apps4equestrians / Privacy
Privacy Policy
Last updated:
How we handle information when you use EquiJUMP, EquiTRAIL, EquiDRIVE, EquiCROSS and our shared website, and how to exercise your privacy rights.
Operator And Product Scope
- The operator and data controller is Somatic Systems, računalniško programiranje, Rok Komatar s.p., Jezerska cesta 132B, 4000 Kranj, Slovenia. Registration number: 7484399000. Contact: apps4equestrians@gmail.com.
- apps4equestrians is the publisher brand for EquiJUMP, EquiTRAIL, EquiDRIVE and EquiCROSS. This policy covers these apps and the shared apps4equestrians website. “We” and “us” mean the operator named above.
- Each app has independent accounts, app data, roles, limits and subscriptions. Signing in to more than one app does not merge their accounts or data.
Information We Receive
- Account information you provide, such as email address, display name, profile photo, Rider or Trainer role, language and preferences. Firebase assigns an authentication identifier, including when you use Guest access without an email address. We also keep account status, plan and usage limits.
- The app creates and stores a random installation identifier. When preparing your account, it sends this identifier with platform and screen information to maintain a bounded list of your account’s devices and select or coordinate device-specific sketch previews. This identifier is linked to your app account; it is not an advertising identifier.
- If you choose an available Google or Apple sign-in option, that provider supplies the identifiers and profile information permitted by that sign-in, such as your email address or an Apple relay address. We do not receive your Google or Apple password.
- Content you choose to add: horse profiles and photos, horse health and care notes, course sketches, calendar events, training notes, groups and participation records, according to the features you use. Horse-care fields are for the horse; do not use them to record a person’s medical or other sensitive information.
- Information other users share with you through enabled trainer and rider features, such as invitations, event details, limited profile information and course previews. Those users are the source of that information.
- Content-safety reports contain the selected reason, any explanation you provide, a limited snapshot of the reported shared text, the relevant content reference and account identifiers where available. Public invitation reports do not require an account. We also retain your sharing-terms agreement and the account references needed to apply a block or sharing restriction.
- Subscription information from Apple or Google through RevenueCat, including the app account identifier, store, product, transaction and purchase history, expiry and entitlement status. Payment-card details are handled by the store or payment provider, not stored by us.
- Technical information generated when you connect, including IP address, request and security logs, app and operating-system versions, error type and diagnostic stack information. Support correspondence includes what you send us and the information needed to investigate your request.
- Older test accounts may contain legacy Challenge or social records, such as posts, follows or friend requests, even though these features are unavailable. These records remain within the applicable account-deletion scope.
Purposes And Legal Bases
- Providing the service you request: account access and recovery, content storage and syncing, selected sharing features, plan limits, subscription validation and customer support. We process the information necessary for these purposes to perform our contract with you or take steps you request before a contract (GDPR Article 6(1)(b)). Without the necessary account or transaction information, we cannot provide the corresponding feature; optional profile content is your choice.
- Security and reliability: preventing abuse and purchase transfers, reviewing content reports, applying blocks and sharing restrictions, protecting deleted accounts from reuse, diagnosing failures and defending legal claims. Our basis is our legitimate interests in operating a safe, reliable service and protecting users and the operator, balanced against your rights (Article 6(1)(f)). You can object to this processing.
- Legal duties: responding to valid legal demands, handling privacy rights and keeping required tax or accounting records (Article 6(1)(c)). We limit this processing to the relevant legal obligation.
- If we ask for consent for a separate optional purpose, we explain that purpose at the time and you can withdraw consent without affecting earlier lawful processing (Article 6(1)(a)). Agreeing to the Terms is not blanket consent to optional data uses.
- Plan limits, account security and subscription access use automated checks. Contact us for a person to review an apparent error. We do not sell personal data or use app content to build advertising profiles.
Vendors And Services
- Google Firebase and Google Cloud provide authentication, verification and recovery messages, databases, file storage, server functions and operational infrastructure. They receive the account, content and technical data necessary for those services.
- RevenueCat receives app account identifiers and store transaction information to validate subscriptions, restore access to the original account and synchronize entitlements where native billing is enabled.
- Apple and Google operate their own sign-in and store services. Their processing of platform accounts, payments, refunds and store purchase records is also governed by their own privacy notices.
- Vercel hosts the shared website and processes connection and request information to deliver and protect it. Google’s Gmail service handles messages sent to our support, privacy and deletion mailbox.
- Where crash reporting is configured, Bugsnag (SmartBear) receives a minimized diagnostic report containing error class, sanitized stack positions, app version and operating-system information. Our reporter removes account identifiers, free-text error messages, user content and interaction breadcrumbs from the report. Network providers still receive connection information such as an IP address; this is not a promise of anonymous processing.
- Providers receive data for their relevant role. We may also disclose necessary information to competent authorities where legally required or to professional advisers for a specific legal, tax or security matter. We do not make private account data public simply because it is stored with a provider.
User Content And Sharing
- Your content remains yours. Private horse records and sketches are not a public profile. Features you choose to use can share limited profile, event and course-preview information with the riders or trainers involved.
- An invitation link can show the event information selected for sharing to someone who has that link. Treat it as a sharing link and send it only to intended recipients. Recipients may keep information they have already received outside the service.
