Skip to content

Privacy Policy

Last updated: September 12, 2026. This policy is part of our Terms of Use.

Cat Colony Tracker ("the App") is a free, non-profit project of Craig Cares. It exists to help volunteers look after community cats, not to collect data about people. This page describes, as plainly as we can, what information the App handles, why, and who else is involved.

1. Information we collect

1.1 Account information

  • Your email address, the name you enter, and an optional phone number on your profile.
  • Your password, which is handled by our authentication provider (Supabase Auth) and is never stored in plain text.
  • If you sign in with Google (where offered), Google shares your name, email address, and profile picture with us to create or sign in to your account.

1.2 Colony and cat records you create

Everything you and your fellow caretakers record in the App: colony names and locations (addresses and map coordinates), feeding stations, individual cats (names, descriptions, photos, TNR status, medical and vaccination records), sightings, behavioural observations, tasks, feeding logs and route runs, volunteer schedules, comments and messages, and any donation, expense, or inventory entries.

1.3 Volunteers without an account

A colony admin can add an "external volunteer" who does not have an account, along with that person's name and an email address and/or phone number. We use those details only to send schedule notifications and an invitation to claim the record as their own account. If you have been added this way and would rather not be, contact us at the address below and we will remove the record.

1.4 Technical information

Like any website, the servers that host the App (Netlify) and our backend (Supabase) receive your IP address and basic browser information in order to serve your requests. Usage analytics are collected only if you accept them (see section 4).

2. How we use it

  • To run the App and show each colony team its own records.
  • To coordinate care: schedules, coverage requests, tasks, and notifications to the people involved.
  • To send schedule notifications by email or SMS to external volunteers who were added by a colony admin.
  • To understand, in aggregate, which features are used so we can improve the App (only with your analytics consent).

We do not sell your data, we do not show advertising, and we do not share your data with third parties for marketing purposes.

3. Who can see your data

  • Other caretakers in your colonies. Access is role-based: what each caretaker can see and edit depends on the role they hold in that colony (for example, medical records require a medical role). Your name is shown alongside the records you create so teammates know who logged what.
  • Service providers listed in section 5, strictly to operate the App.
  • Authorities, only if we are legally required to disclose information.

Please use discretion when recording exact colony locations and when referring to other volunteers, and only share information about other people with their consent (see the Terms of Use).

4. Analytics (Google Analytics 4)

We use Google Analytics 4 to learn how the App is used. The Google Analytics script is not loaded until you click Accept on the consent banner; if you decline or never answer, nothing is sent to Google Analytics. You can change your choice at any time below.

When analytics is on, we record:

  • Page views and the standard Google Analytics session data.
  • These app events: sign_up, colony_created, join_requested, cat_added, activity_logged, quick_start_opened, quick_start_step_done, and quick_start_dismissed.
  • Event details limited to random record identifiers (UUIDs) and fixed category labels such as the activity type or the sign-up method. We never send names, email addresses, phone numbers, addresses, or map coordinates to analytics.
  • While you are signed in, your account's random identifier is attached as the analytics user ID so that a single person is not counted as several users. It is not your email or name.

Google processes this data under its own privacy policy and may set analytics cookies (for example _ga) once the script is loaded.

Your current analytics choice on this device: ...

5. Third-party services

  • Supabase - authentication, database, and file storage. All account data, colony records, and uploaded photos are stored here.
  • Netlify - hosts the website.
  • Google Maps - powers colony maps, location picking, and Street View. Map scripts and tiles are loaded from Google, which receives your IP address and the map areas you view.
  • Google Analytics - usage analytics, only after you accept (section 4).
  • Google Sign-In - optional sign-in method, where offered.
  • Unsplash - stock photographs used for decorative images and empty states are loaded from Unsplash's servers. If you use the photo search feature, your search terms are sent to the Unsplash API.
  • Resend (email) and Twilio (SMS) - deliver schedule notifications and claim invitations to external volunteers. Their email address or phone number is shared with the respective provider for delivery.

6. Cookies and data stored on your device

  • Sign-in cookies from Supabase Auth keep you signed in. They are essential and are not used for tracking.
  • Browser storage (localStorage) remembers your preferences on this device: light or dark theme, list and view modes, your default colony, dismissed tips and the welcome tour, and your analytics choice.
  • Offline cache. The App can be installed as a progressive web app. Its service worker caches app files, images, and recently loaded data on your device so pages keep working with a poor connection. Clearing your browser's site data removes it.
  • Google Analytics cookies are only set after you accept analytics (section 4).

7. Security

The App is served over HTTPS. Database access is protected by row-level security rules so that each record is only readable and editable by members of the relevant colony with the appropriate role. Passwords are handled by Supabase Auth and never stored in plain text. No system is perfectly secure, so please use a strong password and never share your login.

8. Your choices and deleting your data

  • You can edit your name, email, and phone number on your profile page at any time.
  • You can turn analytics on or off in section 4 above.
  • To delete your account, or to ask what data we hold about you, email help@craigcares.org from the address on your account. Colony records you contributed (cats, sightings, logs) belong to the colony and may be kept so the team's history stays intact, but they will no longer be linked to your name.

9. Changes and contact

We may update this policy as the App changes; the date at the top shows the latest revision. Questions about privacy can be sent to help@craigcares.org.