Last updated 30 August 2026. Effective 30 August 2026.
The short version. Nayge is free and has no accounts, no ads and no trackers of our own. Your saved resorts, units, riding window and alerts are stored on your device and nowhere else. Your location is used on your device to sort the list of nearby resorts and is never transmitted to us. The one thing to know is that the map component we license from Mapbox collects data for its own purposes, which section 8 sets out in full along with how to switch it off. The rest of this document is the detail.
Nayge is an iOS app published and operated by Amber Turrentine, an individual ("we", "us", "our"). There is no company behind Nayge, no trade name and no legal entity of any kind. It is one person, which is a large part of why this policy is able to say what it says. The app is built by Sky Turrentine, and mail sent to the address below is read and answered on Amber Turrentine's behalf.
For the purposes of the EU and UK General Data Protection Regulation, Amber Turrentine is the controller of the limited personal data described in this policy.
| Detail | Value |
|---|---|
| Controller | Amber Turrentine, an individual |
| sky@nayge.com | |
| Website | nayge.com |
A postal address and telephone number are available on request to sky@nayge.com.
Representatives in the EU and UK. We are established in the United States and have not designated a representative under Article 27 of the EU GDPR or Article 27 of the UK GDPR. We rely on the exemption in Article 27(2)(a): our processing of personal data relating to individuals in the European Union and the United Kingdom is occasional, is limited to connection metadata and to messages individuals choose to send us, involves no special categories of data and no large-scale monitoring, and is unlikely to result in a risk to their rights and freedoms. We will designate representatives if that ceases to be the case. Inquiries from individuals and from supervisory authorities go directly to sky@nayge.com and are answered by us.
We have not appointed a Data Protection Officer. Article 37 of the GDPR does not require one here, because our core activities do not consist of large-scale regular and systematic monitoring of data subjects or large-scale processing of special categories of data. All privacy inquiries go to sky@nayge.com.
This policy covers the Nayge iOS app and the website at nayge.com (together, the "Service").
Where this policy says "the app" it means the iOS app specifically, and "the Service" means the app and the website together.
It does not cover any third-party service you reach from the Service, including Apple Maps, Google Maps, a resort's own website, or the App Store. Once you leave, that provider's own policy applies.
This policy forms part of the Terms of Use.
Nayge has no user accounts, no login, no registration and no server-side user records. We do not create, assign or store any identifier for you. We operate no database of users, because there are no users to put in one.
The overwhelming majority of what Nayge holds about you is stored only on your device, under your own control, and is deleted when you delete the app.
The personal data that is processed off your device is limited to:
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act as amended. We have never done either. We serve no advertising and operate no advertising relationships.
We do not track you across apps or websites as that term is used in Apple's App Tracking Transparency framework. The app does not request tracking permission and contains no code capable of it.
For the avoidance of doubt, the Service does not collect, request or process any of the following:
The Service requests access to your device location under iOS's "While Using the App" authorization only. Our own code does not request, and cannot obtain, "Always" authorization or background location access, and uses neither significant-location-change monitoring nor region monitoring. The embedded Mapbox Maps SDK runs its own location handling; see section 8. Because the app holds only "While Using the App" authorization and declares no background location mode, neither can reach your location while the app is closed.
How the app uses it. The app asks iOS for a single fix at only kilometer-level accuracy, rather than the finest the device can produce. iOS may still supply a sharper one. Whatever arrives is held in volatile memory for the lifetime of the app session, is used to sort the on-device list of resorts by distance and to set the initial map camera position, and is then discarded. It is not written to persistent storage on your device, and it is not transmitted to us or to any third party by our code. The permission itself is requested once, during the introduction; a fix is requested each time you open the app.
How weather is requested. All forecast requests are made for the published coordinates of resorts, not for your position. Our weather proxy independently enforces this: it accepts only coordinates present on a fixed allowlist of ski-area points and rejects anything else.
Legal basis. Consent, given through the iOS location permission prompt (GDPR Article 6(1)(a)). You may withdraw it at any time in iOS Settings > Privacy & Security > Location Services > Nayge. The Service remains functional without it; you search for resorts manually instead.
