Privacy policy

Draft. Have it reviewed by a lawyer before launch. Items in square brackets depend on open operating decisions (hosting, map provider). The German version is authoritative.

Last updated: 7 October 2026 (draft)

1. Who is responsible?

BYTEPOTATO UG (haftungsbeschränkt), c/o Daniel Ference Broek, Kurze Str. 6, 37073 Göttingen, Germany, e-mail: [email protected]. See the legal notice for further details.

We are not required to appoint a data protection officer. For any privacy question, contact us at [email protected].

2. Our principle

GroundHopper.net is built for hoppers who prefer to stay under the radar. Therefore:

  • No tracking, no analytics, no advertising, no sharing with ad networks.
  • Visiting the website sets no cookies and stores nothing on your device until you sign in. That is why there is no cookie banner.
  • Nothing is loaded from third-party servers when you open a page, not even fonts. The map only loads once you switch it on (see section 9).
  • We remove all metadata, including the location, from photos and videos when you upload them, unless you explicitly choose otherwise.

3. What we process and why

3.1 Using the website and the app (server logs)

On every request our server processes technically necessary data: IP address, date and time, requested address (without query parameters), status code, amount of data transferred, browser and operating system. We need them to deliver the service and to fend off attacks.

Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is secure and stable operation. Logs are deleted automatically after 14 days at the latest.

Website language: if you open a page without a language in its address, we pick the language from your browser's language settings (the "Accept-Language" header) and, if none of them matches, from the country our CDN provider Cloudflare derives from your IP address; otherwise English. Both are read only for that one redirect and are neither stored nor logged. No cookie is set and nothing is stored on your device; your language choice lives only in the address (e.g. /fr/). Legal basis: Art. 6(1)(f) GDPR; our legitimate interest is showing you the site in your language.

3.2 Account

For an account we store your handle, your display name, the sign-in methods you set up (see below) and, optionally, a short bio, a profile picture and your home ground. Legal basis: Art. 6(1)(b) GDPR (contract of use).

You sign in with Apple, with Google or with a passkey. There are no passwords and no e-mail sign-in. We do not store e-mail addresses, not even when Apple or Google include one. You can connect several sign-in methods to your account and remove them again; the last one cannot be removed, otherwise you could no longer get into your account.

Sign in with Apple: Apple sends us a pseudonymous identifier that is only valid for GroundHopper.net and, the first time and if you agree, your name, which we suggest as display name. We store only the identifier. Provider: Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland. Apple's privacy policy applies in addition.

Sign in with Google: signing in happens on Google's page, not ours. No Google script is loaded on our website for it; only when you choose "Sign in with Google" do we forward you to Google, which thereby learns that you are signing in to GroundHopper.net. We ask Google for the sign-in only, not for your e-mail address, name or profile picture. Google then sends us a pseudonymous identifier of your Google account, and that is all we store. During the redirect we set a short-lived cookie (gh_google_state, 10 minutes at most) that makes sure the sign-in finishes in the browser where it started; it is strictly necessary for the sign-in you asked for (§ 25(2) no. 2 TDDDG). Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google may also transfer data to the USA; Google LLC is certified under the EU-US Data Privacy Framework. Google's privacy policy applies in addition.

Passkey: a passkey is a key pair created by your device or your password manager (e.g. iCloud Keychain, Google Password Manager). We store only the public key, the passkey's identifier, a counter that lets us detect copied keys, the name you give it, whether it syncs across devices, and the dates it was set up and last used. The private key and your fingerprint, face or device PIN never leave your device; we never see them. For every sign-in we create a random challenge that expires after a single use, at the latest after 5 minutes.

Try the demo: you can try GroundHopper.net without an account. For that we create a temporary demo account with sample data (visits, photos, statistics). It contains no personal data about you: we ask for nothing, the handle and display name are random or fixed, and it is not connected to any Apple, Google or passkey sign-in. Whatever you add or upload in the demo account is seen by nobody but you, even if you change the visibility. The sample hoppers the demo account follows and whose data it starts with are invented and contain no data of real people (real, public match results and freely licensed photos from Wikimedia Commons); they are only visible in demo accounts. The demo account is deleted with all its data and files 24 hours after it was created (or earlier if you delete it yourself); its session ends then too. So that demo accounts cannot be created without limit, the server counts in memory, for one hour at most, how often a demo was started from an IP address; the IP address is not stored for this. Legal basis: Art. 6(1)(b) GDPR (the use you asked for), for the limit Art. 6(1)(f) GDPR (protection against abuse).

Session cookie: after signing in on the website we set a cookie (gh_session). It contains a random session identifier, is strictly necessary for signing in (§ 25(2) no. 2 TDDDG) and expires after 90 days at most or when you sign out. In the app the session identifier is stored in your device's keychain.

3.3 Visits, statistics and counting rules

When you log a match we store the ground, date, pairing, score, attendance, competition, notes and the attributes you choose (e.g. friendly, saw the full match). From these and your counting rules we compute your statistics (ground points, country points). Legal basis: Art. 6(1)(b) GDPR.

