ScoutIQ

Legal

Privacy Policy

Effective July 1, 2026  ·  Last updated July 1, 2026

Effective Date: July 1, 2026 Last Updated: July 1, 2026

ScoutIQ LLC d/b/a ScoutIQ ("ScoutIQ," "we," "us," "our") built a product that runs on location data. That means we owe you a straight answer about what we collect, why, and what we will never do with it. This Policy is that answer.

This Policy covers huntingscoutiq.com, scoutiq.app, app.huntingscoutiq.com, the ScoutIQ mobile and web applications, and all related services (the "Service").


The short version

We collect precise location when you grant permission, because a forecast for the wrong ridge is worthless.
We never sell your data. Not your location, not your email, not your waypoints. No money changes hands for your personal information, and no data broker ever gets it.
Advertising is the one exception worth naming. We send limited hashed identifiers and conversion events to Meta and Google to measure our ads. Some state laws call that "sharing for targeted advertising." You can turn it off in one click, and precise location is never part of it.
Your spots stay yours. Your waypoints, tracks, harvest logs, trail camera locations, and location history are never published, never sold, and never shown to other users unless you deliberately share them.
Model data is aggregated. When your field data improves our forecasts, it is pooled across users and generalized to a coarse map cell first. We do not build a public product out of your honey hole.
Raw location expires. Individual location pings are deleted after 90 days. Only aggregated, coarse summaries persist.
You control it. Turn location off, delete your location history, export your data, or delete your account, at any time, from Settings.
Marketing email is part of having an account. You can unsubscribe from marketing at any time in one click. See Section 7.

1. Information We Collect

1.1 Information you give us

Category Examples
Account Name or display name, email address, password (stored hashed, never in plain text), state or region, species interests, profile photo.
Authentication If you sign in with Apple or Google, we receive the identifiers that provider sends us. We do not receive your password.
Payment If you subscribe, our payment processor collects and stores your card details. We do not receive or store your full card number. We receive the last four digits, card brand, expiration, billing ZIP, and transaction status.
User Content Waypoints and pins, tracks and breadcrumbs, notes, glassing and observation logs, sign reports (tracks, rubs, wallows, scrapes, bedding), harvest reports, trail camera images and other photos, field reports, and anything you type into the app.
Communications Support requests, bug reports, survey and beta feedback, and messages you send us.
Preferences Notification settings, units, map defaults, saved units and areas.
Website and waitlist leads If you give us your email on our website, at an event, or through a waitlist, referral, or contest form without creating an account, we collect that email, your name if provided, and how you found us. The form tells you at that moment what you are signing up for.

1.2 Location information

This is the sensitive category. Here is exactly how it works.

We collect location only after you grant the corresponding permission on your device and in the app. We use a layered consent model, and each layer is a separate choice you can change at any time in Settings:

Consent scope What it enables What we collect
location_foreground Center the map on you, distance to waypoint, in-field features Your position while the app is open and in use
location_precise Accurate terrain, aspect, and forecast for where you actually are Full-accuracy GPS coordinates instead of an approximate area
location_background Track and breadcrumb recording while your phone is in your pocket Full-accuracy position while the app is in the background, only during an active recording or session you started
location_analytics Helps us understand which regions and features get used Location associated with product usage events
location_research Improves the forecast models for everyone Your location contributions to aggregated, cell-level model inputs

Specifically, we may collect: latitude and longitude, accuracy radius, altitude, heading, speed, timestamp, and the device permission state; the map areas you view, pan to, and zoom into (which is separate from where you physically are); derived stop and dwell information; and derived context such as elevation, slope, aspect, hunting unit, and land ownership for a given point.

We do not collect device GPS location before you create an account. We do not collect background location unless you explicitly enable it. We do not collect location while the app is closed and no recording is active.

Retention: "raw location pings" means the background telemetry stream, not the waypoints, tracks, logs, or photos you deliberately saved. Raw pings are automatically deleted after 90 days, and the things you saved are not touched. Aggregated, coarse-cell summaries (roughly a 150 meter grid) and your own saved waypoints and tracks persist until you delete them or delete your account.

