Skip to main content

Privacy Policy

Effective date: 2026-06-27 This Privacy Policy explains how The Animal Traders (“we”, “us”) collects, uses, and shares information when you use our app and related services (the “Service”).

Summary

  • We collect account and profile information so you can sign in and use the Service.
  • We collect and display listing content (including photos/videos and seller-selected fields) so a marketplace can function.
  • We store exact pickup locations privately for sellers and organizations, and may show only city/state and an approximate map pin to help buyers browse.
  • If you opt into social media promotion, or if we choose to promote a nonprofit listing at no charge, we may use listing content in regional promotion on platforms such as Facebook, Instagram, and TikTok.
  • We use third-party providers for core functionality: Clerk (authentication), Supabase (database, storage, edge functions), Google Places/Geocoding (location search), Uploadcare (media upload/CDN), AWS Rekognition (media moderation), PostHog (product analytics), Sentry (error monitoring), Vercel Speed Insights (web performance telemetry), and MailerLite (email communications).
  • PostHog and Sentry are configured for privacy: we link activity to your Clerk user id only in production, do not send name/email/chat/payment details through those tools, and do not store client IP addresses in PostHog.

Information we collect

Account and authentication

When you sign up or sign in, we process account data through Clerk, such as:
  • Email address and verification status
  • Name and profile image (if you provide them)
  • Organization membership and role (if you create/join an organization)
We also store a corresponding profile row in our database (for example: display name, avatar URL, role flags like buyer/seller).

Listings and marketplace activity

If you browse, create, or interact with listings, we process information such as:
  • Listing details you provide (title, description, category/species/breed, inventory quantities/prices)
  • Listing media (photos/videos) you upload
  • Listing documents you upload (for example, vaccination records or registration papers), and the visibility level you choose
  • Promotion selections you make for a listing, such as social media promotion and browse featured spotlight
  • Favorites (saved listings)
  • Reviews/ratings you submit (where applicable)

Location information

We process location in a few different ways:
  • Device location (optional): If you choose “Use My Location” while browsing, the app may request your device’s location permission to sort listings by distance and show nearby results.
  • Pickup/meetup location (sellers and organizations): If you set a pickup location, we store the exact address and coordinates in a private table restricted by row-level security. For browsing and map display, we publish city/state and an approximate coordinate (rounded, not exact) as a public projection.
  • Location search: When you search for a place (for example, setting your pickup area or picking a browse location), we send your query and, if available, a coarse location “bias” to our server-side proxy which calls Google Places/Geocoding.

Verification documents (nonprofits)

If an organization submits documentation for nonprofit verification, we store:
  • The uploaded PDF document in a private storage bucket
  • A verification request record (status, timestamps, document name/path, reviewer info)

Pre-launch signup and marketing communications

If you submit an early-access signup form on our marketing site (for example, the seller waitlist), we collect:
  • First and last name
  • Email address
  • State
  • Animal categories you selected
  • Species you selected (optional)
  • Optional comments or questions
This information is used to notify you about launch news and updates, and to help us understand demand before launch. We share this data with MailerLite to send you email communications. You can unsubscribe from these emails at any time using the unsubscribe link in any email we send.

Usage and diagnostics

We collect limited usage and diagnostic data to operate, secure, and improve the Service.

In our database

  • Listing view counts (used to rank “popular” listings)

Web performance (Vercel Speed Insights)

On the web version, we collect basic performance telemetry (for example, page load timing) via Vercel Speed Insights. This does not include your name, email, or payment information.

Product analytics (PostHog)

We use PostHog to understand how the Service is used. In production builds we may collect:
  • Screen navigation using redacted route names (for example, document-share tokens and chat channel identifiers are not sent)
  • App context such as platform (iOS, Android, or web) and app version
  • Selected product events, such as listing activation, listing extend/renew, messages sent, and completed purchases — including non-content identifiers like listing id, order id, or channel id where needed for analytics
When you are signed in, we link this activity to your Clerk user id only. We do not send your email, name, phone number, chat message content, payment card details, or similar personal data to PostHog. We do not use touch/click autocapture or PostHog session replay. PostHog is disabled in local development builds so developer testing does not mix with production analytics. In our PostHog project settings we also:
  • Do not store client IP addresses with events
  • Do not populate person profiles with name, email, or similar fields
  • Keep session replay turned off
  • Retain analytics data for 30 days

