This policy explains what Tally Tracker collects, why we collect it, who we share it with, and how you can see, change, or delete it. We've written it in plain English. If something here doesn't make sense, email us at tallytrackercustomerservices@gmail.com and we'll explain.
1. Who we are
Tally Tracker is a water-safety companion app for sailing clubs, paddling groups, swimming clubs, commercial vessel operators, race officers, and solo voyagers. The app is operated by Martingale House Ltd, trading as Tally Tracker, United Kingdom. We are the data controller for the data described below. Contact: tallytrackercustomerservices@gmail.com.
2. What the app actually does
When you "tally on" before going afloat, the app:
- For club sessions, first asks permission. You request to join the session and an approver — the session creator, the on-duty safety team or organiser, or a club admin — confirms you before you go on the water. Until you're approved, none of your details or location are shared with anyone. This protects members' privacy: nobody joins a club session, or appears on its live map, without the club letting them in.
- Records who you are (name, sail number, fleet, boat, emergency contact), how to reach you (phone, email), and where you are (live GPS).
- Tells the people taking part in your session — the other participants, the safety team, beachmaster, organiser, coach, race officer, and club admin, and anyone you have explicitly shared a spectator code with — that you are afloat, and lets them see your live position and status until you tally off.
- Optionally lets you request assistance, send chat messages to safety responders, and capture session photos.
When you tally off, the live sharing stops. The session and its track are kept for your history (and the club's, where the session was a club session) so you can replay it later.
The way you go afloat changes who can see you:
- Solo — you go out on your own. Your live position and details are not shared with any group; only you can see them, plus anyone you have given a spectator code.
- With a group — you create or join a session by sharing a short code. Everyone who has the code and joins takes part in the same session and can see each other's live position and status.
- With a club — you request to join and an approver admits you first (see below). Nothing is shared until you are approved.
- At an event — you sign up to a club or group event, which may ask you to answer entry questions, and then take part in the event's sessions in the same way.
3. What we collect
The lists below cover both the iPhone and Android apps, and mirror the privacy disclosures we file with the App Store and Google Play. None of this is used to track you across other apps or websites, and none of it is sold or shared with data brokers.
Identity and contact
- Name — sailor display name, emergency contact name, crew name, beachmaster name.
- Email address — the email you use to sign in, plus the emails of any spectators you invite.
- Phone number — the mobile number on your sailor profile, your emergency contact's number, and (optionally) a beachmaster's mobile so safety can call them.
Location
- Precise GPS — latitude, longitude, accuracy, speed, heading, and battery level from your device, recorded as a continuous breadcrumb trail while you are afloat.
- Coarse location — used to find nearby clubs and nearby voyagers within five nautical miles when those features are enabled.
Identifiers
- Firebase Auth user ID (UID) — a random string Firebase assigns to your account.
- Device ID — a per-install device identifier we use to register the device with a club and resume an active session after a relaunch.
- FCM push notification tokens — a per-install token Apple/Google issues so we can deliver push notifications.
Media
- Photos — your profile photo, club branding photos you upload as an admin, and any session photos you add during or after a session.
- Voice messages — when you record a voice message in assistance chat (from the iPhone or the Apple Watch), the recording is uploaded to Cloud Storage and shared with the safety responders on the receiving end of the chat. Recordings are limited to 30 seconds. We only record when you explicitly hold the record button — we never listen passively.
Health (Apple Watch only, with your permission)
- Heart rate — read from HealthKit while the Watch workout session is active during a tally-on, displayed on the Watch and (optionally) shared with the safety team and your spectators in real time.
Session data
Tally on/off events, status changes, assistance requests, ship's log entries, race results, mark crossings, wind observations, photos, and chat messages — everything that makes the session a usable record afterwards.
Subscription
Subscription status — on iPhone we use Apple's StoreKit and on Android we use Google Play Billing to check whether you have an active Tally Tracker subscription and (optionally) the Race Officer Portal add-on. We never see your card details; Apple and Google handle that.
Crash and diagnostic data
Firebase Crashlytics collects crash stack traces and basic device model/OS information to help us fix bugs. This is anonymous and not linked to your account.
4. What we don't collect or do
- We don't track you across other apps or websites.
- We don't sell or share your data with brokers.
- We don't show ads.
- We don't collect contacts, calendar, browsing history, financial information, or sensitive personal information such as race, religion, sexual orientation, biometrics, or government IDs.
5. Why we collect each thing
Safety oversight
Your name, contact details, live GPS, status, and assistance requests are visible to the people running the session you tallied into. This is the entire point of the app; it's what gives you accountability if you don't return.
Spectator following
Friends, family, or coaches you have given a six-character spectator code can see what you allow. You can pause sharing per session, pause it indefinitely, or remove a follower from your profile.
