LEGAL INFORMATION
Privacy policy
privacy-v7 · Effective September 17, 2026
Experimental creator sponsorships
Sponsorships are a measure to support route creators. The creator arranges and manages the agreement directly; Rove does not charge or act as intermediary. This sponsorship model is experimental and may change, be suspended or withdrawn in the future; it does not guarantee revenue, reach or permanence. Changes will be communicated through applicable terms and policies.
YouTube advertising loads automatically, muted and inline, and may transmit connection data to YouTube. A static alternative of equal duration is offered. Viewed advertisements are remembered locally by account, route and revision; the server stores only approximate daily aggregated impressions, completions and clicks for up to 25 months, without personal playback history.
How sponsorships work →Data and retention overview
Reading guide updated September 29, 2026. It summarises the processing described below; it does not add purposes or change consent.
- Account and security
- Identity, email, profile, sessions and MFA to manage access and guide compatibility. Profile and preferences remain while the account is active; security, licensing or claims may require justified retention.
- Routes and content
- Tracks, coordinates, sanitised photos, videos and licences to edit, review and publish your submissions. Drafts remain private; publication shares approved material according to access permissions. Trash allows recovery for 30 days; published versions and evidence are managed separately.
- Optional location
- Exact location is used on your device to orient the map and calculate distances. Catalogue queries send approximate map bounds without storing them as location history.
- Preferences and analytics
- Language: one year in the functional cookie. Catalogue order and analytics choice: 180 days in your browser. Clarity only activates with your consent on public pages: 30-day recordings and aggregated data for up to 9 months, with details and exceptions below. You can change your analytics choice in the footer.
- Rove Assist
- One encrypted email address or WhatsApp number to handle your request: the contact is deleted 30 days after closure; unhandled requests expire after 90 days.
- Providers and external services
- Hosting and storage operate the platform; email services deliver messages; Cloudflare protects forms; maps receive mapping queries; Google/YouTube processes connections and playback described in this policy; Microsoft Clarity receives analytics only with your consent. Sponsorships retain aggregated daily metrics for up to 25 months.
Route details, Rove Assist, profiles, the editor and private portals are excluded from Clarity analytics, even when you have accepted analytics on public pages.
Map and route data
The basic map can be browsed without an account. Full content requires a session and a private profile. Warning acknowledgement is bound to your session, route version, profile revision and current reasons for up to four hours. It does not certify suitability or passability.
Language preference
Your explicit choice of Spanish or English is saved in a functional cookie for one year and, when signed in, in your account for other devices. It does not change consent or enable notifications. Visiting a URL in another language does not overwrite your saved preference.
Rove Assist — contact request
After choosing 1, 7 or 15 days, you can ask the administrator to contact you by email or WhatsApp, providing one contact detail. We store that detail encrypted, your language, plan, privacy acknowledgement and, when you come from a route, its identity, title and version; we never copy its geometry. No account, name or dates are required. A request is not a payment, booking, promise of an immediate reply or emergency assistance.
Cloudflare Turnstile checks the form for abuse. HMAC keys limit attempts by IP and contact; the contact detail is excluded from logs and administrator notification emails. We send no automatic replies to the provided contact. Contact details are deleted thirty days after closure; unhandled requests expire after ninety days. Account export or deletion links only a verified email; ownership of WhatsApp or another email must be verified through the privacy channel.
Local preference, cookies and similar technologies
When you choose a default order for the route feed, we store the rove.catalog.order.v1 key in this browser’s local storage. It contains only the sorting criterion and direction, a technical version and its expiry date; it does not contain a name, account, advertising identifier or route history. The key, version and expiry remain in the browser. The criterion and direction are transiently included as parameters needed to order results, without associating them with an identifier or turning them into a tracking profile.
The preference expires 180 days after each choice. You can remove it sooner by resetting the catalogue order or clearing this site’s data in your browser. We do not use a cookie for this function or show a banner for this strictly functional preference, activated by your choice and not used for analytics, advertising or tracking. Optional analytics technologies are described separately and remain disabled until you accept them.
