Privacy Policy
Last updated: 14 September 2026
Who we are, and what this covers
ZSAMM (“we”, “us”) is a mobile app for finding group rides, runs and training partners, operated from Germany. We are the controller for the personal data described here.
This policy covers both the ZSAMM mobile app for iOS and Android and the website at zsamm.cc — including the public activity pages at zsamm.cc/a/… and the club invite and club pages at zsamm.cc/c/… and zsamm.cc/club/….
The controller is:
Jesús Redondo Filloy
Bahnhofstraße 19D
82024 Taufkirchen
Germany
Contact for anything privacy-related: hello@zsamm.cc. Full provider details are in the Impressum.
What the app collects, and why
ZSAMM is built to collect as little as the core loop needs — find an activity nearby, join it, see who else is going. There is no advertising, no profiling, and no analytics or tracking SDK in the app. The one thing we collect that isn’t part of that loop is a crash report when the app crashes — described below, and switchable off.
Your account.You sign in with an email magic link, Google, or Apple — we never see or store a password. We store your email address and an account identifier so the account exists across devices and app restarts. If you use Sign in with Apple and choose to hide your address, we only ever receive Apple’s private relay address. Basis: performance of our contract with you (Art. 6(1)(b) GDPR).
Your profile. Display name, an optional photo or avatar colour, the sports you do, your home city, and an optional short bio. You choose all of it, and it is visible to other signed-in users — see section 03. Home city is a free-text city name used to orient the feed; we do not ask for, derive, or store your home address. Basis: contract (Art. 6(1)(b)).
Activities you create. Title, description, sport, difficulty, date and time, the meeting point (its name and its exact coordinates), plus optional distance, pace note, participant limit, cover image, and a route. Routes come from a GPX file you upload, from which we store the resolved metadata — distance, elevation, surface and the line to draw. Activities created before we removed the option may still carry a link you pasted to Strava, Komoot or RideWithGPS; we stored that as a link and nothing else. We have never fetched your account, your history or any route data from those services, and there is no way to connect them to ZSAMM. Basis: contract (Art. 6(1)(b)).
Activities you join.Which activities you joined and when. This tells the organiser and the other participants that you’re coming, which is the entire point of joining. Basis: contract (Art. 6(1)(b)).
Clubs. If you create or join a club, we store your membership — which club, your role in it, and when you joined. A club itself carries the details whoever runs it enters: its name, short name, description, logo, colour, home city and sports. Club invite links contain a code that works as the credential for joining. Who can see your membership is described in section 03. Basis: contract (Art. 6(1)(b)).
Your device location.Only if you grant the permission, and only while you are using the app. Discover explains why it would use your location and lets you choose; the system permission dialog appears only if you ask for it there. If you allow it, the app reads your current position once and sends it to our server to ask “what’s happening near this point?”. It is used to run that search and is not stored on your profile, not kept as a location history, and never shown to other users. There is no background or continuous location tracking. If you decline the permission, Discover still works — you pick a city by hand instead. Basis: your consent (Art. 6(1)(a)), given by granting the permission and withdrawable at any time in your device settings.
Photos you upload. Profile photos, activity cover images and club logos. Before an image leaves your device it is re-encoded, which strips embedded EXIF metadata — including any GPS coordinates the camera recorded. Basis: contract (Art. 6(1)(b)).
Notifications. To tell you that someone joined, edited or cancelled an activity, we store the notification itself (its type, the activity title, and the first name of whoever triggered it) and your notification preferences. If you turn push notifications on, we also store a push token for that install, its platform, its language, and when it last checked in — the token identifies a device, so we delete it from our systems when you sign out and remove it as soon as Apple or Google reports it as dead. Delivering a push also requires Google and Apple to process their own installation identifiers for that install; that part is theirs, not ours. Push messages are one lean sentence: no meeting point, no time. Basis: contract (Art. 6(1)(b)) for the in-app notification centre; your consent (Art. 6(1)(a)) for push, which you can withdraw in Settings or your device settings.
Reports and blocks. If you report an activity or a user we store who reported what and the reason you picked, so we can review it. If you block someone we store that you did. Blocks work in both directions, and the blocked person is not told. Basis: our legitimate interest in keeping people safe on a platform where strangers meet in person (Art. 6(1)(f)).