GPS check-in (optional): when you tap "Check in", the app sends your location once. We only compute the distance to the ground and store nothing but the result ("checked in" and the distance in metres) — never your coordinates. You can revoke location access in your device settings at any time. Legal basis: Art. 6(1)(a) GDPR.

Match search and hop planner: when you search for matches nearby or plan a hop, the chosen starting point (your location only if you tap "My location", otherwise a ground) is sent with the request, used only for that calculation, and neither stored nor logged. Legal basis: Art. 6(1)(b) GDPR; for the device location additionally your permission in the operating system.

Offline logging: visits logged without a connection are stored on your device only until they can be sent.

3.4 Photos and videos

Uploaded photos are re-encoded on our server, which removes all embedded metadata (EXIF, XMP, IPTC) including location, time of capture and camera model. Videos are re-packaged without metadata. Metadata is kept only if you explicitly choose "keep location" when uploading. We store the file in object storage [provider and location, EU] together with a smaller preview.

Profile picture: You can upload a picture from your device as your profile picture or pick one of your visit photos. An uploaded picture is re-encoded as well, cropped to a square and stored without any metadata; keeping the location is not possible here. The app does not get access to your whole photo library for this, only to the one picture you select. Like your handle and display name, your profile picture is visible to everyone, even if your profile or your photos are not public. When you replace or remove an uploaded profile picture, we delete the file immediately.

3.5 Visibility and social features

You decide separately for your profile, visits, photos and announced matches ("I'm going") who may see them: everyone, your followers only, or only you. A single visit can be stricter than your profile, never more open. Following a non-public profile requires your approval. Blocking someone hides you from each other completely.

Likes, comments and follows are stored until you delete them or your account. Legal basis: Art. 6(1)(b) GDPR.

3.6 Contributions to the ground database and moderation

When you add or correct grounds or matches, we store your proposal with your account so that moderators can review it and changes remain traceable. We rate the quality of your contributions automatically (trust level) so that contributions of experienced users are applied faster. This rating has no legal effect on you; every rejection is made by a human. Legal basis: Art. 6(1)(f) GDPR (quality of the database).

We process reports about content to remove unlawful content and enforce our rules (Art. 6(1)(c) and (f) GDPR).

3.7 Import and export

When you import a CSV file we process its content only to create your visits; we do not keep the file. You can download all your data at any time as CSV (visits) or JSON (everything) (Art. 20 GDPR).

3.8 Premium subscription

Premium is only available as a subscription in the App Store; Apple handles subscribing, payment, renewal, cancellation and refunds. We receive signed confirmations from Apple with product, transaction number, term, renewal status and any refund, but no payment data. So that a purchase can be matched to your account, the app passes your account identifier to Apple when you buy; Apple informs us about renewals, cancellations and refunds even if you do not open the app. You cannot buy anything on the website; premium applies there for as long as your account's App Store subscription runs. Legal basis: Art. 6(1)(b) GDPR. We keep subscription data for as long as your account exists.

3.9 E-mails

We do not send you e-mails, neither for signing in nor as a newsletter. If you write to us, we use your address only to reply.

4. Recipients and processors

We do not pass your data on to third parties, except to service providers processing it on our behalf under contract (Art. 28 GDPR):

  • Hosting and object storage: [provider, location in the EU]
    We do not transfer data to countries outside the EU. Sign-in with Apple or Google is performed by Apple or Google under their own responsibility, as are App Store purchases by Apple.

5. How long we keep data

As long as your account exists. When you delete your account we immediately delete your profile, visits, photos, videos, comments, likes, follows, sessions, sign-in methods (Apple and Google identifiers, passkeys) and subscription data, including the media files. A running App Store subscription does not end with it; you cancel it in your Apple Account settings. Pending sign-ins (passkey challenges, Google redirects and one-time codes for the app) are deleted once expired, at the latest in the hourly clean-up. Demo accounts are deleted with all their data and files 24 hours after they were created (in the hourly clean-up, so at most an hour later; the session itself ends after exactly 24 hours). Contributions to the shared ground and match database (e.g. a ground you added) remain, without any link to you. Backups are overwritten in the regular cycle of [number] days.

6. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). You can withdraw consent at any time with effect for the future (Art. 7(3)).

You can exercise many of these rights directly in the app: export your data, change visibility, delete your account. Otherwise an e-mail to [email protected] is enough.

You may lodge a complaint with a data protection supervisory authority, for example the one responsible for us: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany.

7. Obligation to provide data

Without a sign-in method (Apple, Google or passkey) we cannot create an account. Ground search and public ground pages work without an account.

8. Security

All connections are encrypted (TLS). Session identifiers and one-time codes are only stored as hashes. Passkeys also protect against phishing, because they only work on our own address.

9. Map

The map view loads map tiles from [map provider], which transmits your IP address to that provider. The map therefore only loads after you click "Show map". Legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG), which ends when you close the map or reload the page. The iOS app uses Apple Maps.

10. Changes

When our services change we update this policy. The current version is always available at https://groundhopper.net/en/legal/privacy.