Privacy Policy
Last updated: September 2026
Introduction
We are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose and safeguard your information when you use our website and our mobile app.
Data Controller
Denis.pt, Sociedade Unipessoal, Lda
Address: Estrada Monumental, Nº 277, Bloco 5, 1º E, 9000-250 São Martinho, Funchal, Madeira, Portugal
Email: info@denis.pt
Data We Collect
Automatically Collected Information
- IP address and location data
- Browser type and version
- Device information and operating system
- Pages visited and time spent on pages
- Referral source and search terms
Information You Provide
We may collect information that you voluntarily provide when contacting us, subscribing to newsletters, or using our services. This may include your name, email address, and any other information you choose to provide.
Purpose of Data Processing
- To provide and maintain our website and services
- To respond to your inquiries and communicate with you
- To analyze website usage and improve user experience
- To develop and improve our services
- To comply with legal obligations and protect our rights
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Your consent when you provide it voluntarily
- Performance of a contract or to take steps at your request before entering into a contract
- Compliance with legal obligations
- Our legitimate interests, such as improving our services and ensuring website security
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on our website and store certain information. Cookies are files with a small amount of data which may include an anonymous unique identifier.
Types of Cookies We Use
- Essential Cookies: These cookies are necessary for the website to function properly and cannot be switched off in our systems.
- Analytics Cookies: These cookies help us understand how visitors interact with our website by collecting and reporting information anonymously.
Google Analytics
We use Google Analytics 4 (measurement ID G-YM1ZR45GKF) to count visits and see which pages people read. The tag is loaded only after you accept cookies, so before that your browser makes no request to Google and no analytics cookie exists.
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Once you accept, Google Analytics sets the _ga and _ga_* cookies in your browser to recognise a returning visit. They expire after two years.
What it collects: the pages you open, when and for how long, the page that sent you here, your approximate location from a shortened IP address, and your device, browser and language. We do not use it to identify you, and we have turned off advertising features and IP logging in full.
Legal basis: your consent under Article 6(1)(a) GDPR. You can withdraw it at any time through the cookie settings link in the footer, which stops the measurement for every following page view.
Data may be processed on Google servers outside the European Economic Area. Google LLC is certified under the EU-US Data Privacy Framework, and transfers otherwise rest on the European Commission's standard contractual clauses.
Retention: Google deletes user-level and event-level data after 14 months.
Independently of our banner, Google offers a browser add-on that switches Analytics off on every site: https://tools.google.com/dlpage/gaoptout
Pages with videos or live webcams embed players from YouTube and Windy. These players load only after you click them; until then no request reaches those providers and they set no cookies.
The Azores1 app
Alongside this website we publish an app for iPhone and Android. It shows the same guide, weather, events and trail statuses, sends notifications if you ask for them, and sells four itinerary packages. It works without an account: instead of asking who you are, the app registers the installation.
Device identifier
On first launch the app creates a record for the installation and receives an identifier and a secret. The identifier is a pseudonym: it is not tied to your name, your email address, your Apple ID or your phone number, and on its own it says nothing about who you are. Settings → This device shows it.
The secret is kept in the phone's own secure store - the Keychain on iOS, the Keystore on Android - and never leaves the device. Our server stores only its SHA-256 hash, so a copy of our database holds nothing that could be replayed as your device.
What the app stores on our server
- Platform, app version and operating system version, so we know which build a report comes from and when to suggest an update.
- The language the app runs in, so that what we send back is in it.
- The time zone your phone reports. A daily summary is timed by your local hour, so this is what decides when it would arrive.
- A salted SHA-256 hash of the address the app registered from. The address itself is never written down. The hash does one job: counting how many devices a single address has registered in the past hour, so nobody can fill the table with invented installations.
- Your notification settings: which subjects you switched on (weather warnings, airport wind, trail closures, events), whether you want a daily summary and at which morning hour, and the quiet hours in which nothing but a weather warning or the summary you timed yourself is delivered.
- Your travel dates, if you enter them. The daily summary can be limited to the days you are actually on the island, and that is what the two dates are for. You type them in yourself, they are cleared as soon as you switch the summary off or to every day, and they are used for nothing else.
- The push token, once you allow notifications. It is the address Expo's push service delivers to; it names the installation, not you, and it is cleared when the phone reports the app gone. Next to it we keep a short log of what was sent - the kind of message, what it was about and when - so the same warning is not sent twice.
- Your purchases: a random purchase identifier the server issues to the installation, and for each package you bought the store product, whether it came from the App Store or Google Play, the store's transaction identifier and the dates. No card number, name or billing address ever reaches us - Apple and Google take the payment.
- The date the app last spoke to the server.
Notifications are sent by a job on our server that runs once an hour. It sends only what you switched on in Settings: IPMA weather warnings at orange or red level (pre-selected), rough wind at the airport, trail closures and reopenings, and a daily summary at the hour you chose. The phone asks for the system permission the first time you switch a subject on; until you allow it, nothing is sent. During the quiet hours everything but a weather warning and the summary you timed yourself is held back. The events switch is stored, but no reminder is sent for it yet. Messages travel through Expo's push service, which hands them to Apple or Google; see the list of processors below.
