Last updated: 1 September 2026
This is what Ganja Fight Club — the website and the mobile app — collects about you, why, who sees it, and how to get rid of it. It is written from what the software actually does, not from a template.
[OWNER: insert the legal name and contact address of the entity that operates the Club and is the data controller. If you have or need a data-protection contact, add it here.]
1. What we collect
When you sign up
- Username, email address, and a password (stored only as a one-way hash — we cannot read it).
- Date of birth, to confirm you are 21 or older. We keep the date, not just the yes/no.
- The invitation code you used, so we know who invited you.
- Optionally: first and last name, gender, phone number, country, city, relationship status. Each of these has its own privacy setting on your profile.
What you add to your profile
- Profile and cover photos, bio, website, and the Club’s own profile fields — growing experience, grow method, extraction experience, years growing, cannabis experience, years using, consumption preferences.
What you post
- Posts, photos, comments, likes, grow logs and their updates, strain entries, reviews, stash and seed-vault records, event tickets and entries, and messages to other members.
- Photos can carry metadata such as the date taken and, if your phone adds it, the location. Strip location data from photos before uploading if you do not want it stored. [OWNER: confirm whether the server strips EXIF on upload; if it does, say so here.]
Collected automatically
- When you were last active, and the IP address of failed sign-in attempts (to stop account attacks).
- Approximate location (country and city) when you allow it, used for your profile and nearby events.
- Standard web server logs: IP address, browser, pages requested, timestamps.
- A push-notification token for your device, if you turn notifications on.
In the mobile app specifically
- Google Firebase Analytics — anonymous usage events (which screens are opened, crashes) tied to an app-instance ID, not your name. Used to find what breaks.
- Firebase Remote Config — fetches feature settings; sends the app version and instance ID to Google.
- OneSignal — delivers push notifications; stores your device push token and a subscription ID.
- The app asks for camera and photo library access only when you choose to add a photo, and notifications only when you say yes. It does not access contacts, microphone, or precise location.
- A cache of what you have viewed and your sign-in token are stored on your device so the app works offline and stays signed in. Signing out clears them.
Payments
- Membership payments are processed by the payment methods offered at checkout and by the Club wallet. We receive a record that you paid, the amount, and a transaction reference. We never receive or store your card number. [OWNER: name the live processor(s) once configured.]
2. Why we use it
- To run the Club: sign you in, show your content to members, deliver messages and notifications, enforce tier limits, run events.
- To keep it safe: age checks, invitation tracking, stopping abuse and account attacks, enforcing the Terms.
- To fix and improve it: crash reports and anonymous usage.
- To contact you about your account, your membership, or changes to these documents. Notification emails (likes, comments, mentions and so on) each have their own switch in Settings.
We do not sell your data. We do not run advertising. We do not build profiles for anyone else.
3. Who can see it
- Other members see your public profile and what you post. Your profile’s privacy settings control who sees gender, birthday, relationship, and location. Messages are visible only to the people in the conversation.
- Nobody outside the Club can see member content. The site requires sign-in; it is not indexed by search engines.
- Service providers that process data on our behalf: our hosting provider [OWNER: name it], Google (Firebase), OneSignal, and the payment processor(s) at checkout. Each receives only what it needs to do its job.
- Law enforcement: we release data only when legally compelled by a valid order in the jurisdiction where we operate, and we will tell you if we are allowed to. We do not volunteer member data to anyone. [OWNER: a lawyer must confirm this paragraph for your jurisdiction — it is the one members will care about most.]
4. How long we keep it
- Account and content: while your account exists.
- After you delete your account: removed from the live service immediately; purged from backups within 30 days.
- Server logs and failed-login IPs: [OWNER: state the retention period — 90 days is a reasonable default].
- Payment records: as long as tax and accounting law requires.
5. Your controls
- See and change your information any time in Settings.
- Delete your account yourself from Settings. This is real deletion, not deactivation.
- Turn off each type of notification email, push notifications, and location sharing individually.
- Ask us for a copy of your data, or to correct or delete something you cannot reach yourself, at info@ganjafightclub.com. We answer within 30 days.
- If you are in the EU, UK, or California, you have additional statutory rights (access, portability, objection, and the right to complain to a regulator). Email us to exercise them. [OWNER: if you have EU/UK members, a lawyer should confirm whether a representative or additional GDPR wording is required.]
6. Cookies
The website uses a sign-in cookie so you stay logged in, a “remember me” cookie if you tick that box, and a session cookie. No advertising or tracking cookies. The app uses no cookies; it uses on-device storage as described above.
7. Security
Connections are encrypted (HTTPS). Passwords are hashed. Access to the database is restricted to the people who run the Club. No system is perfectly secure; if we discover a breach that affects you, we will tell you promptly and honestly.
8. Age
The Club is for people 21 and over. We do not knowingly collect data from anyone younger. If we learn that we have, we delete the account and its data.
9. Where data lives
Data is stored on our hosting provider’s servers in [OWNER: country] and by the providers named above, some of which operate in the United States. [OWNER: if members are outside that country, a lawyer should confirm the transfer basis.]
10. Changes
If this policy changes in a way that matters, we’ll post a notice in the Club before it takes effect.
11. Contact
This policy describes the Club’s actual data flows as built on 1 September 2026. The bracketed items must be completed by the operator, and the document reviewed by a lawyer licensed where the Club operates, before it is relied on.