Skip to content
Treasure Hunt
Privacy Terms

Your data, explained plainly

Privacy Policy

Effective August 6, 2026

Treasure Hunt is operated by M3 Platform (“Treasure Hunt,” “we,” “us,” or “our”). This Privacy Policy explains how we handle information when you use the Treasure Hunt mobile apps, website, and related services (together, the “Service”).

The short version
  • You can browse without an account; some community features require sign-in.
  • We do not sell personal information or use it for targeted ads.
  • Trip location is collected only during a trip you explicitly start.
  • Runners see an arrival estimate, not your coordinates or starting point.
  • You choose whether to submit a photo or store map.
  • Raw motion readings used for mapping stay on your device.
  • On iOS, a raw survey video stays on the iPhone unless the mapper explicitly shares it.

1. Information we collect

Information you submit

Depending on the features you use, you may submit:

  • Account information: if you create a password account, we collect your username and password. We store a salted hash of the password, not the original password. If you use Google Sign-In, Google provides your Google account identifier, name, email address, and profile photo. We also maintain your account creation and last-login times, session records, and points balance.
  • Item sighting information: a shelf or product photo, barcode number, product name, price, currency, floor, availability, and the time of the report.
  • Precise location: latitude and longitude, location accuracy, and whether Android marked the reading as a mock location. We use this information to identify the physical store and validate an item report. If you request Runner fulfillment and explicitly start a trip, we also process your latest location fix and capture time to estimate when you will reach the Store. We do not provide the fix or your starting point to a Runner.
  • Store suggestions: precise coordinates and any store name or note you choose to provide when a store is not listed.
  • Store map contributions: the selected store and floor, marked aisle points and connections, landmark labels, and the map capture method.
  • Shopping and hunt activity: items and notes you add to a shopping list, completed-list status, routes, hunts you create or join, hunt submissions and decisions, reward and point history, and related in-app notifications.
  • Runner fulfillment activity: your Store, item choices, quantities, quality and replacement rules, commitment fee quote and status, order and trip status, picked-item manifests, Store-payment provider reference and confirmation status, handoff attempts, cancellations, and support events. We do not receive the card details you submit to the Store's payment provider.
  • Runner operations: if you are an authorized Runner, we maintain your Store memberships, availability, check-in, capacity, heartbeat, assignments, scans, pick results, and handoffs. Runner access is limited to the Stores where the account is authorized.
  • Messages to us: the email address and contents of a message when you contact support.

Information processed on your device

The app uses barcode and text recognition to read a product photo. Recognition occurs on your device. The photo is sent to us only if you review the report and tap Upload.

When you map a store, the app uses step-count and motion sensors to estimate your path. Raw sensor readings, raw walking history, camera frames, GPS coordinates, user IDs, and device IDs are not included in the store map uploaded to us. Only the final aisle graph and labels are submitted.

During an iOS ARKit survey, the app also records one raw camera video without audio or automatic face blurring. The recording is stored in private app storage on that iPhone and is excluded from automatic map-evidence and product-stills uploads. An authorized mapper can explicitly share the file through the iOS share sheet or permanently delete it from Previous AR Surveys.

Technical information

Our servers and service providers may automatically process ordinary request information such as IP address, request time, app version, device or operating-system information, and error or security logs. The app also creates a random app-specific device identifier for its current device-scoped shopping-list feature. This is not a hardware or advertising identifier. The ML Kit libraries used for on-device barcode and text recognition may send Google app information, device information, performance metrics, and a per-installation identifier for diagnostics and usage analytics. We do not include an advertising SDK in the current app.

2. How we use information

We use information to:

  • match a shopper to the store they are visiting;
  • create and display community product sightings and store maps;
  • help shoppers locate products and plan in-store routes;
  • create and manage accounts, sessions, shopping lists, hunts, and rewards;
  • quote and collect the Treasure Hunt commitment fee;
  • estimate arrival, release orders, dispatch Runners, validate picks, and coordinate handoff;
  • confirm the status of a separate merchandise payment made through the Store's provider;
  • review report quality and detect errors, abuse, or location spoofing;
  • operate, secure, debug, and improve the Service;
  • answer support requests; and
  • comply with law and enforce our Terms and Conditions.

