Privacy Policy
Last updated: September 6, 2026
This Privacy Policy explains what information DepthScout (“we,” “us”) collects when you use our website and app, and how we use it. Browsing lakes and depth charts requires no account or profile information.
Information we collect
When you create a free account, we collect:
- Your name and email address
- A securely hashed version of your password (we never store your actual password)
- The fishing spots and waters you choose to save, and any bite alerts you set on them
- Catches you log: species, date, size, bait, private notes, an optional photo, and, when you leave the GPS-stamp option on and location is already allowed, the position where you logged it. Positions are never shown publicly; they power your private pattern stats.
- If you turn on a public profile: your handle, bio and avatar, and the catches you chose to share
- Phone-notification subscriptions you enable, and feedback you send us
- Billing and subscription records, such as checkout status, plan status, renewal dates, payment outcomes, and refunds
- A minimal record of completed Pro product outcomes used to show trial progress and understand whether the subscription is delivering value
- For signed-in production use, one account activity receipt per UTC calendar day used to measure account retention
Payments are processed by Stripe. DepthScout does not receive or store your full card number or card security code. Stripe receives the payment and transaction information needed to provide its payment services.
If you use the live GPS overlay on the water, your device's location is used to show your position on the chart and is processed on your device. The only location we store is the optional position stamp on a catch you log (see above), which stays private to your account. Location data is not sold or shared with third parties.
The browse map loads map tiles from OpenStreetMap and map-label glyphs from OpenMapTiles. Like any third-party web request, those providers can receive your network address, browser request details, and the approximate map area being viewed. When you choose Near me, that viewed area can be close to your device location. DepthScout does not include your account identifier, saved spots, search words, or raw GPS coordinates in those requests.
When a completed water-name search has no match in our catalog, we may keep a normalized, length-limited version of the phrase in a first-party onboarding wishlist. We use that aggregate only to identify missing waters and search aliases. Searches that look like an email address, phone number, street address, postal code, web address, coordinate, or credential are rejected. The record is not tied to an account, advertising identifier, Google Analytics identifier, or precise device location. Abuse protection uses a one-way daily network hash that cannot be reversed to the original address. The limiter record expires after 24 hours and scheduled cleanup removes it within 48 hours. A given network/phrase contributes at most one count per day.
For Pro accounts, the trial-progress record can include the completed outcome, its canonical feature, the in-app surface, a water identifier when relevant, and the time it first occurred. It is tied to the account and subscription generation so retries do not double-count. It does not contain coordinates, spot names, campaign identifiers, or Google Analytics identifiers.
The daily account activity receipt contains only the internal account identifier and UTC date. It does not contain the page or feature used, route, device, browser, campaign, network address, water, event, or location. This first-party retention measurement is independent of the optional Google Analytics and Meta choice and is not used for advertising. Preview and development traffic cannot write it. The receipt is deleted automatically if the associated account is deleted.
In production, Google Tag Manager loads Google Analytics using Google's advanced Consent Mode. Where opt-in is required, analytics and advertising storage remain denied until you allow them. While denied, Google may receive limited cookieless measurement pings with page and coarse device/network context. DepthScout holds its richer lake, search, checkout, and error events only while a regional decision is being resolved. If opt-in is required and no choice is given, or if you decline, those held events are discarded and are not replayed by a later grant. The Meta Pixel requires both advertising-storage and advertising-data consent and does not fire while either is denied. With analytics consent, a 10% sample of lake-page visits also reports page-speed measurements (Core Web Vitals, the page path without query strings or fragments, and coarse connection type) to Vercel Speed Insights; it sets no cookies and stops when consent is withdrawn. When permitted, it measures limited events such as page views, lake views, verified registrations, checkout initiation, trial starts, and first subscription payments. We do not send Meta your name, saved spots, precise GPS location, or card details. With advertising consent, the server-side delivery includes a one-way hashed (SHA-256) form of your email address and account identifier so Meta can match the event to an ad; the readable address is never sent.
