Shopper Privacy Policy
Effective Date: March 14, 2026
This Shopper Privacy Policy describes how Local Treasure collects, uses, stores, and protects personal data for shopper and creator accounts.
1. Definitions
- Platform Data: Data we receive from linked third-party platforms (for example username, platform user ID, and OAuth token metadata).
- UGC Data: Submission content and related metadata for campaigns (for example post URL, caption, tags, likes/views, and thumbnails).
2. Data We Collect
- Account data (name, email, profile details)
- UGC and campaign participation data
- Device and usage data used for security and reliability
- Linked social account data (username, platform user ID, OAuth token, and token expiration metadata)
3. How We Use Social Media Data
- Verify ownership and authenticity of campaign submissions
- Check required mentions/tags for campaign rules
- Fetch approved post metadata needed for campaign review and rewards
- Support account linking, relinking, and token-expiry handling
4. Token Storage and Security
- OAuth tokens are encrypted at rest in our database using application encryption controls.
- All token traffic uses encrypted transport (HTTPS).
- Token access is restricted to server-side workflows that need it.
- Tokens are not displayed to other users.
5. Retention Windows
- Linked social token credentials are retained while your account is linked and active.
- On unlink, token credentials are deleted from active records as part of unlink processing.
- UGC and campaign records are retained while needed for rewards, support, fraud prevention, and legal compliance.
6. Processors and Integrations
We use service providers and APIs, including:
- Cloud hosting and storage infrastructure (including AWS services)
- Identity/authentication providers (including Amazon Cognito)
- Social platform APIs (including Instagram/Meta)
- Email and communications infrastructure
7. Requests from Public Authorities
- We review legal validity and scope of each request.
- We challenge or narrow overbroad requests where legally permitted.
- We disclose only the minimum data required.
- We document requests, responses, and legal reasoning.
8. Your Choices
- Unlink social accounts at any time from account settings.
- Revoke app access directly from platform settings.
- Request data deletion by contacting info@local-treasure.com.
9. Contact
If you have privacy questions, contact info@local-treasure.com.