Legal
Privacy Policy
What we collect
Email + password (hashed by Supabase Auth, we never see plaintext). Optional: name, phone, avatar, city, location (when you grant permission for the "Nearest" sort). Order history and Reviews you write are also stored.
How we use it
To run the service: show you nearby BrowseDeals, fulfill orders, send order updates, surface reviews on businesses. Aggregated, anonymized stats may be used for product improvement.
What we don't do
We don't sell your data. We don't serve ads. We don't share your phone with businesses (except for pickup coordination through Surplush staff).
Sharing
Your order details are shared with the business you ordered from so they can prepare the pickup. Your name is shown on your reviews. We use Supabase as our database and auth provider, hosted on AWS.
Cookies and storage
We use cookies to keep you signed in (Supabase Auth) and localStorage / sessionStorage for things like your sort preference, last known location, and PWA install state. We don't use third-party analytics cookies yet.
Your rights
You can edit your profile and notification preferences at any time from /account. You can delete your account at /account/settings; we keep your data for 30 days in case you change your mind, then permanently remove it.
Children
Surplush isn't for users under 18.
Changes
Material changes will be emailed to registered users.
Contact
Privacy concerns: privacy@surplush.pk.
Working template. Needs Pakistan-based legal review before launch.