This Policy explains who processes data in VOON, why it is processed, which data remains on-device, what reaches VOON servers and how users can exercise their rights.
1. Controller and contact details
1.1. The controller is Rzaev Omar Rzaevich, an individual residing in the Republic of Azerbaijan (“VOON”, “we”, “us”). The channel for legally significant notices, data-subject requests and complaints is voonapp@mail.ru.
2. Scope and principles
2.1. This Policy covers the VOON application, API, accounts, synchronisation, route feed, support and legal pages. It does not govern third-party services opened through external links.
2.2. We process data lawfully, fairly and transparently, for stated purposes, in a proportionate amount and no longer than necessary. We do not sell personal data, use health data for advertising, or disclose it to ad networks or data brokers.
3. Data we process
3.1. Account: email, user ID, sign-in method, language, account/sign-in times and accepted legal-document versions.
3.2. Profile: nickname, avatar, bio, sports and optional Instagram/Telegram handles.
3.3. Activities: time, precise GPS track, distance, duration, speed, pace, altitude, elevation, power, cadence, steps and connected-sensor readings. Heart rate, heart-rate zones, weight, sex, birth date and calories are processed only on-device and are not sent to the Controller (section 5).
3.4. Publications: route title/description, region, sport, surface, difficulty, photos, route geometry, author profile, saves, follows and moderation history.
3.5. Support and security: message content and attachments, IP address, request time, app/OS version, errors and security events.
3.6. Payments: VOON is currently free. If subscriptions are introduced, the payment platform will process payment credentials; VOON may receive product, status, period and transaction identifiers, but not a full card number.
3.7. Sources include the user, device and sensors, Apple Health with OS permission, the sign-in service when the user does not sign in with an email code, and interactions by other users.
4. Purposes and legal bases
4.1. Account creation, security and support. Data: account and technical data. Legal basis: performance of the Terms; legitimate security interests; consent where required.
4.2. Recording, metrics, sync, restore and export. Data: location, activity, sensors and ride files. Legal basis: performance of the Terms; OS permissions.
4.3. Route and profile publication. Data: profile, route, metrics and photos. Legal basis: separate voluntary publication consent.
4.4. Moderation, reports and abuse prevention. Data: content, account and technical events. Legal basis: performance of the Terms; legitimate safety interests; legal obligations.
4.5. Support and compliance. Data: requests, account and audit records. Legal basis: contract/request performance; legal obligations; legal claims.
4.6. An email address is needed to create an account; other data is provided at the user’s choice, and without it only the relevant feature does not work.
5. Health and fitness data
5.1. Heart rate, heart-rate zones, weight, sex, birth date and calculated calories are processed only on the user’s device: the app excludes them from the server copy of an activity, and the Controller neither receives nor stores them. The Controller therefore does not process special categories of personal data concerning health. See the Health Data Notice.
5.2. Workouts and routes imported from Apple Health remain on-device and are not uploaded to VOON, except a route the user chooses to publish in the feed (without heart rate, calories or other workout metrics). Activities moved to a new device from the server copy arrive without calories; if Apple Health holds the same workout, VOON may show the calories from there, on the device only. Apple Health access can be revoked in iOS settings.
6. Location, routes and publications
6.1. Precise location is used to record an activity, including in the background when the screen is locked, if OS permission is granted. Route-planning coordinates may be sent to a routing provider. On the sign-in screen, location is used once to determine the country and show the sign-in methods available there: Apple’s geocoder turns the coordinates into a country code; they are not sent to or stored on VOON’s server. Unpublished activities are not visible to other users. VOON’s server stores the routes of recorded activities but not the user’s current location.
6.2. Publication requires an affirmative action. Before the first publication, VOON displays a separate consent and stores its version and server timestamp. Signed-in VOON users can see the post, and it may also appear in reviews and screenshots of the app in materials about VOON. The feed is not intended for search-engine indexing.
6.3. A route is published in full, with its start and end points, text and photos, so before publishing the user checks that they show only what they are happy to share; the start and end of a route can be trimmed. A post can be hidden or deleted, but VOON cannot recall screenshots or copies other users made earlier.
7. Providers and recipients
7.1. Server-infrastructure and hosting providers that operate VOON.
7.2. The transactional email provider used to deliver sign-in codes and service messages.
7.3. Apple for App Store, maps and HealthKit.
7.4. OpenStreetMap routing, OpenFreeMap, Protomaps and, where selected, MapTiler for maps/routing; they may receive IP address and requested map area/coordinates.
7.5. Authorities or professional advisers when required by law or necessary to protect rights.
7.6. These providers process data under their own terms of use or on the Controller’s behalf, only to the extent needed for the relevant feature.
8. Data storage
8.1. We store data on secured servers and apply the protection measures described in section 10.
9. Retention and deletion
9.1. Accounts, profiles, activities and private routes: while the account exists or until the item is deleted.
9.2. Publications: until unpublished/deleted or the account ends; moderated content may be retained briefly for appeal and repeat-abuse prevention.
9.3. Consent and legal-action records: for the period needed to demonstrate compliance and defend claims.
9.4. Technical logs and backups: for a limited time needed for security and recovery, after which they are overwritten.
9.5. Support requests: until resolution and then for the applicable limitation period.
9.6. Deletion removes data from active systems and backups when they rotate. Longer retention may apply for law, disputes or security investigations. On-device, Apple Health and third-party copies must be deleted separately.
10. Security and incidents
10.1. We apply technical and organisational safeguards, including encryption in transit and access control. No system is absolutely secure. We will contain incidents and notify users and authorities when and within the time required by applicable law.
11. User rights
11.1. Depending on applicable law, users may request information and a copy; correction, deletion, restriction or portability; object; withdraw consent without retroactive effect; request human review of an automated decision; and complain to a regulator.
11.2. Send requests to voonapp@mail.ru. We may reasonably verify identity. We respond free of charge within the period set by applicable law. Server data and the account can also be deleted in the app.
12. Age
12.1. VOON is intended only for people aged 16 or over. We do not knowingly collect data from younger children. If discovered, the account will be restricted and data deleted unless the law requires retention. Parents or guardians may contact us by email.
13. Legal pages, changes and contact
13.1. Legal pages use no advertising or analytics cookies; hosting may retain security logs. We will announce material changes in the app or by email and, where required, ask for renewed consent.
13.2. Questions, requests and complaints: voonapp@mail.ru.