Two disclosures we consider material.
Under the California Consumer Privacy Act, precise geolocation is "sensitive personal information". We do not collect it. Our own code uses your location only on your device, for the purposes described above, and neither transmits nor stores it. The embedded Mapbox Maps SDK does collect precise and coarse location for Mapbox's own purposes, as described in section 8. Because that collection is made by a third-party component we bundle, it is disclosed in our App Store privacy label even though we never receive it. We do not use, retain, disclose, sell or share precise geolocation for any purpose.
The following is written to app storage on your device using iOS's standard preferences and cache mechanisms. It is not transmitted to us, is not synchronized between your devices, and is deleted when you delete the app.
| Category | Contents |
|---|---|
| Saved resorts | Identifier, name and the resort's coordinates for each one you save |
| Recently viewed | Identifiers of the last ten resorts whose detail page you opened, from anywhere in the app |
| Resorts you have looked at | For each resort the app has produced a rating for, the resort's identifier and its time zone, so the app can tell whether that mountain is inside its posted hours without asking again |
| Resort operating status | For resorts that publish a report, the last status and posted lift hours we retrieved |
| Resort requests | The search term for each resort you asked us to add, retained so you are not prompted to request the same one twice |
| Alerts | Alert definitions, including any name you type, the resorts and conditions selected, and the delivery times chosen |
| Preferences | Units, riding window, clock format, map projection, sort order and comparison metric. Your choice of app icon is stored by iOS, not by us |
| Onboarding state | Whether the introduction has been shown |
| Legal acceptance | Which version of these documents you accepted, and the date you accepted it, so we can tell you when they change |
| Diagnostic counters | Aggregate counts of forecast requests made. These contain no identifier, are not displayed anywhere, and are never transmitted |
| Caches | Forecast responses, computed ratings, resort report bodies, the resort reference dataset and map images. Webcam images are held in memory only and are never written to disk |
| Past weather for resorts you have opened | The hours that have already happened at a resort you looked at, kept so the surface model can see the freeze-thaw cycle behind today rather than starting cold. It is weather at a mountain, not anything about you. Keyed by the resort's tier, coordinates and elevation, capped at 500 resorts, and deleted after 14 days |
| Mapbox's own storage | The Mapbox Maps SDK maintains map-data and telemetry-queue databases, and stores identifiers of its own, inside the app's storage. See section 8 |
A disclosure about cache file names. Cached map images are stored under filenames carrying the resort's internal identifier and its coordinates in readable form. A party with file-level access to your unlocked device could therefore work out which resorts you have viewed. Cached forecasts and ratings are stored under one-way hashed filenames that reveal nothing by themselves, although their contents identify the resort. These files sit in the operating system's cache directory, may be purged by iOS at any time, and are pruned by the app after 24 hours for forecasts and reports, 48 hours for ratings, and 30 days for map images. The past-weather store sits outside the cache directory, is excluded from device backup, and is pruned after 14 days. The resort reference dataset is refreshed daily but is kept until you delete the app.
If you back up your device to iCloud or to a computer, Apple's backup may include app preference data. That processing is governed by Apple's privacy policy.
Every service the app contacts necessarily observes your device's IP address and the default network user-agent string generated by iOS, which identifies the app, its build number and the operating-system build it is running on. That is a property of making an HTTPS request rather than something we add, with one deliberate exception: requests to resorts identify Nayge explicitly, described in section 7.5.
Forecast requests are routed through a service we operate on Cloudflare Workers. Requests contain resort coordinates, requested weather variables, and a shared app token common to every installation. They contain no user identifier and no user location.
Forecast data originates from Open-Meteo, used under the Creative Commons Attribution 4.0 license. Open-Meteo receives requests from our proxy only, and receives no personal data relating to you.
Mapbox provides the interactive map and the static map images on resort cards. Mapbox receives your IP address, the map area requested, and our public access token. The embedded Mapbox Maps SDK additionally collects the data described in section 8.
