Privacy Policy
Snowdesk · snowdesk.info · Effective 8 September 2026 · Version 1.2
1. Who we are
Snowdesk is operated by Hugo Rodger-Brown, an individual based in London, UK. Snowdesk is a free service that displays avalanche bulletins published by the WSL Institute for Snow and Avalanche Research (SLF) for Switzerland, by ALBINA / EUREGIO for Tyrol, South Tyrol and Trentino, and by Météo-France for the French mountain ranges. There are no employees; all operations are carried out by the sole operator.
Questions about this policy? Email: privacy@snowdesk.info
2. What data we collect
2a. Your account
You can read every bulletin on Snowdesk without an account. If you create one, we collect your email address, and a password if you set one. You may also register a passkey, in which case your device keeps the private key and we store only the public credential — we never see the biometric or PIN that unlocks it.
2b. Things you save to your account
An account stores what you choose to put in it: favourite places, which are map pins with coordinates; pinned regions, which are saved the same way but without a coordinate; ski-touring routes you upload as GPX files, which describe where a route goes; offline map areas you download; and any field observations you submit. We store these because they are the feature — none of it is collected in the background, and deleting an item deletes the record.
2c. Location
The map can use your browser's geolocation to centre on where you are. That position is used in the browser and is not sent to us. Location does reach us in three other ways, each because you asked for something that needs it: a field observation carries the GPS fix taken when you tapped "Report"; a favourite carries the coordinates of the pin you placed; and an uploaded route carries its track. We also derive an approximate location — country, region and city — from your IP address at a few specific moments, described in section 2e.
2d. Field observation reports
When you submit a field observation, we ask your browser for a GPS fix. Your latitude, longitude and optional accuracy radius are stored with the report so we can match it to an avalanche warning region. Location is captured only at the moment you tap "Report" — we never track your position in the background or between sessions. Reports appear publicly as anonymous aggregate counts (for example "3 people reported whumpfing"); your identity and exact coordinates are never shown.
2e. Request records
At a few specific moments — creating an account, signing in, and opening a shared link — we store a record of the request. It holds your IP address, an approximate country, region and city derived from it, your browser's user agent and language, the page requested, and your session identifier. We use it to understand how people find Snowdesk and to investigate abuse. It is not written on every page view, and the approximate location comes from your IP address rather than from your device's GPS.
2f. Session data
We use cookies that are strictly necessary for the site to work — see section 8. They carry no personal information beyond keeping you signed in.
3. Why we use your data
We process your data under the following legal bases (UK GDPR):
- Email address and password — contract. We need them to give you an account and to sign you in.
- Favourites, routes, downloaded areas and passkeys — contract. These are the features you asked for; we cannot provide them without storing what you saved.
- Field observations — consent. Submitting one is a deliberate act, and you can ask us to remove a report you made.
- Push notifications — consent. Your browser asks you before a subscription is created, and turning notifications off removes it.
- Request records and session data — legitimate interest. We need them to keep the service secure, to investigate abuse, and to understand how people find Snowdesk.
- Anonymous app-usage telemetry — consent. It is off unless you switch it on, and section 5 describes what it contains.
4. How long we keep your data
- Your account and everything in it — kept until you delete it. Deleting your account removes the account, your saved items and the request records described in section 2e, in one operation and without delay.
- Request records — twelve months, then deleted automatically, whether or not they were ever linked to an account.
- Field observations — kept as part of the community record. Ask us and we will remove yours.
- Geolocation from your browser — never stored; used in the browser only.
- Server error logs — 14 days.
Deleting a saved item removes that record; it does not delete your account. Delete the account itself from your account settings if you want everything gone.
5. Who we share your data with
We do not sell, rent, or trade your personal data with anyone.
We use a small number of trusted service providers to operate Snowdesk:
- Render (render.com) — hosts the Snowdesk servers. Your IP address and request data pass through their infrastructure.
- Resend (resend.com) — sends the emails the account itself needs: your sign-in link, the message that verifies your address, a password reset, and the confirmation and notice sent when you change your email address. They receive your email address for this purpose only.
- Open-Meteo (open-meteo.com) — resolves the elevation of a location and supplies its mountain weather forecast. Requests are made by our servers for places, not for people; no personal data is shared with them.
- SLF / WSL — provides the avalanche bulletin data for Switzerland. No personal data is shared with them.
- ALBINA / EUREGIO (avalanche.report) — provides the avalanche bulletin data for Tyrol, South Tyrol and Trentino. No personal data is shared with them.
- Météo-France (meteofrance.com) — provides the avalanche bulletin data (BRA) for the French mountain ranges. No personal data is shared with them.
- PostHog (posthog.com) — processes the anonymous app-usage events described below, if you have telemetry switched on. We never send bulletin content, your email address, or your IP address as part of these events.
- Our map tile provider — your browser loads map tiles directly from the tile host, so it receives your IP address and the area of the map you are viewing. We do not send it anything else, and it is not told who you are.
- swisstopo (geo.admin.ch) — supplies the slope-angle overlay. As with the basemap, your browser requests those tiles directly, so swisstopo receives your IP address and the area you are viewing while the overlay is switched on.
- Your browser's push service (Google, Mozilla or Apple, depending on your browser) — if you turn on push notifications, your browser creates a subscription on its vendor's service and we send notifications through it. We never include bulletin content or your email address in a notification payload.
- MaxMind (maxmind.com) — supplies the GeoLite2 database we use to turn an IP address into an approximate country, region and city. The lookup runs on our own servers against a local copy, so your IP address is never sent to MaxMind.
All providers are contractually required to handle your data in compliance with UK GDPR. We do not use advertising networks, and we do not sell or share data for advertising purposes.
We collect a small stream of anonymous app-usage events — for example pwa.sw.installed or pwa.push.received — so we can keep Snowdesk working reliably across browsers and devices. These events never include bulletin content, your email address, or your IP address. This is switched off by default for browsers set to a European language, and on by default otherwise; you can change this at any time from the toggle in your account settings.
6. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data (“right to be forgotten”)
- Object to processing
- Withdraw consent at any time
You can exercise the most important of these yourself and immediately: deleting your account from your account settings removes the account, everything you saved to it, and the request records described in section 2e.
For anything else, email privacy@snowdesk.info. We will respond within 30 days.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
7. Children
Snowdesk is a publicly accessible information service. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, please contact us at privacy@snowdesk.info and we will delete the data without delay.
8. Cookies
Snowdesk uses two strictly necessary cookies: a session cookie, and a CSRF token that protects forms from cross-site submission. Neither carries personal information beyond keeping you signed in, and because both are strictly necessary no consent banner is required under UK PECR. We use no advertising cookies and no third-party cookies.
Snowdesk also stores things in your browser that are not cookies and are never sent to us on their own: your light or dark theme choice, the map areas you download for offline use, and the queue our anonymous usage-data telemetry (section 5) uses when you have it switched on. Clearing your browser's site data removes all of it.
9. Changes to this policy
If we make material changes to this policy, we will update the effective date and version at the top, and email anyone who has an account with us. Continued use of Snowdesk after changes constitutes acceptance.