This policy explains what Tally Tracker collects, why we collect it, who we share it with, and how you can see, change, or delete it. We've written it in plain English. If something here doesn't make sense, email us at tallytrackercustomerservices@gmail.com and we'll explain.

1. Who we are

Tally Tracker is a water-safety companion app for sailing clubs, paddling groups, swimming clubs, commercial vessel operators, race officers, and solo voyagers. The app is operated by Martingale House Ltd, trading as Tally Tracker, United Kingdom. We are the data controller for the data described below. Contact: tallytrackercustomerservices@gmail.com.

2. What the app actually does

When you "tally on" before going afloat, the app:

When you tally off, the live sharing stops. The session and its track are kept for your history (and the club's, where the session was a club session) so you can replay it later.

The way you go afloat changes who can see you:

3. What we collect

The lists below cover both the iPhone and Android apps, and mirror the privacy disclosures we file with the App Store and Google Play. None of this is used to track you across other apps or websites, and none of it is sold or shared with data brokers.

Identity and contact

Location

Identifiers

Media

Health (Apple Watch only, with your permission)

Session data

Tally on/off events, status changes, assistance requests, ship's log entries, race results, mark crossings, wind observations, photos, and chat messages — everything that makes the session a usable record afterwards.

Subscription

Subscription status — on iPhone we use Apple's StoreKit and on Android we use Google Play Billing to check whether you have an active Tally Tracker subscription and (optionally) the Race Officer Portal add-on. We never see your card details; Apple and Google handle that.

Crash and diagnostic data

Firebase Crashlytics collects crash stack traces and basic device model/OS information to help us fix bugs. This is anonymous and not linked to your account.

4. What we don't collect or do

5. Why we collect each thing

Safety oversight (legitimate interest, with your active opt-in to each session)

Your name, contact details, live GPS, status, and assistance requests are visible to the people running the session you tallied into. This is the entire point of the app; it's what gives you accountability if you don't return.

Spectator following (explicit consent, revocable any time)

Friends, family, or coaches you have given a six-character spectator code can see what you allow. You can pause sharing per session, pause it indefinitely, or remove a follower from your profile.

Session history (legitimate interest)

Your tracks and session events are saved against your sailor profile so you can replay them and so the club has an audit trail. You can export or delete a session at any time.

Account and subscription (contract)

Authentication, profile setup, subscription validation, and customer-service correspondence.

6. Who we share data with

People in the same session as you

When you take part in a session, your tally-on details (name, boat, sail number, fleet, crew, emergency contact) and your live status and GPS position are visible to the other people in that session for as long as you're afloat: the other participants, the safety team, beachmaster and organiser, the coach (if the session has one — used for the post-session debrief), the race officer, and the club admin. That's how oversight works. For club sessions this only happens once an approver has admitted you — before you request to join, and while your request is pending, your details and position are not shared with the group. The app shows you a plain-English "what you share in this session" notice at the point you ask to join, so you can decide before submitting your request. If you don't want to share, don't join the session.

Approval and consent for club sessions

Club sessions are approval-only. A member asks to join — either by pre-registering before the session opens, or by requesting once it's live — and an approver (the session creator, on-duty safety or organiser, or a club admin) confirms them. This means a club controls who can see its members' live positions and details, rather than anyone with a code being able to join automatically. When a request is submitted, the app sends a push notification to the session's approvers so they can review it. The request carries the requester's name, the role they're asking for, and whether the participant is under 18. Approvers can approve, decline, and — for a youth request — must confirm that parental/guardian consent has been checked before approving.

Spectators you have invited

Each follower sees only what your sharing settings allow. You can pause or remove them at any time from your profile.

Nearby app users, if you make an assistance request public

If you raise an assistance request and choose to make it public, other app users who are afloat within about five nautical miles of you can see your position, bearing and distance, and can read and send messages in the assistance chat — so someone nearby can help. This only happens if you actively escalate the request to public; a normal assistance request stays with the people running your session.

Event organisers

When you sign up to an event, your registration — including your answers to any entry questions the organiser has set — is shared with that club or organiser, appears on their entry list, and can be exported by them (for example to a CSV for the race office).

Public event and race pages

A club or organiser can turn on a public entry list, a public live race page, or a public notice board for a session. When they do, the information they choose to publish — which can include participant names, sail numbers, live positions and tracks, and results — is visible to anyone with the link, without signing in. Whether a session has any public page is controlled by the club or organiser running it, not by us.

