Hazely Cookie & Tracker Policy
About this version. Version 2.0 replaces version 1.1 in full. Version 1.1 named a company that never processed anything for us, gave the age gate a lawful basis that does not exist, described withdrawal controls the Android app does not have, and left out several things the App actually stores on or reads from your device. Every statement in this version was checked against the shipping Android and iOS builds on 13 August 2026. Where a control is missing, merged, or different between the platforms, this policy says so instead of describing the design we would prefer to have shipped.
Language. This policy is published in English only. No other language version of it exists, so none can prevail over this one. The only Hazely document currently published in Dutch is the Privacy Policy, at hazely.nl/privacybeleid. If you would like this policy explained in Dutch, write to privacy@hazely.nl — in Dutch if you prefer — and we will answer.
Mobile apps do not strictly use HTTP cookies, but they use the equivalent technologies — on-device key-value storage, device identifiers, and software development kits (SDKs). Under Article 11.7a of the Dutch Telecommunicatiewet and Art. 5(3) of the EU ePrivacy Directive 2002/58/EC the rules are the same as for cookies: storing information on your device, or reading information from it, requires prior, informed, freely-given consent unless it is strictly necessary for the service you asked for.
1. The two categories
We separate everything in this policy into essential — strictly necessary to deliver the service you asked for, so no consent is required — and optional — off by default, running only after you switch it on, and costing you nothing to refuse: every feature of the App works the same either way.
Where we claim something is strictly necessary, that is our own assessment, made in good faith and applied narrowly per the Autoriteit Persoonsgegevens' guidance. It has not been confirmed by an external adviser or a regulator. The Privacy Policy §4.1 sets out the reasoning item by item.
2. What the App stores on your device and never transmits
| What | What it records | Kept until |
|---|---|---|
Age confirmation (age_confirmed_21) | That you confirmed you are 21 or older, with a timestamp | Uninstall, or Settings → "Reset all my privacy choices" |
| Acceptance and consent record | Which versions of the Terms and of this policy you accepted, and your consent choices. On Android the exact version strings you accepted are stored; the current iOS build stores only that you accepted, not which version — see §9 | Same |
| Bookmarks / favourites | The IDs of shops you starred. The list itself is never transmitted. If you turned Analytics on, the act of starring sends an event carrying the shop ID — the Privacy Policy §3.1 discloses this | Same |
| Theme | Your light/dark display preference | Same |
| Review-prompt counters | Counters that decide when to show the store's "rate this app" prompt. They stay on the device; the prompt itself is drawn by Google Play or the App Store | Same |
All of this is essential in the narrow sense of §1: the age gate cannot be remembered, consent cannot be demonstrated (Art. 7(1) GDPR), and your own choices cannot be kept without storing them.
The lawful basis for the age flag is legitimate interest — Art. 6(1)(f) GDPR — not a legal obligation. No law imposes a 21+ gate on an information app: the Dutch tolerance criteria bind coffeeshops, not us, and set 18, not 21. The gate is our own rule, kept in the legitimate interest of keeping a cannabis-related app away from minors and meeting app-store age policies. Version 1.1 called this a "legal obligation"; the Privacy Policy §4.1 explains why that was wrong, and why the correction is in your favour — Art. 6(1)(f) processing carries a right to object that Art. 6(1)(c) processing does not.
3. Optional trackers — consent required, off by default
| Tracker | Set by | What it stores or reads | Retention |
|---|---|---|---|
| Firebase Analytics | A pseudonymous app-instance identifier, plus the usage events listed in full in the Privacy Policy §3.2 | At most 14 months — a setting in Google's console, not something the App controls; the Privacy Policy §7 has the detail | |
| Firebase Crashlytics | A per-installation identifier, plus crash data | 90 days at Google | |
| Firebase Performance Monitoring | An installation identifier, plus timing traces of app start, screens and the App's own network requests | Google's published periods — see the Privacy Policy §7 | |
| Mapbox map telemetry | Mapbox | Map-usage events collected by Mapbox's own SDK, for Mapbox's map-improvement purposes | Governed by Mapbox |
Four things about these, stated plainly:
- Performance Monitoring has no switch of its own — on either platform. It is controlled by the same switch as Analytics, on Android and on iOS alike, and the switch's label does not currently say so. Consenting to analytics therefore also enables performance monitoring. We would rather this were a separate switch; today it is not.
