Privacy and Cookies
1. Data controller
| Controller | Rodrigo Márquez González |
|---|---|
| Spanish tax ID (NIF) | 07075513T |
| Address | Carrer del Cardener 16, 2.º, 08024 Barcelona, Spain |
| Data protection contact | hello@sherppi.app |
| Data Protection Officer | Not appointed. The conditions of article 37 GDPR do not apply. This assessment will be reviewed as the volume of processing grows. |
Sherppi Tech, S.L. is in the process of incorporation. Once registered, it will become the data controller and this policy will be updated. That change will be communicated through the application and the email address linked to the account.
Language. This policy is published in Spanish and in English. The version that applies to you is the one in the language in which you created your account and use the service. Both versions are kept aligned; if a discrepancy is found, we will correct it, and in the meantime the version in the language you contracted in prevails for you.
2. What data we process
The first four are the core of the service. The rest are what the application itself generates as it runs.
| Data | What it is |
|---|---|
| Email address | The address you sign up with and the one we send your access code to. We do not use passwords. |
| Location | Your device's position when you use the Radar, unlock geolocated content or confirm that you have arrived at a stop. |
| Listening and completion activity | Which sherppis you open, which chapters you play, which arrivals you confirm, what you complete, and in which city and neighbourhood. |
| Quiz answers | What you answer in the archetype quiz and the resulting scores on each axis. |
| Name | The name you choose when signing up. It is used to address you and for the initial of your S-Code. |
| Passport | Your S-Code, your Passport type and number, and the archetype assigned. |
| Rewards | STK balance, historical total, total by city and the ledger of movements. |
| Crew | Which Crew you belong to and who its members are. |
| Technical data | IP address, device and browser type, session identifiers, and access and error logs. |
| Communications | What you write to us and how we handle it. |
| Transactions | Once payment is activated: what you bought, the amount, the date and the reference. Your card number is handled directly by the payment provider; we never see it. |
We do not process special categories of data. We do not ask for, and do not want to receive, information about health, beliefs, membership, sexual orientation or any other data covered by article 9 GDPR.
3. Why we process your data and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and managing your account, sending you the access code and providing the service. | Performance of the contract (art. 6.1.b GDPR). |
| Knowing where your device is in order to show you what is nearby, unlock geolocated audio and validate arrivals. | Performance of the contract: without location those functions do not exist. Your operating system's permission is also requested expressly. |
| Issuing your Passport, assigning you an archetype and, where applicable, a Halo number. | Performance of the contract. |
| Recording your activity and keeping track of your STK. | Performance of the contract. |
| Showing your activity to the people in your Crew. | Performance of the contract, following your voluntary decision to join a Crew. |
| Processing purchases, issuing receipts and handling refunds. | Performance of the contract and legal, tax and accounting obligations (art. 6.1.c). |
| Handling enquiries, complaints and the exercise of your rights. | Performance of the contract and legal obligation. |
| Preventing fraud and detecting faked locations or progress, to protect the integrity of the reward system. | Legitimate interest (art. 6.1.f): keeping the service fair. |
| Measuring use of the service in order to improve it, with statistics produced on our own servers, aggregated and without installing identifiers on your device. | Legitimate interest. |
| Producing aggregated, anonymous statistics on how the city is used, by neighbourhood and time slot, and offering them to third parties such as hotels or public authorities. | Legitimate interest. The statistics do not allow anyone to be identified, and you can object to your activity being included (section 4). |
| Sending you commercial communications about Sherppi. | Consent, or legitimate interest in respect of similar services to existing customers (art. 21.2 LSSI). Revocable in every message. |
If we add third-party analytics tools in future, they will not be activated until you give us your consent, and we will update this policy before doing so.
4. Location and aggregated city use
Location is the most sensitive data we process, so we explain it separately.
How we use it.
- It is obtained only while the application is open and in use. There is no background tracking and no continuous monitoring of your movements.
- It serves three purposes: showing you what is nearby in the Radar, unlocking the audio of a Flash, a Spot or a Tour stop, and recording that you have completed a piece of content.
