Privacy Policy
Effective from 3 October 2026
This Privacy Policy explains how personal data is processed when you use LookoutFinder at lookoutfinder.com and the web application under lookoutfinder.com/app (the “Service”). It provides the information required by Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”). Terms used here have the meaning given in our Terms of Service.
1. Controller and contact
The controller of your personal data is Agileo.pl Mirosław Kapinos (sole proprietorship registered in Poland), Poland, tax ID (NIP): 8171833685 (“we”, “us”).
For any privacy matter, including exercising your rights, write to mk@agileo.pl. We have not appointed a data protection officer, as we are not required to.
2. What data we process and where it comes from
| Category | Data | Source |
|---|---|---|
| Account data | Name, e-mail address, Google account identifier, profile picture URL, account role (user, contributor, administrator), account creation date, token balance and token history | Google, when you sign in; our records |
| Profile data | Bio, links to your website or social profiles, profile visibility setting | You |
| Content | Viewpoints you add (including their location), photos and their technical data (size, dimensions, licence), ratings, reviews, condition alerts, lists, photo downloads | You |
| Contributor applications | Portfolio links, bio, motivation, the decision and an administrator’s note | You; our team |
| Session and security data | Sign-in tokens (stored by us only in hashed form) with their creation, last-use and expiry times; IP address, browser user agent and time of requests | Your browser |
| Correspondence | Your e-mail address, the content of your message and our reply, including content reports and appeals | You |
Photos and metadata. Photo files may contain embedded metadata (EXIF), including the camera model and the GPS location where the photo was taken. We do not read or store this metadata in our database, but the original file you upload is stored as it is and may be downloaded by other users under the Terms. Remove metadata you do not want to share before uploading.
Your current location. When you add a viewpoint, you can use the “use my current location” option. Your browser will ask for permission first; the location is used only to fill in the coordinates in the form and reaches us only if you save the viewpoint, in which case it becomes the viewpoint’s public location.
We do not use analytics or advertising tools, do not profile you and do not sell your data.
3. Why we process your data and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account, signing you in, publishing and displaying your content, lists, ratings, tokens and photo downloads — i.e. providing the Service under the Terms | Performance of a contract (Art. 6(1)(b) GDPR) |
| Reviewing your contributor application at your request | Steps taken at your request before entering into a contract and performance of a contract (Art. 6(1)(b)) |
| Keeping the Service secure: protecting against abuse, rate limiting, detecting and fixing errors, keeping server and application logs | Our legitimate interest in a secure and working service (Art. 6(1)(f)) |
| Handling reports of illegal content, moderation decisions, statements of reasons and appeals | Legal obligation under the Digital Services Act, Regulation (EU) 2022/2065 (Art. 6(1)(c)), and our legitimate interest in keeping the Service free from illegal and harmful content (Art. 6(1)(f)) |
| Answering your messages and requests | Our legitimate interest in communicating with users (Art. 6(1)(f)); where a request concerns your GDPR rights — legal obligation (Art. 6(1)(c)) |
| Establishing, exercising or defending legal claims | Our legitimate interest (Art. 6(1)(f)) |
| Displaying web fonts and icons on our public pages and maps in the Service (see section 4) | Our legitimate interest in presenting the Service properly (Art. 6(1)(f)) |
4. Who receives your data
Content you publish (viewpoints, photos, ratings, reviews, alerts) is visible to everyone, together with your display name and profile picture. Your profile page is public unless you make it private. Your e-mail address is never shown publicly; it is visible only to our administrators.
We use the following service providers. Those marked as processors process data only on our instructions under a data processing agreement:
- LH.pl sp. z o.o. (Poland) — server hosting, database and server logs (processor). Data stays in Poland.
- Cloudinary Ltd. (USA) — storage, processing and delivery of uploaded photos (processor). Photos are delivered to visitors from Cloudinary’s servers, so Cloudinary sees the visitor’s IP address and browser data.
- Mapbox, Inc. (USA) — interactive maps on our home page and in the Service. Your browser loads the map software and map tiles directly from Mapbox, which receives your IP address, browser data and the area of the map you view. Mapbox also collects anonymous usage data needed to count map loads.
- Google — Google Ireland Limited (Ireland) and Google LLC (USA): (a) Google Sign-In: when you sign in, Google authenticates you and sends us the account data listed in section 2; Google acts as an independent controller of your Google account data under its own privacy policy; (b) your profile picture is displayed from Google’s servers; (c) Google Fonts: our public pages (home page, legal pages) load fonts from Google’s servers, which receive your IP address and browser data.
- unpkg (content delivery network, USA) — our public pages load an icon stylesheet from unpkg.com, which receives your IP address and browser data.
