Draft placeholder — not legal advice, not yet enforceable This Privacy Policy is a structurally complete draft, not reviewed by privacy counsel. California (CCPA/CPRA) applicability in particular needs confirmation before launch — see IMPLEMENTATION-TODO.md §1 and PRIVACY-DATA-MAP.md, the engineering data inventory this page is drawn from.

Privacy Policy

Last updated: draft, not yet published.

What we collect and why

ThirdSpot collects the information necessary to verify member identity and age, run required background screening, operate event registration and QR check-in, process payments, and maintain platform safety. This includes: legal name, date of birth, city, phone, and email; a profile photo; government-ID verification results (the ID image itself is held by our identity-verification provider, never by ThirdSpot); background-screening results; emergency-contact information; payment references (never raw card numbers); event registrations and attendance; and, for businesses, verification, insurance, and licensing documentation.

Categories of Personal Information Collected (California)

Under the CCPA/CPRA, the categories above map to: identifiers, protected classification characteristics (age), commercial information (payments), biometric information (identity-verification liveness/face-match signals, held by our provider), internet/ network activity, geolocation (city-level), and inferences. A detailed category-by-category table mirroring PRIVACY-DATA-MAP.md lands here before launch, pending counsel review.

How we use it

  • To verify you are 21+ and who you say you are, once, at enrollment.
  • To run required background screening and annual rescreening.
  • To operate registration, waitlists, QR check-in, and attendance tracking.
  • To process membership and business payments through Stripe.
  • To provide emergency-contact information to authorized event-day staff only, on request, with a logged reason.
  • To maintain trust-and-safety records (blocks, reports, audit logs).

Who we share it with

We share data only with the vendor processors necessary to run the service: our cloud/database provider, our authentication provider, Stripe (payments), an identity-verification provider, a background-screening provider, a business (KYB) verification provider, a veteran/first-responder verification provider, a transactional email provider, a maps provider, and a content-moderation provider. We do not sell personal information.

Retention and deletion

Retention periods vary by data type — generally the life of your account plus a period required for audit, fraud, or legal-recordkeeping purposes (background-screening and financial records in particular are retained per FCRA and financial-recordkeeping requirements even after account closure). Closing your account soft-deletes your profile and scrubs non-legally-required personal information; records subject to legal retention or active safety investigations are not deletable on request during that retention window. Full detail is in PRIVACY-DATA-MAP.md.

Your rights

Depending on your location, you may have rights to access, correct, delete, or receive a copy of your personal information, and to opt out of certain processing. Requests can be submitted through your account settings once that self-service flow exists, or by contacting us directly in the meantime. California residents: see the Background-Screening Disclosure for FCRA/ICRAA-specific consumer-report rights, which operate alongside these general privacy rights.

Contact

Questions about this policy: privacy@thirdspot.org (placeholder).