Privacy Policy
Applies to the iHike and iHike Guide mobile apps · Last updated: 9 July 2026
This Privacy Policy explains how iHike ("iHike", "we", "us" or "our") collects, uses, shares and protects your personal data when you use the iHike app (for hikers) and the iHike Guide app (for guides and trip organisers), together with our related websites and back-end services (the "Services").
We are the data controller for your personal data. If you do not agree with this policy, please do not use the Services.
1. What this policy covers
iHike is an outdoor and hiking platform. Hikers use it to discover trips and trails, book or join them, follow guides, track their activity and take part in a community (posts, stories, chat and reviews). Guides use the iHike Guide app to publish trips, manage bookings and receive payouts. This policy applies to both apps because they share the same back-end and data model.
2. Information we collect
2.1 Information you provide to us
- Account and identity — your email address, display name and password. Sign-in is handled by Amazon Cognito; we never see or store your password. You may also add a phone number.
- Profile — profile photo, short bio and any other details you add to your profile.
- Content you create — posts (photos, videos and captions), 24-hour stories, reviews and ratings, comments, and messages you send in one-to-one chats and trip group chats.
- Bookings and activity — the trips you book or join, dates and times, coupons used, wallet balance and your booking history.
- Payments — when you pay for a booking, your card details are entered into Stripe's secure payment sheet and sent directly to Stripe. We receive only a confirmation and the transaction amount — not your full card number, CVV or expiry.
- Guide information (iHike Guide app) — if you are a guide, we also collect your guide/business name, description, address and precise coordinates, contact links (phone, WhatsApp, Instagram, Facebook, YouTube, website), certifications, languages, specialties, experience, staff details you add (name, phone, photo), and payout bank details (account holder, account number, SWIFT and, if provided, a cheque image).
2.2 Information we collect automatically
- Location — with your permission, we use your device location while you are using the app (in the foreground) to show nearby trips, display your position on the map and convert addresses to map coordinates. During a hike you can use live activity tracking (route and speed); this data is stored locally on your device. Sharing your live location is controlled by an in-app toggle, and in the current version this tracking data is not sent to our servers.
- Device and technical data — your device type, the sign-in method you used, and basic diagnostic information needed to operate the app. Authentication tokens are stored securely on your device.
We do not use third-party advertising or analytics SDKs, and we do not use advertising identifiers (such as Apple's IDFA) or track you across other apps and websites.
2.3 Information from third parties
Social sign-in — if you choose "Sign in with Apple" or "Sign in with Google" in the iHike app, that provider shares a basic account identifier and, where you allow it, your email address so we can create or access your account.
3. How we use your information
- To create and manage your account and authenticate you.
- To provide the core Services: show trips and maps, process bookings, enable community features (posts, stories, chat, reviews) and, for guides, manage listings and payouts.
- To process payments (via Stripe) and guide payouts.
- To keep the Services secure, prevent fraud and abuse, and enforce our terms.
- To provide support and respond to your requests.
- To comply with legal, accounting and tax obligations.
4. Legal bases for processing
Where the Kosovo Law No. 06/L-082 on Protection of Personal Data, the EU/UK GDPR or equivalent laws apply, we rely on the following legal bases:
- Performance of a contract — to provide the Services, your account, bookings and payments.
- Consent — for access to your location, camera and photos, and for any optional features. You can withdraw consent at any time in your device or app settings.
- Legitimate interests — to secure the Services, prevent fraud, keep the community safe and improve the app.
- Legal obligation — to meet accounting, tax and lawful-request requirements.
5. How we share your information
We share personal data only as described below. We do not sell your personal data.
- Service providers (processors) — trusted companies that run parts of the Services on our behalf, listed in Section 6.
- Other users — content you choose to share — your profile, posts, stories, reviews, and messages — is visible to the users, guides or groups you share it with. Public posts may be visible to all users of the community.
- Legal and safety — authorities or third parties where required by law, to enforce our terms, or to protect the rights, safety and property of users and the public.
- Business transfers — if the Services are involved in a merger, acquisition or asset sale, subject to this policy.
6. Third-party services we use
- Amazon Web Services (AWS) — Cognito: user authentication, sign-up, sign-in and email verification codes. Receives your email address, display name, password and, for social sign-in, the basic profile returned by the provider. Servers are located in the EU (Stockholm).
- Amazon Web Services (AWS) — S3 & hosting: secure storage of uploaded media and app back-end hosting. Stores the photos, videos and images you upload (profile, posts, stories and — for guides — documents) in a private EU bucket accessed via time-limited links.
- Stripe: processing of card payments for bookings. Receives the card and payment details you enter, sent directly from your device to Stripe. We do not receive or store your full card number.
- Google — Maps Platform: displaying maps, markers and converting addresses to coordinates. Receives approximate/precise location and map queries when a map is shown.
- Apple / Google — Sign-In: optional single sign-on in the iHike app. If you choose social sign-in, receives/shares the basic account identifier and email.
Each provider processes data under its own privacy terms. We keep this list up to date; if we add analytics, push notifications or attribution tools in the future, we will update this policy before doing so.
7. International data transfers
Our back-end, authentication and media storage are hosted in the European Union (AWS, Stockholm region). Some providers, such as Stripe and Google, may process data in other countries. Where personal data is transferred outside Kosovo or the European Economic Area, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
8. Data retention
We keep your personal data for as long as your account is active. After you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must keep certain records longer to meet legal, tax, accounting or dispute-resolution obligations. Activity data stored locally on your device (such as recorded tracks) remains on your device until you delete it or uninstall the app.
9. How we protect your data
We use technical and organisational measures to protect your data, including encryption of data in transit, secure storage of authentication tokens on your device, private media storage accessed through time-limited links, and access controls on our systems. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Your privacy rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate or incomplete data;
- delete your data ("right to be forgotten");
- restrict or object to certain processing;
- data portability (receive your data in a portable format);
- withdraw consent at any time; and
- lodge a complaint with your data protection authority.
To exercise these rights, contact us at ihike.system@gmail.com. If you are in Kosovo, you may also lodge a complaint with the Information and Privacy Agency (Agjencia për Informim dhe Privatësi), the supervisory authority under Law No. 06/L-082 on Protection of Personal Data.
11. Account and data deletion
You can delete your account and associated personal data from within the app, or by contacting us at ihike.system@gmail.com. When you delete your account, we remove or anonymise your personal data, subject to the limited legal retention described in Section 8. Some content you shared publicly or in group chats may remain visible to others unless you remove it first.
12. Children's privacy
The Services are not directed to children under 16, and we do not knowingly collect personal data from them. You must be at least 18 to make bookings or payments, or have the consent and supervision of a parent or legal guardian. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. We will change the "Last updated" date above and, for significant changes, provide notice in the app or on our website. Your continued use of the Services after an update means you accept the revised policy.
14. Contact us
If you have questions about this policy or your personal data, contact:
iHike
Email: ihike.system@gmail.com
Phone: +383 48 296 722
Kosovo
This policy is governed by the laws of Kosovo, including Law No. 06/L-082 on Protection of Personal Data.