BeAngler

Privacy Policy

Version: 2026.08.3 · Effective: 2026-09-10

This Privacy Policy explains how BeAngler ("we", "us", or "our") collects, uses, and otherwise processes your personal data when you use the Service (beangler.com, its subdomains, and the BeAngler mobile applications). In this Policy, "personal data" means any information relating to an identified or identifiable individual, and "process" has the meaning given in the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR").

1. Data controller

The controller responsible for your personal data is:

Andrii Tokar, a registered sole proprietor (Fizychna Osoba-Pidpryiemets, "FOP") in Ukraine, with a place of business in Kharkiv, Ukraine.

You can contact us at:

  • Privacy matters: privacy@beangler.com
  • General support: support@beangler.com
  • Legal matters: legal@beangler.com

At the date of this Policy we have not appointed a representative in the European Union under Article 27 GDPR. We keep the need for such a representative under regular review in the light of the nature, scale, and context of our processing, and we will appoint an EU representative if and when our processing makes this appropriate or required. If you have any question about this, you can contact us at privacy@beangler.com.

2. What data we collect

  • Account and profile data: email address; first and last name; public display name; optional phone number (with SMS verification); profile photo; preferred language.

  • Device and technical data: platform, device model, operating system version, app version, screen size, a device identifier (a "fingerprint" derived from device and browser characteristics, which we use to secure your account and prevent fraud — see Section 3), push notification token, and IP address.

  • Diagnostic and error-report data: when something goes wrong in the app or on the web (a failed synchronisation, a rejected request, a crash), the client sends us a diagnostic report containing the device identifier described above, the platform and app version, an error code and a short technical message, and a truncated technical context (for example the operation that failed and the server response code). Secrets such as tokens and passwords are removed before the report is sent. If the error occurred while you were signed in, the report is linked to your account so that we can investigate your case; otherwise it is linked only to the device identifier.

  • Location data, of two kinds:

    • Coordinates in your content — the locations you enter for or attach to water bodies, sessions, catches, and points of interest. These form part of the content you create and are processed in order to provide those features (see Section 3).
    • Your device's current position — your live GPS location, used only when you actively enable a location feature (for example the "my location" button on the map). This is processed only with your consent, which you may withdraw at any time in your device or app settings.
  • Content you create: water bodies, catches, sessions, strategies and plans, tournaments, events, gear, teams and clubs, comments, and other content you save.

  • Messages you send in chats and community features: the text and attachments of messages you post in team, club, tournament, battle and similar chats, together with basic delivery and membership metadata. These are user-generated content and are processed to provide the messaging features (see Section 3) and may be moderated (see the Terms of Service).

  • Fishing activity data used for analytics and recommendations: details of your catches and fishing sessions — such as species, bait, rig, depth, strategy, the outcome of each attempt (bite/catch), and the associated conditions (water body, sector, date and time, and weather) — which we use to compute your personal analytics and AI recommendations (see Section 3).

  • Payment data: your payments are processed by Paddle (see Section 5). We do not store your full payment card details.

  • App usage and advertising-measurement data (mobile apps): when you use our mobile app, Google Analytics for Firebase records automatically generated usage events (for example the first launch of the app, the start of a session, signing up, signing in, and app crashes) together with a Google-generated app instance identifier, your device's advertising identifier, the device model, the operating-system and app version, the language, and an approximate location (country or region) derived from your IP address. We use this data in aggregate to see how the app is used and to measure which advertising campaign a new installation came from (see Sections 3 and 9). It is not collected at all in our internal test builds. We do not use this app SDK on our website; there, Google Analytics is loaded only if you accept analytics cookies (see Section 8).

  • Website visit and referral data: when you visit our public website we store in first-party cookies (see Section 8) the campaign details of your visit (utm_source, utm_medium, utm_campaign, gclid), the bare host name of the external website you came from, the referral code and click identifier of a partner (affiliate) link you used, and a random visitor token that is not linked to your account. If you later create an account, the campaign and referral information is stored once against your profile so that we know how you found us and can credit the partner who referred you. These cookies are only stored if you accept them in our cookie banner; without your consent none of this is stored on your device. Separately, if you arrive through a member invitation link (beangler.com/r/…), the invitation code itself is stored in a first-party cookie for 24 hours so that the promised bonus can be credited; that cookie is strictly necessary to deliver what you asked for by following the link and is therefore not subject to consent (see Section 8).