1.3 Photos and trail camera images

If you upload a photo, we store the image file and any metadata embedded in it, which commonly includes GPS coordinates, date and time, and camera or phone model (EXIF data). We treat photo GPS coordinates as location data under this Policy. Photo location is never made public by us. If you share a photo into a public or shared area of the Service, we strip embedded GPS coordinates from the copy shown to others unless you explicitly choose to include them.

1.4 Information about other people in your uploads

Trail cameras and field photos sometimes capture other people, including other hunters, landowners, and passers-by. If you upload an image containing another person:

1.5 Information collected automatically

Category Examples
Device Device model, operating system and version, app version, screen size, language, time zone, carrier, browser type, IP address.
Usage Screens viewed, features used, buttons tapped, forecasts and scores viewed, session start and end, session length, crash and error reports, performance timing, referring URL and campaign parameters.
Approximate location from IP A coarse city or region estimate derived from your IP address, used for security, fraud prevention, and regional defaults. This happens for all visitors and is not the precise location described in Section 1.2.
Cookies and similar technologies See Section 9.

1.6 Information from third parties


2. How We Use Your Information

We use the information above to:

  1. Provide the Service. Create and secure your account, authenticate you, sync your waypoints and tracks across devices, render maps, and compute the forecast for the place you are actually standing.
  2. Generate forecasts and scores. Combine terrain, habitat, weather, pressure, and historical inputs into movement probabilities and confidence values.
  3. Improve our models. Validate and refine forecasting, terrain classification, habitat scoring, and human-pressure modeling. Field observations and location contributions used for model improvement are aggregated across users at the map-cell level, not analyzed as individual movement histories for this purpose.
  4. Improve the product. Understand which features get used, find bugs, measure performance, and prioritize work.
  5. Communicate with you. Send account, security, billing, and service messages, respond to support requests, and send marketing as described in Section 7.
  6. Market and grow. Measure campaign performance, run referral and community programs, and reach potential users. See Section 7 and Section 9.
  7. Keep the Service safe. Detect and prevent fraud, abuse, scraping, credential sharing, account takeover, and violations of our Terms.
  8. Comply with law. Meet legal, tax, accounting, and regulatory obligations, and respond to valid legal process.

Automated decision-making. Our forecasts are automated model outputs, but they are informational. We do not use automated processing to make any decision that produces a legal effect or similarly significant effect on you.


3. What We Will Never Do

These are commitments, not descriptions of current practice we reserve the right to change quietly.

The one thing we do that some laws call "sharing." We send hashed email addresses and conversion events (for example, "this person created an account") to Meta and Google so we can measure whether our ads work and reach similar audiences. Under the CCPA and the Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and Maryland privacy laws, that counts as sharing for cross-context behavioral advertising or targeted advertising, even though we are paid nothing for it. Precise location, waypoints, tracks, photos, and harvest data are never included. You can opt out at any time using the Your Privacy Choices link in our footer, in Account Settings, or by sending a Global Privacy Control signal from your browser. We honor those opt-outs across web and app.

If we ever want to do something materially different with data we already hold, we will ask for your affirmative opt-in first. Not a policy update you never read.


If you are in the European Economic Area, the United Kingdom, or Switzerland, we process personal data on these bases:

Purpose Legal basis
Providing the Service, billing, support Performance of a contract (GDPR Art. 6(1)(b))
Precise location processing Your consent (Art. 6(1)(a)), withdrawable at any time
Direct marketing Your consent, collected separately and unbundled at signup
Model improvement using your location data Your consent (Art. 6(1)(a)), via the location_research scope
Storing or reading information on your device for analytics Your consent under ePrivacy, collected through our cookie banner
Security, fraud prevention, and product improvement not involving location Legitimate interests (Art. 6(1)(f)), balanced against your rights
Legal, tax, and regulatory obligations Legal obligation (Art. 6(1)(c))

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.


