Privacy at Signavo
Signavo tells you when to get ready. To do that, we need to know who you follow, and we need to be able to reach your phone. Here is exactly what we store, where it lives, for how long, and what happens when you stop.
There are no ads in Signavo, no tracking, no analytics, and we sell nothing on. That is not a statement of intent — the app talks only to our own server, our database and Expo's update service. The one exception is the timing system's sign-in page, and only if you choose to link your account there (see "Linking your account in the timing system").
Who is responsible
Chris Kalmar, Kringelhusvej 6, 7100 Vejle, Denmark. Write to hej@signavo.dk with questions, access requests or deletion.
Your account
You sign in with your email address and a one-time code we send you. There is no password to forget and none to steal. We store your email address, a user id and when the account was created. Not your phone number, and not your name unless you choose to link your account in the timing system (see below).
What you follow
When you tap Follow me, we create one follow per start. For each of them we store on our server:
- which class and which start on the organiser's start list it is
- a key to your phone so the message can find you (see "Notifications")
- when you opened up for messages — either by tapping the button or by arriving at the showground
- your own choices: when you want the warm-up nudge, whether you follow as the rider or as a helper, and which language the messages should be in
When you follow someone else
If you follow your child, someone you are helping, or someone you just want to watch, we store that rider's name. The name is already on the show's public start list — but it is still information about another person, and that is why it is written here.
We use it for one thing: to phrase your messages correctly ("Malene is up next" rather than "You're up next"). We do not write to the rider, we do not build a profile on her, and her name does not leave our own systems. Delete the follow or your account and the name goes with it.
Notifications
Messages are delivered through Apple's push service (APNs). For that we use a key your phone gives us — a long random string that can only be used to send messages to that one app on that one phone. The lock-screen panel that counts down while you wait has its own key of the same kind.
We keep a log of which messages were sent to which follow and when, and whether they arrived. Without it the question "did I get that message?" cannot be answered — and that is precisely the question that matters on the day something goes wrong. The log is deleted automatically after 90 days.
An older part of our server can send through the ntfy.sh service instead. The app does not use it — it always chooses Apple — but the option exists in the code, and if it were used, the message title and text would pass through ntfy.sh's servers. We name it here rather than pretend it isn't there.
What we measure during the closed beta
Signavo is in closed beta. We have had very few users, and we have a couple of decisions to make about what to build on next. So during this period we store four more things about your account. They are written here so that you can read them rather than discover them.
- Whether an Apple Watch is paired with your phone, and whether Signavo is installed on it. Two yes/no answers. If the phone cannot answer, the fields stay empty. We ask your phone, not the watch, and we ask when notifications are switched on for a start, including when the app does it for you because you have arrived at the venue. We do not get the watch's name, its serial number, or anything about what else you use it for. The watch does read your heart rate while you ride, and saves the round to Health on the watch. That belongs to the watch app, not to this measurement, and neither the heart rate nor the round is ever sent to our server.
- When we measured it. A timestamp, set by our server. Without it, an answer from last season would count as if it were from today, and the number would mean nothing.
- Where your invitation came from. A short word, for example
klubormalene, which we ourselves put into the link we ourselves sent you. The app reads the word from the link and passes it on to us as it stands. It says where we found you, not who you are. It can only be written to your account while you are signed in, and only once: the first word to arrive is the one that stays. We do not check that the word is genuine. We lowercase it and require it to have the right form, so it is an indication of where you came from and not a proof. If you arrived without such a link, the field stays empty.
The word from the link sits on your phone from the moment you open the link until there is an account to write it to. It stays in the app afterwards, but both signing out and deleting your account clear it from the phone. If you do neither, it stays until you delete the app.
Why we do this at all: we need to know whether building further on the watch makes sense before we spend a season on it. And we need to see whether the answers come from a wide circle or from our own friends, because otherwise we are only measuring ourselves.
This does not change the sentence at the top of this page. There is still no tracking and no analytics in Signavo. These four things sit in our own database at Supabase, exactly like the rest of your account — see the processors listed below. They go to no analytics company, they do not follow you into other apps or out onto the web, and we build no profile on you. They are four fields on your account, not a measurement tool.
They belong to the account and go with it. Delete your account and they are deleted along with everything else, as described under "When you delete your account".
The fields were made for the beta period. If they outlive it, this section stays with them, and the date at the bottom says when the text was last changed.
Your results
Once you have gone, we pick up the result from the organiser's timing system and store it so your history is there afterwards: show, class, horse, faults, time, percentage and placing. These are the same figures that appear on the show's public result list.
Showgrounds and notes
You can favourite a show, save a private note about a venue, and you can help correct a venue's position on the map if it is wrong. The note is yours alone. The position, on the other hand, stays as shared knowledge if you delete your account — but your name is removed from it, so nobody can see who set it.
Your address and your location
You can enter your home address so the app can work out when to leave. It is optional, and the app works without it.
- The address stays on your phone. We do not store it in the database.
- To find the coordinates we send the address as text, through our own server, on to OpenStreetMap's address service (Nominatim). It is the single heaviest lookup in the app, which is why it is here and not in a footnote. We do not store the answer on the server.
- To work out the driving time we send two sets of coordinates only — your home and the showground — to the routing engine OSRM. No address, no name, no user id. The answer is cached for 24 hours at Cloudflare's edge, keyed on the coordinate pair, so we do not ask twice for the same journey.
If you turn on arrival by GPS, your phone draws an invisible 400-metre circle around the showground and tells the app when you drive into it. The app then opens up for queue messages by itself, so you don't have to remember to tap. It is iOS that watches — we do not receive your location, neither continuously nor on arrival. The only thing stored is a date on your phone, so you are not welcomed twice on the same day. You can turn it off again in Settings or in iOS.
