Plain language. The Cycling Commons dataset is non-personal — open geodata about places, never about people. The platform account is a different matter: it holds personal data (email, credentials, session logs). Here's what we hold, why, and the control you have over it.
Last updated 15 September 2026
The data controller is BikeCoders (bikecoders.life), based in the Netherlands, which stewards the Cycling Commons today. As set out in our governance, the Commons is committed to spinning out to an independent Dutch foundation; the controller will transfer accordingly, and this page will be updated.
Questions about your data: info@cyclingcommons.org (or use the Contact). You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
We have not appointed a Data Protection Officer (DPO), and the law does not require one of us: we are a small operation, we do not monitor people on a large scale, and special-category data is not part of what we do (GDPR Art. 37). Data protection questions and requests go to the same address as everything else, info@cyclingcommons.org (or use the Contact), and a person reads them. If that ever changes and we do appoint one, this page will name them.
We ask for the minimum needed to run an open, accountable map. We never ask for your real name.
We keep this light. We set two cookies, both of them strictly necessary, and both listed in full below. For usage statistics we run self-hosted analytics on our own infrastructure: it receives the page URL, referrer, screen size and browser type, and it receives your IP address, which is personal data, but does not store it. The address is used only to work out an approximate location (country, region and city) and to derive a one-way session identifier, and is then discarded. No analytics cookies are set, no visitor is given a persistent identifier or tied to an account, and there is no cross-site or cross-device tracking. Analytics data stays on our own infrastructure and is never shared with, or sold to, third parties.
| Name | What it does | How long it lasts |
|---|---|---|
PHPSESSID |
Keeps you signed in, and carries the token that protects every form on the site against cross-site request forgery (CSRF), an attack in which another website makes your browser submit a form here as you. It is set when you sign in, and on the few pages that carry a form we have to remember for you, such as the contact page. Reading the map and the rest of the site sets no cookie at all. It holds a random identifier and nothing else: no name, no email address, no record of what you looked at. | Until you close your browser |
REMEMBERME |
Signs you back in on your next visit without asking for your password. Set only if you tick Remember me when you sign in, and removed when you sign out. | 7 days |
That is the whole list. We set no advertising cookie, no analytics cookie and no cross-site tracking cookie, on any page. Both cookies above are strictly necessary to deliver something you asked for, so the law needs no consent for them, and that is why there is no cookie banner here. If we ever added something that did need one, we would ask you first rather than assume.
The map also keeps a few of your own settings in your browser's local storage: the light or dark map theme, the area you last looked at, and which filters you had switched on. That is not a cookie, it is never sent to our server, and clearing your browser data removes it. No other website can read it. A browser keeps each site's local storage sealed off from every other site, so what we store here is readable by this site alone.
First, what is not in these lists. We run as much of this ourselves as we can: the map data, the route planning, the elevation model behind the climb gradients, the photo storage and even the usage statistics all sit on our own machines. Two services we used to call out to, for routing and for elevation, were brought in-house in 2026 for exactly this reason. It is slower to build that way and it costs more. It is also why your browser talks to five outside services instead of twenty, and why the tables below are as short as they are: every name in them is one we could not reasonably run ourselves.
Three companies hold or handle your data on our instructions. They are our processors: they may only do what we tell them to, under a written contract, and they may not use your data for anything of their own.
| Who | Where | What they do for us | What they can see |
|---|---|---|---|
| Hetzner Online GmbH | Falkenstein, Germany (EEA) | Runs the machines: the website, the database, and the storage that holds uploaded photos. | In principle everything we store, because it sits on their hardware: your email address, your contributions, your photos and the server logs. Passwords and two-factor secrets are unreadable even there (see How we protect it). |
| Scaleway SAS | European Economic Area | Delivers the email the site itself sends (address confirmation, password reset, deletion code, moderation messages), and stores the nightly backups. | Your email address and the contents of the messages the site sends you. The backups are encrypted on our own servers before they are sent, so their contents cannot be read at the other end. |
| Proton AG | Switzerland (covered by an EU adequacy decision) | Holds the project mailbox, the address printed on this page, and the replies a person here writes back. | Your email address and whatever you chose to write to us, for as long as the conversation is kept. |
The map is assembled in your browser, so a few pieces are fetched straight from the people who publish them rather than passing through us. We never hand them your account, your display name or your email address. They do see the network address your request comes from, because every request on the internet carries one. Nothing in this list loads until you open a page that uses it.
| Service | What it is for | What it receives |
|---|---|---|
| OpenFreeMap | The base map: the roads, water and place names under everything else. | Your IP address, and which map squares you asked for. |
| Esri | The satellite view, only once you switch to it. | Your IP address, and which image squares you asked for. Esri is in the United States. |
| Mapillary | Street-level photos, only once you open the street view. | Your IP address, and which photos you opened. Mapillary is run by Meta Platforms Ireland Limited, in Ireland, and the image files themselves come from Meta's content network, which is worldwide. |
| Photon | Place search, while you type in the search box. | Your IP address, and the words you type into the search box. Photon is run by komoot, in Germany. |
| Wikimedia Commons | Reference photos of some climbs and places, where the picture comes from Wikimedia Commons. | Your IP address, and which photo the page showed. The Wikimedia Foundation is in the United States. |
Two of these sit outside the European Economic Area (EEA): Esri and the Wikimedia Foundation, both in the United States. If you never open the satellite layer and never look at a page carrying a Commons photo, your browser never contacts either. See International transfers below.
Some infrastructure providers may process data outside the European Economic Area. Where they do, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses or an adequacy decision.
The law asks us to take measures that fit the risk (Art. 32). In plain words:
That is the short version. The exact measures, and the reasoning behind each one, are in our public source code, which is the point of building it in the open: you do not have to take a security paragraph on trust.
No system is perfect and we will not pretend ours is. There is no certification behind that paragraph and no penetration test: what there is, is a small system that keeps as little as it can, and code anyone can check.
If personal data is lost, exposed, or reached by somebody who should not have it, and that is likely to put people's rights at risk, we report it to the Autoriteit Persoonsgegevens within 72 hours of finding out (Art. 33). If the risk to you personally is high, we also contact you directly and without delay (Art. 34), in plain language: what happened, which of your data was involved, what we have done about it, and what you should do. We keep an internal record of every breach, including the ones we are not obliged to report, so the pattern stays visible to us even when no single one is reportable.
Under the GDPR you have the following rights:
To exercise any of these, email info@cyclingcommons.org (or use the Contact). We answer within one month at the latest, and usually much sooner. The law allows up to three months for a request that is genuinely complicated, but only if we tell you inside the first month that we are taking longer, and why. If you are unhappy with our answer, you can complain to the Autoriteit Persoonsgegevens.
The Commons isn't intended for children under 16. We don't knowingly collect personal data from anyone under that age; if you believe a child has given us data, contact us and we'll delete it.
We don't make decisions about you by solely automated means, and we don't profile you for advertising.
If we change how we handle data, we'll update this page and its date, and — for material changes — let signed-in contributors know.
You can also check that for yourself instead of taking our word for it. The platform is open source, so this page and its wording live in a public repository, and every change to it is recorded with a date and a reason in the page history.
So we can tell you what happened. It is not shown to anybody, not even to curators.
Paste a screenshot with Ctrl+V (Cmd+V). Up to 3.
We will tell you what happened to it.