← Back to home
⚠ DRAFT — NOT YET IN FORCE
This document has not been reviewed by a lawyer and still contains unfilled values, shown highlighted. It must not be relied on, linked from the app stores, or presented to users for acceptance until it is finalised. Delete this banner when it is ready.
Privacy Policy
How we collect, use, and protect your personal information. Schedule A applies in the United States, Schedule B in Canada.
Effective date: [EFFECTIVE DATE] Version: 2.0 (Draft for legal review) — United States and Canada
1. Introduction
This Privacy Policy explains how [COMPANY LEGAL NAME] (“BubblesNetworks,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you use the BubblesNetworks mobile application (iOS and Android), the BubblesNetworks progressive web application, and related services (collectively, the “Service”).
Where you live changes part of this Policy. The numbered Sections below apply to everyone. They are followed by two Schedules — Schedule A — United States and Schedule B — Canada — which set out the privacy rights available to you and how to exercise them. If a Schedule applies to you, it forms part of this Policy and prevails over the numbered Sections to the extent of any inconsistency. The Service is currently offered for Buildings in the United States and Canada.
This Policy forms part of our End User License Agreement (the “EULA”). Capitalized terms not defined here have the meanings given in the EULA. By using the Service, you agree to the practices described in this Policy.
- Account information: email address, password (stored in hashed form by our authentication provider), phone number, username, and optional profile photo.
- Residency information: the Building you join, your unit number, whether you are an owner or tenant, and your residency display ID (a short identifier shown to other Residents in place of your personal details). You supply all of this yourself, whether you joined through a property manager’s invitation or building code or found your Building on your own; we do not independently verify it.
- Content you submit: posts, building alerts, alert confirmations, poll questions and votes, marketplace listings and promotions (including price and contact information you choose to include), management notices, private messages, comments, photos, images, and documents.
- Communications with us: support requests, feedback, and reports of content or conduct.
- Sign-in via Google or Apple: if you sign in with Google or Apple, we receive basic profile information from that provider (such as your name and email address). Apple may provide a private relay email address if you choose to hide your email.
- Device and technical data: device type, operating system, app version and variant, browser type (for the web app), language preference, and time zone.
- Push notification tokens: device tokens for Apple/Google push delivery on mobile, and web push subscription details on the web app.
- Usage and analytics data: in-app events (such as sign-in, sign-up, and feature usage), collected through our analytics provider and associated with your account identifier.
- Crash and diagnostic data: error reports and diagnostic information, collected through our crash-reporting provider, which may include device information and the state of the app at the time of an error.
- Location: only if you grant the location permission. We use your device’s location for two purposes. (a) Finding what is near you — nearby Buildings, businesses, and services; approximate location is sufficient for this. (b) Confirming residency, where we offer it — we may give you the option to use your device’s location to confirm that you are at your Building at the moment you ask to verify your residency. This is a one-off check that you start, it is never run in the background, we record the result of the check rather than a location history, and you may decline it and continue using the Service. We will tell you what the check involves before you use it. We do not track your location in the background for any purpose, and you can withdraw the permission at any time in your device or browser settings.
- Local storage: the web app uses browser storage (localStorage and equivalents) and a service worker cache to keep you signed in, remember preferences, and enable offline behavior. The mobile apps use equivalent on-device storage, with sensitive credentials stored in the device’s secure storage. We do not use third-party advertising cookies.
- Verification and roles: where a Building has an active Building Manager, they may verify (or decline to verify) your residency and may assign or revoke building roles. Many Buildings have no active Building Manager, in which case your residency is never reviewed and remains unverified. Residency is self-declared in all cases — we do not confirm that you, or any other Resident, live where you say you do.
- Content mentioning you: other Users may post content or send messages that reference you. If you believe content about you violates our community standards, report it in the app or contact us.
