Hazely Cookie & Tracker Policy

Effective 14 August 2026 | Version 2.0

About this version. Version 2.0 replaces version 1.1 in full. Version 1.1 named a company that never processed anything for us, gave the age gate a lawful basis that does not exist, described withdrawal controls the Android app does not have, and left out several things the App actually stores on or reads from your device. Every statement in this version was checked against the shipping Android and iOS builds on 13 August 2026. Where a control is missing, merged, or different between the platforms, this policy says so instead of describing the design we would prefer to have shipped.

Language. This policy is published in English only. No other language version of it exists, so none can prevail over this one. The only Hazely document currently published in Dutch is the Privacy Policy, at hazely.nl/privacybeleid. If you would like this policy explained in Dutch, write to privacy@hazely.nl — in Dutch if you prefer — and we will answer.

Mobile apps do not strictly use HTTP cookies, but they use the equivalent technologies — on-device key-value storage, device identifiers, and software development kits (SDKs). Under Article 11.7a of the Dutch Telecommunicatiewet and Art. 5(3) of the EU ePrivacy Directive 2002/58/EC the rules are the same as for cookies: storing information on your device, or reading information from it, requires prior, informed, freely-given consent unless it is strictly necessary for the service you asked for.

1. The two categories

We separate everything in this policy into essential — strictly necessary to deliver the service you asked for, so no consent is required — and optional — off by default, running only after you switch it on, and costing you nothing to refuse: every feature of the App works the same either way.

Where we claim something is strictly necessary, that is our own assessment, made in good faith and applied narrowly per the Autoriteit Persoonsgegevens' guidance. It has not been confirmed by an external adviser or a regulator. The Privacy Policy §4.1 sets out the reasoning item by item.

2. What the App stores on your device and never transmits

WhatWhat it recordsKept until
Age confirmation (age_confirmed_21)That you confirmed you are 21 or older, with a timestampUninstall, or Settings → "Reset all my privacy choices"
Acceptance and consent recordWhich versions of the Terms and of this policy you accepted, and your consent choices. On Android the exact version strings you accepted are stored; the current iOS build stores only that you accepted, not which version — see §9Same
Bookmarks / favouritesThe IDs of shops you starred. The list itself is never transmitted. If you turned Analytics on, the act of starring sends an event carrying the shop ID — the Privacy Policy §3.1 discloses thisSame
ThemeYour light/dark display preferenceSame
Review-prompt countersCounters that decide when to show the store's "rate this app" prompt. They stay on the device; the prompt itself is drawn by Google Play or the App StoreSame

All of this is essential in the narrow sense of §1: the age gate cannot be remembered, consent cannot be demonstrated (Art. 7(1) GDPR), and your own choices cannot be kept without storing them.

The lawful basis for the age flag is legitimate interest — Art. 6(1)(f) GDPR — not a legal obligation. No law imposes a 21+ gate on an information app: the Dutch tolerance criteria bind coffeeshops, not us, and set 18, not 21. The gate is our own rule, kept in the legitimate interest of keeping a cannabis-related app away from minors and meeting app-store age policies. Version 1.1 called this a "legal obligation"; the Privacy Policy §4.1 explains why that was wrong, and why the correction is in your favour — Art. 6(1)(f) processing carries a right to object that Art. 6(1)(c) processing does not.

3. Optional trackers — consent required, off by default

TrackerSet byWhat it stores or readsRetention
Firebase AnalyticsGoogleA pseudonymous app-instance identifier, plus the usage events listed in full in the Privacy Policy §3.2At most 14 months — a setting in Google's console, not something the App controls; the Privacy Policy §7 has the detail
Firebase CrashlyticsGoogleA per-installation identifier, plus crash data90 days at Google
Firebase Performance MonitoringGoogleAn installation identifier, plus timing traces of app start, screens and the App's own network requestsGoogle's published periods — see the Privacy Policy §7
Mapbox map telemetryMapboxMap-usage events collected by Mapbox's own SDK, for Mapbox's map-improvement purposesGoverned by Mapbox

Four things about these, stated plainly:

4. Services that run once you have answered the consent screen — whatever you answered

Two Google services start only after the consent screen has been answered, but then run regardless of which choices you made, and use on-device storage to do it:

ServiceWhat it stores or readsWhy we treat it as strictly necessary
Firebase Remote ConfigA Firebase installation identifier, plus the fetched configurationFeature flags and the "update required" kill switch. Being able to disable a broken or unsafe build has to work for someone who declined everything optional
Firebase App Check / Google Play Integrity (Android)An attestation token derived from the app and deviceTelling a real installation apart from an abusive script when our API is called

Treating these as strictly necessary for delivering a safe, configurable service (Art. 11.7a(3) Tw) is our position, stated as such — the Privacy Policy §4.1 carries the analysis, including the admission that no external adviser or regulator has confirmed it. Neither service runs before the consent screen is answered; that is a hard gate in the code on both platforms.

