Privacy Policy
Last updated 2026-06-23
Sunspot shows which Helsinki terraces are in the sun right now. We keep the amount of data we process as small as possible. This policy explains what data we process, why, and for how long.
Data controller
RK9 AI Oy
Business ID: 3612536-6
Email: privacy@rk9.fi
What data we process
Location (optional)
If you grant the app location permission, we use your precise location (Precise location, GPS). Location is used only while you are using the app (when-in-use) — we do not collect location in the background, and tracking stops automatically when you close the app or stop using it for a while. We need precise location for three purposes: centering the map on your position, showing and sorting the terraces nearest to you by distance, and checking that you are at a terrace when you confirm its sun status.
Your location largely stays on your device — map centering and distance sorting happen on your device and do not send your coordinates to our servers. The sun calculation is performed for the terraces' locations, not yours. You can revoke location permission at any time in your device or browser settings.
The one exception: when you confirm the sun status at a terrace, your location (coordinates) is sent to the server once to check that you are near the terrace. The server computes your distance to the terrace and stores only the rounded distance in metres — not your coordinates. No coordinate or raw-location history is kept. That rounded distance is stored as part of the sun confirmation and retained with it as part of an anonymous observation dataset (after account deletion, with no link to you).
Push notification identifier (optional)
If you enable notifications (for example by starring a favourite terrace in the native app), we store your device's push identifier (a Firebase Cloud Messaging token) together with the ids of the terraces you favourited. We need these to notify you when the sun reaches one of your favourite terraces. The token does not contain your name, email, or any other directly identifying information.
Transfer to the United States: to deliver push notifications your push token and the notification content (e.g. the terrace name) are processed by Google (Firebase Cloud Messaging, Google LLC), and the data may therefore be transferred to the United States. The transfer is safeguarded by the EU–US Data Privacy Framework (Google LLC is DPF-certified); Google additionally applies the European Commission's Standard Contractual Clauses (SCCs). See the subprocessor list below.
Technical logs
Our servers record standard technical information (such as IP address and browser type) to operate the service, keep it secure, and diagnose faults. These logs are not used for profiling.
Visitor analytics (Plausible)
We measure site traffic with Plausible CE (Community Edition) analytics that we host ourselves on our own EU server (stats.sunspot.fi). Plausible is cookieless: it sets no cookies, stores nothing on your device, collects no personal data, and does not store your IP address. Visitors are counted using a daily-rotating, irreversible hash from which an individual visitor cannot be identified afterwards. The collected data is aggregate statistics (such as page views, referrer, browser type, and country), and it stays on our own servers — it is never sent to third parties.
Because the analytics uses no cookies or other device-storage-based tracking and processes no personal data, this site does not need — and does not show — a cookie consent banner (per the Finnish regulator Traficom's guidance, consent is required for cookie-based or device-storage-based tracking).
In addition, the app sends individual anonymous usage events to our servers (for example a completed signup, home-screen install progress, and the sign-in method used). An event contains only the event type and a coarse device or method bucket — no identifiers, names, or IP addresses — and the data is used only in aggregate to improve the service.
Marketing conversion measurement (Meta Conversions API)
So that we can measure whether our paid Meta ads (Facebook/Instagram) actually lead to new accounts, we send Meta a conversion event from our server when a signed-in user who has consented to this creates an account (and, optionally, when they favourite a terrace or confirm sun). This uses the server-side Meta Conversions API. We do not use a Meta Pixel and we do not use any cookie or device-storage tracking — which is precisely why the site needs no cookie consent banner.
We send Meta only what is needed to match the event: a one-way hash (SHA-256) of your email address — only the email is hashed — together with your IP address and browser User-Agent string sent as-is (un-hashed), the address of the page where the event happened, and — if you arrived from a Meta ad — that ad-click identifier (Meta requires the IP and User-Agent un-hashed as matching keys). We do not send Meta your name, password, location, or favourite terraces. Each event carries a unique id to prevent duplicates.
Legal basis: your explicit consent (GDPR Art. 6(1)(a)). You give a separate, optional consent to marketing measurement — via a pre-unchecked choice when you create your account, or later in your consumer account settings. Events are sent to Meta only if you have given this consent; by default (without consent) nothing is sent to Meta. You can withdraw your consent at any time in your consumer account settings, which stops future events (individual events already sent cannot be recalled). If you have deleted (pseudonymised) your account, no events are sent at all. Meta acts as an independent controller for the data it receives; see the subprocessor list below.
Restaurant owner account
If you register a restaurant account (the owner panel), we process the following personal data: your name, email address, a cryptographic hash of your password, and a link between you and the restaurant you manage. We collect only these — we do not ask for or store any other owner PII (data minimisation). Your email is used to identify the account, verify ownership (a 6-digit code), and reset your password. For an owner account, name, email address, and password are mandatory.
