Privacy Policy
Last updated: 25 September 2026
1. Who We Are
South West Coast Walk ("we", "us", "our") is operated by Pixelo Mobile Ltd, which runs the website walksouthwestcoast.co.uk and the South West Coast Walk mobile app: a trail guide, and a marketplace that puts walkers in touch with independent local businesses. Pixelo Mobile Ltd is the data controller for the personal data described here. We are committed to protecting your personal data and respecting your privacy.
2. What Data We Collect
We collect the following personal data when you use the website or the app. We do not ask for, or keep, walkers' phone numbers.
- Account data: your name, email address and password (stored only as a one-way hash). If you add them, your profile photo, bio, nationality, social-media links and language preference. If you sign in with Google or Apple, we receive your name and email address from them (or Apple's private relay address, if you choose it), never your password.
- Enquiries, booking requests and trip requests: your name, email address, number of people, dates, route and the message you write.
- Location data (mobile app): If you use the South West Coast Walk mobile app and grant permission, we collect your device's precise location, including in the background while the app is closed or not in use. This is used to record your route while you hike and to show your position on the trail map. Background location is collected only while you have an active hike in progress, after you accept an in-app disclosure, and you can disable location access at any time in your device settings or stop the hike. Location data is never sold and is not shared with third parties for advertising.
- Your walks: when you are signed in, the hikes you record (the route as GPS points, times and distances), the stages you complete and your walking statistics are stored on our servers so they are kept across your devices.
- Digital Passport and certificates: your stamps, badges and completion records, and the name shown on your certificates. For a premium certificate, the photo you upload, which a member of our team reviews before the certificate is issued.
- Community: the reviews, stories, posts, replies and photos you share, messages you send to other walkers, walking-buddy requests, the people you follow or block, and reports you make about content.
- Trip planning: the answers you give the trip planner, such as dates, pace and preferences.
- Purchases: in-app purchases are handled by Apple or Google, and web payments by Stripe. We receive a receipt or transaction reference, never your card details.
- Communication data: emails you send us, your newsletter subscription and your marketing consent choices.
- Device and technical data: a push-notification token if you allow notifications, your app version and device type, crash and error reports, your IP address in our server logs, and the analytics described in section 6a.
- Approximate country (from your IP): We check your IP address against an offline country database held on our own server, so we can show travel offers that are actually available where you are. Your IP address is not sent to any third party for this, is not stored, and we only ever derive your country — never a precise location. IP geolocation data by DB-IP (CC BY 4.0).
3. How We Use Your Data
- To run your account and the app's features: maps, recorded walks, statistics, the Digital Passport and certificates
- To pass your enquiry, booking request or trip request to the business you choose, and to send you their replies
- To run the community features, including automated and human checks for spam and abuse
- To plan trips and translate content when you use those features
- To send account, enquiry and service-related emails and push notifications
- To respond to enquiries and support requests
- To keep the service secure and prevent abuse
- To improve our website and app (with consent where required)
- To tell you about our other walking trails in the Trailivo network (with your consent) — you can opt out at any time.
- To comply with legal obligations
4. Legal Basis for Processing (GDPR)
We process your data under the following legal bases:
- Contract: running your account and the features you use, and passing your requests to the businesses you choose
- Consent: location permission, analytics cookies and in-app analytics, push notifications and marketing emails. You can withdraw consent at any time.
- Legitimate interest: security and abuse prevention, moderating community content, responding to enquiries and improving our services from anonymous signals
- Legal obligation: tax and accounting requirements
5. Data Sharing
- Businesses you contact. When you send an enquiry or a booking request to a business listed with us, or claim one of its offers, we pass your name, email address and trip details to that business (a guesthouse, guide, tour or transfer operator). For a trip request sent to several operators, they see your trip details but not your name or email address until you choose one of them. General enquiries to us are not passed on. Each business is responsible for the data it receives. The businesses listed on walksouthwestcoast.co.uk are in the United Kingdom, so these details stay in the UK.
- Other walkers see what you share publicly: your display name and photo, reviews, stories, posts and photos.
- Service providers who process data on our behalf, listed in section 10.
- Authorities, only where the law requires it.
We do not sell your personal data, and we do not share it for advertising.
The Trailivo network brands operated by Pixelo Mobile Ltd are: Lycian Way, Coast to Coast, South West Coast Path, Cappadocia, Via Francigena and Göbekli Tepe. If you consent to cross-brand marketing, your contact details may be used to email you about these other trails; you can opt out at any time from your account settings or via the unsubscribe link in any marketing email.
5a. Daily check-ins in older versions of the app
Until 28 September 2026, older versions of the app still include daily check-ins, which automatically email your emergency contacts if you miss one. No person monitors them, and you must not rely on them for your safety.
If you use them, we hold the names and contact details of the emergency contacts you add and your check-ins (date, stage and any note you write), including the location recorded with a check-in, and we send these to your emergency contacts. If you joined a tour departure through the app, its operator may also be told about a missed check-in. After that date nothing more is sent, and stored emergency contacts, check-ins and tracking codes are deleted.
6. Cookies
We use the following types of cookies:
- Essential cookies: Required for the website to function (e.g., session tokens, cookie consent preference). These cannot be disabled.
- Analytics cookies: Help us understand how visitors use our site. Only loaded with your consent.
You can change your cookie preferences at any time by clearing your browser's local storage.
