Privacy Policy

Last updated: [insert date before publishing]

This is a template, not legal advice.

This page was drafted to accurately describe what Give and Take actually does with your data and how the service actually works — not generic filler — but it has not been reviewed by a lawyer. Treat it as a good-faith starting point, not a substitute for counsel, especially before operating at scale or serving users in jurisdictions with specific legal requirements (e.g. GDPR, CCPA).

1. What we collect

Account information:your name, email address, a hashed password (we never store your actual password — see Section 5), and optionally a bio, profile photo, and phone number. Phone numbers are stored if you provide one, but nothing on the platform verifies or uses them today — that's a real, disclosed gap, not a hidden feature.

Listing information: what you post — title, description, category, condition, photos, an estimated value, and a location. The location is stored as real coordinates (needed to power nearby search and distance sorting) but is never shown exactly to anyone: only your neighbourhood and city are ever shown publicly, and the map shows an approximate pin offset by roughly 300 metres from the real location, not the real point.

Exchange information: requests, chat messages, pickup scheduling details (including the exact meeting point you choose to share), and ratings — all visible only to the two people actually involved in that exchange, never publicly.

Verification documents: if you apply for organisation verification, the business documents you upload. These are stored separately from public listing photos and are only ever accessible to you and our admin team.

Technical information: your IP address (used to apply rate limits and protect the service from abuse — see Section 3) and a small number of cookies needed to keep you signed in (see Section 4).

2. What's public vs. private

Publicly visible to anyone: display name, profile photo, approximate location, ratings, and community stats (items shared, people helped, and similar).

Never shown to other users: your exact address, phone number, email address, and exact GPS coordinates.

3. How we use your information

  • To operate the core features — listings, nearby search, requests, chat, pickup scheduling, and ratings
  • To power community trust features — verification badges, reliability signals
  • For safety and moderation — reviewing reports, resolving disputes, enforcing our Terms
  • To send account and activity emails — verification, pickup reminders, notifications you'd otherwise have no way to know about
  • To apply rate limits and protect the service against abuse (using your IP address, not your account identity, for this specific purpose)

We don't use your data for advertising, and we don't sell it.

4. Cookies

Give and Take uses a small number of strictly necessary cookies — one to keep you signed in, and one for CSRF protection (a security measure, not tracking). We don't use third-party advertising or analytics cookies.

5. Data security

Passwords are hashed before storage — we never store or can recover your actual password. The site is served over HTTPS in production. Access to organisation-verification documents is restricted to the applicant and admins, served through a route that checks permission on every request, not by relying on a hard-to-guess URL. We haven't implemented additional application-level encryption of data at rest beyond password hashing — being direct about that rather than implying a stronger guarantee than what's actually built.

6. Who we share information with

With other users — but only what Section 2 says is public, plus whatever you choose to share directly (like an exact meeting point once a pickup is arranged). With service providers strictly to operate the service: an email delivery provider (to send you account and notification emails) and cloud storage (for encrypted backups of the database and uploaded files). These providers only ever receive what they need to do that specific job. We don't share data with data brokers or advertisers. We may disclose information if legally required to.

7. Data retention

Reports and appeals are kept for 180 days after resolution, then permanently deleted. Backups are retained for a limited window (14 days locally, longer offsite) purely for disaster recovery, not as a way to keep data around after you'd otherwise expect it gone. Your account data is retained while your account is active.

8. Your choices

You can edit your name, bio, and profile photo, and change your password, from your account settings at any time.

Honest gap:there is currently no self-service way to delete your account or export your data from within the app. If you want either, contact [insert a real contact address] and we'll handle it manually. This is a real limitation, not fine print — worth fixing before this policy claims a right the product doesn't yet support.

9. Children's privacy

Give and Take isn't directed at children, and our Terms of Service require you to be at least 18 (or the age of majority where you live). We don't knowingly collect information from children.

10. Where your data is hosted

Give and Take is self-hosted — your data lives on infrastructure the operator controls directly, not a large third-party cloud platform. [Insert the actual hosting region/jurisdiction before publishing.]

11. Changes to this policy

We may update this policy as the service changes. Continuing to use Give and Take after an update means you accept the revised policy.

12. Contact

Questions about this policy, or a data request: [insert a real contact address].