Skip to main content

Privacy Policy

Effective Date: February 11, 2026 Last Updated: August 30, 2026

Hamtrax ("we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, store, and share information when you use the Hamtrax application, website, and related services (the "Service").

1. Information We Collect

Information You Provide

  • Account information: Email address, name, callsign, country, and license class.
  • Profile information: Display name, nickname, and profile photo.
  • QSO logs: Contact records you create or import, including callsigns, frequencies, modes, dates, times, and notes.
  • Location data: Grid square, coordinates, or city — depending on the location mode you choose (callsign lookup, device GPS, or manual entry). If you explicitly tap Find Nearest while choosing a park, Hamtrax also stores the fresh GPS coordinates from that request in the same shared location preferences.
  • User-generated content: Photos, livestream URLs, folder cover images, station equipment images, and feedback submissions.
  • Billing information: If you subscribe to a paid plan, payment is processed by Stripe (web and Android) or by Apple via the App Store using RevenueCat (iOS). We do not store your credit card number or full payment details — these processors handle them directly. We store the entitlement status and plan plus the processor identifiers needed to keep billing tied to one account: canonical Stripe Customer and subscription IDs, optional historical Customer IDs, temporary Checkout lifecycle state, or the RevenueCat user ID used for an App Store entitlement.
  • Communication preferences: Which automated emails you have chosen to receive or turn off, set in Settings or from the unsubscribe link in an email.
  • Station equipment: Rig and antenna profiles, including names, descriptions, and photos you upload.
  • Integration credentials: If you connect QRZ Logbook, you provide the API key for the specific QRZ logbook you choose. Other optional integrations may request their own credentials as described in their setup screens.

