Privacy Policy
Last updated: 29 June 2026
This document is a working draft provided for the Locbrant beta and is not legal advice. It must be reviewed by a qualified lawyer before public launch.
This Privacy Policy explains what personal data Locbrant collects, why we collect it, and how we handle it when you use the Locbrant website and services (the “Platform”).
1. Who is responsible for your data
Locbrant (the “platform operator”) is responsible for personal data processed through the Platform. A formal business name, registration details, and contact address will be added here before public launch.
2. Data we collect
We aim to collect the minimum data needed to run a discovery platform. Depending on how you use Locbrant, this may include:
- Account email address, when you create an account.
- Your password is handled by our authentication provider (Supabase) and stored only in securely hashed form by that provider — Locbrant does not see or store your raw password.
- Profile details such as a display name or avatar, if you add them (some profile features may be added later).
- Shop profile and contact information that sellers choose to publish (for example shop name, description, district, WhatsApp number, Instagram handle, or website).
- Product information and images that sellers upload.
- Saved products or shops, when you save them to your account.
- Reports you submit, including the reason and any details you add.
- Analytics events about how the Platform is used, such as product views, shop views, and contact-button clicks.
- Draft or submitted review data, if and when review features are launched in the future.
- Limited operational activity, such as when a seller last opened their shop dashboard, if such features are implemented.
- Technical data created automatically, such as log data, approximate request information used for security and rate limiting, cookies, and session data needed to keep you signed in.
3. Data we do not collect
We do not handle payments, so we do not collect payment-card or bank-account data. We also avoid storing personal data in analytics — for guests, activity is tied to a short-lived session identifier rather than to your identity, and we do not store full IP addresses alongside analytics events.
4. How we use your data
We use personal data to:
- Create and manage your account and keep you signed in.
- Onboard, review, and moderate shops.
- Show shops and products to buyers and power search and discovery.
- Provide saving and other account features where available.
- Route buyers to a shop’s own contact channels.
- Handle reports and moderate content.
- Protect the Platform, including security checks and rate limiting to prevent abuse.
- Understand how the Platform is used and improve it, and give shops a basic sense of how buyers find them.
- Meet legal and regulatory obligations.
5. Service providers we use
We share data with a small number of service providers who process it on our behalf, only as needed to run the Platform:
- Supabase — authentication, database, and file storage.
- Vercel — application hosting and delivery.
- An email / SMTP provider — to send account and service emails such as confirmations and password resets.
- Storage and content-delivery (CDN) services — to store and serve images.
- Analytics or security providers — only if we add them later, and on the same data-minimisation basis.
6. We do not sell your data
We do not sell your personal data, and we do not share it with third parties for their own marketing.
7. How long we keep data
We keep personal data only as long as needed for the purposes above — for example while your account or shop is active, while a report is being handled, or as required by law. When data is no longer needed, we delete or anonymise it. Deleting a shop or product also removes its stored images.
8. How we protect data
We rely on reputable providers and on access controls — including database row-level security so that, for example, buyers can only see their own saved items and sellers can only manage their own shop and products. No system is perfectly secure, but we take reasonable steps to protect your data.
9. Your choices and rights
You can ask to access, correct, or delete your personal data, subject to applicable law. You can update much of your account and shop information directly on the Platform. For a request we cannot complete in-app, contact us using the details below.
10. Marketing
We will only send you direct marketing if you have agreed to receive it, and you can opt out at any time. Service messages needed to run your account — such as confirmations, password resets, and important notices — are not marketing.
11. Children
The Platform is intended for adults and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can remove it.
12. International transfers
Our service providers may process or store data on servers located outside Hong Kong. Where data is transferred across borders, we rely on providers that offer appropriate safeguards. The specific locations and safeguards will be confirmed before public launch.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will change the “last updated” date above, and significant changes may be highlighted on the Platform.
14. Contact
For privacy questions or to make a request about your data, contact the platform operator through the channel published on the Platform. Formal contact details will be added before public launch.