- Of your route we keep the neighbourhood and the moment, not a trail of coordinates. Exact coordinates are used at the instant of verifying that you are on site and are not retained in association with you.
- You can withdraw the permission whenever you want from your device or browser settings. If you do, content that depends on location stops being accessible; Casts keep working.
- Accuracy depends on your device and your surroundings. Where the service offers it, there is an alternative for confirming arrival manually.
Statistics on city use. From that neighbourhood and time-slot data we produce aggregated statistics on how the city is travelled: which areas, at what times, with which formats. We offer those statistics to third parties interested in the use of urban space, such as hotels or public authorities.
Three limits we commit to:
- The statistics are aggregated and anonymous. We never share individual profiles, one person's route, or any data that would allow you to be identified.
- Where the number of people in a neighbourhood and time slot is too small to guarantee anonymity, that figure is not published.
- You can object to your activity being included in these statistics by writing to hello@sherppi.app, without this affecting your use of the application.
5. Profiling and automated decisions
On completing the quiz, the system calculates an archetype from your answers and attaches it to your Passport. This profiling is for entertainment and for personalising the content shown; it produces no legal effects and does not significantly affect the user. The archetype can be changed at any time by retaking the quiz.
Assignment of the Halo Passport is automatic and decided by order of quiz completion within a run limited to one hundred units. It is an automated process by design, precisely to ensure that the order is objective rather than discretionary. Anyone may request information about the logic applied, and human review of an assignment, by writing to hello@sherppi.app.
We do not carry out profiling for third-party advertising purposes.
6. Visibility within the Crew
On joining a Crew, the user shares with its members —a maximum of twelve— their name, avatar, archetype, Passport and the sherppis they complete, together with the date, the time and the Sherppa who narrated them.
This visibility is the direct consequence of a voluntary action: nobody joins a Crew without sharing or accepting an S-Code. The user may leave a Crew at any time, and from that moment their subsequent activity stops being visible to that group.
The S-Code works as a public key. Anyone who knows it can request to join the Crew. We recommend sharing it only with people you trust.
7. Who has access to the data
We do not sell or transfer your data to third parties for commercial purposes. The following providers, acting as processors under a contract compliant with article 28 GDPR, access it as necessary to provide the service:
| Provider | Service | Where it is processed |
|---|---|---|
| Supabase | Database and application hosting | [PENDING: project region] |
| [PENDING: transactional email provider] | Sending your access code and your account emails | [PENDING] |
| [PENDING: mapping provider] | Loading the maps in the Radar and in Tours | [PENDING] |
| Stripe | Payment processing, once the gateway is activated | European Union and United States |
| [PENDING: voice cloning provider] | Generating the translated versions of the audio, once translation is activated | [PENDING] |
We do not use third-party analytics providers. Usage statistics are calculated on our own infrastructure and do not leave it.
The voice cloning service processes the recordings of the Sherppas, with their express authorisation. It does not process the data of the people listening.
In addition, your data may be disclosed to public authorities, law enforcement bodies and courts where there is a legal obligation, and to legal or accounting advisers in the course of their work.
Sherppas do not have access to the personal data of the people who listen to their content. They receive aggregated information on the performance of their pieces, for settlement purposes.
8. International transfers
Some providers may process data outside the European Economic Area, in particular in the United States.
Where that happens, the transfer relies on a European Commission adequacy decision —including the EU-US Data Privacy Framework for certified entities— or, failing that, on Standard Contractual Clauses with any supplementary measures required.
You can ask us for information on the safeguards applied to each transfer at hello@sherppi.app.
