Privacy Policy
Last updated 2026-07-26
Sunspot shows which Helsinki terraces are in the sun right now. We keep the amount of data we process as small as possible. This policy explains what data we process, why, and for how long.
Data controller
RK9 AI Oy
Business ID: 3612536-6
Email: privacy@rk9.fi
What data we process
Location (optional)
If you grant the app location permission, we use your precise location (Precise location, GPS). Location is used only while you are using the app (when-in-use) — we do not collect location in the background, and tracking stops automatically when you close the app or stop using it for a while. We need precise location for three purposes: centering the map on your position, showing and sorting the terraces nearest to you by distance, and checking that you are at a terrace when you confirm its sun status.
Your location largely stays on your device — map centering and distance sorting happen on your device and do not send your coordinates to our servers. The sun calculation is performed for the terraces' locations, not yours. You can revoke location permission at any time in your device or browser settings.
The one exception: when you confirm the sun status at a terrace, your location (coordinates) is sent to the server once to check that you are near the terrace. The server computes your distance to the terrace and stores only the rounded distance in metres — not your coordinates. No coordinate or raw-location history is kept. That rounded distance is stored as part of the sun confirmation and retained with it as part of an anonymous observation dataset (after account deletion, with no link to you).
Push notification identifier (optional)
If you enable notifications (for example by starring a favourite terrace in the native app), we store your device's push identifier (a Firebase Cloud Messaging token) together with the ids of the terraces you favourited. We need these to notify you when the sun reaches one of your favourite terraces. The token does not contain your name, email, or any other directly identifying information.
Transfer to the United States: to deliver push notifications your push token and the notification content (e.g. the terrace name) are processed by Google (Firebase Cloud Messaging, Google LLC), and the data may therefore be transferred to the United States. The transfer is safeguarded by the EU–US Data Privacy Framework (Google LLC is DPF-certified); Google additionally applies the European Commission's Standard Contractual Clauses (SCCs). See the subprocessor list below.
Device id
Your browser or the app stores a random, non-personal device id on your device. It lets us tie favourites, push registration, sun confirmations and star ratings made without an account to the same device, and limits abuse (for example repeated confirmations from the same device). The identifier does not contain your name, email, or any other directly identifying information — it is a technical identifier, not personal data by itself. If you create an account, your device's earlier anonymous rows are linked to it on login; deleting the account removes that link, but the device rows themselves remain (see the Play Store "Device IDs" data safety declaration). You can reset your device id by clearing your browser's or the app's storage.
Technical logs
Our servers record standard technical information (such as IP address and browser type) to operate the service, keep it secure, and diagnose faults. These logs are not used for profiling.
Customer support (AI-assisted)
When you email our support address (hei@sunspot.fi), your message is processed with AI assistance: we use Anthropic's Claude model, via our own Paperclip platform, to read your message and draft a reply. A human reviews and approves every outgoing reply before it is sent to you — the AI never sends a reply directly without human approval.
The content of your email otherwise stays in the EU: we use Amazon SES in the EU region (Stockholm, eu-north-1) to deliver messages, and our Paperclip platform, which handles the support message, runs on a server located in Finland. To draft the reply, your message content is sent to Anthropic (see the subprocessor list below); under our data processing agreement (DPA) with Anthropic, data sent via the API is not used to train their models.
Legal basis: legitimate interest (GDPR Art. 6(1)(f)) — responding to support requests efficiently and quickly — balanced against your privacy; because a human approves every reply, the AI does not make decisions about you autonomously.
Phone support (AI-assisted)
When you call our customer service number, an AI assistant answers. We tell you this in the very first sentence of the call (EU AI Act, Article 50). You can ask for a human to contact you at any point.
No audio is retained. The AI writes a text summary of your matter as a support ticket: the name and phone number you give (if any), a description of your issue, and the time of the call. The summary is handled on the same Paperclip platform as our email support, and a human approves every reply sent to you.
The call is carried by Twilio, and speech understanding and responses are provided by xAI's Grok Voice (see subprocessors). Call summaries are kept for at most 30 days, after which the content and phone number are deleted; only a timestamp and the record that the AI disclosure was played remain (legal evidence obligation).
Legal basis: legitimate interest (GDPR Art. 6(1)(f)) — to receive and handle customer service requests by phone. The AI does not make decisions about you on its own.
Callback requested from the website
If you leave your number on the "Ask us by phone" form, we contact you on the number you gave. You choose on the form whether an AI assistant or a person calls — if you choose a person, no automated call is placed at all and your request goes to a member of our support team.
