Privacy Policy

Last updated 8 September 2026

The short version

You sign in with your Apple ID, your Google account, or an email and password. Nothing is texted to anybody. If your club turns it on, we notice when your phone leaves the property so your stand frees up for somebody else. Pictures and harvests you share are visible to your club and nobody else. We do not sell anything to anybody, we have no advertising, and the only measurement in the app is anonymous — it counts what gets used, never who you are.

Everything below is the detail. If something here does not match what you expected, tell us and we will fix the app or fix the wording.

What we collect

Your sign-in

This is your account. When you sign in with Apple or Google, the provider hands us a signed token proving who you are, plus your name and an email address — and if you chose Apple’s Hide My Email, that address is Apple’s relay, not your real one. We never see your Apple or Google password.

If you sign up with an email and password instead, we store the email and a hashed form of the password that we cannot reverse. Club owners who sign in with a password also receive a six-digit code by email, which expires within ten minutes.

Accounts created before Apple sign-in were keyed to a phone number. Those numbers remain stored encrypted and are no longer used to sign in; delete your account and the number goes with it.

Your name

Whatever you or your club chooses to call you on the board. It is shown to other members of your club and to nobody else.

Location — only if your club enables it

Auto check-out works by asking your phone to tell the app when it crosses a boundary around your club’s property. Three things about this are worth being exact on:

  • We are told that you left, not where you are. The app does not record your position inside the property, so which stand you sat in is known only because you booked it.
  • It uses the phone’s geofencing, which the operating system handles in the background. It is not continuous GPS and does not run a location trace.
  • iOS calls the permission “Always” because the app has to be able to receive the crossing while closed. That is the whole reason the feature works with the phone in your pocket.

You can decline the permission or turn it off later in iOS Settings. Nothing else in the app stops working — your stand is still released when the hunt window closes, exactly as it would have been.

Your bookings

Which stand, which hunt, when you checked in and out, and how the stand came free. Your club’s owner can see this for their own club. It is what makes the board work and what lets a club answer a question about who was on the property.

Harvests

If you log a harvest at check-out — what you took, where, and any note — it becomes part of your club’s season record, visible to your club. Logging is always optional; the app never fills it in for you.

Photos, likes and comments

Pictures you add — of stands, fields, or a harvest — are visible to your club and to nobody else, along with any likes and comments under them. Two details worth being exact on:

  • The app strips a photo’s hidden metadata before upload — including the GPS coordinates cameras embed in image files — so a picture cannot quietly reveal where it was taken.
  • The image files are held on our hosting provider’s storage at web addresses that are unguessable but not sign-in protected. Treat the gallery as shared with your club, not as a private vault.

If somebody likes or comments on a picture you added, we send a push notification to you and only you.

Safety alerts

If you use the Camp Safety button, every member of your club is sent your display name and, when you are checked in, the name and map coordinates of that stand. That is the feature doing its job: getting somebody with a truck to you. It never reads your phone’s live position.

Guests

If you bring a guest, the name you enter is stored against your reservation. Guests are not users and have no account. Please only enter a guest’s name if they are content for their name to be visible to your club. If a guest wants their name removed, ask your club owner or email us.

Payment

Card details never reach us. Plans are bought inside the iOS app and billed by Apple. We store which plan a club is on, whether it is current, and an identifier from Apple so renewals can be matched to the right club.

Email and password accounts

If you sign in with an email and a password, the password is stored hashed, in a form we cannot reverse. Forgot-password codes and the owner’s sign-in codes are emailed, expire quickly, and are stored hashed like everything else.

Anonymous usage counts

The app counts what gets used — sign-ins, bookings, harvests logged — under a random identifier that is never connected to your account, name, or number. It tells us “a stand was booked”, not “you booked a stand”. No advertising identifiers, no tracking across other apps or sites.

Technical

A hashed form of your IP address, used only to rate-limit sign-in attempts, password guesses, and club-code guessing. Ordinary server logs. No cookies for tracking.

Who else sees it

Other members of your club see your display name and your bookings. That is the point of a shared board. They do not see your phone number.

Your club’s owner sees the same plus your booking history and whether you are an active member.

Nobody in another club sees anything. Clubs are separated in the database and every request is checked against your membership.

We use these processors, and no others:

  • Render — the API and the database. Hosted in the United States.
  • Vercel — hosting for this site.
  • Cloudflare — stores the photos your club shares.
  • Resend — sends owner password-reset emails. They receive the email address and the message.
  • Apple — sign-in, payments, and push notifications.
  • Google — sign-in, if you choose it. Google learns that you signed in to Hunt Time; nothing about your club goes back.
  • PostHog — the anonymous usage counts described above. They never receive your name, number, or email.
  • The National Weather Service — receives your club’s property coordinates (never your phone’s position) so the board can show wind and legal light. A US government service; no account data goes with the request.

We do not sell personal information, and we do not share it for advertising. If we are ever compelled by law to hand something over, we will tell you unless we are legally prevented from doing so.

How long we keep it

Your account and bookings stay while your club is using Hunt Time. Password-reset codes expire within the half hour. Reservations are never hard-deleted — they are marked released, because a club’s history of who was on the property is the thing an insurance question turns on.

Delete your account from inside the app (My Club → Delete account) and your email, name, and any stored phone number are removed immediately, your Sign in with Apple connection is revoked with Apple, every signed-in device is signed out, and push notifications stop. Or ask us and we will do the same within 30 days. Your past bookings may remain in your club’s history with your display name, since they are also the club’s records; tell us if you want that discussed.

Your choices

  • Turn off location in iOS Settings. Auto check-out stops; nothing else changes.
  • Sign out everywhere from My Club, which kills every signed-in phone on your account at once. Use it if you lose a handset.
  • Leave a club by asking its owner to remove you.
  • Delete your account from My Club in the app — it takes effect immediately, no email required.
  • Get a copy of your data, or have it deleted, by emailing support@hunttime.app. If you are in California, the EU or the UK you have specific rights to this and we will honour them regardless of where you live.

Children

Hunt Time is not for under-13s and we do not knowingly collect anything from them. Plenty of clubs hunt with children — record them as guests on a member’s reservation rather than giving them an account. If you believe a child under 13 has an account, email us and we will delete it.

Between 13 and 17, an account is allowed only with a parent or guardian’s permission. The app asks every new account holder to confirm they meet the age rule before they join or start a club, and we store the date they confirmed. A parent or guardian who wants a teen’s account and data removed can delete it from inside the app (My Club → Delete account) or email us, same as anybody else — it works immediately and removes their name, email, and any stored number.

Security

Apple and Google sign-ins run on the provider’s signed tokens, so there is no Hunt Time password to lose. Email passwords are stored hashed. Legacy phone numbers are encrypted at rest; reset codes and device tokens are stored hashed, so a database copy is not a set of working credentials — and a signed-in device that goes unused for six months is signed out on its own. Traffic is encrypted in transit, and nightly backups are encrypted too. On your phone, the token is kept in the iOS Keychain and excluded from backups. No system is perfect; if we ever have a breach affecting your information we will tell you promptly and plainly.

Changes, and how to reach us

If we change this in a way that matters, we will say so in the app rather than quietly editing the page. The date at the top is when it last changed.

Hunt Time is operated by Strata Software Group. Questions, deletion requests, or anything that looks wrong: support@hunttime.app.