Rumo

Legal

Privacy & Cookies Policy

How Rumo collects, uses, stores and protects your information — and the two cookies it sets.

Last updated: September 13, 2026

Rumo Adventures LLC (“Rumo”, “we”, “our”, or “us”) is committed to protecting and respecting your privacy. This Privacy and Cookies Policy explains how we collect, use, store, and protect personal information when you use the Rumo application and related services.

1. Who We Are

Rumo Adventures LLC operates the Rumo application and related services.

If you have questions about this policy or how your data is handled, you may contact us at: support@rumoadventures.com

2. Information We Collect

We collect only the information necessary to provide and operate the service.

Personal Information
We collect limited personal information, including:
  • Email address
  • Username
This information is used to:
  • Create and manage your account
  • Authenticate access to the service
  • Communicate with you about your account or the service

Usage and Activity Information
To keep your account secure and to understand how the service is used, we record limited activity information, including:
  • The date and time you last signed in to your account
  • The approximate time you were last active in the application
This information is used to:
  • Show you when your account was last accessed and help detect unusual or unauthorized sign-in activity
  • Understand overall, aggregate usage and retention so we can improve the service
This activity information is not sold, is not shared with third parties for advertising, and is not used to track you across other websites.

We do not sell your personal information and do not share it with third parties for advertising or marketing purposes.

Legal basis:
Article 6(1)(b) GDPR - performance of a contract
Article 6(1)(f) GDPR - legitimate interest (service security and operation)

3. User-Generated Content

Users may create or upload content such as:
  • GPX tracks
  • Photos
  • Comments or other shared materials

This content is stored to provide the service and may be visible to other users or visitors depending on how it is shared within the application.

You are responsible for ensuring that you have the right to upload and share any content you provide.

The community board
Ideas, comments and votes posted on the community board are public. Anyone can read them without an account, and search engines can index them. Your username and profile picture appear beside what you post. Please treat it as writing in public, because it is.

What happens to it if you delete your account
This is the one place where deleting your account does not remove what you wrote, and we want to be plain about it rather than have you discover it.

Ideas and comments you posted on the board stay where they are, anonymized. Your name is removed and replaced with “a former member”, and the post can no longer be traced back to you through Rumo. Votes you cast stay counted, detached from your account.

We do this because the board is a conversation. Other people replied to your idea, argued with it, and voted on it, and removing your half would leave their words answering nothing. Everywhere else on Rumo, deleting your account deletes your content; here it is anonymized instead.

Anything you were following is deleted with your account, so the emails stop.

Taking a post down
You can withdraw an idea yourself while nobody else has commented or voted on it. After that it belongs to a conversation other people have joined, so ask us through support and a person will look at it.

We may also remove a post ourselves if it breaks the Terms. A removed post stops being publicly visible; in rare cases its text is erased permanently.

Email about the board
Following an idea means we email you when it is decided on or when there is an update. Comments never trigger an email. You can turn these off at any time in your notification settings, and every one of those emails carries the same link.

4. Support Requests and Diagnostic Data

When you send a support request, we store what you wrote, our replies, and the status of the request, so that you and we can both see the history of the conversation.

The diagnostic snapshot
To reproduce a problem rather than guess at it, a support request also carries a technical snapshot of your session at the moment you sent it:
  • The Rumo version you were running
  • Your plan tier
  • The map style, the layers you had switched on, and where the map was centred
  • Your browser, operating system, screen size, language and time zone
  • Graphics card and available device memory, where your browser chooses to report them
  • Any errors the application recorded in your browser just beforehand

What it never includes
The snapshot does not include the contents of the page, anything you have typed elsewhere, your location beyond where you had placed the map, or any of your trip data. A trip is attached only if you explicitly tick the box to include it. Screenshots are separate and are covered below — nothing is captured from your screen unless you choose and attach the file yourself.

You are shown the snapshot in full, field by field with the actual values, before you press send. Nothing is collected from you in the background for this purpose.

Screenshots you choose to attach
You may attach up to three images to a support request and to each reply. Unlike the snapshot above, these are supplied entirely by you: nothing is captured from your screen automatically, and a request without attachments carries none.

