Privacy Policy
Summary
Last updated: 16 August 2026.
GreenRah is a walking-route app that shows shaded, cooler, and more accessible paths. We built this policy to be plain and specific: what we collect, why, how long we keep it, who we share it with, and how you stay in control. In short, we do not sell your personal data, we ask for consent before anything optional, and we collect only what the routing and account features need to work.
Who controls your data
The data controller is GreenRah OÜ, a private limited company (osaühing) registered in Estonia, operating the GreenRah application and website (together, "GreenRah", "we", "us"). Contact: support [@] greenrah {.} com.
Our lead supervisory authority for GDPR matters is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). If you live in another EU/EEA country, you may also contact your own national data protection authority.
Scope and who this applies to
This policy explains what personal data we process when you visit greenrah.com or use the GreenRah web app, why we process it, our legal basis, how long we keep it, and the rights available to you under the EU General Data Protection Regulation (GDPR) and Estonian law.
We launched first in Lisbon, are expanding to other cities in Portugal, and plan to grow across the EU. Because GreenRah is a web application, people anywhere in the world can access it. If you are outside the EU/EEA, we apply the same data-handling standards described in this policy to you as a matter of company policy, and you may additionally have rights under the data protection laws of your own country, which we will also honor on request.
Data we process without an account
To calculate a route, we receive the places or coordinates you choose (origin and destination), the trip date or time you set, and the mode you pick (for example Heat Smart or Accessible). We process this on a contractual/necessity basis, it is required to give you the routing result you asked for.
Location. Precise device location (GPS) is only read if you actively grant permission in your browser. It is used to center the map or set your starting point, and is not retained on our servers beyond what is needed to serve that single request unless you save a place as a Favorite. You can deny or revoke location permission at any time in your browser or device settings, the app still works with manually typed addresses (but you can not navigate easily). Our handling of location data follows GDPR data-minimisation principles: we do not build location history profiles of guests, and we do not sell location data to advertisers or data brokers.
We also automatically receive standard technical data needed to serve any web request (such as IP address, browser type, and approximate network location derived from the IP) for security, fraud-prevention, and basic service delivery. This is normal for any website and is not used to build an advertising profile of you.
Account data and signup
If you register, we store your email address and a one-way, salted password hash, we cannot see or recover your actual password. Optional profile fields may include a display name, avatar choice, traveler type, language, and units. We also store your email verification status, sign-in session identifiers, and a record of the consents you gave.
Signup requires acceptance. Creating an account requires you to tick a box confirming that you have read and accept this Privacy Policy and our Terms of Use. This is a condition of registration, without it, we will not create an account for you. Opening or browsing the public site without an account does not require this acceptance, but by using the app at all (with or without an account) you agree to the parts of these policies that govern general use, as described in our Terms of Use.
Legal bases: performance of a contract (to provide the account and features you request) and, where we ask separately, your consent.
Sign in with Google
You can create an account or sign in using Google Sign-In. In that case Google authenticates you and shares with us your Google account identifier, verified email address, and (if you provide it) your name. We store these so we can keep you signed in and show your name in Account. We do not receive your Google password, Gmail, Drive, or other Google data. We request only the standard Sign-In scopes (openid, email, and profile).
Continuing with Google means you accept this Privacy Policy and our Terms of Use. If you already have a GreenRah account with the same email, we link Google Sign-In to that existing account so you do not get a duplicate. You can delete your GreenRah account at any time from Account settings; that does not delete your Google Account.
Optional research contribution
Separately from the required acceptance above, you may opt in to: "Allow anonymized route contribution for urban climate research." If you tick this, we may include your anonymized or aggregated route insights (for example shade-gap or heat-exposure patterns) in research and city-climate analysis. If you leave it unticked, we will not use your account-linked data for that purpose. We store your choice as a yes/no preference and you can change it any time from your account settings or by emailing us. This processing relies entirely on your consent and you can withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Emails
We send transactional email (welcome, email verification, password reset, data-export or account-deletion confirmations) from an address such as no-reply [@] greenrah {.} com. Password-reset links expire after a short window for your security. Optional product emails (for example seasonal heat-wave alerts or tips) include an unsubscribe link and are only sent if you opt in; verification and security emails are not marketing and do not include an unsubscribe option, because they're essential to running your account.
Favorites, data export, and deletion
Saved places (a label and coordinates) are stored with your account so you can reuse them. You can request a portable copy of your personal data (GDPR Article 20) from your account settings or by emailing us; we aim to provide a machine-readable export within 30 days. When you delete your account, we anonymize or delete your identifying data and remove your favorites and active sessions, except where we must keep limited records to comply with a legal obligation, resolve a dispute, or enforce our agreements.
Retention
We keep account data while your account is active. After deletion, we anonymize or erase identifying data within a reasonable period. Security and abuse-prevention logs may be kept for a limited time strictly for integrity purposes. Aggregated or anonymized statistics, which can no longer identify you, may be kept indefinitely for research and product improvement.
Security
We use industry-standard safeguards including encrypted transport (HTTPS), hashed and salted passwords, secure session cookies, and access controls that restrict who inside our organization can reach production data. No system is perfectly secure, and we cannot guarantee absolute security of information transmitted over the internet. If we become aware of a data breach affecting your personal data that creates a real risk to your rights, we will notify affected users and the relevant supervisory authority as required by GDPR.
If you believe you have found a security issue, please report it responsibly to support [@] greenrah {.} com before disclosing it publicly.
International data transfers
We prioritize hosting and processing data within the EU/EEA. Where a service provider processes data outside the EEA, we require appropriate safeguards recognized under GDPR, such as an adequacy decision or Standard Contractual Clauses, before that transfer takes place.
Children's privacy
GreenRah is not directed at children and is not intended for use by anyone under 16 years old (or the minimum age of digital consent in your country, if higher). We do not knowingly collect personal data from children below that age. If you believe a child has created an account or provided us personal data, contact us at support [@] greenrah {.} com and we will delete it.
Automated processing
GreenRah calculates routes and heat/shade estimates automatically using environmental and map data with a special formula named Thermal Comfort Score. This is a functional calculation to answer the question you asked ("show me a cooler route"), it is not automated decision-making that produces legal effects or otherwise significantly affects you, and we do not use your personal data for automated profiling that impacts your rights.
Your rights
Under the GDPR you may request: access to your data, correction of inaccurate data, erasure ("right to be forgotten"), restriction of processing, objection to processing based on legitimate interests, and portability of the data you provided. You may withdraw any consent-based processing at any time without affecting processing carried out before withdrawal. You can exercise these rights by emailing support [@] greenrah {.} com; we will respond within one month as required by law.
You may also lodge a complaint with the Estonian Data Protection Inspectorate or the supervisory authority in your own EU/EEA country. If you live outside the EU/EEA, you may have equivalent rights under your local law, and we will honor reasonable requests consistent with this policy regardless of where you live.
Changes to this policy
We may update this policy as GreenRah grows into new cities and adds features. We will update the "Last updated" date above, and for material changes we will provide reasonably prominent notice (such as an in-app banner or an email to account holders) and, where required by law, ask for renewed consent before applying the change to you.
Contact
GreenRah OÜ, registered in Estonia. Privacy questions and rights requests: support [@] greenrah {.} com.