Privacy
Last updated 23 September 2026. The short version: the map needs no account and sets no tracking cookies. If you make an account, we keep only what the ledger needs, and you can delete all of it yourself.
Who is responsible
Mlok Works, s.r.o., Humpolecká 108/3, 460 05 Liberec, Czech Republic, IČO 24986003 (legal notice). Contact: martin.leskovjan@mlokworks.cz.
Browsing the map
You can use the map, the climbs and the Hall of Fame without an account. We keep no record of your visit. To show the page, your browser asks these servers for files, so they see your IP address:
- Cloudflare hosts this site. It may keep short technical logs under its own privacy policy.
- Esri (ArcGIS) serves the relief, hillshade and satellite map tiles.
- unpkg.com serves the map software (MapLibre).
- Mapy.com (Seznam.cz) serves map tiles only when you pick the Outdoor map.
Fonts and climb photos come from our own server. "Navigate" opens Google Maps only when you click it. "Locate me" asks your browser for your position; it stays in your browser and is never sent to us.
If you make an account
We store:
- Your email address and a hash of your password (never the password itself), to let you sign in.
- The name you choose (optional), and whether your profile is public.
- Your crossings: which climb and side you rode, the date and time, the climb time, and the file or activity it came from. This is the ledger.
- A session: a random token in a cookie called
sid, kept for 30 days so you stay signed in. We store only a hash of it. - The date you accepted The Rules.
Your ride files are not stored. We read an uploaded file once to find the cols you crossed, keep only those crossings, and discard the file. We never keep your route, your start point or your power data.
Why: to provide the account and ledger you asked for (GDPR Art. 6(1)(b)).
Strava (optional)
If you connect Strava, we store the access tokens Strava gives us (encrypted) and your Strava athlete ID, and read your rides to find crossings. Deleting your account removes them with everything else. Strava's own terms and privacy policy apply to your Strava account.
Emails
When we send you an email (to confirm your address or reset your password), it goes through Resend, which sees your address and the message. We send no newsletters or marketing.
Security records
To stop password guessing, we count sign-in attempts per IP address. These records are deleted automatically within 24 hours (GDPR Art. 6(1)(f), our legitimate interest in keeping accounts safe).
What others can see
Nothing, unless you make your profile public. A public profile and the Hall of Fame show your chosen name, the climbs you finished and the dates. Climb times and estimated power are shown only to you.
Cookies and local storage
sid: your sign-in session, only when you are signed in.oauth_state: a 10-minute security cookie while you connect Strava.- One note in your browser's local storage that you have seen the welcome screen.
No analytics, advertising or tracking cookies. That is why there is no cookie banner.
How long we keep it
Account data and crossings: until you delete your account. Sessions: 30 days. Email-confirmation and password-reset links: until they expire. Security records: at most 24 hours.
Your rights
You can see your data in the Me tab and delete your account and everything in it yourself (Me → "Disconnect & delete"). You can also ask us to see, correct, export or delete your data, or object to its use: write to the contact above. You can complain to the Czech data-protection authority, ÚOOU, or to the authority where you live.