BoosterMap
The app Features Launch
The app Features Launch
Legal

Privacy Policy

Internal test draft. Registration remains available for internal beta testing. The operator identity below is an explicit placeholder and must be replaced with verified details before public release.
Operator / controller
[TEST PLACEHOLDER: operator name - replace before public release]
Registration number
[TEST PLACEHOLDER: registration number - replace before public release]
Registered office
[TEST PLACEHOLDER: registered office - replace before public release]
Legal and privacy contact
not-for-public-release@example.invalid

Version: 2026-07-24. Effective date: 24 July 2026.

This Privacy Policy explains how the operator identified above processes personal data when you use BoosterMap. We process only the data needed to provide the booster-stock map, accounts, notifications, moderation, safety and support. We do not sell personal data and we do not use advertising SDKs.

Data we process and why

  • Account and authentication: email, handle, password hash where email sign-in is used, Google or Apple provider subject, session and device records. These are needed to create and secure the account.

  • Legal acceptance: the accepted Terms version and time, acknowledged Privacy Policy version and time, and source channel. These records demonstrate contract formation and delivery of privacy information.

  • Community activity: place, game, stock state, report time, optional comment, photo, moderation state, reputation and reward events. This provides community stock history and protects its reliability.

  • Location: precise coordinates are used for a user-requested nearby search. When separately enabled for Nearby stock alerts, one current location is stored and overwritten rather than used to build a location history.

  • Notifications: push token or web-push subscription, category preferences, delivery status and short-lived delivery diagnostics.

  • App delivery: app/runtime version, platform and ordinary update-request metadata needed to deliver compatible mobile updates.

  • Moderation and safety: reports, evidence, reporter contact, block/strike decisions, statement-of-reasons records and abuse/security logs.

  • Purchases when paid features are enabled: store, product, entitlement, renewal/expiry and transaction or webhook identifiers. We do not receive your full payment-card details from the app stores.

  • Support and diagnostics: messages you send and technical crash/error context required to diagnose failures, including native Firebase Crashlytics reports and Sentry events if Sentry is enabled.

Lawful bases

  • Contract: account creation, sign-in, session security, requested app features, community reports, support and any subscription entitlement you purchase.

  • Consent: precise device location and user-requested push notifications where platform permission or consent is required. You may withdraw these choices in the app or device settings without affecting earlier lawful processing.

  • Legitimate interest: anti-abuse rate limiting, service security, reputation weighting, moderation, fraud prevention, diagnostics and correction of public business listings. You may object; we then assess whether compelling grounds require continued processing.

  • Legal obligation: records required for tax/accounting, consumer claims, authority requests and applicable online-safety duties.

  • Legal claims: limited records may be restricted and retained where necessary to establish, exercise or defend a legal claim.

Providing account identifiers and authentication data is necessary to enter into and perform the account contract. Without them we cannot create or secure an account. Location, push permission and marketing consent are optional; the core map remains available without them.

Location consent

  • Nearby search uses precise location only after your request and does not create a location history.

  • Nearby stock alert location is stored only after the separate control is enabled, as one current value used for matching nearby reports.

  • The stored value is removed when consent is withdrawn, the push token becomes invalid, the account is deleted, or the value is older than 30 days.

Notifications

User-requested push notifications are limited to two transactional categories:

  • Reward updates: badges, approved places, monthly city top-3 results, manual Credit adjustments and gifted Pro weeks.

  • Nearby stock: fresh stock signals that match the user's current nearby location or active watchlist.

Marketing notifications are disabled by default and are not part of either transactional category. Any future marketing messages require a separate opt-in consent that can be withdrawn independently.

Automated tools and human review

Submitted text and shelf photos may be screened by an automated OpenAI moderation service for safety categories. A flag routes or informs moderation; it does not by itself make a final decision with legal or similarly significant effect. Account or content restrictions are subject to human rules and redress. Reputation and nearby-stock matching rank or select community information, but we do not use solely automated decision-making that produces legal or similarly significant effects within the meaning of GDPR Article 22.

