At Loca, security and privacy are built into the architecture of the service. This page explains how your data is protected and which infrastructure providers are involved.
Loca runs on infrastructure providers who hold their own independently audited certifications: Cloudflare (SOC 2 Type II, ISO 27001), Supabase (SOC 2 Type II, ISO 27001), and Anthropic (SOC 2 Type II, ISO 27001) — each reassessed annually by an accredited third party. Loca inherits the security of this underlying infrastructure, though that is not the same as Loca Guide itself holding a certification.
If your organisation requires a signed compliance attestation directly from Loca Guide, contact privacy@loca-guide.com to discuss what's possible.
All data transmitted between your device and Loca is protected using HTTPS (TLS). Database content is encrypted at rest. No queries or responses are transmitted in plain text.
Loca creates a random browser identifier to apply fair daily usage limits and prevent abuse. It contains no personal information and is not linked to your device or stored in our venue database.
If you enable GPS, your coordinates are used only to sort nearby results by distance during your request. They are not stored in the database. You can decline GPS access at any time through your browser settings.
| Data type | Retention |
|---|---|
| Anonymous session logs | Up to 60 days, for reliability and abuse prevention |
| GPS coordinates | Not stored — used only during the request |
| Anonymous browser ID | The raw ID lives in browser storage only. The server never receives or stores the raw value — only a one-way SHA-256 hash of it, used for the usage counters below. |
| Aggregated usage counters (hashed ID) | Up to 12 months, for fair-use limits and client reporting |
| Star ratings (optional) | Stored anonymously — no name, no device link |
| Client configuration | Retained for the duration of the client contract |
Access to Loca's admin interface, database, and infrastructure is restricted to authorised personnel, protected by strong credentials and audit logging. QR tokens are scoped per client and cannot be used across different deployments.
Loca's availability is monitored continuously, with automatic alerts if the service becomes unreachable. Security-relevant activity — failed admin logins, blocked or rate-limited requests, and unusual traffic patterns — is logged and reviewed. In the event of a personal data breach, Loca Guide will notify affected client organisations without undue delay, consistent with the commitments in our Data Processing Addendum.
Privacy or security enquiries: privacy@loca-guide.com
Full details: Privacy & Data Sources Policy
Chez Loca, la sécurité et la confidentialité sont intégrées à l'architecture du service. Cette page explique comment vos données sont protégées et quels fournisseurs d'infrastructure sont impliqués.
Loca s'appuie sur des fournisseurs d'infrastructure disposant de leurs propres certifications auditées de manière indépendante : Cloudflare (SOC 2 Type II, ISO 27001), Supabase (SOC 2 Type II, ISO 27001) et Anthropic (SOC 2 Type II, ISO 27001) — chacun réévalué chaque année par un tiers accrédité. Loca hérite de la sécurité de cette infrastructure sous-jacente, ce qui ne signifie pas que Loca Guide elle-même détient une certification.
Si votre organisation a besoin d'une attestation de conformité signée directement par Loca Guide, contactez privacy@loca-guide.com pour en discuter.
Toutes les données transmises entre votre appareil et Loca sont protégées par HTTPS (TLS). Le contenu de la base de données est chiffré au repos. Aucune requête ni réponse n'est transmise en clair.
Loca crée un identifiant de navigateur aléatoire pour appliquer des limites d'utilisation quotidiennes équitables et prévenir les abus. Il ne contient aucune information personnelle et n'est pas lié à votre appareil.