Crash reports.When the app crashes, it sends a report to Firebase Crashlytics so we can find and fix the fault. A report contains the technical circumstances of the crash: where in our code it happened, your device model, its operating system version, the app version, and the installation identifiers Crashlytics uses to tell one install’s reports from another’s. It does not contain your name, your email, your location, your photos, or the contents of your activities, and we do not link it to your ZSAMM account. Basis: our legitimate interest in an app that works (Art. 6(1)(f)). You can turn it off at any time under Settings ▸ Diagnostics; once off, nothing is sent and nothing is held back to send later.
Kept on your device only.Your theme, unit system and language choices, and a local cache of activities so the app can show your last results when you’re offline. This never leaves your phone and goes away when you uninstall the app.
What other people can see
Signed-in users of ZSAMM can see your profile — display name, photo, sports, home city, bio — and, on an activity you organise or joined, that you are going. That visibility is the product: people decide whether to show up based on who else is showing up.
Your own location is never shared. Other users see the meeting points organisers deliberately set. They do not see where you are, where you live, or the position your device reported when you searched.
You choose who an activity reaches. When you publish one, you pick its audience, and that choice decides what is exposed:
Public — it appears in the Discover feed for signed-in users near it, and anyone signed in can join. Members only— it still appears in the feed, under the club’s name and branding, but only members of that club can join. Unlisted — it is kept out of the feed, and the link is the credential: anyone who has the link can open the activity in the app, including the meeting point. Treat an unlisted link the way you would a key — people you send it to can pass it on, and we cannot tell the difference.
Share links are public. If you or an organiser shares an activity link (zsamm.cc/a/…), anyone with that link — signed in or not — sees a deliberately narrow preview in their browser: title, sport, date, the city— never the exact meeting point — a cover image, the organiser’s first name, and how many people are going. The attendee list is not published.
Clubs.A club invite link (zsamm.cc/c/…) shows anyone who has it the club’s name, description, logo, colour, home city, sports and how many members it has — a count, never the list. A club that publishes a discoverable activity publishes its branding along with it, so that page becomes reachable that way too. The member list is visible only to fellow members of the same club, and never to the public or to signed-in users outside it.
The website
The website collects nothing you type. It has no forms, no sign-up and no account. The launch waitlist it used to offer was removed on 14 September 2026, along with the addresses it had stored.
Technical logs. Our hosting and backend providers process standard technical data (such as IP address and browser information) in server logs. We use those logs to deliver the website and the service, keep them secure, diagnose problems and prevent abuse (Art. 6(1)(f) GDPR — legitimate interest in operating the service).
No advertising or analytics tracking. The website sets no cookies and runs no analytics or advertising trackers, and neither does the app. We use no advertising SDK, no attribution SDK and no cross-service tracking, and we do not combine what you do here with data from anywhere else.
Who else processes your data
We do not sell your data and we do not share it for advertising. We use a small set of service providers, each limited to what their job needs. Most of them act on our instructions as processors; some also process limited information under their own responsibility — for things like billing, security and their own legal obligations — and for that part their own privacy notice applies.
Supabase — our database, authentication and file storage. Holds your account, profile, activities, joins, clubs, images and notifications. Our Supabase project is hosted in Frankfurt, Germany, which is where that data is stored.
Google (Firebase Cloud Messaging) — delivers push notifications to Android and, via Apple, to iOS. Receives your push token, the installation identifiers Firebase needs to target a message, and the one-line notification text, which can contain an activity title and a first name.
Google (Firebase Crashlytics)— receives a crash report when the app crashes: the fault location in our code, your device model and OS version, the app version, and Crashlytics’ own per-install identifiers. Not linked to your account, and switchable off under Settings ▸ Diagnostics. We use no Firebase analytics or advertising service.
Apple — delivers push notifications to iPhones, and handles Sign in with Apple if you use it.
Google — handles Google sign-in if you use it.
MapTiler — supplies map tiles and place search. When you open a map or search for a place, your device requests data from MapTiler; that request carries the IP address of your connection and what is needed to answer it, such as the area you are looking at or the term you typed. MapTiler is based in Switzerland.
Resend — sends our email, including your sign-in magic link. Receives your email address and the content and delivery information needed to send the message. Resend stores customer data in the United States.
Vercel — hosts zsamm.cc, the public activity pages and the club pages.
