Privacy Notice
Updated 25 July 2026. This notice describes the actual data flows of the Little Bear Trail digital audio guide.
1. Controller
Korpiretket, Business ID 2501532-1
Myllykoskentie 30
93900 Kuusamo
+358 40 778 7316
timo@pienikarhunkierros.fi
2. Data processed
- Order email address, order date and language.
- Stripe Checkout Session ID, Payment Intent ID, payment status, price, amount and currency returned by Stripe.
- Consent version, time and records of accepting the terms, requesting immediate delivery and acknowledging loss of the withdrawal right.
- Hashed access token and hashed recovery code. The usable access token is stored in the customer's browser as a secure, HttpOnly cookie.
- Order-confirmation delivery status and technical error code, if sending fails.
- Information submitted in withdrawal notices and complaints, their receipt times, language, message-delivery status and technical error code.
- IP address, time, requested URL, browser and device-related technical information in the hosting provider's ordinary web server and security logs.
The guide processes precise location in the customer's browser to identify the nearest guide point. The application does not send or store the precise location or travelled route on Korpiretket's server. Custom usage tracking is disabled. The fonts used by the service are loaded from Korpiretket's own server.
3. Purposes and legal bases
- Contract performance: creating and delivering the order, granting and restoring access, sending the order confirmation and providing customer service.
- Legal obligation: accounting and consumer-law records, including records of the request for immediate delivery and acknowledgement concerning the withdrawal right.
- Legitimate interests: information security, preventing misuse, troubleshooting, and demonstrating the parties' rights and handling legal claims.
4. Recipients and processors
Payment data is processed by Stripe. Website, database, server-log and email infrastructure is provided through the hosting provider Louhi Networks. Data is not sold.
5. Transfers outside the EU or EEA
Stripe may process data outside the EU or EEA. Stripe is responsible for using an applicable legal transfer mechanism, such as an adequacy decision or the European Commission's standard contractual clauses. Their own privacy notices provide further details.
6. Retention
- Access and recovery records are retained while the access right remains active and for a reasonable period needed to resolve related claims.
- Order, payment, consent and accounting records are retained for the period required for contract, consumer-law and statutory accounting purposes. Accounting material is generally retained for six years from the end of the relevant financial year.
- A fixed retention period has not yet been set for withdrawal notices, complaints or customer-service messages. They are currently retained for handling the matter and related legal claims.
- A fixed retention period has not yet been set for email-delivery error data.
- Web server and security logs follow the hosting provider's operational retention and backup cycles. Korpiretket has not independently verified a precise fixed retention period for these logs.
7. Your rights
Subject to the applicable legal requirements, you may request access to or correction or deletion of your personal data, restriction of processing, data portability, and object to processing based on legitimate interests. Where Statutory retention obligations may limit deletion.
Send privacy requests to timo@pienikarhunkierros.fi. You may also lodge a complaint with the Finnish Data Protection Ombudsman.
8. Browser storage
The service uses a secure, HttpOnly access cookie for access and browser local storage for language, progress and offline status. Cache Storage and a Service Worker store selected application resources and content downloaded for offline use. Removing browser data may require access to be restored with the recovery code.