Map data is © Mapbox and © OpenStreetMap contributors. Your use of the map is also governed by Mapbox's own terms, its privacy policy and its data processing agreement. Mapbox states that it holds the IP address it receives for 30 days, that it does not associate an IP address with geolocation data, and that the link between a session identifier and location is broken within 24 hours.
The app downloads a public dataset of the world's ski areas from OpenSkiMap, normally at most once per day. The request contains no personal data beyond the connection metadata described above.
Where a resort has given written permission, the app retrieves that resort's own conditions report, its current webcam image, or both, directly from servers the resort or its provider operates. These requests carry a user-agent identifying Nayge and our contact email address, so that a resort can identify and contact us. They carry no data about you beyond connection metadata.
Past webcam frames come from us, not from the resort. Two of the resorts we carry overwrite a single image file in place and publish no history, so the timeline you can scrub through would not otherwise exist. Our Cloudflare service copies those cameras' frames every ten minutes into storage we operate, keeps them for 24 hours and then deletes them automatically. When you scrub back through a camera's day, the app is asking our service for those stored frames rather than the resort's server, so the service observes your IP address for those requests in the same way, and on the same terms, as section 7.1 describes for forecasts. The frames themselves are photographs of a mountain: they contain nothing about you, they are keyed by the time the camera captured them, and nothing links a frame to the person who asked for it. Whakapapa publishes its own history, so nothing of theirs is copied.
These are two different forms and they ask for different things. Both are optional and both are read by one person.
In the app. If you submit feedback, request a resort, or report a data correction, the app transmits: the category selected, the type of submission, a generated subject line, the free-text message you wrote, the app version, whatever you chose to put in the optional contact field, and a shared key identifying our account to the relay. For a data correction it also sends the resort's name, identifier and coordinates; for a resort request, the search term you typed.
The form in the app has one optional contact field and asks for nothing else that could identify you. There is no name field, and it transmits no device identifier, no device model and no location. The contact field accepts an email address or any other handle you would rather be reached on, it may be left empty, and we use what you put there for one purpose, which is to reply to you. We do not add it to a mailing list, build a profile from it, or disclose it to anyone beyond the relay described below. Left empty, a submission reaches us pseudonymously unless you choose to include identifying information in your message.
On the website. The contact form at nayge.com asks for your name, your email address and your message, and all three are required to send it. We ask for them for one reason, which is to be able to reply to you, and we use them for nothing else: no mailing list, no marketing, no profile, and no disclosure to anyone beyond the relay below. The form sets no cookie, and the website runs no analytics and no advertising of any kind. If you would rather not give us a name and an email address, write to sky@nayge.com directly, or use the form in the app, which asks for no name at all and leaves the contact field entirely up to you.
Both forms are transmitted to and processed by Web3Forms, a third-party form relay service, which forwards them to our email inbox. According to Web3Forms' own published policy, it retains submission content for a limited period, maintains server logs including the submitting IP address, and may pass the IP address and any email address to anti-spam services such as CleanTalk or Akismet. Their policy, not ours, governs what they do with it; read it at web3forms.com/privacy.
Legal basis. Performance of a request you initiate and our legitimate interest in receiving, understanding and acting on feedback about the Service (GDPR Articles 6(1)(b) and 6(1)(f)).
We do not obtain personal data about you from any third party, from a data broker, or from any publicly accessible source, so the notification duty in Article 14 of the GDPR does not arise in the ordinary course. If a message someone sends us happens to contain a third party's personal data, contrary to our Terms of Use, notifying that person would involve disproportionate effort within the meaning of Article 14(5)(b), because we hold no means of contacting them. We delete such content when we identify it.
| Recipient | Role | Location | Data received |
|---|---|---|---|
| Cloudflare, Inc. | Processor: hosting and caching of the weather proxy | United States, global edge network | IP address, request metadata |
| Web3Forms | Processor: relay of the app's feedback form and the website's contact form to email | United States | Free-text submission, IP address, the optional contact you gave in the app's form, and from the website form your name and email address |
| Mapbox, Inc. | Supplier of map tiles, and independent controller for its own telemetry | United States | IP address, map area, and see section 8 |
| Apple Inc. | Independent controller | Global | App distribution, on-device notification delivery, optional device backup, governed by Apple's own privacy policy |
Cloudflare and Web3Forms process personal data on our instructions as processors. Mapbox and Apple determine their own purposes for the data described above and act as independent controllers in respect of it; their own policies govern that processing and we have no access to it.