A screenshot can show far more than the problem — account details, other people’s information, whatever else is on screen. Please look before you attach, and remember you are choosing to share it.

They are stored privately, never publicly. There is no public address for them and no shareable link. They can be viewed only by you and by Rumo support, through a short-lived link issued after we check it is your request. Location and camera information carried inside an image file is stripped when it is stored.

You can remove one at any time — before you send, or afterwards from the request page. Removing it deletes the image. They are also erased automatically on the same two-year schedule as the diagnostic snapshot; the conversation keeps a note that an image was there, without the image.

Why we hold it
We process this data on the basis of our legitimate interest in diagnosing and fixing faults in the service, in response to a request you chose to send us. It is never used for advertising, profiling, or tracking you across other sites, and it is never sold or shared for those purposes.

How long we keep it
The diagnostic snapshot is retained for two years and is then permanently erased, automatically. We keep it that long because many of the problems Rumo deals with are seasonal, and comparing this winter's report against last winter's is often what identifies the cause.

The request itself - what you wrote, our replies, and the outcome - is kept for as long as your account exists, so you can look back at what was decided. Deleting your account deletes it.

Known Issues
A problem reported by one person often affects others. We may describe a confirmed problem in our public Known Issues list. Those entries are written by us and are never attributed to you; your name, your words and your request are not published.

5. Data Storage and Processing

Personal data and user-generated content are stored and processed using secure cloud infrastructure. This includes storage in Amazon Web Services (AWS), such as Amazon S3, for the purpose of hosting, backing up, and delivering application content.

AWS acts as a data processor on our behalf and processes data only in accordance with our instructions. We rely on AWS's GDPR-compliant data processing agreements and appropriate technical and organizational safeguards to protect personal data.

AWS does not use your personal data for its own purposes.

6. Cookies and Similar Technologies

Rumo uses strictly necessary cookies to enable core functionality and secure authentication.

These cookies:
  • Are required for the service to function
  • Are not used for advertising
  • Are not used to track users across websites
  • Are not shared with third parties

__Host-next-auth.csrf-token
Purpose
Protects against cross-site request forgery attacks
Type
Essential
Duration
Session
__Secure-next-auth.callback-url
Purpose
Enables secure authentication redirection
Type
Essential
Duration
Session

Legal basis:
Article 6(1)(b) GDPR – performance of a contract (account creation and waitlist enrollment)
Article 6(1)(f) GDPR – legitimate interest (user-requested functionality and service operation)

These cookies do not require user consent under EU cookie regulations.

Certain temporary values used to support user flows (such as trip editing or personalized sign-up experiences) are stored using browser storage mechanisms and are removed once their purpose has been fulfilled.

7. Data Retention

We retain personal data only for as long as necessary to:
  • Provide and maintain the service
  • Meet legal or accounting obligations
  • Resolve disputes
  • Enforce agreements

Where a specific retention period applies, it is stated in the section covering that data. In particular, the diagnostic snapshot attached to a support request is erased automatically after two years - see Section 4, Support Requests and Diagnostic Data.

You may request deletion of your account and associated personal data at any time. When you delete your account it is closed straight away, and its data is permanently erased 30 days later. Until then, support can restore it if you change your mind. The exception is what you posted on the community board, which stays there anonymized, as described above.

8. International Users

Rumo is used internationally. If you are located in the European Union or European Economic Area, your personal data is processed in accordance with the General Data Protection Regulation (GDPR).

9. Your Rights Under GDPR

If you are located in the EU or EEA, you have the right to:
  • Access your personal data
  • Request correction of inaccurate data
  • Request deletion of your data
  • Restrict or object to processing
  • Request data portability
  • Lodge a complaint with a supervisory authority

To exercise these rights, contact us at: support@rumoadventures.com

10. Changes to This Policy

We may update this Privacy and Cookies Policy from time to time. Material changes will be communicated through the service or by email where appropriate.

Questions about this?

If anything here is unclear, or you would like to exercise a right described above, contact us directly.