5. How We Share Information

We share personal information only in the situations below.

5.1 Service providers

We use vendors to run the Service. They may process your information only on our instructions and only to perform their function.

Function Provider category What they receive
Database, authentication, file storage Cloud backend platform (Supabase) Account data, User Content, location data
Hosting and content delivery Cloud hosting and CDN Requests, IP address
Transactional and marketing email Email delivery platform (Resend) Email address, name, message content
Product analytics Analytics platform (PostHog) Device, usage events, coarse location, pseudonymous ID
Payments and subscriptions Payment processor Payment and billing data (processed by them, not stored by us)
Customer relationship and marketing operations CRM (HubSpot) Contact details, marketing consent status, engagement history
Advertising measurement Ad platforms (Meta, Google) Pseudonymous or hashed identifiers and conversion events, subject to your opt-out
Mapping and imagery Map tile and imagery providers Map tile requests, which reveal the areas you view
Error monitoring Crash and error reporting Device and diagnostic data

The named providers reflect our stack as of the Last Updated date and may change.

5.2 Aggregated and de-identified data

We may create and use aggregated or de-identified data, including regional usage statistics, model performance metrics, and coarse pressure and activity layers, and may share it publicly or with partners. No aggregated cell is published or shared unless it contains contributions from at least five distinct users, so a single person's spot never becomes a visible cell. This data cannot reasonably be used to identify you or to locate any individual waypoint. We commit to maintaining it in de-identified form and not attempting to re-identify it.

5.3 At your direction

If you share User Content publicly, with a group, or with another user, we share it as you directed.

We may disclose information if we believe in good faith it is necessary to: comply with law, regulation, subpoena, warrant, court order, or other valid legal process; enforce our Terms; detect or prevent fraud, security, or technical issues; or protect the rights, property, or safety of ScoutIQ, our users, or the public, including in a life-threatening emergency.

Our stance on demands for your location. We will require valid legal process before disclosing individual location or waypoint data. Where we are legally permitted to notify you of a demand for your data, we will do so before responding, unless we are prohibited or there is an emergency involving risk of death or serious injury.

5.5 Corporate transactions

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. Any acquirer remains bound by this Policy with respect to information collected before the change, unless you agree otherwise after notice.


6. Sensitive Personal Information

Precise geolocation is "sensitive personal information" under the California Consumer Privacy Act and comparable state laws.

We collect and use precise geolocation only to perform the Service you asked for (rendering your position, computing location-specific forecasts, and recording tracks and waypoints you create), for security and fraud prevention, and, where you have enabled the location_research scope, to improve our models in aggregated form.

We do not use or disclose sensitive personal information for the purpose of inferring characteristics about you, and we do not use it beyond the purposes permitted under Cal. Civ. Code § 1798.121. You may nonetheless limit its use through Settings or by contacting us at privacy@huntingscoutiq.com.


7. Marketing Communications

7.1 Service messages. While you hold an account, we send messages required to operate it: verification, password reset, security alerts, billing, changes to our terms, and material service announcements. These are not marketing and are not opt-out.

7.2 Marketing consent at signup. When you create a ScoutIQ account, you consent to receive marketing and promotional email from us, including product updates, feature launches, season and forecast content, beta and research invitations, surveys, referral and community program messages, and offers. This consent is presented to you at signup and described in Section 5 of our Terms of Service.

7.3 Opting out. Every marketing email contains a working one-click unsubscribe link in the footer. You can also change your preferences in Account Settings, or email privacy@huntingscoutiq.com with "Unsubscribe" in the subject. We process opt-outs promptly and in every case within 10 business days, as required by the CAN-SPAM Act. Opting out of marketing does not close your account and does not stop Section 7.1 messages.

7.4 Text messages. We send marketing text messages only if you separately opt in by checking the SMS consent box and providing your mobile number. That checkbox is unchecked by default, is never bundled with account creation, and is never a condition of purchase. Reply STOP to any message to cancel. Message and data rates may apply.

