Privacy5b

Your sessions are yours.

GDPR · EU and Austrian lawController · Benjamin Orthner, ViennaLast updated: July 2026

Welcome to ClimbSync. This privacy policy explains how we collect, use, store, and protect your personal data when you use our mobile application.

Introduction

ClimbSync is operated by Benjamin Orthner, an individual based in Austria. We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR) and Austrian data protection laws.

ClimbSync is currently in active development (pre-release). Features and processing details may evolve before broad public launch, and this policy may be updated accordingly.

Data Controller

The data controller responsible for your personal data is:

Benjamin Orthner
Vienna, Austria
Email: contact@climbsync.app

Data We Collect

3.1 Account Information

  • Email address (required for account creation)
  • Authentication provider data (if signing in via Google or Apple)
  • Account creation and last login timestamps
  • Billing identifiers and purchase metadata processed by RevenueCat when billing support is enabled (a pseudonymous App User ID derived from the ClimbSync account identifier, plus store purchase and entitlement data). ClimbSync does not transmit or prefill your account email address or display name as RevenueCat customer attributes. RevenueCat may collect contact details that you enter directly during its checkout.

3.2 Profile Information (Voluntary)

  • Display name (publicly visible to other users)
  • Real name (visible according to your profile visibility settings)
  • Profile picture/avatar and avatar visibility settings
  • Short bio description and bio visibility settings
  • Climbing grades (boulder and sport) and grade visibility settings
  • Preferred home city / home gym and related visibility settings
  • Profile preferences such as language and unit/time formatting

3.3 Social Contact Information (Optional, Friends Only)

  • Phone number (international format)
  • WhatsApp number/username
  • Signal number/username
  • Telegram username
  • Instagram username
  • Contact visibility controls, including optional friend-exclusion settings

3.4 Activity Data

  • Climbing session plans and participation data (gym, date, time, duration, notes, visibility)
  • Session invitations/plans, poll votes, and plan outcomes
  • Friend connections, friendship history, and block-list state
  • Favorite gyms and related discovery interactions
  • Notification preferences and in-app notification interactions
  • Profile statistics and insight aggregates generated from your activity

3.5 Technical Data

  • Device type and operating system version
  • App version and platform (iOS/Android/Web)
  • Security and reliability logs (e.g., request/error/rate-limit telemetry)
  • Product analytics events used to improve app flows (e.g., onboarding/session/search usage)

3.6 Contact Discovery and Address Book Matching (Optional)

  • If you enable Contact Discovery, we store a protected phone matching key derived from your phone number and the last four digits for display/conflict handling; we do not store the raw discovery phone number in the Contact Discovery table.
  • When you explicitly choose to import contacts, phone numbers from your device address book are sent to ClimbSync temporarily so the backend can compare them against opted-in ClimbSync users.
  • Address-book contact names stay on your device/in-app session state for display; they are not stored as backend contact profiles by Contact Discovery.
  • Non-matching imported contacts are not retained as contact records, and ClimbSync does not automatically invite them or use imported contacts for marketing.
  • If the same discovery number is claimed by more than one account, matching for that number is paused until the conflict is resolved.
  • Abuse reports and moderation records: if you report a user or content for a safety issue, we store the report (the reason, the optional description you provide, and a snapshot of the reported content as it was visible to you at the time), together with a log of the moderation actions we take. Reports are only visible to the service operator.

Data Storage and Security

Your data is stored on servers provided by Convex, Inc., which uses secure data centers in the European Union. We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit (TLS/SSL)
  • Encryption of data at rest
  • Server-side access controls
  • Secure authentication mechanisms

Data Sharing

We do not sell your personal data. We share your data only as follows:

  • With other ClimbSync users according to your visibility settings (public sessions can be visible to other users, for example through shared session links; friend-only content is visible only to accepted friends)
  • Contact links are friends-only by default and may be hidden from selected friends using your contact visibility controls
  • Blocked users are restricted from seeing your activity as defined by product access rules
  • With service providers used to operate the app (e.g., infrastructure, mapping, authentication/email delivery, and subscription billing/support) under appropriate contractual safeguards
  • When required by law or legal process
  • Friends can see your friend list. Non-friends may see mutual friends, mutual-friend counts, and total friend counts unless blocked or limited by product controls. You can opt out of appearing in non-mutual friend lists and friend suggestions.
  • Private or otherwise hidden session participants may still be represented through anonymous participant counts, aggregate session time ranges, and anonymous coordination placeholders where needed for session coordination.
  • Contact Discovery match results are shown only to opted-in users performing an import, and only for reciprocal opted-in matches. Imported non-match contacts are not shared with other ClimbSync users.

International Data Transfers

Your data is primarily stored in the EU. In case of transfers outside the EU/EEA (e.g., to Convex, Inc. in the USA), appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) as approved by the European Commission.

Data Retention

We retain your personal data for as long as your account is active and as needed to operate the service securely. Current retention approach includes:

  • Core account/profile/session data: retained while your account remains active, then deleted when your account is deleted (subject to short technical backup windows).
  • Billing and subscription data: when you delete your account, we remove our local billing records. However, subscription and purchase history held by RevenueCat, Apple, or Google is subject to their respective retention policies and is not deleted by us. Active subscriptions are not cancelled by account deletion — you must cancel them through your store settings.
  • Raw product analytics events: retained for a limited period (currently 90 days) for reliability and product analysis.
  • Certain aggregated service metrics (including daily/monthly rollups) may be retained longer to understand product performance trends and system health.
  • Backup copies are typically deleted within approximately 30 days.
  • Contact Discovery phone matching data is retained while Contact Discovery is enabled and removed when you turn it off or delete your account. Imported address-book phone numbers are processed transiently for matching and are not stored as backend contact records.
  • Legal acceptance evidence for Terms and Privacy versions may be retained for up to three years after account deletion as minimal legal evidence (document type, version, content hash, acceptance time, source, locale/platform/app version where available).
  • You can delete your account at any time in the app (open Settings, then Account, then Delete account), or request deletion by email at contact@climbsync.app. See https://www.climbsync.app/legal/account-deletion for the steps and details of what is deleted and what is retained.
  • Abuse reports and moderation records may be retained after the reporting or reported account is deleted, to the extent necessary to prevent abuse, keep the service safe, and comply with legal obligations. When a reporter deletes their account, their identity is removed from the retained report.

Your Rights (GDPR)

Under the GDPR, you have the following rights:

  • Right of Access (Art. 15): Request a copy of your personal data
  • Right to Rectification (Art. 16): Correct inaccurate data
  • Right to Erasure (Art. 17): Delete your account and data
  • Right to Restriction (Art. 18): Limit how we use your data
  • Right to Data Portability (Art. 20): Receive your data in a portable format
  • Right to Object (Art. 21): Object to processing based on legitimate interests (including product analytics/telemetry).
  • Right to Withdraw Consent (where consent is used): Withdraw consent at any time for consent-based processing.

Third-Party Services

ClimbSync uses the following third-party services:

Children's Privacy

ClimbSync is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe we have collected data from a child, please contact us immediately.

Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes through the app or by email. The "Last updated" date at the top indicates when this policy was last revised.

For material changes, we may require renewed in-app acceptance before continued use of protected app areas.

Contact

For questions or concerns about this privacy policy or your personal data, please contact:

Benjamin Orthner
Email: contact@climbsync.app

Privacy Policy · Last updated: July 2026
For questions, email contact@climbsync.app.