- Open-Meteo — provides the weather forecast shown on viewpoint pages. Our server requests the forecast for the viewpoint’s coordinates; no data about you is sent.
We may also disclose data to public authorities and courts where we are legally obliged to do so, and to professional advisers (for example lawyers) bound by confidentiality.
5. Transfers outside the European Economic Area
Cloudinary, Mapbox, Google and the unpkg network may process data in the United States or other countries outside the EEA. Where the recipient is certified under the EU–U.S. Data Privacy Framework, the transfer is based on the European Commission’s adequacy decision of 10 July 2023 (Art. 45 GDPR). Otherwise, it is based on the European Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR) included in the provider’s data processing terms. You can obtain a copy of the relevant safeguards by writing to us.
6. How long we keep data
- Account, profile and content — while your account exists. After you ask us to delete your account, we delete it within 30 days (see section 11 of the Terms for what is deleted). Content you delete yourself disappears from the Service immediately; the image files are then deleted from our image storage provider within 30 days.
- Contributor applications — while your account exists.
- Sign-in tokens — until you sign out or for up to 30 days after they are issued, whichever comes first.
- Session records (IP address, user agent) — up to 2 hours after your last activity, after which they are removed by periodic clean-up.
- Server and application logs — up to 30 days, unless needed longer to investigate a specific security incident.
- Content reports, moderation decisions and appeals — for 12 months after the case is closed, or longer if needed for legal claims.
- Correspondence — for as long as needed to handle your matter and then for up to 12 months.
- Backups — deleted data may remain in backups until they are overwritten in the normal backup cycle, and is not restored to the Service.
We may keep data longer where needed to establish, exercise or defend legal claims, until the limitation period for those claims expires.
7. Your rights
Under the GDPR you have the right to:
- access your data and receive a copy of it (Art. 15);
- rectify inaccurate data (Art. 16) — most of it you can edit yourself in your profile;
- erasure of your data (Art. 17), including by deleting your account;
- restrict processing (Art. 18);
- data portability for data you provided to us that we process under a contract (Art. 20);
- object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests (Art. 21);
- lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or the authority in the EU country where you live or work.
To exercise your rights, e-mail mk@agileo.pl, preferably from the address linked to your account. We reply within one month; this can be extended by two further months for complex requests, in which case we will tell you why. Exercising your rights is free of charge.
8. Is providing data required?
You can browse the Service without an account. Creating an account is voluntary, but without the account data we receive from Google we cannot create your account. Profile details and content are optional. Your IP address and browser data are necessarily transmitted when you visit any website, including ours.
9. Automated decisions
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). Uploads whose file names contain certain words are automatically held back for manual review; the final decision is always taken by a person.
10. Cookies and browser storage
We only use cookies and browser storage that are strictly necessary to provide the Service you request; therefore we do not ask for consent. We do not use analytics, advertising or tracking cookies.
| Name | Type | Purpose | Duration |
|---|---|---|---|
Session cookie (named after the application, e.g. lookoutfinder-session) | Cookie, set by us on our public pages | Technical session of the server framework | 2 hours |
XSRF-TOKEN | Cookie, set by us | Protection against cross-site request forgery | 2 hours |
lookoutfinder.auth.token | Local storage | Keeps you signed in to the web application | Until you sign out; the token expires after 30 days |
lookoutfinder.auth.user | Local storage | Your basic account details (name, e-mail, profile picture, role, token balance) to display the interface | Until you sign out |
lookoutfinder.auth.returnUrl | Session storage | Returns you to the page you were on after signing in | Until sign-in completes or the tab is closed |
lookoutfinder.ui.theme | Local storage | Remembers your light/dark mode choice | Until you clear it |
vp-overlays-visible | Session storage | Remembers whether photo overlays are shown | Until the tab is closed |
| Mapbox storage | Local storage / cache, set by Mapbox’s map software | Anonymous identifier for counting map loads and cached map data | As set by Mapbox |
You can delete cookies and browser storage in your browser settings at any time. If you block them, you may not be able to sign in.
11. Children
The Service is not intended for children. You must be at least 16 years old to create an account. If we learn that an account belongs to someone younger, we will delete it. If you believe a child has given us personal data, please contact us.
12. Security
We use encrypted connections (HTTPS), store sign-in tokens only in hashed form, restrict administrative access to authorised team members and limit request rates to prevent abuse. No method of transmission or storage is completely secure, but we work to protect your data and will notify you and the supervisory authority of a personal data breach where the law requires it.
13. Changes to this policy
We will update this policy when we change how we process personal data, for example when we add a new feature or service provider. We will inform account holders of significant changes by e-mail or in the Service before they take effect. The effective date at the top shows the current version.