snagz ✩
Privacy Policy
Last updated: August 30, 2026
This policy explains what we collect, why, and what we do with it, for both the snagz website and the snagz iOS app. Short version: we collect the minimum needed to run drops, memberships, and shipping; we don't sell your data; and we don't use your data to track you across other companies' apps or websites.
1. What we collect
- Account: you sign in with Apple or Google — no password ever exists on snagz. We store your chosen handle and avatar (emoji + color), account timestamps, the stable account identifier the provider gives us, and (if shared) your email address — used only to recognize your account when you sign in again, never for marketing. With Apple you can hide your real email; the private relay address works fine. No phone number is required.
- Shipping details: name, address, and optional phone number — only if you buy a physical item or save an address. Used solely to fulfil and support your orders.
- Purchases & membership: which items you won, prices paid, and your membership status. Card details are handled entirely by Stripe (our payment processor) and never touch our servers. Stripe's privacy policy: stripe.com/privacy.
- Live activity: when you watch, hold, or win in a live drop, your handle and avatar appear to other users in the room and in the app's activity feed (that's the point of a live auction). Prices you paid for wins can appear there too.
- Usage analytics (website only): the website uses Google Analytics 4 to understand feature usage (e.g., screens viewed, checkout funnel events). The iOS app contains no third-party analytics or advertising SDKs.
- Technical logs: standard server logs (IP address, timestamps, requests) kept briefly for security and debugging.
- Bot protection (website only): account sign-up on the website is protected by Cloudflare Turnstile, which runs invisibly (no puzzles). Cloudflare processes limited device and network signals to tell humans from bots, as described in the Cloudflare Turnstile Privacy Addendum. We only receive a pass/fail token.
2. What we do NOT do
- We do not sell or rent your personal information.
- We do not use your data for third-party advertising or cross-app/site tracking, and the iOS app performs no "tracking" as defined by Apple's App Tracking Transparency.
- We do not collect precise location, contacts, photos, or health data. The app requests no sensitive device permissions.
3. Why we process data (legal bases)
To perform our contract with you (running drops, memberships, shipping orders); our legitimate interest in securing and improving the Service (logs, aggregate analytics); and your consent where required (e.g., optional analytics cookies on the web).
4. Sharing
We share data only with processors needed to run the Service: Stripe (payments & membership billing), shipping carriers (name/address to deliver your order), Google Analytics (website usage events), Cloudflare (Turnstile bot protection on website sign-up), and our hosting infrastructure. If you sign in with Apple or Google, those providers authenticate you under their own privacy policies; they do not receive your snagz activity from us. Each processes data under their own agreements and only on our instructions. We may disclose information if the law requires it.
5. Retention & deletion
- Account data is kept while your account exists.
- You can delete your account in the app (Profile → "delete my account") or on the website profile. This permanently deletes your profile, handle, saved addresses, and win history, cancels any active membership, and deletes your customer record at Stripe. Transaction records that we must keep for tax/accounting law are retained in de-identified form for the statutory period.
- Server logs are rotated within 30 days.
6. Your rights
Depending on where you live (e.g., GDPR, UK GDPR, CCPA/CPRA), you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object to certain processing. Contact us (below) and we will respond within the legally required time. We do not discriminate for exercising rights. California residents: we do not "sell" or "share" personal information as defined by the CCPA.
7. Children
The Service is not directed to children under 16, and we do not knowingly collect data from them. If you believe a child has an account, contact us and we will delete it.
8. Security
Data is encrypted in transit (TLS). Payment credentials are held only by Stripe. Access to production data is limited to operators who need it.
9. Changes & contact
We'll post updates here and note material changes in the app. Contact for privacy matters: mosh@neocore.co — or see support.