Privacy Policy

Effective Date: January 15, 2026

1. Introduction

ShowdUp Inc. ("Company," "we," "us," or "our") operates ShowdUp.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service.

By using ShowdUp.com, you consent to the data practices described in this Privacy Policy. If you do not agree with our policies and practices, do not use our Service.

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Effective Date." Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.

2. Information We Collect

2.1 Information You Provide

We collect information you voluntarily provide, including:

  • Account Information: Name, email address, password, and business name
  • Profile Information: Timezone, pickup location preferences, and default settings
  • Booking Information: Item titles, descriptions, prices, and availability schedules
  • Communication Preferences: SMS and email notification settings
  • Payment Information: Billing details processed through Stripe (we do not store full credit card numbers)
  • Support Communications: Messages and information you provide when contacting customer support

2.2 Buyer Information

When buyers book appointments through our Service, we collect:

  • Contact Information: Name, phone number, and email address
  • Verification Data: Phone verification codes and verification status
  • Appointment Data: Selected time slots, booking confirmations, and appointment status

2.3 Information Collected Automatically

When you access our Service, we automatically collect:

  • Device Information: Device type, operating system, browser type, and unique device identifiers
  • Usage Data: Pages visited, features used, time spent on pages, and click patterns
  • Log Data: IP address, access times, referring URLs, and error logs
  • Cookies and Similar Technologies: Session cookies, authentication tokens, and analytics data

2.4 Information from Third Parties

We may receive information from third-party services you connect to your account, such as payment processors (Stripe, PayPal) and authentication providers.

3. How We Use Your Information

We use collected information for the following purposes:

3.1 Provide and Improve the Service

  • Create and manage user accounts
  • Process and manage booking appointments
  • Send appointment confirmations and reminders via SMS and email
  • Verify buyer phone numbers
  • Process subscription payments
  • Provide customer support
  • Analyze usage patterns to improve the Service

3.2 Communications

  • Send transactional communications (confirmations, reminders, receipts)
  • Send service updates and security alerts
  • Send marketing communications (with your consent)
  • Respond to inquiries and support requests

3.3 Legal and Safety

  • Comply with legal obligations
  • Enforce our Terms of Service
  • Protect against fraud and abuse
  • Ensure the security of our Service

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

4.1 Service Providers

We share information with third-party service providers who perform services on our behalf:

  • Stripe: Payment processing for subscriptions
  • PayPal: Deposit payment processing
  • Twilio: SMS messaging services
  • Supabase: Database hosting and authentication
  • Vercel: Website hosting

These providers are contractually obligated to protect your information and use it only for the services they provide to us.

4.2 Between Sellers and Buyers

When a buyer books an appointment, we share their name, phone number, and email with the seller to facilitate the pickup. Similarly, sellers' business names and pickup location information are shared with buyers who book appointments.

4.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid legal requests (e.g., subpoenas, court orders, or government requests).

4.4 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.

5. Data Retention

We retain your information for as long as necessary to:

  • Provide the Service to you
  • Comply with legal obligations
  • Resolve disputes and enforce agreements
  • Maintain business records for legitimate purposes

Account Data: Retained while your account is active and for up to 3 years after account deletion for legal and business purposes.

Appointment Data: Retained for 2 years after the appointment date.

Phone Verification Data: Verification codes are deleted after 10 minutes. Verification records are retained for 90 days.

6. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure authentication with password hashing
  • Row-level security policies for database access
  • Regular security audits and vulnerability assessments
  • Access controls limiting employee access to personal data
  • Secure hosting infrastructure with Vercel and Supabase

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

7. Your Privacy Rights

Depending on your location, you may have the following rights:

7.1 Access and Portability

You have the right to request a copy of the personal information we hold about you in a portable format.

7.2 Correction

You have the right to request correction of inaccurate personal information. You can update most information directly in your account settings.

7.3 Deletion

You have the right to request deletion of your personal information. You can delete your account through your settings, or contact us to request deletion.

7.4 Opt-Out of Marketing

You can opt out of marketing communications by clicking "unsubscribe" in any marketing email or updating your preferences in your account settings.

7.5 California Residents (CCPA)

California residents have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and how it is used, the right to delete personal information, and the right to opt out of the sale of personal information (note: we do not sell personal information).

7.6 European Residents (GDPR)

If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR), including the right to access, rectify, erase, restrict processing, data portability, and object to processing. Our legal basis for processing is consent and legitimate interests.

8. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Essential Cookies: Required for authentication and core functionality
  • Preference Cookies: Remember your settings and preferences
  • Analytics Cookies: Understand how you use the Service to improve it

You can control cookies through your browser settings. Disabling certain cookies may affect the functionality of the Service.

9. Third-Party Links

Our Service may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.

10. Children's Privacy

Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. When we transfer data internationally, we implement appropriate safeguards to protect your information, such as standard contractual clauses.

12. Do Not Track Signals

Some browsers include a "Do Not Track" (DNT) feature. Our Service does not currently respond to DNT signals. We treat all users consistently regardless of DNT settings.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of material changes by posting the updated policy on our website and, where appropriate, by email. Your continued use of the Service after such changes constitutes acceptance of the updated Privacy Policy.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

For data access, correction, or deletion requests, please email privacy@showdup.com with the subject line "Privacy Request" and include your account email address.