Privacy Policy

Effective date: August 2026 — Shot Data Tracker

Short version: Shot Data Tracker does not sell personal data, show advertising, or track you across other companies' apps and websites. Limited providers help host and protect the service, deliver optional verification email, and provide weather only when you request it. You can export your records and permanently delete your account from the app.

1. About this service

Shot Data Tracker is a website and official application set for logging shooting sessions, analyzing results, and taking part in competitions. The default service is available through www.shotdatatracker.com.

2. Data we process

Account information

  • Username and internal account ID
  • Optional email address, used for account verification and support
  • A PBKDF2 hash of your password; the plaintext password is not stored

Shot records and files

  • Session name, date, entered location, caliber, rifle, shot count, distance, temperature, wind, confidence, zero-check status, and notes
  • Ammunition and load details
  • Target photos and CSV shot-data files you upload
  • Custom option lists, templates, presets, and timestamps

Competitions and community content

  • Competition titles, descriptions, participation, roles, scores, group measurements, notes, target photos, and leaderboard results
  • Comments you post and the username displayed beside them
  • Users you block and confidential reports you submit for moderation
  • Moderation status and administrator action on reported content

Competition content is shared with the participants and organisers of that competition. Leaderboards show participant usernames and results according to the competition settings.

Service activity

The hosted service records the normalized page or service route without its query string, action and request method, connection IP address, account ID when signed in, timestamp, response status and reason, duration, response size, and a short bounded diagnostic for completed errors. It does not record request or form content, URL query values, uploaded file names, device fingerprints, advertising identifiers, or user-agent strings in this activity log.

Device and weather data

Official clients may store app preferences, server selection, disclosure acknowledgements, presets, and account-scoped offline entries on your device. If you choose Autofill Weather, the entered location name is sent directly to Open-Meteo for geocoding; the resulting latitude and longitude are then sent to its forecast service. Open-Meteo also receives your request IP address. The app discloses this before the first request, and weather autofill is optional.

3. Your choices

Export and correction

You can export your shot data in CSV or JSON and edit or delete individual records. You can update your optional email address and password from Account.

Delete your account

In the iOS app, open Account > Account Deletion > Delete Account. After re-entering your password and confirming, the service deletes your account, shots, files, options, competition comments and entries, reports, blocks, notifications, and competitions you created. The app also removes that account's pending offline records and local presets. Temporary demo accounts are deleted when you choose End & Delete Demo, and also expire automatically. If you cannot access your account, email [email protected].

4. Storage and access

  • Private shot records are scoped to your account. Competition content is visible to the relevant participants and organisers.
  • Pending iOS records and media are isolated by server and immutable account ID and use iOS file protection where supported.
  • Authorized administrators can access account content when necessary for support, security, service operation, and community moderation. Administrator impersonation is restricted to administrators.
  • Sessions use signed cookies containing an internal user ID, session version, and expiry. They normally expire after seven days.

5. Cookies

The hosted web app uses sdt_session to keep you signed in. Administrator impersonation may temporarily use sdt_admin_backup. These HttpOnly, SameSite cookies are not used for advertising or cross-site tracking. No third-party cookies are set by the application.

6. Providers and disclosure

We do not sell or rent personal data and do not use it for third-party advertising. Data is disclosed only as needed to provide, secure, and support the service:

  • Cloudflare helps deliver and protect the hosted website and receives network information such as IP address and request metadata.
  • Resend receives your email address and verification-message contents only when email verification is configured and you provide an email.
  • Open-Meteo receives the location query, derived coordinates, and request IP only when you request weather autofill.
  • jsDelivr delivers the Chart.js and PDF-export libraries used by the signed-in web app and receives normal network request information such as your IP address and browser request metadata. Shot and account request bodies are not sent to jsDelivr.
  • Hosting and infrastructure providers process stored records and service logs on our behalf.
  • Competition content is shared with participants and organisers as described above.
  • Information may be disclosed when required by applicable law or to protect users and the service.

7. Analytics and tracking

First-party activity data is used to secure and operate the service, understand feature use, assess response health, and diagnose errors. Detailed events are available only to administrators. The application has no advertising SDK, cross-app tracking SDK, social pixel, or device fingerprinting.

8. Hosted and custom servers

The default service is hosted at www.shotdatatracker.com. Some client builds allow you to choose a compatible HTTPS server. When you choose another server, its operator receives and controls the account and shooting data you send there under that operator's privacy terms. Shot Data Tracker cannot control or delete data held by an independently operated server.

9. Retention

Account and shot data is retained while your account exists. Open moderation reports remain while investigated; resolved or dismissed reports are removed after up to 365 days. Service activity is retained for up to 400 days, while IP addresses and bounded diagnostics are cleared after 90 days. Account deletion also deletes associated activity events.

10. Security

Controls include HTTPS for production iOS connections, PBKDF2 password hashing, signed cookies, CSRF protections, authentication rate limits, per-user database and file scoping, Content Security Policy headers, iOS file protection for pending media, and community filtering, reporting, blocking, and moderation tools. No internet service can guarantee absolute security; protect your password and keep your devices updated.

11. Changes

Updates appear at this URL, with the effective date changed above. Material changes may also be communicated in the service or application.

12. Contact

For privacy questions or account help, email [email protected] or visit the Support page.