We may disclose information where we reasonably believe it is necessary to comply with applicable law, regulation, legal process or an enforceable governmental request; to enforce our Terms of Use; to detect, prevent or address fraud, security or technical issues; or to protect against harm to the rights, property or safety of any person as required or permitted by law. Given how little we hold, there is in practice very little that could be produced in response to such a request.
If the Nayge business is acquired or transferred, or if we form a legal entity to operate it, information may be transferred as part of that transaction, subject to this policy and with notice given in the app.
Every third party named in section 7.7, and Mapbox as described in section 8, is bound either by a written agreement with us or by its own published terms and privacy commitments to provide the same or an equal level of protection for user data as is stated in this policy and as required by the App Store Review Guidelines. We do not share user data with any third party that does not. None of them is permitted to use data received through the Service for its own advertising, for cross-context behavioral advertising, or to sell it, and we authorize no onward disclosure except as described in this policy.
Email correspondence. If you email us, our email provider processes that message. We retain correspondence only as long as needed to deal with your enquiry and any follow-up, and delete it on request.
The app embeds the Mapbox Maps SDK for iOS. Apple requires developers to disclose data collected by third-party components they bundle, and we do so here in full.
What Mapbox's privacy manifests declare. The SDK ships two manifests. The maps manifest declares three collected types: a user identifier (Apple's "User ID" category), precise location and coarse location. The companion library's manifest declares those three plus product interaction, other usage data, performance data and other diagnostic data. Every one is marked not linked to your identity and not used for tracking, and each is declared for the purposes of application functionality and analytics. The manifests also record that the SDK reads and writes iOS preferences, which is where your telemetry choice is stored.
What the SDK actually sends, which is a separate fact. Alongside the declared categories, the map-load event carries Apple's Identifier for Vendor, your device model, operating system version, screen scale, text-size setting, device orientation and whether you are on Wi-Fi. The Identifier for Vendor is scoped to apps from the same developer on your device and resets when you delete them all; it is not an advertising identifier and cannot be used to follow you into other companies' apps. The SDK also generates identifiers of its own and stores them in the app's preferences. These fields are sent each time a map loads, alongside a separate monthly-active-user event, and the SDK runs its own telemetry service independently of both.
Collection is enabled by default by the SDK. We receive none of this data, have no access to it, and derive no analytics from it.
How to opt out. Mapbox requires every app using its maps to expose a telemetry opt-out. In Nayge it is reached by tapping the information control on the map, choosing Mapbox Telemetry in the Powered by Mapbox sheet, and then Stop Participating. The setting persists across sessions.
Legal basis. Our basis for including a map at all is our legitimate interest in providing the core function of the Service (GDPR Article 6(1)(f)). Mapbox acts as an independent controller in respect of its own telemetry, determines its own purposes for it, and is responsible for establishing a basis for that processing; see Mapbox's privacy policy. We state plainly that the SDK's collection is on unless you turn it off, and we do not present the absence of an opt-out as your consent.
The only third-party software embedded in the app is the Mapbox Maps SDK and its companion libraries. There is no analytics SDK of our own, no crash-reporting SDK, no advertising SDK and no attribution SDK.
Notifications are composed and scheduled entirely on your device using Apple's local notification framework. The app does not register for remote push notifications, no push token is generated for your device, and we operate no notification server. We therefore cannot send you a notification and hold no record of any notification you have received.
The permission requested is for alerts, sounds and badges. Nothing else is asked for, and no critical or time-sensitive alert entitlement is used.
