Siirry sisältöön

Privacy Policy

Last updated 1 September 2026

The Finnish version at /tietosuoja is the primary document.

In short

Matkapp has no user accounts, shows no advertising, and uses no analytics or tracking. Favourites, recent searches and settings are stored on your device only. The app fetches routing, timetable and weather data directly from third-party open-data services, which therefore receive technical information about your requests. The app also fetches its own announcements from our server. The only thing the app can store on our server is the optional disruption-alert subscription — and only if you enable it yourself.

Controller

Tunneli Company Oy (business ID 3577165-7)
Tampere, Suomi
Privacy enquiries: atk@tunnelicompany.fi

Stored on your device

Favourite stops and lines, favourite places including home and work, recent searches and journeys, and app settings. This data stays on your device and is never sent to us — except that if you turn on disruption alerts, the ids of the favourite stops you pick are stored on our server (see below). It is removed when you uninstall the app or clear its data.

Location

If you grant location permission, the app uses your location to centre the map and to plan a journey from where you are. Your location is not stored outside the device. Coordinates are sent to the routing service when planning, and coordinates rounded to a coarse grid are sent to the weather service. The app is usable without granting location permission.

Third-party services

The app works by fetching data directly from the services below. They receive your IP address and the content of the request (for example the coordinates or stops requested), subject to their own policies:

Our own server

About once an hour the app fetches a ready-made announcements file from matkapp.tunnelicompany.fi, containing the app’s own announcements (for example, news of a new version). The request carries no identifiers, favourites, searches or location — as with opening any web page, the server receives your IP address and the technical details of the request. The app sends nothing to the server to be stored — the one exception is the optional disruption-alert subscription described below. Dismissing an announcement is saved on your device only.

What the app does not do

Push notifications for disruptions

Disruption alerts are opt-in and off by default. If you enable them in the app’s settings, our server stores your device’s push token, the identifiers of the favourite stops you chose, and the time of consent — nothing else. The token is not linked to a name or any other data. The subscription is deleted from the server as soon as you turn the alerts off, and automatically if the app has not contacted the server for 180 days.

Notifications are delivered to your device via Google’s Firebase Cloud Messaging (FCM). Google acts as a data processor in this role: it receives the push token and the notification content (the disruption bulletin’s title and text). Google may transfer data outside the EU/EEA; the transfer is based on the European Commission’s adequacy decision (the EU–U.S. Data Privacy Framework) and Google’s data-processing terms.

Your rights

If you have not enabled disruption alerts, the app sends nothing to our server to be stored, so we hold no records about you to disclose or erase. If you have enabled them, the server holds the subscription described above, and you can erase it directly from the app by turning the alerts off — which also withdraws your consent. Everything the app stores on the device is removed by uninstalling it or clearing its data in your device settings. The third-party services listed above are governed by their own privacy policies. For any privacy matter you can always contact the address above.

Changes

When this policy changes we update the date above.