WATTALO · UPDATED: SEPTEMBER 6, 2026
Privacy Policy
This policy explains the data the current Wattalo PWA and API use and reflects the reviewed source code.
Service provider and contact
- Seller / service provider
- Püspöki Zsolt
- Service / business location
- 2022 Tahitótfalu, Bólyai János utca 2., Hungary
- Support contact
- support@wattalo.com
1. Account and authentication data
Google provides an external subject identifier and may provide email and display-name snapshots. Wattalo maps that identity to a random opaque Wattalo user ID and stores login timestamps and an Admin flag.
Wattalo does not store Google access tokens. A secure, HttpOnly authentication cookie uses a 30-day sliding lifetime. Short-lived Google correlation and antiforgery cookies support sign-in and protected requests. Server-side Data Protection keys protect authentication state and persist across restarts.
2. Route-planning requests
A planning request sends the chosen origin coordinates, ride time, target power, direction, workout, rider/bike values, planning country, route style and blacklist choices needed to calculate a route.
The current database schema does not store planning requests or generated private route results. Server diagnostics record a request ID, region, processing stage, timings, result category and graph-cache counts; they do not intentionally log exact coordinates, street names, GPX points or account identity.
The graph cache contains reusable map/elevation routing data, not a rider’s request history.
3. TCX-derived profile
Raw TCX XML is read and processed only in your browser. Raw files are not uploaded. Filenames, recorded positions, timestamps and per-sample history are not sent to the Wattalo API.
If enabled, a planning request sends only the derived profile schema version and 20 gradient-bin median watt values. The browser may store that derived profile, including a local accepted-segment count, with planner settings. The server does not persist raw TCX or the derived planning request.
4. Shared routes
Creating a share stores a random 128-bit public share ID, creation/expiry timestamps, route geometry, distance, estimated duration, target power and optional direction. It does not store the sharing account ID, rider profile, IP address or full planning request with the share.
Anyone who has the unguessable link can open the shared route. The configured lifetime is currently 30 days; expired records are removed by bounded periodic cleanup.
5. Billing data
When billing is enabled, Paddle receives the customer, checkout, payment and subscription information needed to provide hosted billing. Wattalo does not receive or store raw payment-card details.
Wattalo stores only linkage and entitlement records such as Paddle customer ID, subscription ID, status, event timestamps, short-lived opaque checkout references and processed webhook event metadata.
6. Browser storage, cookies and analytics
Browser local storage holds language and planner preferences, including rider/bike settings, route preferences, blacklists and the optional TCX-derived profile.
Cookies are used for authentication, Google sign-in correlation and cross-site request forgery protection. The reviewed PWA contains no advertising, analytics or third-party tracking integration. Loading Paddle checkout occurs only after an eligible user chooses a subscription action.
7. Retention, security and your choices
Shared-route and authentication-cookie periods are stated above because they are fixed in current configuration. Other account, entitlement, operational log, backup and billing retention periods are not yet finalized.
You can remove locally stored preferences through browser site-data controls and stop sharing a route link. Send requests about access, correction, deletion, or other applicable privacy rights to support@wattalo.com.