Legal
Privacy Policy
We collect what the service needs to work, and nothing to advertise to you.
Draft for review. These terms have not yet been reviewed by a lawyer.
This policy explains what personal information Yaybe collects, how we use it and what choices you have. Yaybe is operated from Canada and follows the Personal Information Protection and Electronic Documents Act (PIPEDA).
What we collect
Account information. Your email address, display name, handle and optional avatar. Sellers also provide a shop name, tagline, About text, location text and links.
Content you post. Products, photos, posts, reviews, comments and favourites.
Purchase confirmations. When a seller records a sale, they enter the buyer’s email so the buyer can leave a verified review. Purchases are matched to accounts by email.
Usage information. Server logs (request path, time, status, and your IP address for security and rate limiting) and privacy-preserving page-view counts. For analytics we store a daily-rotating hash of your IP and browser, never the IP itself, and never a cookie. We do not use third-party analytics or advertising scripts.
Messages. What you send through the contact form.
Places, items, capabilities, needs and bookings (platform features)
- Places you add (a shop, an office, your home city) are stored with a geocoded point so that search by distance works. Your home place is never shown to anyone: public pages show at most the city, and only for places you mark public. Coordinates are never exported to third parties.
- Inventory items are private by default. Their history (added, moved, lent, sold) is kept while the item exists so a transfer carries it; you can export or delete everything from your account page.
- Capabilities and needs are shown to others only at the visibility you choose. A private need still receives suggested matches; the other party sees what you need and the city, never your name or contact details, until you both say you are interested.
- Match messages and booking requests are stored so both sides can read them and moderators can act on reports. Contact details are shared only if you write them yourself.
- Add-on billing goes through Stripe: we store your Stripe customer id, subscription ids and the webhook events Stripe sends us (kept seven years for tax records). We never see or store card numbers.
Why we use it
- To run the service: sign-in codes, your shop, your feed, reviews and notifications.
- To keep it safe: rate limits, spam checks (Cloudflare Turnstile on sign-in and contact), moderation and fraud prevention.
- To understand what works: aggregate statistics for sellers (views, clicks) and for us.
- To reach you: transactional email such as sign-in codes, shop status changes and review notices. The only optional email is “new review on your shop”, which you can turn off.
We do not sell personal information and we do not show ads.
Who sees it
- The public sees your shop, products, posts, public reviews and, if you choose, your public favourites and profile.
- Sellers see the email addresses of buyers whose purchases they recorded (they entered them) and aggregate statistics about their shop.
- Service providers that help us run Yaybe: Cloudflare (network, security, image hosting), Amazon Web Services (server and backups), and Google Workspace (sending email). They process data on our behalf and may store it outside Canada.
- Authorities, if the law requires it.
Cookies
Yaybe sets one cookie when you sign in (your session) and one if you change the measurement units. Neither is used for tracking. Signed-out browsing sets no cookies.
Retention
Account data is kept while your account exists. Raw usage logs are kept 90 days. Backups are kept 30 days. When you delete your account, your profile, sessions, follows, favourites and purchase links are deleted; reviews and comments remain, attributed to “Former member”.
Your choices and rights
You can view and change your information in your account settings, download a copy of your data from your account page, and delete your account. You can ask us to correct or delete information, or to explain how we handle it, by contacting us. If you’re not satisfied, you may complain to the Office of the Privacy Commissioner of Canada.
Security
Sign-in uses one-time codes, not passwords. Data travels over HTTPS. Secrets are stored separately from code and never logged. Access to production systems is limited and audited.
Changes
We’ll post any changes here and update the date at the top. Material changes are announced on the site.
Contact
Privacy questions: contact us.