Legal
Privacy Policy
How Localy handles information for customers, local businesses, and visitors.
Effective: August 5, 2026
1. Scope and who we are
This Privacy Policy explains how Moncada Peon Ventures LLC DBA Localy App ("Localy," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use Localy websites, accounts, business tools, offers, communications, and related services (collectively, the "Service").
This Policy applies to visitors, customers, business owners, and administrators. It does not govern a local business or other third party when that party collects information through its own website, point-of-sale system, or customer relationship.
Localy's mailing address is 418 Broadway STE N, Albany, NY 12207. Privacy questions may be sent to support@localyapp.io or through the Contact page.
2. Information you provide
Account information includes your name, email address, optional phone number, account role, authentication identifiers, account status, notification preferences, and account creation or update timestamps. Supabase provides Localy authentication, including signup, login, session management, email confirmation, and password reset. If you choose Google sign-in, Google also processes information under its own privacy terms.
Business owners provide business names, categories, addresses, descriptions, hours, phone numbers, websites, Instagram handles, profile and cover images, ownership relationships, and other profile details. Business submissions also include approval status, proposed profile changes, moderation records, offer content, and plan information.
Contact and support information includes your name, email address, message category, message content, other information you choose to provide, and technical information used to prevent spam, investigate problems, and respond.
3. Public business and offer information
Approved business profiles are public within Localy. Public information can include the business name, category, address, description, hours, business phone number, website, Instagram, images, approval or founding status, and current or upcoming offers.
Published offers can include titles, images, prices or offer values, included items, timing, intended Localy customer audience, availability, limits, service modes, and terms. Businesses are responsible for the information they publish.
Customer account details, saved offers, activations, favorite businesses, email preferences, and alcohol age confirmations are not public profile information.
4. Customer activity and analytics
Localy records activity needed to operate and understand the Service, including business profile views, offer views, saved and unsaved offers, activations, favorite and unfavorite actions, offer eligibility, and timestamps. An activation records intent to use an offer; it is not proof of a visit, completed purchase, or redemption.
Localy can classify activity as a first or returning Localy interaction with a business based on prior Localy offer activations. This classification supports offer eligibility and aggregate business analytics. It does not establish whether a person visited or purchased from the business outside Localy.
Business and administrative analytics can include offer and profile views, saves, activations, weekday activity, offer performance, and first or returning Localy activity. Businesses receive aggregate operational signals and do not receive raw customer age-confirmation records.
5. Location, cookies, and browser storage
Location is optional. If you grant browser permission, Localy uses your current coordinates to estimate distance and sort eligible offers or businesses. In the current Service, those customer coordinates are used in your browser, are not sent to or stored on Localy servers, and are cached in browser storage for up to ten minutes. The cache is removed when it expires or when Localy detects that permission was denied or revoked.
Localy remains usable without location and can display a Nearby label or a general discovery order instead. You can deny or revoke location permission through your browser or device settings.
Localy uses first-party cookies and browser storage to maintain authentication sessions, remember location-request state, prevent duplicate view events during a session, remember Localy installation prompts, and preserve supported preferences. A signed, HttpOnly, Secure, SameSite=Lax analytics-security cookie lasts for up to 24 hours and helps enforce abuse limits without trusting a browser-supplied visitor ID.
Localy analytics can record the page path, referrer host, campaign attribution parameters, viewport category, and rotating HMAC identifiers derived from short-lived request, network, session, or user-agent signals. Localy does not store or log raw IP addresses for this analytics control, and it does not use third-party advertising trackers.
6. Business plans and payments
For business plans, Localy stores plan and feature-limit information, billing status and source, Stripe customer and subscription identifiers, Stripe price identifiers, billing interval, trial dates, and billing-period dates.
Stripe processes checkout, payment methods, invoices, and the billing portal. Localy does not directly store full card numbers or card security codes. Stripe handles payment information under its own privacy policy.
7. Communications, email records, and contact forms
Localy sends authentication, account-security, business-review, billing, support, and offer-related service messages. Optional messages can include offer-marketing communications, business offer reminders, performance summaries, and product updates, subject to feature availability, eligibility, and your preferences.
Localy and Postmark maintain delivery records such as message type, template, recipient identifiers or email hashes, sent and delivered status, bounces, spam complaints, failures, suppression status, unsubscribe activity, and links clicked in a Localy email. These records help deliver messages, honor preferences, prevent repeated sending, and investigate delivery problems.
You can manage supported email preferences in Localy or use an unsubscribe link in an optional email. Disabling optional messages does not stop essential account, security, legal, support, or billing notices.
Cloudflare Turnstile processes anti-abuse information when you submit the Contact form. Localy uses the submission and verification result to prevent spam and respond to the message.
8. Alcohol-offer records
For offers containing alcohol, Localy records merchant attestations, customer age self-attestations, offer and business snapshots, warning acknowledgments, applicable Terms and confirmation versions, compliance events, administrative notes, and timestamps.
The customer flow asks a customer to confirm that they are at least 21 for each applicable offer. Localy does not collect a birth date, identification image, or identification number through this flow, and the confirmation is not identity or government-ID verification.
