← Back to cmaps

Privacy Policy

Effective Date: August 9, 2026

cmaps ("the App") is an outdoor mapping application built for hunters and outdoor recreationists, developed and operated by Connor Callison. This Privacy Policy describes how we collect, use, store, and protect your information when you use the App.

By using cmaps, you agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the App.

1. Information We Collect

Account Information. If you choose to create an account, we collect your name, email address, and a securely hashed version of your password. You are not required to create an account; the App can be used in a local-only mode without providing any personal information.

Location Data. The App collects GPS coordinates from your device to display your real-time position on the map, record hiking or hunting tracks, create waypoints, and, if you explicitly join a Field Party in Share mode, show your latest position to that party. Track recording and active Field Party sharing may continue in the background. Watch-only Field Party mode does not upload your location. Location data is only collected while you are actively using the relevant features.

User-Generated Content. You may create waypoints (including names, coordinates, photos, and notes), GPS tracks, and offline map regions. This content is stored on your device and, if you have an account, may be synced to our servers.

Feedback Information. If you choose to send feedback from the App, we collect the category and message you provide, whether you allow us to contact you, and limited technical context consisting of the App version, build number, and iOS version. Feedback submissions do not automatically include your location, coordinates, saved map content, or advertising identifiers.

Technical and SDK Diagnostics. The App integrates Mapbox for map rendering and tile delivery. Mapbox may collect non-linked technical, usage, diagnostic, and location-related data for app functionality, map reliability, and analytics as described in Mapbox's privacy policy.

Local Preferences. The App stores your map layer preferences and settings locally on your device using standard system storage (UserDefaults). This data never leaves your device.

Purchase and Evaluation Information. When you start the seven-day evaluation, buy lifetime access, restore a purchase, or receive family access, Apple supplies a signed StoreKit transaction. We use the product, transaction status, purchase date, and an account-scoped token to verify and deliver access. We store a one-way SHA-256 hash of the original transaction identifier; we do not receive your payment-card number.

First-Party Product Interaction. For signed-in users, the App sends a limited set of product events to the cmaps API: paywall viewed, evaluation started, first meaningful map action, offline download started, day-return milestones, evaluation expired, purchase completed, purchase restored, and family access granted. Events contain an event name, time, and limited primitive context such as the entitlement state or product ID. They do not include coordinates, device or advertising identifiers, waypoint or track content, photos, or notes. When a signed-in person chooses an App Store link on our public marketing page, we record that named first-party CTA intent and its page placement. We do not retain this marketing CTA event for unsigned visitors or use it to track people across websites.

2. How We Use Your Information

Property and parcel boundary data displayed in the App is sourced from official government records and authorized data sources and does not contain personally identifiable information.

3. Data Sharing and Third Parties

We do not sell your data to third parties. Ever.

The App uses the following third-party services:

When you join a Field Party in Share mode, your latest reported position, its age, a coarse accuracy band, motion data, and a coarse battery band are visible to the other authenticated members of that party. Field Parties are limited to eight members and can run for 24 hours, 48 hours, or until the creator ends an indefinite session. You can choose Watch Only before joining, pause sharing, or leave at any time.

The App does not include any third-party analytics SDKs or advertising SDKs. First-party product interaction events are sent only to the cmaps API and are not used to track you across other companies' apps or websites.

4. Data Storage and Security

On your device: Your data is stored in a local database (SwiftData), with preferences saved via UserDefaults and authentication tokens secured in the iOS Keychain. Offline map tiles are cached locally on your device.

On our servers: If you create an account, your account information, waypoints, tracks, entitlement state, limited first-party product interaction events, and any feedback you voluntarily submit are stored in a PostgreSQL database. During a Field Party, the server stores only the most recent location fix for each sharing member, replacing the prior fix instead of retaining a route history. We implement reasonable technical and organizational measures to protect your data from unauthorized access, alteration, or destruction.

While we take data security seriously and employ industry-standard practices, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security.

5. Background Location Use

The App uses background location access only during an active track recording session or an active Field Party that you explicitly joined in Share mode. Track collection stops when you pause or end recording. Field Party collection stops when you pause sharing, switch to Watch Only, leave, end the party, or a timed party expires.

6. Your Rights and Choices

7. Data Retention

We retain your account data, synced content, entitlement state, and first-party product events for as long as your account is active. If you delete your account, that linked data is permanently deleted from our servers. A non-account-linked purchase-claim ledger and any already-issued Family Pack recipient grants are retained as described above. Locally stored data remains on your device until you uninstall the App or delete it manually. Field Party latest fixes are deleted when a member leaves or pauses sharing and when the party ends or expires; a scheduled expiry process removes fixes when all party devices are offline.

8. Children's Privacy

The App is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will take steps to delete that information promptly.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Effective Date" at the top of this page. We encourage you to review this Privacy Policy periodically. Your continued use of the App after any changes constitutes your acceptance of the updated policy.

10. Contact

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:

cmaps
connor@cmaps.app
cmaps.app