3. Purposes and legal bases

We process your personal data for the purposes set out below. For each purpose, we rely on a lawful basis under Article 6(1) GDPR.

  • To provide and administer the Service — including creating and managing your account, storing your content (including the coordinates you enter for or attach to water bodies, catches, sessions, and points of interest), and providing subscriptions. Lawful basis: performance of a contract (Art. 6(1)(b)).
  • Accessing your device's current GPS position and sending marketing communications — Lawful basis: your consent (Art. 6(1)(a)), which you may withdraw at any time without affecting the lawfulness of processing carried out before withdrawal. Withdrawing consent to device-location access does not delete coordinates that already form part of your saved content, which we keep on the contract basis above until you edit or delete that content.
  • To keep the Service secure and prevent fraud and abuse — including using a device identifier or "fingerprint" to detect suspicious sign-ins and protect accounts — and to carry out basic service analytics and improve the Service. Lawful basis: our legitimate interests (Art. 6(1)(f)) in operating a secure and reliable Service. You may object to this processing (see Section 11).
  • To diagnose faults and keep the Service stable — we collect and analyse the diagnostic error reports described in Section 2 in order to find and fix crashes, failed synchronisations and rejected operations. These reports are used for troubleshooting only; they are not used to profile you and are not used for marketing. Lawful basis: our legitimate interests (Art. 6(1)(f)) in a reliable, working Service. You may object to this processing (see Section 11).
  • To meet our accounting, tax, and other legal obligations — handled together with Paddle acting as Merchant of Record. Lawful basis: compliance with a legal obligation (Art. 6(1)(c)).
  • To provide chat and community features — delivering the messages you send and showing messages sent to you. Lawful basis: performance of our contract with you (Art. 6(1)(b)).
  • To provide personalised analytics and AI recommendations — we analyse your own fishing activity data (see Section 2) and environmental conditions to compute statistics and to suggest, for example, which bait, rig, depth or time of day tends to work best for you in given conditions. This involves profiling within the meaning of Art. 4(4) GDPR (an automated evaluation of certain aspects relating to you in order to predict your fishing results). Lawful basis: our legitimate interests (Art. 6(1)(f)) in offering a more useful Service. These recommendations are advisory only, produce no legal or similarly significant effect on you, and are not solely-automated decisions within the meaning of Art. 22 GDPR. Even though this profiling is advisory and is not a solely-automated decision under Art. 22, you may at any time ask that any automated output affecting you be reviewed by a person, express your point of view, and contest it, and you may object to this profiling at any time (see Section 11).
  • To train and improve our recommendation models. Your personal model is computed from your own data only. To improve a general model we use anonymised, aggregated data across users: before a record enters that dataset we remove your account and session identifiers, your private strategies and sectors, and identifiers of non-public water bodies, so the data is no longer personal data and cannot be linked back to you. We also use the photos you attach to your catches, together with the fish species you saved, to train and improve our fish-recognition model (Fish ID) that runs on your own phone. Before a photo enters that training set we re-encode it, removing all metadata (including EXIF and any capture location stored in it), and detach it from your account: only the picture and the species label go into the set — no account or session identifier, no nickname, no location and no date — so that the set is not personal data. Lawful basis: our legitimate interests (Art. 6(1)(f)) for your own personal model; the anonymised general-model dataset is not personal data and therefore falls outside the GDPR.
  • To measure how our apps are used and how our advertising performs — we analyse the usage events described in Section 2 to see which features are used and how stable each release is, and to establish how many people install and start using the app after seeing one of our advertisements (campaign attribution, including campaigns run through Google Ads). Lawful basis: our legitimate interests (Art. 6(1)(f)) in operating, improving and promoting the Service; where the law applicable to you requires consent for storing or accessing information on your device or for the use of advertising identifiers, we rely on your consent (Art. 6(1)(a)), which you may withdraw at any time. You may object to this processing, or switch it off on your device, at any time (see Sections 9 and 11). On our website, the same Google Analytics service is loaded only if you accept analytics cookies in our cookie banner — lawful basis: your consent (Art. 6(1)(a)), which you may withdraw at any time (see Section 8).
  • To measure how people find our website and to credit our partners — we record which campaign, search advertisement, external website or partner link a visit and a later sign-up came from, count unique visitors per partner link in aggregate, and calculate the rewards due under our partner (affiliate) programme. This is limited to our own website: we do not build advertising profiles and we do not follow you across other websites. Lawful basis: your consent (Art. 6(1)(a) GDPR) for storing and reading the cookies described in Section 8 and for the measurement we carry out with them — nothing is stored before you accept, and withdrawing your consent deletes those cookies; once a sign-up has been credited to a partner, we calculate and pay the reward under our partner programme on the basis of our legitimate interests (Art. 6(1)(f) GDPR) in running that programme correctly. You may withdraw your consent or object at any time (see Sections 8 and 11).

