Privacy Policy
Overview
This Privacy Policy describes how OpenStand ("we," "us," or "our") collects, uses, discloses, and safeguards personal information when you use our website, mobile web application, and related services (collectively, the "Services").
We process personal information in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).
1. Information We Collect
We collect information that identifies, relates to, or could reasonably be linked with you or your device.
A. Information You Provide
- Identifiers: Name, email address, and account credentials when you create an account.
- Vendor Profile Data: Stand name, bio, typical hours, payment handle, and product tags submitted by vendor users.
- Session Data: Session titles, descriptions, tags, and location coordinates you enter when going live as a vendor.
- Support Communications: Any messages sent to us through contact forms or email.
B. Information Collected Automatically
- Precise Geolocation: With your permission, we collect your device's GPS coordinates to show nearby vendors and to place your stand on the map when you go live. You may deny or revoke location access at any time through your browser or device settings.
- Device and Network Data: IP address, browser type, operating system, and general location derived from your IP address (used as a fallback when GPS is unavailable).
- Usage Data: Pages visited, features used, session timing, and interaction patterns within the Services.
- Cookies: We use session cookies required for authentication. We do not use third-party advertising or behavioral tracking cookies.
2. How We Use Your Information
We use collected data for the following purposes:
- Service Delivery: To operate the map, display nearby vendor pins, manage your account, and enable vendor sessions.
- Location Services: To calculate distances, surface relevant vendors, and position your stand on the map.
- Authentication and Security: To verify your identity, protect your account, and detect or prevent fraud and abuse.
- Communications: To send security alerts, service updates, and respond to support requests. We do not send marketing email without your explicit consent.
- Product Improvement: To analyze usage patterns and improve platform performance and features.
- Legal Compliance: To satisfy applicable statutory, regulatory, or legal obligations.
3. Sharing and Disclosure
We do not sell your personal information. We may share it only under the following circumstances:
- Public Map Display: When a vendor goes live, their stand name, location, session description, and tags are visible to all users of the map. Vendors control this visibility and can end their session at any time.
- Service Providers: We share data with trusted infrastructure vendors — including our authentication provider (Clerk), database provider (Supabase), and hosting provider (Vercel) — who are contractually bound to protect your data and may not use it for their own purposes.
- Legal Requirements: When required by law, court order, or regulatory authority, or to protect the rights, safety, or property of OpenStand or others.
- Business Transfers: In connection with a merger, acquisition, or sale of company assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.
4. International Data Transfers
OpenStand is operated from the United States. If you access the Services from outside the U.S., your information may be transferred to and processed in the U.S., where data protection laws may differ from those in your country. Where required, we implement appropriate safeguards — such as Standard Contractual Clauses approved by the European Commission — to ensure an adequate level of protection.
5. Data Retention
We retain your personal information only for as long as necessary to provide the Services and fulfill the purposes described in this Policy, or as required by law. Vendor location data from ended or expired sessions is retained in anonymized or aggregated form for service analytics. You may request deletion of your account and associated data at any time.
6. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
A. EEA and UK Residents (GDPR)
- Access and Portability: Request a copy of your personal data in a structured, machine-readable format.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data under applicable conditions.
- Restriction and Objection: Object to or restrict processing, including for direct marketing.
- Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
B. California Residents (CCPA/CPRA)
- Right to Know: Request disclosure of the categories and specific pieces of personal information collected about you.
- Right to Delete: Request deletion of personal information we have collected from you.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out: Opt out of the sale or sharing of your personal information. We do not sell or share personal information for cross-context behavioral advertising.
- Non-Discrimination: We will not discriminate against you for exercising any of your rights under the CCPA/CPRA.
To exercise any of these rights, please contact us at app@openstand.io. We will respond within the timeframe required by applicable law (typically 30–45 days).
7. Security
We implement technical, administrative, and physical safeguards designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These include encrypted data transmission (TLS), access controls, and regular security reviews. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
8. Children's Privacy
The Services are not directed to children under the age of 13, and we do not knowingly collect personal information from children. If we become aware that a child under 13 has provided us with personal information, we will delete it promptly. If you believe a child has submitted information to us, please contact us at app@openstand.io.
9. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page. For material changes, we will provide more prominent notice, such as an in-app notification or email. Your continued use of the Services after changes are posted constitutes your acceptance of the updated Policy.
10. Contact
For questions, concerns, or to exercise your privacy rights, please reach us at:
OpenStand
app@openstand.io
Sarasota, Florida, USA