Privacy

Privacy

This page covers both our homes — the walk at app.saveourfields.com and the campaign site at www.saveourfields.com. They share the same promise, so they share this page.

"Hello. It's me. Rusty. Scarecrow, narrator, professional stander. I'm also the one who keeps the ledgers round here, so it falls to me to talk about privacy — not some fellow in a necktie. I'll keep it plain."

The short version

What we keep, and what we never see

On the walk (app.saveourfields.com)

On the campaign site (www.saveourfields.com)

The servers

Your choices

The small print (the precise version, no poetry)

Who we are. Save Our Fields is operated by Vivid Atom Limited (ICO registration ZB010144), the data controller for both app.saveourfields.com and www.saveourfields.com. You can reach us at hello@saveourfields.com for anything on this page.

What we process, why, and for how long:

DataPurposeLegal basis (UK GDPR)Retention
App analytics (random visitor id, device type, walk events, coarse ~1 km zone)Improve the walk; see where people wanderLegitimate interests, Art. 6(1)(f) — data is pseudonymous; raw IP hashed on receipt~12 months
Website analytics (hashed visit id, hashed IP, host-only referrer, page/CTA)See what's read and clickedLegitimate interests, Art. 6(1)(f)13 months
Contact messages (name, email, location, message)Answer your enquiryLegitimate interests, Art. 6(1)(f) — you asked us to respond30 days (auto-deleted)
Bug-bounty reports (name, email, report, optional postal address)Fix the bug; post your swagLegitimate interests, Art. 6(1)(f)12 months
Field Ranger identity (one-way hash of your secret + chosen display name)Roll of Honour; carry progress across devicesYour choice — entirely optionalUntil you "forget me"
Friend meetings (hashed tokens, method, day)Face-to-face meet-and-greetYour choice — self-declared (both phones scanning the same field)2 years (auto-deleted)
Security & rate-limit records (hashed IP buckets)Stop abuse and robotsLegitimate interests, Art. 6(1)(f)Pruned
Erasure log (counts only, no personal data)Report how many erasures we've honoured— (not personal data)Kept
Field team recon surveys (the team's own fieldwork, admin-only)Run the field walksInternal operationsKept (backed up)

Who sees your data. Nobody for advertising — we have none. Personal data (contact messages, bug reports) is visible only to the field team through a locked admin area (authenticated, rate-limited, behind a second password gate). A small set of infrastructure suppliers (hosting, CDN, DNS, monitoring, encrypted backup) process limited technical data on our behalf under contract; they don't get to use it for their own purposes. We never sell or rent personal data.

Your rights. You have the right to access a copy of what we hold on you; have it corrected; have it erased (in-app "forget me", or email us); restrict or object to processing; and data portability. We respond to requests at hello@saveourfields.com and aim to act within one month. Nothing here affects those rights.

Complaints. If you're unhappy with how we've handled your data, tell us first — but you also have the right to complain to the UK regulator, the Information Commissioner's Office (ico.org.uk).

Cookies & similar technology. We don't use advertising or tracking cookies, and no consent banner is needed. The anonymous visitor numbers use your browser's local storage (not a cookie), and they're wiped if you clear your browser. The app's offline "kit" uses the browser's service-worker cache so the walk works with no signal.

Children. The walk is a family walk, but we collect no personal data from anyone just for taking part — no chat, no messaging, no purchases, and a parent can watch the whole thing. The only time we'd hold a child's data is if someone (child or adult) writes to us through the contact form, which auto-deletes after 30 days.

Where data goes. Your data is stored and processed on servers in the UK and European Union. Backups are encrypted with a key held only in the UK before they leave, and our off-site backup supplier holds only that encrypted copy — never a readable one. Our status-page monitor only checks that the sites are up and receives no personal data. We'll say plainly if that ever changes.

Changes. If we change anything material here, we'll update this page. The honest record of every data point lives in our internal privacy ledger, and this page is its mirror.

"There. That's the lot — every scrap of it, and the scraps we don't take. If you'd like any of it gone, say the word and I'll fetch the matches myself. A promise, not a feature.— Rusty"

← Back to the meadow