Legal basis: performance of a contract (GDPR Art. 6(1)(b)) — providing the owner account — together with your consent, given by accepting this policy during registration. We record your consent and key data-protection actions (export, deletion) in a minimal audit log for accountability.
Retention: owner account data is kept for as long as the account exists. When you delete your account it is pseudonymised: name, email, and password hash are overwritten and the restaurant link is released. The row is not deleted from the database entirely; instead we retain the account's technical identifier (a randomly generated UUID) so the unique-email index and references to your data stay intact and the deleted identifier cannot be reused. Because the identifier is retained, this is pseudonymisation, not irreversible anonymisation — we do not claim that re-identification is fully prevented; for transparency, pseudonymisation is in principle reversible with administrative database access. In addition we retain a personal-data-free audit log (only the account's technical identifier, action, and timestamp), which is retained for at most 12 months (an automatic sweep deletes rows older than that).
Consumer account
If you create a consumer account in the app (for example to save your favourites or to confirm sun), we process the same personal data types as for an owner account: your email address, a cryptographic hash of your password, and an optional name. For a consumer account, email address and password are mandatory; the name is optional (the location permission is optional too). It is processed under the same legal basis (performance of a contract together with the consent you give at registration) and with the same rights as an owner account.
Retention and deletion: when you delete your consumer account it is pseudonymised in the same way as an owner account (email, name, and password hash are overwritten, favourites and notification preferences are removed, but the account's technical identifier is retained for integrity and abuse-prevention reasons), leaving only a personal-data-free audit log, which is retained for at most 12 months (an automatic sweep deletes rows older than that). You can delete your account yourself directly in the app from your consumer account settings (confirming either by typing DELETE or with your password) or by contacting privacy@rk9.fi. You can also download your data (GDPR Art. 15) as self-service from your consumer account settings (GDPR Art. 17).
Note that the consumer account can involve marketing conversion measurement: if you consent to it, we send Meta a server-side conversion event (account creation, and optionally favouriting a terrace or confirming sun) as described under Marketing conversion measurement (Meta Conversions API) above. No events are sent if you have not consented to measurement (the default), have withdrawn your consent, are signed out, or have deleted your account.
Favourites and settings
Your favourite terraces and language preference are stored primarily on your device (in the browser's localStorage). They are only sent to the server if you enable push notifications (see above).
Subprocessors (data processors)
We do not sell the data we process. For marketing measurement we share with Meta — only with your consent — the hashed identifiers described under Marketing conversion measurement above; Meta acts as an independent controller for them (not a processor acting on our behalf). Otherwise we use a limited set of processors to run the service, who process data only on our behalf and only to deliver the service:
- Amazon SES (AWS) — email delivery (verification codes, password reset). Privacy
- Meta Platforms Ireland Ltd — paid-advertising conversion measurement (Conversions API), an independent controller. We send only the hashed and technical identifiers described above, and only for signed-in accounts that have consented — no Pixel and no cookie. Privacy
- Nominatim / OpenStreetMap — place and address search during registration. Only the search term you type (e.g. a restaurant name) is sent — never your name, email, or location. Privacy
- City of Helsinki (open data) — the sun calculation uses the City of Helsinki 3D city model and the Korkeusmalli elevation model (CC BY 4.0, © City of Helsinki). This is open geodata — no data about you is ever sent to the City of Helsinki. Dataset
- Hetzner Online GmbH — server hosting (EU, Germany). Privacy
- Google Firebase Cloud Messaging (Google LLC, United States) — push notification delivery in the native app. The push token and notification content may be transferred to the United States; safeguard: EU–US Data Privacy Framework (Google LLC DPF-certified); additionally Standard Contractual Clauses (SCCs). Privacy
Retention
The push identifier is kept for as long as notifications are enabled. When you disable notifications or remove the app, the identifier is deleted. Technical logs (such as IP address and browser type) are kept for no more than 30 days, after which they are removed by log rotation.
Your rights
You have the right to request access to your data, its rectification or erasure, and to lodge a complaint with the Finnish Data Protection Ombudsman. We respond to your requests within one month (GDPR Art. 12). You can delete your push identifier by disabling notifications or by contacting privacy@rk9.fi. Favourites and settings stored on your device can be removed by clearing the app's data or your browser's storage.
Deleting your account: you can delete a consumer account yourself directly in the app from your consumer account settings or by contacting privacy@rk9.fi. Restaurant owners can download all their data (GDPR Art. 15) and delete their account (GDPR Art. 17) directly from the Privacy screen in the owner panel or by contacting the same address — access and erasure are available as self-service, with no separate request needed.
Contact
For any privacy questions, contact us at privacy@rk9.fi.