Skip to main content

Privacy Policy

Effective Date: May 28, 2026 · Version 1.7

Hunt Outfitter (“we,” “us,” or “our”) is operated by OnX BizTech LLC. This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use the Hunt Outfitter platform (“Service”).

1. Information We Collect

1.1 Information You Provide

  • Account information: name, email address, phone number, and login credentials. If you sign in with Google, we receive your name, email address, and profile picture from your Google account.
  • Lead capture information: if you submit a lead capture form on an outfitter’s website or landing page (before creating an account), we collect your name, email address, phone number, hunt interest, and any additional notes you provide.
  • Client profile data: mailing address, date of birth, emergency contacts, dietary restrictions, medical conditions, fitness level, and hunting experience.
  • Identification documents: passport number, driver’s license number, wildlife identification numbers (e.g., fish & wildlife IDs), and species tag numbers.
  • Firearms information: firearm type, make, model, caliber, serial number, and declaration status.
  • Travel details: flight information, vehicle details, hotel reservations, and meeting point preferences.
  • Payment information: payment amounts and records are stored in our system; credit card details are processed and stored exclusively by Stripe, our PCI-compliant payment processor.
  • Photos and uploads: profile pictures, identification document photos (FWID cards, hunting tags), gallery images, form templates, and expense receipts. These files are stored in Supabase Storage.
  • Feedback and testimonials: post-hunt feedback including ratings, written testimonials, and whether you consent to public display of your testimonial.
  • Document signing data: when you sign a document through the platform, we record the signature (checkbox confirmation or drawn signature image), signing timestamp, IP address, and browser user agent as part of the signing audit trail.
  • Hunt sign-off data: when you confirm completion of a hunt, we record the confirmation timestamp and any optional notes you provide.
  • Communications: messages, notes, and other content you provide through the platform.

1.2 Information Collected Automatically

  • IP address and approximate location.
  • Browser type, device information, and operating system.
  • Pages visited, features used, and timestamps of activity.
  • Authentication tokens and session data.
  • Anonymous usage analytics collected by Vercel Analytics (page views, navigation patterns). Vercel Analytics does not use cookies and does not collect personally identifiable information.

1.3 Consent Records

When you accept this Privacy Policy or our Terms of Service, we record your acceptance along with the version accepted, timestamp, IP address, and browser user agent. This information is retained to demonstrate your informed consent.

2. How We Use Your Information

  • To provide and operate the Service, including booking management, client profiles, document tracking, and gallery management.
  • To facilitate communication between outfitters, guides, and clients.
  • To process payments and send transactional notifications (booking confirmations, payment receipts, document reminders).
  • To send automated operational emails, including hunt reminders and payment due notifications, based on your booking schedule.
  • To send SMS text-message notifications for transactional and operational events (such as booking confirmations, payment reminders, document notifications, and hunt reminders) to registered users who have opted in to SMS in their notification preferences. Transactional SMS is off by default. Message and data rates may apply. You can opt out at any time by replying STOP to any message or by disabling SMS in your notification preferences.
  • To send marketing text messages (SMS) about hunting trips, promotions, and updates to prospective clients (leads) who have provided express consent via our lead capture form. Marketing SMS is only sent with your explicit opt-in. Message frequency varies. Message and data rates may apply. Reply STOP to unsubscribe at any time, HELP for help. Mobile opt-in information and phone numbers collected for SMS marketing will not be shared with or sold to third parties for marketing purposes.
  • To display your testimonial on your outfitter’s public landing page, only if you have explicitly consented to public display.
  • To comply with legal obligations, including firearms declaration requirements and hunting license regulations.
  • To enforce document signing requirements before payment processing, when configured by the outfitter organization.
  • To store payment configuration preferences (such as accepted payment methods) set by each outfitter organization.
  • To maintain an activity audit trail for security and accountability.
  • To improve the Service and develop new features.
  • To protect against fraud and ensure platform security.

3. How We Share Your Information

We do not sell your personal information. We share data only in the following circumstances:

  • With your outfitter organization: Outfitters and their authorized staff (guides, admins) can access client data within their organization for the purpose of managing hunts and bookings.
  • Across multiple outfitter organizations (if applicable): If you are a client at more than one outfitter organization on the platform, your shared profile data — name, contact information, mailing address, date of birth, identification documents (passport, driver’s license, FWID), emergency contact, fitness/health self-reporting, dietary restrictions, hunting experience, and uploaded license photos — is visible to each outfitter you are actively booked or active with. This lets you fill out your profile once and re-use it across operators. Each outfitter only sees your relationship-level data (booking status, internal notes, hunt tag information, per-trip companion contact) within their own organization.
  • With service partners: If an outfitter designates a partner (e.g., meat processor, taxidermist), relevant booking and contact information may be shared with that partner to fulfill post-hunt services, with your knowledge.
  • Public testimonials: If you submit a testimonial and consent to public display, your first name, last initial, location, hunt type, and testimonial text may be displayed on your outfitter’s public landing page. You may withdraw this consent at any time by contacting your outfitter or us.
  • With third-party service providers: We use the following services to operate the platform:
    • Supabase (database hosting, file storage, and authentication)
    • Vercel (application hosting and anonymous usage analytics)
    • Google (OAuth authentication, if you choose to sign in with Google)
    • Stripe (payment processing)
    • Resend (transactional email delivery)
    • Twilio (SMS text-message delivery, for users who opt in to transactional SMS notifications and leads who consent to marketing SMS)
  • As required by law: We may disclose information to comply with legal obligations, law enforcement requests, or to protect rights and safety.