Si vous activez le GPS, vos coordonnées sont utilisées uniquement pour trier les résultats à proximité par distance pendant votre requête. Elles ne sont pas stockées dans la base de données. Vous pouvez refuser l'accès GPS à tout moment via les paramètres de votre navigateur.
| Type de données | Conservation |
|---|---|
| Journaux de session anonymes | Jusqu'à 60 jours, pour la fiabilité et la prévention des abus |
| Coordonnées GPS | Non stockées — utilisées uniquement pendant la requête |
| Identifiant navigateur anonyme | L'identifiant brut reste uniquement dans le stockage du navigateur. Le serveur ne reçoit et ne conserve jamais la valeur brute — seulement un hachage SHA-256 à sens unique, utilisé pour les compteurs d'usage ci-dessous. |
| Compteurs d'usage agrégés (identifiant haché) | Jusqu'à 12 mois, pour les limites d'utilisation équitable et les rapports client |
| Notes en étoiles (optionnel) | Stockées anonymement — sans nom ni lien avec l'appareil |
| Configuration client | Conservée pendant la durée du contrat client |
L'accès à l'interface d'administration, à la base de données et à l'infrastructure de Loca est réservé au personnel autorisé, protégé par des identifiants robustes et une journalisation des accès. Les jetons QR sont limités par client et ne peuvent pas être utilisés sur différents déploiements.
La disponibilité de Loca est surveillée en continu, avec des alertes automatiques si le service devient inaccessible. L'activité liée à la sécurité — échecs de connexion administrateur, requêtes bloquées ou limitées, schémas de trafic inhabituels — est journalisée et examinée. En cas de violation de données personnelles, Loca Guide informera les organisations clientes concernées sans délai excessif, conformément aux engagements de notre Accord de Traitement des Données.
Demandes de confidentialité ou de sécurité : privacy@loca-guide.com
Détails complets : Politique de confidentialité et sources de données
En Loca, la seguridad y la privacidad están integradas en la arquitectura del servicio. Esta página explica cómo se protegen sus datos y qué proveedores de infraestructura participan.
Loca funciona sobre proveedores de infraestructura que cuentan con sus propias certificaciones auditadas de forma independiente: Cloudflare (SOC 2 Type II, ISO 27001), Supabase (SOC 2 Type II, ISO 27001) y Anthropic (SOC 2 Type II, ISO 27001) — reevaluados cada año por un tercero acreditado. Loca hereda la seguridad de esta infraestructura subyacente, aunque esto no equivale a que Loca Guide cuente con una certificación propia.
Si su organización necesita una certificación de cumplimiento firmada directamente por Loca Guide, contacte con privacy@loca-guide.com para hablarlo.
Todos los datos transmitidos entre su dispositivo y Loca están protegidos mediante HTTPS (TLS). El contenido de la base de datos está cifrado en reposo. Ninguna consulta ni respuesta se transmite en texto plano.
Loca crea un identificador de navegador aleatorio para aplicar límites de uso diario justos y prevenir abusos. No contiene información personal y no está vinculado a su dispositivo.
Si activa el GPS, sus coordenadas se utilizan únicamente para ordenar los resultados cercanos por distancia durante su solicitud. No se almacenan en la base de datos. Puede rechazar el acceso al GPS en cualquier momento a través de la configuración de su navegador.
| Tipo de dato | Retención |
|---|---|
| Registros de sesión anónimos | Hasta 60 días, para fiabilidad y prevención de abusos |
| Coordenadas GPS | No almacenadas — usadas solo durante la solicitud |
| ID de navegador anónimo | El ID original vive solo en el almacenamiento del navegador. El servidor nunca recibe ni guarda el valor original — solo un hash SHA-256 de un solo sentido, usado para los contadores de uso siguientes. |
| Contadores de uso agregados (ID hasheado) | Hasta 12 meses, para límites de uso justo e informes al cliente |
| Valoraciones con estrellas (opcional) | Almacenadas anónimamente — sin nombre ni vínculo con el dispositivo |
| Configuración del cliente | Conservada durante la vigencia del contrato del cliente |
El acceso a la interfaz de administración, base de datos e infraestructura de Loca está restringido al personal autorizado, protegido con credenciales robustas y registro de auditoría. Los tokens QR tienen alcance por cliente y no pueden usarse en diferentes implementaciones.
