordinates, and the applicable API credentials rather than your device IP for those proxied calls. Normalised place-search terms and responses may be cached for up to 24 hours; weather coordinates and responses may be cached for up to 3 hours.

The interactive Google map loads directly in your browser. Google therefore receives information directly from your device, including your IP address and map interaction data, and handles it under Google's privacy policy and Google Maps Platform terms.

Live location sharing is off by default, and Plot does not request device coordinates until you enable it for an active trip. Once enabled, the latest point is sent to Plot and shown to that trip's members. While sharing is active, Plot also stores a breadcrumb no more often than once every five minutes. The raw trail stays server-side and is used for proximity nudges and compact recap insights. Sharing runs only while Plot is open and pauses when the app is closed or backgrounded. Turning sharing off withdraws consent and deletes your live markers and breadcrumb trail across your trips; account or trip deletion also removes them.

Cookies and browser storage

After sign-in, Plot sets one essential session cookie named plot_session. It is HttpOnly, SameSite=Lax, Secure in production and valid for up to 7 days after the latest active session.

Plot also uses localStorage for requested preferences, dismissed notices, a marker that the landing intro has already played and a non-secret cached copy of account and trip state; IndexedDB for queued offline writes; Cache Storage for the installable app shell and static assets; and sessionStorage for temporary navigation, guest and game state. This storage supports authentication, continuity and the offline service.

Acquisition measurement does not write an analytics identifier to cookies, localStorage, IndexedDB or sessionStorage. Its random identifier exists only in page memory and disappears on reload. Plot does not embed advertising pixels or third-party analytics scripts.

Data sharing and service providers

We do not sell or rent personal data, and we do not share it for third-party advertising. Trip content is visible to the members invited to that trip.

Hosting, database, cache, email-delivery and object-storage providers may process the limited data needed to operate Plot under the operator's instructions. If optional Google Cloud Vision photo moderation is configured, the selected uploaded image is sent to that service for safety analysis.

Google Maps Core Services receive end-user data directly when the interactive map loads. Proxied place and weather requests send the search term or coordinates from Plot's server. If you choose Google or Apple sign-in, the selected identity provider processes the sign-in interaction and Plot receives the provider account identifier and profile data you authorise. These providers may process data outside the EEA under their own terms and applicable transfer safeguards.

Limited product-usage events may be sent to Plot's separately operated event service when enabled. The payload is restricted to operational and product fields and is not supplied to advertising networks.

Data retention and deletion

Registered account and trip data are kept while the account or shared trip remains active. Disposable demo sessions become eligible for cleanup after 24 hours without activity. Name-only invite guest sessions use a sliding 90-day inactivity window and are retired only after their real trips have ended; direct identifiers and access credentials are then removed while historical trip attribution may remain. Account deletion is applied to the active database immediately: sole-member trips are deleted; shared trips remain available to their other members. Where shared expense or settlement records require the former member to remain in the accounting roster, login credentials and direct account identifiers are removed and the person is displayed as 'Former traveller'. An internal roster identifier remains solely to preserve historical payer, split and settlement attribution; otherwise the membership is removed.

Files belonging to deleted trips are placed in a durable object-storage deletion queue and retried until removed. Disaster-recovery backups, where configured by the operator, are isolated from normal use and expire under the deployment's backup-rotation schedule.

Raw product events are retained for up to 180 days and persistent error records for up to 90 days. Aggregated counts may be kept longer after they can no longer reasonably be linked to an account or page session. Device-local data remains until logout removes account and trip state, the app replaces it, or you clear Plot's site data in your browser.

Your rights under GDPR

You may have the right to:
• Access — request a copy of personal data held about you. 'Export current trip' is a convenience download of the account and trip currently loaded in the app; contact us for a broader rights request covering other server-held records.
• Rectification — correct inaccurate data.
• Erasure — delete your account and request deletion where applicable.
• Restriction — ask us to pause processing while a dispute is resolved.
• Portability — receive data you provided in a machine-readable format.
• Objection — object to processing based on legitimate interests, including operational telemetry and product measurement.
• Withdraw consent — stop live-location sharing, notifications or optional marketing at any time without affecting earlier lawful processing.

To exercise a right, contact privacy@acronym.sk. We will respond without undue delay and normally within one month.

Right to lodge a complaint

If you believe we have not handled your personal data in accordance with GDPR, you may lodge a complaint with the Slovak data protection supervisory authority:

Úrad na ochranu osobných údajov Slovenskej republiky (UOOU SR)
Galvaniho Business Centrum II
Galvaniho 7/B, 821 04 Bratislava, Slovak Republic
Tel: +421 2 3231 3214 or +421 2 3231 3249
Email: statny.dozor@pdp.gov.sk
Web: dataprotection.gov.sk

Automated decision-making

Plot does not use personal data for automated decisions that produce legal or similarly significant effects. Automated spam, abuse or photo-safety checks may flag content for technical handling, but they are not used for advertising profiles or legally significant decisions about you.

Changes to this policy

Material changes to personal-data processing will be explained in the app before they take effect where required. Non-material corrections may be made without a separate notice. The date shown at the top records the latest revision.

Contact

Data-protection questions and rights requests: privacy@acronym.sk