We may also disclose data where the law requires it, or where it is necessary to establish, exercise or defend legal claims. That includes passing information to law enforcement where we learn something that suggests a threat to someone’s life or safety.
Where your data lives
Your account, profile, activities, participations, clubs, images and notifications are stored in the EU — a database and file storage hosted by Supabase in Frankfurt, Germany. Backups, support access and a provider’s own subprocessors can involve processing elsewhere, which is what the rest of this section is about.
Some of the providers above operate outside the EU, so certain data — push notification content, crash reports, sign-in requests, map and email traffic, and website requests — may be processed in a third country. Where it is, we rely on a transfer mechanism permitted by Chapter V GDPR.
In practice: MapTiler is in Switzerland, which the European Commission has recognised as providing an adequate level of protection, so no further safeguard is needed. Resend stores data in the United States, and Google, Apple and Vercelmay process data there or elsewhere; those transfers are covered by the European Commission’s standard contractual clauses, and additionally by the EU–US Data Privacy Framework where the provider is certified under it.
How long we keep it
Your account data is kept while your account exists. Delete your account and it goes with it — see section 08.
Push tokens are deleted from our systems when you sign out on that device, and pruned as soon as Apple or Google tells us the install is gone. Google and Apple hold their own installation identifiers on their own schedules, which we do not control.
Activities stay in your history after they happen, so you and the people who joined can see what you did. We keep them for as long as your account exists, unless you cancel or delete them sooner. See section 08 for what happens to an activity when the organiser deletes their account.
Reports are kept for as long as is reasonably necessary to investigate the report, to deal with repeat or related behaviour, and to document the decision we made — and are deleted when that is no longer necessary, or sooner if either account involved is deleted, unless a longer period is required for a legal obligation or a legal claim.
Crash reports are retained by Firebase Crashlytics for 90 days, after which Firebase begins removing them from its live and backup systems.
Technical logs are short-lived and we keep no copies of our own: our website host retains request logs for about an hour, and our backend provider retains API, database and authentication logs for up to a day. We do not export them anywhere else.
Your device location is not retained at all: it answers one search and is then discarded.
Your rights
You may request access to, correction of, or deletion of your personal data, and restriction of its processing. Where the legal conditions apply, you may also object to processing — in particular to processing we base on our legitimate interests — and you have the right to data portability for data you gave us that we process by consent or under a contract. Where we rely on your consent, you can withdraw it at any time, which does not affect the lawfulness of what we did before. Email hello@zsamm.ccand we’ll take care of it.
No automated decision-making. We do not use automated decision-making or profiling that produces legal effects for you or similarly significantly affects you.
Deleting your account.You don’t need to ask us — the app can do it. Open Settings and choose to delete your account, or start from zsamm.cc/delete-account. Deletion is permanent: your profile, your joins, your club memberships, your notifications and preferences, your reports and blocks, and your uploaded images are removed, and any upcoming activity you were organising is cancelled first so the people who joined are told.
What outlives your account. Activities you organised that have already happened are not erased. They stay as a record of an event other people took part in, with your name detached from them — nobody can edit them and nobody inherits them. This is so the people who joined keep a coherent history rather than watching a ride vanish from their calendar. If a club you ran has no other owner, the club itself also remains. We may keep particular information for longer where we are required or entitled to — for a legal obligation, for security and abuse prevention, or to establish, exercise or defend legal claims.
You can also change most things yourself at any time: edit or clear your profile, cancel an activity, leave one you joined, leave a club, turn push notifications or crash reports off, or revoke the location permission in your device’s settings.
Complaints. You have the right to lodge a complaint with a data-protection supervisory authority. The one responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany. You may also complain to the authority where you live or work.
Children
ZSAMM is not intended for people under 16, and we do not knowingly collect data from them. If you believe a child has created an account, email us and we will delete it.
How we protect it
Traffic is encrypted in transit. Access to your data is enforced in the database itself — row-level security rules decide what each account may read or write, rather than trusting the app to behave — and those rules are covered by automated tests. Uploaded images are size- and type-limited, and stripped of EXIF metadata before upload. Push tokens and notification text are kept out of our logs.
No service is perfectly secure. Where a personal-data breach triggers a notification obligation under the GDPR, we will notify the competent supervisory authority and, where required, the people affected.
Changes
If this policy changes, we’ll update this page and the date at the top. We’ll tell you about material changes in the app.
Questions? hello@zsamm.cc