7.5 Push notifications. Controlled by you in your device settings and in Account Settings.

7.6 EEA, UK, and Switzerland. If you are in one of these regions, we collect a separate, unbundled, affirmative opt-in for marketing at signup and do not rely on account creation as consent.


8. Data Retention

Data Retention
Raw location pings 90 days, then automatically deleted
Aggregated coarse-cell location summaries Retained while your account is active, in aggregated form thereafter
Waypoints, tracks, logs, photos (your User Content) Until you delete them or delete your account
Account and profile data Life of the account, plus up to 90 days in encrypted backups
Analytics and usage events Up to 24 months
Marketing consent and opt-out records Retained indefinitely, because we are legally required to prove consent and to honor suppression lists
Billing and transaction records Up to 7 years, for tax and accounting obligations
Support and legal correspondence Up to 3 years, or longer where a legal hold applies

When you delete your account, we delete or de-identify your personal information within 30 days, except for records we must keep for legal, tax, fraud-prevention, or dispute-resolution purposes, and except for aggregated data that no longer identifies you. Residual copies may persist in encrypted backups for up to 90 days before rotation.


9. Cookies and Tracking Technologies

We and our providers use cookies, local storage, SDKs, pixels, and similar technologies to keep you logged in, remember preferences, measure usage, and evaluate advertising.

Type Purpose Can you turn it off?
Strictly necessary Authentication, session, security, load balancing No, the Service will not function without them
Preferences Units, map defaults, dismissed prompts Yes, via your browser
Analytics Product usage measurement Yes, via our cookie controls and browser settings
Advertising Campaign measurement and audience building on Meta and Google Yes, via our cookie controls and via each platform's ad settings

Your Privacy Choices. Use the Your Privacy Choices link in our website footer, or the privacy controls in Account Settings, to turn off analytics and advertising technologies. Your choice is stored per browser and, once you are signed in, applied to your account across devices.

Global Privacy Control. We honor the Global Privacy Control (GPC) signal. If your browser sends GPC, we treat it as a valid request to opt out of sale and sharing for targeted advertising for that browser. Because we do not sell personal information, this primarily affects advertising cookies.

Do Not Track. There is no industry-accepted standard for responding to browser DNT signals, so we do not respond to DNT. We do honor GPC.


10. Your Privacy Rights

10.1 Everyone

Regardless of where you live, you can:

Use Account Settings, or email privacy@huntingscoutiq.com.

10.2 U.S. state privacy rights

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Maryland, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, Indiana, Kentucky, Rhode Island, or another state with a comprehensive privacy law, you have the right to:

How to exercise. Submit a request through Account Settings, or email privacy@huntingscoutiq.com with "Privacy Request" in the subject line. We will verify your identity by confirming control of the email address on your account, and may ask for additional information for high-risk requests. We acknowledge your request within 10 business days and respond substantively within 45 days, and may extend once by another 45 days with notice.

Authorized agents. You may use an authorized agent. We will require written authorization and may require you to verify your own identity directly.

Appeals. If we deny your request, you may appeal by replying to our decision or emailing privacy@huntingscoutiq.com with "Privacy Appeal" in the subject. We will respond within 45 days with our decision and reasoning. If we deny the appeal, you may contact your state Attorney General. Colorado residents: the Colorado Attorney General's office is at coag.gov/file-complaint. California residents: you may also contact the California Privacy Protection Agency.

California "Shine the Light." We do not disclose personal information to third parties for their own direct marketing purposes.

10.3 EEA, UK, and Swiss rights

You have the rights of access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent. You also have the right to lodge a complaint with your supervisory authority. Contact privacy@huntingscoutiq.com.

10.4 Nevada residents

Nevada residents may direct us not to sell certain personal information. We do not sell personal information, but you may submit a request to privacy@huntingscoutiq.com.


