Legal · Plain language
Privacy policy
Effective 28 August 2026The short version
Your collection starts private. We use account data to operate Riffsticks, store the gear records you ask us to store, and do not sell personal data. Serial numbers, purchase details, and notes are never public by default.
Data we process
- Identity and session data handled by Clerk, such as your user ID, email, and sign-in methods.
- Collection data you enter: gear descriptions, condition, purchase details, serial numbers, notes, and valuations.
- Temporary provider-hosted reference-image links you explicitly select, together with their source and expiry metadata. Riffsticks does not copy those images into its own storage at launch.
- Operational data such as security logs, request diagnostics, and consent or webhook event IDs.
Why we process it
We process data to authenticate you, display and calculate your collection, preserve value history, prevent fraud and abuse, provide support, and meet legal obligations. We do not use marketplace content to train models or create unauthorized analytics.
Market sources
Market evidence is always labeled with its source, method, and observation date. Reverb integration is disabled unless configured under appropriate terms. Live asking prices are not represented as sold prices or guaranteed value.
Sharing and processors
We use service providers only to run the product, including Clerk for authentication, Neon/Postgres for application data, and hosting/monitoring providers configured for the deployment. These providers process data under their respective agreements. We do not sell or rent collection data.
Retention and deletion
Collection data remains until you remove it or delete your account, subject to limited security backups and legal retention. A verified Clerk account-deletion event removes the application user and cascades their collection records. Temporary external image references expire and return to a category placeholder.
Your choices
You may correct or archive gear at any time and manage identity data from account settings. For access, export, correction, or deletion requests, email privacy@riffsticks.com.
Security and changes
We use signed sessions, owner-scoped database queries, verified webhooks, restrictive browser policies, and least-privilege integrations. No service can promise absolute security. Material policy changes will be dated here.