Privacy Policy
Last Updated: January 27, 2025
1. Information We Collect
We collect information in several ways to provide and improve our Service:
1.1 Information You Provide Directly
- Account Information: When you create an account, we collect your username, email address, and password (stored in encrypted form)
- Profile Information: Optional information you choose to add to your profile
- User-Generated Content: Information you submit through the app, including location markers, notes, and other contributions
- Communications: When you contact us for support or feedback, we collect the content of those communications
1.2 Information Collected Automatically
- Device Information: Device type, operating system, unique device identifiers, and mobile network information
- Usage Data: Features used, pages viewed, actions taken, time spent, and interaction patterns
- Log Data: IP address, browser type, access times, and referring URLs
- Location Data: With your permission, we may collect precise or approximate location data to provide location-based features
1.3 Information from Third-Party Services
If you choose to link your account with third-party services or sign in using social authentication, we may receive information from those services in accordance with their privacy policies.
2. Analytics and Monitoring
We use third-party analytics and monitoring tools to understand how our Service is used and to maintain its performance and reliability.
2.1 Google Analytics
We use Google Analytics to collect and analyze usage data. Google Analytics uses cookies and similar technologies to collect information about your use of the Service, including:
- Pages and features you access
- Time spent on pages
- Navigation paths through the app
- Device and browser information
- Geographic location (country/region level)
Google may use this data in accordance with their own privacy policy. You can learn more about Google's practices at https://policies.google.com/privacy and opt out of Google Analytics by using the Google Analytics Opt-out Browser Add-on.
2.2 Application Performance Monitoring
We use Prometheus and Grafana for application performance monitoring and infrastructure metrics. This includes:
- Server response times and error rates
- API endpoint performance metrics
- System resource utilization
- Request volume and patterns (aggregated, non-personal)
This monitoring data is used solely to ensure the reliability, performance, and security of our Service. Performance metrics are collected in aggregate form and do not include personally identifiable information.
3. How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Description |
|---|---|
| Provide the Service | To operate, maintain, and deliver the features and functionality of the Service |
| Account Management | To create and manage your account, authenticate your identity, and provide customer support |
| Personalization | To personalize your experience and provide content relevant to your interests and location |
| Communication | To send service-related notices, security alerts, and respond to your inquiries |
| Improvement | To analyze usage patterns, diagnose technical issues, and improve our Service |
| Security | To detect, prevent, and address fraud, abuse, and security issues |
| Legal Compliance | To comply with applicable laws, regulations, and legal processes |
4. Information Sharing and Disclosure
We do not sell your personal information (information that directly identifies you). However, we may share, sell, or license aggregated or de-identified data as described below. We may share your information in the following circumstances:
4.1 With Your Consent
We may share information when you explicitly consent to such sharing.
4.2 Service Providers
We engage trusted third-party service providers to perform services on our behalf, including:
- Cloud hosting and data storage
- Analytics services (Google Analytics)
- Email delivery services
- Customer support tools
These providers are contractually obligated to protect your information and use it only for the purposes we specify.
4.3 Legal Requirements
We may disclose your information if required to do so by law or in response to valid legal requests, including:
- Court orders or subpoenas
- Government or law enforcement requests
- To protect our rights, privacy, safety, or property
- To protect against legal liability
4.4 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and your choices regarding your information.
4.5 Aggregated and De-identified Data
We may collect, create, use, share, sell, or license aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you. This data is not considered personal information and may be used for any lawful purpose, including but not limited to:
- Market research and industry analysis
- Statistical reports on user activity and trends
- Geographic distribution data (e.g., number of users in specific regions, states, or metropolitan areas)
- Usage patterns and behavioral analytics
- Product development and improvement
We may share or sell this aggregated data to third parties, including data brokers, research firms, advertisers, and business partners. Because this data does not identify you personally, it is not subject to the same restrictions as personal information.
5. Data Security
We implement industry-standard security measures to protect your information:
5.1 Technical Safeguards
- Encryption: Data is encrypted in transit using TLS/SSL and at rest using AES-256 encryption
- Password Security: Passwords are hashed using secure, one-way cryptographic algorithms
- Access Controls: Strict access controls limit who can access your data
5.2 Operational Safeguards
- Regular security assessments and monitoring
- Employee training on data protection practices
- Incident response procedures
- Regular backups with secure storage
6. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy:
- Account Data: Retained while your account is active and for a reasonable period thereafter
- Usage Data: Retained in identifiable form for up to 24 months, then aggregated or deleted
- Analytics Data: Retained according to Google Analytics data retention settings (currently 26 months)
- Log Data: Retained for up to 12 months for security and troubleshooting purposes
When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law or for legitimate business purposes.
7. Your Rights and Choices
You have certain rights regarding your personal information:
7.1 Access and Portability
You can request a copy of the personal information we hold about you. We will provide this information in a commonly used, machine-readable format upon request.
7.2 Correction
You can update or correct your account information at any time through the app settings or by contacting us.
7.3 Deletion
You can request deletion of your account and personal information. Some information may be retained as required by law or for legitimate business purposes.
7.4 Opt-Out Options
- Marketing Communications: You can opt out of marketing emails by clicking the unsubscribe link in any marketing email
- Push Notifications: You can disable push notifications through your device settings
- Location Data: You can disable location services through your device settings
- Analytics: You can opt out of Google Analytics using browser extensions or device settings
7.5 California Residents
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA), including:
- The right to know what personal information is collected about you
- The right to request deletion of your personal information
- The right to opt out of the sale of personal information
- The right to non-discrimination for exercising your privacy rights
Sale of Personal Information: We do not sell your personal information as defined under the CCPA. However, aggregated, anonymized, or de-identified data that cannot reasonably identify you is not considered "personal information" under the CCPA and may be shared or sold to third parties as described in Section 4.5.
To exercise your California privacy rights, contact us at support@graysheeparmory.com.
8. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to collect information and improve the Service:
- Essential Cookies: Required for the Service to function properly (authentication, security)
- Analytics Cookies: Help us understand how you use the Service (Google Analytics)
- Preference Cookies: Remember your settings and preferences
You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the Service.
9. Children's Privacy
The Service is not intended for individuals under the age of 18 (or 21 where required by law). We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately and we will take steps to delete such information.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using the Service, you consent to the transfer of your information to the United States and other jurisdictions where we operate.
We take appropriate measures to ensure that your information receives an adequate level of protection in the jurisdictions in which we process it.
11. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party services you access.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you via email or in-app notification
- Obtain your consent where required by law
Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy. We encourage you to review this policy periodically.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
For data subject requests (access, deletion, correction), please email us with the subject line "Data Subject Request" and include sufficient information to verify your identity.