Privacy Policy
Your data, handled with care
Exactly what we collect, why, who we work with, and the rights you
have — no vague promises.
Last updated 9 July 2026
In short
We collect what we need to run your account and the coordination features — and not much
else. We don’t sell your data and we don’t use advertising trackers.
Our analytics is our own and cookieless. You can see, correct, export or delete your data any time.
Who’s responsible
Snacknap is run by JGHP BV (KvK 81817312), the data controller for the personal
data described here. Questions about privacy? Email
[email protected].
What we collect
Depending on how you use Snacknap, this can include:
- Account & sign-in — your username, email, and a securely hashed
password. If you use Google or Apple to sign in, we receive a stable ID and your email from them
(we never receive or store your Google/Apple password, and we don’t keep their access
tokens).
- Profile — anything you choose to add, like your team, level, trainer
code, country/city, languages, and a short “about” text and avatar.
- Technical & sign-in activity — your IP address and basic device
info, kept to keep your session secure and to prevent abuse (for example, temporary records of
failed sign-in attempts).
- Coordination data — the raids and Remote Raids you host or join, your
queue activity, and reliability/reputation. If you report another trainer, we store your report
(including your note) so we can act on it.
- Friends, follows & messages — who you add as a friend or follow, who
you block, and the content of the direct messages you send and receive (including sender,
recipient, timestamps and read status). Messages are visible to the trainers you exchange them
with, and to our moderators only if a message is reported.
- Photos you attach to messages — you can attach a photo to a direct message,
but only to a trainer you are friends with. Before we store it we re-encode the
image on our own server, which strips embedded metadata such as GPS location and camera
info. Attachments are stored outside the public web and only served to members of that
conversation. They are removed automatically after 90 days. Trainers whose age
band is under 16 can neither send nor receive photo attachments.
- Age range — we ask which age band you fall in (not your full date of
birth) so we can apply the right safety settings, especially for younger trainers.
- Screenshots you share for reading — when you use the screenshot reader
to fill in raid details, the image is processed on our own server and deleted right
away. We don’t store the image or keep a copy — only the details you confirm.
- Telegram — if you link Telegram, we store your Telegram ID and handle so
we can send the notifications you asked for.
- Notifications — if you enable web push, we store the subscription your
browser gives us so we can deliver alerts.
- Payments — if you support us, we keep a record of your orders (what,
when, amount, and IDs from our payment provider). We never see or store your
card or bank details.
Why we use it
To create and run your account, provide the coordination, social and notification features you use
(including delivering your direct messages and keeping conversations safe), keep
the platform secure and fair, handle any support you give us and meet our legal duties, and to
understand — in aggregate — how the site is used so we can improve it. We rely on the
usual legal grounds: performing our agreement with you, your consent (e.g. notifications), our
legitimate interest in a safe, working service, and legal obligations (e.g. bookkeeping).
Who we share it with
We don’t sell your data and we don’t share it for advertising. We do rely on a small
set of trusted providers to run the service:
| Provider | What for | What they get |
| Mollie | Processing your payments | Your payment details & order info (as an independent controller for the payment) |
| Cloudflare | Delivering & protecting the site | Technical request data, incl. your IP |
| Telegram | Notifications, if you link it | Your Telegram ID & the messages we send |
| Push services (Google, Mozilla, Apple) | Delivering web-push alerts | The push “address” your browser issued |
| Our analytics (self-hosted) | Aggregate usage stats | Cookieless, IP-anonymized visit data — not shared onward |
| jsDelivr (CDN) | Loading site code libraries | Your IP, as part of loading the page |
| Our email server | Sending account & support emails | Your email & message content |
Our analytics runs on our own infrastructure (at orbit.xynta.com), is cookieless and
IP-anonymized, and isn’t an ad network — so there’s no cross-site tracking. See
the Cookie Policy for details.
Your private messages aren’t shared with third parties. When you report a
message or conversation, the relevant part becomes visible to our moderators so we can review it
and act — we don’t otherwise read your direct messages.
Where it’s stored
Your data is stored on our own hardware in a data center in the Netherlands, and stays within the
European Union.
How long we keep it
We keep your account data for as long as your account is active. When you delete your account, it
first enters a 30-day recovery window (in case you change your mind or it was a
mistake), after which it’s permanently removed. One exception: records of payments are kept
for about 7 years, because Dutch tax law requires it.
Direct messages are kept while both accounts stay active. When you delete your account, your
messages are anonymised (your name becomes “Deleted trainer”) rather
than removed from the other trainer’s copy of the conversation, and a reported message may be
kept a little longer where we need it to handle a safety issue. Photo attachments are
removed automatically 90 days after they are sent — the message stays in the
conversation, but the image is gone.
Your rights
You can see, correct, export, or delete your data, and object to or restrict
certain uses. Most of this you can do yourself from your profile
and security settings; for anything else, email
[email protected]. If you think we’ve mishandled your data,
you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Because a conversation always involves another trainer, exporting or deleting your side of it
unavoidably touches their copy too — so for messages we anonymise your identity instead of
wiping the other person’s record, and we may keep a message where the law requires it or we
need it to handle a report.
Children
Snacknap is for trainers aged 13 and over. We don’t knowingly collect data
from children under 13; if you believe a child has given us data, contact us and we’ll remove
it. Because Dutch law sets the digital age of consent at 16, we take extra care with younger
trainers: for anyone under 16, only mutual friends can send them a direct message,
they can’t be added to a group chat by someone they aren’t already friends with, and we
encourage a parent or guardian to be involved. Questions about a young trainer’s account?
Email [email protected].