6a. Analytics & Measurement
We measure how the website, the mobile app and business listings are used, in three clearly separated ways:
- Anonymous product signals. The app and website send us anonymous counters — an app was opened, a screen was viewed, a listing was seen or tapped, a technical error occurred. These carry no account identifier and no precise location; for abuse prevention they include a truncated, daily-rotating hash of your network address, from which your IP cannot be recovered, plus your approximate country. Raw signals are deleted within 90 days; only aggregate counts are kept.
- Account activity. When you are signed in, we record which days you used the app or website for this brand, so we can understand engagement and improve the product (legitimate interest, Art. 6(1)(f) GDPR). These records are kept for at most 24 months, are included in your data export, and are deleted with your account.
- Optional analytics. Google Analytics runs only if you accept it in the cookie banner. In the mobile app, person-level product analytics run only if you switch on "Share anonymous usage data" in Settings (off by default).
Businesses listed on our platform see only aggregate statistics about their own listing — counts of views and taps, by month, source and approximate country. Small groups are suppressed so no individual visitor can ever be singled out, and no partner ever sees who you are.
7. Data Retention
- Account data, recorded walks and Digital Passport records: kept until you delete your account
- Community content: kept until you delete it or your account (see section 13)
- Booking data: retained for 6 years (UK tax requirements)
- Enquiry and trip-request data: retained for 2 years
- Analytics data: as described in section 6a
- Marketing consent records: kept while we rely on them, plus a suppression record after you opt out.
8. Your Rights
Under GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request erasure ("right to be forgotten")
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
To exercise these rights, email us at hello@walksouthwestcoast.co.uk.
9. Data Security
We protect your data using industry-standard measures, including HTTPS encryption and hashed passwords (PBKDF2-SHA256). Our servers and database are in London (UK), and uploaded photos are stored in Amsterdam (EU).
10. Who processes your data on our behalf (subprocessors)
We use the following third-party services to operate South West Coast Walk. Each has its own privacy practices — follow the links for detail. We have a UK-GDPR Article 28 data processing agreement in place (or equivalent standard terms) with each of them.
- DigitalOcean (LLC, USA) — server and database hosting in London (UK), and photo storage in Amsterdam (EU). Privacy
- Cloudflare (Inc., USA) — website hosting, CDN, DNS, security and bot protection, and email routing. Privacy
- Stripe (Payments Europe Ltd, Ireland / Inc., USA) — card payments on the website. We never see or store your full card number. Privacy
- Apple (Inc., USA) and Google (LLC, USA) — app stores and in-app purchases, Sign in with Apple and Google sign-in, and push notifications (Apple Push Notification service and Firebase Cloud Messaging). Apple privacy · Google privacy
- Google Analytics (Google LLC, USA) — website analytics, only if you accept analytics cookies. Privacy
- PostHog (Inc., EU cloud in Frankfurt) — in-app product analytics, only if you switch them on in Settings. Privacy
- Resend (Inc., USA) — transactional email (account, enquiry and notification emails). Privacy
- Mapbox (Inc., USA) — interactive trail maps and offline map packs. It receives map requests and anonymised usage and location telemetry from the map software in the app, never your account details. Privacy
- Sentry (Functional Software, Inc., USA) — crash and error reports from the app, used to fix bugs. Privacy
- Anthropic (PBC, USA) — the AI behind the trip planner, translations, and automated checks of community posts for spam and abuse. It processes the text involved only to provide these features, under terms that do not allow it to train its models on that text. Privacy
International transfers. Our own servers are in the UK. Where a provider above processes data in the USA, we rely on the UK Extension to the EU–US Data Privacy Framework (the "Data Bridge") or on the UK International Data Transfer Addendum to Standard Contractual Clauses; where it does so in the EU, on the UK's adequacy regulations for the EU. Transfers to the businesses you contact are described in section 5.
11. Children
South West Coast Walk is intended for adults aged 18 and over. Accounts are not offered to minors, and we do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has provided us with personal data, contact us and we will delete it.
12. Your consumer cancellation right (Consumer Contracts Regulations 2013)
Tours, stays and transfers are booked directly with the businesses that provide them, and their own cancellation and refund terms apply. For paid features we sell directly (for example, a provider marketplace subscription), you generally have a 14-day right to cancel under the UK Consumer Contracts (Information, Cancellation and Additional Charges) Regulations 2013 — email hello@walksouthwestcoast.co.uk within 14 days of purchase to exercise it. In-app purchases are refunded through Apple or Google under their own terms.
13. How to delete your account
You can de-identify your account and request erasure of your content at any time:
When you delete your account we immediately replace your name, email, bio, photos and social links with placeholder values and invalidate all your sessions. Content you posted in public spaces (reviews, trail feed, stories) is displayed under "Deleted User" — you can request full removal of that content under Article 17 of UK-GDPR by emailing us with the word "FULL ERASURE" in the subject. We retain booking invoices for 7 years to meet HMRC tax record-keeping obligations. Stripe retains payment records under its own policy. Full details: /delete-account.
14. Complaints
If you believe we have mishandled your personal data, you have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
15. Changes to This Policy
We may update this policy from time to time. The "last updated" date at the top will reflect the most recent revision.
16. Contact
Data controller: Pixelo Mobile Ltd (trading as South West Coast Walk), company number 10585806. Registered office: c/o Demsa Accounts, 565 Green Lanes, Haringey, London, England, N8 0RL.
For privacy-related queries: hello@walksouthwestcoast.co.uk