2.4 What we do not collect
We do not collect government identifiers, payment card information (the Service does not process payments between Users), biometric data, or precise background location. We do not use advertising trackers and we do not serve third-party ads.
We use personal information to:
- create and manage your account, authenticate you, and keep you signed in;
- connect you to your Building’s community and, for certain Marketplace features, to nearby Buildings within the applicable radius;
- deliver the Service’s features: posts, alerts, polls, notices, messaging, and the Marketplace;
- send push notifications and emails you have enabled (such as new messages, alerts, notices, and verification codes);
- moderate content and enforce our community standards, including automated moderation and classification;
- translate content into other Users’ preferred languages;
- provide AI-assisted features, such as the AI listing assistant;
- understand how the Service is used, measure and improve features, and fix bugs and crashes;
- secure the Service, prevent fraud and abuse, and enforce the EULA;
- comply with legal obligations and respond to lawful requests.
We do not use your personal information for third-party advertising. We do not sell personal information, and we do not “share” personal information for cross-context behavioral advertising as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA).
4. AI Processing
Certain features process your content automatically using artificial intelligence, including through third-party AI providers:
- Content moderation: content you submit (posts, alerts, listings, messages where applicable) is screened automatically before or after posting.
- Classification: content may be automatically categorized (for example, routing a for-sale post to the Marketplace).
- Translation: content may be machine-translated so other Residents can read it in their preferred language.
- AI listing assistant: if you use the assistant, the information you type into the conversation is processed to help generate your listing.
Content sent to our AI providers is used to provide these features. We do not permit our AI providers to use your content to train their generally available models, per our provider agreements. [CONFIRM CURRENT PROVIDER DATA-USE TERMS BEFORE PUBLICATION.]
The Service is a community product, and some of your information is visible to others by design:
- Within your Building: your username, residency display ID, profile photo, and the content you post (posts, alerts, poll participation counts, listings, and comments) are visible to other Residents of your Building. Your unit number is not visible to other Residents. Access to it is restricted at the database level: other Residents cannot retrieve it, and it is available only to you, to staff of a property management company that manages your Building (through their management portal), and to our platform administrators.
- Nearby Buildings: Marketplace listings you scope to the wider community are visible to Residents of other Buildings within the applicable radius.
- Private messages: visible to the participants of the conversation.
- Property management staff: where your Building is managed by a property management company using our management portal, its authorised staff can see residency information for that Building (name, username, unit number, owner/tenant status, verification status) for legitimate building-management purposes. Building Managers who only use the resident app do not have access to other Residents’ unit numbers.
Think before you post: anything you share in community features can be seen, copied, or shared further by other Residents.
We share personal information only as described below. We do not sell personal information, and we do not share it with advertisers.
- Service providers (processors): we use third-party providers to operate the Service, including cloud database, authentication, and file-storage services; web hosting and content delivery; push-notification delivery (Apple, Google/Firebase, and web push services); transactional email delivery; product analytics; crash reporting; and AI processing (moderation, classification, translation, generation). These providers process personal information on our instructions under contractual protections.
- Building organizations: limited residency information is visible to your Building’s managers as described in Section 5. Building Managers and building organizations are independent of us and are responsible for their own handling of information they access.
- Legal requirements: we may disclose information where required by law, subpoena, court order, or other lawful process, or where reasonably necessary to protect the rights, property, or safety of Users, the public, or the Service.
- Business transactions: if we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this Policy’s protections.
- With your consent: in any other case, we will ask you first.
Categories disclosed (CCPA)
In the preceding 12 months, we have disclosed the following categories of personal information to service providers for business purposes: identifiers (email, phone, username, device identifiers); user content (audio/visual/written); approximate geolocation (where permitted); internet or electronic network activity (usage events, diagnostics); and inferences limited to feature operation (for example, content classifications). We have not sold or shared (for cross-context behavioral advertising) any category of personal information.
7. Data Retention
- Account data: retained while your account is active.
