Controller and contact
The Thway provider identified at the top of this notice is the data controller for the processing described here. This means that the provider decides why and how Thway processes personal data.
For privacy questions or to exercise a right, use the public email shown above or Thway contact. Please write "Privacy request" in the subject and do not send passwords, payment-card details, or unnecessary sensitive data.
Data we collect and where it comes from
- Account and authentication data: your name, email address, email-verification state, authentication method, account and login timestamps, security state, and a password hash if you use password sign-in. We do not store your readable password.
- Google sign-in data: a Google account identifier, verified email, name, and an optional profile image returned by Google. Section 03 explains exactly what is requested and retained.
- Route data: start and end points, custom-stop names and coordinates, distance and walking settings, selected route options, generated geometry and day segments, stays and places, saved-route names, export choices, and share tokens.
- Billing data: Stripe customer, subscription, product, price, invoice, and event identifiers; subscription status; amount, currency, interval, billing-period dates; and synchronization timestamps. Stripe collects payment-card and billing details directly. Thway does not store complete card numbers.
- Complimentary-access data: grant, expiry, and revocation dates, the responsible administrator, and an internal operational reason.
- Contact and support data: your name, email, subject, category, messages, ticket history, replies, and limited hashed network and browser signals used to prevent abuse.
- Technical and security data: IP address, browser and device information, request and error details, timestamps, session and security events, and operational logs generated when the service is used.
Most data comes directly from you or your use of Thway. Google provides sign-in data, Stripe provides billing status, and service infrastructure produces technical records. Thway does not collect continuous or background GPS location. Route coordinates can still reveal where you are, plan to travel, or have traveled, so share them carefully.
Sign in with Google
If you choose Continue with Google, Thway uses Google's OpenID Connect service and requests only the openid, email, and profile scopes. Google may return its stable account identifier (the sub claim), your email and whether Google verified it, your name, and an optional profile-image URL. Thway does not request access to Gmail, Google Drive, contacts, calendars, or your Google password.
We store the Google account identifier, provider name, email, verification state, your Thway display name, and sign-in timestamps so we can create or connect the correct account, authenticate you, prevent account takeover, and support security reauthentication. We do not save the Google profile image in the database. OAuth access and ID tokens are not retained after the sign-in callback. During a sign-in or account-conversion flow, returned profile data can be held in an encrypted, HTTP-only transaction cookie for up to 10 minutes.
We use Google account data only for authentication, account linking, security, and the service you request. We do not sell it, use it for advertising, or use it to build a marketing profile. Google processes its own data as a separate controller under the Google Privacy Policy.
You can manage Thway's connection in your Google Account connections. Removing the connection at Google stops future Google sign-in but does not itself delete data already held by Thway. Delete your Thway account in account settings or contact us to request deletion. If Google is your only sign-in method, make sure you can still access Thway before disconnecting it.
Purposes and legal bases
We process personal data for these purposes and legal bases:
- Contract and requested steps (GDPR Article 6(1)(b)): creating and authenticating an account, generating and saving routes, creating share links and exports, supplying Plus, managing billing, and providing requested account support.
- Legal obligations (Article 6(1)(c)): accounting, tax, consumer-law records and requests, responding to valid legal process, and meeting data-protection duties.
- Legitimate interests (Article 6(1)(f)): protecting accounts and infrastructure, preventing spam, fraud and abuse, diagnosing faults, maintaining reliable service, enforcing terms, and establishing or defending legal claims. We balance these interests against your rights and expectations.
- Consent (Article 6(1)(a)): only where we separately ask for optional processing. Thway currently does not use non-essential analytics or advertising cookies and does not send consent-based marketing email.
Account, authentication, route, and necessary billing information is required to provide the corresponding feature. If you do not provide it, we cannot provide that feature. Optional fields can be left blank.
Who receives data
We disclose data only where needed for the purposes above:
- Infrastructure and communications providers that host applications, databases, cache data, backups, or email and act under contractual confidentiality and data-processing terms.
- Google when you choose Google sign-in. Your browser is redirected to Google and Google receives the information normally sent when visiting its service.
- Stripe for Checkout, payment, invoicing, fraud prevention, tax, and billing-portal functions. Stripe acts as our processor for some tasks and as an independent controller for certain regulatory, fraud-prevention, and payment purposes. See the Stripe Privacy Policy.
- OpenTopoMap when a map view loads its public map tiles. Your browser connects directly to OpenTopoMap, which can receive your IP address, browser/request headers, referrer, and the tile coordinates that indicate the map area and zoom level being viewed. See OpenTopoMap information.
- People who receive a route share link. Anyone with the link can see the shared route until the link is revoked or the route is deleted. They may make their own copy.
- Professional advisers, authorities, courts, or a successor where reasonably necessary for legal compliance, a claim, a corporate transaction, or protecting users and the service.
We do not sell personal data and do not share it with data brokers or advertising networks. Access inside ThWay is limited to people who need it for administration, support, security, or legal compliance.
International transfers
We aim to process data in the European Economic Area, but Google, Stripe, infrastructure, or communications providers may process data in other countries. Where the GDPR requires a transfer safeguard, we use an adequacy decision, the EU-US Data Privacy Framework for an eligible certified recipient, the European Commission's Standard Contractual Clauses with supplementary safeguards, or another lawful mechanism.
