Privacy policy

Last updated: 4 October 2026

This is a translation. The Spanish version is the reference text: if they differ, the Spanish one prevails.

Controller

David López Cuadrado, an individual. For any privacy matter: contacto@funtechfactory.com.

This policy covers Atlas (atlas.funtechfactory.com). You sign in to Atlas with your FunTech Factory account, which is governed by its own privacy policy.

What data Atlas stores and why

Your account

When you sign in, Atlas receives your identifier, first name, last name and email from your FunTech Factory account, and stores them to know who you are, show your name to the people you share trips with and show you your details in My account; they're refreshed every time you sign in. If you administer Atlas, it also receives that role, and stores that you have it and when it was checked. It also stores the username (@handle) you pick when you first sign in: people who want to share a trip with you find you by it. When someone types at least three characters of an @handle, Atlas suggests the ones that start the same way, showing only the name and the @handle, never the email, and never hidden accounts (see "Profile and visibility"). It also stores the language you use Atlas in, when you sign in and whenever you change it, to write to you in that language. Your session is stored as a random code (only its encrypted fingerprint) that expires after 180 days without use. Legal basis: providing the service you ask for (art. 6.1.b GDPR).

Your trips

What you write in your trips and plans: titles, destinations, dates and times, places and their coordinates, links, booking codes, who you booked with, flight or train numbers, amounts, notes and the list of what to get ready before you go (with its dates and what's done), and who travels: the participants, with the name whoever created the trip types (also for people not on Atlas) or linked to their account, who paid each plan, and the trip's other payments (group expenses and participants paying each other back). Only the people you share each trip with see it, except what you publish in Inspiration (see "Published trips"). Legal basis: providing the service (art. 6.1.b GDPR).

Don't store data you don't need in Atlas, such as passport or card numbers: Atlas doesn't ask for them or protect them in any special way.

Shared trips

When you share a trip, by @handle or by email, that person gets an invitation they can accept or decline, and Atlas keeps it until they answer or you cancel it. Atlas also sends them an email in your name: to create their account if they don't use Atlas yet, or to accept the invitation if they do. The email shows your name, your email (so they can reply to you) and the trip's title. Each person gets a single email per trip and at most one a day; for that we store when we last wrote to them. If they don't use Atlas yet, we also store their email until they first sign in, to show them the invitation. Legal basis: our legitimate interest in letting you share your trips (art. 6.1.f GDPR).

Link to view a trip

Whoever created a trip can create a link so that other people, without an account, can view it without being able to change it: the days, the plans with their times, places and flight or train numbers, the map and the name and @handle of whoever created it (whatever their visibility), but not prices, booking references, who it was booked with, who paid, the other payments, booking links or notes. Atlas stores the link, so its creator can copy it again, and, if a password is set, only an encrypted fingerprint of it. The link works until it's turned off, another one is created or the trip is deleted. Whoever opens it gives Atlas no data beyond the technical logs. Legal basis: providing the service (art. 6.1.b GDPR).

Trips in your calendar

Each person on a trip can create their own calendar link to subscribe to it from their calendar app (Google Calendar, Apple Calendar, Outlook…). That app downloads the trip every so often: its dates and each plan with its day, time, place and flight or train number, but not prices, booking references, who it was booked with, who paid, booking links or notes. What the app keeps is subject to its provider's policy. Atlas stores the link, so you can copy it again. It works until you turn it off, create another one, leave the trip or the trip is deleted. Legal basis: providing the service (art. 6.1.b GDPR).

