TreeTap
Sign in
TreeTap
MapLeaderboardShop
Sign in
Privacy PolicyTerms of ServiceCookie Policy

© 2026 TreeTap LLC. All rights reserved.

Privacy Policy

Last updated: April 5, 2026

TreeTap LLC ("TreeTap," "we," "us") operates the TreeTap website and web application. This Privacy Policy explains what data we collect, why, and how we handle it. By using the Service you acknowledge this policy.

1. Data We Collect

Account data

If you sign in with Google, we receive your name, email address, and profile picture from Google. If you create a username, bio, or upload a profile photo, we store those too.

Anonymous sessions

When you tap an NFC tag, we automatically create an anonymous session so you can log your find without signing up. This stores a session token, your IP address, and user agent. If you later sign in, your anonymous data merges into your account.

NFC tag data

Each tap sends us the tag's unique identifier (UID), a read counter, and a cryptographic signature. We use this to verify the tap is authentic and prevent replay attacks.

Location data

Some caches require GPS verification. If so, your browser will ask for location permission before we collect coordinates. This is optional. You control it through your browser settings. We never collect location data in the background.

Usage data

We collect basic analytics (page views, performance metrics) through Vercel Analytics and Speed Insights. These services do not use cookies and do not track you across sites.

User content

Photos you upload, notes you write, and cache descriptions you create are stored on our servers.

Device & technical data

We collect your IP address, browser type, operating system, and user agent as part of standard web requests and authentication sessions.

2. Legal Basis for Processing (GDPR)

If you are in the EU/EEA, we process your data under the following bases:

  • Contract performance: account creation, find logging, and core service functionality.
  • Legitimate interest: anonymous session creation, NFC verification and anti-replay, security, analytics.
  • Consent: GPS location collection, email notifications.

3. How We Use Your Data

  • Authenticate you and manage your account.
  • Verify NFC taps and log finds.
  • Display your profile, finds, and leaderboard ranking.
  • Send you notifications (if enabled).
  • Improve the Service through analytics.
  • Prevent fraud and protect security.

4. Third-Party Services

We share data with these providers to operate the Service:

  • Vercel: hosting, analytics, performance monitoring.
  • Neon: PostgreSQL database hosting.
  • AWS S3: photo and media storage (EU-West-1 region).
  • Google: OAuth sign-in provider.
  • Apple MapKit: map rendering and cache location display.
  • Resend: transactional email delivery.
  • DiceBear: default avatar generation.

We may also disclose data if required by law, to protect rights or safety, or in connection with a business transfer (merger, acquisition).

5. International Data Transfers

TreeTap LLC is based in Texas, USA. Our infrastructure providers (Vercel, Neon, AWS) may process data in the United States. Where personal data is transferred outside the EU/EEA, we rely on Standard Contractual Clauses or other approved transfer mechanisms to protect your data.

6. Data Retention

  • Account data: retained while your account is active. Deleted on account deletion.
  • Anonymous sessions: may be purged after prolonged inactivity.
  • Find and interaction data: retained while your account exists.
  • Uploaded media: deleted when you delete the content or your account.
  • Session logs (IP, user agent): retained for security purposes and deleted when the session expires.

7. Your Rights

If you are in the EU/EEA, you have the right to:

  • Access your personal data.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten").
  • Restrict processing in certain circumstances.
  • Data portability: receive your data in a structured format.
  • Object to processing based on legitimate interest.
  • Withdraw consent at any time (e.g. location permissions, notifications).

To exercise any of these rights, email us at support@treetap.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority (e.g. the AEPD in Spain).

Regardless of your location, you can update your profile information in your account settings or request account deletion by contacting us.

8. Children's Privacy

The Service is not intended for anyone under 16. We do not knowingly collect data from children under 16. If you believe we have, please contact us and we will delete it promptly.

9. Security

We use HTTPS, encrypted sessions, and cryptographic NFC verification to protect your data. However, no system is 100% secure, and we cannot guarantee absolute protection.

10. Cookies

We use a small number of cookies, all either strictly necessary or functional. See our Cookie Policy for the full list.

11. Changes to This Policy

We may update this policy from time to time. When we do, we will update the date at the top. Continued use of the Service after changes means you acknowledge the updated policy.

12. Contact

Data controller: TreeTap LLC, Texas, USA

Email: support@treetap.com