Legal
Privacy
There is not much of this, and that is deliberate. No analytics, no advertising, no third-party scripts, and two cookies, neither of which is there to follow you.
Last checked
The short version
- Reading this site sends us nothing beyond the ordinary web request and stores nothing on your device.
- Pressing “Larger text” stores one cookie, so the next page arrives in the size you asked for.
- Buying something stores a second: the signed token by which your browser proves a purchase is yours. There is no third.
- Buying a tour gives us the email address you paid with, from Stripe, so that a lost phone does not cost you your purchase.
- Playing a hunt stores your progress, and uses the position your phone reports at the moment you check in. A photo challenge is on your honour — the picture stays on your phone.
- There is no analytics, no advertising, no tracking pixel and no third-party script on any page of this site.
- Two outside services do see the address your request came from, because your browser fetches files from them: Google, for the typefaces, and OpenFreeMap, for the map tiles on the pages that draw a map.
- We do not sell data, we do not profile you, and there is nobody to sell it to.
Who is responsible
The publisher named in the legal notice is the data controller for everything described here, and is established in France. There is no data protection officer: the operation is not the size that requires one. Write to the address in the legal notice and a person reads it.
What we hold, and why
This is the whole list. It is short enough to print in full rather than summarise.
- A device record. The first time you buy something or start a hunt we mint a random identifier for your device and store a hash of its access token beside it, with the language you read in, the platform, and three timestamps. The token itself is never stored — only the hash — so a copy of our database is not a stack of working keys.
- Your purchase. Stripe passes us the email address you paid with, a reference to the payment session, which product you bought, and when access starts and ends. We never see your card number and never receive it.
- The confirmation you gave at checkout: that you accepted the terms, and that you asked for immediate access knowing it ends your right of withdrawal — with the wording you were shown, the language, and the moment you sent it.
- Your progress in a hunt: which stops you have solved, how many attempts each took, how many hints you took, your score and the times. To check a find, we need the position your phone reports at that moment. We use it to answer “are you there”, record that the stop was found, and keep no trail of where you walked. Where a stop asks for a photograph the challenge is on your honour: no image is uploaded and none is stored.
- Ordinary server logs: the page requested, the time, the status, the user agent, and the IP address the request arrived from. They exist to keep the site up and to spot abuse.
- Two cookies: the text-size preference, and — once you buy or play something — the signed token your browser presents to prove that access is yours. Both are described below.
The legal grounds
Your purchase, your access, your progress and the running of the service are processed because they are necessary to perform the contract you entered into — Article 6(1)(b) of the GDPR. Without them there is nothing to deliver.
The record of your checkout confirmation is kept because the law puts on us the burden of proving that you gave it, and because we may need it to answer a claim: Article 6(1)(f), our legitimate interest in being able to evidence a consumer's consent, and Article 6(1)(c) where a rule obliges us to keep it.
Server logs are kept for security and abuse prevention, Article 6(1)(f). The text-size cookie is stored because you asked for it, and only then.
We do not rely on consent for anything else, because there is nothing else.
Leaving the EEA
We are in France, and data stays in the European Union wherever the platform allows it. Stripe and Cloudflare both belong to groups with United States parents, so a transfer can happen: for support, or because a global network routes a request through the nearest city rather than the nearest country. The same is true of the font request your browser makes to Google.
Where it does, it is covered by the European Commission's standard contractual clauses, and by the EU–US Data Privacy Framework in the case of a provider certified under it. Ask us and we will tell you what is in place for a particular provider.
How long we keep it
- Your access, and the device record behind it: for as long as the access lasts — 365 days for a pass, 180 for a hunt — and then twelve months more, so that a phone lost in month eleven is still recoverable. Then deleted.
- The purchase record: ten years, which is what French commercial law requires of an accounting document. The checkout confirmation: five years, the ordinary limitation period for a claim on a contract like this one — it is evidence rather than a ledger entry, and there is no reason to hold it as long.
- Hunt progress: with the access it belongs to.
- Server logs: days, not months. Cloudflare's own retention applies to what its network holds.
- The text-size cookie: twelve months from the day you set it, or until you clear it.
- The access cookie: up to four hundred days from the last time it was used, which is the longest life a browser will now give a cookie. Every visit renews it, so it lapses only if you stop.
Your rights
You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, ask for it in a portable form, and object to processing we base on a legitimate interest. Where a right is limited — we cannot delete an accounting record the law obliges us to keep — we will tell you which rule applies rather than simply refuse.
Write to the address in the legal notice, and say which email address you bought with. That is how we find you: there is no account and no password, so it is the only handle we have. We answer within one month.
You can also complain to a supervisory authority. Ours is the CNIL in France, at cnil.fr, and you may equally go to the authority of the country where you live.
How it is kept
Everything travels over TLS. The site refuses to be framed and refuses third-party script outright; the only JavaScript it serves anywhere is the map, and that comes from our own domain rather than a CDN. Access tokens are stored hashed. Paid material is checked against a live entitlement on every request rather than trusted from a session. A hunt's answers never leave our server, which is also why a hunt cannot be solved by reading the page source.
Children
This is a product for adults buying a walk. We do not market it to children, we do not knowingly sell to them, and we ask for no data beyond what a purchase needs. If you believe a child has bought something here, write to us: we will refund it and delete the record.
Changes to this notice
When the service changes, this page changes with it and the date at the top moves. If a change means we start doing something materially different with data we already hold, we will say so here plainly, before it takes effect.