DepthScout does not send the words you searched for to Google Analytics or Meta. When product analytics is permitted, search events include only fixed query-length and word-count ranges, result counts, and selected filters. The first-party missing-water wishlist described above is independent of advertising analytics consent and is used only to improve catalog coverage and search quality.
If analytics or advertising consent is denied, or where opt-in is required and has not been given, DepthScout does not attach the corresponding analytics, advertising, or campaign identifiers to a new checkout record. With permission, a checkout can temporarily store Google Analytics client/session identifiers, Google or Meta click identifiers, Meta browser identifiers, the browser user-agent string and network address of the checkout request (with advertising consent only, because Meta requires them to match a website conversion), and limited campaign fields so a real Stripe trial or first payment can be attributed. Browser, network, and click identifiers are removed within seven days when a checkout does not complete, and within 14 days after a completed checkout once its trial and first payment have been reported. Limited campaign fields may remain with a completed billing record for first-party attribution. Consented campaign context may be kept on your device for up to seven days so a passwordless sign-in or later paid-campaign return can resume in a new tab; it is cleared after checkout starts or on denial.
With the corresponding current consent, a confirmed Stripe trial start can be sent to Google Analytics and Meta, and a confirmed first subscription payment can be sent as a purchase. These deliveries use an opaque duplicate-prevention identifier and are retried for no more than 72 hours. They do not include your name, card details, saved spots, or precise location. With advertising consent, the Meta delivery includes a one-way hashed form of your email address and account identifier, plus the browser user-agent string and network address recorded at checkout, which Meta requires to match a website conversion. Renewals, refunds, and subscription-status changes are not sent to advertising platforms. Stripe and DepthScout's first-party billing records remain the source of truth for revenue, trials, renewals, refunds, and subscription status.
You can change or withdraw your analytics and marketing choice at any time. Essential account, security, and billing functions continue to work either way.
How we use your information
- To create and secure your account
- To save and sync your saved fishing spots
- To send account-related emails (verification, password reset)
- To operate subscriptions, provide billing support, prevent duplicate processing, and reconcile account access
- To measure aggregate account retention, understand usage patterns, and improve DepthScout
What we don't do
We don't sell your personal information. We don't share your saved spots, precise location, name, or payment details with advertising services, and we never share your readable email address with them. When measurement is permitted, Google and Meta receive only the limited analytics and advertising events described above. Under California law the advertising events may count as "sharing"; you can turn them off at any time below, and browsers that send the Global Privacy Control signal are treated as having done so.
Data retention & deletion
We keep account and product information while your account is active. If you ask us to delete your account, we delete or de-identify the associated product data. We may retain limited billing and transaction records for as long as reasonably necessary for accounting, tax, fraud prevention, disputes, and other legal obligations. Stripe may retain payment records under its own privacy and legal obligations. Daily activity receipts are deleted about 13 months after their UTC day, and always removed immediately with their account. Analytics and advertising consent preferences are deleted with the associated account. Vendor-delivery receipts contain only opaque internal source identifiers and operational status; they do not store event payloads or vendor credentials. New-policy missing-water aggregates are deleted one year after their last accepted signal. Existing aggregates are preserved at the policy cutover and receive the same forward retention window; their phrases and historical counts are not rewritten. You can download everything we hold about your account, or delete the account yourself, from Settings → Your data. Deleting the account cancels any Pro subscription, removes your catch photos and avatar from storage, and deletes the account record; billing ledger rows keep their Stripe identifiers for our books but no longer reference you. You can also email support@depthscout.com.
Security
Passwords are hashed and never stored in plain text, and account sessions use secure, HTTP-only cookies. No method of storage or transmission is 100% secure, but we take reasonable steps to protect your information.
Children's privacy
DepthScout is not directed at children under 13, and we do not knowingly collect information from children under 13.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above.
Contact us
Questions about this policy or your data? Reach out through the feedback link in the app, or email support@depthscout.com.
See also our Terms of Use.