Skip to the content
Privacy

What is collected, and what is not

One person runs this. There are no advertisers, no trackers sold to anybody, and no profile being assembled. What follows is the whole of it.

The short version

An email address, because a pass has to belong to somebody. What you paid, because a shop has to be able to reconcile what it took. Which stops you have marked, and any day you have saved, because both are yours to come back to. Nothing else.

Where you are standing never leaves your phone. The app reads your location to sort stops by distance and to tell you when you have arrived. It is used on the device and discarded. It is never sent here, never stored, and never asked for in the background.

A place you tick off is different, and it is worth being exact about the difference. Ticking is something you did on purpose, and if you are signed in it is kept, so that a visit in one year still counts in the next. That is a list of places, not a record of your movements: it holds what you marked, never where your phone was. How far through today’s route you are stays on the device and is never sent at all.

What is held, and why

  • Your email address. Signing in is a one-time code to an address, so there is no password here to lose. The address is what a pass attaches to on both surfaces.
  • A purchase record. What was bought, when, how much, and the Stripe session it came from. Card numbers are never seen by this site. Payment happens on Stripe’s own checkout; what comes back is an amount, a status and the email you paid with.
  • Your pass. Which pass, how many days, and when the clock started. The clock starts the first time the pass is opened, not when it is paid for, so that date is recorded on first use.
  • Which places you have stood in. If you are signed in on the app, a place you tick off is kept against your account, so that coming back in another year, or on another phone, still knows what you have already done. Nothing more than the place and the date it became true.
  • Any day you saved. The name you gave it and the places in it.
  • A waitlist address, if you left one. With the town you asked for, which is the only thing deciding which town is made next. One email to confirm, and one when it opens.

Location, in detail, because it is the one that matters

The app asks for location only while you are using it. There is no background location, no always-on permission, and no motion tracking: those are switched off in the app’s own configuration, not merely unused.

It is read to do two things, both on the phone: put the nearest stop at the top of the list, and notice when you have arrived at one. No coordinate of yours is transmitted to this site or to anyone else. If you refuse the permission, everything still works except the sorting and the arrival notice.

The map is the same story from the other side. The tiles are served from our own storage rather than from a commercial map provider, so panning around a town does not report your route to a third party.

Who else touches it

Four companies, each doing one job, none of them given anything beyond it:

  • Supabase, which holds the database and the sign-in, in the United States.
  • Stripe, which takes the payment. Your card details are theirs, not ours, and their privacy terms govern them.
  • Resend, which sends the sign-in code and the receipt.
  • Vercel, which hosts this, and counts page views in a way that is aggregate and cookieless. It measures which pages are read, not who read them.

Nothing is sold, and nothing is handed to an advertiser. There is no advertising here to hand it to.

What is counted, and what is not

The app adds one to a counter when a route is opened, so that the catalogue can eventually say which routes people use rather than guessing. That is the whole of it: a number against a route and a date, with no account, no device identifier and no time more precise than the day.

It is not a record of where you went. It counts a route being opened on the catalogue screen, not stops visited, and there is nothing in it that could be traced back to a person, including by us. Which stops you have ticked off stays on your phone and is never sent here at all.

Cookies

One, and it is the session: the cookie that remembers you are signed in. There are no advertising cookies and no third-party trackers, which is why this site has never asked you to accept anything.

Deleting your account

You can delete it yourself, from the app or from your account page on this site. There is no grace period and no soft delete: the account stops existing when you press the button.

One email is sent as it happens, to the address on the account, confirming the deletion and what stayed. It is the receipt for the operation and it is the last thing sent to that address: nothing is kept in order to send anything else.

One honest caveat: the live database forgets you immediately, and the backups taken before you left still hold what was in them until they expire on their own. They are never used to bring an account back.

Your pass, the places you have ticked off, your progress and your saved days all go with it. One thing survives, and it is worth saying plainly: the purchase record stays, with your account removed from it. A shop has to be able to reconcile what a payment processor says it took, and an anonymised row does that without keeping a customer who asked to be forgotten.

If you would rather ask than press a button, or you want a copy of what is held first, contact support.

What you can ask for

Three things, and none of them need a reason given.

A copy of what is held. Ask on the support page and you will be sent it. A correction. A place ticked off by mistake can be taken back off your list in the app, on the stop itself, and your email address is corrected by signing in with the right one. Deletion, which is the button described above.

Nothing here is sold, and there is nothing to opt out of being sold. No profile is built, no data goes to an advertiser, and nothing is shared with a data broker.

If you write to support

The support page is a form rather than an address, because nothing receives mail at this domain. What you send is kept with the address you gave, so that it can be answered and so that the same fault reported twice is recognised as the same fault. It is not used for anything else and never joins a mailing list.

A support message outlives a deleted account on purpose: asking for an account to be deleted is itself a support message, and one that vanished with the account could not be confirmed.

Children

Standshot is not directed at children under 13, and no account is knowingly created for one.

Changes

If this policy changes in a way that affects what is collected, the date below moves and the change is described here rather than quietly folded in.

Who holds it

The data described here is held by IberiaTech Solutions LLC, a limited liability company registered in South Carolina and based in Charleston, which makes and sells Standshot. It is the same company named in the terms and wherever the app is listed. To ask what is held about you, or to have it removed, use the support form, which reaches the same place.

Last updated 29 August 2026