← Back to Grid90

Privacy Policy

Grid90 · Effective date: 29 July 2026

Grid90 is an offline-first mapping and navigation app for walkers and hillwalkers. This policy explains what personal data we collect, why, who else receives it, and the rights you have over it.

The short version. Grid90 contains no advertising SDKs, no analytics or tracking SDKs, and no advertising identifiers. We do not sell or share your personal data for advertising, and we do not build profiles about you. Most of what the app does — including your maps, tracks and routes — works entirely on your device, offline. Cloud features are optional and only apply if you choose to sign in.

1. Who we are

Grid90 is operated by GRID90 Ltd, which is the data controller for the personal data described in this policy.

We are subject to the UK GDPR and the Data Protection Act 2018.

2. Data we collect

2.1 Location data

With your permission, Grid90 uses your device's location to show your position on the map, record tracks, provide navigation and live statistics, and calculate route information. Location is used while the app is in use and, if you enable track recording, in the background so that a walk continues to be recorded with the screen off.

Recorded tracks are stored on your device. They are only uploaded to our cloud storage if you are signed in and use sync features. We do not use your location for advertising or profiling.

2.2 Account data

If you choose to create an account or sign in with Google, we process your email address, a unique account identifier, and basic profile information supplied by the sign-in provider. Signing in is optional — the core mapping and navigation features work without an account.

2.3 Content you create

Tracks, routes, waypoints, notes, timestamps, elevation and distance data, and any photos you capture or attach. This content is stored on your device. If you are signed in, it may also be stored in our cloud services so it can sync across your devices.

2.4 Photos and camera

With your permission, Grid90 can access your camera and photo library so you can capture and attach images to tracks and routes. Photos you attach may include location metadata. Photos are only uploaded to our cloud storage if you are signed in and use sync features.

2.5 Diagnostic data

We collect crash reports and stability diagnostics through Firebase Crashlytics. These include device model, operating system version, app version, and technical details of the crash. This is used solely to fix bugs — particularly important for an app people rely on in the outdoors.

2.6 Support requests

If you contact support from inside the app, we receive the message you write, your reply address, and — so we can reproduce the problem — your account identifier, platform, OS version, app version and build number, device model, and a recent excerpt of the app's diagnostic logs. You can see what is being sent before you send it.

2.7 Purchases

Where paid features are offered, purchases are processed by the Apple App Store or Google Play. We receive confirmation of entitlement status. We never receive or store your payment card details.

3. Why we process it, and our legal basis

PurposeDataLegal basis (UK GDPR)
Showing your position, recording tracks, navigationLocation, activity dataConsent (Art. 6(1)(a)) — given via the device permission prompt, withdrawable at any time
Capturing and attaching photosPhotos, cameraConsent (Art. 6(1)(a))
Providing accounts and syncing your dataAccount data, contentPerformance of a contract (Art. 6(1)(b))
Serving map tiles, offline packs, weather and terrain dataIP address, approximate or precise coordinatesPerformance of a contract (Art. 6(1)(b))
Fixing crashes and improving stabilityDiagnostic dataLegitimate interests (Art. 6(1)(f)) — keeping a safety-relevant app reliable
Responding to support requestsSupport request dataLegitimate interests (Art. 6(1)(f))
Processing purchasesEntitlement statusPerformance of a contract (Art. 6(1)(b))

4. Who else receives your data

We do not sell your personal data. We share data only with the service providers below, each acting under their own privacy terms.

4.1 Our own infrastructure

Map tiles, offline map packs and support messages are served from infrastructure operated by GRID90 Ltd (tiles.grid90.com, offline.grid90.com). These receive your IP address and the map areas you request.

4.2 Google Firebase

We use Firebase Authentication (sign-in), Cloud Firestore and Cloud Storage (syncing your routes, tracks and photos when signed in), and Crashlytics (crash reporting). Provided by Google Ireland Limited / Google LLC.

4.3 Map, weather and terrain providers

Depending on which map layer or feature you use, the app requests data directly from third-party services. These providers receive your device's IP address, and in some cases location-derived information:

ProviderUsed forWhat they receive
Open-MeteoWeather forecasts and place searchIP address and the coordinates you request a forecast for, which is typically your position
Overpass API (overpass-api.de, overpass.kumi.systems)Nearby peak identification (Sky View)IP address and a bounding box around your location
MapTilerOptional online vector map layersIP address and the map tiles you view
ThunderforestOptional Landscape / Outdoors map layersIP address and the map tiles you view
OpenTopoMap, CyclOSM / OpenStreetMap FranceOptional community map layersIP address and the map tiles you view
Esri ArcGIS OnlineOptional satellite imagery layerIP address and the map tiles you view

The map tiles you request reveal which part of the world you are looking at. If you prefer to minimise this, use Grid90's downloaded offline maps, which are served from your device and require no network requests while you walk.

4.4 App stores

Apple and Google process purchases and subscription entitlements where paid features are offered.

5. International transfers

Some providers above, including Google Firebase, process data outside the UK, including in the United States. Where that happens, transfers are covered by the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or an applicable adequacy decision.

6. How long we keep it

DataRetention
Tracks, routes and photos stored on your deviceUntil you delete them or uninstall the app — under your control
Cloud-synced content (signed-in users)Until you delete the item, or until 30 days after you delete your account
Account dataUntil you delete your account, then removed within 30 days
Crash reportsUp to 90 days
Support correspondenceUp to 24 months
Server logsUp to 30 days

7. Deleting your account and data

You can permanently delete your Grid90 account and its associated cloud data at any time. Write to support@grid90.com from the address associated with your account, and we will delete your sign-in record and the routes, tracks and photos held in our cloud services within 30 days.

Deleting your account does not remove data held only on your device; uninstalling the app removes that.

8. Your rights

Under the UK GDPR you have the right to:

To exercise any of these, contact support@grid90.com. We will respond within one month.

If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or on 0303 123 1113. We would appreciate the chance to address your concern first.

9. Children

Grid90 is not directed at children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Security

Data in transit is encrypted using industry-standard TLS. Cloud data is held in access-controlled Firebase services with rules restricting each user's data to their own account. No system is completely secure, but we take reasonable and proportionate steps to protect your information.

11. Changes to this policy

We may update this policy from time to time. The effective date at the top will change, and significant changes will be communicated in the app.

12. Contact

GRID90 Ltd · support@grid90.com