AnglerDash

Legal

Privacy policy.

How AnglerDash collects, uses and protects personal information.

Last updated: 27 July 2026

This policy explains what personal information AnglerDash Limited ("AnglerDash", "we", "us") collects through the AnglerDash mobile app and this website, why we collect it, who it is shared with, and the choices you have. It applies to everyone who uses AnglerDash, wherever you fish.

The short version

  • We collect the minimum we need to run the app: your account details, the fishing data you choose to record, and location when you use location features.
  • Your fishing spots are private. Precise coordinates are never published, never shown to other users, and never sent to our forecast providers.
  • Catches are private by default. If you choose to share one, it appears under a broad fishing region — never at the spot you caught it.
  • We do not sell your personal information, we do not share it for advertising, and there are no advertising or analytics trackers in the app.
  • You can access, correct, export or delete your data at any time.
  • AnglerDash is not intended for anyone under 13.

The sections below set out the detail. The short version is a summary only — it does not replace what follows.

Who we are

AnglerDash is operated by AnglerDash Limited, a New Zealand company, which is the agency responsible for the personal information described in this policy. You can reach us about anything in it at privacy@anglerdash.com.

Information we collect

Account information

You need an account to use AnglerDash, because your spots, catches and photos are stored against it. Accounts are handled by Firebase Authentication, a Google service. You can either:

  • Sign in with Google. We receive only your email address and your Google profile picture. We do not receive your Google password, your contacts, your calendar, or anything else in your Google account, and we have no access to your Google account beyond that one-time sign-in.
  • Sign up with an email address and password. Your password is set and stored by Firebase Authentication and is never visible to us or stored on our servers. We use your email address to verify your account and to send password resets.

On top of that we store a username you choose, which is public and appears on catches you share, and — if you add them — an optional short bio and profile photo.

The fishing data you record

Everything you log in the app is stored against your account:

  • Saved spots — the name, notes and coordinates of each spot you save
  • Catches — species, quantity, size and weight, method, gear, bait or lure, date and time, the conditions at the time, and any notes
  • Photos — images you attach to a catch, to your gear, or to your profile
  • Preferences — your unit and display settings

Location information

The app asks for location permission so it can centre the map on where you are, save a spot at your current position, and record where a catch was made. AnglerDash only ever requests while-in-use location access — it does not track you in the background, and it does not collect a history of your movements. If you decline the permission, the rest of the app still works; you can place spots on the map manually instead.

We use location for exactly two purposes: saving the spots you choose to save, and producing the forecast and conditions for those spots. Nothing else.

Support correspondence

If you contact us through the support form on this website or by email, we receive your name, your email address and whatever you write, and we keep that correspondence so we can answer you and follow up.

Technical information

Our servers keep short-lived operational logs of requests to the AnglerDash API, which can include an IP address, a device or app version and error details. These are used to keep the service running, diagnose faults and detect abuse — not to build a profile of you. There are no third-party analytics, attribution or advertising SDKs in the app.

How we use your information

  • To provide the app: your account, your spots, your catch log and your photos
  • To generate spot-specific forecasts, conditions and the ratings built on them
  • To show you insights drawn from your own fishing history
  • To publish the catches you have explicitly chosen to share, in the form described below
  • To keep accounts secure, prevent abuse and enforce our terms
  • To reply when you contact support, and to send essential service emails such as verification and password resets
  • To improve AnglerDash, using aggregated information that does not identify you

We do not use your personal information to make automated decisions that have a legal or similarly significant effect on you.

Your fishing spots stay private

Spot secrecy matters to anglers, so it is built into how AnglerDash works rather than being a setting you have to find:

  • Saved spots are visible only to you. There is no way for another user to see them, search them or browse them.
  • The coordinates of a spot, and of an individual catch, are never included in anything published to other users.
  • Forecasts are not requested per spot. We ingest forecast and tide data in advance for a fixed grid of locations covering the coastline, and your spot is matched to the nearest point on that grid on our own servers. Our forecast and tide providers therefore never receive your coordinates, your account, or any indication that a spot exists.

Sharing catches with the community

Every catch you log is private by default. A catch becomes visible to others only if you deliberately set it to public.

When you do share a catch, other AnglerDash users can see:

  • your username, and your profile photo and bio if you have set them
  • the species and how many you caught
  • the date
  • the broad fishing region — for example a harbour or stretch of coast
  • any photos attached to that catch

They cannot see:

  • the coordinates of the catch, or the spot it was linked to
  • the name or notes of any of your spots
  • your email address
  • any of your other catches that are still private

Region is deliberately the finest level of location AnglerDash will ever publish. Setting a catch back to private removes it from the community feed. Please keep in mind that anything you post publicly — including what you write and what appears in your photos — may have been seen or saved by others before you change your mind, and that photos can carry location information in their metadata if you add them from your camera roll.

Who we share information with

We do not sell your personal information, and we do not share it with anyone for their own marketing or advertising. We have no advertising business and no data-broker relationships.

