← BearGig

Privacy Policy

Effective March 2026

1. Information We Collect

Account data: your name, @berkeley.edu email address, and password (stored as a secure hash).

Profile data: optional bio and avatar image you choose to add.

Gig data: the titles, descriptions, prices, categories, and locations of gigs you post.

Messages: the content of messages you send to other users within the app.

Usage data: app interactions, device type, and crash logs for improving reliability.

2. How We Use Your Data

• Provide and operate the BearGig marketplace.
• Allow other students to find and contact you about gigs.
• Send email verification and account-related notifications.
• Investigate reports of abuse or policy violations.
• Improve app performance and fix bugs.

3. How We Share Your Data

Profile name and avatar are visible to all BearGig users.

Your @berkeley.edu email is only visible to users in an active conversation with you.

We do not sell your personal data to third parties.

We use Supabase (supabase.com) as our backend infrastructure. Your data is stored on Supabase servers under their privacy and security policies.

We may disclose data if required by law or to protect the rights and safety of our users.

4. Data Retention

We retain your account and gig data for as long as your account is active.

After account deletion, we delete personal data within 30 days, except where retention is required by law or for resolving outstanding disputes.

5. Your Rights (CCPA & California Law)

As a California resident you have the right to:

• Know what personal information we collect and how it is used.
• Request deletion of your personal information.
• Opt out of the sale of personal information (we do not sell data).
• Non-discrimination for exercising your rights.

To exercise these rights, email privacy@beargig.com.

6. Children

BearGig requires users to be at least 13 years old. We do not knowingly collect information from children under 13. If we become aware of such data, we will delete it promptly.

7. Security

We use industry-standard encryption in transit (TLS) and at rest. Passwords are never stored in plain text. However, no system is 100% secure — please use a strong, unique password.

8. Changes to This Policy

We may update this Privacy Policy. We will notify you of significant changes via in-app notification or email. Continued use after notice constitutes acceptance.

9. Contact

Privacy questions or data requests: privacy@beargig.com