Legal basis. Consent, given through the iOS notification permission prompt (GDPR Article 6(1)(a)), withdrawable at any time in iOS Settings.
| Processing | Legal basis |
|---|---|
| Device location, used on-device | Consent, Art. 6(1)(a) |
| Composing and scheduling notifications on your device | Consent, Art. 6(1)(a), given through the iOS notification permission prompt and withdrawable in iOS Settings |
| Including a map in the Service | Legitimate interests, Art. 6(1)(f). Mapbox's own telemetry is Mapbox's processing as an independent controller; you can switch it off in the map's information control |
| Serving forecast requests and preventing abuse of our proxy (IP address) | Legitimate interests, Art. 6(1)(f): operating and securing the Service |
| Receiving and acting on feedback | Art. 6(1)(b) and legitimate interests, Art. 6(1)(f) |
| Responding to your email | Art. 6(1)(b) and legitimate interests, Art. 6(1)(f) |
| Complying with legal obligations | Art. 6(1)(c) |
Where we rely on legitimate interests, we have considered the impact on you and concluded it is minimal: the data is limited to connection metadata, is retained briefly, is not combined with anything else, and is not used to identify or profile you.
Whether you have to provide anything. You are under no statutory or contractual obligation to provide us with any personal data, and none of it is necessary in order to enter into a contract with us. Providing your location is entirely optional, and Nayge remains fully functional without it. Submitting feedback is optional, and the only consequence of not submitting it is that we do not receive it. The one thing that cannot be avoided is your IP address being observed by the services the app contacts, which is a property of connecting to the internet rather than a requirement we impose. There is no data you must give us in order to use Nayge.
| Data | Retention |
|---|---|
| Everything stored on your device | Until you delete it in the app or delete the app. Caches self-prune after 24 hours (forecasts and resort reports), 48 hours (ratings) or 30 days (map images). The resort reference dataset is refreshed daily but kept until you delete the app |
| Rate-limiting counters | Rolling 60-second windows; not retained |
| Cloudflare request logs | Set by our plan, never more than 7 days, then expired automatically |
| Cached forecast data (keyed by resort, contains nothing about you) | Reused for 30 minutes, deleted after 24 hours |
| Archived webcam frames on our service (photographs of a mountain, contain nothing about you) | 24 hours, then deleted automatically |
| Past weather on your device for resorts you have opened | 14 days, or sooner once 500 resorts have accumulated |
| Aggregate request counters (no identifier) | Retained for cost monitoring |
| Feedback and contact-form submissions held by Web3Forms | Up to 30 days, per that provider's policy |
| Feedback and email in our inbox | As long as needed to handle the matter, then deleted on request |
We are established in the United States. Our processors listed in section 7.7 are predominantly United States companies operating global infrastructure. If you use the Service from outside the United States, the limited personal data described in this policy will be processed in the United States and in other countries where those processors operate.
Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, it is transferred to the United States. The European Commission has adopted an adequacy decision for the United States limited to organizations certified under the EU-US Data Privacy Framework; where a recipient we use is so certified, we rely on that decision together with its UK Extension and Swiss Extension. Where a recipient is not certified, we rely on the European Commission's Standard Contractual Clauses and, for the United Kingdom, the International Data Transfer Addendum, as implemented by that recipient.
You may obtain a copy of the safeguards relied on for any of these transfers, free of charge, by emailing sky@nayge.com. We will send you the relevant Standard Contractual Clauses, or a link to the recipient's published copy, and tell you which mechanism applies to which recipient.
Subject to the conditions and exceptions in applicable law, you have the right to request access to your personal data; rectification of inaccurate data; erasure; restriction of processing; data portability; to object to processing carried out on the basis of legitimate interests; and to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Location, notification and Mapbox telemetry consents are withdrawn directly in iOS Settings and in the map's information control, and take effect immediately.
