Privacy Policy
Last updated: 2026-05-14Legal review pending
This Privacy Policy describes how RingTime, Inc. (“RingTime”, “we”, “us”) — operator of The HITS App and the websites at thehitsapp.info (collectively, the “Service”) — collects, uses, discloses and protects personal data when you use the Service. We act as a data controller with respect to most processing described below. For data processed on behalf of HITS Shows in the operation of a specific event, we act as a processor.
1. Categories of personal data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, display name, password hash, mode preference (Spectator / Competitor) | You, at sign-up |
| Precise location | GPS coordinates while the app is in the foreground, used only to show your position on the venue map and surface nearby rings or vendors. Never collected in background. Retained 90 days then aggregated. | Your device (with consent) |
| Push tokens | Apple/Google push notification tokens, notification preferences | Your device (with consent) |
| Usage & device data | App screen views, button taps, crashes, device model, OS version, app version, anonymized IP address (truncated to /24 within 24 hours) | Automatic |
| Commerce data | Order history at on-site vendors, items, totals, vendor pickup status. Payment card data is handled exclusively by our PCI-DSS Level 1 payment processor — we never store full card numbers. | You, when you place an order |
| Competitor data | Rider/horse entries, division placements, USEF/USHJA numbers if you choose to link them, results history | You and HITS show management |
| Support data | Email content, attachments and metadata when you contact support | You |
2. Purposes & legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Providing the core Service (account, schedules, results, map, orders) | Art. 6(1)(b) — performance of a contract |
| Sending transactional notifications (order updates, ring assignments) | Art. 6(1)(b) — performance of a contract |
| Push notifications, precise location, marketing emails | Art. 6(1)(a) — your explicit consent (withdrawable at any time) |
| Fraud prevention, security monitoring, audit logging | Art. 6(1)(f) — legitimate interest in operating a secure service |
| Aggregate analytics & service improvement | Art. 6(1)(f) — legitimate interest, with privacy-preserving aggregation |
| Legal, accounting and tax obligations | Art. 6(1)(c) — legal obligation |
3. Retention
- Precise location: retained at user-resolution for 90 days, then aggregated to anonymous heatmap tiles.
- Account data: retained for the life of your account. Deleted within 30 days of an account-deletion request, except where retention is required by law.
- Audit & security logs: retained 12 months in hot storage, then deleted.
- Order history: retained 7 years for tax and accounting purposes (US IRS / EU equivalent).
- Marketing data: retained until you withdraw consent or unsubscribe.
4. Recipients & sub-processors
We share data only with the sub-processors below, under written DPAs:
- Amazon Web Services (AWS) — hosting, storage, encryption-at-rest (KMS). Regions: US-East-1 primary, EU-West-1 for EU data residency.
- Expo / Apple APNs / Google FCM — push-notification delivery (token + payload only).
- MapLibre tile providers (MapTiler / OSM) — anonymous map tile requests. Your IP is sent to the tile provider to deliver tiles; we never associate map requests with your account.
- Stripe, Inc. — PCI-DSS Level 1 payment processor; receives only the data needed to authorize a charge.
- PostHog — privacy-respecting product analytics, configured with IP-truncation and without session-replay of sensitive screens.
- HITS Shows, LLC — receives competitor entry and result data necessary to run a horse show in which you are participating.
We do not sell personal data, and do not share it with advertising networks.
5. International transfers
Personal data may be transferred to the United States. When data is transferred from the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (SCCs) plus supplementary technical measures (encryption in transit and at rest, access controls, audit logging). A copy of the SCCs is available on request to dpo@thehitsapp.info.
6. Your rights under the GDPR (EEA / UK)
- Right of access — request a copy of the personal data we hold about you (Art. 15).
- Right to rectification — correct inaccurate data (Art. 16).
- Right to erasure — “right to be forgotten” (Art. 17).
- Right to restriction — pause processing while a dispute is resolved (Art. 18).
- Right to portability — receive your data in a structured, commonly-used, machine-readable format (Art. 20).
- Right to object — to processing based on legitimate interest, including direct marketing (Art. 21).
- Right to withdraw consent — at any time, without affecting the lawfulness of processing already carried out (Art. 7(3)).
- Right to lodge a complaint with your local supervisory authority (Art. 77). A non-exhaustive list:
- Ireland: Data Protection Commission
- UK: Information Commissioner's Office
- Germany (federal): BfDI
- France: CNIL
To exercise any right, email dpo@thehitsapp.info. We respond within 30 days (extendable by 60 days where complex).
7. Your rights under the CCPA / CPRA (California)
California residents have the following additional rights:
- Right to know what personal information we have collected, used, disclosed or sold/shared.
- Right to delete personal information we have collected.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing — note that we do not sell or share personal information as defined by the CPRA.
- Right to limit use of sensitive personal information — we do not use sensitive personal information for any purpose beyond providing the Service requested.
- Right to non-discrimination for exercising any of the above rights.
California requests may be submitted to privacy@thehitsapp.info. We will verify your identity before fulfilling a request.
8. Children
The Service is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact dpo@thehitsapp.info and we will delete it promptly.
9. Automated decision-making
We do not engage in automated decision-making that produces legal or similarly significant effects on you within the meaning of GDPR Art. 22.
10. Security
We protect your data with encryption in transit (TLS 1.2+), encryption at rest (AWS KMS), least-privilege IAM with MFA enforced for all staff access, and continuous logging and monitoring. See the Security page for full details.
11. Changes to this policy
We will post the updated policy at this URL and update the “Last updated” date. Material changes will be notified in-app or by email at least 30 days before they take effect.
12. Contact
Data Protection Officer: dpo@thehitsapp.info
Postal: RingTime, Inc. — Attn: DPO. (Postal address to be added at incorporation; flag for V.)