PRIVACY POLICY
Green Time Tracker
1. INTRODUCTION
Green Time Tracker ("we," "our," or "us") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, share, and protect your information when you use our mobile application ("App") and related services.
Green Time Tracker is a mobile application designed to help users track and monitor their outdoor activities and time spent in nature. We are committed to transparency in our data practices and your privacy rights.
2.1 Personal Information You Provide
Account Information:
- First name and last name
- Email address
- Date of birth (for age verification and COPPA compliance)
- Password (encrypted and never stored in plain text)
Profile Data:
- Annual outdoor activity goals
- User preferences and settings
- Profile customization choices
Activity Data:
- Outdoor activity logs and entries
- Duration of outdoor activities
- Activity types and categories
- Notes and descriptions you add to activities
- Optional location data (GPS coordinates) when explicitly enabled by you
2.2 Information Collected Automatically
Device Information:
- Device identifiers (IDFA/GAID when available)
- Operating system and version
- App version
- Device model and manufacturer
- Screen resolution and device specifications
Usage Analytics:
- App interaction data and navigation patterns
- Feature usage statistics
- Session duration and frequency
- Crash reports and error logs
- Performance metrics
2.3 Location Information (Optional)
GPS Location Data:
- Precise location coordinates for activity logging
- Only collected when explicitly permitted by you
- Used to enhance activity records with location context
- Stored encrypted and associated with specific activities
3. HOW WE USE YOUR INFORMATION
3.1 Service Provision
- Account Management: Create, maintain, and secure your user account
- Activity Tracking: Process and store your outdoor activity logs and data
- Progress Monitoring: Calculate and display progress toward your goals
- Data Synchronization: Sync your data across devices when logged in
- Subscription Services: Provide premium features and manage subscription access
3.2 Communication
- Account Verification: Send email verification and account setup communications
- Customer Support: Respond to your support requests and technical issues
- Service Notifications: Send important updates about your account or service changes
- Security Alerts: Notify you of security-related account activities
3.3 Service Improvement
- Analytics: Analyze aggregated usage patterns to improve app functionality
- Feature Development: Understand user needs to develop new features
- Bug Fixes: Identify and resolve technical issues and crashes
- Performance Optimization: Monitor and improve app performance
4.1 Service Providers
We share information with trusted third-party service providers who assist us in operating our services:
| Service Provider |
Purpose |
Data Shared |
Safeguards |
| Supabase |
Database and Authentication |
Account data, activity logs |
DPA, encryption, US East region |
| Apple Inc. |
App Store and Payments |
Subscription status only |
Apple's privacy policies apply |
| Analytics Providers |
App Performance |
Anonymized usage data only |
No PII shared |
4.2 What We Don't Share
We will never:
- Sell your personal information to third parties
- Rent or lease your data to advertisers
- Share your individual activity data without your consent
- Provide your information to data brokers
- Use your data for purposes other than described in this policy
5. DATA SECURITY
5.1 Security Measures
Encryption:
- All data transmitted using TLS 1.3 encryption
- Database storage encrypted at rest (AES-256)
- End-to-end encryption for sensitive personal data
- Secure key management practices
Access Controls:
- Row-level security policies in database
- Multi-factor authentication for admin access
- Principle of least privilege for data access
- Regular access reviews and audits
5.2 Data Retention
| Data Type |
Retention Period |
Notes |
| Account Data |
While account is active + 30 days |
Deleted upon account deletion request |
| Activity Logs |
Up to 7 years |
Personal record-keeping purposes |
| Analytics Data |
Up to 2 years |
Anonymized and aggregated |
6. YOUR RIGHTS AND CHOICES
6.1 Data Subject Rights (GDPR - EU Residents)
If you are located in the European Union, you have the following rights:
Right of Access:
- Request copies of your personal data
- Understand how your data is being used
- Receive information about data processing activities
Right of Rectification:
- Correct inaccurate or incomplete personal data
- Update your information to ensure accuracy
Right of Erasure (Right to be Forgotten):
- Request deletion of your personal data
- Have data removed when no longer necessary
- Withdraw consent for data processing
Right of Data Portability:
- Receive your data in a structured, commonly used format
- Transfer your data to another service provider
6.2 California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights:
- Right to Know: Categories and specific pieces of personal information collected
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: We do not sell personal information
- Right to Non-Discrimination: Equal service regardless of privacy choices
- Right to Correction: Request correction of inaccurate personal information
6.3 How to Exercise Your Rights
7. CHILDREN'S PRIVACY
7.1 Age Requirements
Minimum Age:
- Users must be at least 13 years old to create an account
- Age verification required during registration
- Accounts for users under 13 will be immediately deleted
Parental Consent (EU - Ages 13-15):
- Users aged 13-15 in the EU require verifiable parental consent
- Parents must approve account creation
- Parental rights to access and control child's data
7.2 COPPA Compliance
Children Under 13: We do not knowingly collect personal information from children under 13. If we become aware of collection from a child under 13, we will delete it immediately.