Provider arrangements and transfer locations can change. Google describes its transfers in its privacy documentation; Stripe provides details in its Data Processing Agreement. Contact us for information about the safeguard relevant to your data and, where available, a copy of it.
Cookies and browser storage
ThWay currently uses only storage needed to provide requested features or remember a local interface choice:
- thway_session: an encrypted, HTTP-only sign-in and security cookie lasting up to 7 days. It is removed when you sign out, and server-side checks can invalidate it earlier.
- thway_oauth_tx and thway_oauth_pending: encrypted, HTTP-only cookies that protect a Google sign-in, connection, conversion, or security reauthentication. They last up to 10 minutes and are consumed or cleared when the flow finishes.
- thway_locale:a language preference cookie, set when you pick a language in a language switcher or follow a link from one language version of the site into the planner or sign-in pages. It holds just the language code (for example “da”) so the front page and the planner open in that language, and lasts up to 12 months.
- thway:tune_open: local browser storage remembering whether advanced route controls are open. It contains only a yes/no interface preference and remains until you change it or clear site storage.
These items are technically necessary or requested by you, so they do not require the consent used for advertising or analytics cookies. Google and Stripe may set their own cookies when you visit their domains. Their notices control those cookies. If ThWay later adds non-essential analytics, marketing, or similar storage, we will update this notice and request consent before using it where required.
How long data is kept
- Accounts, Google connections, and saved routes are kept while the account exists and are deleted from the live database when the account is deleted, subject to the exceptions below. An individual route is removed when you delete it.
- Temporary route-generation sessions normally expire after 30 minutes of inactivity. Google OAuth transaction data expires after 10 minutes. Account verification links expire after 24 hours, password-reset links after 1 hour, and contact-form verification codes after 10 minutes.
- Share links remain active until revoked or the route or account is deleted. Revocation does not erase copies made by another person.
- Support correspondence is kept for as long as needed to handle the request, maintain an appropriate service history, prevent abuse, and establish or defend claims. It is periodically reviewed. Deleting an account unlinks the ticket from the account but does not necessarily erase the contact details and messages supplied in the ticket.
- Billing and accounting records are kept for the statutory period, normally 5 years from the end of the financial year to which the record relates under Danish bookkeeping law, and longer only where another obligation, dispute, or enforcement hold requires it.
- Security and operational logs are kept only as long as needed for security, troubleshooting, service integrity, and claims, using access limits and routine rotation. Deleted data can remain in protected backups until those backups rotate or are no longer required.
Account deletion and Google disconnection
Account settings let you permanently delete your ThWay account. For safety, we may require a recent password or Google reauthentication. Active Stripe subscriptions are canceled before local deletion; deletion stops if that cancellation fails. Account, Google-identity, saved-route, local billing-mapping, and complimentary-access records are then removed from the live database.
Limited billing, support, security, dispute, and backup records may remain for the periods and reasons in section 08. Stripe can retain payment records for its own legal duties. Removing ThWay in your Google Account is different: it revokes the Google connection but does not send ThWay a request to delete the ThWay account or its data.
Security
Measures used to protect data include encrypted transport, password hashing, hashed verification and reset tokens, encrypted HTTP-only authentication cookies, access controls, provider reauthentication for sensitive actions, signed Stripe-webhook verification, rate limits, data minimization, and restricted administrative access.
No online system can guarantee absolute security. Use a unique password, protect access to your Google account, sign out on shared devices, and contact us promptly if you suspect misuse. If a personal data breach creates a legal notification duty, we will notify the relevant authority and affected people as required.
Your data-protection rights
Subject to the conditions and exceptions in applicable law, you may ask us to access, correct, or delete your personal data; restrict or object to processing; and provide data you supplied in a portable format where portability applies. You may withdraw consent at any time where processing is based on consent, without affecting earlier lawful processing. You may also object specifically to processing based on legitimate interests.
Contact us to exercise a right. We may ask for proportionate proof of identity and clarification needed to find the data. We normally respond within one month; where the law permits more time for a complex request, we will explain the extension within the first month. Rights are not absolute, and we will explain any lawful refusal.
You may complain to the Danish supervisory authority, Datatilsynet, at Carl Jacobsens Vej 35, 2500 Valby, Denmark, or through its complaint page. You may instead contact the supervisory authority where you live or work or where an alleged infringement occurred.
Automated decisions and children
Thway does not use personal data for solely automated decisions that produce legal or similarly significant effects, and does not build advertising profiles. Route generation is automated, but it responds to route settings and does not make a legal or significant decision about you.
Thway is not directed to children under 13, and we do not knowingly collect their account data. A parent or guardian who believes a child has provided data without appropriate permission should contact us so we can investigate and delete it where required. Please do not place health information or other special-category data in route names, custom stops, or support messages unless it is necessary for your request.
Updates and related terms
We update this notice when our processing or legal obligations materially change. The effective date will be updated, and we will give additional notice where a change materially affects you or the law requires it.
General service rules appear in the Terms of Service, and billing-specific information appears in the Subscription Terms.