1. Information we collect
We collect information in three ways:
Information you provide. When you create an account or use the Service, you provide things like your name, email address, password (stored as a salted hash), profile details, board content, feature requests, votes, comments, and API keys you create. If you contact us, we keep a record of that correspondence.
Information we collect automatically. When you use the Service, we automatically record certain information, including device and browser type, operating system, IP address, referring URL, pages or features viewed, actions taken (such as votes or comments), timestamps, and crash diagnostics. We use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand usage.
Information from third parties. If you sign in through a third party (for example, a social or single-sign-on provider), we receive basic profile information from that provider, as authorized by you. We may also receive information from service providers that help us operate the Service (such as hosting, analytics, and abuse-prevention vendors).
2. How we use information
We use information to:
- Operate, maintain, and improve the Service and its features.
- Authenticate users, secure accounts, and protect against fraud, abuse, and security incidents.
- Communicate with you about your account, updates, security alerts, and support requests.
- Understand how the Service is used so we can prioritize improvements and troubleshoot issues.
- Send service-related and, where permitted, product announcements. You can opt out of non-essential email at any time.
- Comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information, and we do not use the content of your boards, requests, or comments to train machine-learning models for third parties.
3. Legal bases (EEA / UK users)
If you are located in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases:
- Contract: to provide the Service you have requested.
- Legitimate interests:to keep the Service secure, prevent abuse, understand usage, and improve features — balanced against your rights.
- Consent: where required, for example for certain analytics or marketing communications. You can withdraw consent at any time.
- Legal obligation: to comply with laws and respond to lawful requests.
6. Data retention
We keep personal information for as long as your account is active and as needed to provide the Service. If you delete your account, we will delete or anonymize your personal information within a reasonable period, except where we are required to retain it for legal, accounting, security, or fraud-prevention purposes. Public content (such as a request you posted to a public board) may remain visible after your account is closed, attributed to a deleted user.
7. Security
We use administrative, technical, and organizational measures designed to protect personal information, including encryption in transit, hashed passwords, scoped API keys, and access controls. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Your rights & choices
Depending on where you live, you may have the right to access, correct, delete, or port your personal information; to object to or restrict certain processing; and to withdraw consent where processing is based on consent. You can exercise many of these rights directly from your account settings.
California residents have additional rights under the CCPA/CPRA, including the right to know, delete, and correct personal information, and to opt out of “sales” or “sharing” of personal information as those terms are defined under California law. As noted above, we do not sell personal information.
To exercise your rights, email us at privacy@pahata.com. We may need to verify your identity before fulfilling your request.
9. International data transfers
Pahata is based in California, United States, and we process information in the United States and other countries where our service providers operate. When we transfer personal information out of the EEA, UK, or other jurisdictions with data-export restrictions, we rely on appropriate safeguards such as Standard Contractual Clauses.
10. Children
The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete it.
11. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you, for example by posting a notice in the Service or updating the “Last updated” date above. Your continued use of the Service after the changes take effect constitutes acceptance of the updated Policy.
12. Contact us
Pahata LLC, a California limited liability company · privacy@pahata.com · pahata.com