lenkkı
ExploreMy RoutesUploadsCollections
+ Upload route

Privacy policy

Last updated: 13 August 2026

This is a convenience translation. Only the German version is legally binding.

1. Controller

The controller within the meaning of the GDPR is:
Dennis Michalski, c/o Online-Impressum.de #5482, Europaring 90, 53757 Sankt Augustin, Germany
E-mail: [email protected] · Phone: +49 (0) 40 870 902 82

2. Principles

Lenkki is deliberately built to minimise data: there are no passwords, an account works without an e-mail address, we use no advertising trackers, and we serve fonts from our own server. Anonymised usage statistics (Matomo, self-hosted) only run with your explicit consent. We process personal data only insofar as it is necessary to operate the platform.

3. Server logs and abuse prevention

When you visit the site, our server necessarily processes your IP address, the time, the resource requested and the user agent (legal basis: Art. 6 (1) (f) GDPR — operational security). Logs are deleted after 7 days at the latest.

To protect against overload and abuse we limit the number of writing and computationally expensive requests per IP address. For this the IP address is counted in memory for at most one minute; it is not stored and not combined with any other data (Art. 6 (1) (f) GDPR).

4. Hosting and server location

Lenkki runs on servers we operate ourselves; the location is Germany. No external hosting provider with access to content or usage data is involved. Accounts, routes and media metadata are held in a database on those servers, uploaded files in the file system alongside. All traffic does, however, pass through the Cloudflare proxy described in section 5 before it reaches our server.

5. Cloudflare (DNS, reverse proxy and attack protection)

We use Cloudflare of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, as our DNS provider with the reverse proxy enabled (“orange cloud”). All HTTP(S) traffic to this site is therefore routed through Cloudflare’s network before it reaches our server — which means Cloudflare sees every page request. Processed in the course of this are your IP address, the request headers (browser, operating system, referrer, URL requested), the timestamp and connection metadata (TLS version, status code).

The purposes are protection against denial-of-service attacks and abusive traffic, faster delivery, and encryption of the transfer: Cloudflare terminates TLS and forwards the request to our server encrypted, so both legs are protected. The legal basis is our legitimate interest in the security and availability of the service (Art. 6 (1) (f) GDPR).

A data processing agreement under Art. 28 GDPR is in place with Cloudflare. The transfer to the USA relies on the EU-US Data Privacy Framework (Art. 45 GDPR), under which Cloudflare, Inc. is certified, and additionally on the EU standard contractual clauses (Art. 46 (2) (c) GDPR). Cloudflare generally retains log data for up to 24 hours for security purposes; aggregated statistics may be kept longer. Further information: Cloudflare’s privacy policy.

6. Cookies and local storage

  • Session cookie (encrypted): keeps you signed in — necessary, § 25 (2) TDDDG.
  • Language cookie (lk_locale): remembers your chosen language — necessary for the service to work.
  • localStorage: theme, map style, your cookie decision (lk_consent), view settings (among others panel sizes and the progress of the intro tour) and the list of routes stored locally (anonymous use). This data does not leave your browser unless you assign your routes to an account by signing in.

These necessary cookies and storage operations are required to operate the service (§ 25 (2) TDDDG) and need no consent. We do not use marketing or advertising cookies.

Statistics with Matomo (only with consent)

To improve the platform we use the self-hosted analytics software Matomo on a server of our own under our domain; no third party is involved. If statistics are not set up on this installation, nothing is recorded even with your consent — the consent then has no effect. Matomo is loaded only once you choose “Accept all” in the cookie banner (legal basis: Art. 6 (1) (a) GDPR, § 25 (1) TDDDG). Recorded are, among other things, the pages visited, the browser used and a truncated IP address; the data stays on our server and is not passed on to third parties. If you choose “Necessary only”, no statistics cookie is set and nothing is recorded. You can withdraw or give your consent at any time with effect for the future:

