Privacy Policy
Effective as of 2026-06-19
This privacy policy is applicable to the Buck Hub application and any related services operated by Buck Hub LLC (collectively, the "Application"). Buck Hub LLC is hereinafter referred to as the "Service Provider".
Data Controller Information
Buck Hub LLC acts as the Data Controller responsible for the processing of your personal data.
- Name: Buck Hub LLC
- Address: 440 35 Rd, Palisade, CO 81526
- Email: Brandi.Heffner@gmail.com
For data protection inquiries and to exercise your GDPR rights, please contact the Data Controller using the contact information above.
What information does the Application obtain and how is it used?
The Application and related services acquire the information you supply when you access or register for the service. For the current waitlist, this is your first name, email address, and any optional message you choose to share. Registration is not mandatory; however, you might not be able to use some features unless you register.
The Service Provider may also use the information you provide to send important information, required notices, and, where permitted by law, marketing communications.
If you submit feedback through the in-app feedback tool, the message you write, the page you were on, and any email address you choose to include are recorded in the Service Provider's analytics (PostHog) and, where enabled, as an issue in its GitHub repository, so the team can review and respond.
Legal basis for processing your personal data
Where the GDPR applies, the Service Provider relies on one or more lawful bases to process your personal data, including:
- Contract performance: processing necessary to provide the Application or fulfil a contract with you.
- Consent: where you have given explicit consent to processing, including for marketing, analytics, or optional features. You may withdraw consent at any time without affecting processing that occurred before withdrawal.
- Legitimate interests: where processing is necessary for the Service Provider's specific legitimate interests, such as maintaining network and information security, preventing fraud and abuse, or improving the Application's core functionality through analytics, provided those interests are not overridden by your data protection rights or fundamental freedoms.
- Legal obligation: to comply with laws or government requests.
Cookies and similar technologies
The Application or its third-party SDKs may use cookies, SDKs, pixels, and similar technologies to support functionality, analytics, and service delivery. Where required by law, the Service Provider will obtain your consent before using non-essential tracking technologies.
Automated decision-making and profiling
If the Application uses automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, you have the right to request human review, express your point of view, and contest the decision. Information about the logic involved and the likely consequences of that processing will be provided where required by law.
What information does the Application collect automatically?
In addition, the Application may collect certain information automatically, including, but not limited to, the type of device you use, your device's unique identifier, the IP address of your device, your operating system, the type of browser you use, and information about the way you use the Application.
Do third parties see and/or have access to information obtained by the Application?
Only aggregated, anonymized data is periodically transmitted to external services to aid the Service Provider in improving the Application and their service. The Service Provider may share your information with third parties in the ways that are described in this privacy statement.
International Data Transfers
The Service Provider or its third-party service providers may transfer personal data outside the European Economic Area (EEA). Where such transfers occur, the Service Provider will use an appropriate transfer mechanism required by GDPR Chapter V, such as adequacy decisions or Standard Contractual Clauses approved by the European Commission. Countries outside the EEA may not provide the same level of data protection as the EEA.
Please note that the Application utilizes third-party services that have their own Privacy Policy about handling data. Below are the links to the Privacy Policy of the third-party service providers used by the Application:
The Service Provider may disclose User Provided and Automatically Collected Information:
- as required by law, such as to comply with a subpoena, or similar legal process;
- when they believe in good faith that disclosure is necessary to protect their rights, protect your safety or the safety of others, investigate fraud, or respond to a government request;
- with their trusted services providers who work on their behalf, do not have an independent use of the information disclosed to them, and have agreed to adhere to the rules set forth in this privacy statement.
Where the GDPR applies, the Service Provider enters into Data Processing Agreements (DPAs) with third-party service providers that process personal data on its behalf, as required by Article 28 of the GDPR.
What are my opt-out rights?
You can stop further collection of information by discontinuing use of the Application. To request deletion of your personal data, withdraw consent, or exercise any of your rights, contact the Service Provider at Brandi.Heffner@gmail.com.
What is the data retention policy and how can you manage your information?
The Service Provider retains personal data based on its necessity for the stated purposes:
- User Provided Data: Retained for the duration of your use of the Application plus 12 months thereafter, unless longer retention is required by law
- Automatically Collected Data: Retained for up to 24 months from collection, unless longer retention is required for legal compliance or security purposes
- Aggregated and Anonymized Data: Retained indefinitely as it no longer identifies you
- Data required for legal compliance: Retained as long as required by applicable law
You have the right to request deletion of your personal data at any time, except where retention is required by law. To do so, please contact Brandi.Heffner@gmail.com.
How does the Application address children's privacy?
The Application is not intended for children under 18 years of age, or where a higher age of digital consent is established under applicable law. The Service Provider does not knowingly solicit data from children or market the Application to them. If the Service Provider discovers that a child has provided personal information, it will immediately delete this from its servers. If you are a parent or guardian and believe your child has provided personal information, please contact Brandi.Heffner@gmail.com.
How is your information kept secure?
The Service Provider is committed to safeguarding the confidentiality of your information, implementing physical, electronic, and procedural safeguards. However, no security system can prevent all potential security breaches.
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, the Service Provider will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by applicable law. Where the breach is likely to result in a high risk to your rights and freedoms, the Service Provider will also notify you without undue delay.
How will you be informed of changes to this Privacy Policy?
The Service Provider may update this Privacy Policy from time to time and will notify you of material changes by posting the updated policy with an effective date. Previous versions are available upon request at Brandi.Heffner@gmail.com. This privacy policy is effective as of 2026-06-19.
What are your GDPR data protection rights?
Under the GDPR, you have the following rights:
- Right of Access: You can request access to your personal data.
- Right to Rectification: You can request correction of inaccurate data.
- Right to Erasure: You can request deletion of your personal data (the "right to be forgotten").
- Right to Restrict Processing: You can request that the Data Controller limits how they use your data.
- Right to Data Portability: You can request a copy of your data in a structured, commonly used, machine-readable format.
- Right to Object: You can object to processing based on legitimate interests. You have an absolute right to object to processing for direct marketing purposes at any time.
- Right to Withdraw Consent: Where processing is based on your consent, you can withdraw it at any time.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority (EDPB members). If you are in the United Kingdom, you may contact the Information Commissioner's Office at ico.org.uk.
What are your California privacy rights (CCPA/CPRA)?
If you are a resident of California, the CCPA and CPRA provide additional rights: the Right to Know, Right to Delete, Right to Correct, Right to Opt-Out of sale/sharing, Right to Limit Use of Sensitive Personal Information, and Right to Non-Discrimination. To exercise any of these rights, contact the Service Provider at Brandi.Heffner@gmail.com.
How do you give your consent?
Where processing is based on consent, you provide that consent by affirmatively opting in to the relevant feature or action. You may withdraw consent at any time without affecting processing carried out before withdrawal.
How can you contact the Data Controller?
If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at Brandi.Heffner@gmail.com.