1. Information We Collect
We collect information to provide, personalize, and secure our product launch and testing ecosystem:
- Account Information: When you sign up via Email OTP or Google OAuth, we receive your email address, name, and profile picture.
- Profile & Role Details: Details you provide, such as your headline, bio, user role (
USERorCREATOR), social links, and primary industry tags. - Creator Content & Media: Product listings, descriptions, logos, screenshots, and beta testing cohort questions submitted by startup founders.
- Community Contributions: Product reviews, star ratings, beta application survey answers, comments, and upvotes.
- Device & Telemetry Data: IP address, browser user-agent, session cookies, and anonymized page view telemetry used strictly for platform health, rate-limiting, and bot defense.
2. How We Use Your Information
We use the data we collect solely for core platform functionality:
- Authenticating accounts and securing logins via one-time verification codes and OAuth.
- Facilitating beta cohort recruitment and connecting founders with qualified product testers.
- Publishing community reviews, comments, and feedback loops on verified product pages.
- Enforcing platform safety, mitigating spam, rate-limiting malicious automated crawlers, and preventing abusive content.
- Sending essential transactional updates (such as login OTPs, cohort status changes, and weekly digests if subscribed).
3. Data Sharing & Third-Party Services
We do not share your personal data with third parties, except with trusted infrastructure providers that power our platform:
- Supabase & PostgreSQL: Secure database and file storage hosting with strict Row Level Security (RLS) enforcement.
- Google OAuth: Identity verification for users opting for Google Sign-In.
- Stripe: Payment processing for creators upgrading to Pro plans. We never store credit card numbers or financial details on our servers.
- Vercel: Application hosting, edge routing, and Web Vitals performance telemetry.
- Transactional Email (SMTP): Secure delivery of verification codes and digest notifications.
4. Cookies & Session Management
We use minimal, strictly necessary cookies to keep you signed in securely:
next-auth.session-token: An encrypted,httpOnly,sameSite: 'lax'cookie with a 30-day bounded lifecycle used to maintain your authenticated session.next-auth.csrf-token: A cryptographic token ensuring protection against Cross-Site Request Forgery.- We do not deploy third-party advertising cookies or cross-site tracking pixels.
5. Your Privacy Rights & Self-Service Tools
Regardless of your geographic location, we provide full transparency and control over your personal data:
- Right to Access & Export: You can download a complete copy of your profile, products, and contributions via our export tool in Account Settings.
- Right to Erasure (Right to Be Forgotten): You can permanently delete your account, products, and private records at any time.
- Right to Rectification: You can edit and update your personal details, avatar, and notification preferences at any time.
- Unsubscribe from Newsletters: Every digest email contains a one-click unsubscribe link that immediately cancels all marketing digests.
6. Security Safeguards
We employ defense-in-depth security measures to protect your information against unauthorized access, alteration, or disclosure. These include strict PostgreSQL Row Level Security (RLS), multi-proxy rate limiting, cryptographic secrets scanning, strict Content Security Policies (CSP), and sanitized data serialization.
7. Contact Our Privacy Team
If you have any questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact us at:
Launchloop Privacy & Security Team
Official Inquiries: contactlaunchloop@gmail.com
Surat, Gujarat, India 🇮🇳