IsleHop · Greek Islands Guide

Privacy Policy
& Data Protection

Last updated: 26 August 2026  ·  Effective: 26 August 2026  ·  Applies to: iOS & Android app

Summary: IsleHop collects only what is necessary to help you explore the Greek islands — account details, optional location, and app usage. We do not sell your personal data to anyone. We use Firebase (Google) to run the service. You have full rights over your data under GDPR.
01

Overview

IsleHop ("we", "our", "us") is a mobile application for discovering and planning travel across the Greek islands. This Privacy Policy explains how we collect, use, store, and protect personal information when you use the IsleHop app on iOS or Android.

By creating an account or using the app, you agree to the practices described in this policy. If you do not agree, please do not use the app.

We are committed to compliance with the General Data Protection Regulation (GDPR) and applicable Greek data protection law.


02

Data We Collect

Account Information

When you create an account you provide:

  • Email address and password (or sign in via Google / Apple)
  • Display name (optional)
  • Profile photo (optional)

Content You Create

  • Trip itineraries and saved places
  • Island ratings and reviews
  • Community-submitted spots and comments
  • Favourite islands and preferences

Usage & Technical Data

Type What we collect Purpose
App events Screens visited, features used, search terms Improve the app experience
Device info OS version, device model, app version Debug and compatibility
Crash reports Stack traces, device state at crash time Fix bugs (Crashlytics)
Push tokens Anonymous FCM token Send notifications (if enabled)
Location Approximate or precise (see §4) Nearest island, map features

03

How We Use Your Data

We use personal data for the following purposes, each grounded in a legal basis under GDPR:

  • Providing the service — account management, saving trips, syncing content across devices (Contract)
  • Personalisation — showing island recommendations based on your preferences and saved places (Legitimate Interest)
  • App improvement — analysing usage patterns to prioritise new features (Legitimate Interest)
  • Safety & integrity — detecting abuse, enforcing our community rules (Legitimate Interest)
  • Notifications — sending travel tips or alerts you explicitly enable (Consent)
  • Legal obligations — complying with applicable law (Legal Obligation)
We do not
Sell, rent, or trade your personal data to third parties for marketing. We do not use your data to build advertising profiles.

04

Location Data

Location access is entirely optional. The app requests location permission only for features that clearly benefit from it:

  • Finding which Greek island you are closest to
  • Displaying your position on the interactive island map
  • Sorting nearby businesses or points of interest

You can deny or revoke location permission at any time in your device settings. The app continues to work without location access, though map centering and proximity features will be unavailable.

Location data is processed on-device for proximity calculations. We do not continuously track your movement or store a history of your location on our servers.

05

Third-Party Services

IsleHop is built on Firebase (Google LLC), which processes data on our behalf under a Data Processing Agreement. The following Firebase services are in use:

Service Purpose Data processed
Firebase Authentication Account sign-in & management Email, UID, provider token
Cloud Firestore Database: trips, ratings, businesses All user-created content
Firebase Storage Profile photos, uploaded images Image files
Firebase Analytics App usage analytics Pseudonymous events
Firebase Crashlytics Crash reporting Stack traces, device info
Firebase Cloud Messaging Push notifications FCM device token

Google's privacy policy governs Firebase's own data handling: policies.google.com/privacy

If you sign in with Google or Apple, their respective authentication services handle credential verification. We receive only a user identifier and email address from them.


06

Data Sharing

We share personal data only in these limited circumstances:

  • Service providers — Firebase/Google, acting as data processors under contract, as described above
  • Other users — content you post publicly (community spots, comments) is visible to other logged-in users. Ratings are aggregated and displayed without identifying the author.
  • Legal requirements — if required by law, court order, or to protect the safety of users
  • Business transfer — in the event of a merger or acquisition, your data may transfer to the new owner; you will be notified

07

Data Retention

We keep your data for as long as your account is active or as needed to provide the service:

  • Account data — retained until you delete your account
  • Trip and preference data — retained until you delete it or your account
  • Analytics events — aggregated, retained up to 14 months (Firebase Analytics default)
  • Crash reports — retained for 90 days (Crashlytics default)

When you delete your account, we delete or anonymise your personal data within 30 days, except where we are legally required to retain it longer.


08

Security

We take reasonable technical and organisational measures to protect your data:

  • All data in transit is encrypted via TLS/HTTPS
  • Firestore data is encrypted at rest by Google
  • Access to the Firebase project is restricted to authorised developers only
  • Firestore Security Rules enforce that users can only access their own data

No system is perfectly secure. If you discover a security vulnerability, please contact us at the address below rather than disclosing it publicly.


09

Children's Privacy

IsleHop is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.


10

Your Rights (GDPR)

If you are located in the European Economic Area, you have the following rights regarding your personal data:

👁
Right of Access
Request a copy of the personal data we hold about you.
✏️
Right to Rectification
Correct inaccurate or incomplete data.
🗑
Right to Erasure
Request deletion of your personal data ("right to be forgotten").
🔒
Right to Restriction
Ask us to limit how we process your data in certain circumstances.
📦
Data Portability
Receive your data in a structured, machine-readable format.
🚫
Right to Object
Object to processing based on legitimate interest.

To exercise any of these rights, contact us using the details in §12. We will respond within 30 days. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA).


11

Policy Changes

We may update this policy from time to time. When we make material changes, we will notify you via an in-app notification or email at least 14 days before the changes take effect. Continued use of the app after that date constitutes acceptance of the updated policy.

The date at the top of this page always reflects when the policy was last revised.


12

Contact Us

For privacy questions, data requests, or to exercise your rights, please reach out:

✉️
Data Controller
IsleHop isle.hop.2026@gmail.com

We aim to respond to all privacy-related requests within 5 business days, and in any case within the 30-day period required by GDPR.