Privacy Policy
Who we are
Crockett is a hunting and fishing license app operated by WorldTech Miami (WTM Trading LLC). This policy covers the Crockett mobile app and this website.
What we collect
We collect only what the app needs to do its job. You choose what to enter.
| Information | Why |
|---|---|
| Email address | To send your sign-in code. If you sign in with Apple or Google instead, we receive the email address that service gives us. |
| Phone number | An optional value saved to fill state checkout forms. Sign-in by text message is switched off in this version of the app, so we do not send you a text. |
| Profile details | Name, date of birth, address, driver license number, hunter education number, and customer number, when you add them, so the app can fill them into a state's official checkout for you. |
| License records | Licenses you add, or import from a photo, PDF, or the iOS share sheet: state, license name, type, expiration, and barcode. A license photo you import is saved with the record. |
| Harvest log | Entries you save, including species, notes, an optional photo, and, if you allow location, GPS coordinates. |
| Location | Used for the map, local weather, tides, sunrise and sunset, harvest pins, and area alerts you turn on. A saved hunt location may be stored for alerts. |
| Draw points and hunt plans | The states and species you track, saved to your account. |
| Camps | A camp name and invite code you create or join, and your membership. |
| Shared links | Sharing a pin, waypoint, parcel or saved area from the map creates a link on gocrockett.com. The link carries the coordinates or area, the name, and the kind of place. It carries nothing about your account, and nobody can tell who shared it from the link itself. We store it until you delete it from the app's Shared links list or delete your account, which removes every link you created. |
| Ask Davy questions | The question you type or dictate, plus context from your screen. The next section lists exactly what that context is. |
| Feedback | Any message or photo you submit through the in-app feedback form, plus your app version and device browser string. |
| Automatic error reports | If the app hits an error, it sends the error message, stack trace, screen name, app version, platform, and time. When you are signed in, each report is linked to your account_id. Guest reports are not linked to an account id. A hashed client context (ua_hash) can also be stored so we can tell reports apart. Reports are kept for 90 days. This is used only to find and fix crashes. It is not used for ads or tracking. |
| Waitlist | On this website, your email if you join the waitlist, plus the referring site and country. |
What Ask Davy sends
Ask Davy is the in-app assistant. Every question you send carries context from your screen so the answer fits where you are. That context is:
- Your saved license names and your resident state.
- The location your Home screen is showing, rounded to about a mile, and whether it came from your phone or from a place you picked.
- The name, state and time zone of that place.
- The kind of animal your Home screen is set to, and the legal shooting hours Crockett worked out for it.
- The weather, sun, moon and solunar readings and the Crockett conditions score your Home screen is showing.
- The names, kinds, distances, managers and posted access and permit rules of the three nearest public-land areas the map has loaded.
- The upcoming season openings the seasons list is showing.
- The names and rounded locations of your saved places.
Crockett's own server picks which answer service handles the question. The app never picks. This version uses Cloudflare Workers AI, which runs on Crockett's own server. The other choice is Google Gemini, which would receive the same question and the same context if the server were set to it.
If you dictate a question instead of typing it, your phone's Apple speech services receive the audio.
How your information is used
- To sign you in and keep you signed in.
- To show license requirements, fees, seasons, and maps.
- To fill your details into a state's official checkout when you choose to buy.
- To store your licenses, harvest log, plans, points, and camps on your account.
- To answer your Ask Davy questions and send alerts you turn on.
- To find and fix crashes from automatic error reports.
We do not sell your information. We do not show ads. We do not use your information for cross-app tracking.
Where a purchase happens
When you buy a license, the purchase completes on the state's own official system. Crockett opens that system and can fill in your saved details. Crockett does not sell licenses and does not take payment.
Who receives your information
This is every outside service Crockett can reach, and what reaches it. Some are reached by the app on your phone. Some are reached by Crockett's own server on your behalf. The address in each row is the exact one your phone or our server connects to.
Where a row says a location is rounded to two decimal places, that means it is cut back to about a mile before it leaves your phone. It points at an area, not at you.