Information Collected Automatically

  • Device information: Browser type, operating system, and device identifiers.
  • Language preference: The language your browser asks for, the language Hamtrax actually displayed, and whether we were able to match the two. We record a coarse language tag such as de or pt-br — not the full list of languages your browser reports — and we use it only to decide which languages to translate Hamtrax into next.
  • Session platform: Which platform each of your sessions runs on — web, the iOS app, or the Android app. Your account record keeps the platform of your most recent session and a running list of the platforms your account has used, so we can tailor platform-specific communications (for example, asking iOS app users for an App Store review — by email, or through the in-app "Enjoying Hamtrax?" prompt shown only in the mobile apps).
  • Usage data: Pages visited, features used, and interaction patterns within the Service. This includes tutorial and walkthrough completion state (so we can avoid re-running first-run flows you've already seen), and in-app prompt history — for the "Enjoying Hamtrax?" review prompt, when it was last shown, whether you chose a response or closed it without choosing, and whether you asked us not to show it again — so we can honor its frequency limits and your permanent opt-out.
  • Analytics data: We use Google Analytics 4 (GA4) — in the app via Firebase and on our website and documentation site (docs.hamtrax.com) via Google's gtag — to collect usage metrics. These include page views, sign-up and login completions, and interaction signals such as scroll depth, expanding explanatory sections, and clicks on App Store badges. In the app, signed-in activity may be linked using a pseudonymous Firebase user ID; Hamtrax does not send your email address, callsign, or name as the analytics identity. This data helps us understand how the Service is used and where to improve. IP addresses are anonymized on the documentation site, and analytics data is processed according to Google's privacy policies.
  • Performance measurements: We measure how well the Service performs for real visitors: standard page-speed metrics (such as how long the page takes to render and how quickly it responds to your input), and — when a network request takes longer than one second — a record of that delay. A slow-request record contains only the elapsed time, the server the request went to (for example api.pota.app), a generalized version of the requested path with any identifiers replaced, the kind of request, and the feature area you were using. Full addresses and query strings are never sent, so a callsign, grid square, or search term travelling in a request cannot appear in these measurements. A given slow resource is reported at most once per session. We use these measurements solely to find and fix slow parts of the Service.
  • Analytics location exclusion: Before the production or beta web app loads GA4 or Microsoft Clarity, it asks a Hamtrax Cloud Function whether the visitor's approximate IP location may fall within 30 miles of Kansas City, Missouri. At app startup, the Function sends the public IP address to GeoJS for an approximate location and returns only an exclusion decision to the browser; the browser caches only that decision for the tab. Hamtrax application code does not write the IP address or returned coordinates to its databases or application logs. Google Cloud and GeoJS process request metadata under their respective privacy policies. Sessions within the radius, sessions whose reported accuracy area overlaps it, and sessions whose location cannot be resolved are not sent to GA4 or Clarity. This is not continuous physical-location monitoring, and the exclusion does not apply to docs.hamtrax.com.
  • Cookies and similar technologies: Our website and documentation site use Google Analytics cookies (such as _ga) to distinguish visitors and measure usage. Because these cookies are shared across hamtrax.com subdomains, a visit to our documentation and a later sign-up may be recognized as the same journey. You can block or delete these cookies via your browser settings.
  • Referral and campaign data: When you arrive from a marketing link, we record the campaign parameters in the entry URL (for example, utm_source and utm_campaign) so we can understand which campaigns bring people to Hamtrax. This is retained for the browser session, attached to that session's analytics events, and is not linked to your identity.
  • Session replay: We use Microsoft Clarity to record session replays of how the Service is used — including page interactions such as clicks, scrolling, and mouse movement — so we can identify usability issues and improve the Service. Clarity may also collect device and browser information. For signed-in activity, Hamtrax may send the same pseudonymous Firebase user ID described above so activity can be linked without sending your email address, callsign, or name as the analytics identity. Recordings are processed by Microsoft and are subject to Microsoft's Privacy Statement.
  • Crash and error reports: When the app encounters an error, we record an anonymous report containing the device class (mobile, tablet, or desktop), platform, app version, environment, the feature area in use, the error message and technical stack trace, and a random per-session identifier. These reports contain no account ID, callsign, page URL, or browser user agent and are not linked to your identity. We use them solely to find and fix problems in the Service. On the iOS and Android apps, error reports are also processed by Firebase Crashlytics.
  • Signup callsign diagnostics: When a callsign was entered and its lookup or final profile save during signup is unsuccessful, Hamtrax first attempts to place a report in a device-local queue scoped to the pseudonymous Firebase account ID, attempts to create a private server-only record, and removes any queued copy after confirmed delivery. If delivery is unavailable and the local queue was available, the queued report remains for a later connectivity and authentication retry. The report contains the normalized callsign entered, failure stage and stable result code, and an opaque ID; when both deliveries succeed, that ID can link the private record to the corresponding analytics outcome. We use this record only to distinguish Hamtrax service failures from gaps or delays in public licensing databases. The callsign field is masked from Microsoft Clarity, and the value is not sent to GA4, crash reports, or Cloud Logging.
  • Authentication data: OAuth tokens and session information from third-party sign-in providers (Google, Apple).

Information from Third Parties

  • Callsign lookups: We query external callbook and licensing databases (HamQTH, QRZCQ, QRZ Digital, DMR/global callsign data, and the FCC ULS amateur database) to retrieve publicly available registration data such as name, address, grid square, and license class. Callsign detail views use only a respectful projection of that data and do not display street addresses, ZIP codes, or exact coordinates.
  • Activity and reception data: We aggregate public amateur radio activity from POTA, HamQTH's DX cluster, Reverse Beacon Network, and PSK Reporter. These services may report the callsign actually heard or spotted, time, frequency, mode, signal information, and public activity references.
  • Location imagery: We use Flickr's public API and Wikimedia Commons to source freely licensed photography for park, country, and location displays, with the photographer credited on each image. The images are loaded directly from those providers' servers, so — like any web request — that load sends your IP address and the requested image to Flickr or the Wikimedia Foundation; their handling of that data is described in the Flickr Privacy Policy and the Wikimedia Foundation Privacy Policy.
  • Map imagery: When you zoom into the detailed map view, map tiles are loaded directly from OpenStreetMap's public tile servers. Like any web request, these tile loads send your IP address and the requested map area to the OpenStreetMap Foundation; their handling of that data is described in the OpenStreetMap Foundation Privacy Policy.

