decode the city.

Decode the City privacy policy

Last updated: 20 September 2026

Who we are

Decode the City is created and operated by Hatch, an independent developer. Asa is responsible for deciding how the personal information described in this notice is used. Decode the City is the web app name, not a separate incorporated company.

Privacy and support email: hello@decodethe.city

This notice covers the Decode the City website at https://decodethe.city and web app at https://play.decodethe.city. Other services you choose to open have their own privacy notices.

Information we use

Accounts. The game creates a Firebase identifier for guest access. When you sign in with Apple or Google, we receive the account information supplied by that provider, including your identifier, email and any supplied profile/display name. We use account identifiers to connect you to purchases, team membership and saved games. We do not receive your Apple or Google password. A guest identifier still identifies an app account; guest play is not data-free.

Game activity. We store player and team names, invitations and membership, organiser/leader roles, selected routes, progress, submitted game actions and answers, hints, penalties, timestamps and results. This keeps players in sync and allows games to resume. Completing a location-specific stage can reveal that a team reached that place, even though our game database does not keep a continuous GPS trail.

Location and navigation. The app accesses location to check proximity to game destinations and support directions. Local arrival checks use device-reported position. Embedded Google Maps processes location, device and network information, service identifiers, interactions and diagnostics. If you open external Google Maps, the destination is sent to Google; Google Maps can also use your location under its permissions and terms. Denying location limits arrival checks and navigation.

Puzzle views. Some puzzles ask you to recreate a historical view using your rear camera. When you choose Check my view, your photograph and a current location reading are sent to our server to verify the scene and approximate position. These are processed for that check without saving the photograph or precise coordinates in our game database. A short-lived verification receipt links the successful check to your team and stage. Your photograph remains temporarily in device memory for the then-and-now reveal and is cleared when you continue or close the game. Other augmented-reality puzzles may use on-screen alternatives. We do not operate a photo or video upload gallery.

Purchases. Stripe handles web payment credentials. We receive and retain order and transaction references, product and route choices, team count, purchase state and account associations to provide the game and handle recovery, refunds and disputes. The game does not ask you to enter card details into its own forms.

Support. If you contact us through Help & support or email, we receive your reply email, message, topic and any game/order reference you provide. In-app support also records your account identifier and ticket status. Email correspondence is handled through Google Workspace; messages sent to our legacy hello@racethecity.com address are also copied to the founder’s Gmail inbox for support. Please do not include passwords, payment card details or unnecessary information about other people.

Service and device information. Firebase provides authentication, database, backend, notifications and security services. These services process technical information such as app/device identifiers, IP addresses, integrity signals, error traces and device/app versions. Race-start notifications use Firebase Cloud Messaging. Our abuse limiter stores hashed request identifiers with expiry metadata. We do not display advertising in the game or use its data for advertising profiles.

On your device. Local storage retains game state, cached data and pending actions to help restore sessions. Signing out, deleting an account and clearing browser data have different effects: clearing browser data alone does not remove server records.

Why we use information

We use account, game and purchase data to provide the service requested by the purchaser and participating players; support data to answer requests; and technical information to protect accounts, prevent duplicate fulfilment and fraud, and diagnose failures. We keep records necessary to meet applicable legal obligations.

For purchasers, we rely on the steps needed to enter into and perform our contract to provide purchased games, account access and purchase support. For invited participants and service operations, we rely on our legitimate interests in providing the requested shared game, maintaining service reliability, answering support requests and preventing misuse, balanced against players' rights. We rely on legal obligations where applicable to accounting records and valid legal requests. Location and notification permissions control access to those device features. When processing is based on consent, you can withdraw that consent without affecting processing that took place before withdrawal. Declining permissions can limit the related feature.

Who can see information

The organiser and your own team can see team membership and player names. Other participating teams can see standings, including team names, progress, timing and player counts. Choose a team/display name you are comfortable sharing in the game. People receiving invitation links or codes can see limited invitation information. A results card you choose to share goes to the destination you select.

As the founder, Asa accesses information needed to provide support and operate and protect the service. Google/Firebase, Google Maps, Apple and Stripe process information relevant to their services. Some act as processors for us; others have their own purposes and privacy terms. We may disclose information where legally required or necessary to address fraud, security incidents or legal claims. We do not sell your personal information.

