CommonGround
Effective 14 July 2026

Privacy Notice

Common Ground is designed so movement can shape a shared game without turning a person’s route into public content. This notice explains what the service processes, why, and what controls members have.

1. Who controls your data

Rachid Ait Moussa (ra7ch), at Benguerir, Morocco, is the Common Ground operator and controller for account data. Infrastructure and payment providers act only for the purposes described here and under their contracts with that operator.

2. Data we process

3. How we use it

We process data to create and protect accounts; save personal history; verify eligible activity; calculate delayed aggregate territory, strongholds, challenges, and ratings; operate crews and matches; prevent fraud and unsafe behavior; provide support, exports, deletion, and billing; meet legal obligations; and improve reliability using minimized operational signals.

4. Public and crew visibility

Visibility controls apply to activity presentation. The shared world contains fixed game cells and delayed aggregate influence—not raw routes or live member locations. Shared challenge and team totals use a minimum-contributor daily UTC snapshot. Private activity is excluded from public and organizer aggregates. Blocking suppresses reciprocal discovery and named feed signals without notifying the blocked person.

5. Legal bases

Depending on the member’s jurisdiction, processing is based on performing the service contract, legitimate interests in security and fair competition, consent for optional marketing or device permissions, and compliance with law. You can withdraw optional consent without affecting earlier lawful processing.

6. Sharing and international processing

Data may be handled by contracted hosting, database, email, monitoring, and payment providers; by authorized moderators who need it for safety; or by authorities when legally required. We do not sell precise location data or use it for behavioral advertising. Providers may process data in other countries using safeguards required for the deployment’s jurisdiction.

7. Retention

Raw GPS samples are transient. Account and game records remain while the account is active or as needed to provide the service. Completed deletion removes or pseudonymizes identifying records while narrowly required fraud, financial, moderation, and backup records follow documented legal and expiry periods. One-time proof and recovery credentials expire automatically.

8. Your choices and rights

Profile controls let you correct your public identity and regional preferences, request a password-confirmed email change, change privacy, recovery, notifications, accessibility, and blocks, export allow-listed account data, revoke sessions, appeal verification labels, schedule deletion, or delete immediately after re-authentication. Applicable law may also provide access, correction, erasure, restriction, portability, objection, consent withdrawal, and a complaint to a supervisory authority.

9. Device storage and permissions

The installable web app caches only its public offline shell and static assets. It does not cache private API responses or page HTML. A manual activity may be held in account-bound IndexedDB until the open app reconnects; verified GPS and gym proof is never queued there, and raw GPS points are never stored there. Geolocation is requested only when you start live outdoor proof and can be revoked in device settings.

10. Security, age, and changes

We use same-origin secure cookies, CSRF protection, least-privilege roles, audit trails, rate limits, encryption in transit, and operational safeguards. No system is risk-free. Accounts are limited to people aged 18 or older. Material notice changes will be dated and communicated where law requires it.

Privacy questions and rights requests can be sent to rachidaitmoussa1999@gmail.com. The operator is established in Morocco. Account export and deletion remain available directly in Profile.