Privacy notice — DaytripTracker
Last updated: 2026-09-20 · Version 1.1
This notice explains how personal data is processed when you use DaytripTracker, either as a participant of a trip or event, or as an organiser working for an organisation. Placeholders in double curly braces (for example the organisation that invited you) are filled in by the organisation and the platform operator before this notice is published.
1. Who is responsible for your data
DaytripTracker is a tool that organisations use to organise trips and events and to keep track of who is present. Two parties are involved:
- The organisation that invited you to its trip or event,
the organisation that invited you, decides why and how your data is used. Under the General Data Protection Regulation (GDPR) it is the data controller for everything that concerns the trip: your name, your check-in, messages, and, where you enable it, your location. Contact:the contact address of the organisation. - The platform operator,
Level IT up,`, hosts and maintains DaytripTracker on behalf of the organisation. It acts as **data processor** for the trip data and only processes it on the organisation's instructions, under a written data processing agreement. Contact:hello@levelitup.be`.
For a limited set of data the operator acts as an independent controller: the account data of organisers (registration, login, security), the technical logs needed to keep the platform secure, and the data exchanged directly with the operator (for example a support request).
If you have a question about your data, contact the organisation first. The operator will help the organisation to answer you and will forward any request it receives directly.
2. Who this notice applies to
- Participants: people taking part in a trip or event. A participant does not need an account. The organisation registers a name and the number of people travelling under that name and hands out an identifier code (for example
TRP7K2-A4X9) and a QR code. Participants can be adults or children; see section 10 for what applies to children. - Organisers: people with an account inside an organisation who create events, check participants in, send messages and respond to emergencies.
- Visitors of the public website (landing page, install page, this notice).
3. What data we process and why
3.1 Participants
What the organisation registers about you:
- Your name and the number of people registered under your name (party size).
- Your identifier code and QR code. The code is random and not linked to any other identity. It is not a password: anyone who sees the code can see the trip information, so treat it like a ticket.
- Optionally, your email address and phone number, if the organisation chooses to record them (for example to email you your code).
- Your preferred language.
What the app records when you use it:
- The fact that you linked a device to your code (date and time), the device platform (iOS, Android or web) and a random device identifier, so the organisation can send you messages and you can see your trip on that device.
- A push notification token issued by Apple, Google or your browser, if you allow notifications.
- Your check-in: when you were checked in, by which organiser, how (app QR, printed QR or manually), how many people of your party were present, and per transport (for example "Bus 2") whether you were on board.
- Which messages from the organisation were delivered to you and when you opened them.
- Whether you switched live location sharing on or off, and when.
- Location updates (latitude, longitude, accuracy, time), only while location sharing is on or an emergency is active.
- Emergency alerts you raise: the time, your location at that moment and afterwards while the emergency is active, the text you type, and the replies from organisers.
What the organisation may record about you without you seeing it:
- Internal notes written by organisers (for example "needs to sit at the front of the bus", "picked up by parent at 16:00"). Notes are only visible to the organisation's own staff. You can ask the organisation what notes exist about you (see section 8).
Purposes and legal bases:
- Organising the trip, showing you the programme, meeting point and transports, and registering your presence for headcounts and safety: necessary for the organisation to perform its agreement with you or with the person who registered you (Article 6(1)(b) GDPR), and, where there is no such agreement, the organisation's legitimate interest in running the trip safely and knowing who is present (Article 6(1)(f) GDPR). Schools and other public bodies may instead rely on their public task (Article 6(1)(e) GDPR).
- Sending you messages and push notifications about the trip: same bases as above. Notifications can be switched off in your device settings at any time; you will still see the messages in the app.
- Live location sharing: only with your consent (Article 6(1)(a) GDPR). It is switched off by default. It only works while the event is running (from the start of the first day until one hour after the end of the last day, in the event's time zone); outside that window the platform refuses location updates even if the switch is on. You can switch it off at any time in the app; from that moment no new locations are sent, and locations already sent are deleted automatically 24 hours after the event ends. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
- Emergency: when you press the emergency button, your location is sent to the organisation for as long as the emergency is active, even if location sharing is switched off. This processing protects your vital interests and those of other participants (Article 6(1)(d) GDPR) and supports the organisation's duty of care (Article 6(1)(f) GDPR). Location streaming stops automatically when you cancel the emergency or an organiser marks it as resolved. If you describe your situation in the emergency text, you decide yourself what you share; health details are never required.
- Internal notes: the organisation's legitimate interest in organising the trip and caring for participants (Article 6(1)(f) GDPR).
- Keeping the platform secure and keeping an audit trail of sensitive actions (check-ins, exports, deletions, emergency actions): legitimate interest of the organisation and the operator (Article 6(1)(f) GDPR).
3.2 Organisers
- Account data: name, email address, phone number (optional), password (stored only as a salted hash), role in the organisation, language preference, alarm-sound preference.
