Last updated: 31 July 2026
Account data. Your email address, and — if you choose to provide them — your name, phone number, postal address and profile photo. If you sign in with Google or Apple, we receive your email address and basic profile information from that provider; we never receive your password.
Tracker and location data. The GPS positions your collars report, the times they reported them, the routes recorded during a hunt, and technical device details such as the tracker's identifier, model and the phone number of the SIM inside it. Location data comes from the collar, not from your phone, except where you turn on the "my location" feature in the app — that position is shown on your screen and is not sent to us.
Usage analytics. Which screens you open and which actions you take in the app, with a timestamp, plus the app version, platform, device model and operating system version. We use this to find broken flows and to see which features are used. The same events are also sent to Google Analytics for Firebase, which counts them in aggregate and identifies your install by a randomly generated app instance ID rather than by your account. We do not collect the advertising ID — the permission that would allow it is removed from the app.
Crash and error diagnostics. When the app crashes or hits an error it can handle, it sends a diagnostic report: the stack trace, the app version, the device model and operating system version, and a short log of the actions leading up to it. These reports are about the software, not about you, and we use them only to fix faults.
Support messages. Whatever you send us by email, WhatsApp, Viber or Messenger.
Payment data. We do not collect or store your card details. Payments are processed by Paddle (see section 4).
We do not sell your personal data, and we do not use it for advertising or profiling.
Where a provider processes data outside the European Economic Area, that transfer relies on the European Commission's Standard Contractual Clauses or an adequacy decision.
Your account, tracker and location data is stored on servers in the European Union. Backups are held in the same region.
Traffic between the app, the website and our servers is encrypted with TLS. Access to the production database is restricted to the people who operate the service. No system is perfectly secure, and we cannot guarantee absolute security, but we will notify you and the competent supervisory authority of a personal data breach where the law requires it.
Under the GDPR and comparable local law you may ask us to: give you a copy of your data; correct it; delete it; restrict or object to how we use it; or provide it in a portable format. You can delete your account and its data from the Account tab in the app, or by emailing us. Where we rely on legitimate interests — including usage analytics — you can object and we will stop unless we have compelling grounds not to.
To exercise any of these, write to tragtracking@gmail.com. We respond within one month. If you are not satisfied, you may complain to your national data protection authority.
Trag is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
If we change this policy we will update the date at the top and, for material changes, tell you in the app or by email before the change takes effect.
Slash d.o.o., Halilovići 10, 71000 Sarajevo, Bosnia and Herzegovina
Company ID (JIB) 4202807780006 · VAT ID (PDV) 202807780006
tragtracking@gmail.com · +387 61 074 474