7. User account (sign-in via third-party providers)

Registration happens exclusively via sign-in providers (OAuth 2.0/OpenID Connect). Google, GitHub and Strava are offered insofar as they appear in the sign-in menu — providers that are not set up are not shown there and therefore process no data. We store only: the provider’s stable user identifier, your display name, the URL of your profile picture where applicable, and your planner preferences. No e-mail address, no passwords, no access tokens. When signing in, the privacy terms of the respective provider apply (Google, GitHub, Strava). Legal basis: Art. 6 (1) (b) GDPR. You can delete your account at any time in the profile settings; your account data is then removed in full.

8. Routes, photos and videos (uploads)

Uploaded GPX files contain location data and, where applicable, timestamps of your activity. Photos are matched to route sections using their EXIF coordinates; we then strip the EXIF data from the stored image file, so that camera model, serial number and original timestamp are not published along with it. Uploaded media stays private at first — only you can see it. Only once you explicitly submit a medium for publication and it has been approved is it stored per route segment and visible to all users whose tours run along the same ways. You can withdraw that decision at any time; the medium is then immediately visible to you alone again. The legal basis for publication is your consent (Art. 6 (1) (a) GDPR). For videos — where video upload is enabled for your account — the following applies: uploaded videos are not stored or played back as a video file; our server converts them into a series of still images instead (roughly every 40 metres of route). Before that conversion you can hide sections of the video — hidden sections are never converted into images and are at no point visible to anyone. The uploaded raw video exists only temporarily between the upload and the completion of your edit and is deleted automatically afterwards (retention: see section 14). The resulting images pass through automatic anonymisation before publication (blurring of faces and, depending on the method in use, licence plates) — just like photos; until then they are visible only within your own tour. Anonymisation follows the state of the art; a hundred per cent detection rate cannot be guaranteed. Legal basis: Art. 6 (1) (b) GDPR. Do not upload media in which third parties are identifiable without their consent.

Device location: whenever the site asks for your location, you decide in the browser, and the permission applies to that visit only. In live mode on a tour page your position stays inside your browser (playhead, map marker) — it is neither transmitted to us nor stored. If you use “Take a photo” and the shot carries no coordinates of its own, the current position is sent along with the photo and stored as its place on the route — exactly as EXIF coordinates would be. For place search in the route planner we pass the requested coordinates to the services listed in section 12. Legal basis: Art. 6(1)(a) and (b) GDPR.

9. People shown in uploaded images

Photos, and the images generated from videos, may show people who did not upload them themselves. We do not collect that data from the people concerned but receive it from the person uploading — this notice informs them of that origin pursuant to Art. 14 GDPR. Processed are image data as well as the place and time the shot was taken; the purpose is a route-related preview of a tour, the legal basis our legitimate interest in a realistic view of the route (Art. 6 (1) (f) GDPR). Informing the people shown individually is impossible because they are unknown to us (Art. 14 (5) (b) GDPR); this policy takes the place of that notification.

Before publication, every image passes through automatic blurring of faces (and, depending on the method in use, licence plates) — nobody is meant to remain identifiable. Because no method catches every case: anyone who recognises themselves in an image can demand its removal — informally to the contact address in the legal notice, or via the ⚑ button on the image itself. We remove such images without requiring proof that you are the person concerned. The rights set out in section 15 apply to you even if you did not upload the image yourself.

10. Publishing tours

Your tours are private by default: reachable only via the direct link, listed nowhere, and excluded from search engines. Only when you explicitly publish a tour is it listed under “Explore”, included in our sitemap and opened up to search engines; your display name is then shown as the author, along with an automatically generated preview image of the route. Legal basis: Art. 6 (1) (a) GDPR (consent). You can withdraw the publication at any time — the tour then becomes private again; copies already made by search engines are beyond our control.