- Security data: email verification status, last login time, number of failed logins, temporary lockout, IP address in the audit log, devices and app sessions linked to your account (device name, platform, token hash, push token).
- Your activity in the platform: events you create, participants you add or check in, messages and notes you write, emergencies you acknowledge or resolve. This activity is recorded in the audit log of your organisation.
- Your contact details shown to participants: when you are assigned to an event as organiser, your name, email address and phone number are shown to the participants of that event so that they can reach you during the trip. This is based on the organisation's legitimate interest in giving participants a way to contact the staff responsible for them (Article 6(1)(f) GDPR). The organisation can switch this off per organiser and per event ("show contact to participants"). Speak to your organisation if you do not want your details shown.
Legal bases: performing the agreement between the organisation and the operator and giving you access to the service (Article 6(1)(b) GDPR); the legitimate interest of the organisation and the operator in securing the platform, preventing abuse and keeping an audit trail (Article 6(1)(f) GDPR); the organisation's obligations as an employer or towards its volunteers.
3.3 Website visitors
The public pages use only a technical session cookie (see section 11). We do not use analytics, advertising or tracking cookies, and we do not profile visitors. Web server logs (IP address, requested page, time, browser type) are kept for security purposes for a short period on the basis of the operator's legitimate interest (Article 6(1)(f) GDPR).
4. Who receives your data
- Organisers of your organisation. Trip data is visible to the organisers assigned to that specific event and to the administrators of the organisation. Internal notes are never shown to participants. Live locations are only shown to organisers of the event and only while sharing is on or an emergency is active. Emergency alerts are sent to the organisers assigned to the event and to the administrators of the organisation so that someone can respond quickly.
- Other participants never see your data. The participant app shows only your own data, the event programme, messages and the contact details of the organisers.
- The platform operator (
Level IT up), as processor, and its hosting provider` located inEuropean Economic Area`. Data is stored in the European Economic Area (EEA) unless stated otherwise here. - Push notification services: to deliver notifications to your device we use Firebase Cloud Messaging (Google Ireland Ltd / Google LLC) for Android and iOS apps (Apple Push Notification service, Apple Inc., is reached through Firebase), and your browser's push service for the web app. These services receive a device token and the notification content. Message notifications contain the title and text of the organisation's message; emergency notifications to organisers contain the participant's name and the event name. Google and Apple may process this data in the United States. Both are certified under the EU-US Data Privacy Framework, and transfers are additionally covered by the European Commission's Standard Contractual Clauses.
- Email provider
mail.motovation.be: to send account emails, participant codes (when the organisation chooses to email them) and emergency alert emails to organisers. - Map tiles: maps in the app and on the website are drawn using tiles from OpenStreetMap (OpenStreetMap Foundation, United Kingdom) unless the operator hosts its own tile server. When a map is displayed, your device requests the tiles directly, which reveals your IP address and the area of the map you look at to the tile server. The United Kingdom benefits from an EU adequacy decision. No location you share is ever sent to the tile server; only the map area displayed on your screen is.
- Navigation apps: the "Navigate" button opens Google Maps or Apple Maps on your device with the meeting point coordinates. That happens on your device and is governed by the privacy notice of the app you open.
- Authorities: where the organisation or the operator is legally obliged to disclose data, or to protect the vital interests of a person in an emergency (for example passing a location to emergency services).
We never sell personal data and never use it for advertising.
5. How long we keep your data
Retention is automated. The platform runs a scheduled retention task that applies the following periods:
- Live locations shared with the location toggle: deleted 24 hours after the end date of the event.
- Participant data (name, email, phone, device links, notes about you): anonymised
30days after the end date of the event (the platform default is 30 days; the organisation can set a different period). After anonymisation, only a numbered record with check-in counts remains, so the organisation can still know how many people were present but no longer who. - Emergency records: the text and timeline are kept with the participant record until anonymisation; the locations sent during an emergency and the location attached to the emergency are deleted 30 days after the emergency is resolved, and in any case when your record is anonymised.
- Messages sent by the organisation: kept with the event.
- Audit log entries: 365 days.
- Device sessions and tokens: participant device links expire after 120 days and organiser app sessions after 90 days; expired and revoked tokens are deleted. Email verification and password reset links expire within hours.
- Organiser accounts: for as long as the account exists. When the organisation removes a member, the account is deactivated and all its access tokens are revoked; the account data is deleted when the organisation is deleted.
- Organisation data: until the organisation deletes its account, after which all its data is deleted from the live database. Backups are overwritten within
30days.
You can shorten these periods yourself: unlink your device in the app at any time, or ask the organisation to erase your record (section 8).
6. How we protect your data
- All traffic between your device and the platform is encrypted (HTTPS).
- Passwords are stored as salted hashes (Argon2). Access tokens and email links are stored only as cryptographic hashes.
- Participant codes are random and long enough not to be guessable; requests are rate limited and repeated failed logins lock an account temporarily.
