Data & Privacy
Last updated: July 22, 2026. Short version: we self-host everything, collect the minimum needed to run the service, and don't sell or share your data with anyone.
What we collect
If you use SideStops without signing in:
- Standard web server logs (IP address, browser, timestamps) for security and abuse prevention.
- Locally on your device: saved routes, favorites, filter preferences, and search history. This data never leaves your browser unless you sign in.
- Anonymized ad-click events (which listing was clicked; not who clicked) to help merchants understand which deals get attention.
If you create an account:
- Email address (required for login and account recovery).
- A hashed version of your password (bcrypt — we cannot recover the plaintext).
- Your saved routes and favorites, stored server-side so they follow you across devices.
- Your subscription plan tier and, if applicable, a Stripe customer ID linked to your subscription.
- The timestamp when you agreed to our Terms and Privacy Policy.
- The timestamp when you attested (if you did) that you are 21 or older to view age-restricted categories.
If you are a merchant:
- Your business name, address, phone, website, logo, product listings, deals, and photos you upload.
- Subscription tier and Stripe customer ID.
What we don't collect:
- Real-time GPS location. If you enable the GPS toggle and tap Explore, your browser shares your coordinates once to find nearby businesses — those coordinates are never stored or sent anywhere else.
- Your name, phone number, address, or other identifying information (unless you volunteer it as a merchant listing).
- Credit card numbers. If you subscribe, payment goes through Stripe directly; we only see a customer ID token.
- Third-party tracking data. We do not embed Google Analytics, Facebook Pixel, or any similar tracker.
How we use it
- To operate the service: authenticate you, save your routes and favorites, show you deals along your commute.
- To communicate with you about your account (email verification, password reset, subscription status).
- To prevent abuse (rate limiting based on IP address and account).
- To help merchants understand aggregate engagement with their listings (anonymized ad-click counts, not per-user data).
We do not use your data for advertising, do not sell it, and do not share it with third parties for their marketing purposes.
Who we share with
- Stripe: if you subscribe, Stripe processes your payment. Stripe has their own privacy policy.
- Cloudflare: we use Cloudflare in front of our web server for security and delivery. Cloudflare receives your IP address as part of routing traffic.
- Law enforcement: only if we receive a valid legal request (subpoena or court order) that we're legally required to comply with.
That's the complete list. We do not share your data with data brokers, advertisers, or affiliates.
How long we keep it
- Account data: as long as your account exists. If you close your account, everything is deleted within 30 days.
- Web server logs: 30 days, then rotated out.
- Anonymized ad-click events: retained indefinitely in aggregated form (no per-user identity attached).
- Stripe records: retained as required by financial regulations (typically 7 years).
Your rights
You can:
- Access your data: everything we have about you is visible in your account — routes, favorites, subscription.
- Correct your data: delete routes, delete favorites, cancel your subscription.
- Export your data: use the Download my data button in the "Manage your data" section above (signed in). You'll get a readable summary page — with an option to download the raw JSON for machine-readable use. We ask for your password again before releasing anything.
- Delete your account: use the Close account button in the "Manage your data" section above. Your data becomes invisible immediately and is permanently deleted within 30 days.
If you're in a state or country with specific privacy laws (California, Virginia, Colorado, the EU, etc.), you have these rights by law and the buttons above are how you exercise them. If anything doesn't work, contact us.
Cookies and local storage
We use one cookie: a session cookie set after you sign in, so we know it's you on subsequent requests. It's HttpOnly (JavaScript can't read it), Secure (only sent over HTTPS), and SameSite=Lax. When you sign out, we delete it.
We also use your browser's localStorage to save your routes, favorites, and preferences when you're not signed in. This data stays in your browser and is never sent to us.
Children
SideStops is not directed at children under 13. We do not knowingly collect information from anyone under 13. If you believe we have, contact us and we will delete the information promptly.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by updating the "Last updated" date at the top and, for signed-in users, presenting a notice on your next visit.
Contact
Questions about this policy or your data? Contact us via the "Request your city" link on the map, or by any contact information we publish elsewhere on the service.