- Content: when you delete content, it is deactivated (a “soft delete”) — no longer visible to Users — and subsequently removed from active systems after [RETENTION PERIOD]. Messages you sent remain visible to the other participant, consistent with how messaging works.
- Account deletion: when you delete your account (My Account → Delete Account), your authentication record and profile image are deleted and your profile is removed. Community content you authored is deactivated or disassociated from your identity. Some records may be retained where required or permitted by law (for example, for security, fraud prevention, dispute resolution, or backup integrity), and residual copies may persist in encrypted backups for up to [RETENTION PERIOD] before being overwritten.
- Analytics and crash data: retained per our providers’ configured retention periods [SPECIFY].
- Seller attestations: if you accepted a seller addendum (for example, for food or care listings), we retain the record of your acceptance (addendum version and date) after account deletion, as a record required for legal purposes, including dispute resolution. [COUNSEL TO CONFIRM: retention of attestation records post-deletion, and the retention period.]
We retain each category of personal information no longer than reasonably necessary for the purposes described in this Policy.
8. Security
We use reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit, access controls enforced at the database layer (row-level security), credential storage in device secure storage on mobile, and least-privilege access for our systems. Private messages are stored on our infrastructure and are not end-to-end encrypted. No system is perfectly secure; if a breach affecting your personal information occurs, we will notify you and regulators as required by applicable state breach-notification laws.
9. Your Choices
- Push notifications: control them in the app’s notification settings and in your device or browser settings.
- Location: the permission is optional; you can revoke it at any time in device/browser settings.
- Profile: you can edit your profile information (username, photo, phone) in the app.
- Marketing: we send transactional messages (codes, alerts you enabled); we do not send third-party marketing. Any promotional messages from us will include an opt-out.
- Account deletion: available in-app at any time (My Account → Delete Account). You may also request deletion at info@bubblesnetworks.com / https://bubblesnetworks.com/account-deletion.html.
10. Your Privacy Rights
The rights you have over your personal information, and how to exercise them, depend on where you live. See Schedule A if you are in the United States, or Schedule B if you are in Canada. Whichever applies, you can always reach us at info@bubblesnetworks.com, and we do not sell your personal information.
11. Children
The Service is not intended for anyone under 16, and we do not knowingly collect personal information from children under 13 (or under 16 without appropriate consent). If you believe a child under 16 has created an account, contact us at info@bubblesnetworks.com and we will delete the account and associated personal information.
We use service providers for hosting, databases, push notifications, analytics, crash reporting, and AI processing. Your information may be stored and processed outside the country you live in, including in the United States, and may be subject to the laws of those jurisdictions, including lawful access requests by their authorities. We rely on contractual protections with our providers. See your Schedule for detail specific to your country. Primary hosting regions: [CONFIRM AND LIST PRIMARY HOSTING REGIONS — check the region of each Supabase project in the Supabase dashboard].
13. Third-Party Links and Services
Content in the Service may include links to third-party websites or services (for example, in Marketplace listings). This Policy does not apply to third parties, and we are not responsible for their privacy practices. Sign-in through Google or Apple is subject to those providers’ privacy policies.
14. Changes to this Policy
We may update this Policy from time to time. For material changes, we will provide reasonable advance notice (for example, in-app notice or email) with the effective date. The current version will always be available in the app and on our website.
[COMPANY LEGAL NAME] [REGISTERED ADDRESS] Email: info@bubblesnetworks.com
Schedule A — United States
A.1 Application. This Schedule applies if you are resident in the United States, and prevails over the numbered Sections to the extent of any inconsistency.
Depending on your state of residence (including California, Colorado, Connecticut, Delaware, Montana, Oregon, Texas, Utah, and Virginia, among others), you may have the right to:
- know/access the personal information we have collected about you, including the categories collected, sources, purposes, and third parties to whom it was disclosed;
- obtain a portable copy of your personal information;
- correct inaccurate personal information;
- delete your personal information;
- opt out of sale, “sharing” for cross-context behavioral advertising, and certain profiling — noting that we do not sell or share personal information, so there is nothing to opt out of;
- non-discrimination for exercising your rights.