Session history
Your tracks and session events are saved against your sailor profile so you can replay them and so the club has an audit trail. You can export or delete a session at any time.
Account and subscription
Authentication, profile setup, subscription validation, and customer-service correspondence.
6. Who we share data with
People in the same session as you
When you take part in a session, your tally-on details (name, boat, sail number, fleet, crew, emergency contact) and your live status and GPS position are visible to the other people in that session for as long as you're afloat: the other participants, the safety team, beachmaster and organiser, the coach (if the session has one — used for the post-session debrief), the race officer, and the club admin. That's how oversight works. For club sessions this only happens once an approver has admitted you — before you request to join, and while your request is pending, your details and position are not shared with the group. The app shows you a plain-English "what you share in this session" notice at the point you ask to join, so you can decide before submitting your request. If you don't want to share, don't join the session.
Approval and consent for club sessions
Club sessions are approval-only. A member asks to join — either by pre-registering before the session opens, or by requesting once it's live — and an approver (the session creator, on-duty safety or organiser, or a club admin) confirms them. This means a club controls who can see its members' live positions and details, rather than anyone with a code being able to join automatically. When a request is submitted, the app sends a push notification to the session's approvers so they can review it. The request carries the requester's name, the role they're asking for, and whether the participant is under 18. Approvers can approve, decline, and — for a youth request — must confirm that parental/guardian consent has been checked before approving.
Spectators you have invited
Each follower sees only what your sharing settings allow. You can pause or remove them at any time from your profile.
Nearby app users, if you make an assistance request public
If you raise an assistance request and choose to make it public, other app users who are afloat within about five nautical miles of you can see your position, bearing and distance, and can read and send messages in the assistance chat — so someone nearby can help. This only happens if you actively escalate the request to public; a normal assistance request stays with the people running your session.
Event organisers
When you sign up to an event, your registration — including your answers to any entry questions the organiser has set — is shared with that club or organiser, appears on their entry list, and can be exported by them (for example to a CSV for the race office).
Public event and race pages
A club or organiser can turn on a public entry list, a public live race page, or a public notice board for a session. When they do, the information they choose to publish — which can include participant names, sail numbers, live positions and tracks, and results — is visible to anyone with the link, without signing in. Whether a session has any public page is controlled by the club or organiser running it, not by us.
Service providers we use to run the app
- Google Firebase — we use Google's Firebase platform for the app's database, authentication, storage (photos and voice messages), serverless functions, push messaging, crash reporting and web hosting. The Tally Tracker backend is currently hosted in the United States. We are evaluating a move to a UK region in a future update; until then your data is processed under Google's standard contractual clauses for international transfers.
- Apple — App Store / StoreKit (subscriptions on iPhone), Push Notification Service, HealthKit (heart rate, on-device on the Apple Watch).
- Google Play — Play Billing (subscriptions on Android) and Google Play services for push delivery on Android.
- Google Sign-In and Apple Sign-In — if you use these to sign in, the provider passes your email and name to us. We don't get your password or any other Google/Apple profile data.
- Gmail SMTP — used to send transactional emails (password reset, club approval notifications) from
tallytrackercustomerservices@gmail.com. - Web3Forms — used by the contact and fleet registry forms on
tallytracker.co.ukto relay form submissions to our support inbox. Anything you type into those public website forms passes through Web3Forms.
We do not share data with any other third party.
When the law requires
We will disclose data if compelled by a valid legal request from UK authorities. We will tell you unless we are legally prohibited from doing so.
7. International transfers
The Tally Tracker Firebase backend (database, serverless functions and storage) is currently hosted in the United States. Firebase Authentication, Apple Push Notification Service and Google Play services route metadata through Google and Apple infrastructure that may also be located outside the UK and EEA. All such transfers happen under Google's and Apple's standard contractual clauses for international data transfers, which are the safeguards the UK ICO recognises for transfers outside the UK. We are evaluating a migration to a UK region in a future release and will update this policy when that happens.
8. How long we keep things
- Sailor profile — kept until you delete it.
- Session history — kept until you or the club admin delete it.
- GPS breadcrumbs — kept with the session they belong to.
- Session photos — automatically deleted from Cloud Storage 10 days after the session ends.
- Voice messages — kept alongside the assistance chat they belong to. When the assistance request is resolved, the chat (text + voice) is moved to an archive subcollection then deleted from the live collection.
- Assistance chat — moved to an archive subcollection when the assistance request is resolved, then deleted from the live collection.
- Solo sessions — auto-expire 12 hours after tally on if you don't tally off.
- Push notification tokens — invalidated at sign-out; any stale tokens left under a previous profile are automatically cleared on the next sign-in, so notifications for an old profile never leak to the device.
- Email queue — outbound emails older than 7 days are deleted.
- Crashlytics — Firebase's default retention applies (typically 90 days).
- Liability acceptances — kept indefinitely as proof the disclaimer was accepted.