- On Android, turning Analytics on currently also collects the Google Advertising ID. That is the analytics SDK's default behaviour; it rides the Analytics switch rather than any advertising control, and no advertising runs. Collection of the Advertising ID is being disabled in the next Android release.
- Android shortens every analytics event value to 100 characters before sending it. No analytics event on either platform carries text you typed — the Privacy Policy §3.2 lists every event and every parameter.
- Mapbox telemetry is only half-gated today. On Android it is tied to the Analytics switch: Analytics off means Mapbox telemetry off, re-applied from the stored setting every time the map is built. On iOS the App does not currently gate it — it runs under Mapbox's own SDK defaults, and you can opt out through the ⓘ (attribution) menu on the map itself. An app-level gate arrives in the next iOS update; until it ships, this paragraph is the honest description. On both platforms one item cannot be suppressed: the SDK sends one aggregate monthly-active-user "turnstile" count for Mapbox's licence metering regardless of any setting. It carries no location and no usage detail.
4. Services that run once you have answered the consent screen — whatever you answered
Two Google services start only after the consent screen has been answered, but then run regardless of which choices you made, and use on-device storage to do it:
| Service | What it stores or reads | Why we treat it as strictly necessary |
|---|---|---|
| Firebase Remote Config | A Firebase installation identifier, plus the fetched configuration | Feature flags and the "update required" kill switch. Being able to disable a broken or unsafe build has to work for someone who declined everything optional |
| Firebase App Check / Google Play Integrity (Android) | An attestation token derived from the app and device | Telling a real installation apart from an abusive script when our API is called |
Treating these as strictly necessary for delivering a safe, configurable service (Art. 11.7a(3) Tw) is our position, stated as such — the Privacy Policy §4.1 carries the analysis, including the admission that no external adviser or regulator has confirmed it. Neither service runs before the consent screen is answered; that is a hard gate in the code on both platforms.
5. Essential network services
- Mapbox map rendering. Drawing the map is the service you opened the App for: tile, style and font requests go to Mapbox whenever the map is on screen, carrying your IP address and the area you are looking at. This cannot be switched off — without it there is no app.
- Play in-app update check (Android). At app start — before the age gate and before any consent screen — the Android app asks Google Play whether an update is required. This is a Google Play system interaction between your device and the store you installed from; we receive nothing from it.
6. Advertising: built in, switched off
The Android app contains the Google AdMob SDK and Google's consent platform (UMP). Both are fully disabled: every ad placement is off, the ads SDK is never started, no ad has ever been served, and no advertising consent dialog is ever shown. The iOS app contains no advertising SDK at all. If advertising is ever enabled, it would run only after a separate consent flow of its own, and this policy would be updated before that happens, not after. The Android consent screen and Settings still offer a "personalised ads" choice; while no advertising runs, it controls nothing. iOS shows no such switch.
7. What this policy does not cover
Processing that happens on our servers rather than on your device — the menu-scan AI (Google Gemini), the strain-catalogue generation, our API and its request logs — stores nothing on your device and reads nothing from it, so it is outside this policy. The Privacy Policy covers all of it, in particular §3.3 (menu scans and the strain catalogue) and §7 (retention).
The hazely.nl website serves static pages and one report form. It sets no cookies, loads no analytics or advertising tags, and stores nothing in your browser; the report form submits what you type and keeps nothing client-side.
8. When and how we ask for consent
On first launch, after the age gate, the App shows a Consent Screen with three equally-prominent options:
- Accept all — turns on the optional categories;
- Reject optional — leaves them all off;
- Customise — switch each optional category on or off individually.
Nothing is pre-ticked, every optional category defaults to off, and the screen blocks the App until you answer — not answering enables nothing (per CJEU Planet49 and the Autoriteit Persoonsgegevens' reading of Art. 11.7a Tw). Nothing optional runs before you have answered.