In-app purchases
Four itinerary packages are sold as one-time purchases through the App Store and Google Play; the three-day package is free. To sell without an account, the server gives each installation a random purchase identifier, and the app passes it together with the store's receipt to RevenueCat, which checks the receipt with the store. Our server then asks RevenueCat what the installation owns and records the result: the package, the store product, the store, whether it was a test or a live purchase, the store's transaction identifier and the dates. RevenueCat also notifies our server of later changes, such as a refund, and we keep those notifications.
A purchase belongs to the Apple or Google account it was made with. A reinstall or a new phone is a new installation with no purchases on it; Restore purchases, in the package card and under Settings → Purchases, asks the store for them again.
Usage statistics and crash reports
Only after you explicitly allow usage statistics and error reports, the app sends short usage events to PostHog: the name of a screen or an action (an article opened, a trail filter chosen, a camera started), the app launching or going to the background, and crash reports with the technical trace of the error. Each event carries the phone model, the operating system and app version, the language and the time zone. PostHog discards the address the event came from before storing anything, and derives no location from it. The events are filed under a random identifier that PostHog's library creates on the phone. It is not your name, not the device identifier above and not an advertising identifier, and we never link it to a person.
On iPhone, iOS asks once after the intro with its own tracking dialog: Allow turns usage statistics and error reports on, Ask App Not to Track keeps them off. On Android, one dialog on the home screen offers Allow and Decline. Before consent, the PostHog SDK is not started and no analytics events are collected or sent. The app works the same if you decline. We store your choice, its date and the notice version on your phone. Settings → Privacy → Usage statistics lets you withdraw consent at any time, and on iPhone give it again only while iOS Settings → Privacy & Security → Tracking allows it. Withdrawal stops new collection and blocks pending analytics requests; it does not delete events already received by PostHog. If you opt in again, a new random analytics identifier is created.
Deleting the device does not reach PostHog, which holds the events under its own identifier. Write to info@denis.pt if you want them deleted there as well, and tell us the phone model and the period you used the app, since that identifier is shown nowhere.
Your location
The 3D map has a button that shows where you are. It asks for the location permission while the app is open, draws your position on the map and forgets it when you leave the screen or put the app away. The position is never sent to our server or to anyone else, and nothing stores it.
The legal basis for usage statistics and error reports is your consent (Article 6(1)(a) GDPR). The legal basis for the device record and notifications you switched on is our legitimate interest in running a working app and protecting it from abuse (Article 6(1)(f) GDPR). Travel dates and notification settings are held because you entered them. Purchase records are processed to deliver what you bought (Article 6(1)(b) GDPR).
A device record stays until it is deleted, and deleting it takes one tap. The record of a store transaction is kept after that, under the random purchase identifier only, because it is our record of the sale and of any refund. We have not set a separate retention period at PostHog; the usage events stay there until we delete them.
Deleting the app's data
In the app, Settings → This device → Delete this device removes the device record, its notification settings, the push token, the delivery log and its purchase grants from our server, and drops the credential from the phone's secure store. Nothing is left behind under the old identifier. The next launch registers a new device; a package you bought comes back through Restore purchases, because the store still knows it.
If the app is already off your phone, write to info@denis.pt and we will delete the record. Give us the identifier from Settings → This device if you noted it: the record holds no name, address or email, so without it we cannot tell which row is yours.
Data Sharing and Disclosure
We do not sell your personal data. We may share your information in the following circumstances:
- With service providers who assist us in operating our website and conducting our business
- When required by law or to respond to legal process
- In connection with a business transfer, merger, or acquisition
Who processes data for us
We do not sell data and we do not hand it over for advertising. These companies come into contact with it because they run something we use:
- Vercel Inc. hosts the website and the server the app talks to. Every request passes through it, and its server logs hold the address a request came from for a short time.
- The database, including the device records described above, sits with the managed PostgreSQL provider we rent it from.
- Apple and Google distribute the app through the App Store and Google Play and take the payment for a purchase. Your card details stay with them; we never see them. What either records about a download, an installation or a payment is theirs.
- Expo (650 Industries, Inc.) runs the push service the app registers with. The push token and the text of each notification pass through it on the way to Apple's and Google's notification services.
- RevenueCat, Inc. checks store receipts and keeps the purchase state of each installation under its random purchase identifier. It receives the receipt from the app and tells our server what the installation owns; it does not get your name.
- PostHog Inc. measures how the app is used, on its European cloud. It receives the usage events and crash reports described above, discards the sender's address before storing anything and derives no location from it. Settings → Privacy switches it off.
- Google Analytics measures the website only, and only after you accept cookies. It is not part of the app.
Data Security
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or electronic storage is 100% secure.
Your Rights Under GDPR
If you are located in the European Economic Area (EEA), you have certain data protection rights:
- Right to Access: You have the right to request copies of your personal data.
- Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- Right to Erasure: You have the right to request that we erase your personal data, under certain conditions.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
- Right to Data Portability: You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
- Right to Object: You have the right to object to our processing of your personal data, under certain conditions.
- Right to Withdraw Consent: You have the right to withdraw your consent at any time where we relied on your consent to process your personal data.
Data Retention
We will retain your personal data only for as long as is necessary for the purposes set out in this Privacy Policy, unless a longer retention period is required or permitted by law.
International Data Transfers
Your information may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ. We ensure that appropriate safeguards are in place to protect your data.
Children's Privacy
Neither our website nor our app is aimed at children under the age of 16. The app has a section for parents about places to visit with children; it is written for the adult and collects nothing from a child. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:
Email: info@denis.pt