Error monitoring (Sentry)

We use Sentry to detect crashes and performance problems. In production we may collect:
  • Error reports (exception type, stack trace, device/OS context needed to debug)
  • Performance traces on a sampled basis
  • Masked session replays when an error occurs — text, images, and vectors are masked so replay is intended for debugging, not reading your content
When you are signed in, we link error reports to your Clerk user id only. In production we do not automatically attach IP addresses, cookies, request headers, or other default personally identifiable information to Sentry events. Sentry session replay is separate from PostHog and is configured with masking enabled. Automatic collection of default personal data in Sentry is limited to development builds.

How we use information

We use information to:
  • Provide the Service (sign-in, listings, browsing, documents)
  • Enforce seller privacy protections (for example, hiding exact pickup addresses)
  • Create and run optional listing promotion features, including regional social media promotion when selected
  • Run trust/safety and content moderation (including automated checks for uploaded media)
  • Prevent abuse, secure the Service, and troubleshoot issues

How we share information

Public and buyer-facing sharing

Some information is visible to others as part of the marketplace experience:
  • Public browsing: Active listings and certain related data may be visible to visitors who are not signed in.
  • Seller pickup area: Buyers may see a seller’s city/state and an approximate map pin. Exact addresses and exact coordinates are not shown publicly.
  • Documents: Buyers may see document metadata depending on the visibility you select. File downloads are served using time-limited signed URLs after authorization checks.

Social media promotion

If you opt into social media promotion for a listing, we may use listing content in promotional posts, ads, or similar campaign materials on platforms such as Facebook, Instagram, and TikTok. This promotional content may include:
  • Listing title and description
  • Listing photos or videos
  • Animal details and seller-provided listing attributes
  • General location context, such as city, metro area, county, state, or a broader regional market
We use general regional targeting based on the listing location. We do not publish your exact pickup address or exact coordinates as part of social media promotion. If we do not have any paid social media promotions scheduled for a given week, we may choose to promote nonprofit listings at no charge. This promotional use is optional, discretionary, and not guaranteed.

Service providers

We share information with vendors that help us run the Service:
  • Clerk for authentication and organization management
  • Supabase for database, storage, and edge functions
  • Google Places/Geocoding to power place search and reverse geocoding
  • Uploadcare to upload, store, and deliver photos/videos via CDN
  • AWS Rekognition (via Uploadcare add-ons) for automated media moderation
  • PostHog for product analytics (see “Product analytics” above). PostHog processes data on our behalf; analytics events are retained for 30 days in our project configuration.
  • Sentry for error monitoring and performance diagnostics (see “Error monitoring” above)
  • Vercel Speed Insights for web performance measurement
  • MailerLite for email communications to pre-launch signups and marketing subscribers
These providers process information on our behalf under their terms and privacy practices.

Your choices

  • Location permissions: You can deny location permission. Browsing still works, but distance-based sorting may be unavailable.
  • Pickup location: Sellers can update or delete their pickup location. Deleting it removes the public pickup area display.
  • Account: You can manage your account via the app’s account settings.
  • Marketing emails: If you signed up for early access or launch updates, you can unsubscribe at any time using the link in any email we send, or by contacting us directly.

Security

We use a combination of technical and organizational safeguards, including:
  • Row-level security policies for sensitive tables
  • Private storage buckets for documents
  • Time-limited signed URLs for file downloads

Data retention

We keep information for as long as needed to provide the Service and for legitimate operational, security, and compliance purposes. You can remove certain information directly in the app (for example, delete a pickup location or listing documents). PostHog analytics data in our project is retained for 30 days, after which it is deleted according to PostHog’s retention settings. Sentry retains error and performance data according to our Sentry project configuration and Sentry’s data processing terms.

Changes to this policy

We may update this Privacy Policy from time to time. If we make changes, we will update the effective date above.

Contact

To ask questions about privacy or request help, contact us through the app.
Last modified on June 27, 2026