Detailed customer alcohol attestations are restricted to authorized Localy administrators and service providers that process information for Localy. They are not provided to the business. Localy can preserve alcohol-offer and compliance records after an offer, business, or account is deleted when reasonably necessary for legal compliance, safety, dispute handling, or regulatory cooperation.
Offers containing alcohol are excluded from promotional campaigns, automated offer-recommendation emails, optional offer-marketing communications, and alcohol-offer activation emails.
9. How we use information
Localy uses information to create and secure accounts; operate customer and business features; display and moderate profiles and offers; support saves, favorites, and activations; determine offer eligibility; provide analytics; process business plans; send requested or permitted communications; and respond to support requests.
We also use information to prevent fraud and abuse, enforce role and plan controls, troubleshoot errors, protect the Service, maintain records, comply with law, and investigate disputes or safety concerns.
Alcohol-offer information is also used to enforce age-confirmation requirements, review merchant attestations, investigate incidents, suspend alcohol-offer privileges, preserve moderation history, and respond to lawful regulatory requests.
10. How we disclose information
Localy discloses public business and offer information as described above. We disclose personal information to service providers only as needed to operate the Service, including Supabase for authentication, database, and storage; Vercel for hosting; Stripe for business billing; Postmark for email delivery; Cloudflare Turnstile for anti-abuse verification; and Google when a user chooses Google sign-in.
Localy can also disclose information when required by law or legal process; to protect users, businesses, Localy, or others; to investigate fraud, abuse, security, or legal violations; or as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and notice requirements.
When you choose an external link, such as a business website, Instagram profile, phone link, or directions link, the third party's privacy practices apply after you leave Localy.
11. No sale or targeted advertising
Localy does not sell personal information for money and does not share personal information for cross-context behavioral advertising. Localy does not use third-party advertising trackers to build advertising profiles across unrelated websites or services.
Disclosures to service providers that process information to operate Localy are not treated by Localy as sales of personal information.
12. Retention, deletion, and de-identification
Localy keeps personal information for as long as reasonably necessary to provide the Service, maintain accounts and business records, deliver communications, support analytics, meet billing and tax obligations, secure the Service, resolve disputes, and comply with law. Retention varies by the type of information and the reason it is needed.
Users can permanently delete their Localy account through Account Settings. Localy cancels active Stripe subscriptions before account deletion. Account-linked profiles, offers, saves, favorites, activations, preferences, and related content are then deleted or de-identified according to the relationships in Localy systems.
Some information can remain after deletion, including Stripe transaction and billing records held by Stripe; de-identified or hashed analytics; email delivery, suppression, security, fraud-prevention, and dispute records; and alcohol attestation or compliance snapshots. Localy retains these records only for legitimate operational, legal, safety, or compliance purposes.
Localy also retains keyed, pseudonymous eligibility markers derived from verified account identifiers. These markers contain no raw email address, Google identifier, profile content, or offer code and are used only to prevent account deletion from resetting once-per-customer, same-day, or first-time-at-a-business offer eligibility. They remain only while a referenced offer or business requires that history.
Internal Admin Demo Mode uses isolated sample data and a session cookie. Demo sessions expire after four hours and are not included in customer discovery, production analytics, billing, or email activity.
13. Your choices and privacy requests
You can update supported account and business profile information, manage optional email preferences, unsubscribe from optional messages, choose whether to save or activate offers, control favorite businesses, and grant or revoke browser location permission.
You can request account deletion through Account Settings. You can also contact Localy to ask about access to, correction of, or deletion of personal information where applicable. Localy can request information reasonably necessary to verify the request and can deny or limit a request where permitted by law, including when records must be retained for security, billing, fraud prevention, dispute handling, or compliance.
Submit privacy questions or requests through the Contact page or email support@localyapp.io. Localy will not discriminate against a user for exercising an applicable privacy right.
14. Children and teen users
Localy is not directed to children under 13, and children under 13 may not create or use a Localy account. If we learn that we collected personal information from a child under 13 in a manner not permitted by law, we will take reasonable steps to delete it.
Customer accounts require users to be at least 13. A customer under the age of legal majority where they live must have a parent or legal guardian review and agree to the Terms on their behalf. Business accounts require users to be at least 18 and authorized to act for the business.
Localy does not collect a birth date to verify general account eligibility. The separate alcohol-offer confirmation records only a customer's self-attestation that they are at least 21 for that offer.
15. Security
Localy uses reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information and the Service. These include access controls, server-side secret handling, database row-level security, anti-abuse controls, and established providers for authentication, hosting, payments, and email.
No online service can guarantee absolute security. Protect your credentials, use a unique password, and contact Localy promptly if you suspect unauthorized account activity.
16. Changes to this Policy and contact
Localy can update this Privacy Policy when the Service, data practices, providers, or legal obligations change. The effective date at the top of the Policy will identify the current version. We will provide additional notice when reasonably required for a material change.
Questions or privacy requests can be submitted through the Contact page, emailed to support@localyapp.io, or mailed to Moncada Peon Ventures LLC DBA Localy App, 418 Broadway STE N, Albany, NY 12207.
