Log In

011 / PRIVACY

Privacy policy.

What we collect, why we collect it, and what we refuse to do with it. We do not sell data. We do not run ad-network trackers in the app. We answer access requests in 14 days.

DOC ID

CS-PRV-001

VERSION

3.0

EFFECTIVE

2026-05-27

LANGUAGE

EN-US

JURISDICTION

OREGON, USA

─ INDEX ─

§ 1 What we collect

§ 2 Why we collect it

§ 3 What we do not do

§ 4 Who we share with

§ 5 Your rights

§ 6 Security

§ 7 Children

─ PLAIN-LANGUAGE SUMMARY ─

Email + optional display name, your watches, subscription state from Apple. No passwords (passwordless sign-in). No credit cards (Apple handles billing). No advertising. Aggregate analytics on the marketing website only. Delete your account in-app at any time.

§ 1

What we collect

1 . 1

Account data: email address you use to sign in, plus the identity-provider subject ID returned by Sign in with Apple or Sign in with Google (a stable identifier that is not your Apple ID or Google account password). Campsite Sniper sign-in is passwordless — we never see or store a Campsite Sniper password. Display name is optional; if you provide one or your sign-in provider supplies it, we store it to personalize alerts.

1 . 2

Auto Cart credentials (only if you enable optional Auto Cart): the Recreation.gov email and password you choose to save are stored only on your device's secure store and are never sent to or stored on our servers. When you use Auto Cart, your device sends them directly to Recreation.gov to sign in and prepare the selected site in your cart. You can delete them at any time in the app.

1 . 3

Subscription data: a subscription state record provided by RevenueCat after Apple processes your in-app purchase — Apple transaction ID, plan tier, renewal status, trial status. We do not see your credit card or payment instrument; Apple handles billing.

1 . 4

Watch data: the campground IDs, date ranges, and notification preferences you configure for each watch.

1 . 5

Device data: APNs push notification tokens (anonymous, supplied by Apple, scoped to your account on this device), app version, iOS version, device model. Used to deliver push alerts and to debug crashes.

1 . 6

Operational data: IP address (used for rate-limiting and abuse detection), request timestamps. Server logs are retained 30 days, then deleted.

1 . 7

Crash and error telemetry via Sentry: stack traces, breadcrumbs, device model, app version. Email addresses, auth tokens, push tokens, and other PII are scrubbed before transmission.

1 . 8

Marketing-site analytics (this website only, not the app): Google Analytics 4 (G-PTSB3XWKW9) for aggregate traffic and Microsoft Clarity (wl1b8o0dtb) for anonymized session replay on landing pages. These do not run inside the iOS app.

1 . 9

What we do not collect: contacts, photos, microphone, IDFA / advertising identifiers, browsing history, location beyond what is necessary to show campgrounds on the map (and only while the app is in use, per iOS permission).

§ 2

Why we collect it

2 . 1

To deliver alerts. Without your watches and a push token, we cannot tell you about availability.

2 . 2

To deliver the service you paid for. RevenueCat tells us which tier you have so we can gate features. Apple handles charging your payment method; we never see it.

2 . 3

To diagnose problems. Server logs and Sentry crash reports help us find bugs, detect abuse, and respond to incidents.

2 . 4

To prevent abuse. We rate-limit requests by IP, block disposable email domains at signup, and cap watch creation per hour.

§ 3

What we do not do

3 . 1

We do not sell your data. We do not share it with advertisers or data brokers.

3 . 2

We do not run advertising in the app. There is no IDFA tracking, no Facebook Pixel, no ad-network SDK in the iOS binary.

3 . 3

We do not run cross-app or cross-site behavioural tracking. The marketing-site analytics named in §1 are first-party aggregate measurement only; they do not link to your in-app identity.

3 . 4

We never store your passwords or credit card numbers on our servers, and we never see them. We never book, hold, reserve, pay for, hoard, transfer, or resell inventory. If you enable Auto Cart, the Recreation.gov credentials you save stay on your device and are sent only to Recreation.gov -- see "What we collect."

§ 4

Who we share with

4 . 1

Apple — handles in-app purchase billing, payment method, and subscription state. Apple's privacy policy governs the data Apple holds for you.

4 . 2

RevenueCat — receives your Apple subscription transactions and exposes plan state to our backend. Their privacy policy: revenuecat.com/privacy.

4 . 3

Supabase — our backend database and authentication provider. Hosts the data described in §1.

4 . 4

Sentry — crash and error telemetry. PII scrubbed at send time.

4 . 5

Mapbox — renders the campsite map. We disable Mapbox telemetry; the SDK does not phone home with your activity.

4 . 6

Resend — sends your magic-link sign-in emails and the optional email digest. They process the email address to deliver the message.

4 . 7

Apple Push Notification service — delivers push alerts using the anonymous device token Apple issued for our app.

4 . 8

Recreation.gov and other reservation operators -- when our availability checks run for sites you have asked us to watch, the requests come from our server infrastructure, identified by our user agent, and operators do not receive your Campsite Sniper email or account details. Separately, if you enable Auto Cart, your device sends the Recreation.gov credentials you saved directly to Recreation.gov to sign in and prepare the selected site in your cart.

4 . 9

Law enforcement, only with valid legal process. We do not voluntarily disclose user data.

§ 5

Your rights

5 . 1

Access: email [email protected] from your account email to request a copy of all data we hold on you. We respond within 14 days.

5 . 2

Deletion: from inside the app, Account → Delete Account → confirm. We delete your data within 30 days, except billing records, which we retain as required by tax authorities.

5 . 3

Subscription cancellation: cancel the Apple App Store subscription in your iPhone Settings → Apple ID → Subscriptions. Deleting your account in our app does not cancel your Apple subscription — you must do that separately or you may continue to be billed by Apple.

5 . 4

Portability: email us to request your watches and account data in machine-readable form.

5 . 5

Correction: edit any profile field directly in the app via Account → Profile.

§ 6

Security

6 . 1

Data in transit: TLS 1.3 minimum, HTTPS-only (no cleartext). Apple Transport Security is enforced and arbitrary loads are disabled in the iOS binary.

6 . 2

Data at rest: AES-256 (managed by Supabase) for the application database. Auth tokens are managed by Supabase Auth and Apple/Google identity providers -- we never see your plaintext Campsite Sniper sign-in credentials. Auto Cart credentials, if you enable it, are stored in your device secure store and sent only to Recreation.gov.

6 . 3

In the event of a breach affecting your data, we will notify you within 72 hours of confirmed scope.

§ 7

Children

7 . 1

The service is not directed to children under 13. We do not knowingly collect data from children under 13. If you believe a child under 13 has created an account, email [email protected] and we will delete it.

Questions? [email protected] · This document supersedes all prior versions.

CAMPSITE SNIPER

Recreation.gov cancellation alerts. We notify; you review and book directly on Recreation.gov.

PRODUCT

COMPANY

LEGAL

© 2026 CAMPSITE SNIPER │ v1.0 · BUILT FOR THE LONG WAIT │ N 37.74° W 119.57°

SYSTEMS NOMINAL │

Campsite Sniper is not affiliated with, endorsed by, or sponsored by Recreation.gov or any government agency. Data source: Recreation.gov.

tyrannosaurx.com ↗

Campgrounds & pages