Privacy Policy
Last updated 30 July 2026
Controller
Lev Kats, Vienna, Austria
Email: [email protected]
Processing location: the Winter Map application servers operated for this project (currently in the European Economic Area / EU-adjacent hosting used by the service).
Data processed when you use the map
- IP address, request time, requested path, response status and standard technical request metadata (including reverse-proxy logs).
- A random browser session identifier (
X-User-UUID) and a lightweight technical client fingerprint derived from non-unique device properties such as screen size, timezone, language and platform (X-Client-FP), used for rate limiting and approximate usage statistics under CGNAT. - Map-related location context needed to answer a request (for example coordinates for snow-state queries, viewport interest for archive basemap selection, or a requested winter-tile bounding box).
- Browser-local preferences, recent searches (up to five places), disclaimer acknowledgements, archive-layer choices and map settings stored in localStorage.
- Map camera position may appear in the URL hash when you share or bookmark a view.
Purposes: delivering the service, security, abuse prevention, rate limiting, fault diagnosis and aggregate capacity planning. Legal basis: legitimate interest under Article 6(1)(f) GDPR in operating a secure non-commercial service.
Drawn routes and GPX import/export remain in your browser or local files and are not uploaded to Winter Map servers.
Photos, videos and voluntary submissions
If you submit a photo or video, Winter Map stores the media file, selected map coordinates, season, optional caption (up to 1,000 characters) and submission time for moderation and possible publication. Videos are limited to 100 MB and Full HD after browser-side compression; video archives are primarily kept on the operator’s home server disk (with short-term staging on the public host when needed). No account, email or name is required for upload. Legal basis: your consent under Article 6(1)(a) GDPR.
Winter Map may also store voluntary geographic winter-coverage requests (bounding box, technical tile parameters, and an optional free-text note of up to 400 characters about urgency or context — without requiring contact details) and optional archive-training labels (folder class, coordinates, tile metrics) used to improve imagery selection.
To withdraw consent or request removal, email [email protected] with enough information to identify the content (map location, photo ID shown in the viewer, or approximate time). There is currently no self-service delete button; removals are handled by the operator.
Cookies and local storage
Winter Map does not set advertising cookies and does not use a first-party cookie jar for the public map. Technical identifiers and preferences are stored in browser localStorage. Clearing site data resets preferences and creates a new anonymous identifier; it does not by itself erase server-side rate-limit or photo records.
Retention
- Anonymous usage sessions are pruned after about seven days of inactivity (capped inventory of session/IP keys).
- Short rate-limit windows expire within about one minute; automatic security blocks normally expire after 24 hours.
- Aggregate usage counters and some security event logs may remain until manually reset.
- Approved photos remain until removed; rejected photos are deleted during moderation.
- Winter-generation request records and archive labels are retained until deleted by the operator (no automatic TTL).
- Nginx and operational logs are kept only as reasonably required for security and troubleshooting.
- Cached map tiles are technical caches and are purged by size/age rules, not as user profiles.
External services contacted by your browser
Depending on enabled layers, your browser may contact third parties and disclose your IP address plus ordinary request metadata (and, for search, the typed query):
- Esri World Imagery / Esri Wayback for satellite and archive imagery.
- Amazon Web Services public terrain tiles (Terrarium) as a DEM fallback.
- OpenFreeMap, OpenStreetMap and OpenSkiMap-related map data services.
- Komoot Photon for place autocomplete when you type a search.
- External webcam or resort websites only when you open their outbound links.
Core Winter Map assets, the snow model API and most overlays are served from Winter Map's own servers. No advertising network or analytics SDK is integrated.
Hosting and recipients
Processing occurs on infrastructure operated for Winter Map. Cloudflare may provide DNS, security and tunnel connectivity. Data is disclosed only where necessary to operate the service, prevent abuse, comply with law or fulfil a feature you explicitly request. Weather-model and lift-status jobs may contact external meteorological or resort sources from the server without transmitting your personal profile.
Your rights
Subject to applicable conditions, you have rights of access, rectification, erasure, restriction, objection, data portability and withdrawal of consent. Contact [email protected]. You may also complain to the Austrian Data Protection Authority (Datenschutzbehörde).