PRIVACY POLICY
1. What we collect
Account info: email or phone number, display name, handle, optional bio and location.
Content you post: photos, build logs, posts, comments, and messages.
Vehicle data: makes, models, years, modifications you choose to add to your garage.
Device info: model, OS version, app version. Required for crash reports and performance.
Usage info: which screens you visit, which posts you interact with. Used to improve the app and personalize your feed.
2. What we do NOT collect
We do not collect: payment card numbers (handled by Stripe), social security numbers, biometric data, browsing history outside Rollout, or precise location without your explicit permission.
We do not track you across other apps or websites.
3. How we use it
To deliver the service: show your feed, deliver messages, surface meets near you.
To enforce our Community Guidelines and act on user reports.
To improve product features and fix bugs (aggregated, non-identifying analytics).
To send transactional emails (sign-in codes, receipts, account notifications). Marketing emails are opt-in only.
4. Who we share it with
Other Rollout users: per your privacy settings (DM policy, Ghost Mode, hide location, etc.).
Our service providers: Supabase (database/auth), Resend (email), Twilio (SMS), Stripe (payments), and crash-reporting services. Each is bound by data-processing agreements.
Law enforcement: when required by valid legal process. We will notify you unless prohibited.
We do not sell your personal data. Ever.
5. Your rights
Access: request a copy of your data via Settings → Privacy → Download Your Data.
Deletion: delete your account in-app via Settings → Delete Account. Deletion is permanent.
Correction: edit your profile at any time in Settings.
California (CCPA) and EU (GDPR) residents have additional rights including the right to opt out of any sale of personal information (we do not sell). Email [email protected] to exercise these.
6. Data retention
Active accounts: retained while your account is in use.
Deleted accounts: profile + content removed within 30 days. Some records (moderation history, legal holds) retained as required by law.
Logs and analytics: retained up to 90 days then aggregated.
7. Children
Rollout is not intended for users under 13. We do not knowingly collect data from children under 13. If you believe a child has created an account, email [email protected].
8. Security
All traffic uses HTTPS. Passwords are hashed (we use Supabase Auth). We follow industry-standard practices but no system is perfectly secure. We will notify affected users of any breach as required by law.
9. Changes
We will revise the "Last updated" date above when this policy changes and notify you in-app for material changes.
10. Contact
Privacy questions: [email protected]