Shopper Privacy Policy

Effective Date: March 14, 2026

This Shopper Privacy Policy describes how Local Treasure collects, uses, stores, and protects personal data for shopper and creator accounts.

1. Definitions

  • Platform Data: Data we receive from linked third-party platforms (for example username, platform user ID, and OAuth token metadata).
  • UGC Data: Submission content and related metadata for campaigns (for example post URL, caption, tags, likes/views, and thumbnails).

2. Data We Collect

  • Account data (name, email, profile details)
  • UGC and campaign participation data
  • Device and usage data used for security and reliability
  • Linked social account data (username, platform user ID, OAuth token, and token expiration metadata)

3. How We Use Social Media Data

  • Verify ownership and authenticity of campaign submissions
  • Check required mentions/tags for campaign rules
  • Fetch approved post metadata needed for campaign review and rewards
  • Support account linking, relinking, and token-expiry handling

4. Token Storage and Security

  • OAuth tokens are encrypted at rest in our database using application encryption controls.
  • All token traffic uses encrypted transport (HTTPS).
  • Token access is restricted to server-side workflows that need it.
  • Tokens are not displayed to other users.

5. Retention Windows

  • Linked social token credentials are retained while your account is linked and active.
  • On unlink, token credentials are deleted from active records as part of unlink processing.
  • UGC and campaign records are retained while needed for rewards, support, fraud prevention, and legal compliance.

6. Processors and Integrations

We use service providers and APIs, including:

  • Cloud hosting and storage infrastructure (including AWS services)
  • Identity/authentication providers (including Amazon Cognito)
  • Social platform APIs (including Instagram/Meta)
  • Email and communications infrastructure

7. Requests from Public Authorities

  • We review legal validity and scope of each request.
  • We challenge or narrow overbroad requests where legally permitted.
  • We disclose only the minimum data required.
  • We document requests, responses, and legal reasoning.

8. Your Choices

  • Unlink social accounts at any time from account settings.
  • Revoke app access directly from platform settings.
  • Request data deletion by contacting info@local-treasure.com.

9. Contact

If you have privacy questions, contact info@local-treasure.com.