We do rely on a small number of service providers to run AnglerDash. They act on our instructions, may only use the information to provide their service to us, and are covered by their own privacy commitments:

  • Google — Firebase Authentication and Google Sign-In. Creates and secures your account, and holds your sign-in credentials. Receives your email address, and your Google profile picture if you sign in with Google.
  • Google — Firebase Storage. Stores the photos you upload for catches, gear and your profile. Access is controlled by security rules, and photos are served through short-lived links rather than public URLs.
  • Mapbox. Draws the maps in the app. Your device connects directly to Mapbox to download map tiles. Like most internet services, Mapbox receives technical information such as your IP address and the map area being viewed. Your saved spots, catches and account details are not sent to Mapbox.
  • Our weather, marine and tide data suppliers. Supply the raw forecast data we ingest. As described above, this is fetched for a fixed grid of locations on a schedule, so these suppliers receive no personal information at all — no coordinates of yours, no account identifiers, nothing tied to you. They are data sources to us, not recipients of anything about you.
  • Our cloud hosting and email providers. Run the AnglerDash API and database, and deliver service emails and support replies.

We may also disclose personal information where we are legally required to:

  • to comply with the law, a court order or a lawful request from an authority
  • to protect the rights, safety or property of you, other users or AnglerDash — for example when investigating abuse
  • to a purchaser, if AnglerDash is ever sold or reorganised, in which case this policy continues to apply to your information unless and until you are told otherwise and given a choice

Where your information is stored

The AnglerDash database and API run on managed cloud infrastructure. Photos are held in Firebase Storage and accounts in Firebase Authentication, both operated by Google. Some of these providers store and process data on servers outside New Zealand, which means your information may be held in, or accessed from, another country. Where that happens we rely on providers that are required to protect your information to a standard comparable to New Zealand law.

How long we keep it

  • Your account and fishing data — kept while your account is open, so your history stays intact season after season.
  • Deleted content — a spot, catch or photo you delete is removed from the live service straight away and purged from backups within 90 days.
  • A closed account — deleted within 30 days of your request, and purged from backups within a further 90 days.
  • Support correspondence — kept for up to two years so we have context if you get in touch again.
  • Operational logs — kept for a short period, then discarded.

We may keep information for longer where the law requires it, or where it is needed to resolve a dispute or investigate abuse. Aggregated statistics that no longer identify you — such as how many anglers caught a species in a region — may be retained indefinitely.

How we protect your information

Security is treated as part of building AnglerDash, not an afterthought. In practice that means:

  • All traffic between the app and our servers is encrypted in transit (HTTPS/TLS), and stored data is encrypted at rest by our infrastructure providers.
  • Every API request is authenticated with a short-lived token, and each request is authorised against the account that owns the data — you can only ever reach your own spots, catches and photos.
  • Photo storage is protected by security rules and time-limited access links rather than public URLs.
  • Passwords are handled entirely by Firebase Authentication and are never stored on our servers.
  • Access to production systems is limited to those who need it, and credentials are held in secret storage rather than in code.
  • Dependencies are kept current, and changes are reviewed for security before release.

No system can be guaranteed completely secure, but if a breach affecting your personal information ever occurred, we would act to contain it, notify affected users, and notify the Office of the Privacy Commissioner where the Privacy Act 2020 requires it.

Your rights and choices

Under the Privacy Act 2020 you have the right to ask for the personal information we hold about you, and to ask us to correct it. In the app you can, at any time:

  • view and edit your profile, spots and catches
  • change a catch between private and public
  • delete individual spots, catches or photos
  • turn location permission on or off in your device settings

To request a copy of your data, or to close your account and have your profile, spots, catches and photos deleted, email privacy@anglerdash.com from the address on your account. We will respond to your request within 20 working days.

If you are unhappy with how we have handled your information or your request, you can complain to the New Zealand Office of the Privacy Commissioner at privacy.org.nz. If you are in a country whose privacy law gives you further rights, we will honour those rights where they apply to you.

Children

AnglerDash is not intended for, or directed at, children. You must be at least 13 to create an account, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has created an account, contact us at privacy@anglerdash.com and we will delete the account and its data. Where a young person over 13 uses AnglerDash, we encourage a parent or guardian to be involved — particularly in anything shared publicly.

This website

This site has no accounts, no advertising and no third-party analytics or tracking cookies. It stores one item in your browser's local storage to remember whether you chose the light or dark theme; that never leaves your device.

If you use the support form, your name, email address and message are emailed to our support address so we can reply. They are not stored in a database on this site and are not used for marketing.

Changes to this policy

We will update this policy as AnglerDash changes. The date at the top always shows when it was last revised. If a change materially affects how we handle your personal information, we will tell you in the app or by email before it takes effect, rather than relying on you to notice.

Contact

Questions, requests or complaints about privacy can go to privacy@anglerdash.com, and reach the person responsible for privacy at AnglerDash Limited.