An honest limitation. We hold almost nothing that is identifiable to you. We operate no account system and no user database, so in most cases we are unable to locate any data relating to you. GDPR Article 11 applies here: where we cannot identify a data subject, we are not obliged to acquire additional information in order to do so. Where that is the case we will tell you so rather than simply not respond, and you are entitled to provide additional information that would let us identify any data relating to you, which we will then act on. If you have emailed us or submitted feedback containing identifying information, we can and will locate and delete that on request. Everything else is on your device, where you can delete it yourself by deleting the app.
To exercise a right, email sky@nayge.com. We will respond within one month, which may be extended by two further months for complex requests, and we will tell you if we extend it. There is no charge unless a request is manifestly unfounded or excessive.
Right to complain. You may lodge a complaint with your national supervisory authority. In the United Kingdom this is the Information Commissioner's Office (ico.org.uk). In the EEA, a list is maintained at edpb.europa.eu. We would appreciate the chance to address your concern first.
We may not meet the applicability thresholds of the California Consumer Privacy Act as amended by the California Privacy Rights Act. We describe our practices in its terms below and honor its rights regardless of whether it applies to us.
Categories of personal information. In the last twelve months, the following categories as defined in Cal. Civ. Code § 1798.140(v) have been involved:
| Category | Collected? | Source | Purpose | Disclosed for a business purpose to |
|---|---|---|---|---|
| Identifiers (IP address) | Yes, by our processors as an inherent property of a network request | Your device | Operating and securing the Service | Cloudflare, Web3Forms, Mapbox |
| Identifiers (a user identifier, and Apple's Identifier for Vendor) | Not by us. Collected by the bundled Mapbox SDK | Your device | Mapbox's application functionality and analytics | Mapbox |
| Internet or other electronic network activity | No | |||
| Precise geolocation (sensitive personal information) | Not by us. Used on your device only, never transmitted or stored by us. Collected by the bundled Mapbox SDK for Mapbox's own purposes | Your device | Sorting nearby resorts; Mapbox's own purposes | Mapbox |
| Other user content (free-text feedback) | Only if you submit it | You | Responding to and acting on feedback | Web3Forms |
| Identifiers (your name and email address) | Only if you use the contact form on nayge.com, fill in the optional contact field in the app's form, or write either into a message | You | Replying to you, and nothing else | Web3Forms |
| Commercial information, biometric information, professional or education information, audio, visual, olfactory or similar information, inferences | No |
We do not sell personal information and we do not share it for cross-context behavioral advertising, and we have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of consumers under 16 years of age.
Sensitive personal information. We do not use or disclose sensitive personal information for purposes other than those permitted by Cal. Civ. Code § 1798.121(a).
Your rights, to the extent they apply: to know, to access, to delete, to correct, to opt out of sale or sharing (we conduct neither), to limit the use of sensitive personal information (we do not use it beyond permitted purposes), and to be free from retaliation for exercising any of them. Exercise any of these at sky@nayge.com. We will verify your request by corresponding with you at the address you contact us from; because we hold no account records, we may be unable to match a request to any data, and will tell you so. An authorized agent may submit a request on your behalf with written proof of authorization.
Do Not Track, and opt-out preference signals. These are two different things and we answer both. California Business and Professions Code section 22575(b)(5) requires us to state how we respond to a browser "Do Not Track" signal: we do not track consumers across third-party websites or apps over time, so we have no such tracking to switch off, and we do not respond to Do Not Track signals. Separately, the California Consumer Privacy Act's opt-out preference signal, including Global Privacy Control, applies to the sale or sharing of personal information and to cross-context behavioral advertising. We do none of those, so there is no processing of ours for such a signal to stop. We do not disregard the signal; there is nothing for it to apply to. We do not permit third parties to collect personally identifiable information about your activity across different sites through the Service.
These disclosures are required of any commercial online service that collects personal information from California residents, with no size threshold, and they apply to us regardless of section 13.2's first paragraph.
The categories of personal information collected and the categories of third parties it may be disclosed to are in the table in section 13.2. The effective date of this policy is at the top. How we notify you of material changes is in section 17. Our response to Do Not Track signals, and whether third parties may collect information about your activity across sites through the Service, are immediately above.
