Privacy Policy
Version 1.0 · Last updated 2026-04-06
1. Information We Collect
We collect information you provide to us and information generated by your use of the platform.
Account & Profile Data
- Name, email address, and profile photo
- Bio, skills, service tags, availability, and neighborhood (self-reported — not GPS)
- Business name, professional credentials, licenses (optional)
- External links you provide: Instagram, LinkedIn, TikTok, custom URLs (not verified)
Platform Activity
- Listing data: service descriptions, tags, estimated hours, media
- Trade data: swap agreements, trade status, hours committed, completion records
- Messages and media shared in conversations
- Social data: vouches given and received, vouch notes, network memberships
- Review data: star ratings, written feedback, reputation flags
Technical Data
- IP address, browser user agent, device type
- Session activity and feature usage (aggregate analytics)
- Terms acceptance records: IP address and user agent at acceptance time
2. How We Use Your Data
We use the information we collect to:
- Operate the marketplace: match users, display listings, facilitate trades, and display profiles.
- Send notifications: trade proposals, messages, review prompts, and platform updates via in-app notifications and email.
- Safety & moderation: detect abuse, enforce our Terms of Service, and respond to user flags and reports.
- Analytics: understand aggregate, non-identifying usage patterns to improve the product.
- Legal compliance: respond to lawful requests from government authorities and comply with applicable laws.
We do not use your data for advertising, profiling for sale, or any purpose beyond operating and improving the BarterBoo platform.
3. Third-Party Data Processors
We use a small number of trusted service providers to operate BarterBoo. Each receives only the data necessary for their function.
| Provider | Purpose | Data shared |
|---|---|---|
| Database & Auth Provider | Database, auth, file storage, realtime | All user data |
| Hosting Provider | Hosting, edge functions, CDN | Request logs, serverless execution metadata |
| Email Provider | Transactional email | Email addresses and message content for notifications |
We do not sell your data. We do not use ad networks. We do not share data with data brokers.
4. Data Retention
- Active accounts: data is retained for the life of the account.
- Deleted accounts: a 30-day soft-delete grace period, then hard purge of profile data, listings, and messages.
- Reviews: retained with anonymized attribution after account deletion to preserve platform integrity.
- Trade history: retained in anonymized form to prevent re-disputes.
- Server logs: 90 days.
- Legal hold: data may be preserved longer if required by law or an active dispute.
5. Your Rights (CCPA-Aligned)
Under California law, you have the following rights regarding your personal data:
- Access: Request a copy of all data we hold about you.
- Correction: Update your profile information at any time from your account settings.
- Deletion: Request account deletion and data purge (subject to the retention policy above).
- Portability: Export your data in JSON format from your account settings.
- Opt-out: Control email notification preferences from your settings. There is no targeted advertising to opt out of.
- Non-discrimination: We will not discriminate against you for exercising these rights.
To exercise your rights, contact us at privacy@barter.exchange.
7. Security Measures
We take reasonable technical and organizational measures to protect your data:
- All data is encrypted in transit using TLS/HTTPS.
- Data is encrypted at rest via industry-standard database encryption.
- Row Level Security (RLS) at the database layer ensures users can only access their own data — even a compromised API key cannot expose other users' data.
- Auth tokens are httpOnly, secure, and SameSite.
- No plaintext storage of sensitive data.
No system is 100% secure. If you discover a security vulnerability, please report it responsibly to legal@barter.exchange.
8. Children's Privacy
BarterBoo is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If you believe a minor has created an account, please contact us and we will remove the account promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will notify you and require you to review and accept the updated policy before continuing to use BarterBoo — the same versioned acceptance mechanism as our Terms of Service.
Material changes will be clearly flagged with a summary of what changed.
10. Contact
Privacy questions or requests: privacy@barter.exchange
General legal inquiries: legal@barter.exchange