Overview
IsleHop ("we", "our", "us") is a mobile application for discovering and planning travel across the Greek islands. This Privacy Policy explains how we collect, use, store, and protect personal information when you use the IsleHop app on iOS or Android.
By creating an account or using the app, you agree to the practices described in this policy. If you do not agree, please do not use the app.
We are committed to compliance with the General Data Protection Regulation (GDPR) and applicable Greek data protection law.
Data We Collect
Account Information
When you create an account you provide:
- Email address and password (or sign in via Google / Apple)
- Display name (optional)
- Profile photo (optional)
Content You Create
- Trip itineraries and saved places
- Island ratings and reviews
- Community-submitted spots and comments
- Favourite islands and preferences
Usage & Technical Data
| Type | What we collect | Purpose |
|---|---|---|
| App events | Screens visited, features used, search terms | Improve the app experience |
| Device info | OS version, device model, app version | Debug and compatibility |
| Crash reports | Stack traces, device state at crash time | Fix bugs (Crashlytics) |
| Push tokens | Anonymous FCM token | Send notifications (if enabled) |
| Location | Approximate or precise (see §4) | Nearest island, map features |
How We Use Your Data
We use personal data for the following purposes, each grounded in a legal basis under GDPR:
- Providing the service — account management, saving trips, syncing content across devices (Contract)
- Personalisation — showing island recommendations based on your preferences and saved places (Legitimate Interest)
- App improvement — analysing usage patterns to prioritise new features (Legitimate Interest)
- Safety & integrity — detecting abuse, enforcing our community rules (Legitimate Interest)
- Notifications — sending travel tips or alerts you explicitly enable (Consent)
- Legal obligations — complying with applicable law (Legal Obligation)
Location Data
Location access is entirely optional. The app requests location permission only for features that clearly benefit from it:
- Finding which Greek island you are closest to
- Displaying your position on the interactive island map
- Sorting nearby businesses or points of interest
You can deny or revoke location permission at any time in your device settings. The app continues to work without location access, though map centering and proximity features will be unavailable.
Third-Party Services
IsleHop is built on Firebase (Google LLC), which processes data on our behalf under a Data Processing Agreement. The following Firebase services are in use:
| Service | Purpose | Data processed |
|---|---|---|
| Firebase Authentication | Account sign-in & management | Email, UID, provider token |
| Cloud Firestore | Database: trips, ratings, businesses | All user-created content |
| Firebase Storage | Profile photos, uploaded images | Image files |
| Firebase Analytics | App usage analytics | Pseudonymous events |
| Firebase Crashlytics | Crash reporting | Stack traces, device info |
| Firebase Cloud Messaging | Push notifications | FCM device token |
Google's privacy policy governs Firebase's own data handling: policies.google.com/privacy
If you sign in with Google or Apple, their respective authentication services handle credential verification. We receive only a user identifier and email address from them.
Data Retention
We keep your data for as long as your account is active or as needed to provide the service:
- Account data — retained until you delete your account
- Trip and preference data — retained until you delete it or your account
- Analytics events — aggregated, retained up to 14 months (Firebase Analytics default)
- Crash reports — retained for 90 days (Crashlytics default)
When you delete your account, we delete or anonymise your personal data within 30 days, except where we are legally required to retain it longer.
Security
We take reasonable technical and organisational measures to protect your data:
- All data in transit is encrypted via TLS/HTTPS
- Firestore data is encrypted at rest by Google
- Access to the Firebase project is restricted to authorised developers only
- Firestore Security Rules enforce that users can only access their own data
No system is perfectly secure. If you discover a security vulnerability, please contact us at the address below rather than disclosing it publicly.
Children's Privacy
IsleHop is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
Your Rights (GDPR)
If you are located in the European Economic Area, you have the following rights regarding your personal data:
To exercise any of these rights, contact us using the details in §12. We will respond within 30 days. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA).
Policy Changes
We may update this policy from time to time. When we make material changes, we will notify you via an in-app notification or email at least 14 days before the changes take effect. Continued use of the app after that date constitutes acceptance of the updated policy.
The date at the top of this page always reflects when the policy was last revised.
Contact Us
For privacy questions, data requests, or to exercise your rights, please reach out:
We aim to respond to all privacy-related requests within 5 business days, and in any case within the 30-day period required by GDPR.