La disponibilidad de Loca se supervisa de forma continua, con alertas automáticas si el servicio deja de estar accesible. La actividad relevante para la seguridad — inicios de sesión de administrador fallidos, solicitudes bloqueadas o limitadas, patrones de tráfico inusuales — se registra y se revisa. En caso de violación de datos personales, Loca Guide notificará a las organizaciones clientes afectadas sin demora injustificada, conforme a los compromisos de nuestro Acuerdo de Tratamiento de Datos.
Consultas de privacidad o seguridad: privacy@loca-guide.com
Detalles completos: Política de Privacidad y Fuentes de Datos
Bei Loca sind Sicherheit und Datenschutz in die Architektur des Dienstes integriert. Diese Seite erklärt, wie Ihre Daten geschützt werden und welche Infrastrukturanbieter beteiligt sind.
Loca läuft auf Infrastrukturanbietern, die über eigene, unabhängig geprüfte Zertifizierungen verfügen: Cloudflare (SOC 2 Type II, ISO 27001), Supabase (SOC 2 Type II, ISO 27001) und Anthropic (SOC 2 Type II, ISO 27001) — jährlich von einer akkreditierten Stelle neu geprüft. Loca profitiert von der Sicherheit dieser zugrunde liegenden Infrastruktur, was jedoch nicht bedeutet, dass Loca Guide selbst zertifiziert ist.
Falls Ihre Organisation eine von Loca Guide direkt unterzeichnete Compliance-Bestätigung benötigt, kontaktieren Sie privacy@loca-guide.com, um dies zu besprechen.
Alle Daten, die zwischen Ihrem Gerät und Loca übertragen werden, sind durch HTTPS (TLS) geschützt. Der Datenbankinhalt ist im Ruhezustand verschlüsselt. Keine Anfragen oder Antworten werden im Klartext übertragen.
Loca erstellt eine zufällige Browser-Kennung, um faire tägliche Nutzungslimits anzuwenden und Missbrauch zu verhindern. Sie enthält keine persönlichen Informationen und ist nicht mit Ihrem Gerät verknüpft.
Wenn Sie GPS aktivieren, werden Ihre Koordinaten nur zur Sortierung nahegelegener Ergebnisse nach Entfernung während Ihrer Anfrage verwendet. Sie werden nicht in der Datenbank gespeichert. Sie können den GPS-Zugriff jederzeit über Ihre Browsereinstellungen ablehnen.
| Datentyp | Speicherdauer |
|---|---|
| Anonyme Sitzungsprotokolle | Bis zu 60 Tage, für Zuverlässigkeit und Missbrauchsprävention |
| GPS-Koordinaten | Nicht gespeichert — nur während der Anfrage verwendet |
| Anonyme Browser-ID | Die Roh-ID liegt nur im Browser-Speicher. Der Server erhält und speichert nie den Rohwert — nur einen Einweg-SHA-256-Hash davon, verwendet für die untenstehenden Nutzungszähler. |
| Aggregierte Nutzungszähler (gehashte ID) | Bis zu 12 Monate, für Fair-Use-Limits und Kundenberichte |
| Sternbewertungen (optional) | Anonym gespeichert — kein Name, keine Geräteverknüpfung |
| Kundenkonfiguration | Für die Dauer des Kundenvertrags gespeichert |
Der Zugriff auf Locas Admin-Interface, Datenbank und Infrastruktur ist auf autorisiertes Personal beschränkt, geschützt durch starke Anmeldedaten und Audit-Logging. QR-Token sind kundenbezogen und können nicht für verschiedene Deployments verwendet werden.