4. Data Storage and Security

  • Your data is stored on servers operated by Supabase (AWS infrastructure) in the United States (us-west-1 region).
  • Uploaded files (photos, documents, receipts) are stored in Supabase Storage with role-based access policies.
  • Data is encrypted at rest and in transit using industry-standard encryption.
  • Access to production data is restricted to authorized personnel only.
  • We implement role-based access controls so that outfitters can only access data within their own organization.

5. Data Retention

We retain your personal information according to the following schedule:

  • Active accounts: Your data is retained for the duration of your active account.
  • Deleted accounts: Upon account deletion, personal data (profile, contact information, preferences) is purged within 90 days.
  • Financial records: Booking and payment records are retained for 7 years after the transaction date to comply with IRS record-keeping requirements and applicable tax law.
  • Consent records: Records of your consent (privacy policy acceptance, terms acceptance) are retained indefinitely as proof of informed consent.
  • Uploaded files: Photos, documents, and receipts are deleted when your account is removed, unless they are part of a financial record subject to the 7-year retention period.

You may request deletion of your data at any time (see Section 8). Deletion requests are subject to the retention periods described above.

6. Cookies and Tracking

6.1 What Are Cookies

Cookies are small text files stored on your device by your web browser. They are widely used to make websites work, maintain your session, and remember preferences.

6.2 Cookies We Use

Hunt Outfitter uses only strictly essential cookies required for the Service to function. We do not use any optional, advertising, or tracking cookies.

  • Authentication session (sb-*-auth-token): Set by Supabase when you sign in. These cookies maintain your authenticated session so you stay logged in as you navigate the platform. They persist until you sign out or they expire, and are scoped to the .huntoutfitter.app domain to support subdomain portal access.
  • PKCE code verifier (sb-*-auth-token-code-verifier): A temporary cookie used during the OAuth sign-in flow to securely complete the authentication handshake. It is deleted automatically after sign-in completes.

We also store a cookie-banner-dismissed flag in your browser’s local storage (not a cookie) to remember that you have acknowledged this notice.

6.3 Third-Party Cookies

We do not set or allow any third-party cookies. No advertising networks, social media trackers, or cross-site tracking pixels are present on Hunt Outfitter.

6.4 Analytics

We use Vercel Analytics to collect anonymous, aggregated usage data (page views and navigation patterns). Vercel Analytics is cookieless and does not collect personally identifiable information. No data from Vercel Analytics is shared with third parties.

6.5 Managing Cookies

You can view and delete cookies through your browser settings. Because we only use essential cookies, blocking or deleting them will sign you out and may prevent you from using the Service. There are no optional cookies to disable.

7. Do Not Sell or Share My Personal Information

We do not sell, rent, or share your personal information with third parties for their own marketing purposes. We do not participate in data brokerages or sell user data in any form. This applies to all users, including California residents under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA).

If you are a California resident, you have the right to know what personal information we collect, request its deletion, and opt out of any sale of personal information. Since we do not sell personal information, there is no need to opt out, but you may still exercise your other rights as described in Section 8 below.

8. Your Rights

Depending on your jurisdiction (including rights under PIPEDA for Canadian residents and CCPA/CPRA for California residents), you may have the right to:

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete information.
  • Deletion: Request deletion of your personal information, subject to legal retention requirements.
  • Data portability: Request an export of your data in a machine-readable format.
  • Withdraw consent: Where processing is based on consent (including testimonial display), you may withdraw it at any time.

To exercise any of these rights, contact us at privacy@huntoutfitter.app.

9. Data Breach Notification

In the event of a confirmed data breach that affects your personal information, we will notify affected users within 72 hours of becoming aware of the breach, in accordance with GDPR requirements and industry best practices. Notification will be provided via email and, where possible, through an in-app notification. The notice will describe the nature of the breach, the types of data involved, the steps we are taking in response, and recommended actions you can take to protect yourself.

10. Children’s Privacy

The Service is not directed to individuals under 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact us.

11. International Data Transfers

If you are located outside the United States, your data will be transferred to and processed in the United States. By using the Service, you consent to this transfer.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the effective date. If you have an account, we may also send you an in-app notification. Continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at: