Privacy Policy

Your privacy matters. This policy explains what data we collect, how we use it, and the choices you have.

Last updated: March 21, 2026

1. Information We Collect

Account Information

When you create an account, we collect your name, email address, and authentication credentials. If you sign up via a third-party provider (e.g., Google), we receive your name and email from that provider.

Inventory & Sale Data

We store the inventory items, photos, descriptions, pricing data, and sale records you create within the platform. This data is necessary to provide our core services — AI-powered pricing, catalog management, and payment processing.

Payment Information

Payment processing is handled by Stripe. We do not store your full credit card number on our servers. Stripe collects and processes payment details in accordance with PCI DSS standards. We receive only a transaction summary and the last four digits of your card.

Usage & Analytics

We collect anonymous usage data such as pages visited, features used, and performance metrics. This helps us improve the product and identify issues. We use privacy-respecting analytics tools and do not sell this data to third parties.

Device & Log Data

When you access Curator, we automatically collect standard log information including your IP address, browser type, operating system, referring URL, and timestamps. This data is used for security, debugging, and service improvement.

2. How We Use Your Information

Providing & Improving the Service

We use your data to operate the platform, process transactions, deliver AI-powered features (pricing suggestions, marketing generation), and continuously improve accuracy and performance.

Communications

We may send you transactional emails (receipts, account alerts, security notifications) and, if you opt in, product updates and marketing communications. You can unsubscribe from marketing emails at any time.

Security & Fraud Prevention

We use account and log data to detect and prevent unauthorized access, fraud, and abuse of the platform.

AI Model Training

Aggregate, de-identified data (e.g., item categories, price ranges) may be used to improve our AI pricing models. We never use your personal information or identifiable inventory photos for model training without your explicit consent.

3. How We Share Your Information

Service Providers

We share data with trusted third-party services that help us operate the platform — including Stripe (payments), Supabase (database hosting), AWS (infrastructure), and OpenAI (AI features). These providers are contractually bound to protect your data.

Legal Requirements

We may disclose your information if required by law, regulation, legal process, or governmental request — or to protect the rights, property, and safety of Curator, our users, or the public.

Business Transfers

If Curator is involved in a merger, acquisition, or asset sale, your data may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.

With Your Consent

We will share your personal information with third parties outside of the above scenarios only with your explicit consent.

4. Data Retention & Deletion

Retention

We retain your data for as long as your account is active or as needed to provide services. If you delete your account, we will remove your personal data within 30 days, except where retention is required by law (e.g., tax records, transaction history).

Export

You can export your inventory, sale records, and account data at any time from your account settings in CSV or PDF format. Your data is yours.

Deletion Requests

To request complete deletion of your data, email privacy@curatorapp.com. We will process your request within 30 days and confirm once complete.

5. Security

Infrastructure

Curator is hosted on SOC 2 compliant infrastructure. All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Database backups are encrypted and stored in geographically separate regions.

Access Controls

We enforce role-based access control internally. Only authorized personnel can access user data, and all access is logged and audited. We conduct regular security reviews and penetration testing.

Incident Response

In the event of a data breach, we will notify affected users within 72 hours as required by applicable law, along with details of the breach and steps taken to mitigate it.

6. Your Rights

Access & Portability

You have the right to access, correct, and export your personal data at any time through your account settings or by contacting us.

Opt-Out

You can opt out of marketing communications, analytics tracking, and AI model training contributions at any time from your settings.

California Residents (CCPA)

If you are a California resident, you have the right to know what personal data we collect, request its deletion, and opt out of any sale of personal information. Curator does not sell personal information.

EU/EEA Residents (GDPR)

If you are located in the EU/EEA, you have additional rights including the right to erasure, restriction of processing, data portability, and the right to lodge a complaint with your local supervisory authority.

7. Cookies & Tracking

Essential Cookies

We use essential cookies for authentication, session management, and security. These cannot be disabled without breaking core functionality.

Analytics Cookies

We use privacy-respecting analytics to understand how the product is used. You can opt out of analytics cookies from your account settings.

No Third-Party Ad Tracking

We do not use third-party advertising cookies or trackers. We do not participate in ad networks or retargeting programs.

8. Children’s Privacy

Curator is not directed at children under 16. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at privacy@curatorapp.com.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a prominent notice on the platform at least 30 days before the changes take effect. Your continued use of Curator after the effective date constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy or your data, contact us at privacy@curatorapp.com or write to: Curator Inc. Privacy Team United States