Where the start lists come from
Start lists, classes, times and results come from the organiser's timing system, the same one the show office types into. We send nothing about you to the organiser or to the system behind it; if you link your account there yourself, we use your key to fetch your name and nothing else, we never write (see the next section). We read the same public start list that is pinned to the wall in the show office.
Signavo is a product of its own and is not made by the company behind the timing system.
Linking your account in the timing system
You can link your account with the timing system to Signavo, so the app knows who you are there. It is optional, and the app works without it.
How it works: your phone opens the provider's own sign-in page in a browser, and you sign in with them, not with us. We never see your password there. The provider sends a one-time code back to our server, which exchanges it for access keys and fetches your name, if the provider gives us one. We ask for read access only, never write access, and not your email. Signavo can therefore never change anything on your account there.
On your Signavo account we store your user id with the provider, your name there, the status of the link and when it was made. The access keys are stored encrypted at Cloudflare, separately from the database, and they are not shared with anyone but the provider itself; the app does not see them.
You unlink in Settings. We then revoke the keys with the provider and delete them, and the four fields are cleared. If you delete your account, the same happens automatically.
What your phone stores
Some things live only on your phone and never reach our database:
- who you follow, with the rider's and horse's name, class and times
- your home address and its coordinates
- your settings, your language choice and your sign-in key
- a temporary copy of the show list, so the app can show something with no signal
If you delete your account or sign out, the phone's own copy is cleared with it.
How long we keep things
| What | How long |
|---|---|
| The message log | 90 days, then deleted automatically |
| Follows after the show has ended | 30 days |
| Share links | 30 days after they expire |
| Account, results, saved rider names, favourites, notes | Until you delete your account |
| The beta measurements: watch, measurement time and invite source | Until you delete your account |
| The link to the timing system, access keys included | Until you unlink or delete your account |
| Backups | Nightly copy, the oldest kept up to six months |
When you delete your account
You delete the account in the app under Settings. That removes in one go: your profile, the rider names you have saved, your follows, the message log, your results, your favourites, your venue notes, your start-list watches, the beta measurements and the link to the timing system, access keys included.
Two things deliberately remain:
- Venue positions you have corrected or submitted. They are shared knowledge, and the next show at that place should not sit in the wrong spot on the map again. Your name is taken off, so the correction cannot be traced back to you.
- The waiting list. If you signed up for news, that is a separate consent with its own unsubscribe button. Deleting an account is not an unsubscribe, and we will not remove a record you did not ask to lose. The unsubscribe link is at the bottom of every email.
A backup made before the deletion may still contain your information for up to six months. The copies are not rewritten, but they are deleted automatically.
The waiting list
If you signed up on signavo.dk or signavo.app, we store your email address, the language you signed up in, and when. If you answered the question about which showgrounds you ride at, we store that answer too; it is optional. Nothing else. We process it because you gave your consent by signing up and confirming in the email. You unsubscribe with the link at the bottom of every email we send, or by writing to hej@signavo.dk; we then delete the address and the answer. We keep that the unsubscribe happened, and when, so it can be shown.
Our legal basis
- To keep our agreement with you (GDPR art. 6(1)(b)): account, follows, messages, result history. That is what you ask for when you tap Follow me.
- Because you said yes (art. 6(1)(a)): notifications, arrival by GPS, the link to the timing system and the waiting-list emails. You can withdraw each of them separately without the rest stopping.
- Because we have a legitimate interest in the service working (art. 6(1)(f)): operational logs, backups and abuse protection.
We make no automated decisions about you, and we do no profiling.
Who else sees it
We sell, share or rent nothing. These providers process information on our behalf:
| Provider | Role | What they see |
|---|---|---|
| Supabase | Database and sign-in (EU) | Everything under "Your account" and below |
| Cloudflare | Server, website, backups and the encrypted store for the link's access keys | The traffic to our server, the backup files, and the access keys in encrypted form |
| Apple (APNs) | Delivers the messages to your iPhone | The key to your phone, and the message content |
| Resend | Sends our emails | Your email address |
| Proton | Our mailbox, hej@signavo.dk (Switzerland) | What you write to us yourself, and your sender address |
| OpenStreetMap / Nominatim | Looks up your address | The address as text — only when you save it |
| OSRM | Works out driving time | Two sets of coordinates. No name, no id |
| ntfy.sh | Older message channel, the app does not use it | Would see the message text if it were used |
| Expo | Delivers updates to the app | That your phone asked for an update |
| healthchecks.io | Watches that our nightly job ran | Nothing about you. Only that the job ran |
Supabase runs in the EU. Proton is in Switzerland, whose level of protection the European Commission has approved (adequacy decision). The others are global services and may process data outside the EU/EEA; that happens under the European Commission's standard contractual clauses.
Your rights
You can request access to what we hold about you, have it corrected, deleted, or handed over in a machine-readable format, and you can object to our processing. Write to hej@signavo.dk. If you have an account, you can delete everything yourself from the app straight away.
Deletion applies to the live database. Backups are deleted automatically, see above.
If you are unhappy with how we handle your information, you can complain to the Danish Data Protection Agency, datatilsynet.dk.
Children
Signavo is made for riders, parents and helpers. If you are under 13, a parent must create the account and consent on your behalf. We do not ask for your age, and we do not knowingly collect information from children who have created an account themselves — but if we find out, we delete the account.
Cookies
The app uses no cookies. This page sets no cookies and uses no tracking or analytics.
When this text changes
If we change something material, we say so in the app before the change takes effect. The date below is the only truth about which version you are reading.
Last updated: 18 September 2026