5. Essential network services

6. Advertising: built in, switched off

The Android app contains the Google AdMob SDK and Google's consent platform (UMP). Both are fully disabled: every ad placement is off, the ads SDK is never started, no ad has ever been served, and no advertising consent dialog is ever shown. The iOS app contains no advertising SDK at all. If advertising is ever enabled, it would run only after a separate consent flow of its own, and this policy would be updated before that happens, not after. The Android consent screen and Settings still offer a "personalised ads" choice; while no advertising runs, it controls nothing. iOS shows no such switch.

7. What this policy does not cover

Processing that happens on our servers rather than on your device — the menu-scan AI (Google Gemini), the strain-catalogue generation, our API and its request logs — stores nothing on your device and reads nothing from it, so it is outside this policy. The Privacy Policy covers all of it, in particular §3.3 (menu scans and the strain catalogue) and §7 (retention).

The hazely.nl website serves static pages and one report form. It sets no cookies, loads no analytics or advertising tags, and stores nothing in your browser; the report form submits what you type and keeps nothing client-side.

8. When and how we ask for consent

On first launch, after the age gate, the App shows a Consent Screen with three equally-prominent options:

Nothing is pre-ticked, every optional category defaults to off, and the screen blocks the App until you answer — not answering enables nothing (per CJEU Planet49 and the Autoriteit Persoonsgegevens' reading of Art. 11.7a Tw). Nothing optional runs before you have answered.

9. Changing your mind — the controls that actually exist

Withdrawal is free and affects future processing only (Art. 7(3) GDPR). The controls, as they exist in the current builds:

WhereControlWhat it really does
AndroidSettings → "Analytics & performance"One combined switch that currently governs analytics, performance monitoring and crash reporting together. If you consented to only one of the three, the switch shows as off — and switching it on turns on all three, including crash reporting you may have refused. This is a defect, disclosed in the Privacy Policy §10; separate switches ship in the next Android release
iOSSettings → Analytics; Settings → Crash reportingTwo separate switches. The Analytics switch also governs performance monitoring — see §3 — and its label does not currently say so. The crash switch stands alone
BothSettings → "Reset all my privacy choices"Clears every stored choice, including the age flag, and puts you through the full consent flow again
iOS mapⓘ (attribution) menu on the mapMapbox's own telemetry opt-out, which is the operative control on iOS until the app-level gate in §3 ships

10. Cross-border transfers

The optional trackers in §3 and the services in §4 are Google and Mapbox services running on global (Google) and United States (Mapbox) infrastructure. For transfers outside the EEA we rely on the EU Standard Contractual Clauses and, where the recipient is certified, the EU–US Data Privacy Framework. The Privacy Policy §6 has the full, honest version — including which location claims from earlier documents were withdrawn.

11. Third-party documentation

12. Children

Hazely is not intended for anyone under 21, and we do not knowingly set any tracker on the device of a person under 21. The age gate is a self-declaration; the Privacy Policy §12 says exactly what that does and does not achieve.

13. Changes to this policy, and what re-prompts you

We update this policy when what the App stores or reads changes. What an update does, per platform — promised only as far as each platform can actually deliver:

Earlier versions of this policy are available on request from privacy@hazely.nl; there is no public archive page.

14. Contact

Changelog

Version 2.0 — 14 August 2026 (replaces version 1.1 of 21 May 2026)

1. The second AI vendor is gone. Version 1.1's third-party list named a company as a menu-scan processor that has never processed anything for Hazely: menu scanning uses Google Gemini only, server-side. A server-side API is not a device-storage matter in any case, so this policy now carries a pointer to the Privacy Policy instead of a tracker row (§7, §11). 2. The age flag's lawful basis corrected from "legal obligation" to legitimate interest, Art. 6(1)(f) GDPR — no law imposes the 21+ gate. The change is in your favour: Art. 6(1)(f) carries a right to object (§2). 3. The inventory is now complete. Added: Firebase Performance Monitoring and the fact that it has no switch of its own; Firebase Remote Config and App Check / Play Integrity, their installation identifiers, and the strictly-necessary position we take for them; the Play in-app update check that runs before any gate; the Android Advertising ID riding the Analytics switch; the theme setting; and the review-prompt counters (§2–§5). 4. Withdrawal routes now describe the real controls. Version 1.1 promised per-tracker routes ("Settings → Privacy → Crash reporting → Off") that do not exist on Android, where one merged switch drives three purposes. The defect is now stated here and in the Privacy Policy §10, and the fix — separate switches — is named for the next Android release (§9). 5. The Mapbox iOS gap is stated: telemetry is not app-gated on iOS today. The ⓘ-menu opt-out and the planned app-level gate are described as they are, and the unsuppressible monthly-active-user count is kept disclosed (§3, §9). 6. AdMob re-described as dormant. Version 1.1 described advertising signals "after consent is recorded"; in fact no ad has ever been served, the ads SDK is never started, and the iOS app has no ads SDK at all (§6). 7. The re-prompt promise is cut to what each platform can do. Android re-prompts; the current iOS build cannot, and this policy now says so instead of promising it (§13). 8. Analytics retention hedged to "at most 14 months — a console setting", matching the Privacy Policy §7, instead of stating a bare figure (§3). 9. A language note was added, and this changelog begins with this version — version 1.1 carried none.