Privacy Policy
Last updated: July 20, 2026
TrailForge is built by people who don't like being tracked. The short version: we never sell your data, we never will, and the core map works without an account. The details below explain what data exists, why, and the choices you have.
1. Our covenant
- We never sell, rent, or broker your personal data. We never share it with third parties for their marketing.
- Advertising on TrailForge, if shown, is contextual — placed because of the page you're looking at (a park, a trail topic), never because of a profile built about you. We do not use behavioral ad tracking.
- Your public identity on TrailForge is a trail persona — a nickname you choose. We never require your real name for public display.
- We collect the minimum data that makes a feature work, we protect what we store, and we delete it when you ask.
- The core map — park directory, closures, trail lines, and state plate/permit info — works without an account, without cookies, and without tracking, forever. That is a product commitment, not a promotional one.
2. What works without an account (and always will)
Browsing the map, park pages, closures, trail geometry, and plate/permit information requires no sign-up, sets no cookies, and collects no personal data. We use Cloudflare Web Analytics, which is cookieless and collects no personal data — overall traffic only, never individual profiles.
Routes and GPX data you save while browsing anonymously live in your browser's local storage on your own device and never leave it unless you deliberately share or sync them.
Some pages offer embedded videos hosted by third parties (YouTube, Vimeo). Embeds are click-to-load: nothing is requested from those providers until you press play. Once you do, that playback is governed by the provider's own privacy policy.
Watching a park. Email status alerts are not active this round (no mail vendor). We are not collecting watch emails from the park drawer. A watcher count may still appear when previously confirmed subscriptions exist.
3. If you create an account
Accounts are optional and exist to unlock features like park management (for verified operators). Sign-in uses a passkey or an invite link from TrailForge Ops — there is no password to breach. Email magic-links are not used this round. When you create an account we store:
- Your email address — the account identifier from the invite; not used to send mail this round.
- Your trail persona — the public nickname you choose.
- Content you deliberately create — posts, reports, events, media submissions, routes you choose to sync.
- Your role grants — e.g., verified park operator status and the parks you are approved to manage.
- Sign-in records — session and last-login timestamps, stored to keep your account secure. Session credentials are stored only as cryptographic hashes.
We do not collect your real name (unless you choose to share it), your precise location history, your contacts, or any data from third-party trackers — because there aren't any. Signing in sets a single session cookie required to keep you logged in; anonymous browsing sets none.
Ops-issued invite links store the invited email and a hashed IP (rate limiting). Unused invites expire after 72 hours. Local development may issue a 15-minute sign-in link that is shown on the page instead of emailed.
4. Community posts: board, repair reports, and RSVPs
Board posts and trail repair reports are public. What you post (park, category, persona, text, timestamp) is visible to every visitor. We store a hashed version of your IP address, used only for abuse prevention (rate limiting and spam blocking); it is never displayed publicly and cannot be casually reversed. Repair report coordinates are rounded to roughly 1 km before being shown publicly. Do not post personal information — yours or anyone else's.
Event RSVPs ("I'm in" responses on rides and workdays) store the nickname, party size, and note you submit, plus the same hashed-IP abuse protection. Only aggregate counts are shown publicly — individual RSVP names and notes are visible only to staff organizing the event.
5. Park operator accounts
If you claim a park, we ask for information demonstrating you operate it (for example, business contact details or documentation). This proof is reviewed by staff, used only for verification, and never published. Approved operators can update their park's status, profile, and events; these edits are attributed to the park, not to you personally.
6. Service providers
A small number of vendors process limited data on our behalf, under contract, only as needed to operate TrailForge:
- Cloudflare — hosting, D1 database, R2 media, security.
We do not currently use a mail vendor or a payments vendor. Map tiles and MapLibre load from CDNs named in the content-security policy; YouTube/Vimeo load only after you press play (see §2). These providers may not use your TrailForge account data for their own purposes.
7. Your rights (all states)
Regardless of where you live, you may:
- Export — request a copy of the data tied to your account.
- Delete — delete your account and we will remove your personal data within 30 days, except records we are required to keep (for example, financial records) and content already public (which we will anonymize on request).
- Correct — fix your persona or email at any time.
- Opt out — of any optional notification at any time.
Contact for any of these: BluntForceReporting@Proton.me.
Retention. Sign-in links expire in 15 minutes, sign-in sessions in 30 days, and both are purged automatically after expiry. Rate-limit records store only salted hashes of IP addresses, never the addresses themselves. Account deletion removes your sessions, credentials (including passkeys), role grants, subscriptions and notification watches; content you made public is anonymized on request as described above.
8. State privacy disclosures
Some states (including California, Virginia, Colorado, Connecticut, and others) give residents specific privacy rights. Here is what matters in plain terms:
- We do not sell or share personal information for cross-context behavioral advertising, as those terms are defined in state privacy laws — so there is no "sale" to opt out of. If that ever changes, this policy will change first, loudly.
- Categories of data collected: identifiers you give us (email, persona), content you create, and limited technical logs (hashed IPs for abuse prevention). We do not collect precise geolocation, biometric, or sensitive personal data.
- Purpose: operating the features you use — nothing else. No data broker relationships, no third-party marketing lists.
- Residents of states with privacy acts may exercise access, correction, deletion, and portability rights via the contact above. We will not discriminate against you for exercising them.
9. Children
TrailForge is not directed at children under 13, and we do not knowingly collect their data. Accounts require the account holder to be 13 or older. If you believe a child has posted personal information, contact us and we will remove it.
10. Security
Data in transit is encrypted (TLS). Sign-in tokens and session credentials are stored only as cryptographic hashes. Access to operational data is limited to staff tooling with logged actions.
11. Changes
If this policy changes, the updated version will be posted here with a new date, and material changes will be announced on the site before they take effect. We will never quietly start tracking you — that would defeat the point of building this.
12. Contact
Questions, export, or deletion requests:
Blunt Force Reporting LLC
7540 Township Line Road, Waynesville, OH 45068
BluntForceReporting@Proton.me