| Service | What it receives, and why |
|---|---|
Crockett's own server (Cloudflare)crockett-api.wtmtrading1.workers.devgocrockett.comwww.gocrockett.com | Hosting, the database that holds your account, file storage, and automatic error reports including the hashed client context. The Ask Davy answer service used in this version, Cloudflare Workers AI, also runs here. |
Apple Weatherweatherkit.apple.com | The main weather source. It receives the coordinates of the place you are looking at, rounded to two decimal places, sent through Crockett's own server. |
National Weather Serviceapi.weather.gov | Receives the same rounded coordinates through Crockett's own server, for local observations and forecasts. It also receives the rounded coordinates of a spot you tap on the map, sent straight from the app, to show active weather alerts for that spot. |
Open-Meteoapi.open-meteo.com | A weather source Crockett no longer calls. Nothing in the app or on our server sends anything to it today. We list it because the app still allows the address and the code path is kept. |
Open-Meteo geocodinggeocoding-api.open-meteo.com | City or US ZIP search and reverse-geocode queries. It receives the text you type when you search for a place, and, when Crockett turns a location back into a place name, a coordinate rounded to two decimal places. |
NOAA Tides and Currentsapi.tidesandcurrents.noaa.govtidesandcurrents.noaa.gov | Receives requests for a tide station near a coastal location, to show tide times. |
FCC census area lookupgeo.fcc.gov | Receives the coordinates of a spot you tap on the map, rounded to two decimal places, and returns the state and county that point sits in, so the rules you are shown belong to the right state. The app sends this straight from your phone. It does not pass through Crockett's server. |
USGS National Hydrography Datasethydro.nationalmap.gov | Receives the coordinates of a spot you tap on the map, rounded to two decimal places, plus a small box around that point, and returns the name of the lake, reservoir, river or creek under it. The app sends this straight from your phone. It does not pass through Crockett's server. |
AWS Terrain Tiless3.amazonaws.com | When terrain shading or contour lines are used, the app requests elevation tiles directly from AWS. The requests include tile coordinates that describe the map area being viewed and nearby tiles. They do not include a separate device GPS position or pass through Crockett's server. |
USGS The National Mapbasemap.nationalmap.gov | Map tiles for the topographic layer and the water layer. A tile request shows the map area you are looking at. |
National Park Servicedeveloper.nps.gov | Receives the two-letter state of a national-park spot you tap on the map, sent through Crockett's own server, to show that state's active park closures, hazards and hours. |
Google Geminigenerativelanguage.googleapis.com | Receives a license image you choose to import, to read the details off it. It would also receive your Ask Davy question and its context if Crockett's server were set to use Gemini as the answer service. In this version the server uses Cloudflare Workers AI instead. |
Google Cloud Text-to-Speechtexttospeech.googleapis.com | Receives the text of Davy's spoken answer, sent through Crockett's own server, to make the voice you hear. |
Apple sign-inappleid.apple.com | Used when you choose Sign in with Apple. Apple tells us the account identifier and the email address you agree to share. |
Google sign-inaccounts.google.comwww.googleapis.com | Used when you choose Sign in with Google. Google tells us the account identifier and the email address you agree to share. |
AgentMailapi.agentmail.to | Receives your email address, to deliver your sign-in email. |
Twilioapi.twilio.com | Would receive your phone number to send a sign-in code by text. Sign-in by text message is switched off in this version, so no phone number reaches Twilio. We list it because the code path is still there. |
Google OAuthoauth2.googleapis.com | Issues the token Crockett's server uses to send push notifications through Firebase. It receives Crockett's own credentials, not your information. |
Push notification deliveryapi.push.apple.comapi.sandbox.push.apple.compush.apple.comfcm.googleapis.compush.services.mozilla.comnotify.windows.com | Receive the alerts you turned on, addressed to your device, so they can reach your phone. A test build of the app registers with Apple's sandbox address instead of the live one. |
| Apple Wallet | Receives a license pass when you choose to add one. This happens on your phone. |
Google Walletpay.google.com | Would receive a license pass when you choose to save one. Save to Google Wallet is switched off in this version, so nothing reaches it. We list it because the code path is still there. |
| Apple speech services | Receive the audio when you dictate a question for Davy. |
Official state agency sites, and the U.S. Fish and Wildlife Servicewww.fws.gov | Receive whatever you type, or choose to have Crockett fill in, after Crockett opens their page for you. These are the states' own sites, not ours, and their own privacy policies apply once you are on them. |
If a service is not in this table, Crockett does not send it anything. The app on your phone is also locked to a fixed list of addresses, so a connection to anywhere else is blocked by the app itself and not only by our policy.
How your information is protected
- Traffic between your phone, our server, and every service above travels over HTTPS.
- Sign-in codes and session tokens are stored as hashes, not in the clear.
- Reaching your account requires your session token.
- Coordinates sent to the weather, water and census services are rounded to about a mile before they leave your phone.
Your choices
- You can edit or clear your profile details in the app at any time.
- You can remove licenses, harvest entries, plans, points, and camps you added.
- You can turn location and alerts on or off.
- You can turn Diagnostics off, which stops automatic error reports.
- You can download a copy of your data from the About screen in the app.
- You can sign out, which clears your session on that device.
- You can delete your account from the About screen in the app.
Data retention
We keep your account information while your account is active. Sign-in codes expire within minutes. Automatic error reports are kept for 90 days, then deleted.
Deleting your account
When you delete your account, we delete your rows from our database straight away. That covers your profile details, your licenses and any license photo, your harvest log and its photos, your saved places, stands and properties, your plans, points and camps, your sign-in codes and sessions, your email address and your phone number. Deleting also clears that account's saved work off the phone you did it on, including property and stand locations.
Automatic error reports are the one thing we do not delete. In the same step we unlink them from your account, so nothing left in a report points to you, and they are deleted 90 days after they were made.
One part is not instant, and you should know about it. Our database is hosted by Cloudflare, and Cloudflare keeps a rolling 30 day history of the whole database so that it can be rolled back after a bad change. We cannot switch that history off. For as long as that history still reaches back past the day you deleted, rolling the database back would bring your rows back with it. Thirty days after you delete, the history no longer reaches that far, and a rollback cannot return your information.
Changes to this policy
We will update this page when our practices change and revise the date above.
Contact
Questions about privacy: sales@worldtechmiami.com.