Privacy Policy

Effective Date: September 30, 2025 (Last Updated)

1. Introduction

Welcome to EXOTRAILS COMPANY LIMITED ("ExoTrails", "we", "our", or "us").

This Privacy Policy explains how we collect, use, disclose, store, and protect personal data of individuals who use exotrails.com or our mobile apps (collectively, the "Service").

We comply with:

  • Decree 13/2023/NĐ-CP on Personal Data Protection (PDPD) of Vietnam (currently applicable)
  • Law No. 91/2025/QH15 on Personal Data Protection of Vietnam (effective Jan 1 2026), we will transition to full compliance by that date
  • EU General Data Protection Regulation (GDPR)
  • California Consumer Privacy Act (CCPA) and CalOPPA
  • Other applicable global privacy laws

We use your data to provide and improve Service. By using Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, the terms used in this Privacy Policy have the same meanings as in our Terms and Conditions.

Our Terms and Conditions ("Terms") govern all use of our Service and together with the Privacy Policy constitutes your agreement with us ("agreement").

2. Definitions

Key terms used in this Policy:

Service: the ExoTrails platform (website & apps) operated by EXOTRAILS COMPANY LIMITED

Personal Data means data about a living individual who can be identified from those data (or from that and other information either in our possession or likely to come into our possession).

Usage Data is data collected automatically either generated by the use of Service or from Service infrastructure itself (for example, the duration of a page visit).

Cookies are small files stored on your device (computer or mobile device).

Data Controller means a natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal data are, or are to be, processed. For the purpose of this Privacy Policy, we are a Data Controller of your data.

Data Processors (or Service Providers) means any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively.

Data Subject is any living individual who is the subject of Personal Data.

The User is the individual using our Service. The User corresponds to the Data Subject, who is the subject of Personal Data.

3. Lawful Bases for Processing

We process Personal Data based on:

4. Data We Collect

a) Account & Contact Data

Name, email, phone, password, profile photo, language preference.

b) Activity, Health & Location Data

c) Usage Data

Technical & Log Data: When you access the Service, we automatically collect technical data (browser, OS, referrer, URL visited, request timestamp, IP address, device identifiers, app/network latency). We use this to operate the Service, prevent abuse, and diagnose incidents. IP addresses and security logs are kept up to 90 days, then deleted or anonymized unless the law requires longer.

d) Contacts

If you opt in, we hash and compare your device contacts solely to help you discover friends; you can revoke this permission at any time.

e) Cookies, SDKs & Similar Technologies

We use (i) essential cookies/SDKs to run the Service, (ii) analytics (with consent where required) to improve performance, and (iii) profiling/marketing (only with your opt-in consent). You can manage non-essential cookies via our cookie banner and in-app controls, and adjust OS ad preferences (iOS/Android) or withdraw consent anytime in app/browser privacy settings.

f) Subscription & Billing Data

If you buy a subscription plan we collect:

We use third-party payment processors to handle payments. They receive only the data needed to process your transaction and store card details on their systems. We receive confirmation of payment status and basic billing metadata. See our payment processor's privacy notice for details.

g) Third-Party Accounts

If you sign up or log in with Apple/Google or connect social accounts, we receive the info you authorize (e.g., name, email, profile image). You can disconnect anytime in settings or the third-party account.

h) AI/ML Features

We use machine learning/AI to power features such as route recommendations, anomaly detection on leaderboards, and training insights. We prefer aggregated/de-identified data where possible; where features rely on health or precise location data, we only process them with your settings and explicit consent (where required).

i) Other Data

While using our Service, we may also collect the following information: sex, age, date of birth, place of birth, passport details, citizenship, registration at place of residence and actual address, telephone number (work, mobile), details of documents on education, qualification, professional training, employment agreements, NDA agreements, information on bonuses and compensation, information on marital status, family members, social security (or other taxpayer identification) number, office location and other data.

5. Use of Data

We use your data to:

You can control your preferences anytime in settings.

6. Privacy Controls

7. Retention of Data

8. International Transfers

If your data is transferred outside Vietnam (e.g., to cloud servers in Singapore or the EU), we will:

9. Disclosure of Data

We may disclose Personal Data:

10. Security

We apply appropriate technical and organizational measures to safeguard your data.

No online system is 100% secure; we will notify affected users and authorities of breaches as required by law.

11. Your Data Protection Rights

a) Vietnamese Users – Current PDPD (Decree 13/2023)

You have the right to:

These rights will remain under Decree 13/2023 until Law 91/2025/QH15 takes effect on Jan 1 2026; we will then align fully with the updated rights framework.

b) EU / EEA Users Under General Data Protection Regulation (GDPR)

If you are a resident of the European Union (EU) and European Economic Area (EEA), you have certain data protection rights, covered by GDPR.

We aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.

If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please email us at support@exotrails.com.

In certain circumstances, you have the following data protection rights to:

Please note, we may not be able to provide Service without some necessary data.

You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA).

c) California Users under the California Privacy Protection Act (CCPA / CalOPPA)

If you are a California resident, ExoTrails complies with the California Online Privacy Protection Act (CalOPPA) and the California Consumer Privacy Act (CCPA).

Under these laws, you have the right to:

How we comply:

"Do Not Track" Signals:

We honor browser-based "Do Not Track" settings. When enabled, we do not track, place cookies, or deliver personalized advertising.

To adjust your Do Not Track settings, visit your browser's Preferences or Privacy Settings page.

d) Data Request Process

To protect your privacy and comply with applicable laws (PDPD, GDPR, CCPA), we verify your identity before processing any personal data request.

How to submit a request:

Email support@exotrails.com with:

What you can request:

Limitations:

We may refuse or limit requests that:

Response time:

We will acknowledge your request within 10 working days and respond within 45 calendar days, unless extended for legitimate reasons.

For all privacy-related requests, contact: support@exotrails.com

12. Advertising & Analytics

We use analytics to improve the Service and, with your consent, cookies/SDKs for personalized offers/ads. Manage non-essential cookies via our banner and in-app controls; adjust advertising preferences in your device OS. You may opt out of marketing emails via unsubscribe links and manage push notifications in app/OS settings.

13. Third-Party Services & APIs

If you connect third-party apps, devices, or integrations (e.g., wearables, training platforms), we share only the minimum data needed for an integration and prohibit unrelated use. Partners and developers may not use ExoTrails data to train AI models or for purposes outside the user-authorized feature. We may limit or revoke access for violations.

When you interact with our official pages on third-party platforms, those platforms may process your data under their terms. We may receive aggregated analytics about page visits and engagement.

14. Law-Enforcement Requests

15. Children's Privacy

The Service is not intended for anyone under 18, and we do not knowingly collect data from minors. For any permitted teen accounts in specific regions, stricter defaults apply (e.g., Followers-only visibility, stronger map privacy, messaging limits). Uploading heart-rate/health data generally requires being 16+ with explicit consent (where allowed by law). If you believe we collected data from a minor, contact support@exotrails.com.

16. Changes to This Policy

We may update this Policy to reflect changes in laws, technologies, or practices.

We will update the "Effective Date" above and, where appropriate, notify you by email or prominent notice in-app or on the website.

17. Contact Us

For any privacy-related questions, concerns, or rights requests:

Privacy Contact - ExoTrails
Email: support@exotrails.com