This policy applies only from v1.0.0 onward. Earlier versions (v0.7.x and below) collected no data of any kind — they were fully offline, single-device tools with no cloud relay. If you are using v0.7.x or earlier, no information about you is collected or stored anywhere outside your own device.
BassBuddy is a personal Android app for logging bass fishing catches, owned and operated by XtendIT Agricultural Solutions PTY (LTD), a registered South African entity. Contact: bassbuddy@xtendit.co.za.
Under the Protection of Personal Information Act 4 of 2013 (POPIA), XtendIT Agricultural Solutions PTY (LTD) is the Responsible Party for any personal information processed through BassBuddy and its relay service. Information Officer: cvs (escalation only — please use the support email for routine matters).
Nothing. The app makes no calls to our servers, sends no analytics, and collects no information about you. The only outbound network traffic is to Open-Meteo (weather), OpenStreetMap (map tiles), and Google's URL unshortener (only when you paste a Google Maps link to import a location). We do not see, log, or store any of these requests.
When you tap Enable Buddies, we generate and store:
| Information | Purpose | Retention |
|---|---|---|
Pseudonymous handle (e.g., a4b9c2) | Identifies your device on the relay so buddies can send you items | Until you delete your data |
| Bearer token | Authenticates your device's requests | Until you delete your data |
| Optional display name | What buddies see when you push something to them. You choose this; default is blank | Until you change or delete it |
| Buddy relationships | The handles of people you've added as buddies | Until you remove the buddy or delete your data |
| Consent timestamp + policy version | Records that you agreed to this policy on a specific date | Until you delete your data |
| Item | Contents | Retention |
|---|---|---|
| Inbox items (catch alerts, brag cards, trip invites, PB announcements, trip reports) | The item payload + recipient handles | 7 days, or until all recipients have acknowledged receipt, whichever is first |
| Photos attached to shared items | Compressed JPEG thumbnail (max 1080px long edge, EXIF stripped) | Same as the item it's attached to |
| Live trip locations | Latitude/longitude packets pushed during an active shared trip | Replaced on each new packet; deleted when the trip ends or you stop sharing |
| Trip broadcast group membership | Which buddies have accepted which trip | Trip's planned window + 24 hours |
| Public share links | Brag card content + the short URL | 90 days from creation, or until you revoke the share |
| Invite codes | The 6-character code itself | 24 hours regardless of use |
Our hosting provider (Afrihost) and CDN (Cloudflare) automatically log HTTP requests for security and abuse-prevention. These logs include source IP, timestamp, endpoint, response status, and user-agent. We do not access these logs routinely. Retention: 30 days at Cloudflare, 14 days at Afrihost. We do not link IP addresses to your handle in our application database.
If you enable Crash reports in Settings → Owner (default: OFF), the app sends anonymous crash diagnostics to Sentry. What Sentry sees: crash stack trace, app version, Android version, device model, approximate region (IP-derived by Sentry), app breadcrumbs (last 100 screen transitions). What Sentry never sees, enforced by code in the app: your handle or display name, any buddy data, any catch data, GPS coordinates, photos, or anything from your local database. You can turn this off any time.
| Information | Lawful basis |
|---|---|
| Pseudonymous handle, token, buddy relationships, shared items | Consent — captured when you enable Buddies, time-stamped, revocable |
| Server access logs (IPs) | Legitimate interest — abuse prevention, security, service operation |
| Crash reports | Consent — separate opt-in, OFF by default |
You can withdraw consent at any time. Withdrawing stops further processing and triggers deletion.
| Sub-processor | Purpose | Where they store data |
|---|---|---|
| Afrihost (SA) | Hosting the relay API and database | South Africa |
| Cloudflare (global) | TLS termination, DDoS protection, request caching, edge logs | Global edge network |
| Sentry (only if Crash reports enabled) | Crash diagnostics | United States / European Union |
| Open-Meteo (app, not relay) | Weather forecasts | European Union |
| OpenStreetMap Foundation (app, not relay) | Map tiles | UK / Global |
We do not share your data with advertisers, analytics companies, data brokers, or marketing partners. We have never received or complied with a government data request — if we ever do, we will note it in this policy without naming the request (a "warrant canary").
Cross-border transfers: Cloudflare and Sentry process data outside South Africa. POPIA permits this when the recipient is subject to a law providing adequate protection. By enabling Buddies (and, separately, Crash reports), you consent to these transfers.
You have the right to:
DELETE /me on the relay. Items already delivered to other buddies' devices cannot be recalled.We respond within 30 days, usually much sooner.
password_hash()) in the relay database; never logged in plaintext.If a data breach materially affects your personal information, we notify the Information Regulator and affected users within 72 hours, as required by POPIA.
BassBuddy is not directed at children under 18. We do not knowingly collect data from minors. If you believe a minor has registered, contact us and we will delete the data.
Material changes (new data collected, new sub-processors, longer retention) are announced in-app the next time you open Buddies, with the option to review and re-consent. Non-material changes (typo fixes, contact info updates) take effect on publication.
| Version | Date | Changes |
|---|---|---|
| 1.0 | 2026-06-30 | Initial policy — covers v1.0.0 launch. |
For any privacy matter — questions, complaints, data requests, security disclosures:
bassbuddy@xtendit.co.za
Include your handle (visible in Buddies → top of screen) so we can identify your data. If you've already deleted your data, just describe the issue.