9. Changing your mind — the controls that actually exist
Withdrawal is free and affects future processing only (Art. 7(3) GDPR). The controls, as they exist in the current builds:
| Where | Control | What it really does |
|---|---|---|
| Android | Settings → "Analytics & performance" | One combined switch that currently governs analytics, performance monitoring and crash reporting together. If you consented to only one of the three, the switch shows as off — and switching it on turns on all three, including crash reporting you may have refused. This is a defect, disclosed in the Privacy Policy §10; separate switches ship in the next Android release |
| iOS | Settings → Analytics; Settings → Crash reporting | Two separate switches. The Analytics switch also governs performance monitoring — see §3 — and its label does not currently say so. The crash switch stands alone |
| Both | Settings → "Reset all my privacy choices" | Clears every stored choice, including the age flag, and puts you through the full consent flow again |
| iOS map | ⓘ (attribution) menu on the map | Mapbox's own telemetry opt-out, which is the operative control on iOS until the app-level gate in §3 ships |
10. Cross-border transfers
The optional trackers in §3 and the services in §4 are Google and Mapbox services running on global (Google) and United States (Mapbox) infrastructure. For transfers outside the EEA we rely on the EU Standard Contractual Clauses and, where the recipient is certified, the EU–US Data Privacy Framework. The Privacy Policy §6 has the full, honest version — including which location claims from earlier documents were withdrawn.
11. Third-party documentation
- Firebase (Analytics, Crashlytics, Performance, Remote Config, App Check): https://firebase.google.com/support/privacy
- Mapbox: https://www.mapbox.com/legal/privacy
12. Children
Hazely is not intended for anyone under 21, and we do not knowingly set any tracker on the device of a person under 21. The age gate is a self-declaration; the Privacy Policy §12 says exactly what that does and does not achieve.
13. Changes to this policy, and what re-prompts you
We update this policy when what the App stores or reads changes. What an update does, per platform — promised only as far as each platform can actually deliver:
- On Android, the App stores the exact version string of this policy that you accepted, and a material change re-prompts you on the next launch after the update reaches your device.
- The current iOS build cannot do that: it records only that you accepted, not which version, so a document change re-prompts nobody on iOS today. The next iOS build records version strings and makes re-prompting possible; existing iOS installs will be asked once that update arrives. We are not promising more than that.
Earlier versions of this policy are available on request from privacy@hazely.nl; there is no public archive page.
14. Contact
- Questions: privacy@hazely.nl
- Complaints: Autoriteit Persoonsgegevens — https://autoriteitpersoonsgegevens.nl/en
Changelog
Version 2.0 — 14 August 2026 (replaces version 1.1 of 21 May 2026)
1. The second AI vendor is gone. Version 1.1's third-party list named a company as a menu-scan processor that has never processed anything for Hazely: menu scanning uses Google Gemini only, server-side. A server-side API is not a device-storage matter in any case, so this policy now carries a pointer to the Privacy Policy instead of a tracker row (§7, §11). 2. The age flag's lawful basis corrected from "legal obligation" to legitimate interest, Art. 6(1)(f) GDPR — no law imposes the 21+ gate. The change is in your favour: Art. 6(1)(f) carries a right to object (§2). 3. The inventory is now complete. Added: Firebase Performance Monitoring and the fact that it has no switch of its own; Firebase Remote Config and App Check / Play Integrity, their installation identifiers, and the strictly-necessary position we take for them; the Play in-app update check that runs before any gate; the Android Advertising ID riding the Analytics switch; the theme setting; and the review-prompt counters (§2–§5). 4. Withdrawal routes now describe the real controls. Version 1.1 promised per-tracker routes ("Settings → Privacy → Crash reporting → Off") that do not exist on Android, where one merged switch drives three purposes. The defect is now stated here and in the Privacy Policy §10, and the fix — separate switches — is named for the next Android release (§9). 5. The Mapbox iOS gap is stated: telemetry is not app-gated on iOS today. The ⓘ-menu opt-out and the planned app-level gate are described as they are, and the unsuppressible monthly-active-user count is kept disclosed (§3, §9). 6. AdMob re-described as dormant. Version 1.1 described advertising signals "after consent is recorded"; in fact no ad has ever been served, the ads SDK is never started, and the iOS app has no ads SDK at all (§6). 7. The re-prompt promise is cut to what each platform can do. Android re-prompts; the current iOS build cannot, and this policy now says so instead of promising it (§13). 8. Analytics retention hedged to "at most 14 months — a console setting", matching the Privacy Policy §7, instead of stating a bare figure (§3). 9. A language note was added, and this changelog begins with this version — version 1.1 carried none.