Published trips

Whoever created a trip can publish it in Inspiration. Who sees it depends on their account's visibility: if it's public, anyone, with or without an account, sees on a public page its title, destination, dates (or only its length, if chosen), the plans with their type, place and time, the map, and the name and @handle of whoever published it, and search engines may index it; if it's private, only their followers; if it's hidden, nobody else. Prices, booking references, who it was booked with, who paid, flight or train numbers, booking links, notes, which plans are done and who else is on the trip are never published. Atlas stores since when it's published and whether the dates are shown. It can be unpublished at any time, and the page stops being available at once. Whoever uses a published trip as a template creates a private copy of their own, without prices, bookings or notes, and Atlas notes on the copy which trip it came from: the copy shows its members whose the original is, whoever published it gets a notification with the name of whoever used it, and the trip's page shows how many times it has been used as a template (only the number). Legal basis: your consent when publishing it (art. 6.1.a GDPR).

If you save a published trip, Atlas notes which trip and when, to show it to you in Saved. Only you see what you've saved; whoever published it sees how many people have saved it, never who. You can unsave it whenever you like. Legal basis: providing the service (art. 6.1.b GDPR).

If you rate a published trip (1 to 5 stars), Atlas stores your rating and when you gave or changed it. Everyone else, including whoever published it, sees only the average and how many ratings it has, never who gave them. You can change or remove it whenever you like. Legal basis: providing the service (art. 6.1.b GDPR).

If you comment on a published trip, Atlas stores the text, who wrote it and when. The comment is shown on the trip's page, with your name (and your @handle, unless your account is hidden), and search engines may index it if the trip is public. You can delete it whenever you like; whoever published the trip can also delete it or close comments, and then they're no longer shown. While the trip isn't published, its comments aren't shown. If you reply to a comment or mention someone by their @handle, that person gets a notification (only if they can see the trip and their account isn't hidden). A deleted comment that has replies stays as "Comment deleted", without its text or its author. Legal basis: providing the service (art. 6.1.b GDPR).

Profile and visibility

You have a profile at atlas.funtechfactory.com/your-handle with your name, your @handle, an optional bio you write yourself, your published trips and how many people follow you and how many you follow. It never shows your email or your private trips. Your account starts out public; you can change its visibility whenever you like in Settings:

  • Public (the default): anyone can see your profile and your published trips, search engines may index them and anyone with an account can follow you.
  • Private: anyone with an account can find you by your name or @handle and see your profile, but search engines don't index it. Whoever wants to follow you sends you a request, and your published trips are only seen by the followers you accept.
  • Hidden: nobody finds you or sees your profile, and you can only be invited to a trip by your exact email. Your published trips and comments are shown with your name only.

In People, anyone with an account can search for others by name or @handle (with at least three characters) and sees some suggestions: your name, your @handle and your bio may appear there if your account is private or public, never if it's hidden, and never your email. To choose the suggestions, Atlas looks at who you share trips with, who the people you follow follow and whose published trips you've saved, rated or commented on, never saying why it suggests someone. There's no list of every account. Legal basis: providing the service (art. 6.1.b GDPR).

Accounts with a private profile from before these three options existed became private, which lets them be found by @handle. Atlas stores who each person follows, since when and whether the request is pending or accepted, to show them the trips those people publish in "Following". Only you see who follows you, who has asked to and who you follow; you can accept or decline requests (declining isn't notified), remove followers or unfollow someone whenever you like. Legal basis: providing the service (art. 6.1.b GDPR) and, for a public account, your consent when making it public (art. 6.1.a GDPR).

Inviting friends

From People you can invite someone to Atlas by typing their email. If they don't have an account yet, we send them an email in your name, with your name and your email so they can reply to you; if they already have one, we send them nothing, and we tell you the same in both cases. As with shared trips, an address gets at most one of these emails a day, and for that we store when we last wrote to it. We also keep their email, and nothing else, until they create an account or for 90 days at most, to know whether they came to Atlas through an invitation (see "Usage statistics"). You can also share your profile's link with your device's share menu. Legal basis: our legitimate interest in letting you invite people you know (art. 6.1.f GDPR).

Blocks and reports

You can block someone from their profile, from one of their comments or from your followers. Atlas stores who you've blocked and since when: while it lasts, neither of you sees the other's profile, published trips or comments, you don't find each other in searches and you can't follow each other or invite each other to a trip. Blocking deletes your follows and the notifications between you. The blocked person isn't told. You unblock whenever you like in Followers and following.

