Legal

Amble Privacy Policy

Last updated: August 2026

1. Data controller

The data controller for the Amble social walking app is:

BurmCorp Labs UG (haftungsbeschränkt)
Kollwitzstraße 76
10435 Berlin
Germany

Represented by: Nils Torben Burmeister
Phone: +49 30 20009797
Email: legal@burmcorp.com

Register: Amtsgericht Charlottenburg, HRB 285559 B · VAT ID: DE463621479

Website: https://burmcorp.com · Product: https://burmcorp.com/en/labs/amble

2. Overview

Amble is a social walking application for Apple platforms (and related backend services we operate). This policy explains what personal data we process, for what purposes, legal bases under the EU GDPR (DSGVO), retention, and your rights.

We do not sell your personal data. We do not use walk content or chat for third-party advertising profiles.

3. Categories of data we process

Depending on how you use Amble, we may process:

  • Account data — email address, display name, password hash (if you register with email), Sign in with Apple subject identifier, profile text (bio, prompt, pace, neighbourhood, age if you provide it), optional avatar tint, notification preferences.
  • Walk offers & applications — routes (polyline points), meet points, titles/notes, schedule labels, capacity, access needs, applications and accept/decline decisions, walk lifecycle state (confirmed, walking, ended, cancelled).
  • Communications — chat messages within a walk thread between participants.
  • Live location — approximate coordinates and accuracy you share during an active walk, visible only to that walk’s participants for the duration of the walk; cleared when the walk ends or is cancelled.
  • Safety contact — name and phone number you optionally store for your own safety workflow (used as you configure in the app; not published to other walkers as a public profile field).
  • Ratings & connections — mutual ratings after a walk and “connected” relationships formed after rating.
  • Moderation — reports and blocks you submit about other users.
  • Device & technical data — app version, device type, push tokens if notifications are enabled, IP address and server logs needed to operate and secure the service.
  • Support — content of emails or messages you send to us.

4. Purposes and legal bases

We process data to:

  • provide the social walking service (accounts, discover, apply, walk lifecycle, chat) — Art. 6(1)(b) GDPR;
  • share live location among walk participants when you enable it during a walk — Art. 6(1)(b) and, where required by platform rules, consent for device location access;
  • send transactional notifications you request (e.g. requests, replies, plan updates) — Art. 6(1)(b) or (f) GDPR;
  • ensure security, prevent abuse, enforce community rules, process reports/blocks — Art. 6(1)(f) GDPR;
  • comply with legal obligations — Art. 6(1)(c) GDPR;
  • improve the product in aggregate where compatible with legitimate interests and law — Art. 6(1)(f) GDPR.

Where we rely on consent (e.g. optional push notifications, precise location permission), you may withdraw it at any time in system or app settings without affecting prior lawful processing.

5. Location

Amble may use device location to help you discover nearby walks (if you allow it) and, during an active walk, to share live location with co-participants only.

Live location is stored only for the active walk instance and is deleted when the walk ends or is cancelled. Other participants see coordinates for coordination and safety — not as a permanent public track.

You can deny or revoke location permission in iOS Settings; discovery may fall back to broader filters and live sharing will not work without permission.

6. Chat and profile content

Messages and profile text you enter are stored to provide the service to participants in that walk or to show your public profile to people you interact with on Amble. Do not share illegal content or personal data of third parties without a lawful basis.

7. Sign in with Apple / email authentication

If you use Sign in with Apple, Apple processes authentication under Apple’s terms; we receive a stable subject identifier and, if you share them, email/name to create your Amble account. Email/password accounts store a one-way password hash. Refresh tokens are stored hashed.

8. Push notifications

With your permission, we may send push notifications (requests, chat, plan updates) via Apple Push Notification service. Device tokens are stored to deliver messages. You can disable notifications in system or app settings.

Note: live APNs delivery depends on production configuration; until configured, in-app notifications and the product UI still work over the network.

9. Hosting and processors

We use infrastructure and service providers (hosting, databases, object storage if used, email, error monitoring as configured) as processors under Art. 28 GDPR where they process personal data on our behalf. Where data is transferred outside the EEA, we use appropriate safeguards (e.g. Standard Contractual Clauses) as required.

10. Retention

Account and walk data are kept while your account is active and as needed to provide the service, resolve disputes, and meet legal duties. Soft-deleted accounts are marked deleted and blocked from login; residual data is deleted or anonymised within a reasonable period unless longer retention is required by law or for legal claims. Live location is short-lived (cleared at walk end). Chat and walk history may remain for counterparties where needed for safety or dispute context; contact us for specific erasure requests.

11. Your rights

Under the GDPR you have rights including access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where processing is based on consent. Contact legal@burmcorp.com.

You may also delete your account in the app (You → Delete account) where available.

You may lodge a complaint with a supervisory authority. The competent authority for our company is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
https://www.datenschutz-berlin.de

12. Children

Amble is not directed at children under 16. We do not knowingly create accounts for children under 16. If you believe a child has provided us personal data, contact us and we will take appropriate steps.

13. Website & company policy

For the BurmCorp website and general company processing, see the company privacy policy and imprint.

This Amble policy applies specifically to the Amble social walking application and related product surfaces.

14. Changes

We may update this policy to reflect product or legal changes. The current version is always available at this URL. The date of the last update is noted at the top of this page.

← Amble