2. How We Use Your Information

We use collected information to:

  • Provide, operate, and improve the Service.
  • Create and manage your account.
  • Display your profile and QSO statistics to other users (based on your privacy settings).
  • Power location-based features such as distance calculations and map displays.
  • Resolve callsign data and derive default settings (band plan, license privileges).
  • Perform third-party integration actions you request, such as importing contacts from QRZ Logbook or uploading Hamtrax contacts to it.
  • Process subscriptions, reconcile billing state, prevent overlapping charges, and refund payments from rejected duplicate Stripe Checkouts.
  • Send account-security communications you request and, while your account remains active, eligible activity, product, and occasional promotional emails — for example, a request to review the app, which may be targeted using the platforms your account has used. Before each non-transactional automated send, Hamtrax rechecks that the authentication account is active and that applicable stored email preferences allow delivery. You control these emails individually under Settings → Preferences → Notifications, and every such email carries an unsubscribe link in its footer plus a one-click unsubscribe header that Gmail and Yahoo surface natively. Account and security emails, such as password resets and account notices, are transactional and are always delivered.
  • Occasionally ask, inside the mobile apps only, whether you are enjoying Hamtrax — routing you to the App Store review sheet or to the in-app feedback form depending on your answer, subject to the frequency limits, dismissal backoff, and permanent opt-out recorded in the prompt history described above.
  • Detect and prevent abuse, fraud, or violations of our Terms of Service.

3. How We Share Your Information

We do not sell your personal information.

We may share information in the following circumstances:

  • Public profile data (your Showcase): Your Showcase has a short link of the form hamtrax.com/<your short code>. That page is public: anyone who has the link can open it without a Hamtrax account or signing in. Your callsign, display name, username, profile photo, and general location (city/state/country and grid square, not a precise address) are published there, along with any of the following you have not hidden: your social links; your radios and antennas; your activation and monthly hunting folders, including their names, contact counts, photos, and notes; and a summary of the countries and DXCC entities you have contacted together with the number of contacts it was calculated from. Contact-by-contact details are published only if you leave your logbook visible. Each of these has its own visibility toggle on your Showcase — your equipment, and each activity program's activations and hunting separately — and hiding one stops it being sent to that page at all. Your email address, password, exact address, and payment details are never published there.
  • Service providers: We use third-party services (Firebase/Google Cloud for hosting, storage, and crash and error reporting — including Firebase Crashlytics on the iOS and Android apps; Microsoft Clarity for session replay analytics) to host, store, and process data on our behalf. These providers are bound by their own privacy commitments.
  • IP geolocation provider: Hamtrax sends the public IP address to GeoJS to obtain the approximate location used by the analytics exclusion described above. GeoJS's handling of that request is governed by the GeoJS Privacy Policy.
  • Payment processors: If you subscribe to a paid plan on the web or Android, billing is handled by Stripe, Inc. Stripe receives the payment information you provide during checkout plus a pseudonymous Firebase account ID and Hamtrax project marker used to associate and deduplicate billing; Stripe's use of your data is governed by Stripe's Privacy Policy. If you subscribe through the iOS app, billing is handled by Apple via the App Store and entitlements are mediated by RevenueCat, Inc.; their use of your data is governed by Apple's Privacy Policy and RevenueCat's Privacy Policy.
  • External services you connect: When Hamtrax checks a connected QRZ logbook's status, or when you request an import or upload, Hamtrax sends your API key and the data required for that operation to QRZ over HTTPS. QRZ handles that data under its own privacy policy. Importing from QRZ always requires an explicit action. If you enable the Auto-Push New Contacts setting, that choice is ongoing consent for Hamtrax's servers to automatically send each newly logged contact to QRZ — along with update and delete requests for pushed contacts you later edit or remove — until you turn the setting off.
  • Legal requirements: We may disclose information if required by law, regulation, or legal process.
  • Safety: We may share information to protect the rights, safety, or property of Hamtrax, our users, or the public.

4. Data Storage and Security

  • Your data is stored using Google Firebase (Firestore, Firebase Authentication, and Firebase Storage for user-uploaded media) with encryption in transit and at rest.
  • A connected QRZ API key is additionally encrypted before it is stored in a server-only Firestore document. Client applications cannot read that document, and the stored key is never returned to the app after connection.
  • Certain data is cached locally on your device (IndexedDB and session storage) for offline access and performance.
  • The unsubscribe link in our emails carries a cryptographically signed token identifying your account, so the page works without signing in. The token cannot be altered to reach another account, the page displays no email address or callsign, and opening the link never changes a setting on its own — a change is applied only when you submit the form or use your mail provider's one-click unsubscribe control.
  • We implement reasonable technical and organizational measures to protect your information. However, no system is completely secure, and we cannot guarantee absolute security.

5. Your Location Data

For app features, you control how Hamtrax determines your location:

  • Callsign mode: Location is derived from your callsign registration address (publicly available data).
  • Device mode: Location is obtained from your device's GPS with your permission. We do not track your location in the background.
  • Manual mode: You enter a grid square, coordinates, or city of your choosing.

You can change your location mode at any time in Settings. Location data is used for distance calculations, propagation estimates, and map features.

The analytics location exclusion described above is separate from these profile settings. It uses only an approximate IP-derived location, does not update your Hamtrax location, and is not used for app features.

Opening the POTA activation setup or the Hunt tab's Hunting from a park? setup does not request GPS by itself. If you tap Find Nearest, Hamtrax requests a one-time fresh GPS reading -- regardless of your chosen location mode -- to find nearby parks and stores that reading in the same shared location preferences. With a blank park field, Hamtrax auto-selects the closest park only when you're within 0.5 miles; otherwise it shows the nearby-parks list. On iPhone, tapping Find Nearest shows the standard iOS location prompt the first time. If you deny permission, manual park search remains available. This is a foreground reading; we do not track your location in the background.

6. Data Retention

  • We retain your account data for as long as your account is active.
  • Disconnecting QRZ removes the stored QRZ API key. Deleting your Hamtrax account also removes the server-stored integration-credential document.
  • Practice contacts generated by the in-app guided walkthrough are temporary and are deleted automatically by a server-side cleanup task -- they are not retained as part of your logbook.
  • Signup callsign diagnostic records are marked to expire 30 days after collection and are deleted automatically by Firestore TTL. An undelivered device-local report is pruned the next time Hamtrax opens after it reaches 30 days. Deleting an account does not shorten the server record's automatic expiry period; you may request earlier deletion using the contact information below.
  • When you use Delete account in Hamtrax settings, Hamtrax first closes unfinished Stripe Checkout and cancels and confirms every recurring Stripe subscription linked to your account. If a rejected Checkout was paid, deletion remains blocked until its exact payment is confirmed refunded or an exact provider chargeback already reimbursed it. If Stripe cannot confirm those outcomes, the in-app authentication deletion does not proceed. Hamtrax then removes your authentication credentials, server-stored integration credentials, and the email address from the retained profile. Minimal Customer, subscription, Checkout, payment, refund, and dispute identifiers/statuses remain in a private server-only billing record to prove cancellation, prevent duplicate compensation, and reconcile financial history; card data is never stored by Hamtrax. Automated activity and product email delivery stops. App Store subscriptions are controlled by Apple and must be canceled separately in Apple Subscriptions. Contact logs and other logbook/profile data are preserved and become inaccessible through that account; to export your data beforehand, use the ADIF export feature.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate information in your profile.
  • Request deletion of personal information we hold about you, subject to applicable exceptions.
  • Export your QSO logs and data.
  • Object to certain processing of your information.
  • Opt out of marketing email at any time, without contacting us — per email type under Settings → Preferences → Notifications, or from the unsubscribe link in any automated email (no sign-in required).

Settings can delete your login account as described above. To exercise rights covering retained profile or logbook data, contact us at info@hamtrax.com.

8. Children's Privacy

The Service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child under 13, we will delete it promptly.

The Service may contain links to third-party websites or integrate with external services (QRZ, HamQTH, POTA, etc.). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy with a new "Last Updated" date. Continued use of the Service after changes constitutes acceptance.

11. Contact

If you have questions or concerns about this Privacy Policy, contact us at info@hamtrax.com.