Privacy Policy
Effective date: April 21, 2026
Contents
1. Scope
This Privacy Policy explains how StickyBid ("we", "us") collects, uses, and shares information when you visit our website, create an account, or use the StickyBid desktop application and browser extension (collectively, the "Service").
2. What we collect
| Category | Examples |
|---|---|
| Account | Email address, password hash, subscription plan and status, license key. |
| Payment | Handled entirely by Stripe. We receive only the billing status, last 4 digits of the card, and Stripe customer ID. We never see or store full card numbers. |
| Device & app | Operating system, app version, connected printer model (so we can help with troubleshooting). |
| Diagnostic logs | If you opt in to send error reports, we receive stack traces and redacted app logs. Nothing is sent without your action. |
| Support | Any information you voluntarily provide when you email us. |
| Website analytics | Basic page views and referrer via privacy-friendly analytics (no cross-site tracking). Newsletter signups from the landing page are stored in a Google Sheet under our control. |
3. Data that stays on your computer
This is important: the core function of StickyBid — listening to your live show and printing labels — runs locally on your computer. Whatnot event data, buyer usernames, item names, sale amounts, and the labels we generate are processed on your machine and sent directly to your printer. That data is not transmitted to StickyBid's servers.
If you opt in to cloud features later (for example, cross-device analytics or cloud backup of your show reports), we'll tell you clearly what that adds before you turn it on.
4. How we use data
- To provide and operate the Service (authenticate, check subscription status, deliver updates).
- To process payments and prevent fraud (through Stripe).
- To respond to your support requests.
- To send transactional email (account, billing, security) and — only if you've opted in — product update emails.
- To improve the Service using aggregated, de-identified usage data.
- To comply with legal obligations.
5. Who we share with
We do not sell your personal information. We share data only with service providers that help us run the business, under written agreements that require them to protect your information:
- Stripe, Inc. — payment processing (privacy policy).
- Transactional email provider (Resend or Postmark) — sending license keys, receipts, and account emails.
- Hosting — our landing page and API are hosted by Cloudflare and Vercel (or equivalent).
- Google LLC — newsletter signups from the landing page are appended to a Google Sheet.
- Legal/safety — if required by law, or to protect rights, property, or safety.
6. Cookies
Our website uses a minimal number of first-party cookies and local storage keys for essentials like remembering that you've dismissed a banner or that you're logged in. We do not use cross-site advertising cookies. If we add analytics, we will use a privacy-friendly tool that does not require consent banners in most jurisdictions, and we will update this page before doing so.
7. Retention
We keep account data while your account is active. If you cancel, we keep minimal billing records for up to 7 years to meet tax and accounting requirements, and delete the rest within 90 days. Support emails are kept for 2 years. Newsletter subscribers can unsubscribe at any time; we remove you from the list within 7 days of unsubscribing.
8. Your rights
You have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your account and associated personal data.
- Export your data in a common format.
- Object to or restrict certain processing.
- Withdraw consent at any time where we rely on it.
To exercise any of these rights, email hello@stickybid.app. We respond within 30 days.
9. California residents (CCPA / CPRA)
If you live in California, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- The right to know what personal information we have collected about you, including categories and sources.
- The right to delete personal information we collected from you, subject to limited exceptions.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising.
- The right to limit the use of sensitive personal information. We do not collect sensitive personal information as defined by the CPRA.
- The right not to be discriminated against for exercising these rights.
To exercise these rights, email hello@stickybid.app. You may designate an authorized agent to make a request on your behalf; we may require verification.
10. Children
StickyBid is a business tool not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with information, please contact us and we will delete it.
11. Security
We use industry-standard safeguards — TLS in transit, encryption at rest where supported by our providers, least-privilege access, and audit logging — to protect personal information. No system is perfectly secure; if we learn of a breach affecting your personal information, we'll notify you as required by applicable law.
12. Changes
We may update this policy. When we do, we'll update the effective date at the top and, for material changes, notify active users by email at least 14 days before the changes take effect.
13. Contact
Questions or privacy requests: hello@stickybid.app.