9. Your rights
You can, at any time:
- See your data — your profile, session history, followers, and any racing or admin data is visible inside the app. We can also send you a JSON export by email on request.
- Correct your data — edit your profile, session, boats, crew, or club details in the app.
- Delete your data — delete your profile via Profile → Account. Sessions you participated in inside a club may be retained by the club admin as part of their oversight log.
- Withdraw consent — unfollow sailors, pause sharing, sign out, or stop using the app.
- Object, restrict, or request portability — under UK GDPR. Email us.
- Complain to the ICO — the UK Information Commissioner's Office. We'd rather you tell us first so we can fix it.
Most requests are handled within seven days; complex requests within one month.
10. How we protect your data
- All traffic between the app and Firebase is over TLS.
- Firestore data is encrypted at rest by Google.
- Access is governed by server-side security rules that restrict who can read and write each type of data; we review and update them regularly.
- Sign-in uses Firebase Authentication. Passwords are hashed by Google; we never see them.
- Your Apple Watch syncs auth credentials over Apple's encrypted WatchConnectivity channel.
11. Children and under-18 participants
Tally Tracker is rated 4+ but it is intended for use by people who are competent on the water, or under the supervision of a responsible adult. Youth sailing programmes typically operate with the responsible adult holding the iPhone and tallying the child on.
The app supports an "Under 18" flag that a participant can set once on their profile. When set, the participant is itemised as a youth wherever they take part, so the people running a session know a minor is on the water:
- At tally-on and when requesting to join a club session, the under-18 status is pre-filled from the profile so it doesn't have to be re-entered each time.
- For club sessions, when a youth requests to join, the approver is required to confirm that parental/guardian consent has been checked before they can approve the request. The app records that this confirmation was made, together with who made it and when.
- The emergency-contact fields on a youth profile are used to hold the parent's or guardian's name and number.
We do not knowingly collect data from children under 13 without verifiable parental consent. Where a club enables youth participation, the club (as the organisation running the session) is responsible for obtaining and holding the underlying parental consent for the children in its care; Tally Tracker records the in-app confirmation that consent was checked, but is not itself the keeper of the consent paperwork. If you believe a child has provided us with personal data without appropriate consent, email us at tallytrackercustomerservices@gmail.com and we'll delete it.
12. Push notifications
Push is used for assistance alerts, race start countdowns, spectator follow updates, status changes, chat messages, and — for approvers on a club session — new join-request notifications (carrying the requester's name, the session name, and the role they're requesting). Push payloads can contain the sailor's display name, the session name, the type of alert (eg "assistance requested"), and the first line of any chat message — so that the alert is meaningful at a glance on a locked screen. Push notifications travel via Apple's Push Notification Service (APNs) on iPhone and Apple Watch, and via Firebase Cloud Messaging / Google Play services on Android; we don't have access to push delivery logs beyond confirmation that Apple or Google accepted the payload. You can disable push entirely in your device's notification settings for Tally Tracker (on iPhone: Settings → Notifications → Tally Tracker; on Android: Settings → Apps → Tally Tracker → Notifications).
13. Subscriptions
Tally Tracker is a subscription app — an active subscription is required to use it. The annual Tally Tracker subscription unlocks the full app: live tracking, safety oversight, assistance, voyage log, ship's log, Watch app, Live Activities, and competing in races. The Race Officer Portal is available as an annual add-on for race officers and clubs running races. Billing is handled entirely by Apple (on iPhone, via StoreKit) or Google (on Android, via Google Play Billing); we only ever receive a yes/no entitlement and never see your payment details. Current prices are shown in the app and on the store listing. You can cancel any time from your subscription settings — on iPhone via Settings → Apple ID → Subscriptions, on Android via Google Play → Subscriptions.
14. Liability and the on-water disclaimer
Before using safety-critical features you accept a separate liability disclaimer (currently version 2026-04-v2). That disclaimer is a contract between you and Tally Tracker and is not part of this privacy policy, but you can review it in the app at any time under Profile → Liability Acceptance.
15. Cookies and analytics
The iPhone and Android apps don't use cookies. We don't use third-party product-analytics or ad-attribution SDKs such as Mixpanel, Amplitude, Segment, Adjust, AppsFlyer or Branch, and we don't target advertising or profile you. Our diagnostic data is Firebase Crashlytics crash reports. On Android, Firebase Analytics is included as part of Firebase's crash-reporting and stability tooling; we use it only for aggregate crash-free and stability metrics, not to identify or track you.
16. Changes to this policy
We'll update this page when the app changes in a way that affects what we collect or how we use it. Material changes will be announced in the app and via push notification. The "Last updated" date at the top of this page tells you when the policy last changed.
17. Contact
Tally Tracker · United Kingdom · tallytrackercustomerservices@gmail.com
Tally Tracker