Privacy Policy
- App
- Trailmark for iOS, iPadOS and macOS
- Effective
- 1 October 2026
- Last updated
- 1 October 2026
- Version
- 1.0
Summary
This policy explains what Trailmark (“the App”) collects, why, and what control you have. The detail follows; the short version is:
- We collect the minimum needed to run the App — your account email, the content you create, and basic diagnostics.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
- We do not track you across other companies’ apps and websites unless you give permission through the iOS tracking prompt. You can say no, and the App still works.
- You can delete your account and all associated data from inside the App, at any time — Settings → Account → Delete Account.
- You can reach a human at privacy@example.com.
Who we are
Northbay Labs, Inc. (“we”, “us”) is the developer of Trailmark and is the data controller for the personal data described in this policy. We are registered in the United States.
This policy covers the App and https://example.com. It does not cover third-party services you choose to connect to the App, which are governed by their own policies.
Data we collect
The categories below use the same names Apple uses in the App Store’s privacy labels, so you can compare this policy against the App’s listing on the App Store directly.
| Data | Examples | Why we collect it | Source | Treatment |
|---|---|---|---|---|
| Contact Info | Email address, display name | Create and secure your account; send service messages such as password resets | You provide it | Linked to you |
| User Content | Notes, photos, files and other content you create in the App | Store and sync your content across your devices | You provide it | Linked to you |
| Identifiers | Account ID, device identifier for push notifications | Keep you signed in; deliver notifications you have enabled | Generated automatically | Linked to you |
| Purchases | Subscription status, transaction identifier | Unlock paid features and restore purchases | Apple (we never see your card details) | Linked to you |
| Usage Data | Screens opened, features used, session length | Understand which features are used so we can improve them | Collected automatically | Not linked to you |
| Diagnostics | Crash logs, error traces, performance data, OS and device model | Find and fix crashes and performance problems | Collected automatically | Not linked to you |
| Location (optional) | Approximate location, only while the App is open | Show nearby results — only if you grant permission | You permit it | Linked to you |
What we never collect: we do not collect your payment card details (Apple handles all in-app purchases), your contacts, your health data, your browsing history outside the App, or your precise background location.
App Store privacy labels
Apple groups data into three treatments on the App Store product page. This is how our disclosures map onto them:
| Apple treatment | What it means | What we declare |
|---|---|---|
| Data used to track you | Data linked to you and shared with other companies for advertising or measurement | None, unless you accept the iOS tracking prompt — see section 8 |
| Data linked to you | Data tied to your identity or account | Contact Info, User Content, Identifiers, Purchases, Location |
| Data not linked to you | Data collected without any link to your identity | Usage Data, Diagnostics |
How we use your data
We use personal data only for the purposes below. Where the GDPR or UK GDPR applies, the legal basis for each purpose is given in the final column.
| Purpose | Data used | Legal basis (EEA / UK) |
|---|---|---|
| Provide the App and sync your content | Contact Info, User Content, Identifiers | Performance of a contract |
| Authenticate you and keep accounts secure | Contact Info, Identifiers, Diagnostics | Performance of a contract; legitimate interests (security) |
| Manage subscriptions and restore purchases | Purchases, Identifiers | Performance of a contract |
| Fix crashes and improve performance | Diagnostics | Legitimate interests (maintaining a working product) |
| Understand feature usage in aggregate | Usage Data | Consent, where required |
| Show nearby results | Location | Consent (the iOS permission prompt) |
| Respond to support requests | Contact Info and anything you send us | Legitimate interests (customer support) |
| Meet legal and tax obligations | Purchases, Contact Info | Legal obligation |
We do not use your personal data to train machine learning models, and we do not make decisions about you by automated means that produce legal or similarly significant effects.
Device permissions
iOS asks for your permission before the App can use any of the following. Every one of them is optional, you can change your answer at any time in iOS Settings → Trailmark, and declining does not stop the rest of the App from working.
| Permission | What we do with it | If you decline |
|---|---|---|
CameraNSCameraUsageDescription | Capture a photo to attach to your content. Images are processed on your device and uploaded only when you save them. | You can still attach images from your photo library or use the App without images. |
Photo LibraryNSPhotoLibraryUsageDescription | Let you choose an existing image to attach. We only ever receive the images you pick. | You can still use the camera or skip attachments. |
Location (When In Use)NSLocationWhenInUseUsageDescription | Show results near you. We never collect location in the background. | You can search by entering a place name instead. |
| Notifications | Send reminders and alerts you have asked for. | The App works normally; you simply receive no push notifications. |
TrackingNSUserTrackingUsageDescription | See section 8. | Nothing changes. No feature is withheld. |
Third parties and SDKs
We use a small number of service providers to run the App. Each one is contractually bound to process data only on our instructions, to protect it to the standard described in this policy, and not to use it for their own purposes. We do not permit them to sell it.
