Privacy Policy
Last updated: 9 August 2026
Who we are
Magical Trails (“we”, “us”, “our”) is a platform for creating and playing location-based, QR-code story trails. The Service is operated by Magic Zebra Ltd, a company registered in England & Wales (company no. 17298687), whose registered office is at Belmont Suite, Paragon Business Park, Chorley New Road, Bolton, Lancashire, England, BL6 6HG. Magic Zebra Ltd is the controller of personal data for which it determines the purposes and means of processing, including data used to operate, secure and improve the platform, and you can reach us at hello@magiczebra.co.uk.
One nuance worth flagging: where a school, PTA, community group, or other organisation runs a trail, that trail operator may be a separate (or joint) controller for the personal data it uses to organise its trail — for example the details it uses to choose who to invite, or personal data it puts into the content it creates. In some arrangements we act on the operator’s instructions in relation to that data. The actual facts of a given trail determine who is responsible for what; if you are unsure, contact us or the trail operator.
Data we collect
- Maker accounts. When you sign in to build trails we process your name and email address, your membership of and role within an organisation, an internal account identifier, and records of the content you create and actions you take in the maker dashboard.
- Invite-only player accounts. For trails that require an invite, we process the email address you sign in with, authentication and session data, an internal account identifier, a record of the invites you have redeemed, and the trail-access claims that grant you entry to specific trails. The organisation that runs a trail can see the email address attached to a claim so it can manage or revoke access to its trail.
- Public play & on-device progress. Most trails are playable without an account. Your progress through a trail and your preferences are stored on your own device so you can pick a trail back up; we do not need an account to make this work.
- Location, camera & motion features. Some activities ask your browser for permission to use your precise device location, your camera, or motion sensors so the activity can run. Your precise location is processed on your device to check whether you are near a trail point — it is compared locally and is not uploaded to us. If an activity lets you take a selfie, the image is created on your device and is saved only if you choose to download it.
- Usage & diagnostics. When analytics are enabled (see below), PostHog may record a session-scoped identifier, your IP address and an approximate location derived from it, your device, browser and operating system, timestamps, the trail events you trigger, and error diagnostics (including diagnostic messages and stack traces). This information may incidentally contain personal data.
- Maker-uploaded content. Trail makers may upload images, audio, video, and text used within their trails, which may contain personal data (for example a photograph of a person).
- Technical & support records. Our hosting, authentication, and security providers log IP addresses, request metadata, and timestamps in the course of running and protecting the Service, and we keep records of support requests and any rights requests you make.
How we use your data
- To authenticate you and control access to trails.
- To deliver trail content and the playing experience.
- To measure and improve the product and diagnose errors through analytics and error monitoring (you can opt out — see below).
- To keep the Service secure and to respond to your requests.
We do not sell your personal data.
Analytics & error monitoring
We use PostHog in the player app to understand how trails are played. What PostHog collects is privacy-minimised, session-scoped usage statistics that we do not link to a named player account or a persistent cross-session identifier. Analytics are enabled by default, and you can opt out at any time from the privacy controls in the player app. Opting out stops PostHog analytics and player-side exception capture on that device; it does not stop the technically necessary hosting, authentication, and security logs described above, which are required to run the Service. Declining analytics does not affect access to any feature.
Separately from product analytics, and for a separate purpose, we use error monitoring to keep the Service reliable: the player app can capture runtime exceptions, and the maker dashboard may send server-side errors and associated diagnostic context to Sentry — which may incidentally contain personal data — when the operator has enabled it.
Our legal basis
Under UK GDPR, we rely on the following:
- Providing the Service (maker accounts, invite-only access, delivering trail content) — performance of a contract with you and/or our legitimate interests in operating the platform.
- Analytics. For any personal data our usage statistics involve, we rely on our legitimate interests in understanding and improving the product and in giving the organisations who run trails information about how their trails are used — balanced against your privacy by keeping the data privacy-minimised and by offering a simple, free means of objecting (the opt-out toggle in the player app). You can opt out at any time; we are finalising our position under the Privacy and Electronic Communications Regulations (PECR) for any storage of, or access to, information on your device.