Optional analytics with Microsoft Clarity
Only on public pages and after you accept analytics, Rove Signal uses Microsoft Clarity to understand through behavioural metrics, heatmaps and session replays how the site is navigated and to correct experience problems. We do not enable advertising storage or send Clarity names or email addresses entered by visitors, account identifiers, or form content. We mask public names and self-assessments; creator pages use only their canonical public slug. We exclude every URL with unaudited parameters or fragments and any dynamic route that does not resolve published content. Capture stops when you enter an application, access, registration, recovery, an authenticated form, or any private portal.
Your decision is kept for 180 days in the local rove.analytics.consent.v1 key. You can reject analytics or change your decision at any time from the footer. Without acceptance, Clarity is not loaded and no data is sent; withdrawing consent or preference expiry defensively removes its cookies and stops capture.
Microsoft retains session recordings for 30 days and certain aggregate data, heatmaps or preserved sessions for up to 9 months. Read the Microsoft Privacy Statement.
Device location
Location is optional and requested only when you select the option to use it and approve the browser permission. Your exact location is used on your device to centre the map. To load routes and circles in that area, the application transiently sends Rove Signal only approximate bounds of the visible area, not the exact GPS coordinate. The map provider receives technical tile requests for the visible area, but the application does not send it the exact GPS coordinate returned by the device. Neither the exact location nor those bounds are added to the catalogue preference; the application does not persist them in the catalogue database or use them to create a location history. You can withdraw permission in your browser or device settings.
Creation, editing and public route maps load Esri satellite imagery without a key by default. The editor also offers the configured credential-based provider—Esri ArcGIS or Amazon Location. The provider in use receives the tile requests needed for the visible area and normal network metadata, including the Rove Signal origin. It does not receive the full private URL, draft identifier, geometry or exact GPS coordinate. To control the budget of credential-based options, Rove Signal retains for a limited operational period only daily counters aggregated by account and provider. That measurement does not store tile coordinates, zoom level, private URL, draft or geometry; the count is an operational estimate and may differ from the provider report.
Applications, drafts and route publication
The creator application uses an existing verified account and retains the chosen name, biography, optional link, declared countries and acceptance evidence. It does not enable marketing communications. Approval enables individual permission; it does not create an organisation or another identity. The public profile shows only the name, biography, avatar and links the creator chooses to publish; email and safety profiles stay private.
Drafts, sanitised copies, coordinates and upload receipts remain in private storage while they are prepared and moderated. Submission seals a read-only copy and records the accepted licence version, date, user, revision and submission fingerprint. Approval publishes the selected material and its editorial locations; changing it requires a new submission.
Editor, GPX and road calculation
When you select a GPX file, the original file is analysed in your browser. The original, its timestamps, elevation and device identifiers are not uploaded. After you confirm the import, normalised coordinates become part of the private document and are sent to the server through autosave, including when you preserve the geometry without calculating it. When you place or move the start, finish or passing points, the application sends those controls to Valhalla through the backend to recalculate the route. Elevation review also queries the elevation model for points along the final track; saved corrections become part of the private draft. The provenance receipt identifies the technical result, not your device. Coordinates and receipts are excluded from application and gateway logs. If you open a Google Maps, Street View or Earth reference link, Google receives the coordinates of the point you selected.
The private draft retains the confirmed geometry, calculated metrics and verifiable provenance needed to edit, moderate and version the route. Surfaces are proposed from the road graph and slopes are derived from the reviewed elevation profile; they may be incomplete or out of date and do not establish current conditions, passability or safe passage.
Photos, GPS and editorial location
Photos, including the cover, are first processed in your browser: the original file is checked for GPS and a WebP copy without EXIF or XMP metadata is created. This check does not use the device’s current location. You can correct or add the location on the map before submitting. The original is not uploaded; only the sanitised copy enters private quarantine. We retain its identity, fingerprint, dimensions, description, credit, crop, order, rights confirmation, editorial location and the source of that location to save, moderate, export and publish the same photo.