Die Verfügbarkeit von Loca wird kontinuierlich überwacht, mit automatischen Warnungen, falls der Dienst nicht erreichbar ist. Sicherheitsrelevante Aktivitäten — fehlgeschlagene Admin-Anmeldungen, blockierte oder ratenbegrenzte Anfragen, ungewöhnliche Verkehrsmuster — werden protokolliert und überprüft. Im Falle einer Verletzung des Schutzes personenbezogener Daten informiert Loca Guide betroffene Kundenorganisationen unverzüglich, gemäß den Zusagen in unserem Auftragsverarbeitungsvertrag.
Datenschutz- oder Sicherheitsanfragen: privacy@loca-guide.com
Vollständige Details: Datenschutz- und Datenquellen-Richtlinie
Bij Loca zijn beveiliging en privacy ingebouwd in de architectuur van de service. Deze pagina legt uit hoe uw gegevens worden beschermd en welke infrastructuurproviders betrokken zijn.
Loca draait op infrastructuurproviders met hun eigen onafhankelijk geauditeerde certificeringen: Cloudflare (SOC 2 Type II, ISO 27001), Supabase (SOC 2 Type II, ISO 27001) en Anthropic (SOC 2 Type II, ISO 27001) — jaarlijks opnieuw beoordeeld door een geaccrediteerde derde partij. Loca profiteert van de beveiliging van deze onderliggende infrastructuur, maar dit betekent niet dat Loca Guide zelf gecertificeerd is.
Als uw organisatie een door Loca Guide rechtstreeks ondertekende compliance-verklaring nodig heeft, neem dan contact op met privacy@loca-guide.com om dit te bespreken.
Alle gegevens die tussen uw apparaat en Loca worden verzonden, zijn beschermd met HTTPS (TLS). Database-inhoud is versleuteld in rust. Geen zoekopdrachten of antwoorden worden in platte tekst verzonden.
Loca maakt een willekeurige browseridentificator aan om eerlijke dagelijkse gebruikslimieten toe te passen en misbruik te voorkomen. Het bevat geen persoonlijke informatie en is niet gekoppeld aan uw apparaat.
Als u GPS inschakelt, worden uw coördinaten alleen gebruikt om nabijgelegen resultaten op afstand te sorteren tijdens uw verzoek. Ze worden niet opgeslagen in de database. U kunt GPS-toegang op elk moment weigeren via uw browserinstellingen.
| Gegevenstype | Bewaring |
|---|---|
| Anonieme sessielogboeken | Tot 60 dagen, voor betrouwbaarheid en misbruikpreventie |
| GPS-coördinaten | Niet opgeslagen — alleen gebruikt tijdens het verzoek |
| Anonieme browser-ID | Het originele ID leeft alleen in browseropslag. De server ontvangt en bewaart nooit de originele waarde — alleen een eenrichtings-SHA-256-hash ervan, gebruikt voor de gebruikstellers hieronder. |
| Geaggregeerde gebruikstellers (gehasht ID) | Tot 12 maanden, voor fair-use-limieten en klantrapportage |
| Sterbeoordelingen (optioneel) | Anoniem opgeslagen — geen naam, geen apparaatkoppeling |
| Clientconfiguratie | Bewaard voor de duur van het clientcontract |
Toegang tot Loca's beheerinterface, database en infrastructuur is beperkt tot bevoegd personeel, beschermd door sterke inloggegevens en auditregistratie. QR-tokens zijn per client beperkt en kunnen niet worden gebruikt voor verschillende implementaties.
De beschikbaarheid van Loca wordt continu gemonitord, met automatische meldingen als de service onbereikbaar wordt. Beveiligingsrelevante activiteit — mislukte beheerdersaanmeldingen, geblokkeerde of beperkte verzoeken, ongebruikelijke verkeerspatronen — wordt gelogd en beoordeeld. Bij een inbreuk op persoonsgegevens informeert Loca Guide getroffen klantorganisaties zonder onnodige vertraging, in overeenstemming met de toezeggingen in onze Verwerkersovereenkomst.
Privacy- of beveiligingsvragen: privacy@loca-guide.com
Volledige details: Privacy- en Gegevensbronnenbeleid