PeakScout takes your privacy seriously. We collect minimal data to operate the Service, we never sell your personal data, and we give you meaningful control over what you share. This policy explains exactly what we collect, why, how long we keep it, and what rights you have.
1.1 Account & Identity
1.2 Location & Activity Preferences
1.3 Trip Safety Data
1.4 Community Reports
1.5 Usage & Technical Data
1.6 Legal Acceptances
2.1 How Location is Collected
PeakScout does not continuously track your real-time GPS position. Location data is collected only through explicit user actions:
2.2 Storage and Retention
Saved location coordinates are retained for the life of your account. Discovery queries (one-time geolocation) are cached for 30 minutes in an anonymized bucket (rounded to ~10km precision) and not linked to your account identity.
2.3 Sharing Location Data
Your saved location coordinates are transmitted to third-party weather and conditions APIs (NOAA/NWS, Open-Meteo, USGS) as query parameters to fetch relevant data. These are outbound queries with no user identity attached — the APIs receive coordinates, not your email or account ID.
2.4 Anonymization
Discovery and "What's Open Now" queries use coordinate buckets (rounded latitude/longitude) rather than precise GPS coordinates. We cannot re-identify your precise location from bucketed data.
We do not use your data for behavioral advertising, user profiling for ad targeting, sale to data brokers, or any commercial purpose beyond operating PeakScout.
We share data with the following third parties, for the specified purposes only:
| Service | Purpose | What we share |
|---|---|---|
| Stripe, Inc. | Payment processing, subscription management | Email, payment card details, billing address Raw card numbers never stored by us |
| Postmark (Wildbit) | Transactional email delivery (alerts, briefings, trip notifications) | Email address, email content |
| NOAA / NWS | Weather forecasts and station data | None — outbound-only public API call |
| CAIC | Colorado avalanche forecasts | None — outbound-only public API call |
| Recreation.gov / RIDB | Campsite availability and federal facility data | None — public API, no personal data transmitted |
| NPS Developer API | National park alerts | None — API key authentication only, no user data |
| USGS | Stream gauge and snowpack data | None — public data feed |
| Geoapify | Forward and reverse geocoding (address ↔ coordinates) | Search query strings (no user ID), IP address |
| Open-Meteo | Supplemental weather forecasts | Latitude/longitude of requested location (no user ID) |
| Polsia Analytics | Aggregate product analytics and session intelligence | Anonymous visitor fingerprint, page views, feature events No cross-site tracking or advertising profiles |
We do not share your personal data with any advertising networks, data brokers, or parties not listed above.
Under the California Consumer Privacy Act (CCPA), California residents have the following rights:
To submit a CCPA request, email peakscout@polsia.app with subject line "CCPA Request." We will respond within 45 days. We may request verification of your identity before processing your request.
In the 12 months prior to the effective date of this policy, we have not sold or disclosed California consumers' personal information to third parties for commercial purposes.
PeakScout is a U.S.-based service focused on U.S. outdoor recreation. We do not actively target users in the European Economic Area (EEA) or United Kingdom. If you choose to access the Service from the EEA or UK, your data will be processed in the United States.
For EEA/UK users, our legal bases for processing personal data are:
EEA/UK residents may have the right to lodge a complaint with their local data protection authority. Contact peakscout@polsia.app to exercise GDPR rights — we will respond within 30 days.
PeakScout is not directed to children under 13. We do not knowingly collect personal information from children under 13. If a parent or guardian believes their child has provided us with personal information, please contact peakscout@polsia.app immediately and we will delete that information promptly.
Users between 13 and 17 must have parental consent. If we discover an account belongs to a user under 13 without parental consent, we will terminate the account and delete associated data.
PeakScout uses the following types of cookies and local storage:
| Type | What it does | Required? |
|---|---|---|
| Session cookies | Maintains your login session and CSRF protection | Yes — core functionality |
| Visitor fingerprint (localStorage) | Pseudonymous ID to associate anonymous actions across sessions (not linked to email unless logged in) | Yes — core functionality |
| Analytics (localStorage) | Tracks feature usage and page views for product analytics. No cross-site tracking. | No — functional but not identity-linked |
| Stripe cookies | Set by Stripe during checkout for fraud prevention. Governed by Stripe's privacy policy. | Yes — required for payments |
We do not use third-party advertising cookies, retargeting pixels, or cross-site tracking for ad delivery. You can disable cookies in your browser settings, but session cookies are required for login and some features will not work without them.
PeakScout supports browser-based web push notifications for campsite availability alerts, trip overdue alerts, and condition updates. Push notification delivery requires:
To revoke push notification consent: use your browser's site settings to remove push permission for peakscout.polsia.app. You can also manage notification preferences in your account settings. Revoking push permission does not affect email alerts.
All payment processing is handled by Stripe, Inc., a PCI DSS Level 1 certified payment processor. PeakScout never receives, stores, or processes raw payment card data (card numbers, CVV, expiry).
When you subscribe or make a purchase:
For questions about Stripe's data practices, see the Stripe Privacy Policy.
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data (email, preferences) | Duration of account + 90 days after deletion request | Service operation; 90-day window for recovery |
| Briefing and alert delivery logs | 12 months | Delivery troubleshooting and abuse prevention |
| Payment records (Stripe events) | 7 years | Financial regulation and tax compliance |
| Trip plan and check-in data | 30 days after trip return date | Emergency safety; auto-purged after confirmed safe return + buffer |
| Emergency contact information | Deleted with associated trip plan (30 days after return) | Minimal retention; not retained beyond trip lifecycle |
| Community reports (trail conditions, dog hazards) | 72 hours (dog reports) / 12 months (other reports) | Condition data has limited shelf life; aggregated historical patterns retained anonymously |
| Legal acceptances (typed signatures) | Indefinite | Legal compliance; proof of informed consent |
| Analytics events (page views, interactions) | 24 months | Product analytics and trend analysis |
| Push notification tokens | Until revoked or 12 months of inactivity | Required for alert delivery; pruned on delivery failure |
Regardless of your location, you have the following rights:
To exercise any right, email peakscout@polsia.app with subject line "Privacy Request" and describe your request. We respond within 45 days. We may need to verify your identity before processing the request.
We implement industry-standard security controls including:
No method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we take reasonable precautions and maintain incident response procedures.
In the event of a data security breach that affects your personal information, we will:
If you suspect unauthorized access to your account, immediately email peakscout@polsia.app with subject line "Security Incident."
We may update this Privacy Policy from time to time. We will notify you of material changes by email to your registered address at least 14 days before the changes take effect. The "Effective" date at the top of this policy reflects the date of the most recent revision. Continued use of the Service after changes take effect constitutes your acceptance of the revised policy.
For historical versions of this policy, contact us at the email below.
Privacy questions, data requests, or security concerns: