2. Privacy Policy (PP.md)
ClaySquad.com Privacy Policy
Last Updated: July 2026
ClaySquad.com is operated by un9 ltd. and is built on a privacy-first, non-enumeration framework designed to connect shooters safely. This policy outlines how we handle data for our users.
1. Information We Collect & Account Integrity Data
- Profile Registration Data: When you create an account, we collect your email address, username, country, skill level, and gender (including an explicit, structurally immutable "Prefer not to say" option).
- Social OAuth Providers: If you sign in via a social provider (Google, Apple, or Facebook), we receive only the baseline identifiers permitted by that provider, typically your name and email address.
- System Design Tokens: We utilize ULID (Universally Unique Lexicographically Sortable Identifier) primary keys across all application database tables instead of sequential integers. This protects your account records and squad postings from public enumeration and harvesting. Avatars and squad identification badges are generated automatically from unique random seeds—no personal photo or private image is required or stored.
2. How We Use Your Data, Private Notebooks, and Squad Check-Ins
We use your data to operate the core ClaySquad service (managing squad requests, replies, the clubs and requests you follow, and browsing preferences).
- Private Arrival Check-Ins: On a squad's club-local shoot date, the organiser and accepted members may submit a self-reported arrival check-in with an optional location note. We store the member, squad, schedule version, check-in time, current note, undo time, and an append-only history of meaningful changes.
- Roster Access and Notifications: Current check-in status and activity are visible only to the organiser and accepted members of that squad. Every meaningful change sends email and in-app notifications to the other current roster members.
- Following: You can follow clubs and squad requests. ClaySquad stores those choices and the last time you opened each followed item so it can show new activity and send Following notifications. You can stop following at any time. Organisers automatically follow their active squad requests.
- Notification Preferences: Optional community email is grouped into squad conversations, squad participation and changes, Following, and connections, relationships, and invitations. Turning off email does not turn off in-app notifications. Authentication, security, and moderation email remains mandatory.
- No Device Location Collection: Arrival check-ins do not request or store browser coordinates, IP-derived location, or independent proof of attendance. Security audit logging described below remains separate from the check-in feature.
- History Retention: Undone check-ins and activity from earlier schedule versions remain stored as private history but are excluded from the squad's current check-in status and feeds.
- Private Member Notebooks: You may store private notes, five-level rating answers, encounter context, and personal join reminders about another member. Only the author can access notebook contents. The subject, other members, administrators, support staff, and impersonated sessions cannot access them.
- Encryption Boundaries: Every notebook note and rating is encrypted with the application's encryption key. If you add a personal lock, ClaySquad also encrypts each value with a key derived from your passphrase. We store lock metadata, record ownership, subject, squad context, and timestamps, but never the passphrase or derived key.
- Lost Passphrases: ClaySquad cannot recover a personally locked record if its passphrase is lost. You may still permanently delete the record without unlocking it.
- Limited Metadata Use: Squad pages and roster notifications may indicate only that you have a record or asked to be reminded. They never include note text or rating values. Notebook contents are excluded from activity logs, security audit logs, analytics, Discord alerts, and notifications.
- No Selling of Data: We never sell, rent, or trade your personal data to third parties.
3. Security Audit Logs & Account Deletion Policy
To detect platform abuse, maintain safety, and log security-relevant events, our system maintains an append-only, permanent audit_logs table.
- Data Logged: These entries record events such as logins, registrations, referral trail mappings, report filings, and moderation actions, alongside IP addresses, raw user agents, and MaxMind GeoIP2 location markers.
- Anonymization Upon Deletion: You may request deletion of your account at any time by contacting us. Upon account removal, your public profile identity fields are deleted. To ensure platform integrity, security audit log entries are retained indefinitely but are completely anonymized—the system severs all links to your individual identity (user_id becomes null), permanently rendering the remaining log data anonymous.
- Notebook Deletion and Backups: Account deletion permanently removes live notebook records authored by or about the account, their rating answers, and reminders in either direction. Deleted notebook data remains only in encrypted backups until those backups expire under the normal backup retention schedule.
4. Analytics
We use Matomo in two separate properties to understand how ClaySquad is used and to detect abuse and technical problems.
- Server analytics: For every request handled by ClaySquad, Matomo receives the request method, response status class, normalized page or route class, request type, request IP address, browser language and user agent, referrer where supplied, and the account's retained internal User ID when signed in. For completed registration, it also receives the registration country and authentication method. We record confirmed account, squad, following, connection, and check-in outcomes here.
- Browser analytics: Matomo receives browser and device information, referrer, page views, navigation and CTA choices, search and filter interactions, onboarding/page views, and client-side errors. It does not receive confirmed product outcomes from the browser.
- Location: The server property may derive country, region, city, and approximate latitude and longitude from the request IP using MaxMind GeoIP data. ClaySquad does not collect browser GPS coordinates for analytics.
- Retention: Matomo retains this analytics data according to the retention settings configured by ClaySquad in Matomo administration.
5. Children's Privacy (COPPA)
The Service is strictly restricted to individuals aged 18 and older. We do not knowingly collect or solicit personal information from anyone under the age of 13 or 18. If we discover that a minor has bypassed registration and created an account, we will terminate it and delete all associated data immediately.