8. INTERNATIONAL DATA TRANSFERS
8.1 Data Processing Locations
- Primary Processing: United States (Supabase infrastructure - US East region)
- Cross-Border Transfers: Data may be accessed from various countries for support and maintenance
- Safeguards: All transfers protected by appropriate legal and technical safeguards
8.2 Transfer Safeguards
- Standard Contractual Clauses (SCCs): For EU personal data transfers
- Adequacy Decisions: Where European Commission has deemed adequate protection
- Encryption: All data encrypted during transfer and storage
9. SUBSCRIPTION AND PAYMENT INFORMATION
9.1 Apple App Store Integration
Payment Processing: All payments processed through Apple's App Store. We do not handle or store payment information directly.
- Subscription Management: Managed through your Apple ID account
- Billing: Handled by Apple according to their policies
- Refunds: Processed according to Apple's App Store policies
9.2 Free Trial Information
- Duration: 7-day free trial for new users
- Limitation: One trial per user/device
- Auto-conversion: Converts to paid subscription unless cancelled
- Privacy: Same privacy protections apply during trial
10. COOKIES AND TRACKING TECHNOLOGIES
10.1 Mobile App Tracking
What We Use:
- Usage analytics for app improvement
- Crash reporting for stability
- Performance monitoring
- Feature usage tracking
What We Don't Use:
- Third-party advertising networks
- Cross-app tracking for advertising
- Social media tracking pixels
- Marketing cookies or persistent identifiers for advertising
11. DATA BREACH NOTIFICATION
11.1 Our Commitment
Breach Response:
- Immediate containment and assessment
- Investigation to determine scope and cause
- Implementation of corrective measures
- Transparent communication with affected users
Notification Timeline:
- Regulatory authorities within 72 hours (GDPR requirement)
- Users notified without undue delay
- Clear information about breach impact
- Steps taken to address the breach
12. CHANGES TO THIS PRIVACY POLICY
12.1 Policy Updates
Notice of Changes:
- Email notification to registered users
- In-app notification upon opening
- Updated "Last Modified" date
- Summary of material changes provided
Material Changes:
- 30-day advance notice for material changes
- Option to delete account before changes take effect
- Clear explanation of how changes affect you
13. SPECIFIC JURISDICTION REQUIREMENTS
13.1 European Union (GDPR)
Legal Basis for Processing:
- Consent: For optional features like location sharing
- Contract: For providing our services
- Legitimate Interests: For security and improvement
- Legal Obligation: For compliance requirements
Supervisory Authority: Right to lodge complaints with local data protection authority
13.2 California (CCPA/CPRA)
Sensitive Personal Information:
- Precise geolocation (optional location features)
- Account login credentials (securely encrypted)
- We limit use to necessary business purposes
PRIVACY POLICY VERSION CONTROL
| Version |
Date |
Changes |
| 1.0 |
August 11, 2025 |
Initial privacy policy creation
Comprehensive GDPR and CCPA compliance
iOS App Store compliance framework
COPPA compliance for children's privacy
|
EFFECTIVE DATE: August 11, 2025
NEXT REVIEW DATE: February 11, 2026
DOCUMENT STATUS: Production Ready - Requires Legal Review Before Deployment