You can also report an account or a comment, with a reason if you like. The report reaches contacto@funtechfactory.com by email with your name, @handle and email, those of the reported person, the link, the comment's text and the reason, so it can be reviewed and answered. Atlas stores the report (who reported what, when, the reason and the comment's text as it was) so the people who run Atlas can review and resolve it, and stores who resolved it, when and with what note. Only they see who reported. The reported person isn't told. Legal basis: our legitimate interest in keeping Atlas safe (art. 6.1.f GDPR).

Administration

The people who run Atlas, with a permission granted in FunTech Factory, can see what moderation needs: accounts, what is published (trips, comments and profiles) and reports. They never see the content of private trips or sessions. Every action they take is logged with who took it, what it was, what it was about, when and, if they give one, the reason; that log is never deleted or changed, so every decision can be accounted for. Legal basis: our legitimate interest in keeping Atlas safe (art. 6.1.f GDPR).

If they remove a comment of yours, Atlas keeps it whole (without showing it) so it can be shown again, and tells you. If they take a trip of yours off Inspiration, it tells you why and notes that it can't be published again. If they suspend your account, Atlas stores since when, until when and why, ends your sessions and stops showing your profile, published trips and comments; it deletes nothing, and everything shows again when the suspension is lifted. The terms explain it.

Notifications

Atlas lets you know when someone starts following you or asks to, when someone accepts your request to follow them, when someone you follow publishes a trip, when your published trips get a comment or a rating, and when someone else changes a trip you share (unless you had it open at the time). For that it stores each notification: who it's for, what kind it is, who caused it, which trip, since when and when you read it; what changed in a trip it reads from the trip's change log. Ratings never say who gave them: Atlas stores who rated only to notify you once per person. Notifications are deleted after 180 days. In the notification settings you choose what you want to hear about; what you turn off is no longer stored. If you turn on the email summary (off at first), Atlas sends your unread notifications to your email, at most once a day, and stores when it sent it; each email has a link to stop receiving it. Legal basis: providing the service (art. 6.1.b GDPR) and, for the email summary, your consent when turning it on (art. 6.1.a GDPR).

Usage statistics

To understand how Atlas is used and decide what to improve, Atlas keeps on your account when you last used it, on the web or through an assistant (to the nearest hour), which days you used it and which days you used an assistant (the date only), and how you arrived: because someone invited you to a trip, because a friend invited you to Atlas, or on your own. It also counts, without saying whose, how many invitations are accepted or declined and how many emails are sent, held back or fail. From that and what it already stores, it works out overall figures each day, such as how many accounts, trips and published trips there are or how many people used it in the last day, week or month, and keeps them to see how they change. Those figures are totals only: they say nothing about anyone in particular. None of this is shown to other people or used to make decisions about you. Legal basis: our legitimate interest in running and improving the service (art. 6.1.f GDPR).

Your feedback

Once you’ve used Atlas for a few days, it asks how it’s working for you; you can also send feedback any time from “Send feedback”. If you send it, Atlas keeps your rating (1 to 5), your comment if you write one, the page you sent it from (without what follows the “?”), the version of Atlas, your language and when, linked to your account. Only Atlas’s admins read it, to understand what works and what to improve; if the rating is low and you write a comment, it’s also emailed to support. Atlas keeps on your account when you last sent feedback and until when you chose “Not now”, so it doesn’t ask again too soon. Legal basis: our legitimate interest in running and improving the service (art. 6.1.f GDPR).

Change log

Every change to a trip is noted: who made it, what kind of change it was, on which trip or plan, when, and whether it came from the web or from an assistant. It serves to know what happened to a shared trip and to detect misuse. Legal basis: legitimate interest (art. 6.1.f GDPR).