Reviewing and changing your information. Almost everything Nayge holds is on your own device, where you can review and change it directly: saved resorts, alerts and preferences are all editable inside the app. The list of recently viewed resorts is not separately editable; it holds ten at most and each one falls off as newer ones arrive. Deleting the app removes all of it. We maintain no other record for you to review, because we operate no account system. If you have sent us feedback or email containing personal information, email sky@nayge.com and we will tell you what we hold, correct it, or delete it.
Residents of states with comprehensive privacy legislation, including Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia, have rights broadly corresponding to those above, including to confirm processing and obtain access, to correct, to delete, to obtain a portable copy, and to opt out of targeted advertising, sale and profiling. We conduct no targeted advertising, no sale and no profiling. We honor equivalent requests regardless of your state of residence, subject to the same practical limitation described in section 13.1: we generally hold nothing identifiable to you.
Sensitive data. Several of these laws treat precise geolocation as sensitive data requiring your consent before processing. Our own code processes your location only on your device and never transmits it. Third-party collection by the Mapbox Maps SDK, which can include location, is described in section 8 along with how to switch it off.
Appeals. If we refuse a request, we will tell you why in writing. You may appeal by replying to that message, or by emailing sky@nayge.com with "Appeal" in the subject line. We will respond in writing within 45 days, or within 60 days where the law that applies to you allows, explaining the reasons for our decision. If we deny the appeal we will give you a way to contact your state Attorney General to submit a complaint.
The Service is not directed to children, is not designed to attract them, and is not intended for use by anyone under 13 years of age. If you are in the United Kingdom or the European Economic Area and your country sets a higher age of consent for information society services under GDPR Article 8, that age applies to you.
Riders under 18. Nayge is likely to be used by riders under 18, and it is built accordingly: there is no account, no profile and no behavioral record; nothing is personalized, ranked or recommended using your data; there is no advertising, no in-app purchase and no messaging; location is requested at coarse accuracy, used only on your device, and the app works fully if you decline it. We use no design technique intended to encourage you to give up a privacy protection.
We do not knowingly collect personal data from a child under 13. Given the design of the Service, there is in practice almost nothing to collect from anyone. If you believe a child has provided us with personal data, contact sky@nayge.com and we will delete it.
We use HTTPS with current transport security for all network connections made by the app; iOS App Transport Security is enforced with no exceptions configured. API credentials are held server-side where possible rather than embedded in the app, which is the principal reason forecast requests are routed through our own proxy.
The most substantial protection here is architectural: we hold no user accounts, no credentials and no central store of user data, so there is no repository of personal data to compromise.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Where a personal data breach occurs and applicable law requires it, we will notify the relevant supervisory authority and affected individuals within the periods the law prescribes.
Nayge is distributed through the App Store. Apple's collection and use of information in connection with the App Store, app distribution, device backup and the delivery of notifications by the operating system is governed by Apple's own privacy policy and is not covered here.
App Analytics. Apple provides us with aggregate App Analytics for the app, including counts of impressions, product page views, downloads, installations, deletions, sessions, active devices, crashes and retention, broken down by territory, device type, operating system version and acquisition source. Apple compiles these from devices whose owners have enabled "Share With App Developers" in iOS Settings, aggregates them before making them available to us, and provides us with no individual-level record and no identifier for you. We do not combine App Analytics with anything else, and we cannot use it to identify you or to determine which resorts you have viewed. You may disable the underlying sharing in iOS Settings, under Privacy & Security, Analytics & Improvements.
We may update this policy. The current version, with its date, is always available inside the app under Account > SUPPORT > Privacy Policy and at nayge.com/privacy.
We review this policy at least once every twelve months and update the date at the top whether or not anything has changed.
If we make a material change, in particular one that expands the categories of personal data collected or the purposes for which it is used, we will give notice within the app before or when the change takes effect, and where the law requires it we will obtain your consent. Continuing to use the Service after a change takes effect means you accept the updated policy.
Questions, requests, complaints or corrections:
Amber Turrentine sky@nayge.com