Privacy Policy

Effective date: July 2026 — Shot Data Tracker

Short version: Your data belongs to you. Shot Data Tracker is a proprietary hosted service and official client application set. Access is provided only through www.shotdatatracker.com and the associated official macOS, iOS, Android, and Windows applications. You can export or delete your data at any time. No data is shared with third parties, and no advertising or third-party tracking services are used. Limited first-party service activity is recorded for security, reliability, and an administrator-only activity dashboard.

1. What is Shot Data Tracker?

Shot Data Tracker is a proprietary website and application set for logging shooting sessions. The service is accessed through www.shotdatatracker.com and the associated official client applications for macOS, iOS, Android, and Windows.

Shot Data Tracker is not open source. No source code access is provided to users, customers, or the public, and this policy does not grant permission to inspect, copy, modify, redistribute, or self-host the source code or service.

2. Data You Provide

When you use this application, the following information is stored:

Account information

  • Username (required to create an account)
  • Email address (optional; used only for account verification if provided)
  • A hashed copy of your password (the plaintext password is never stored)

Shot session data

  • Session name, date, location, caliber, rifle
  • Number of shots, distance, temperature, wind
  • Confidence rating, zero-check status, notes
  • Ammunition details (bullet name, powder, load/charge, primer, factory ammo)
  • Target photos and CSV shot data files you upload
  • Timestamps for when entries were created

Configuration data

  • Your custom option lists (locations, calibers, rifles, primers, factory ammo)
  • Saved filter presets

Service activity data

Shot Data Tracker records a minimal first-party activity event when a page or service route is used. Each event contains:

  • The page or normalized service route, without its query string
  • The action type and request method
  • The response status and timestamp
  • Your account ID when you are signed in; public page views are recorded without a visitor identifier

These events do not contain IP addresses, device fingerprints, user-agent strings, request or form contents, URL query values, uploaded file names, or advertising identifiers.

3. Your Rights and Control

You have full control over your data. You can export everything you have entered, and request deletion at any time.

Export your data

You can download a complete copy of all your shot data at any time from your Account page in both CSV and JSON formats. These exports include every field you have entered.

Delete your data

You may request deletion of your account and all associated data by contacting Shot Data Tracker through the official website or client application support channel. Upon deletion, all shot records, uploaded files, option configurations, and account information are permanently removed from the service.

Correct your data

You can edit or delete individual shot entries directly from the application at any time. You can update your email address and password from your Account page.

4. How Data is Stored

  • Service-side data is stored in a SQLite database and file directory on Shot Data Tracker service infrastructure.
  • Every piece of data is scoped to your user account — other users cannot access your records.
  • Uploaded files (target photos, CSV files) are stored in a directory named after your username.
  • Official client applications may store limited local data on your device, such as app preferences, cached account state, or pending offline entries waiting to sync.
  • Passwords are hashed using PBKDF2 before storage. Plaintext passwords are never saved.
  • Sessions are managed via a cryptographically signed cookie (sdt_session) with a 7-day lifetime. No session data is stored server-side.

5. Cookies

This application uses a single session cookie (sdt_session) to keep you logged in. This cookie:

  • Contains only a signed session token — no personal data
  • Expires after 7 days
  • Is marked HttpOnly and SameSite=Lax to protect against cross-site attacks
  • Is not used for tracking or advertising

No third-party cookies are set by this application.

6. No Third-Party Sharing

Your data is not sold, rented, or shared with any third parties. It is not used for advertising, profiling, or any purpose other than providing you the application's functionality.

The only potential external service contact is email verification (if you provided an email and email verification is enabled). Your email address is used solely to send you a verification link and is not shared with any other party.

7. First-Party Activity Reporting

Shot Data Tracker uses the limited service activity data described above to understand current traffic, historical usage, response health, and feature interaction. Detailed reporting is available only to administrator accounts.

The application does not include third-party analytics scripts, advertising networks, social media pixels, cross-site tracking, or device fingerprinting. No activity data is sent to an external analytics or advertising service.

8. Service Access and Software Ownership

Shot Data Tracker is operated as a proprietary service. The only supported ways to access the service are through www.shotdatatracker.com and the associated official macOS, iOS, Android, and Windows client applications.

No source code access is provided. Access to the service or client applications does not include any right to receive, inspect, copy, modify, redistribute, reverse engineer, or self-host the source code or server software.

9. Data Retention

Your shot and account data is retained for as long as your account exists. You may request deletion of your account and all associated data at any time. There is no automatic expiry of shot records.

Service activity events are retained for up to 400 days. If an account is deleted, its identifier is removed from retained activity events so those events can no longer be associated with that account. Disposable demo activity is deleted with the demo account.

10. Security

This application implements several security measures to protect your data:

  • CSRF protection on all data-mutating requests
  • Rate limiting on authentication endpoints
  • Cryptographically signed session cookies
  • PBKDF2 password hashing
  • Per-user file and database scoping
  • Content Security Policy headers

However, security also depends on how you protect your account credentials, keep your devices updated, and use the official website or official client applications.

11. Changes to This Policy

If this privacy policy changes, the updated version will be available at this URL. The effective date at the top of the page will reflect when it was last revised.

12. Contact

For questions about this privacy policy or to request deletion of your data, contact Shot Data Tracker through the official website or the support channel provided in the official client applications.