This Privacy Policy explains how Timkelo collects, uses, protects, and processes your personal data when you use the Timkelo mobile application and our website at https://timkelo.com.
1. Data Controller & Hosting
The data controller responsible for personal data processed through Timkelo is:
[À COMPLÉTER AVANT PUBLICATION : publisher legal entity or individual name]
[À COMPLÉTER AVANT PUBLICATION : legal status (e.g. individual, sole trader, or incorporated company)]
[À COMPLÉTER AVANT PUBLICATION : registered office or domicile address]
[À COMPLÉTER AVANT PUBLICATION : business registration / identification number (if applicable)]
General contact email: [À COMPLÉTER AVANT PUBLICATION : contact email address, e.g. contact@timkelo.com]
Privacy contact email: [À COMPLÉTER AVANT PUBLICATION : dedicated privacy email address, e.g. privacy@timkelo.com]
Technical infrastructure hosting providers:
- Database, authentication & storage: Supabase Inc. (secure cloud infrastructure).
- Public website & content delivery network (CDN): Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA).
2. Data Collected & Purposes
Timkelo is the social network for theme park enthusiasts. We only process data strictly necessary to deliver active features:
A. Account Creation & Profile
Data: email address, username, password secured via industry-standard cryptographic hashing, optional profile photo (avatar), and optional bio.
Purpose & legal basis: performance of Terms of Use (providing the Timkelo service) and securing your account.
B. Posts & Social Feed
Data: photos and text you explicitly choose to publish, tagged attractions or parks, likes, and comments.
Explicit action: no activity is ever published automatically. All sharing requires an intentional user action.
Purpose & legal basis: contract performance and voluntary sharing within the community.
C. “My Map” & Logged Attractions
Data: explored theme parks, attractions marked as completed, optional visit dates, personal ratings, and review notes.
Punctual location check: if you choose to verify an attraction check-in on-site, a punctual geographic proximity check can certify your presence inside the park boundary. This verification never performs continuous tracking, stores no precise GPS history, and declared logs remain possible without geolocation.
Purpose & legal basis: contract performance (maintaining your personal park map and ride history).
D. Outings (Planned Visits)
Data: selected theme park and planned visit date.
Functioning and privacy: an Outing represents a planned visit. Users can view their own participation and see accepted friends participating in the same Outing. Non-friend participants remain strictly invisible: no public headcount reveals their presence, no collective Outing chat exists, and no contact with strangers is enabled through Outings. No real-time location or continuous movement tracking is performed.
Purpose & legal basis: service performance (coordinating park visits among accepted friends).
E. Private Messaging & Friends
Functioning: private messaging allows accepted friends to communicate directly. No new private messages are permitted with non-friends.
Data: accepted friends list, friend requests sent or received, and private direct messages between friends.
F. Technical Data & Website Storage
On the website: we use no advertising cookies and no third-party trackers. Only browser local storage (key timkelo_lang) is used to remember your preferred language (French or English).
Security logs: temporary IP addresses and server diagnostic logs processed to prevent abuse and guarantee platform security.
3. Advertising & Monetization (Google AdMob)
To finance hosting infrastructure and ensure free access to core features, the Timkelo mobile application integrates the Google Mobile Ads (AdMob) advertising solution, provided by Google LLC.
Google Mobile Ads may process technical device information and app usage signals necessary for ad delivery, performance measurement, fraud prevention, and, where authorized, ad personalization.
The data that may be processed and the type of advertising displayed depend in particular on your region, platform, the applicable Google Mobile Ads configuration and, where required, your consent choices. Timkelo does not systematically access the IDFA (iOS) or the Google Advertising ID (Android); availability or transmission of such identifiers depends on the platform, operating system settings, and permissions granted.
Consent Management (Google UMP): Where required by applicable privacy laws (notably in the European Economic Area, the United Kingdom, and Switzerland), Timkelo utilizes the certified Google User Messaging Platform (UMP) to collect and manage your advertising consent preferences.
Current Ad Formats and Placements:
In the current version of the application, integrated advertising formats include:
- Native ads integrated within certain content surfaces (e.g. social feed, parks list, or Outings list);
- An occasional interstitial ad optionally displayed after a successfully published post.
These placements and surfaces are indicative and subject to change across future application updates. To date, no ad formats are displayed within private messaging, the interactive map, or ride sheets.
4. Managing Your Ad Choices
You may review and adjust your advertising consent preferences at any time:
- In the mobile app: where applicable and available, via Profile > Settings > Ad Privacy (opening the UMP consent manager);
- In your operating system settings: on iOS under Settings > Privacy & Security > Tracking, and on Android under Settings > Security & Privacy > Ads.
5. Recipients & Processors
Your personal data is strictly confidential. It is only shared with technical service providers essential to operating Timkelo:
- Supabase Inc.: backend infrastructure, secure database management, authentication, and media storage.
- Cloudflare, Inc.: public website hosting, content delivery, and DDoS protection.
- Google LLC (Google Mobile Ads / UMP): ad delivery and consent collection services.
- Judicial or regulatory authorities: only when strictly required by enforceable legal process.
6. International Data Transfers
Some technical providers operate infrastructure located outside the European Economic Area (notably in the United States).
These transfers rely on recognized legal mechanisms, such as the EU-US Data Privacy Framework or European Commission Standard Contractual Clauses (SCCs).
7. Data Retention
We retain personal data only as long as necessary for the purposes set out in this Policy:
- Account & profile data: retained as long as your account remains active.
- Posts & map logs: retained while your account is active or until deleted by you.
- Account deletion: upon request to close your account, your personal data is permanently deleted or irreversibly anonymized.
- Technical security logs: retained for a period not exceeding [À COMPLÉTER AVANT PUBLICATION : retention period for server logs, e.g. maximum 12 months].
8. Your Rights & Complaints
In accordance with GDPR and applicable privacy legislation, you have the following rights:
- Right of access: request confirmation and a copy of your personal data.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure (« right to be forgotten »): request deletion of your account and personal data.
- Right to restriction: request temporary freezing of data processing under statutory conditions.
- Right to object: object to processing based on legitimate interests for valid grounds.
- Right to data portability: receive your personal data in a structured, machine-readable format.
- Right to withdraw consent: withdraw your consent at any time for consent-based processing.
To exercise your rights, please write to our dedicated address: [À COMPLÉTER AVANT PUBLICATION : dedicated privacy email address, e.g. privacy@timkelo.com]
You also have the right to lodge a complaint with your competent data protection supervisory authority (such as the CNIL in France, www.cnil.fr).
9. Data Security
Timkelo applies technical and organizational security measures conforming to industry standards to protect your information against unauthorized access, loss, or alteration: HTTPS/TLS encryption, cryptographic password hashing, and strict database row-level access controls.
10. Protection of Minors
Timkelo is intended for individuals who have reached the digital age of consent in their country of residence: [À COMPLÉTER AVANT PUBLICATION : minimum age requirement, e.g. 15 in France / 13-16 depending on local jurisdiction].
We do not knowingly collect personal data from children below this age. If we learn that an account was created by an underage user without valid parental authorization, we will promptly close the account and erase associated data.
11. Policy Updates
We may update this Privacy Policy from time to time to reflect product enhancements or regulatory changes. When significant updates occur, advance notice will be provided via the application or our website.
12. Contact Information
For any questions regarding this Privacy Policy or your personal data:
Email: [À COMPLÉTER AVANT PUBLICATION : contact email address, e.g. privacy@timkelo.com]
Address: [À COMPLÉTER AVANT PUBLICATION : publisher domicile or registered address]