Skip to content

Privacy Policy

Last updated: August 3, 2026

This explains what [FIGSTEAD LLC — REGISTERED NAME PENDING] collects when you use FigStead, why, and what you can do about it. We've written it to be read rather than to be technically survivable, and it describes what the software actually does.

The short version

We collect what a marketplace needs to work: your email, what you list, what you buy, and what you say to other members. We never see your card number. We don't sell your data, we don't run advertising trackers, and there is no analytics or ad-network script on this site. Email us at [SUPPORT EMAIL] to get your data or have your account deleted.

1. What we collect

Account: your email address, display name, optional public @handle, and optional avatar. Your password is stored only as an Argon2 hash — we cannot read it, and neither can anyone who obtains the database. If you sign in with Google we receive your email and basic profile from Google, not your Google password.

Optional details you choose to add: a phone number, only if you turn on SMS alerts; and a ZIP code, used to work out your USDA hardiness zone so listings can show whether a plant suits your climate.

Security data:the IP address you signed up from and most recently logged in from, session records, devices you've marked as trusted, and — if you enable two-factor authentication — your TOTP secret, encrypted at rest with AES-256-GCM, plus hashed backup codes. We keep short-lived rate-limit counters keyed to your IP to blunt brute-force attacks.

Marketplace activity: your listings and their photos, bids, offers, orders, shipment tracking numbers you enter, ratings you give and receive, saved searches, watched listings, favourited sellers, reports you file, and messages you exchange with other members.

Payment records: order amounts, fees, and Stripe identifiers. We never receive your card number — card details go directly from your browser to Stripe.

2. What other people can see

Public to anyone, including people who aren't logged in:

  • Your display name, @handle and avatar
  • Your listings, their photos and descriptions
  • Your seller ratings and recommendation percentage
  • Completed sale prices. Sold listings and what they sold for appear in our public price history at /sold. If you don't want a sale price public, don't sell it here.

Your email address is never shown publicly. Your phone number and ZIP code are never shown publicly. Private messages are private between you and the other member — but see the next section.

3. Administrator access

Site administrators can see account details, orders and — where a report has been filed or abuse is suspected — the contents of messages. This is how moderation and fraud investigation work, and we'd rather state it plainly than let you assume otherwise. Administrators are bound by the same rules; access for curiosity rather than cause is not acceptable use.

4. Who we share it with

We do not sell personal information, and we do not share it for advertising. We use these service providers to run the site, each receiving only what their job requires:

  • Stripe — payments, payouts and seller identity verification. Sellers provide Stripe with identity and bank details directly; we never see them.
  • Vercel — hosting and content delivery. Processes request metadata including IP addresses.
  • Neon — the managed PostgreSQL database where the data above is stored.
  • Cloudinary — storage and delivery of listing photos and avatars.
  • Resend — transactional email (password resets, sale notifications, alerts).
  • Twilio — SMS, only if you opt in and provide a number.
  • Google — sign-in with Google, if you use it; and reCAPTCHA on the signup, login and password-reset forms.
  • Shipping carriers (USPS, FedEx, UPS, DHL) — tracking numbers are sent to the relevant carrier to look up delivery status.

We may also disclose information where legally required, or where necessary to investigate fraud or protect someone's safety.

5. reCAPTCHA

The signup, login and password-reset forms are protected by Google reCAPTCHA v3, which scores how likely a submission is to be automated. To do that it collects device and browser information and sends it to Google, subject to Google's Privacy Policy and Terms of Service. We use it only to tell humans from bots on those three forms, never to profile you or to target anything at you.

6. Cookies

We use cookies only to make the site function, which is why you aren't reading this behind a consent banner. Specifically: a session cookie that keeps you logged in; a short-lived cookie during two-factor sign-in; a cookie remembering a device you chose to trust; a state cookie protecting the Google sign-in flow against CSRF; and your light/dark theme preference.

There are no advertising cookies, no third-party analytics, and no cross-site tracking on this site.

7. How long we keep it

Account data is kept while your account is open. Order records, including amounts and Stripe identifiers, are kept after that where we need them for financial, tax and dispute purposes.

Some records survive deletion of your account because they belong to other people too: a rating you left on a seller, a completed sale in the public price history, and the other side of a conversation remain, with your account no longer identified by name.

8. Your choices and rights

You can edit your profile, change your email, add or remove a phone number, turn two-factor on or off, and manage notification preferences from your account settings at any time. Marketing and alert emails have an unsubscribe link; transactional messages about your own orders do not, because you need them.

Access and deletion: email [SUPPORT EMAIL]and we'll provide a copy of your data or delete your account, subject to the retention exceptions above. We'll respond within 30 days.

Depending on where you live you may have additional statutory rights — for example under the California Consumer Privacy Act, or the Illinois Personal Information Protection Act. We extend the access and deletion rights described here to everyone regardless of location, because maintaining two standards isn't worth it at our size.

9. Security

Passwords are hashed with Argon2. TOTP secrets are encrypted at rest. The site is served over HTTPS with HSTS, a content security policy and strict framing rules. Authentication endpoints are rate-limited and protected by reCAPTCHA.

No system is perfectly secure, and we won't pretend otherwise. If a breach affects your personal information we will notify you as required by law. If you find a security problem, please tell us at [SUPPORT EMAIL] before disclosing it publicly.

10. Children

FigSteadis for adults. It is not directed at children, and we don't knowingly collect information from anyone under 18. If we learn that we have, we'll delete the account.

11. Changes and contact

If we change this policy the date at the top changes with it, and we'll flag material changes on the site. Questions, requests, or anything you think this page gets wrong:

[FIGSTEAD LLC — REGISTERED NAME PENDING]
[MAILING ADDRESS]
[SUPPORT EMAIL]