We do not make decisions producing legal or similarly significant effects about you that are based solely on automated processing (Art. 22 GDPR). We do, however, carry out profiling in the limited sense described above — analysing your fishing activity and conditions to generate personalised, advisory recommendations. This profiling has no legal or similarly significant effect on you, the recommendations are suggestions only, and you may object to it at any time (see Section 11).

4. Where data is stored

Your personal data is hosted on servers located in the European Union (Frankfurt, Germany).

5. Recipients and processors (sub-processors)

We share your personal data with the categories of recipients listed below, and only to the extent needed to operate the Service. These providers act as our processors and process personal data on our behalf and under our instructions, except where they act as independent controllers for their own legal or operational purposes (for example, Paddle as Merchant of Record for tax and accounting).

Provider Purpose Amazon Web Services (AWS SES) Transactional email Amazon S3 / object storage Photo and media storage Google Maps Maps and geocoding Paddle Payments (Merchant of Record), billing, and tax Prelude Phone-number verification Apple APNs / Google FCM Push notifications (mobile apps) Open-Meteo Weather data for forecasts and fishing analytics CDN (cdn.beangler.com) Delivery of static assets Google (Google Analytics for Firebase, Google Ads) Mobile app usage analytics, website analytics (only if you accept analytics cookies) and advertising-campaign measurement FirstPromoter Affiliate (partner) programme: attribution of partner referrals and calculation of partner commissions

We may also disclose personal data to public authorities, courts, or professional advisers where we are legally required to do so or where it is necessary to establish, exercise, or defend legal claims.

We do not sell your personal data.

Payment (card) data. We do not have access to your full payment-card details. All card and payment processing is carried out solely by Paddle as Merchant of Record, under Paddle's own privacy policy; we receive only limited transaction data (such as the billing country, the last digits of the card, and the transaction status) that we need for accounting, support, and fraud prevention.

Business transfers. If we sell, reorganize, merge, or transfer all or part of the BeAngler business or its assets (for example in a merger, acquisition, or asset sale), personal data may be transferred to the successor or acquirer as part of that transaction, subject to the protections of this Policy. We will inform you of any such transfer and of any choices you may have.

6. International transfers

Some of our processors and sub-processors — including Paddle, Google (Maps, FCM and Firebase Analytics), and Amazon Web Services — may process personal data in the United States or in other countries outside the European Union and the European Economic Area (EU/EEA). Where personal data is transferred outside the EU/EEA, we put in place appropriate safeguards under Chapter V GDPR: we conclude the European Commission's Standard Contractual Clauses (SCCs) with each such recipient and, where the recipient is certified, also rely on the EU–US Data Privacy Framework (DPF). We also enter into a Data Processing Agreement (DPA) with each processor, governing the security and confidentiality of your data, and we assess the level of protection available in the destination country (in line with the Schrems II ruling). You may request a copy of the relevant safeguards by contacting privacy@beangler.com.

