Privacy notice

Last changed: 2026-09-05

This notice describes how BoulderRoute handles the personal data of people who use the app. It is written from how the system actually behaves: every duration and every visibility rule stated here corresponds to a constraint enforced by the database, not to an intention.

Data controller

To be completed before launch

BoulderRoute is in a validation phase ahead of opening the service, and is not yet incorporated as a legal entity.

The identity of the data controller and the contact details for exercising your rights will be stated here before the service opens to the public.

Two separate controllers

BoulderRoute is the controller for your account and for the content you create in the app: profile, problems you set, sends you log, beta you write.

The gym is the controller for your membership data held by that gym: enrolment card, subscription, entries, staff notes. For those, BoulderRoute acts as a processor — it provides the tool but does not decide the purposes.

The boundary is enforced, not merely asserted: a gym’s member register can only be written through the code-redemption procedure, and can only be read by the subject and by that gym’s staff.

Account data

Email address
Required to sign in. Not visible to other users: read permission on that column is revoked for every client role.
Display name and picture
Shown next to the content you publish. Publicly visible only if you have at least one approved problem.
Preferred language
Italian or English.

Content you create

The problems you set, the sends you log and the beta you write are content meant for the community. A problem becomes publicly visible only after the gym’s staff approves it; before that only you and the staff can see it.

Sends logged in a gym are readable by signed-in users, because they feed the community grade. The personal note you may attach to a send is not: read permission on that column is granted to no client role.

Sends logged on outdoor lines are visible only to you.

The enrolment card, and the medical certificate

When you join a gym you fill in a card with your name, fiscal code, date and place of birth, address, contact details, federation memberships and, where applicable, a medical certificate.

Until you hand it over, that card does not exist on our servers: it stays on your device, in the browser’s local storage. Handing it over means generating a code that you show at the desk.

A medical certificate is health data, a special category under art. 9 GDPR. BoulderRoute does not store it: the file passes through a private store for the duration of the handover and is deleted the moment staff downloads it. From then on the document is in the gym’s archive, under the gym’s responsibility. All that remains on our side is its expiry date.

Enrolment is for adults only: both the form and the database procedure reject a date of birth belonging to a minor.

For how long

Unredeemed handover code
10 minutes, after which the row and the file are deleted automatically.
Certificate redeemed but never downloaded
1 hour.
Handover receipt (who, when, which gym — no content)
12 months.
Failed code attempts
24 hours. They exist only to rate-limit repeated guessing.
Account deletion request
30-day grace period, during which you can cancel it.
Card handed to a gym
Decided by the gym, which is its controller.

Legal basis

To be completed before launch

The legal bases for the processing described on this page are being settled with legal advice and will be stated here before the service opens.

They concern in particular the gym’s processing of the medical certificate, which is health data.

Who sees what

You
Your card, your sends, your receipts, and your own problems even before approval.
Staff of the gym you joined
Your card, your membership, your entries, and the problems awaiting moderation on their own walls.
Staff of another gym
Nothing about you.
Any other signed-in user
Your public content and your indoor sends. Not your card, not your email, not your notes.
A visitor who is not signed in
Only approved public content and the name of whoever created it.

Providers and recipients

Data is stored on Supabase, with the database and file storage in the European region, and the site is served by Vercel. No transfer outside the European Union is involved.

In the outdoor guide, searching for a place queries OpenStreetMap’s Nominatim geocoding service. The request is made by our server rather than your browser, so the service receives the search text but not your IP address.

We use no third-party analytics, advertising or profiling. There are none in the code.

Your rights

You can export your data in a machine-readable format directly from the profile section.

You can ask for your account to be deleted. It is not carried out by deleting rows but by anonymising them: a cascading delete would also destroy other people’s data, for instance problems that others have logged sends on. Your content stays, stripped of its link to you.

Cards handed to a gym where you hold an active membership are not removed: they are that gym’s member register, which the gym has its own duty to keep. The deletion screen says so in full and points you to the gym for those records.

You can correct your card by generating a new code and having the desk update it: a gym’s register cannot be edited from outside.

Contact and complaints

To be completed before launch

The address for exercising your rights will be published here together with the controller’s identity, before the service opens.

Data a gym holds about you should be requested from that gym, which is its controller.

The right to lodge a complaint with the Italian supervisory authority remains in any case.