Legal draft: Before publishing, add and verify the controller, address, actual processors, retention periods, and business status.
1. Controller
[Full name/company name]
[Service address]
Email: Support.Geocrack@gmail.com
2. Data we process and why
| Area | Data | Purpose |
|---|---|---|
| Website | IP address, time, requested resource, browser/device information | Delivery, security, and troubleshooting |
| Account | Email address, Firebase user ID, verification status, session data | Registration, sign-in, and access control |
| Extension | Random device ID, app version, settings, access status, trial/weekly usage | Service delivery, synchronization, and abuse prevention |
| Payment | Stripe customer/subscription/payment identifiers, status, account association | Checkout, subscriptions, Lifetime access, customer portal, refunds, and disputes |
| Support | Email, subject, message, optional device/account data, browser, and app version | Handling support requests |
| Operational log | Time, account ID or email, event type, and required technical metadata | Support, access control, billing security, and auditability of administrative actions; no recording of map positions or page content |
3. Legal bases
Depending on the processing activity, we rely on Article 6(1)(b) GDPR for contracts and pre-contractual steps, Article 6(1)(c) GDPR for legal obligations, and Article 6(1)(f) GDPR for IT security, abuse prevention, and reliable operation. We only rely on consent under Article 6(1)(a) GDPR where it is genuinely voluntary and can be withdrawn.
4. Hosting with Vercel
The website and API are hosted by Vercel. Technically required connection and log data may be processed. Before publishing, document the data processing agreement, region, retention periods, and possible international transfers based on the actual Vercel account.
5. Firebase Authentication and Realtime Database
Firebase is used for sign-in, email verification, account association, and selected synchronization data. Database rules limit direct client access to the signed-in account; administrative server data is not publicly accessible.
6. Stripe
Stripe is used for paid subscriptions and one-time Lifetime payments. Payment details are collected in Stripe Checkout and are not stored on our servers. We receive technical identifiers and status information needed to grant and manage access and to handle refunds or payment disputes.
7. Website and email support
Support tickets are stored so we can handle the request. Replies may be sent through the listed support address and, where configured, an email service provider. Never send passwords, secret keys, or full payment details.
8. Local extension storage
The extension uses Chrome storage for settings, a random device identifier, session status, and temporarily cached access information. This data supports the extension and may partly sync with the signed-in account.
9. Cookies, tracking, and external content
The current website does not use advertising or marketing trackers. Technically necessary storage may be used for sign-in and security. Product videos will only be added with a privacy-conscious setup; external video providers must not load automatically without prior review.
10. Retention
Data is kept only as long as needed for the account, contract, support, security, or legal retention duties. Specific deletion periods must be defined in a retention policy before launch. After a valid account deletion request, data that is no longer required is deleted or anonymized unless legal obligations require otherwise.
11. Recipients and international transfers
Recipients may include Vercel, Google/Firebase, Stripe, and an optional email provider. Where data is processed outside the European Economic Area, the applicable transfer mechanism, such as an adequacy decision or suitable safeguards, must be documented before launch.
12. Your rights
Under the GDPR, you may have rights including access, correction, deletion, restriction, data portability, and objection. Consent can be withdrawn for the future. You also have the right to lodge a complaint with a competent data protection authority.
13. Security
We use access controls, verified accounts, server-side authorization, and encrypted HTTPS connections. No internet transmission can be guaranteed to be completely risk-free.
14. Changes
We will update this notice when features, providers, or legal requirements change.
15. Checkout record
Before Stripe Checkout, the versions of the accepted terms, price, billing interval, app version, and a server timestamp are stored with the account. This records the declarations made before the paid purchase.
16. Page data and Limited Use
Location and page data from supported games is processed locally in the browser to provide the clearly described extension features. GeoCrack does not transmit detected map positions or page content to the GeoCrack backend and does not use this data for advertising, profiling, or sale to third parties.
GeoCrack's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Draft dated July 1, 2026