11. Map display (content from third-party servers)

To display maps, your browser loads map tiles directly from the servers of the following providers; this necessarily transmits your IP address (Art. 6 (1) (f) GDPR — map display required for the service to function, in part a transfer to third countries):

  • OpenFreeMap (Ridgeline map style: map data, fonts and icons — also for the map previews on the route cards)
  • OpenStreetMap Foundation (OSM map style)
  • OpenTopoMap and OSM France / CyclOSM
  • Esri (satellite imagery, hillshading)

Insofar as data is processed outside the EU in the course of this — which concerns Esri (USA) in particular — the providers rely on the European Commission’s standard contractual clauses or on the EU-US Data Privacy Framework. You can avoid that transfer by staying with the Ridgeline or OSM style in the map selector.

12. Services used server-side

For route calculation and place search, our server (not your browser) calls the following services; your IP address is not transmitted to them, but the requested coordinates or search terms are: BRouter (routing), Photon/Komoot (address search), Nominatim/OpenStreetMap Foundation (reverse lookup for place names), Overpass API instances (way attributes). For an approximate location as a fallback, our server queries its own public IP location at ipwho.is. For the route film, our server also retrieves — insofar as this feature is set up — street-level imagery from Mapillary/Meta (image positions and thumbnails along the route, per leg while a route is being drawn, and in the preview of route alternatives) and serves it to your browser itself — your browser makes no direct connection to Mapillary/Meta; only the coordinates of the requested route are transmitted, not your IP address.

13. Feedback, reports and getting in touch

Messages sent through the feedback form and the report function are stored on our own server. The feedback form transmits technical context data (page visited, language, colour scheme, window size, browser identifier) along with the contact details you volunteer. If our internal ticket integration is active, the content is additionally transferred into our self-operated ticket system — no third party is involved. Legal basis: Art. 6 (1) (f) GDPR (improving the service and handling reports).

If you write to the e-mail address given in the legal notice, we process your sender address, the content of your message and the time in order to answer your enquiry (Art. 6 (1) (f) GDPR, or (b) for contractual matters). We delete the correspondence once it has been dealt with conclusively and no statutory retention obligations stand in the way.

14. Retention

Accounts until you delete them; routes and media until you or their owner delete them; server logs as per section 3. After account deletion, public media and routes you uploaded remain in the service without a personal reference unless you delete them beforehand. Uploaded raw videos are deleted automatically at the latest when you complete your edit (section 8); if you do not complete the edit, we delete the raw video automatically after 14 days at the latest. The images generated from a video are subject to the retention described in the first sentence, like any other media.

Backups: we create nightly backups of the database and the files and keep the seven most recent ones. If you delete an account, a route or a medium, it disappears from live operation immediately, but it may still be contained in those backups for up to seven days, until the backup in question is overwritten. Backups are restored solely to recover from data loss.

15. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Consent you have given — for the statistics, say, or for publishing a tour — can be withdrawn at any time with effect for the future. Please use the contact address given in the legal notice. You can export your routes as GPX at any time yourself (data portability) and delete them.

You also have the right to lodge a complaint with a data protection supervisory authority. What governs is the controller’s place of establishment — this is Hamburg; the address given in the imprint is a mere delivery address. The authority responsible is therefore:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Straße 22, 20459 Hamburg, Germany, datenschutz-hamburg.de.
You may equally turn to the supervisory authority of your place of residence or work.

16. Automated decision-making

No automated decision-making or profiling takes place.

17. Data security

The connection to Lenkki is TLS-encrypted throughout. Session data is held in an encrypted cookie, and access to administrative functions is restricted to explicitly named accounts. Uploaded media is retrievable only by the person who uploaded it until it is released — a check that applies not just to what is displayed but to the delivery of the files themselves.

18. Changes to this policy

We adapt this policy when the legal situation or the scope of Lenkki changes. The version published on this page is the one that applies; the date above shows its current state.

Legal noticeTermsHome
lenkkı
ImprintPrivacyTerms
© 2026 Lenkki