Submitted product details and photos may be shown to other shoppers, store operators, and service administrators as part of the community catalog. Location is used to associate a contribution with a store and place it on a store map. We do not intend to show your live location or identify you to other shoppers.

3. When we disclose information

We may disclose information:

  • To the community: product reports, photos, prices, availability, timestamps, and mapped locations may be visible through the Service.
  • To service providers: companies that provide cloud hosting, database hosting, object storage, app processing, payment processing for Treasure Hunt fees, notifications, and security services. These currently include Google services, Cloudflare, and Supabase. They process information for us under their applicable terms.
  • To Stores, authorized Runners, and Store payment providers: we disclose the order and operational details needed to pick, pay for, and hand off your items. A Runner receives an ETA band and journey state, not your precise coordinates or origin. Merchandise payment information you submit directly to a Store provider is governed by that provider's terms and privacy policy.
  • For legal and safety reasons: when reasonably necessary to comply with law, protect users, investigate abuse, or defend legal rights.
  • In a business transaction: as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections.

We do not sell personal information. We do not disclose precise location, photos, or sensor-related data for targeted advertising.

4. Your choices and controls

  • Location: Android asks for your permission before the app accesses precise location. A fulfillment trip starts only after you tap the trip control while the app is visible. During that trip, Android shows an ongoing notification and the app may continue updating your arrival estimate while the screen is off or you use another app. You can stop the trip from the app or notification, and collection stops automatically on arrival, cancellation, or completion. Treasure Hunt does not request Android's all-the-time background-location permission. You can decline or revoke location permission in Android settings; manual arrival remains available for fulfillment.
  • Photos: you decide whether to take or select a photo, and you can cancel before uploading it.
  • Local iOS survey video: starting an ARKit survey starts the on-device recording. It is not uploaded automatically. Previous AR Surveys shows its size and provides separate Share and Delete controls.
  • Physical activity: this permission is used only when you choose to map a store. You can decline it and skip mapping.
  • Account and data deletion: you may ask us to delete your account, a contribution, or other associated data by emailing [email protected]. Include your username or account email. For an anonymous or device-scoped record, include enough detail for us to locate it, such as the store, date, product, list item, or photo. We may be unable to identify an anonymous record if the details are insufficient. You can sign out at any time, but signing out or uninstalling does not by itself delete server records.

5. Retention

We retain account records while an account is active and retain community item reports, photos, shopping and hunt activity, and map contributions while they remain useful for the Service. A signed-in session normally expires after 30 days, although related security records may be kept longer when reasonably necessary. During a fulfillment trip we keep only the latest operational location fix; a new fix replaces it, and the fix is cleared when the trip ends or expires. Derived ETA bands and order events may remain with the fulfillment record. Order, fee, external payment, manifest, and handoff audit records may be retained as needed for accounting, dispute, fraud-prevention, and legal obligations. We may retain information as needed to resolve disputes, prevent abuse, satisfy legal obligations, or protect the Service. Operational and security logs are kept according to our providers’ settings and are deleted or de-identified when no longer reasonably needed. If we honor a deletion request, backups may retain a copy for a limited period until they cycle out. Raw iOS survey videos remain in private app storage until the mapper deletes them, clears app data, or uninstalls the app.

6. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information. App data is sent to our production services over HTTPS. Passwords are stored as salted hashes, server session tokens are stored as cryptographic hashes, and handoff codes are stored as one-way hashes. The app stores its active session and local iOS survey videos in app-private storage. No security measure is perfect, and we cannot guarantee absolute security.

7. Children’s privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can investigate and delete it where appropriate.

8. International use

Treasure Hunt is operated from the United States. If you use the Service elsewhere, information may be processed in the United States or other countries where our service providers operate, which may have different data-protection laws.

9. Changes to this policy

We may update this Privacy Policy as the Service changes. We will post the revised policy here and update its effective date. If a change materially affects how we handle information, we will provide additional notice when reasonably practical.

10. Contact us

For privacy questions or deletion requests, contact: [email protected].

Treasure Hunt

List it. Route it. Find it.

Terms Contact © Treasure Hunt