- Report controls send a private report to the operator for review. Reports are not a public discussion and we do not show the reporter’s identity to the reported user through these controls. Blocking stops new invitations, joins and signed-in shared views between the affected accounts. Unblocking does not restore previous invitations or memberships. Blocking cannot erase information already copied outside the service or identify a person who opens a public link without their account.
- Only add information about another person when you have a lawful basis and have told them how it will be used. Trainers remain responsible for their own independent records and arrangements outside our service.
- Account deletion removes your authored shared content and participation references as described below. It does not erase another person’s independently owned records.
Device Storage And Permissions
- The apps keep local account state, preferences and working data needed for the features you use. Access to a selected photo or camera is requested through the device’s permission controls. You can decline or revoke permission; the related photo feature may then be unavailable.
- Website account pages use browser storage to retain the selected app’s Firebase sign-in session. Invitation continuation uses a short-lived record valid for up to 20 minutes; the deletion page keeps request-recovery information in that browser tab’s session storage.
- These records support the account or continuation feature you request. The website does not include advertising cookies or an audience-analytics script. Browser or device settings let you clear local data, but doing so can sign you out or remove a saved deletion-request recovery record. Clearing local data is not the same as deleting a server account.
Storage, Deletion, And Retention
- Account and app content are kept while your account is active and needed to provide the service. You can remove individual records or request account deletion. We do not set one retention period for every kind of information.
- Individual deleted sketches, horses and events are normally eligible for archive cleanup after 90 days. Records with ownership or integrity problems are retained for review. Account deletion separately removes the account’s personal app content, profile and uploads.
- Content reports expire 90 days after their creation and are scheduled for removal. Reviewing a report does not extend that period. Account deletion removes reports linked to the deleted reporter or reported account sooner. Blocks and sharing restrictions remain while needed to enforce the current sharing choice or restriction and are cleaned up during account deletion.
- Use the selected app’s account-deletion control in the app or on the website, or contact us if you cannot sign in. Once the service accepts a deletion request, it locks the account and begins resumable cleanup; there is no voluntary grace period or undo. Sending a support email does not itself mean deletion has been accepted or completed.
- Cleanup removes your personal profile, private content, uploads and authored shared content, cancels your future trainings and revokes invitations. Other people retain their independently owned records, with only minimal unavailable references where needed. Temporary deletion and retry records expire 30 days after cleanup completes. Unfinished cleanup retains the records needed to finish safely.
- Minimal records of the account ID, Guest account and purchase ownership remain without automatic expiry. They prevent reuse of deleted access and transfer of purchases to another account.
- No automatic expiry does not remove your privacy rights. You may ask us to review whether a retained record is still necessary for its security, ownership or legal purpose.
- Editable RevenueCat customer attributes are removed. RevenueCat customer IDs, aliases, purchase history and provider-controlled system metadata remain. These records can still be linked to an account; they are not anonymous.
- A deletion request applies to the selected app account. It does not delete your accounts in the other apps or cancel, refund or transfer an Apple or Google subscription.
- Support correspondence and security or diagnostic records are kept for as long as needed to resolve the issue, protect the service or address a legal claim. The relevant issue, its resolution and any applicable legal period determine that retention. Business accounting records are kept for the applicable statutory period, separately from ordinary app content.
- Provider backups and operational records can follow a separate lifecycle from live app data. A completed app cleanup is not a claim that every provider backup or legally required store record disappears immediately.
Your Rights
- You can request access to your personal data, correction, erasure, restriction of processing and, where applicable, a portable copy. You may object to processing based on legitimate interests and withdraw any optional consent. These rights have legal conditions and exceptions, including protection of other people’s rights.
- Email apps4equestrians@gmail.com and identify the app and your request. We may ask for proportionate information to verify account ownership. Do not send your password, sign-in codes, payment-card details or private deletion-request tokens.
- We respond to privacy-rights requests without undue delay and normally within one month. If a legally permitted extension is needed because of complexity or the number of requests, we explain the reason within that first month. Requests are normally free.
- You can complain to the Slovenian Information Commissioner (Informacijski pooblaščenec) or the data-protection authority where you live, work or believe an infringement occurred. You do not have to contact us first.
International Processing
- Our providers can process information outside the European Economic Area, including in the United States. Selecting European database or storage locations does not mean all authentication, support, diagnostics or provider operations stay in Europe.
- The applicable provider data-protection terms describe processing locations, subprocessors and transfer arrangements, including EU-approved Standard Contractual Clauses or an applicable adequacy decision. Contact us for information about the safeguards applicable to a particular transfer and a copy of the relevant terms, with confidential material removed where necessary.
Age And Younger Users
- App accounts and Guest access are for people aged 16 or over. If you are 16 or 17, your parent or legal guardian must agree to your use and supervise it. An adult must authorize any paid subscription. These service rules are separate from an app store’s content age rating.
- We do not request a date of birth or identity document as part of ordinary registration, and we do not claim to verify every user’s age. If you believe someone under 16 is using an account, contact us so we can investigate and arrange appropriate deletion or restriction.
Policy Changes
- We update this notice when the service or its data practices change and show the revision date above. We will give an appropriate notice of material changes before new processing begins and ask for consent where the law requires it.