Privacy policy
Privacy Policy
Last updated: 31 August 2026.
This policy explains how we handle your personal data, including the activity file or screenshot you upload. Because that upload describes where and how you moved, we treat it as sensitive; the retention section below says exactly how long we keep it.
Who is responsible (data controller)
AREION QUANTUM, s.r.o., a company incorporated in the Czech Republic, operating the Traceform brand, is the controller of your personal data.
- Privacy contact: privacy@gettraceform.com
- Registered office: Chvalská 718/10, Hloubětín, 198 00 Praha 9, Czech Republic
- Company ID (IČO): 19621809
- Registered in the Commercial Register kept by the Municipal Court in Prague, Section C, Insert 389344
Because we are established in the EU, we apply the EU General Data Protection Regulation (GDPR) to our processing, in addition to the US state-law rights described below.
What we collect
- Order and contact data: your name, email, shipping address, and payment status. Payment is handled by Shopify Payments and PayPal; we do not store card numbers.
- Your upload, in one of two forms. You choose which:
- a GPX activity file — your route, timestamps, elevation, and pacing. This is precise location and activity data. Before it leaves your device, your browser strips heart rate, cadence, power, and any other sensor data out of the file. Our server strips the same things again on arrival, in case the first pass was skipped or failed.
- a photo or screenshot of an activity summary card — for example the share card an activity app generates. From it we trace the shape of your route and read the distance, moving time, and pace printed on the card. We do not read the activity name. We cannot strip anything out of an image before you send it, so the picture reaches us exactly as you took it. If your screenshot happens to show your name, your profile picture, an app logo, or anything else on screen, that is stored with it until the file is deleted on the schedule below. Crop it first if you would rather not send that.
- What you write: the caption or dedication you choose to print, and any note you leave for us at the proof step.
- Usage data: advertising cookies, used for measurement (see Cookies and ads).
Why we use it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Generate your preview and produce, ship, and support your order | Performance of your contract |
| Keep an order record for tax and accounting | Legal obligation |
| Prevent fraud and secure the store | Legitimate interests |
| Measure our advertising | Consent — and see Cookies and ads, which states plainly that we do not currently operate a consent banner to collect it |
| Send marketing | Consent, which you can withdraw at any time |
How we handle your upload
Your upload is used only to create your artwork and keep an order record. We do not sell it.
- We never send your uploaded file, its coordinates, or your proof image to our advertising providers. The events that do reach them are listed in full under Cookies and ads, and no part of your route or your artwork is among them.
- We do not take orders for delivery to Washington State in round 1, because Washington's My Health My Data Act may treat route and activity data as consumer health data and we have not had that reviewed. See our Shipping Policy.
Who we share it with
We share data only with providers who help us operate:
- Gelato — to produce and ship your print.
- Shopify — store platform and payments.
- PayPal — payment processing.
- Meta — advertising measurement. Meta receives the events described under Cookies and ads, together with your name, email address, phone number, and location, so that it can match them to your Meta account. It does not receive your upload, your route, or your proof image.
- Our hosting provider — a single server in North America runs the preview and proof service, so your upload and the images made from it are stored there while we work on your order.
- Backblaze — the encrypted off-site copy described under retention.
Data-processing agreements and international-transfer safeguards with each provider are confirmed before public launch.
International transfers
Your data is processed outside the European Economic Area: our server is in North America and several of our providers are in the United States. Those transfers rely on an approved safeguard — the EU Standard Contractual Clauses, or an adequacy decision covering the destination country.
How long we keep it (retention)
- Abandoned previews — if you upload a file to preview but do not order, we delete the preview and the uploaded file after 24 hours.
- Your uploaded file or photo — deleted as soon as your final print file is produced, or on refund or cancellation, whichever comes first, and in every case no later than 30 days after upload.
- Derived images — your preview and proof images, and any note you write at the proof step, are kept up to 90 days for reprint and support, then deleted.
- Encrypted off-site copy — once you have paid, an encrypted copy of your order, including your upload, is written to backup storage so a server failure cannot lose your order. This copy is deliberately immutable: we cannot delete it early, not even on request. It expires on the storage provider's schedule, about a month after it is written.
- Order records (name, address, amounts, and the caption you chose) are kept for as long as Czech accounting and tax law requires us to keep the invoice they belong to.
Your rights
Under GDPR you can request access, rectification, erasure, restriction, objection, and portability, and you can withdraw consent at any time without affecting prior processing. You can also lodge a complaint with the Czech supervisory authority (Úřad pro ochranu osobních údajů, ÚOOÚ) or your local authority.
Under US state law (for example California residents), you can request access, correction, and deletion, and opt out of the sale or sharing of personal data for cross-context targeted advertising.
To exercise any right, email privacy@gettraceform.com. A person reads that inbox and answers it.
Cookies and ads
We use cookies and Meta advertising pixels to measure our advertising. Two separate things report to Meta and they do not send the same amount, so each is described on its own below.
Our own preview pixel sends a fixed list, and your upload is not on it. It carries which print style and variant you looked at, whether the digital add-on was selected, which upload source you used, whether a step succeeded or failed and why, how long a render took, a rough size bucket for the file, and whether you retried. Nothing in that list identifies you, and no part of your route, your photo, or your proof reaches Meta through it. That list is what we put on the event. Because these events go through the same Meta pixel as the store integration described next, Meta can attach the matching details described there to them as well.
The Meta store integration sends more. We run it at its enhanced data-sharing level, the middle of the three levels it offers. At that level your name, email address, phone number, and location are shared with Meta together with your activity in the store, so that Meta can match it to your Meta account. When you complete an order, Shopify also sends that purchase to Meta from its own servers instead of from your browser, so the sale is recorded even if your browser blocks the pixel. We do not use the highest level, which would additionally enroll the store in advertising technology Meta has not released yet.
We do not currently operate a cookie banner, and we do not act on browser Do-Not-Track or Global Privacy Control signals. The pixel is set when you open the store. To stop advertising cookies, use your browser's cookie controls, or your ad settings with Meta.
Children
Our store is not directed to children, and we do not knowingly collect data from anyone under 18.
Changes to this policy
We may update this policy. The effective date is shown at the top.
Contact
Data controller: AREION QUANTUM, s.r.o. — privacy@gettraceform.com.