Privacy Policy
Last updated: April 19, 2026
1. Information We Collect
Account Information: When you create an account, we collect your name, email address, and password (stored securely).
Address Information: When you join a community, we collect and verify your home address using AWS Location Services. Your address is used to confirm you belong to the community and may be shared with other members during pickup coordination.
Listing Information: When you post a listing, we collect the details you provide (title, description, photos, price, condition, pickup method, and notes).
Photos: Photos you upload are stored on Amazon S3 (AWS cloud storage) and are visible to members of your community.
Messages: We store messages you send to other members to facilitate transactions. Messages are visible to the sender, recipient, and may be accessed by platform administrators and community admins for safety, security, and moderation purposes (such as investigating reported harassment or prohibited content).
Community Membership: We record your membership status, role (member or admin), and activity within communities you join.
Usage Data: We automatically collect information about how you use the platform, including pages visited, features used, and timestamps. This helps us improve the platform.
Cookies: We use cookies and similar technologies to authenticate you, remember your preferences, and analyze platform usage. See our Cookie Policy below for details.
2. How We Use Your Information
We use your information to:
- Operate and provide the platform services
- Authenticate you and maintain your account
- Display your listings to community members
- Facilitate requests and transactions between neighbors
- Verify your address and community membership
- Send transactional emails (OTP codes, request notifications, approval status, password changes)
- Moderate content and enforce our Terms of Service
- Investigate reported violations, harassment, or prohibited content
- Improve platform features and user experience
- Comply with legal obligations
We do not sell your personal information to third parties.
3. Who Can See Your Information
Community Members: Your name, listings, and profile information are visible to verified members of your community. Your full address may be shared with buyers during pickup coordination.
Community Admins: Admins can see your email address, profile information, membership status, and may access reported messages for moderation purposes.
Platform Administrators: BuyShareLocal staff may access your information for platform operation, security, moderation, and support purposes.
Public Visibility: We do not make any listings or member information publicly accessible outside of your community. Your information is private to your community only.
4. Third-Party Services
We use the following third-party services to operate the platform:
- Amazon Web Services (AWS): Data storage (DynamoDB), photo storage (S3), email delivery (SES), and address verification (Location Services)
- Authentication Services: NextAuth.js for secure login and session management
These services may have access to your data as necessary to provide their services. They are contractually obligated to protect your data and use it only for the purposes we specify.
We do not share your data with third parties for their own marketing purposes.
5. Data Storage and Security
Your data is stored securely on AWS infrastructure in the United States:
- Account and community data: Amazon DynamoDB (encrypted at rest)
- Listing photos: Amazon S3 (encrypted at rest)
- Messages: Amazon DynamoDB (encrypted at rest)
We use industry-standard security practices to protect your data, including:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest for stored data
- Secure password hashing
- Regular security updates and monitoring
- Access controls and authentication
However, no method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide services. Specifically:
- Account data: Retained until you delete your account
- Listings: Retained until you delete them or your account
- Messages: Retained until you delete your account
- Photos: Retained until you delete the listing or your account
- Moderation records: Retained for 2 years for safety and legal compliance
After account deletion, we may retain certain information for legal compliance, fraud prevention, and dispute resolution (typically 90 days, or longer if required by law).
7. Emails and Communications
We send transactional emails related to your account activity via Amazon SES:
- OTP verification codes for registration and password reset
- Membership approval or rejection notifications
- Request notifications (when someone requests your item)
- Request status updates (accepted, declined, cancelled)
- Password change confirmation emails
- Community admin notifications
We do not send marketing emails without your explicit consent. Transactional emails are necessary for platform operation and cannot be opted out of while maintaining an active account.
8. Cookies and Tracking
We use cookies and similar technologies for:
- Authentication: To keep you logged in (session cookies)
- Preferences: To remember your settings
- Security: To prevent fraud and protect your account
- Analytics: To understand how the platform is used (aggregated, non-personal data)
We also use browser sessionStorage to cache community data temporarily (5-minute TTL) to improve performance.
You can control cookies through your browser settings, but disabling cookies may affect platform functionality.
9. Your Rights and Choices
You have the following rights regarding your personal information:
- Access: Request a copy of your personal data
- Correction: Update your profile information at any time
- Deletion: Request deletion of your account and associated data
- Portability: Request your data in a machine-readable format
- Objection: Object to certain data processing activities
To exercise these rights, contact us at privacy@buysharelocal.com. We will respond within 30 days.
Account Deletion: You may delete your account at any time. Upon deletion, your listings, membership records, messages, and personal information will be removed from our systems (subject to legal retention requirements).
10. Data Breach Notification
In the event of a data breach that affects your personal information, we will:
- Notify you by email within 72 hours of discovering the breach
- Describe what information was affected
- Explain what steps we are taking to address the breach
- Provide recommendations for protecting your information
- Notify relevant regulatory authorities as required by law
11. Children's Privacy
BuyShareLocal is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If we discover that we have collected information from a child under 18, we will delete it immediately.
If you believe we have collected information from a child under 18, please contact us at privacy@buysharelocal.com.
12. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information we collect, use, and share
- Right to delete your personal information
- Right to opt-out of the sale of your personal information (we do not sell your information)
- Right to non-discrimination for exercising your privacy rights
To exercise these rights, contact us at privacy@buysharelocal.com.
13. International Users
BuyShareLocal is currently available only to users in the United States. Your data is stored on servers located in the United States and is subject to U.S. laws.
If we expand internationally in the future, we will update this Privacy Policy to address international data transfers and compliance with laws such as GDPR.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by email or through the platform.
The "Last updated" date at the top of this page indicates when this Privacy Policy was last revised. Continued use of the platform after changes constitutes acceptance of the updated Privacy Policy.
15. Contact Us
If you have questions about this Privacy Policy or how we handle your data, please contact us at:
- Email: privacy@buysharelocal.com
- Support: support@buysharelocal.com