11. Security

We protect your information with measures including: encryption in transit (TLS) and at rest; hashed and salted password storage; row-level security policies enforced at the database layer, so one user's data is not reachable from another user's session; least-privilege access controls for our team; audit logging; and vendor security review.

No system is perfectly secure. We cannot guarantee absolute security, and you share information with us at your own risk. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities as required by law.

What you should do: use a unique password, enable multi-factor authentication where offered, keep your device locked, and tell us immediately at support@huntingscoutiq.com if you suspect unauthorized access.


12. Children's Privacy

The Service is for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If we learn we have collected it, we will delete it. If you believe a minor has given us information, contact privacy@huntingscoutiq.com.

We do not sell or share personal information of consumers under 16.


13. International Users and Transfers

The Service is operated from the United States and our providers are primarily located in the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States, where privacy laws differ from those in your country.

Where required for transfers from the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, together with supplementary technical and organizational measures.


The Service links to and integrates third-party sites and services. This Policy does not cover their practices. Review their privacy policies. We are not responsible for what they do with information you give them.


15. Changes to This Policy

We may update this Policy. We will post the updated version with a new Effective Date. For material changes, including any change to how we use location data or to our commitments in Section 3, we will notify you by email or in-app notice before the change takes effect and, where the change would apply to data we already hold, we will ask for your affirmative consent.


16. Appendix: Statutory Categories of Personal Information

For readers who need this mapped to the categories used in California and other state privacy statutes. Every category below has been collected in the preceding 12 months.

Statutory category What we collect Sources Business purpose Recipient categories Retention
Identifiers (Cal. Civ. Code § 1798.140(v)(1)(A)) Name, email, account ID, device ID, IP address You, your device, sign-in providers Provide the Service, authenticate, support, security, marketing Cloud backend, email platform, analytics, CRM, ad platforms (hashed only) Life of account + 30 days
Customer records (§ 1798.80(e)) Name, email, billing ZIP, payment card metadata You, payment processor Billing, fraud prevention, tax and accounting Payment processor, accounting 7 years for transaction records
Commercial information Subscription plan, purchase and renewal history You, payment processor Provide and bill the Service Payment processor, CRM 7 years
Internet or network activity Screens viewed, features used, session data, crash and performance data, referrer and campaign parameters Your device, cookies and SDKs Product improvement, debugging, security, ad measurement Analytics platform, error monitoring, ad platforms Up to 24 months
Geolocation data, including precise geolocation (sensitive) GPS coordinates, accuracy, altitude, heading, speed, map areas viewed, derived stops and dwell, derived terrain and ownership context Your device, with your permission Provide location features, compute forecasts, record tracks you create, security, model improvement where you enabled location_research Cloud backend only. Never sold, never shared with ad platforms, never brokered Raw pings 90 days; aggregated cells indefinitely; your saved content until you delete it
Sensory or visual information Photos and trail camera images you upload, with embedded EXIF You Store and display your content, at your direction Cloud file storage Until you delete it
Professional or employment information None n/a n/a n/a n/a
Education information None n/a n/a n/a n/a
Inferences Species and region interests, engagement segments, feature affinity Derived from the above Personalize the product, prioritize development, target our own marketing CRM, analytics Life of account
Sensitive personal information Precise geolocation only. We do not collect government ID numbers, financial account credentials, racial or ethnic origin, religious beliefs, union membership, health, sex life or sexual orientation, genetic or biometric data, or the contents of your mail, email, or texts Your device, with your permission Only the purposes permitted under Cal. Civ. Code § 1798.121, as described in Section 6 Cloud backend only Raw pings 90 days

We do not use or disclose personal information for purposes other than those listed above without giving you notice.


17. Contact Us

ScoutIQ LLC d/b/a ScoutIQ 2262 Deer Trail Creek Dr, Brighton, CO 80601

Purpose Contact
Privacy requests and questions privacy@huntingscoutiq.com
General support support@huntingscoutiq.com
Legal notices legal@huntingscoutiq.com
EU/UK representative, if appointed Not currently appointed

ScoutIQ. Your spots stay yours.