Who We Are
Trek Health provides a multi-tenant software platform that enables trekking companies ("Operators") to assign guides, enrol travellers, and record daily health checks during high-altitude expeditions. When Operators use our platform, we act as a data processor on their behalf. For data you provide directly to us (account registration, billing), we act as the data controller.
Questions about this policy: [email protected]
Data We Collect
2.1 Account Data
When you are registered on the platform (directly or by a company admin): full name, email address, role, company affiliation, and password hash.
2.2 Traveller Health Data
Guides record daily health checks for each enrolled traveller. This includes:
- Blood oxygen saturation (SpO₂) and pulse rate
- Symptom flags — headache, cough, weakness, vomiting
- Appetite rating, medication notes, free-text clinical notes
- Altitude destination and walking hours logged per day
2.3 Traveller Personal Data (Client Profiles)
- Full name, age, gender, nationality
- Emergency contact name and phone number
- Digital signature collected via the guide mobile app at trip start
2.4 Technical & Device Data
- Expo push notification token (guides only) — for real-time health alerts
- Device OS type (iOS / Android), reported by the mobile app
- IP address, retained in server-side access logs for up to 30 days
2.5 Billing Data
When a company admin purchases slot quota, payment details are handled entirely by Stripe. Trek Health stores only the Stripe Customer ID, the slot quantity purchased, and the transaction timestamp. We never receive or store full card numbers.
Legal Basis for Processing
| Data category | Basis | Detail |
|---|---|---|
| Account data | Contract | Necessary to provide the platform service |
| Health records | Vital interests / legitimate interests | Safety monitoring at altitude; explicit traveller consent obtained at enrolment via digital signature |
| Client PII | Legitimate interests (Operator) | Operators are responsible for obtaining consent from their travellers |
| Push tokens | Consent | Granted when notification permissions are accepted on device; withdrawn by revoking permissions |
| Billing data | Contract & legal obligation | Required to fulfil quota purchases and comply with financial record-keeping rules |
How We Use Your Data
- Display health dashboards and trend charts to authorised guides, agents, and company admins within the same Operator tenant
- Trigger real-time push and email alerts when a traveller's SpO₂ falls below defined safety thresholds
- Generate PDF health reports for authorised company agents
- Synchronise offline health records from the guide's mobile device to our servers when connectivity is restored
- Manage trip assignments, slot quota, and billing for Operators
- Send transactional emails (account setup, invoices, alert notifications) — no marketing emails without separate consent
- Monitor platform errors and performance via anonymised error reports
We will never use your health data for advertising, profiling, or sale to third parties.
Storage & Security
5.1 Cloud Storage
All data is stored in Supabase-managed PostgreSQL, hosted in [region, e.g. AWS eu-central-1]. Row-Level Security (RLS) policies enforced at the database level ensure each Operator company can only access its own data — isolation is structural, not just application-level.
5.2 On-Device Encryption (Guide App)
When a guide's mobile device is offline, health records and traveller data are stored in a local SQLite database. Before any data is written to disk, it is encrypted using AES-256-GCM. The encryption key is generated uniquely per device on first launch and stored in the device's secure enclave via the operating system keychain (iOS Keychain / Android Keystore). No health data is ever written to device storage in plain text.
5.3 Data in Transit
All communication between the app, the web dashboard, and our servers is protected by TLS 1.2 or higher. Authentication tokens are short-lived JWTs with custom company and role claims, issued by Supabase Auth.
5.4 Access Controls
Platform roles (Super Admin, Company Admin, Operation Manager, Guide, Agent) carry strictly scoped permissions. Guides can only read and write records for their assigned trips. Agents have read-only access to their assigned clients. No cross-tenant data access is possible by design.
5.5 Breach Notification
In the event of a data breach affecting personal data, we will notify affected Operators and, where required by law, the relevant supervisory authority, within 72 hours of becoming aware.
Data Sharing
6.1 Within Your Organisation
Health records and client data are shared within a single Operator tenant only — between the company's admins, assigned operation managers, guides, and agents. Data from one company is never visible to another.
6.2 Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | AWS [region] |
| Stripe | Payment processing | USA / EU |
| Resend | Transactional email | USA |
| Expo (EAS) | Mobile build & push notifications | USA |
| Sentry | Error monitoring (anonymised) | USA / EU |
| Vercel | Web dashboard hosting | USA / Edge |
All sub-processors have been evaluated for GDPR adequacy or are covered by Standard Contractual Clauses where required.
6.3 Legal Disclosure
We may disclose personal data if required by a valid court order, legal process, or to prevent serious and imminent risk to life or safety. We will notify affected users where legally permitted to do so.
6.4 No Sale of Data
We do not sell, rent, or trade personal data — particularly health data — to any third party, under any circumstances.
Data Retention
- Account data: Retained while the account is active. Deleted within 30 days of account closure.
- Health records: Retained for 5 years after the end of the trip assignment, then permanently deleted. Operators may configure a shorter retention window.
- Client profiles: Retained while the client has at least one active assignment in the Operator's account.
- Billing records: Retained for 7 years to comply with financial record-keeping obligations.
- Server access logs: Automatically deleted after 30 days.
- On-device data: Remains on the guide's device until the guide signs out or the app is uninstalled. Synced records can be cleared from device by the guide at any time via the app settings.
Your Rights
Depending on your location, you may have the following rights in relation to your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Ask us to correct inaccurate or incomplete data.
- Deletion: Request erasure of your data ("right to be forgotten"), subject to legal retention obligations.
- Restriction: Ask us to restrict how we process your data while a dispute is resolved.
- Portability: Receive your data in a machine-readable format (JSON or CSV).
- Objection: Object to processing based on legitimate interests.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. Identity verification may be required.
If you are in the EEA or UK and believe we have not handled your data lawfully, you may lodge a complaint with your national data protection authority — for example, the ICO (UK) or your local EU supervisory authority.
Children
Trek Health platform accounts are for adults (18+) only. Traveller client profiles may include minors — for example, on family trekking expeditions. In those cases, the Operator (trekking company) is responsible for obtaining appropriate parental or guardian consent before enrolling a minor and collecting their health data. Trek Health does not independently verify the age of enrolled travellers.
If you believe a child's data has been collected without appropriate consent, contact us immediately at [email protected].
Cookies & Tracking
The Trek Health web dashboard uses strictly necessary cookies only — a session cookie to maintain your authenticated state. No advertising, tracking, or analytics cookies are set.
The guide mobile app does not use browser cookies. It stores authentication tokens in the device's secure storage (iOS Keychain / Android Keystore).
We do not use third-party analytics scripts (no Google Analytics, no Meta Pixel, no fingerprinting). Error monitoring via Sentry uses anonymised, session-scoped identifiers only.
Changes to This Policy
We will notify all registered users by email at least 14 days before any material change to this policy takes effect. The "Last updated" date at the top of this page will reflect the most recent revision. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
For minor changes (correcting typos, clarifying existing practices), we may update the policy without advance notice, but the "Last updated" date will always change.
Past versions of this policy are available on request.