Technical logs

The server logs data about each request (IP address, browser, page requested and time) to serve Atlas and protect it. Legal basis: legitimate interest in keeping the service secure (art. 6.1.f GDPR).

Analytics

Google Analytics, only if you accept it in the cookie notice, to know how much Atlas is used and which pages. It doesn't send the content of your trips. Legal basis: your consent (art. 6.1.a GDPR), which you can withdraw at any time from "Cookies", at the foot of every page.

Assistants (Claude and ChatGPT)

If you connect Atlas to Claude (Anthropic) or ChatGPT (OpenAI), the assistant can read and change your trips when you ask it to. The data it looks up goes to that service, which handles it under its own privacy policy. Atlas only receives from the assistant an authorization from your FunTech Factory account and the requests it makes in your name. Each assistant is off until you turn it on in Assistants, and you can turn it off there or disconnect it from the assistant at any time.

On your device

Atlas keeps a copy of the pages you open in the browser, so they work offline. It's deleted when you sign out of Atlas. It also uses these cookies:

  • atlas_session: keeps you signed in (180 days).
  • atlas_oidc and atlas_no_access: the sign-in process (10 minutes).
  • tz: your time zone, to know which day is "today" (1 year).
  • lang: the language you picked for Atlas (1 year).
  • atlas_view: the trip view you picked (1 year).
  • atlas_link: remembers that you typed the password of a link to view a trip, only on that link (1 year).
  • atlas_consent: your choice about analytics cookies (1 year).
  • atlas_login, _ga and _ga_*: analytics, only if you accept it.

More details in the cookie policy.

Who else handles your data

We don't sell or hand over your data. Only these are involved, as far as needed:

  • IONOS SE (Germany, EU): hosts Atlas's server and sends its emails, as a processor.
  • The storage provider for the backups, as a processor.
  • OpenFreeMap, which serves the map images, and Photon (Komoot), which searches for places: your browser asks them for the data directly, so they receive your IP address and, in Photon's case, the text you search for.
  • Google Ireland Limited: Google Analytics, with your consent. Google may transfer data to the United States under the EU-U.S. Data Privacy Framework and standard contractual clauses.
  • Anthropic and OpenAI, only if you connect their assistant, as explained above.

We'll only disclose data to authorities when a law requires us to.

How long we keep data

  • Account, trips and change log: while you use Atlas. What you delete disappears at once, also for the people you shared that trip with.
  • Pending invitations: until the person signs in or the invitation is cancelled.
  • Log of admin actions: with no time limit, so each one can be accounted for.
  • Emails invited to Atlas from People: until they create an account, 90 days at most.
  • Usage statistics: the days you used Atlas or an assistant, 400 days; the overall figures, with no time limit, as they identify no one.
  • Your feedback: as long as your account exists.
  • Technical logs: at most 90 days.
  • Backups: at most 30 days.
  • Google Analytics: at most 14 months.

If you ask us to delete your Atlas account, we delete your data and the trips that were only yours. In shared trips, what you added stays for the other people, without your name. Deleting your FunTech Factory account doesn't delete your Atlas data: write to us as well.

Your rights

You can ask for access to, rectification or erasure of your data, restriction of processing, portability, and object to processing, and withdraw your consent at any time. Write to contacto@funtechfactory.com from your account's email. We'll answer within one month at most. If you think we haven't handled your rights properly, you can file a complaint with the Spanish Data Protection Agency (www.aepd.es).

Minors

Atlas isn't aimed at children under 14 and we don't knowingly process their data. If you're under 14, don't use Atlas. If we learn that an account belongs to a child under 14, we'll delete their Atlas data. If you think that's the case, write to us at contacto@funtechfactory.com.

Security

Connections are encrypted (HTTPS), each trip is only accessible to its members and sessions are stored only as an encrypted fingerprint. We don't make automated decisions or build profiles about you.

Changes

If we change this policy, we'll update this page's date and, if the change is significant, we'll let you know by email before it applies.