- Error monitoring and security — our legitimate interests in keeping the Service reliable and secure.
Children
Children do not create Magical Trails accounts. They may play public trails without an account and under the supervision of a responsible adult. A child’s use can nevertheless generate the usage and technical information described above, including analytics events, an IP address and device information. We minimise this information and do not link it to a named account or persistent cross-session identifier.
We do not use children’s data for advertising, profiling, or cross-service tracking. Where an organisation runs a trail for children, it is responsible for complying with data-protection and safeguarding requirements that apply to its own activities. This does not reduce Magic Zebra Ltd’s responsibilities for processing it controls. Consent is only required where it is the applicable lawful basis. If you believe a child’s personal data has been provided to us and should be removed, contact us at hello@magiczebra.co.uk.
Processors and where your data is stored
Personal data and content are processed by the following providers:
- Convex — application database (accounts, organisations, trails, invites, and trail-access records). Player sign-in is handled within Convex by the self-hosted Better Auth component, whose tables live in the Convex deployment — it is not a separate hosted authentication provider.
- Supabase Storage — the active store for uploaded media. A migration to AWS S3 is planned but not yet live.
- PostHog — product analytics and error monitoring for the player app (enabled by default; opt out any time).
- Sentry — server-side errors and associated diagnostic context for the maker dashboard, which may incidentally contain personal data (active only when the operator has enabled it).
- WorkOS — maker sign-in (authentication).
- Vercel — hosting, and the request, security, and operational logs that hosting produces.
Some providers may process personal data outside the UK. See International transfers below for how we approach this, or contact us for current details of the providers we use and the regions they operate in.
International transfers
Some providers may process personal data outside the UK. We are confirming the locations and legal mechanism applicable to each provider. Before making a restricted transfer, we require it to be covered by UK adequacy regulations, an applicable UK safeguard or another lawful transfer mechanism.
Cookies, local storage & similar technologies
We use the following on your device:
- Authentication cookies and tokens to keep signed-in users signed in.
- Browser storage to hold trail content, your progress and preferences, and your privacy/consent choices.
- A service-worker cache so the app can load reliably.
- In-memory session storage for PostHog’s session identifier.
We do not use advertising or cross-site tracking technologies.
Your rights
Depending on your circumstances and the lawful basis that applies, you have rights under UK GDPR to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to data portability, and to withdraw consent where processing is based on consent. Not every right applies to every kind of processing.
You can object to PostHog analytics and player-side exception capture using the opt-out control. To object to other processing based on legitimate interests, including maker-dashboard diagnostics, contact us. We will consider the objection and stop the processing unless we have compelling legitimate grounds to continue or require it for legal claims.
If you are in the UK and think we have not handled your data properly, you can complain to the Information Commissioner’s Office (ICO) at ico.org.uk. We’d welcome the chance to resolve it first.
Erasure and account deletion
The “delete” control in the player app removes your trail-access claims and signs you out. It does not currently delete the underlying login account and authentication records — that is a separate step. To request full account deletion, email hello@magiczebra.co.uk and we will action it. After deletion, some information may persist in restricted backups until the normal backup cycle expires.
Data retention
We keep each category of personal data only for as long as necessary for the purposes described above, then delete or de-identify it. In practice that means:
- Accounts and trail-access claims — for as long as the account or claim is active, and for a reasonable period afterwards.
- Deleted content and media — removed when deleted, though copies may persist briefly in routine backups until the normal backup cycle expires.
- Analytics — raw PostHog events are kept no longer than needed to produce aggregate statistics; the aggregate statistics themselves may be kept longer.
- Error diagnostics and hosting/security logs — kept for a limited period for reliability and security purposes.
- Support and rights-request records — kept for as long as needed to handle the request and to meet our legal obligations.
Contact
For any privacy question or request, contact us at hello@magiczebra.co.uk.
See also our Terms of Service.