Privacy Policy

Last Updated: January 2026

1. Introduction

Welcome to gsyrocks. We are a bouldering logbook web application that helps climbers in Guernsey track their ascents, discover new climbs, and compete on leaderboards.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.

2. Information We Collect

2.1 Information You Provide Directly

Account Information: Email address, username, profile picture, first/last name (optional), gender (optional)

Climbing Data: Climbs you log (grade, status, date, location), photos you upload, crag information you add

2.2 Information Collected Automatically

Usage data, IP address, browser type, operating system, cookies, and similar tracking technologies. We use PostHog, a privacy-first analytics service, to help us understand how users interact with our app.

2.3 Location Data

We collect location information for climbing routes and crags:

  • GPS coordinates from uploaded photos (extracted from EXIF metadata)
  • Crag locations you add or verify
  • Your default location preference (stored in account settings)
  • Map interaction data for route discovery

Location data is displayed publicly on our interactive map and is essential to the core functionality of gsyrocks.

3. How We Use Your Information

  • Create and manage your account
  • Record and display your climbing logbook
  • Show your climbing statistics and progress
  • Display your profile on leaderboards
  • Allow you to search and discover climbs on the map
  • Enable you to contribute new climbs and crag information
  • Improve our services and analyze usage patterns
  • Comply with legal obligations

4. Information Sharing

4.1 Public Information

Your username, profile picture (if uploaded), and climbing statistics are displayed publicly on leaderboards.

4.2 Service Providers

We use Supabase for authentication/database, Vercel for hosting, and PostHog for analytics. These services have access to information necessary to perform their functions.

4.3 Legal Requirements

We may disclose information if required by law or to protect our rights and safety.

5. Data Security

We implement appropriate technical and organizational measures to protect your information. However, no method of transmission over the Internet is 100% secure.

6. Data Retention

We retain your information for as long as your account is active. You may delete your logged climbs at any time. After account deletion, your data is removed within 30 days.

7. Your Rights

  • Access and correct your personal information
  • Request deletion of your account and data
  • Download a copy of your data at any time through your account settings
  • Opt out of leaderboard display (leave username blank)

Your data will be permanently removed within 30 days of account deletion.

7.1 Additional Rights (GDPR - EU/EEA Users)

If you are located in the European Union or European Economic Area, you have additional rights under the General Data Protection Regulation (GDPR):

  • Right of Access: You can request a copy of all personal data we hold about you
  • Right to Rectification: You can request correction of inaccurate or incomplete personal data
  • Right to Erasure: You can request deletion of your account and all associated data
  • Right to Restriction of Processing: You can request that we limit how we use your data
  • Right to Data Portability: You can request a copy of your data in a machine-readable format
  • Right to Object: You can object to processing based on legitimate interests or direct marketing

To exercise any of these rights, join our Discord server. We will respond within 30 days.

8. Cookies

We use cookies for authentication, preferences, and analytics through third-party services including PostHog. You can control cookies through your browser settings.

9. Analytics

We use PostHog, a privacy-respecting analytics tool, to understand how users interact with our application. PostHog helps us improve our services by showing us aggregate usage patterns. PostHog does not sell your data and is configured to minimize personal information collection.

You can opt out of analytics tracking by joining our Discord server.

10. Children's Privacy

gsyrocks is not intended for children under 13. We do not knowingly collect information from children under 13.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes by posting the new policy on this page.

12. Contact Us

gsyrocks is operated by:

GSYROCKS LTD
Guernsey, Channel Islands

If you have questions about this Privacy Policy or your data, please contact us at hello@gsyrocks.com

13. International Data Transfers

13.1 Data Storage Location

Your personal data is primarily stored and processed in the European Union through Supabase's EU-based infrastructure.

13.2 Analytics Transfers

PostHog processes analytics data in the United States under Standard Contractual Clauses (SCCs) approved by the European Commission.

13.3 UK Adequacy

For users in the United Kingdom, data transfers comply with UK data protection laws and UK adequacy decisions for EU/US data transfers.

13.4 Data Protection

We ensure adequate protections are in place when transferring data outside the EU/UK, including SCCs and other appropriate safeguards as required by applicable data protection laws.

14. California Privacy Rights

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):

14.1 Information We Collect

We collect the following categories of personal information:

  • Identifiers (username, email, IP address)
  • Geolocation data (GPS coordinates from uploads)
  • Activity data (climbs logged, routes submitted)
  • Profile information

14.2 Your Rights

  • Right to know what personal information we collect
  • Right to request deletion of your personal information
  • Right to opt-out of sale of personal information (we do not sell data)
  • Right to non-discrimination for exercising your rights

14.3 Do Not Sell

gsyrocks does not sell your personal information to third parties.

14.4 Exercise Your Rights

To submit a request, email hello@gsyrocks.com with "CCPA Request" in the subject line. We will verify your identity before processing.

15. Image Retention After Deletion

15.1 Deletion Options

When you delete your account, you may choose:

  • Delete my account and all my image uploads
  • Delete my account but keep my image uploads (attributed to "[anonymous]")

15.2 Third-Party Content

If you have shared images from gsyrocks to social media or other platforms:

  • We cannot remove images from those platforms
  • We cannot delete cached copies or reposts
  • You are responsible for contacting those platforms directly

15.3 Retention Period

Images retained on gsyrocks after account deletion remain visible until:

  • You subsequently request their removal
  • Content is removed for policy violations
  • gsyrocks ceases operations