7. Retention

We keep your personal data only for as long as necessary for the purposes set out in this Policy:

  • Account and personal data: retained while your account is active. Upon an account deletion request, we initiate a "soft deletion" process: your personal data is immediately deactivated and rendered inaccessible to you and to other users. We retain this data for a period of up to 30 days to allow for account restoration in case the deletion was accidental or unauthorized. Following this 30-day period, the data is automatically and permanently purged from our primary systems. Data contained in our technical backups may be retained for an additional period (up to 90 days) until it is overwritten during the standard backup cycle, after which it is also permanently destroyed. When we delete your personal data, we also inform the processors and other third parties to whom it was disclosed of the deletion, so that they can erase it too, unless this proves impossible or involves disproportionate effort.
  • Public content: not deleted when you delete your account, but anonymized so that it is no longer linked to you.
  • Team and club data: retained within the relevant team or club scope.
  • Chat and community messages: retained while your account is active and while the relevant chat exists; deleted or anonymized when you delete your account, subject to the public-content rule above.
  • Fishing activity and recommendation-model data: retained while your account is active and used to compute your personal analytics and recommendations; deleted with your account. Anonymised data contributed to the general model is not linked to you and is not removed when you delete your account, because it is no longer personal data.
  • Security and audit logs: typically retained for up to 12 months.
  • Diagnostic error reports: retained for up to 60 days, after which they are permanently deleted; an administrator may also delete them earlier.
  • Backups: kept on a rolling basis for up to 90 days, after which they are overwritten.
  • Payment and transaction records: retained for the period required by applicable accounting and tax law (handled together with Paddle as Merchant of Record), after which they are deleted or anonymized.
  • Deletion-request logs: we keep anonymized logs of deletion requests for up to 12 months for auditing and compliance purposes. These logs contain no personal data and serve only to confirm that a deletion request has been processed.
  • App usage and advertising-measurement data: kept by Google for our configured default retention period of 2 months from collection, after which the user-level and event-level records are deleted; aggregated reports that no longer identify you may be kept for longer.
  • Website visit and referral data: the first-party cookies described in Section 8 expire on your device after 30 days (ba_aff, ba_aff_cid), 90 days (ba_attr) or 12 months (ba_vid). Aggregated click and unique-visitor counts per partner link, which no longer identify you, are kept for as long as we operate the partner programme. The campaign and referral information attached to an account is kept while the account is active and is deleted with the account. These cookies are stored only if you accepted them, and they are deleted as soon as you withdraw your consent.

8. Cookies and local storage

The apps and website use local storage on your device (localStorage and IndexedDB) together with a small number of first-party cookies that we set on our own domain. Apart from the strictly necessary cookies listed below, nothing is stored before you accept it in our cookie banner — this applies both to our own measurement cookies and to the cookies of Google Analytics, which are the only third-party cookies on our website. We do not use advertising cookies and we do not track you across other websites.

Storage and cookies that are strictly necessary. localStorage and IndexedDB keep you signed in (your authentication session), enable offline use and data synchronization, and remember your preferences, including your cookie choice. That choice is stored both in localStorage and in a cookie of the same name (ba_cookie_consent), because our servers have to know your decision before they set anything else. Together with the strictly necessary cookies listed below they are essential to provide the Service and do not require your consent. Some of the cookies listed below do not run the Service itself but simply remember an action you took yourself — following an invitation link or opening a test session; they are stored in order to deliver what you asked for, are never used for advertising and never follow you across other websites.

Cookie Purpose Lifetime ba_sess The sign-in token of your web session. It is set when you sign in, can be read only by our server (HttpOnly) and travels over an encrypted connection; it is what keeps you signed in between visits. Signing out deletes it. 90 days ba_session A yes/no flag telling our public pages that this browser has an active sign-in, so that a shared link opens in your account instead of the guest view. It is not an authentication token and holds no information about you. 30 days ba_cookie_consent Your cookie choice — whether you accepted or declined measurement and analytics cookies — so that every page you open respects it and nothing you refused is ever set. The same choice is also kept in localStorage. 12 months ba_ref The invitation code of the referral link (beangler.com/r/…) you followed, kept so that the promised bonus can be credited to you and to the person who invited you if you sign up in this browser. It contains no information about you, is not shared with anyone and is not used for advertising or to follow you across other websites — it is stored only because you asked for it by following the link. 24 hours ba_test Marks this browser as a test session of one of our own QA accounts: the app is switched to the separate test database, shows test content and loads no analytics at all. It is set only when signing in with such an account, never for ordinary users. 24 hours