| Provider | Purpose | Data it receives | Their policy |
|---|---|---|---|
| Amazon Web Services | Hosting, database and file storage | Account data, User Content | https://aws.amazon.com/privacy/ |
| Sentry | Crash and error reporting | Diagnostics, device model, OS version | https://sentry.io/privacy/ |
| PostHog | Product analytics | Usage Data, not linked to your identity | https://posthog.com/privacy |
| Apple | In-app purchases, subscriptions, push notification delivery | Purchase records, device push token | apple.com/legal/privacy |
Each of these SDKs publishes a privacy manifest describing the data it collects, and those manifests are included in the App’s privacy report as required by Apple.
Tracking and advertising
“Tracking” means linking data collected in this App with data from other companies’ apps, websites or offline properties for advertising or advertising measurement, or sharing it with a data broker.
Trailmark does not track you and does not display third-party advertising. We do not access the Identifier for Advertisers (IDFA) and we do not share your data with data brokers.
How long we keep data
| Data | Retention period |
|---|---|
| Account data and User Content | Until you delete your account, then erased within 30 days |
| Diagnostics and crash logs | 90 days, then deleted automatically |
| Aggregated, anonymised usage statistics | Retained indefinitely — it can no longer identify you |
| Purchase and tax records | As required by law, typically 7 years |
| Support correspondence | 24 months after the ticket closes |
| Encrypted backups | Purged on a rolling cycle of 35 days |
Deleting your account
You can delete your account and its data from inside the App, without contacting us and without visiting a website:
- 1.Open Trailmark
- 2.Go to Settings → Account
- 3.Tap Delete Account and confirm
Your account is deactivated immediately and your personal data is permanently erased from our live systems within 30 days, and from encrypted backups within 35 days. We retain only what the law requires us to keep — principally purchase records for tax purposes — and anonymised statistics that cannot identify you.
If you cannot access the App, email privacy@example.com from your registered address and we will complete the deletion for you.
Cancelling a subscription is separate. Subscriptions are billed by Apple and must be cancelled in iOS Settings → your name → Subscriptions. Deleting your account does not automatically cancel an active subscription.
Your privacy rights
Wherever you live, you can ask us to:
- Access a copy of the personal data we hold about you
- Correct data that is wrong or incomplete
- Delete your data — see section 11
- Export your data in a portable, machine-readable format
- Restrict or object to a particular use of your data
- Withdraw consent at any time, where we relied on consent
Email privacy@example.com and we will respond within 30 days. We will not charge you, and we will never treat you differently for exercising a privacy right.
If you are in the EEA or the UK and you believe we have not handled your data properly, you may complain to your local supervisory authority. We would appreciate the chance to resolve it first.
US state privacy rights
If you live in California, Colorado, Connecticut, Virginia or another state with a comprehensive privacy law, you have the rights listed above, plus the right to opt out of the sale or sharing of your personal information and of profiling for targeted advertising.
We do not sell or share personal information as those terms are defined in the CCPA/CPRA, and we do not engage in targeted advertising — so there is nothing to opt out of. If that changes we will publish a “Do Not Sell or Share My Personal Information” link here before it takes effect.
You may designate an authorised agent to make a request for you. We will verify your identity by confirming control of the email address registered to your account.
Children’s privacy
The App is rated 4+ and is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, email privacy@example.com and we will delete it promptly.
Security
- All traffic between the App and our servers is encrypted with TLS 1.2 or higher.
- Data at rest is encrypted on our servers, and credentials are stored in the iOS Keychain on your device.
- Passwords are stored only as salted hashes; nobody at Northbay Labs, Inc. can read them.
- Access to production data is limited to staff who need it, protected by multi-factor authentication and logged.
- We review our dependencies and infrastructure regularly for known vulnerabilities.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant regulator without undue delay and, where required, within 72 hours.
International transfers
We are based in the United States and our servers are located in the United States. If you use the App from elsewhere, your data will be transferred to and processed there.
For transfers out of the EEA or the UK we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), together with technical measures including encryption in transit and at rest. You can request a copy of the safeguards we use by emailing privacy@example.com.
Changes to this policy
We update this policy when the App changes. When we do, we revise the “Last updated” date at the top and keep the previous version available on request.
If a change materially affects how we use your data, we will notify you in the App or by email before it takes effect, and where the law requires it we will ask for your consent.
Contact us
We aim to answer every privacy enquiry within 30 days.