Once published, the cover and up to two distinct photos may be shown without sign-in, without coordinates. The full gallery and each photo’s precise location are delivered only to people with route access. A location may be outside the track line, and you must avoid revealing sensitive places without permission.
Videos and external media services
For each video, Rove Signal retains the YouTube link or identifier, title, credit, rights confirmation, editorial metadata and selected route position. If you upload a file through the YouTube integration, the browser may analyse it locally and the file, title and required data are sent to Google/YouTube under its own terms; Rove Signal does not retain a public copy of the video file. If you paste a link, the video remains on YouTube. When the player is loaded or used, YouTube receives the normal technical request data under the notice and consent applicable to that external service.
Optional YouTube connection
Rove Signal uses YouTube API Services. With your Google authorisation, it requests permission to upload videos and read YouTube information. We use these permissions to identify your channel and check uploads you initiate from the editor. Connecting is optional: you can paste a link without granting access to your account. Rove Signal does not receive your Google password.
We store the channel ID and name, granted permissions, connection and consent dates, and the encrypted refresh token that maintains the connection on our server. Temporary access tokens are used during operations and are not stored persistently. We record upload attempts, their status, dates, video ID and visibility, and daily quota usage. The file is sent directly from your browser to YouTube; Rove Signal does not store the original video.
These data are used to provide and protect the upload feature you request. Google/YouTube receives the file and data needed for that operation; our hosting providers process the records needed to operate Rove Signal. We do not sell data obtained from Google or use it for advertising, advertising profiles or training general-purpose artificial intelligence models. Its use and transfer adhere to the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect the channel from the editor: Rove Signal deletes the connection and its stored token and attempts to revoke access at Google. If Google does not confirm revocation, you can complete it through your Google Account permissions. Disconnecting does not delete YouTube videos, links added to your routes or the local upload-attempt history. You can export metadata without credentials and request data deletion from your profile; when deletion is executed, the connection and local upload attempts are purged. For privacy questions or requests, contact info@rovesignal.com.
Accounts and safety profile
To provide account features we process identity, verified email, sessions, roles and MFA. The private profile includes country of residence only at country-code level and may include experience, practical training, usual protective equipment, riding time, travel mode and basic motorcycle types. We use that country as geographic context for route-related features; saving it does not enable newsletters or alerts. We do not request a city, address, coordinates, precise usual location, make, model, licence plate, medical information or an emergency contact for this profile.
Compatibility and warnings
We compare the profile with each route’s known requirements. Warning acknowledgement preserves the necessary binding to the user, session, route version, profile revision and current reasons, without inventing answers for unknown conditions. This assessment provides guidance and does not certify personal ability.
Newsletter, countries and creators
The newsletter and route alerts are optional. You may follow creators without enabling email, select countries with published routes and withdraw each consent separately. Preferences are not preselected and an unsubscribe request overrides any prior subscription.
Providers and transfers
Hosting, email, mapping and media providers, together with Microsoft Clarity when accepted, may process data according to their roles and locations. Shared data is minimised. This free version does not activate payment providers or request banking, tax or KYC information to enable creators.
Retention, withdrawal and deletion
The profile and preferences are retained while the account is active. Deleted drafts follow the stated recovery period; unlinked assets and quarantined copies follow their technical deletion lifecycle. Removing a photo, video or track from a draft does not immediately change an already published version: replacement applies when a new submission is approved or the publication is withdrawn through the applicable process. Non-essential communications stop when deletion is requested. Data linked to published routes, licences, safety, claims or audits may be retained, restricted or anonymised only for a justified period.
Data subject rights
From your profile you can correct your data, export a copy and request or cancel deletion. You may also request access, updates, proof of authorisation, information about use, withdrawal or deletion where applicable through the published privacy channel.