Skip to content
BETA Sign In

Privacy Policy

Effective date: March 23, 2026 · Last updated: March 23, 2026

This Privacy Policy describes how Heartland Software LLC ("Company," "we," "us," or "our") collects, uses, shares, and protects information when you use the BagTrax application and website at bagtrax.app (the "Service"). By accessing or using the Service, you agree to this Privacy Policy. If you do not agree, do not use the Service.

1. Information We Collect

1.1 Information You Provide

  • Account information — Name and email address provided during sign-up through our authentication provider (WorkOS).
  • Profile information — Display name, team names, and other optional profile details you choose to provide.
  • Game data — Scores, statistics, game history, tournament registrations, and other content you create through the Service.
  • Communications — Information you provide when contacting us for support or feedback.

1.2 Information Collected Automatically

  • Usage data — Page views, feature usage, session duration, and interaction patterns collected via PostHog analytics.
  • Device and browser information — Browser type, operating system, screen resolution, and language preferences.
  • Log data — IP address, access times, referring URLs, and server request logs.
  • Cookies — Session cookies necessary for authentication and service functionality (see Section 6).

1.3 Information from Third Parties

  • Authentication provider — We receive your name, email, and authentication identifiers from WorkOS when you sign in.
  • Payment processor — Stripe provides us with transaction confirmations, subscription status, and limited billing details (last four digits of card, card brand, expiration date). We never receive or store your full payment card number.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service, including scoring, statistics, leaderboards, and tournament management.
  • Process transactions and manage your subscription.
  • Send transactional emails such as tournament confirmations, payment receipts, and account notifications.
  • Analyze usage patterns to improve the Service's performance, features, and user experience.
  • Generate aggregate, anonymized statistics that cannot be used to identify you.
  • Detect, prevent, and address fraud, abuse, security incidents, and technical issues.
  • Enforce our Terms of Service and comply with legal obligations.

3. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We share information only in the following circumstances:

3.1 Service Providers

We use the following third-party service providers who process data on our behalf under contractual obligations to protect your information:

  • Stripe — Payment processing and subscription management.
  • WorkOS — Authentication and identity management.
  • Resend — Transactional email delivery.
  • Railway — Cloud infrastructure and application hosting.
  • PostHog — Product analytics.
  • Cloudflare R2 — Database backups and file storage.

3.2 Public Information

Certain information is visible to other users by design, including your display name, game scores, tournament standings, leaderboard rankings, and ELO ratings. Do not include personal information in display names or team names that you do not want to be publicly visible.

3.3 Legal Requirements

We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a government request.

3.4 Business Transfers

If Heartland Software LLC is involved in a merger, acquisition, asset sale, or bankruptcy, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Service before your information is subject to a different privacy policy.

4. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. After account deletion, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal, accounting, or regulatory purposes. Anonymized and aggregate data that cannot identify you may be retained indefinitely.

5. Data Security

We implement reasonable administrative, technical, and physical safeguards to protect your information, including:

  • Encryption in transit (TLS/HTTPS on all connections).
  • Encrypted database backups.
  • Rate limiting.
  • Session-based authentication with secure, HTTP-only cookies.
  • Regular infrastructure updates and monitoring.

However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, and you use the Service at your own risk.

6. Cookies and Tracking

We use essential cookies only:

  • Session cookies — Required for authentication and maintaining your logged-in state. These are strictly necessary and cannot be disabled while using the Service.
  • Theme preference — Stored in your browser's local storage (not a cookie) to remember your display settings.

We do not use advertising cookies, third-party tracking cookies, or cross-site tracking technologies. PostHog analytics may use cookies or similar technologies to distinguish unique users; you may opt out of analytics tracking through your browser's Do Not Track setting.

7. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights:

  • Access — Request a copy of the personal information we hold about you.
  • Correction — Request correction of inaccurate or incomplete information.
  • Deletion — Request deletion of your account and associated personal data. We will process deletion requests within 30 days.
  • Data portability — Request an export of your data in a structured, machine-readable format.
  • Opt out of analytics — You may use browser Do Not Track settings or contact us to opt out of PostHog analytics.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. We may ask you to verify your identity before processing your request.

8. Children's Privacy

The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will promptly delete that information. If you believe a child under 13 has provided us with personal information, please contact us at [email protected].

9. International Data Transfers

Your information is stored and processed in the United States. If you access the Service from outside the United States, you consent to the transfer, storage, and processing of your information in the United States, where data protection laws may differ from those in your jurisdiction.

10. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • The right to know what personal information we collect, use, and disclose.
  • The right to request deletion of your personal information.
  • The right to opt out of the "sale" of personal information — we do not sell your personal information.
  • The right to non-discrimination for exercising your privacy rights.

To exercise these rights, contact us at [email protected].

11. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party sites you visit.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Service with a revised "Last updated" date. For significant changes, we may also notify you by email. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the revised Privacy Policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, contact us at:

Heartland Software LLC
Email: [email protected]