Privacy Policy
What we collect
To make the Platform work, we collect:
- Account info â name, email, password (hashed via bcrypt), optional phone, optional avatar.
- Profile info â location label, bio, public posts and listings you choose to share.
- Activity â listings, messages, comments, saves, reviews, reports.
- Approximate location â neighborhood-level only. We do NOT publish your exact address. Pickup coordinates are stored server-side for matching but never exposed publicly.
- Technical data â hashed IP (raw IPs are never stored), browser, device info, login times, audit-log entries for security.
What we do NOT do
- We do not sell your personal information. (CCPA / CPRA non-sale & non-share confirmation.)
- We do not share your data with advertisers.
- We do not use third-party advertising trackers.
- We do not publish your exact home address.
- We do not access your contacts, microphone, or camera outside what you explicitly upload.
- We do not knowingly collect data from anyone under 18.
Who sees what
- Public: your display name, profile slug, avatar, listings, posts, comments, public reviews, neighborhood label.
- Other party in a conversation: your messages and any photos you attach.
- Admins: all of the above, plus audit logs, content reports, and policy-acceptance records â used only for moderation, safety, and legal compliance.
- Nobody else.
How long we keep your data
- Active account data â for as long as your account is active. Edit anytime via your profile.
- Account after self-deletion â permanently scrubbed 30 days after you request deletion. The 30-day window lets you cancel by mistake.
- Page-view analytics â 180 days, then auto-purged. IP addresses are hashed with a daily-rotating salt so the same person can't be tracked across days.
- Auth tokens (verification, password reset) â purged 7 days after they expire or are used.
- Transactional + tax records â up to 7 years where required by U.S. tax law.
- Audit log + Data-Subject-Rights log + policy acceptances â kept indefinitely as proof of compliance, even after account deletion. These contain no identifiable personal data beyond an internal user ID.
Full details in our public retention policy at /compliance/RETENTION-POLICY.md.
Your rights
You can:
- Edit your profile and listings at any time at /profile/edit.
- Download a copy of your data at /profile/data-export (right to know / data portability). Limit 3 per 24h.
- Correct anything wrong at /profile/edit (right to rectification).
- Permanently delete your account at /profile/delete-account (right to erasure). 30-day grace window, then irreversible.
- Opt out of non-essential analytics + marketing email at /profile/privacy. We also honor the browser's Do-Not-Track signal.
- Limit use of sensitive information â we do not collect special-category data, so nothing to limit.
If you are a California resident, you have additional rights under CCPA/CPRA (know, delete, correct, opt out of sale/sharing, limit use of sensitive information). We do not "sell" or "share" personal information in the CCPA sense. Exercise any right via /profile/privacy or by emailing privacy@mygrowcommunity.com. We will respond within 45 days.
If you are an EU / UK resident, you have rights under GDPR / UK GDPR (access, rectification, erasure, restriction, portability, objection). We act as the controller; sub-processors are listed below. Lodge complaints with your local Data Protection Authority.
Sub-processors
We rely on these vendors to operate the Platform. Each has access only to the data they need for their service:
- Stripe, Inc. â payment processing. Card data is entered into Stripe directly; we never see card numbers or CVVs. We are not PCI-scope.
- DreamHost â hosting (web server, database, file storage, backups).
- Amazon SES â outbound transactional email delivery.
- Microsoft Clarity (optional) â UX heatmaps and session replay using hashed session IDs. Loads only after you allow "Optional analytics" in the Privacy Choices banner. If you never answer, or choose Essential only, Clarity is never loaded.
- NVIDIA Corporation â AI inference (chat, vision, embeddings) via https://integrate.api.nvidia.com. Loads only after you allow "AI features." Inputs are not retained for model training when accessed via their inference API. https://www.nvidia.com/en-us/privacy/
- Groq, Inc. â fallback AI inference for chat-style features when configured. Groq does not retain API inputs for training. https://groq.com/privacy-policy/
- Self-hosted / local model (when configured by the operator) â inference runs on infrastructure we control; no third party receives the input.
We do not transfer data outside the United States except through these processors' standard regional infrastructure.
Security
We protect your data with:
- HTTPS everywhere; HSTS enforced
- Bcrypt password hashing
- CSRF tokens on every state-changing form
- Rate limiting on signup, login, password reset, file uploads, and DSR requests
- Content-Security-Policy with no inline JavaScript
- Prepared SQL statements only
- Server-side MIME validation + EXIF stripping on every image upload
- 2-factor authentication required for all admin access
- Audit logging of every admin action
- Daily-rotated IP hashing for analytics â raw IPs are never stored
No system is perfect. If we detect a breach affecting your data, we will notify you within 72 hours where required by law, including the nature of the data exposed and steps you can take to protect yourself.
Cookies
We use:
- A session cookie to keep you signed in. Required to use the Platform.
- A CSRF token to prevent forged form submissions. Required for security.
- A page-view session cookie (`mgc_pv`) to count anonymous unique visitors. Can be disabled at /profile/privacy or by sending the Do-Not-Track header.
- A privacy-choices cookie (`mgc_consent`) that remembers whether you allowed optional analytics and AI features. It stores only your choices and a timestamp â no identifiers. Without it we would have to ask on every page.
- Microsoft Clarity cookies â only if you allow "Optional analytics." Never set otherwise.
- No third-party advertising or behavioral tracking cookies. None.
Children
The Platform is for users 18 and over only. We do not knowingly collect data from anyone under 18. If you believe a child has registered, contact privacy@mygrowcommunity.com and we will delete the account.
AI features and third-party AI processing
Some features on the Platform (the Grow Assistant, the listing helper, Plant Doctor photo analysis, automated content moderation, and semantic search) work by transmitting the text or image you submit to a third-party AI provider so it can generate a response.
- Who receives it: NVIDIA, and Groq as a fallback where configured. If the operator has configured a self-hosted model, that request stays on our own infrastructure. The current list is always published in our [AI Policy](/legal/ai-policy) and updated within 30 days of any change.
- What is sent: only the content of your request â your question, the listing text you are writing, the photo you upload for analysis, or the post being screened.
- What is never sent: your name, email, password, payment details, exact address, or any other account identifier. Requests are not linked to your identity at the provider.
- Consent: AI features are off until you explicitly allow them. On your first visit you will see a Privacy Choices notice describing this; nothing is sent to an AI provider unless you turn AI features on. You can change your mind at any time via Privacy Choices in the site footer, and the rest of the Platform works fully without AI.
- Training: we do not permit your inputs to be used to train these providers' models, and we do not train any model of our own on your content.
- Human review of automated decisions: if automated moderation flags your content in error, email moderation@mygrowcommunity.com and a person will review it within 5 business days.
Outputs are educational suggestions, not professional, medical, legal, or financial advice. See our separate [AI Policy](/legal/ai-policy).
Changes
We will re-prompt for acceptance when this policy materially changes. Past versions of this policy and the date you accepted each one are recorded in your account.
Contact
For any privacy concern, DSR request, or to report a breach: privacy@mygrowcommunity.com
For DMCA/copyright: dmca@mygrowcommunity.com
For safety / abuse reports: safety@mygrowcommunity.com
For general legal: legal@mygrowcommunity.com
Operating entity: Vendstop LLC.