Service providers we use to run the app

We do not share data with any other third party.

When the law requires

We will disclose data if compelled by a valid legal request from UK authorities. We will tell you unless we are legally prohibited from doing so.

7. International transfers

The Tally Tracker Firebase backend (database, serverless functions and storage) is currently hosted in the United States. Firebase Authentication, Apple Push Notification Service and Google Play services route metadata through Google and Apple infrastructure that may also be located outside the UK and EEA. All such transfers happen under Google's and Apple's standard contractual clauses for international data transfers, which are the safeguards the UK ICO recognises for transfers outside the UK. We are evaluating a migration to a UK region in a future release and will update this policy when that happens.

8. How long we keep things

9. Your rights

You can, at any time:

Most requests are handled within seven days; complex requests within one month.

10. How we protect your data

11. Children and under-18 participants

Tally Tracker is rated 4+ but it is intended for use by people who are competent on the water, or under the supervision of a responsible adult. Youth sailing programmes typically operate with the responsible adult holding the iPhone and tallying the child on.

The app supports an "Under 18" flag that a participant can set once on their profile. When set, the participant is itemised as a youth wherever they take part, so the people running a session know a minor is on the water:

We do not knowingly collect data from children under 13 without verifiable parental consent. Where a club enables youth participation, the club (as the organisation running the session) is responsible for obtaining and holding the underlying parental consent for the children in its care; Tally Tracker records the in-app confirmation that consent was checked, but is not itself the keeper of the consent paperwork. If you believe a child has provided us with personal data without appropriate consent, email us at tallytrackercustomerservices@gmail.com and we'll delete it.

12. Push notifications

Push is used for assistance alerts, race start countdowns, spectator follow updates, status changes, chat messages, and — for approvers on a club session — new join-request notifications (carrying the requester's name, the session name, and the role they're requesting). Push payloads can contain the sailor's display name, the session name, the type of alert (eg "assistance requested"), and the first line of any chat message — so that the alert is meaningful at a glance on a locked screen. Push notifications travel via Apple's Push Notification Service (APNs) on iPhone and Apple Watch, and via Firebase Cloud Messaging / Google Play services on Android; we don't have access to push delivery logs beyond confirmation that Apple or Google accepted the payload. You can disable push entirely in your device's notification settings for Tally Tracker (on iPhone: Settings → Notifications → Tally Tracker; on Android: Settings → Apps → Tally Tracker → Notifications).

13. Subscriptions

Tally Tracker is a subscription app — an active subscription is required to use it. The annual Tally Tracker subscription unlocks the full app: live tracking, safety oversight, assistance, voyage log, ship's log, Watch app, Live Activities, and competing in races. The Race Officer Portal is available as an annual add-on for race officers and clubs running races. Billing is handled entirely by Apple (on iPhone, via StoreKit) or Google (on Android, via Google Play Billing); we only ever receive a yes/no entitlement and never see your payment details. Current prices are shown in the app and on the store listing. You can cancel any time from your subscription settings — on iPhone via Settings → Apple ID → Subscriptions, on Android via Google Play → Subscriptions.

14. Liability and the on-water disclaimer

Before using safety-critical features you accept a separate liability disclaimer (currently version 2026-04-v2). That disclaimer is a contract between you and Tally Tracker and is not part of this privacy policy, but you can review it in the app at any time under Profile → Liability Acceptance.

15. Cookies and analytics

The iPhone and Android apps don't use cookies. We don't use third-party product-analytics or ad-attribution SDKs such as Mixpanel, Amplitude, Segment, Adjust, AppsFlyer or Branch, and we don't target advertising or profile you. Our diagnostic data is Firebase Crashlytics crash reports. On Android, Firebase Analytics is included as part of Firebase's crash-reporting and stability tooling; we use it only for aggregate crash-free and stability metrics, not to identify or track you.

16. Changes to this policy

We'll update this page when the app changes in a way that affects what we collect or how we use it. Material changes will be announced in the app and via push notification. The "Last updated" date at the top of this page tells you when the policy last changed.

17. Contact

Tally Tracker · United Kingdom · tallytrackercustomerservices@gmail.com

If you've read this far — thanks. Stay safe on the water.