Cookies used to measure our own website and to credit our partners — only with your consent. These are not needed to operate the Service, but they let us see which campaign or partner a visit came from. They are set only after you accept them in our cookie banner; if you decline, or make no choice at all, they are never set, and if you withdraw your consent later they are deleted from your browser:

Cookie Purpose Lifetime ba_aff The referral code of the partner (affiliate) link you arrived through, so that the partner is credited if you sign up later. 30 days ba_aff_cid A random identifier of that individual click on the partner link, so that a sign-up can be matched to the click that produced it. 30 days ba_attr The campaign details of your visit — utm_source, utm_medium, utm_campaign, gclid and the bare host name of the external website you came from — so that a later sign-up can be attributed to the right campaign. Only the first campaign is kept. 90 days ba_vid A random token generated in your browser that lets us count unique visitors to a partner link instead of raw clicks. It is not linked to your account and is kept on our side only in aggregated, non-reversible form (a probabilistic counter per partner code and day). 12 months _fprom_ref The referral token of the partner whose link you arrived through, set by our affiliate platform FirstPromoter, so that a later purchase is credited to that partner. 60 days _fprom_tid A random identifier of that individual click on the partner's link, set by FirstPromoter, so that a purchase can be matched to the click that produced it. 60 days

None of these cookies contains your name, your email address or any other information that identifies you; our own measurement cookies (ba_aff, ba_aff_cid, ba_attr, ba_vid) are set by us and are never shared with a third party, while the two affiliate cookies _fprom_ref and _fprom_tid are set by our affiliate platform FirstPromoter, acting as our processor, solely so that the partner whose link brought you to us is credited; and none of them is used to build advertising profiles or to follow you across other websites. We use them for audience measurement and referral attribution on our own website only. Lawful basis: your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time on the Cookie Policy page in the web app; withdrawing it deletes these cookies and stops the measurement.

Analytics cookies — only with your consent. Our website can load Google Analytics 4, provided by Google Ireland Limited, to give us aggregate statistics on how the site is used. It is loaded only after you accept analytics cookies in our cookie banner; if you decline, or make no choice at all, it is never loaded and no Google Analytics cookie is set. You can change your choice at any time on the Cookie Policy page in the web app, and analytics is never loaded in test mode.

Cookie Purpose Lifetime _ga, _ga_* Set by Google Analytics to distinguish browsers and sessions for aggregate website statistics. Set only if you accept analytics cookies. up to 2 years

Lawful basis: your consent (Art. 6(1)(a) GDPR), which you may withdraw at any time. Google's role, the international transfers involved and the retention period are described in Section 9.

How to refuse or remove them. You can give or withdraw your consent at any time on the Cookie Policy page in the web app: declining stops Google Analytics from being loaded and removes the first-party measurement cookies described above. Those cookies can also be blocked or deleted at any time in your browser settings — for example by clearing the site data for beangler.com, by using a private window, or by using a browser that blocks cookies by default. Refusing any of them does not restrict the Service in any way: everything continues to work, we simply cannot tell which campaign or partner brought you to us. You may also write to us about this processing at any time at privacy@beangler.com (see Section 11).

Our mobile apps additionally include an analytics SDK that stores identifiers on your device and reads your advertising identifier — see Section 9, which also explains how to switch it off.

9. Analytics and advertising measurement in our mobile apps

Our mobile apps include Google Analytics for Firebase (also called Firebase Analytics), provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We use it for two purposes only: to see, in aggregate, how the app is used and how stable it is, and to measure how many people install and start using the app after seeing one of our advertisements — including campaigns we run through Google Ads.

What is collected. Automatically generated events (such as the first launch of the app, the start of a session, signing up, signing in, and app crashes), a Google-generated app instance identifier, your device's advertising identifier, the device model, the operating-system and app version, the language, and an approximate location (country or region) derived from your IP address. We do not send your email address, your name, your messages, your content, your catches or the coordinates you enter to Google Analytics, and we do not use this data to build advertising profiles about you beyond the campaign measurement described here.

