Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Write and publish a privacy policy for https://transitous.org/ routing service #580

Open
Altonss opened this issue Nov 1, 2024 · 3 comments

Comments

@Altonss
Copy link
Contributor

Altonss commented Nov 1, 2024

Personal data gets processed by the transitous.org routing service, and therefor it would be great to write and publish a privacy policy for the service.

@jbruechert
Copy link
Collaborator

Good point, do you think the following suffices?
#582

@Altonss
Copy link
Contributor Author

Altonss commented Nov 3, 2024

Good point, do you think the following suffices? #582

Thanks a lot for the PR, it is a step in the right direction!

I'm not quite sure it is enough as it is right now. Also depending on the jurisdiction transitous is hosted, it might also need an Impressum/legal notice ;)

As for the GDPR compliance of the current policy, I don't think it is compliant. Too much non-necessary data is processed/stored by default, the legitimate interest seems a wrong legal basis to me and consent would be a better/more correct one IMHO (for storing the requested URL/user agent 14 days for example, which should then be opt-in).

@jbruechert
Copy link
Collaborator

jbruechert commented Nov 3, 2024

We had cases of queries crashing the routing engine reproducibly and taking the service down for multiple minutes. I think being able to debug these is necessary to run the service.

Consent doesn't work here, as then it's basically random whether we actually have the necessary information or not.

Currently we don't permanently log the query parameters, but I think the policy should allow temporarily enabling it for this purpose.

I think we can probably reduce the storage duration if that helps.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants