DRAFT — final legal text pending attorney review. Content adapted from the canonical repo draft (`store/legal/privacy-policy.md`). Do not publish until reviewed.
Privacy Policy
Effective date: {{EFFECTIVE_DATE}} · Operator: {{ENTITY_NAME}} · Contact: support@yardup.xyz
This policy describes what YardUp collects, why, how long we keep it, and how you control it. It is written against how the service actually works.
1. What we collect
- Account data. Email address, a display name, and a password — stored only as a salted hash, never in plaintext. Email is the sole account identifier.
- Listing content. Sale title, description, categories, dates and hours, highlights, photos/videos you upload, and the sale’s location.
- Location — two distinct things:
Sale location (from sellers): you place a pin when creating a listing. While a sale is scheduled, the public sees only an approximate pin (neighborhood precision with deliberate jitter). The exact address is visible only while the sale is live, then hidden again. Publishing requires you to confirm the pin — that confirmation is the only path to exact coordinates.
Shopper location (transient): for “nearby”, the app asks for device location or a ZIP/city you type. Your precise device coordinates are used to compute nearby results and are not stored — no precise coordinate is recorded in analytics, and discovery queries do not persist a GPS point. - Purchase records. What was purchased (boost, ad-free), its state, and the store receipt reference. We never receive your payment-card number — purchases are processed by Apple/Google.
- Support requests. Support you send us and its handling status, visible to you in-app.
- Aggregate usage counters. Event name, coarse location (ZIP, or coordinates truncated server-side to roughly 3 decimals), and context like discovery radius. These records contain no user identifier — not hashed, not pseudonymous, absent.
- Push notification tokens. A device token so we can send reminders you opted into. You can unregister any or all devices any time.
2. What we do NOT collect or do
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising. No third-party advertising or tracking SDKs in the app receive your identity or precise location.
- We do not build advertising profiles from your in-app browsing.
- We do not require your location — a denied permission still leaves the full app usable by typing a ZIP or city.
- We do not post anything anywhere on your behalf.
- Push payloads contain the sale title and sale id only — no addresses, never your location.
3. What we use it for
| Data | Purpose | Legal basis (EEU/UK users) |
|---|---|---|
| Account | Provide the account, security, service email | Contract |
| Listing + media | Show listings, previews, share cards | Contract |
| Sale location | Approximate pins, exact reveal while live | Contract; the seller's choice |
| Shopper location (transient) | Nearby search, distance | Consent (OS permission) |
| Purchase records | Deliver entitlements, refunds, accounting | Contract; legal obligation |
| Usage counters | Understand aggregate feature use | Legitimate interests (aggregated, no identifiers) |
| Support | Answer you | Contract |
| Device tokens | Reminders you opted into | Consent (opt-out anytime) |
DRAFT flag: the legal-basis column is a draft mapping under GDPR-style regimes and must be confirmed for every jurisdiction of distribution.
4. Sharing
We share data only with:
- Infrastructure providers that operate the service for us (cloud hosting, database, object storage, delivery network, app-store billing, and the geocoding service that turns the address you typed into map coordinates). They process data on our instructions to provide the service. DRAFT flag: vendor names must be made concrete before publication.
- Legal process where required by law.
- No one else. We do not sell data; we do not share it for others’ advertising.
5. Retention — how long we keep things
| Data | Retention |
|---|---|
| Media (photos/videos) | Deleted 30 days after the sale is archived; originals stay private until then |
| Account deletion | In-app deletion erases profile, contact details, media, and sales immediately; the account row is anonymized (email/name/password unrecoverable). Media objects are purged from storage, not just the rows |
| Purchases / entitlements / audit / moderation events | Retained as operational and financial records; they keep the user id but no longer resolve to a person after deletion |
| Sale data (title, categories, dates) | Anonymized up to 12 months for metrics, then purged |
| Exact address of a sale | Hidden when scheduled (approximate only), visible while live, hidden again after it ends |
| Usage counters | Retained as aggregate counters |
6. Your rights and choices
- Delete your account and data: in-app, self-serve, immediate — Profile → Settings → Delete Account. You never need to email us. Google Play also requires a web page where deletion can be requested without the app: yardup.xyz/account-deletion
- Unregister devices / stop push: in-app, any time.
- Withdraw location consent: deny the OS permission; the app remains fully usable with ZIP/city search.
- Access/export: the in-app profile and support history show what we hold for you; a formal export request can be sent to support@yardup.xyz.
- Object/complain: contact support@yardup.xyz; if you are in the EEU/UK you may also complain to your local supervisory authority.
7. Children
YardUp is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact support@yardup.xyz and we will delete it.
8. Security
- Passwords are stored as salted scrypt hashes.
- All traffic to the service is TLS-encrypted; the app asserts HTTP-Strict-Transport-Security, and a deployment that has not declared TLS termination refuses to boot.
- The database is encrypted at rest and never publicly reachable; backups are point-in-time recoverable.
- Every database role is least-privilege: the application role cannot bypass row-level security, cannot create tables, and cannot read the audit tables.
- Secrets are generated at deploy time, stored only in the platform’s secret manager, and bound to a manifest the app verifies at boot — a secret with no manifest entry, or bound to another environment, refuses to start the service.
- Media originals are private: full-size files require a signed URL; the publicly cached form is the thumbnail.
9. Changes to this policy
We will post any changes here with a new effective date, and will give in-app notice for material changes.
10. Contact
{{ENTITY_NAME}} · {{ENTITY_ADDRESS}} · support@yardup.xyz
DRAFT — final legal text pending attorney review. Placeholders {{EFFECTIVE_DATE}}, {{ENTITY_NAME}}, and {{ENTITY_ADDRESS}} are intentional and must be filled before publication.