CatchTrack Privacy Policy
Last updated: June 2026
This Privacy Policy describes how CatchTrack ("we", "us", "our") collects, uses, and protects information when you use the CatchTrack mobile application and web service (the "Service"). By using CatchTrack, you agree to the terms of this policy.
1. Information We Collect
Information you provide:
- Account info: email address, password (hashed — we never store your plaintext password), full name (optional).
- Fishing operation data: vessels, captains, trips, fish tickets, expense receipts, crew members, logbook entries, GPS coordinates, weather notes, and any other information you enter into the app.
- Payment information: when you purchase a paid feature, payment details (card number, expiry, CVC) are sent directly to Stripe, our payment processor. We never see, store, or log your card numbers. We only receive a payment confirmation from Stripe.
Information collected automatically:
- Device info: device type, operating system version, and app version — for crash reporting and bug fixes.
- Usage info: which features you use and when, so we can improve the app.
- Photos: when you scan a fish ticket or receipt, the image is uploaded to our servers and processed by an AI service (OpenAI, via Emergent Integrations). The image is then stored on your account for your reference. The image is not used to train any AI models.
- Location: when you tap the GPS button in the Daily Logbook, we capture your latitude and longitude. We never collect location continuously or in the background.
2. How We Use Your Information
We use your information only to:
- Provide the CatchTrack service (store your data, sync across devices, generate reports).
- Process payments via Stripe.
- Extract data from your photos via AI OCR.
- Improve the app (bug fixes, feature improvements).
- Send service-related emails (account verification, payment receipts, important changes). We do NOT send marketing emails unless you opt in.
3. Sharing Your Information
We do NOT sell your data. We share data only with these third parties, and only as needed:
- Stripe: We share the payment info you enter on the Stripe Checkout page. Purpose: to process payments.
- OpenAI (via Emergent Integrations): We share the fish ticket or receipt photo you scan. Purpose: to extract structured data via AI OCR. OpenAI does not retain images for training, according to their API terms.
- MongoDB Atlas and the Emergent platform: We share all your account data. Purpose: hosting and storage.
We will share information with law enforcement only when required by a valid court order or subpoena.
4. Your Rights and Choices
You can at any time:
- View and edit any of your data in the app.
- Export all your data as a CSV file from Settings and Export.
- Delete your account by emailing support@catchtrack.app from the email address on your account. We will permanently delete all your data within 30 days.
- Cancel a subscription from Settings and Subscription and Billing or from the Stripe billing portal.
If you are a resident of the European Union, United Kingdom, California, or another jurisdiction with privacy laws granting additional rights, such as GDPR or CCPA, you may have the right to:
- Access a copy of your data.
- Correct inaccurate data.
- Request deletion, also known as the right to be forgotten.
- Object to processing.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email support@catchtrack.app.
5. Data Retention
We retain your data for as long as your account is active. If you delete your account, your data is removed within 30 days. Stripe retains payment records longer according to their own legal requirements, typically 7 years for tax and accounting compliance. For more details, see Stripe's privacy policy at stripe.com/privacy.
6. Security
- All data in transit is encrypted using HTTPS and TLS.
- All data at rest is encrypted on our servers.
- Passwords are hashed using industry-standard bcrypt. We cannot see your password.
- Payment data is handled exclusively by Stripe, which is PCI-DSS Level 1 certified. We never handle raw card data.
No system is completely secure. We commit to notifying affected users within 72 hours of discovering any breach that could put their personal data at risk.
7. Children's Privacy
CatchTrack is not intended for users under 13 years old. We do not knowingly collect data from children under 13. If you believe a child has signed up, contact support@catchtrack.app and we will delete the account.
8. Changes to This Policy
We may update this policy from time to time. When we do, we will update the Last updated date at the top. Material changes will be communicated via an in-app notice or email at least 14 days before they take effect.
9. Contact Us
If you have questions or concerns, email support@catchtrack.app.
If you live in a jurisdiction with a data protection authority, such as the ICO in the United Kingdom, you can also lodge a complaint there directly. We would appreciate the chance to address your concerns first.
CatchTrack is operated by Alaska Maintenance & Rental, P.O. Box 1021, Kodiak, AK 99615.