How to exercise your rights: contact us at info@bubblesnetworks.com or use the in-app account deletion flow. We will verify your request using the email associated with your account and respond within the time required by applicable law (generally 45 days, extendable once). You may use an authorized agent where permitted by law; we will require proof of the agent’s authorization. If we deny your request, you may appeal by replying to our decision, and we will inform you of the outcome; unresolved appeals may be directed to your state Attorney General.
California notice at collection: the categories of personal information we collect and the purposes are described in Sections 2 and 3. We do not collect sensitive personal information as defined by the CCPA beyond account log-in credentials (used solely to provide the Service), and we do not use or disclose personal information for purposes requiring a “Limit the Use of My Sensitive Personal Information” right. We do not currently detect or respond to Global Privacy Control (GPC) or other opt-out preference signals. We do not sell or share personal information for cross-context behavioural advertising, which is the processing such a signal would opt you out of. If that changes, we will implement GPC support and update this Policy before doing so.
Cross-border processing. Our service providers store and process data in data centres located in [CONFIRM AND LIST PRIMARY HOSTING REGIONS — check the region of each Supabase project in the Supabase dashboard] and other jurisdictions. By using the Service, you understand that your information may be processed in jurisdictions with privacy laws different from those of your state.
Schedule B — Canada
B.1 Application. This Schedule applies if you are resident in Canada, and prevails over the numbered Sections to the extent of any inconsistency. Schedule A does not apply to you.
B.2 The law that applies. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, provincial legislation — including British Columbia’s Personal Information Protection Act (PIPA) and Alberta’s PIPA. Where a province has its own substantially similar legislation, that legislation applies to information handled within the province and PIPEDA applies to information crossing provincial or national borders.
Subject to limited exceptions under PIPEDA and BC PIPA, you have the right to:
- access the personal information we hold about you and be told how it is used and to whom it has been disclosed;
- request correction of inaccurate or incomplete information;
- withdraw consent to our collection, use, or disclosure of your information (which may limit or end our ability to provide the Service);
- complain — first to us, and then to the Office of the Information and Privacy Commissioner for British Columbia (OIPC BC) or the Office of the Privacy Commissioner of Canada (OPC).
To exercise any of these rights, contact our Privacy Officer at info@bubblesnetworks.com. We will respond within the time required by law (generally 30 days) and may need to verify your identity first.
B.4 Cross-border transfer. Our service providers store and process data in data centres that may be located outside Canada, including in the United States. [CONFIRM AND LIST PRIMARY HOSTING REGIONS — check the region of each Supabase project in the Supabase dashboard]. While your information is in another jurisdiction, it is subject to the laws of that jurisdiction, and courts, law enforcement, and national-security authorities there may be able to access it. We use contractual and technical safeguards with our providers to protect personal information regardless of where it is processed.
B.5 Privacy Officer. Questions, access or correction requests, and complaints should be directed to our Privacy Officer:
[PRIVACY OFFICER NAME / TITLE] [COMPANY LEGAL NAME] [REGISTERED ADDRESS, British Columbia, Canada] Email: info@bubblesnetworks.com
If you are not satisfied with our response, you may contact the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca) or the Office of the Privacy Commissioner of Canada (priv.gc.ca).
B.6 Quebec — not yet covered. ⚠️ TO DO. Quebec’s Act respecting the protection of personal information in the private sector, as amended by Law 25, imposes obligations beyond this Schedule — including privacy impact assessments, express consent for sensitive information, data portability, and notification of automated decision-making — and Quebec law may require this Policy be made available in French. This Policy has not been prepared for Quebec. Before offering the Service for Buildings in Quebec, obtain Quebec-qualified advice and add a Quebec schedule.