Google's role and international transfers. Google processes this data on our behalf as our processor for analytics purposes, and for its own advertising-measurement purposes as an independent controller. The data may be processed outside the EU/EEA under the safeguards described in Section 6. Google's privacy policy is available at https://policies.google.com/privacy, and Google explains how it uses data from apps that use its services at https://policies.google.com/technologies/partner-sites.

Retention. The user-level and event-level analytics data is kept for our configured default retention period of 2 months from collection, after which it is deleted. Aggregated reports that no longer identify you may be kept for longer.

How to opt out. You can stop this collection at any time:

  • on Android — delete or reset your advertising ID and turn off ads personalisation in your device settings (Settings → Privacy → Ads, or Settings → Google → Ads);
  • on iOS — refuse or withdraw app-tracking permission and turn off personalised advertising (Settings → Privacy & Security → Tracking and Apple Advertising);
  • or write to privacy@beangler.com to object to this processing — we will act on your objection.

Opting out does not restrict any other part of the Service: the app continues to work in full. This collection is switched off entirely in our internal test builds. We do not use this app SDK on our website; there, Google Analytics is loaded only if you accept analytics cookies in our cookie banner (see Section 8).

10. Marketing communications

We send marketing emails on an opt-in basis only, that is, only after you have given your consent. You can opt out at any time by using the unsubscribe link in any marketing email or by changing your preferences in your account settings.

11. Your rights

Subject to the conditions and exceptions in applicable data protection law, you have the following rights in relation to your personal data:

  • Right of access — to obtain confirmation of whether we process your data and a copy of that data.
  • Right to rectification — to have inaccurate or incomplete data corrected.
  • Right to erasure ("right to be forgotten") — to have your personal data deleted without undue delay (subject to the retention rules in Section 7), for example through account deletion. Where we have shared your data with processors or other third parties, we will inform them of the erasure so that they can delete it too, unless this proves impossible or involves disproportionate effort.
  • Right to restriction of processing — to limit how we process your data in certain circumstances.
  • Right to object — to object to processing based on our legitimate interests, and to object to direct marketing at any time.
  • Right to human intervention — where a decision is based on automated processing (including profiling), to request that it be reviewed by a person, to express your point of view, and to contest the decision. As explained in Section 3, our recommendations are advisory and are not solely-automated decisions producing legal or similarly significant effects; where you nonetheless want a human to review any automated output that affects you, contact privacy@beangler.com.
  • Right to data portability — to receive the data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Right to withdraw consent — to withdraw any consent you have given at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Right to lodge a complaint — to lodge a complaint with a data protection supervisory authority, in particular in the EU/EEA member state of your habitual residence, place of work, or the place of the alleged infringement.

To exercise any of these rights, contact us at privacy@beangler.com. Account deletion (and the resulting erasure of your personal data) is available directly in your settings. We will respond to your request without undue delay and within the time limits required by applicable law. We do not charge a fee for exercising your rights, unless your request is manifestly unfounded or excessive.

12. Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, loss, or destruction. These measures include encryption of data in transit, access controls, and regular monitoring. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.

Personal data breaches. In the event of a personal data breach, we act in accordance with the GDPR and other applicable law, including notifying the competent supervisory authority and affected users where, and within the timeframes, the law requires.

13. Children

The Service is intended for users aged 16 and older. We do not knowingly collect or process the personal data of children under 16. If you believe that a child under 16 has provided us with personal data, please contact privacy@beangler.com and we will take appropriate steps to delete it.

14. Changes to this Policy

We may update this Policy from time to time. We will notify you of material changes within the Service, and we will update the version number and effective date at the top of this Policy upon publication. We encourage you to review this Policy periodically.

15. Contact

For any privacy question or request, contact us at privacy@beangler.com.

BeAngler © 2026
We use analytics and measurement cookies to see how the site is used and which campaign or partner brought you here. They are set only if you accept; the cookies needed to run the site work either way. Cookie Policy · Privacy Policy