Privacy Policy
Last updated: 24 August 2026
The Summit Social ("TSS", "we", "us") is a climbing social app operated from Norway. This policy explains what personal data we collect through the TSS mobile app and this website, why we collect it, where it is stored, and your rights. We keep it in plain English.
The short version: we collect what the app needs to work, we store it in the EU, we do not sell it, we run no advertising trackers, and you can delete your account — and the data with it — from inside the app at any time.
1. Who is the data controller
The Summit Social — operated by a private individual based in Norway.
Contact for all privacy matters: support@thesummitsocial.app
2. What we collect and why
| Data | Why (purpose) | Lawful basis (GDPR) |
|---|---|---|
| Email address, username, password (hashed) or Apple/Google sign-in identity | Creating and securing your account | Contract (Art. 6(1)(b)) |
| Date of birth | TSS is an 18+ app — your date of birth is how we verify this at signup. It is not shown publicly. | Legal obligation / legitimate interest in child safety (Art. 6(1)(c)/(f)) |
| Profile data you choose to add (photo, bio, climbing grades) | Your public profile in the app | Contract |
| Climbing logs (climbs, grades, dates, venue, optional photos, optional weather readings) | The core logbook feature | Contract |
| Location of venues you log or plan at (crag/gym coordinates) | Venue features, maps, conditions. You can hide exact coordinates on planned sessions. We do not run background location tracking. | Contract |
| Posts, comments, likes, direct messages, group messages | The social features | Contract |
| Push notification device token | Sending notifications to your phone — for example when someone sends you a direct message. The token is an identifier issued to your device by Apple or Google; it does not identify you personally to them. Your phone asks your permission first, and you can turn notifications off at any time in the app's Settings or in your phone's own settings. | Consent (Art. 6(1)(a)) |
| Coach–client data (session plans, training notes, invoices) | The coaching features, where you use them | Contract |
| Subscription status | Unlocking paid tiers; billing itself is handled by Apple/Google | Contract |
| Reports you file about content | Moderation and community safety | Legitimate interest / legal obligation |
We do not collect: advertising identifiers, contact books, background GPS trails, or analytics profiles from third-party tracking SDKs. We do not store identity documents — coach identity checks are performed by Stripe and we receive only the outcome.
3. Where your data lives
- App database — hosted on our own servers in the EU.
- Photos and media — stored privately, never in a public bucket. Your media is only reachable through your own authenticated session; the links are not public or shareable.
- On your device — your logbook keeps an encrypted offline copy so logging works with no signal; it syncs when you reconnect.
4. Who processes data for us
| Processor | What they do |
|---|---|
| Hetzner Online GmbH (EU) | Server hosting for the app database |
| Cloudflare, Inc. | Private media storage and network services |
| Apple / Google | Sign-in (if you choose it), all subscription billing, and delivery of push notifications — the Apple Push Notification service (APNs) on iPhone and iPad, Firebase Cloud Messaging (FCM) on Android |
| RevenueCat, Inc. | Subscription management (receives purchase status, not your messages or logs) |
| Stripe, Inc. | Identity verification for coaches only (we never see or store your documents) |
| Netlify, Inc. | Hosting for this website, and storage of newsletter sign-ups (email addresses only — no app data) |
| Open-Meteo | Weather data for venues (receives venue coordinates, nothing about you) |
| CARTO & OpenFreeMap | Map background tiles. Loading a map sends your IP address and the area you're viewing to the tile host — standard for any online map; no account data is sent. |
We do not sell personal data, and we don't share it with advertisers. Where a processor is outside the EU/EEA, transfers are covered by standard contractual clauses or an adequacy decision.
What a push notification actually contains. To place a notification on your screen, Apple or Google must receive your device token and the text of the notification. For a direct message that text is the sender's display name and up to the first 120 characters of the message. It passes through their delivery systems so they can reach your phone, and it is not used for advertising or analytics. Hiding previews in your phone's settings changes what is displayed on your lock screen; it does not change what is sent for delivery. To stop message content being sent at all, turn message notifications off in the app's Settings.
5. How long we keep it
- Your account and content — until you delete your account (Settings → Delete Account in the app). Deletion removes your profile, logs, posts and media.
- Reported content — content that has been reported for moderation is preserved for up to 1 year, as required for safety and legal purposes, even if otherwise deleted.
- Backups — routine encrypted backups roll off automatically.
- Push notification device token — kept only while notifications are active for your account. It is deleted when you sign out, when you delete your account, and when Apple or Google report that the device is no longer registered (for example after you uninstall the app).
6. Your rights
Under the GDPR you can: access your data, correct it, delete it, restrict or object to processing, and take your data with you (portability). Most of this you can do directly in the app; for anything else email support@thesummitsocial.app and we'll respond within one month.
You also have the right to complain to the Norwegian Data Protection Authority, Datatilsynet (datatilsynet.no).
7. Children
TSS is strictly 18+. We verify age at signup via date of birth and refuse under-18 registrations. If you believe an under-18 has an account, contact us and we will remove it.
8. Security
Your data is protected in transit and at rest. Access is restricted so you can only reach your own data, and uploads are authenticated and rate-limited. The offline copy on your device is encrypted. This website enforces HTTPS at the browser level.
9. This website
This website currently uses no analytics at all — no visitor counting, no tracking scripts, and the pages make no third-party requests. It sets no cookies, stores nothing on your device, does not fingerprint you and cannot identify you individually. Your light/dark preference is stored only in your own browser and never leaves your device. If we ever add analytics, it will be a cookieless, aggregate-only service and this section will be updated first.
Newsletter. If you enter your email address in one of the sign-up forms on this site (the newsletter on our home page, or the beta list on the Get the app page), we store that address and use it for one thing only: emailing you about The Summit Social — beta invites, new features and launch news. We never sell it, share it with advertisers, or add you to anything else. The lawful basis is your consent (Art. 6(1)(a)), and you can withdraw it at any time: every email carries an unsubscribe link, or email support@thesummitsocial.app and we will delete your address. Sign-ups are received and stored by Netlify, who host this website; we keep your address until you unsubscribe.
10. Changes
If this policy changes materially we'll note it in the app and update the date at the top of this page.