AI Business

Effective 2026-09-16

Privacy policy

This policy explains what AI Business collects when you use AI Business, why, and what control you have over it. It is written to describe what the software actually does, so it is specific where it can be.

What we collect

Account data. Your email address, username, display name, and a one-way hash of your password. We never store the password itself.

Security records. Each sign-in, failed sign-in, password change, email change, two-factor event, and similar action is recorded with the time, your browser’s user-agent string, and a keyed hash of your IP address. We store the hash, not the address: it lets us tell “same network” from “different network” without keeping where you were.

Two-factor data. If you turn on two-factor, the shared secret for your authenticator app and hashes of your recovery codes.

Sign-in provider data. If you sign in with Google or another provider, the email and name that provider shares with us.

Content you create in the Service, as described in the terms.

What we use it for

  • Running your account and the Service.
  • Keeping your account secure: rate limiting, locking out repeated failed sign-ins, and emailing you when something security-relevant happens (a password change, a sign-in from a device we have not seen).
  • Responding when you contact us.
  • Meeting legal obligations.

We do not sell personal data, show advertising, or use your content to train machine-learning models.

Password checking

When you choose a password we check it against the Have I Been Pwned database of passwords exposed in public breaches. We send only the first five characters of a SHA-1 hash of the password; the password itself never leaves our server and cannot be reconstructed from what is sent.

If you buy in the market

You do not need an account to buy. We keep the name, email address and (if you gave one) phone number and note you entered at checkout, with the order or ticket itself, for as long as the business keeps its records; the business you bought from sees them too, because it is the seller. Your card details never reach us: they go to Stripe. When you ask for your orders, a link is sent to your address and a cookie on that device keeps it signed in for 30 days.

Following. Businesses you follow are kept in a cookie on your device; if you ask for the weekly email, they are kept against your address instead, and one email a week says what is new — you can stop it from the Following page at any time.

Where you are looking. The place you choose in the bar is a cookie on your device. If you choose “Near me”, your browser asks you for your position; we keep it rounded to about a kilometre, in that cookie only, and never store it against you. Where the browser cannot say, we use the rough location of your connection, which our hosting provider reports with every request.

Reports. When you report a listing we keep what you wrote, the address if you gave one, and a one-way hash of your connection to stop abuse. The business is not told who reported it.

Who processes it

We use these providers to run the Service. Each processes data only on our behalf.

  • Supabase — database and authentication hosting, including sending account emails (confirmation, password reset, email change).
  • Resend — delivery of security notices, if configured.
  • Cloudflare — bot protection on sign-up and sign-in forms, if configured. Cloudflare may set a cookie for that purpose.
  • Have I Been Pwned — the password check described above. Receives a hash prefix only.
  • Stripe — payments. A buyer’s card details and billing address go to Stripe, never to us; a business’s identity and bank details go to Stripe when it connects its account. Stripe’s own privacy policy applies to what it holds.
  • OpenStreetMap (Nominatim) — the geocoder. A business’s address, and an event’s venue address, are sent once to be turned into a point on the map.
  • Esri — map tiles. When you open a map, your browser fetches the tiles from Esri, which sees your connection as any website you visit does.
  • Vercel — hosting. Vercel serves the site and reports the rough location of each connection to it, which we use only for “Near me” when you ask.

We disclose data beyond this only when the law requires it, or to protect the rights and safety of users or the public.

How long we keep it

  • Account data: for as long as your account exists.
  • Orders and tickets: for as long as the business you bought from keeps its records, and as the law on business records requires.
  • Reports of a listing: until resolved, and then for a year.
  • Security records: up to 90 days, then deleted. Records tied to a deleted account are kept for the remainder of that period without the account reference.
  • Rate-limit counters: minutes to hours; they expire automatically.
  • Backups: up to 30 days after the data is deleted from the live system.

Cookies

We set cookies to keep you signed in, to keep a buyer’s orders link open on a device, to remember the businesses a device follows and the place it is looking at, and to remember which organization you were last working in. They are essential to the Service and are not used for tracking; none is shared with anyone. The bot-protection provider may set its own cookie when a challenge is shown.

Your rights

You can see and change your account data in Settings. You can delete your account, and everything in it, from Settings → Security; this takes effect immediately.

Depending on where you live you may also have rights to access, correct, export, or restrict the processing of your data, and to complain to a data-protection authority. Write to hello@example.com and we will respond within 30 days.

Security

Passwords are hashed with bcrypt. Sessions use short-lived tokens that are refreshed and revoked server-side. Two-factor authentication is available to every account and we recommend turning it on. If you find a security problem, tell us at security@example.com.

Changes

When this policy changes materially, the version date at the top changes and you will be asked to accept it the next time you sign in.