The legal basis here is your consent (GDPR Art. 6(1)(a) and the Finnish Act on Electronic Communications Services, s. 200) — we never call anyone who has not asked us to. We store the time of consent, the number you gave and the version of the consent text so that we can show what you agreed to. Those are kept for 12 months; the other form fields (name, topic) are deleted within 30 days like all other call data. You can withdraw your consent at any time by contacting us.
Visitor analytics (Plausible)
We measure site traffic with Plausible CE (Community Edition) analytics that we host ourselves on our own EU server (stats.rk9.fi). Plausible is cookieless: it sets no cookies, stores nothing on your device, collects no personal data, and does not store your IP address. Visitors are counted using a daily-rotating, irreversible hash from which an individual visitor cannot be identified afterwards. The collected data is aggregate statistics (such as page views, referrer, browser type, and country), and it stays on our own servers — it is never sent to third parties.
Because the analytics uses no cookies or other device-storage-based tracking and processes no personal data, this site does not need — and does not show — a cookie consent banner (per the Finnish regulator Traficom's guidance, consent is required for cookie-based or device-storage-based tracking).
In addition, the app sends individual anonymous usage events to our servers (for example a completed signup, home-screen install progress, and the sign-in method used). An event contains only the event type and a coarse device or method bucket — no identifiers, names, or IP addresses — and the data is used only in aggregate to improve the service.
Marketing conversion measurement (Meta Conversions API)
So that we can measure whether our paid Meta ads (Facebook/Instagram) actually lead to new accounts, we send Meta a conversion event from our server when a signed-in user who has consented to this creates an account (and, optionally, when they favourite a terrace or confirm sun). This uses the server-side Meta Conversions API. We do not use a Meta Pixel and we do not use any cookie or device-storage tracking — which is precisely why the site needs no cookie consent banner.
We send Meta only what is needed to match the event: a one-way hash (SHA-256) of your email address — only the email is hashed — together with your IP address and browser User-Agent string sent as-is (un-hashed), the address of the page where the event happened, and — if you arrived from a Meta ad — that ad-click identifier (Meta requires the IP and User-Agent un-hashed as matching keys). We do not send Meta your name, password, location, or favourite terraces. Each event carries a unique id to prevent duplicates.
Legal basis: your explicit consent (GDPR Art. 6(1)(a)). You give a separate, optional consent to marketing measurement — via a pre-unchecked choice when you create your account, or later in your consumer account settings. Events are sent to Meta only if you have given this consent; by default (without consent) nothing is sent to Meta. You can withdraw your consent at any time in your consumer account settings, which stops future events (individual events already sent cannot be recalled). If you have deleted (pseudonymised) your account, no events are sent at all. Meta acts as an independent controller for the data it receives; see the subprocessor list below.
Restaurant owner account
If you register a restaurant account (the owner panel), we process the following personal data: your name, email address, a cryptographic hash of your password, and a link between you and the restaurant you manage. We collect only these — we do not ask for or store any other owner PII (data minimisation). Your email is used to identify the account, verify ownership (a 6-digit code), and reset your password. For an owner account, name, email address, and password are mandatory.
Legal basis: performance of a contract (GDPR Art. 6(1)(b)) — providing the owner account — together with your consent, given by accepting this policy during registration. We record your consent and key data-protection actions (export, deletion) in a minimal audit log for accountability.
Retention: owner account data is kept for as long as the account exists. When you delete your account it is pseudonymised: name, email, and password hash are overwritten and the restaurant link is released. The row is not deleted from the database entirely; instead we retain the account's technical identifier (a randomly generated UUID) so the unique-email index and references to your data stay intact and the deleted identifier cannot be reused. Because the identifier is retained, this is pseudonymisation, not irreversible anonymisation — we do not claim that re-identification is fully prevented; for transparency, pseudonymisation is in principle reversible with administrative database access. In addition we retain a personal-data-free audit log (only the account's technical identifier, action, and timestamp), which is retained for at most 12 months (an automatic sweep deletes rows older than that).
Consumer account
If you create a consumer account in the app (for example to save your favourites or to confirm sun), we process the same personal data types as for an owner account: your email address, a cryptographic hash of your password, and an optional name. For a consumer account, email address and password are mandatory; the name is optional (the location permission is optional too). It is processed under the same legal basis (performance of a contract together with the consent you give at registration) and with the same rights as an owner account.
