Legal
Privacy Policy
Last updated:
The short version
- Students and visitors use the NaviCampus app without giving us a name, email or password.
- Your route settings, recent routes and saved places stay on your phone. Routes are worked out on your phone too.
- The app uses your location only if you allow it, to show where you are and route you from there.
- University staff who use the dashboard have an account with their name and email, and we record who changed which map.
- We don't sell data, and we don't show ads.
1. Who we are
This policy explains how NaviCampus ("NaviCampus", "we", "us") handles personal data. You can reach us at [email protected]. This policy covers the NaviCampus mobile app, the website at this address and the staff dashboard (sign-in, dashboard, map editor and admin pages).
Universities decide what goes on their campus maps. For the staff accounts a university asks us to create, we process data on that university's behalf.
2. The mobile app (students and visitors)
No sign-up. When you open the app, it signs in to our backend anonymously. This creates a random identifier that is not linked to your name, email or phone number. It only lets the app read published campus maps.
What stays on your phone. Your settings, such as "step-free routes" or "prefer air-conditioned paths", places you save, recently opened maps, and an email address if you choose to enter one, are stored only on your device. We never receive them. Deleting the app deletes them.
Routes. The app downloads a campus map once and calculates routes on your phone. The rooms you search for and the routes you take are not sent to us.
Suggestions from recent routes. If you turn this option on, the app keeps a list of your recent routes on your phone and uses it to suggest places you're likely to go next. The list stays on your device. You can turn the option off at any time, and clearing the app's data or uninstalling it deletes the list.
Location. The app asks for permission before it uses your phone's location. If you allow it, your location is used on your phone to show where you are on the map and to start routes from there. It is not stored by NaviCampus. You can say no, or withdraw permission later in your phone's settings; you can still choose a starting point by hand.
Your app identifier. The anonymous identifier described above doesn't expire at the moment. It contains no personal details.
3. The staff dashboard
If your university gives you a NaviCampus staff account, we process:
- Account details: your name, email address, your role and which university you work for. If you sign in with Google, Google shares your name, email and profile picture with us.
- Sign-in data: your password is handled by our authentication provider and is never visible to us. Sign-in times are kept by that provider.
- Activity on maps: which account created, edited, submitted, reviewed, published or archived a map or campus, and when. This keeps a clear record of who changed what.
- Content you upload: floor plans, site maps, location names, notes and photos. Once published, map content (not your name or email) is public in the app.
The map editor's "Pick on map" feature loads satellite and street map tiles from Esri and OpenStreetMap, and place searches you type are sent to OpenStreetMap's Nominatim service. Those providers receive your IP address and the search text under their own privacy policies.
4. This website
The website is served by Cloudflare, which processes technical request data such as your IP address to deliver and protect the site. Fonts are loaded from Google Fonts. We don't use advertising cookies or cross-site trackers. The site remembers your light or dark theme choice in your browser's storage; that setting never leaves your device. We use Cloudflare Web Analytics to count visits and see which pages are used and how fast they load. It doesn't use cookies, doesn't store your IP address and doesn't follow you across other websites.
5. Why we use data
- To provide the app and the dashboard, and to let staff sign in (performance of our agreement with your university).
- To keep the service secure, prevent abuse and keep an audit trail of map changes (our legitimate interests).
- To understand, in aggregate, how the website is used so we can improve it (our legitimate interests).
- To send account emails such as password set-up and reset links.
We don't sell personal data, use it for advertising, or make automated decisions about people with it.
6. Where data is stored and who processes it
We use these service providers, which process data only to run NaviCampus:
- Google Firebase (Google Cloud): authentication, database, file storage and server functions. The map database is hosted in the Middle East (Dammam, me-central1); server functions run in the United States (us-central1).
- Cloudflare: website hosting and delivery, and privacy-friendly visit statistics (Web Analytics).
- Esri and OpenStreetMap: map tiles and place search in the staff map editor.
Some of these providers may process data outside your country. Where the law requires it, transfers rely on appropriate safeguards offered by those providers.
7. How long we keep it
- Staff accounts are kept while your university uses NaviCampus and you have access. Ask your university admin or us to remove your account.
- Archived universities, campuses and maps are deleted automatically 30 days after they are archived.
- Published map content stays in the app until the university or NaviCampus removes it.
- Anonymous app identifiers don't expire at the moment. They contain no personal details.
8. Your choices and rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict how we use it, and to complain to a data protection authority. App users can clear their settings at any time by clearing the app's data or uninstalling it. Staff can ask us, or their university admin, for a copy of their data or to delete their account. We'll answer within the time the law requires.
9. Security
All traffic is encrypted in transit. Access to data is enforced by server-side security rules: staff can only change their own university's maps, and only reviewers can publish. No system is perfectly secure, and we'll tell affected people and authorities about a breach when the law requires it.
10. Children
NaviCampus is made for university campuses. The app does not ask anyone for personal details, and we don't knowingly collect personal data from children.
11. Changes to this policy
If we change this policy, we'll update the date at the top. For significant changes affecting staff accounts, we'll also let universities know.
12. Contact
Questions or requests about privacy, including access or deletion requests: [email protected].