International processing and security

Our providers operate internationally and may process information in the United States and other countries outside the UK. Hosting a backend in London does not mean all information remains in the UK. Google’s published data-processing terms provide contractual safeguards for applicable transfers, including standard contractual clauses and the UK addendum where applicable. Different Google services, Apple and Stripe have their own terms and privacy notices; not all provider processing is performed solely on our instructions. Contact hello@decodethe.city for information about the safeguards relevant to your data. Provider information is available at https://firebase.google.com/support/privacy, https://policies.google.com/privacy, https://www.apple.com/legal/privacy/ and https://stripe.com/privacy.

The app communicates with its hosted services over encrypted connections. Access controls limit private game, payment and support records. No system can guarantee absolute security.

Retention and deletion

We use the following criteria to decide how long information is needed. Deletion requests can shorten retention, except for information that must remain for a valid legal or security reason. We do not apply one blanket retention period to every record.

Account and game records. We retain information needed to maintain your account, recover purchased games, operate games you have joined and provide shared results. We consider whether a game is unfinished, whether access is still owed to a purchaser, whether other participants still rely on the shared record and whether a support issue is open. Deleting an account does not remove other players’ independent records.

Support. We retain correspondence while resolving the enquiry and for the period needed to handle follow-up questions, complaints or disputes. Account deletion removes associated in-app support tickets; email correspondence must be considered separately when handling a deletion request.

Purchases. We retain the minimum transaction and accounting information needed for purchase recovery, refunds, disputes and applicable tax obligations. We do not retain an entire player profile just because an accounting record is needed. The duration depends on the relevant tax year, record-keeping rules and any unresolved enquiry or claim.

Security and deletion records. We retain limited records for as long as they are needed to prevent deleted credentials being reused, duplicate purchase fulfilment or other abuse, and to demonstrate that a request was handled. A retained account identifier or hash can still be personal information.

Backups and provider records. Removing information from the active game database does not instantly remove every provider backup, log or recovery copy. These copies follow the applicable provider’s deletion and retention arrangements. The same applies to provider-managed diagnostics and navigation information. Deleting your game account does not delete your separate Google, Apple or Stripe account.

You can request deletion from Account → Delete account, or use https://decodethe.city/account-deletion/ in your browser. You may need to sign in again to verify ownership. If you cannot access the account, email hello@decodethe.city or use Help & support.

Our deletion process removes the authentication account, team membership, associated support tickets and account subcollections. It removes the player from team rosters, redacts associated activity text and replaces certain account references with a pseudonymous deleted-account identifier. It cancels unfinished games you organise, affecting everyone in those games. Other players keep their own history and shared results.

Transaction references and minimal deletion/security records remain where needed. Some retained records are pseudonymous or contain an account-linked deletion lock; we do not describe all retained records as irreversibly anonymous. A successful deletion request starts processing and is not a promise of instant completion. We handle requests without undue delay and normally respond within one month. If a lawful extension or an exception applies, we explain the reason and the expected next step. The initial acknowledgement of a queued request is not confirmation that every deletion step has completed. Deleting an account does not itself request a refund.

Your choices and rights

You can change location and notification permissions in your browser or device settings. You can choose guest participation where available. Purchasers must sign in to create and recover purchased games.

Depending on the applicable law, you may have rights to access, correct, erase, restrict or receive a portable copy of your information and object to certain processing. Contact hello@decodethe.city to make a request; we may need to verify your identity. You can complain to the UK Information Commissioner's Office at https://ico.org.uk/make-a-complaint/ or your local supervisory authority.

Younger players

Decode the City includes routes for families, teenagers and adults. An adult should organise and supervise children’s participation and choose a route appropriate for their age. Current route guidance recommends Crown & Politics and Fire & River for ages 10+ with an adult, Royal London for ages 12+ with an adult and The Whitechapel Files for ages 14+. These route recommendations do not guarantee that all content suits every child.

Use a nickname rather than a child’s full name and do not include a child’s contact details in team names or support messages. Guest participation still creates a service identifier and gameplay records. An adult’s presence does not by itself provide any consent that may be required for a child’s data. Parents and guardians can contact hello@decodethe.city with questions or requests relating to a child’s information; we may need to verify their authority. Read the route guidance before choosing it.

Changes

We will update this notice when our practices change and use an appropriate in-app or other notice for material changes. The last-updated date above identifies this version.