Operator, scope, and contact
This owner-adopted Privacy Notice explains how The Foundery Group, LLC, a South Carolina limited liability company operating LimitLine, handles personal information. It is scheduled to become effective prospectively at the effective time shown with this exact version and is not represented as reviewed by licensed counsel.
Privacy and account-deletion questions may be sent to support@thefounderygroup.com or by mail to The Foundery Group, LLC, attention Trevor Klenke, 2267 Blakers Blvd, Bluffton, SC 29909. Trevor Klenke is the Business Owner and Privacy Request Owner.
Information the product handles
Depending on the features a user chooses, LimitLine can handle account and profile data; workspace membership and roles; properties, boundaries, waypoints, GPS tracks, routes, plans, notes, journal and harvest records; weather and analysis context; photos and storage references; contacts selected for Field Check-ins; discrete party-location evidence; equipment and custody records; client, trip, booking, workday, and incident records; billing identifiers and subscription state; and limited device, security, diagnostic, and marketing-attribution data.
Precise field locations, private photos, contact details, equipment serial numbers, landowner outreach, client records, and safety evidence can be highly sensitive. LimitLine collects a category only when needed for an enabled feature, a user supplies it, or security and service operation require it.
How information is used
The product uses information to authenticate users, provide role-scoped workspaces, render and analyze maps, save field records, coordinate teams, operate safety tools, manage professional workflows, administer subscriptions, protect the service, diagnose failures, and support exports and deletion preparation.
AI features send selected planning context needed for the requested task to OpenAI, including recent messages and eligible map, property, route, stand, pin, weather, and location context. Current product rules exclude owner contact details, photos, pursuit source text, and precise pursuit-marker coordinates from the hunting assistant, but eligible location and map coordinates can be included. Requests use an API storage-disabled flag and a one-way safety identifier; LimitLine does not represent that this controls every provider security, abuse-prevention, or legal retention obligation.
Location, contacts, and safety sharing
Location access is permission-based. Field Check-ins stores discrete captures rather than promising uninterrupted background tracking. A user chooses a contact, and an intended guardian must accept the relationship before authorized sharing. Stale, offline, disabled, or unavailable location can never be treated as proof of a person’s safety or presence.
Production push, SMS, and outbound safety-email delivery are not launch-approved and must not be relied on or advertised as available. If a channel is later activated, this Notice and the applicable permission or consent disclosure must be updated before use.
Storage, access, and sharing
Database access is scoped by workspace membership, role, feature entitlement, and record privacy rules. Private photo objects use restricted storage and time-limited access links. Some map tiles and analysis context can remain on a user’s device for field use until the user clears offline data, signs out, removes the application, or the device platform evicts it.
When nationwide street-address search is launch-approved and a user submits a complete address, LimitLine sends that address from its server to the U.S. Census Bureau MAF/TIGER Geocoder to request an approximate address-range coordinate. The feature is not a place, business, owner, or parcel search. Provider handling, request logs, retention, and the final disclosure require review before activation.
In supported Beaufort County coverage, while the visible LimitLine CarPlay map—primary or Dashboard—has a recent precise location, LimitLine sends quantized map-tile envelopes for that viewport to the official Beaufort County GIS service to retrieve rendered parcel-boundary and high-zoom Parcel PIN-label images. A Parcel PIN is a parcel identifier, not an owner name. When the map follows the vehicle, the viewport is derived from device location; a driver can also pan the map. The request contains no LimitLine account identifier and requests no feature JSON, owner, situs-address, mailing-address, or contact fields. The county service may still receive each tile envelope, IP address, timestamp, and ordinary network metadata. Only one visible CarPlay scene owns these requests at a time. LimitLine uses an ephemeral, cookie-free session, keeps returned images only in that scene’s bounded memory cache, and clears them when the scene becomes inactive, CarPlay disconnects, or location permission is revoked. Parcel boundaries and PIN labels are informational and do not establish ownership, title, surveyed boundaries, access, or permission.
LimitLine uses Vercel for web hosting and server execution, Supabase for authentication, database, and private storage, OpenAI for user-requested AI processing, and public-agency sources including the U.S. Census Bureau and supported local GIS services for bounded map or address functions. Stripe paths exist for server-side billing identifiers, but this no-fee beta does not offer a public purchase. Regrid, push delivery, camera connectors, Shopify, Printful, advertising SDKs, and other dormant providers must not process launch-user data unless separately enabled, reviewed, and disclosed.
LimitLine does not sell personal information or use it for cross-context behavioral advertising or targeted advertising in this release. That statement must be reassessed before enabling advertising, tracking SDKs, new attribution uses, or a provider that uses data for its own unrelated purposes.
Retention, export, and deletion
Signed-in owners and members can download a structured workspace export, and users can clear offline field data. Export files can contain precise and sensitive information and do not embed every binary photo file.
Signed-in users can record a non-destructive account-deletion intake request after recent-session identity verification. The intake reports active safety-session, billing-action, and last-owner-transfer preflight items, but it never deletes data, closes an account, cancels billing, or schedules deletion. Destructive self-service deletion remains inactive, and neither Apple nor Google submission may claim completed account deletion from this intake alone.
LimitLine keeps information while an account or workspace is active and as reasonably needed to provide a user-selected feature, preserve authorized shared records, secure the service, investigate abuse or incidents, meet financial or legal duties, resolve a request, or honor a bounded legal hold. Local caches remain until cleared, signed out, removed, or evicted by the device. Backup expiry, provider deletion, shared-record anonymization, and destructive account execution remain operational gates; LimitLine will not promise a completion period until those controls are approved and proven.
Privacy choices and rights
Users can control device permissions, workspace sharing, record privacy where offered, offline cache cleanup, and selected safety relationships. Depending on applicable law, a user may request access, correction, deletion, a portable copy, an appeal, or an opt-out from a covered use. Access, correction, portability, appeal, opt-out, and authorized-agent inquiries may be sent to support@thefounderygroup.com. The signed-in privacy-request path currently records only non-destructive account-deletion intake. LimitLine verifies identity in proportion to the request, may request authority for an agent, will explain a denial or appeal path where required, and will not discriminate for exercising an applicable privacy right.
LimitLine is adult-only: every account holder must be at least 18. The gate retains only a boolean threshold confirmation, threshold number, eligibility version, exact document evidence, bounded reason code, application revision, and server time—not a birth date, identity document, or parent information. The checkbox is a contractual eligibility attestation for an adult-directed service, not a claim of COPPA certification or a neutral age-screening method. If LimitLine receives credible information that an account holder is under 18, it may restrict access, minimize further processing, preserve necessary safety, security, and legal-hold evidence, and determine appropriate deletion or other action. It does not seek parental consent or collect guardian data for account eligibility.
Security and changes
LimitLine uses role-scoped access, restricted private storage, short-lived object access links, server-only privileged operations, and data minimization in several workflows. No system can guarantee absolute security. Suspected privacy or security incidents may be reported to support@thefounderygroup.com; The Foundery Group, LLC will preserve evidence and determine legally required notice without characterizing an event before review.
Material changes to this Notice apply prospectively after clear notice and, where appropriate, renewed acceptance. The page identifies the exact version and content hash. Store disclosures and permission prompts must be reconciled whenever a feature, vendor, SDK, jurisdiction, data category, or processing purpose changes.