Privacy Policy
This Privacy Policy explains how HuntrMap ("we", "us"), operated by David Steinbrede, Dycker Str. 13, 41564 Kaarst, Germany, collects, uses, and shares information when you use our mobile and web application (the "Service"). Contact: privacy@huntrmap.com.
1. Information We Collect
- Account data: email address, hashed password (bcrypt; we never store plaintext), registration timestamp, chosen region (DE/AT/CH/US), and optional region subdivision. If you sign in with Apple, we receive a stable user identifier and (if you allow it) an email — Apple may provide a relay email address.
- Property data: names, geographic coordinates (property boundaries, markers, stands, paths), notes, harvest records, hunt journal entries.
- Photos: if you attach photos to markers, they are stored securely in your account. EXIF data (GPS, timestamps) that you include remains part of the image.
- Device location: when you tap "my location", your device prompts once for permission. Coordinates are used on-device and are not transmitted to our servers.
- Technical data: IP address and user-agent are processed by our hosting/CDN providers (listed below) for delivery, rate-limiting, and abuse prevention.
- Camera tokens: only if you connect a third-party trail-camera service (Spypoint, Zeiss SECACAM). Tokens are stored encrypted in our database.
- Subscription data: when you subscribe, our payment processors (Lemon Squeezy, Apple, Google) receive your email, name, country, tax status, and payment details. We receive only a subscription status (active / trial / cancelled) and the product you chose.
2. How We Use Information
We use your information to:
- Provide and operate the Service (sync your data across devices, render your maps, fetch weather for your stands).
- Authenticate you and keep your account secure.
- Process subscriptions and send service-related emails (receipts, security alerts, material changes to these policies).
- Detect and prevent abuse, fraud, or technical problems.
- Comply with legal obligations.
We do not sell your personal information. We do not use your data for advertising. We do not share it with advertisers or data brokers.
3. Third-Party Service Providers
We use the following service providers to operate HuntrMap. Each acts as a processor or independent controller under applicable law.
- Supabase Inc. (San Francisco, CA) — hosting, database, authentication. Data is stored in the EU (Frankfurt, AWS).
- Strato AG (Germany) — hosting for the landing page and the proxy server (api.huntrmap.com).
- Mapbox, Inc. (Washington, DC) — map tiles (streets, satellite). Receives your IP address, zoom level, and map viewport when the map is loaded.
- CARTO DB Inc. (New York / Madrid) — fallback OSM-based map tiles via basemaps.cartocdn.com.
- Esri Inc. (Redlands, CA) — satellite fallback tiles via server.arcgisonline.com.
- Open-Meteo (Switzerland) and Bright Sky (Germany) — weather data. Receive coordinates of the location you query.
- Cloudflare, Inc. (USA) via cdnjs.cloudflare.com — JavaScript library delivery.
- jsDelivr (UK, delivered via Cloudflare/Fastly) via cdn.jsdelivr.net — Supabase client library delivery.
- Google Ireland Ltd. — web font "Inter" delivery via fonts.googleapis.com.
- Spypoint Inc. (Canada) — trail-camera integration. Only if you connect your Spypoint account.
- Carl Zeiss SECACAM GmbH (Germany) — trail-camera integration. Only if you connect your Zeiss account.
- Lemon Squeezy LLC (Wilmington, DE — part of the Stripe group) — web subscription processing as Merchant of Record.
- Apple Inc. (USA) — iOS subscription processing via the App Store; Sign in with Apple.
- Google LLC (USA) — Android subscription processing via Google Play.
- RevenueCat, Inc. (USA) — subscription management across stores.
- Functional Software, Inc. dba Sentry (San Francisco, CA) — error monitoring in the web app and the iOS app. Activated only when a technical error occurs. Transmits: error message, stack trace, app/browser and operating-system version, device type, and truncated IP. In the iOS app no personal data is transmitted (no account, no email address, no user identifier) — crash data is anonymous. No session recording, no click tracking, no performance analytics. EU server region (Frankfurt) where available.
- Aptabase (EU hosting) — anonymous, non-personal usage analytics in the iOS app (e.g. which features are opened). No personal data, no IP addresses and no cross-device identifiers are stored; the data cannot be linked to an individual. No cross-app tracking and no sharing for advertising purposes.
4. International Data Transfers
We are based in Germany. When we transfer personal data to providers in the United States, we rely on the EU-U.S. Data Privacy Framework (for providers that are certified) or on Standard Contractual Clauses. For U.S. users, data processing occurs on U.S.-based infrastructure where applicable.
5. Data Retention
We retain your account and content until you delete your account. You can delete your account at any time from within the app ("Delete account permanently"). Deletion is completed within 30 days. Certain records may be kept longer where required by law (e.g. billing records for paid subscriptions). Backups are rotated and purged on a rolling basis.
6. Your Rights
6.1 EU / UK users (GDPR)
You have the right to access (Art. 15), rectify (Art. 16), erase (Art. 17), restrict (Art. 18), and port (Art. 20) your personal data, and to object (Art. 21) to processing based on legitimate interests. You may withdraw any consent at any time without affecting prior processing. You may complain to a supervisory authority (Art. 77).
6.2 California residents (CCPA / CPRA)
If you reside in California, you have the right to:
- Know what personal information we collect, use, disclose, and sell/share.
- Delete the personal information we hold about you.
- Correct inaccurate personal information.
- Opt out of sale/sharing of personal information. HuntrMap does not sell or share personal information as those terms are defined by the CCPA, and has not done so in the preceding 12 months.
- Limit the use of sensitive personal information. We do not collect sensitive personal information for purposes beyond those expressly permitted by the CCPA (e.g. login credentials used to sign you in).
- Non-discrimination for exercising these rights.
To exercise these rights, email privacy@huntrmap.com or use the "Delete account permanently" button and data-export option in the app. We verify requests using the email on your account.
6.3 Other U.S. state laws
If you reside in Virginia, Colorado, Connecticut, Utah, or another U.S. state with a comprehensive privacy law, you have rights substantially similar to those above. Contact us at privacy@huntrmap.com to exercise them.
7. Children
HuntrMap is not directed to children. We do not knowingly collect personal information from anyone under 16 (EU/UK) or 13 (U.S., under COPPA). If you believe a child has provided us personal information, email privacy@huntrmap.com and we will delete it.
8. Security
Connections use TLS (HTTPS). Passwords are stored as bcrypt hashes. Access to your data in our database is isolated per user via row-level security — other users cannot see your data. No system is perfectly secure; we will notify affected users of material breaches as required by law.
9. Cookies and Similar Technologies
The web app uses local storage (not cookies) to keep your session, preferences, and offline cache on your device. We do not use advertising or analytics cookies.
10. Do Not Track
We do not track users across third-party websites and so do not respond differently to Do Not Track browser signals. If your browser sends a Global Privacy Control (GPC) signal, we treat it as a request to opt out of sale/sharing (even though we do not sell or share).
11. Changes to This Policy
We may update this Privacy Policy. Material changes will be announced in-app or by email at least 14 days before they take effect. The "Effective" date above indicates the latest version.
12. Contact
Email privacy@huntrmap.com for any privacy question, access request, or complaint. Postal address: David Steinbrede, Dycker Str. 13, 41564 Kaarst, Germany.