- Every request is checked against the organisation and event it belongs to. Participants can only ever see their own record.
- Precise locations are never written to server logs.
- Sensitive actions (login, check-in, exports, deletions, emergency handling) are recorded in an audit log that the organisation can review.
- Data is deleted automatically at the end of the retention periods above.
- Only strictly necessary cookies are used, with the
Secure,HttpOnlyandSameSiteattributes.
7. Where your data is stored
The platform is hosted in European Economic Area. Where a recipient outside the EEA is involved (push notification services, see section 4), we rely on an adequacy decision of the European Commission or on the Standard Contractual Clauses, and we send only the minimum needed to deliver the notification.
8. Your rights
Under the GDPR you have the right to:
- Access the data held about you and receive a copy.
- Rectify inaccurate data (for example a misspelled name).
- Erase your data ("right to be forgotten"), unless the organisation must keep it for a legal reason.
- Restrict processing while a question about your data is being resolved.
- Data portability: receive the data you provided in a machine-readable format.
- Object to processing based on legitimate interest, including internal notes and audit records, on grounds relating to your particular situation.
- Withdraw consent for live location sharing at any time, with immediate effect for the future.
- Lodge a complaint with a supervisory authority (section 9).
How to exercise them:
- In the app, participants can download all data held about them ("Export my data" in settings) and unlink their device ("Unlink this device"), which stops all messages and location sharing immediately.
- Participants can ask the organisation to correct or erase their record; organisation administrators and lead organisers have an "erase participant" function that removes the name, contact details, device links, locations, message receipts, emergency texts and notes at once, and an "export participant data" function to answer access requests.
- Organisers can edit their own profile and ask their organisation administrator to remove their account.
- Organisation administrators can export all of the organisation's data and delete the organisation.
- For anything else, write to
the contact address of the organisation(organisation) orhello@levelitup.be(operator). To protect your data we will ask you to prove who you are; for participants, giving your identifier code together with the name registered on the trip is normally sufficient. We answer within one month; in complex cases this can be extended by two months, and we will tell you if that is the case. Exercising your rights is free of charge.
9. Complaints and supervisory authorities
You can always contact us first, but you also have the right to complain to a data protection authority, in particular in the country where you live:
- Belgium: Gegevensbeschermingsautoriteit / Autorité de protection des données (GBA/APD), Drukpersstraat 35, 1000 Brussels, contact@apd-gba.be, www.gegevensbeschermingsautoriteit.be / www.autoriteprotectiondonnees.be
- Netherlands: Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, www.autoriteitpersoonsgegevens.nl
- Germany: the data protection authority of your federal state (Landesbeauftragte:r für den Datenschutz) or the Federal Commissioner (BfDI), Graurheindorfer Str. 153, 53117 Bonn, www.bfdi.bund.de
- France: Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr
10. Children
Trips are often organised for children and young people. The following applies:
- The organisation registers children in the same way as adults: name and party size. The organisation, not the child, decides to use DaytripTracker and is responsible for informing parents or guardians. The organisation will normally provide this notice to parents as part of the trip information.
- Location sharing requires consent. Where the participant is a child below the age at which they can consent themselves in their country (13 years in Belgium, 15 in France, 16 in the Netherlands and Germany), the consent must be given or authorised by a parent or guardian. Organisations must obtain that consent before asking a child to switch location sharing on, and the app reminds participants of this next to the toggle.
- The emergency button works for everyone, regardless of age, because it protects the child's vital interests. Organisations are asked to explain the button to children and to their parents.
- Parents or guardians may exercise the rights in section 8 on behalf of their child. Please contact the organisation.
11. Cookies and local storage
The website uses only strictly necessary cookies, which do not require consent:
session: a signed session cookie that keeps you logged in as an organiser, stores the security token that protects forms (CSRF token) and remembers the language you selected. It is deleted when you close the browser or after 12 hours of inactivity.remember_token(only if you tick "remember me" at login): keeps you logged in on this browser for a longer period.
The mobile app and the installable web app store on your device: your chosen role, your access token, a random device identifier, your language, the trip information you last received (so the app works offline), any check-ins, locations or emergency messages waiting to be sent while you are offline, and your notification token. This data stays on your device and is removed when you unlink your device, log out, or uninstall the app. No analytics or advertising trackers are used. Full details are in the cookie inventory available from the operator.
12. Automated decision-making
DaytripTracker does not make automated decisions with legal or similarly significant effects on you and does not profile you.
13. Changes to this notice
We may update this notice when the platform or the law changes. The date and version at the top tell you when it was last changed. Material changes are announced in the app and on the website. The organisation is responsible for informing its participants about changes that affect them.
14. Contact
- Organisation (controller):
the organisation that invited you,the contact address of the organisation - Platform operator (processor):
Level IT up,`,hello@levelitup.be` - Data protection officer, where appointed: ``