Retention schedule

  • Account profile data is kept while the account exists and during the disclosed 30 days deletion grace window.

  • At final account deletion, credentials and personal identifiers are erased; useful stock facts are retained only after removal of author, client UUID, comment/hash, photo and reporter-location metadata.

  • Last-known alert location is overwritten on update and purged after 30 days without refresh.

  • Notification delivery logs are retained for 90 days.

  • Rejected shelf photos and their pending objects are removed after 30 days.

  • Moderation free text is redacted after 12 months; structured safety/DSA records are retained only for the documented accountability or legal-claim period and with restricted access.

  • Billing, refund, tax and legal-claim records are kept for the period required by applicable law or until the relevant claim period expires.

  • Encrypted backups are access-restricted and expire under the backup schedule; any restored data is re-subjected to completed deletion requests.

Account deletion

In-app account deletion immediately revokes API tokens, all web sessions and password-reset credentials, removes registered devices and disables alerts. A 30 days restoration window then applies. At its end the account is hard-deleted and retained community facts are de-attributed as described above. Anonymous aggregate counts may continue to record that an account registration, deletion request or completed purge occurred, but contain no per-user row, email, UUID or recomputable user hash.

Deleting a BoosterMap account does not cancel an App Store or Google Play subscription. Subscription cancellation must also be completed in the relevant store settings. Store, accounting, fraud-prevention or legal records may remain with the store, RevenueCat or the operator where a legal retention ground applies.

Community reports and photos

Stock reports may remain as anonymous place history after account deletion only once unnecessary attribution has been removed. Shelf photos are reviewed before public display, may be removed through moderation, and are deleted during account purge or an upheld takedown. Do not upload photos of identifiable people or personal documents.

Processors and recipients

  • Roští.cz: EU application/database hosting, queues, server logs and transactional email transport.

  • Cloudflare: DNS, CDN and R2 object storage for photos and backups, plus the Worker, D1 release metadata and private R2 bundles used to deliver mobile updates.

  • Google: Google Sign-In, FCM and browser push delivery, Firebase Crashlytics for native crash diagnostics, Google Places for public-place enrichment when configured, and Google Play purchase processing when paid features are enabled.

  • Apple: Sign in with Apple, APNs and Safari push delivery, and App Store purchase processing when paid features are enabled.

  • Mozilla: browser-selected Web Push delivery when a Firefox subscription uses Mozilla Push Service.

  • Expo: mobile build/update tooling and legacy push delivery where an installed build still uses an Expo token.

  • RevenueCat: subscription purchase and entitlement synchronisation when consumer subscriptions are enabled.

  • OpenAI: automated safety screening of submitted text and images, with the final restriction process described above.

  • Sentry: error diagnostics if enabled, with request and personal-data scrubbing.

  • OpenFreeMap: external map style and tile delivery. The service receives ordinary HTTP request metadata and the map area requested by the client.

Public map/business facts can also originate from OpenStreetMap and Overture Maps. Google Places may be queried by the backend for public-place enrichment when configured. BoosterMap does not intentionally send an account identifier with those import/enrichment queries. See the Attribution page.

International transfers

Some processors or store providers may process data outside the European Economic Area. Where GDPR Chapter V requires a transfer safeguard, the operator relies on an applicable adequacy decision or the European Commission's Standard Contractual Clauses together with supplementary measures as appropriate. Contact us for the applicable safeguard or a copy of its relevant terms. Final processor contracts and transfer assessments are a launch gate.

Your rights

Subject to the GDPR conditions and exceptions, you may request access, correction, erasure, restriction, portability, or object to legitimate-interest processing. You may withdraw consent at any time and complain to the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz). Use the legal and privacy contact listed above. We may need proportionate information to verify that a request concerns your account.

Changes

The version above identifies this notice. Material contractual changes will use a new version and, where required, a fresh acceptance flow. Privacy-notice changes will be communicated in an appropriate form; we will not silently record historical users as having accepted a document they did not receive.

BoosterMap is a mobile-first TCG discovery app.
Support Privacy Terms Cookies Attribution DSA contact