Privacy Policy
1. Introduction
Wombat CCW (“we”, “us”, or “our”) operates a mobile application and related services (the “Service”) that provide informational guidance regarding firearm laws and concealed carry considerations. This Privacy Policy describes how we collect, use, disclose, and safeguard personal information.
By using the Service, you acknowledge that your information will be handled as described in this Privacy Policy.
2. Scope and Role
For purposes of applicable data protection laws, Wombat CCW is the “data controller” (or equivalent term) with respect to personal information processed through the Service.
3. Information We Collect
3.1 Information You Provide
- Account Information: Email address, authentication credentials, and identifiers from third-party sign-in providers.
- User Content: Inputs you provide within the Service, including queries submitted to AI features and location/jurisdiction selections.
- Communications: Information provided in support requests or correspondence with us.
3.2 Information Collected Automatically
- Device and Technical Data: Device type, operating system, app version, and unique device identifiers.
- Usage Data: Feature usage, session duration, interaction patterns, and crash diagnostics.
- Log Data: IP address, timestamps, and request metadata.
3.3 Location Information
With your explicit permission, we may collect precise or approximate location data to provide location-aware features such as jurisdictional guidance and geofencing alerts. You may revoke location permissions at any time through your device settings.
3.4 Sensitive Information
We do not intentionally collect sensitive personal information as defined under applicable law (e.g., precise geolocation is collected only with consent and solely to provide core functionality). Users should not submit highly sensitive personal data through the Service.
4. Purposes of Processing
We process personal information for the following purposes:
- Providing, operating, and maintaining the Service
- Delivering location-based and jurisdiction-specific functionality
- Processing and responding to user queries, including via AI systems
- Improving performance, reliability, and user experience
- Monitoring for fraud, abuse, and security incidents
- Communicating with users regarding updates, support, and service-related notices
- Complying with legal and regulatory obligations
4.1 Legal Bases (EEA/UK Users)
- Contractual Necessity: To provide the Service
- Legitimate Interests: To improve, secure, and analyze the Service
- Consent: For location data and optional processing
- Legal Obligation: Where required by law
5. AI Processing
The Service includes AI-powered features that process user inputs to generate responses. User inputs may be transmitted to and processed by third-party AI service providers solely to provide functionality. We do not use AI outputs as a substitute for professional or legal advice.
6. Disclosure of Information
We do not sell personal information. We may disclose information as follows:
- Service Providers: To vendors providing hosting, infrastructure, analytics, authentication, customer support, and AI processing, under contractual confidentiality obligations.
- Legal Compliance: When required to comply with applicable law, regulation, legal process, or enforceable governmental request.
- Business Transfers: In connection with a merger, acquisition, financing, or sale of assets.
- Protection of Rights: To protect the rights, safety, or property of users, the public, or Wombat CCW.
7. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.
- Account Data: Retained while the account is active and for a reasonable period thereafter
- Usage Data: Retained in aggregated or de-identified form where feasible
- Support Data: Retained as necessary for support and legal compliance
8. Your Rights
8.1 General Rights
- Access, correct, or delete your personal information
- Withdraw consent where processing is based on consent
- Disable location collection through device settings
8.2 U.S. State Privacy Rights (including California)
Depending on your state of residence, you may have rights under applicable laws such as the California Consumer Privacy Act (CCPA/CPRA), including:
- Right to know categories and specific pieces of personal information collected
- Right to request deletion of personal information
- Right to correct inaccurate personal information
- Right to non-discrimination for exercising privacy rights
We do not sell or share personal information for cross-context behavioral advertising as defined under California law.
8.3 EEA/UK Rights
- Right of access, rectification, erasure, or restriction
- Right to object to processing
- Right to data portability
- Right to lodge a complaint with a supervisory authority
To exercise any of these rights, contact us using the details below. We may need to verify your identity before processing requests.
9. Data Security
We implement reasonable administrative, technical, and organizational safeguards designed to protect personal information. However, no system is completely secure, and we cannot guarantee absolute security.
10. International Data Transfers
If you access the Service from outside the United States, your information may be transferred to and processed in the United States or other jurisdictions where our service providers operate. Where required, we implement appropriate safeguards for such transfers.
11. Children’s Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
12. Third-Party Services
The Service may rely on third-party providers (e.g., cloud hosting, analytics, authentication, and AI services). These providers process data under their own privacy policies and contractual obligations with us.
13. Changes to This Policy
We may update this Privacy Policy periodically. Updates will be reflected by revising the “Last updated” date. Continued use of the Service constitutes acceptance of the updated Policy.
14. Contact Information
For questions, requests, or concerns regarding this Privacy Policy or your personal information:
Email: [email protected]