Retention and deletion: when you delete your consumer account it is pseudonymised in the same way as an owner account (email, name, and password hash are overwritten, favourites and notification preferences are removed, but the account's technical identifier is retained for integrity and abuse-prevention reasons), leaving only a personal-data-free audit log, which is retained for at most 12 months (an automatic sweep deletes rows older than that). You can delete your account yourself directly in the app from your consumer account settings (confirming either by typing DELETE or with your password) or by contacting privacy@rk9.fi. You can also download your data (GDPR Art. 15) as self-service from your consumer account settings (GDPR Art. 17).
Note that the consumer account can involve marketing conversion measurement: if you consent to it, we send Meta a server-side conversion event (account creation, and optionally favouriting a terrace or confirming sun) as described under Marketing conversion measurement (Meta Conversions API) above. No events are sent if you have not consented to measurement (the default), have withdrawn your consent, are signed out, or have deleted your account.
Favourites and settings
Your favourite terraces and language preference are stored primarily on your device (in the browser's localStorage). They are only sent to the server if you enable push notifications (see above).
Subprocessors (data processors)
We do not sell the data we process. For marketing measurement we share with Meta — only with your consent — the hashed identifiers described under Marketing conversion measurement above; Meta acts as an independent controller for them (not a processor acting on our behalf). Otherwise we use a limited set of processors to run the service, who process data only on our behalf and only to deliver the service:
- Amazon SES (AWS) — email delivery (verification codes, password reset, customer support messages). Processed in the EU region (eu-north-1, Stockholm). Privacy
- Anthropic PBC (AI service, United States) — AI-assisted reading and reply drafting for your customer support emails via our Paperclip platform; a human reviews and approves every outgoing reply. Under our data processing agreement (DPA), data sent via the API is not used to train their models. Transfer outside the EU is safeguarded by Standard Contractual Clauses (SCC, Art. 46.2.c). Privacy
- xAI Corp. (AI service, United States) — speech understanding and responses for phone support (Grok Voice) and drafting the text summary of the call. Transfer outside the EU is safeguarded by Standard Contractual Clauses (SCC, Art. 46.2.c). Privacy
- Twilio Inc. (telephony, United States) — carrying calls to our customer service number (your phone number and call metadata). Transfer outside the EU is safeguarded by Standard Contractual Clauses (SCC, Art. 46.2.c). Privacy
- Meta Platforms Ireland Ltd — paid-advertising conversion measurement (Conversions API), an independent controller. We send only the hashed and technical identifiers described above, and only for signed-in accounts that have consented — no Pixel and no cookie. Privacy
- Nominatim / OpenStreetMap — place and address search during registration. Only the search term you type (e.g. a restaurant name) is sent — never your name, email, or location. Privacy
- City of Helsinki (open data) — the sun calculation uses the City of Helsinki 3D city model and the Korkeusmalli elevation model (CC BY 4.0, © City of Helsinki). This is open geodata — no data about you is ever sent to the City of Helsinki. Dataset
- Finnish Meteorological Institute (open data) — the sun-status calculation uses FMI's cloud-cover forecast (CC BY 4.0, © Finnish Meteorological Institute). Open weather data — nothing about you is sent to FMI. Dataset
- MET Norway — short-range cloud nowcast complementing the FMI data. Open weather data — nothing about you is sent to MET Norway. Terms
- Hetzner Online GmbH — server hosting (EU, Germany). Privacy
- Google Firebase Cloud Messaging (Google LLC, United States) — push notification delivery in the native app. The push token and notification content may be transferred to the United States; safeguard: EU–US Data Privacy Framework (Google LLC DPF-certified); additionally Standard Contractual Clauses (SCCs). Privacy
Retention
The push identifier is kept for as long as notifications are enabled. When you disable notifications or remove the app, the identifier is deleted. Technical logs (such as IP address and browser type) are kept for no more than 30 days, after which they are removed by log rotation. Phone-support text summaries are kept for no more than 30 days; after that the content and phone number are deleted and only a timestamp and the record of the AI disclosure remain.
Your rights
You have the right to request access to your data, its rectification or erasure, and to lodge a complaint with the Finnish Data Protection Ombudsman. We respond to your requests within one month (GDPR Art. 12). You can delete your push identifier by disabling notifications or by contacting privacy@rk9.fi. Favourites and settings stored on your device can be removed by clearing the app's data or your browser's storage.
Deleting your account: you can delete a consumer account yourself directly in the app from your consumer account settings or by contacting privacy@rk9.fi. Restaurant owners can download all their data (GDPR Art. 15) and delete their account (GDPR Art. 17) directly from the Privacy screen in the owner panel or by contacting the same address — access and erasure are available as self-service, with no separate request needed.
Contact
For any privacy questions, contact us at privacy@rk9.fi.