9. How long we keep the data
| Data | Retention period |
|---|---|
| Account and profile | For as long as the account is active. |
| Activity, Diary and STK ledger | For as long as the account is active. |
| Billing and transaction data | Six (6) years from the transaction, under the Spanish Commercial Code, and four (4) years for tax purposes. |
| Technical and security logs | Twelve (12) months, unless needed to investigate an incident. |
| Communications and complaints | Three (3) years from closure. |
| Aggregated statistics by neighbourhood and time slot | No time limit: once aggregated and anonymised they stop being personal data and can no longer be linked to you. |
| Data after account closure | Deleted or irreversibly pseudonymised. Only what is strictly necessary to meet legal responsibilities is kept, blocked, for the applicable limitation periods. |
STK ledger. For accounting integrity, that ledger is append-only and is not modified. When you cancel your account, its entries are detached from your identity by irreversible pseudonymisation: the ledger keeps the economic fact, but no longer allows anyone to know it was yours.
10. Your rights
You may at any time exercise your rights of access, rectification, erasure, objection, restriction of processing and portability, and withdraw any consent you have given, without this affecting the lawfulness of processing carried out beforehand.
To exercise them, write to hello@sherppi.app from the address linked to your account, or to the postal address in section 1, stating the right you are exercising. We may request additional information if there is reasonable doubt as to your identity.
We will respond within one month, extendable by a further two months where complexity justifies it.
A technical limit you should know about. The S-Code is immutable by design: it permanently identifies the Passport and underpins Crew links already shared. It cannot be rectified or reissued. The right of rectification is satisfied over the name, the avatar and the archetype; the S-Code disappears only when the account is deleted.
If you consider that the processing does not comply with the law, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es, C/ Jorge Juan 6, 28001 Madrid), without prejudice to contacting us first. If you reside in another Member State of the European Union, you may also lodge your complaint with the supervisory authority of your country of residence.
11. Security
We apply technical and organisational measures appropriate to the risk: encryption of communications, role-based access control, logging of administrative operations and backups.
Validation of whether a piece of content has been completed is performed on the server, not on the device, precisely to protect the integrity of the reward balance.
No system is infallible. In the event of a security breach posing a high risk to your rights, we will inform you without undue delay, and we will notify the supervisory authority where required.
12. Minors
The service is intended for people aged 18 or over. We do not knowingly collect data from minors. If you become aware that a minor has created an account, tell us at hello@sherppi.app and we will cancel it and delete the data.
13. Changes to this policy
This policy may be updated because of regulatory, technical or service changes. The version in force is the one published, with its date of update. Substantial changes will be communicated through the application or the email address linked to the account.
Cookie Policy
14. What cookies are and which ones we use
A cookie is a small file saved on your device when you visit certain pages. This section also covers other browser storage technologies that do the same thing.
Sherppi does not use advertising, tracking or third-party analytics cookies. We only use the storage that is essential for the application to work.
| Type | Purpose | Consent? | Duration |
|---|---|---|---|
| Technical and session | Keeping you signed in after you enter the code, remembering the state of the application and protecting access. | No (art. 22.2 LSSI). | Session and up to [PENDING] |
| Preferences | Remembering the language and the settings you choose. | No: they respond to an explicit choice of yours. | [PENDING] |
| Third-party mapping | Loading the maps in the Radar and in Tours. | [PENDING: depends on the provider — yes, if it installs its own identifiers] | [PENDING] |
How we measure usage. Usage statistics are generated on our own servers, from the application's logs, in aggregated form and without installing anything on your device. That is why they require no consent and do not appear in the table.
[PENDING: replace the table with the real inventory —technical name, owner, purpose and expiry of each cookie or local storage entry, including the Supabase Auth session token— once the application has been audited. A generic table does not meet the Spanish Data Protection Agency's standard.]
15. How to manage cookies
While Sherppi uses only technical and preference storage, no consent panel is shown, because the law does not require one for that kind of storage. This policy is the information that replaces such a panel.
If in future we add third-party analytics, mapping that installs its own identifiers, or any other non-exempt technology, we will activate a panel allowing you to accept all, reject all or configure by category, with the same ease in all three options, and those technologies will not load until your consent is obtained. You will be able to change your choice at any time from the settings link available in the site footer.
In any case, you can block or delete storage from your browser settings. Note that disabling technical storage prevents the service from working.
16. Third parties
If we add third-party technologies, they will additionally be governed by the privacy policies of their owners, whose links we will provide in the settings panel and on this page.