Privacy Policy

Last updated March 2026

1. What we collect

We collect your name, email address, and username when you register. We collect transaction data (amounts, descriptions, parties) as part of operating the escrow service. We collect payment method tokens from Stripe — never raw card numbers. We log IP addresses and device information for fraud prevention.

2. How we use your data

We use your data to operate the TownPay service, process payments, resolve disputes, send transactional emails (which you can manage in Settings → Notifications), detect and prevent fraud, and comply with legal obligations. We do not use your data to show you ads.

3. Data sharing

We share transaction data with the other party (buyer or seller) as necessary to operate the escrow. We share data with Stripe for payment processing, Resend for transactional email delivery, and Supabase for database and authentication. We do not sell your data to third parties.

4. Trust score

Your trust score is derived from your transaction history on TownPay. It is visible on your public profile (/u/username). You cannot delete individual transaction records that contribute to your score — they are part of the immutable ledger. You can delete your account, which removes your profile from public view.

5. Data retention

We retain transaction records for 7 years to comply with financial regulations. Account data is deleted within 30 days of account deletion. Backup copies may persist for up to 90 days in encrypted cold storage.

6. Your rights

If you are located in the EEA or UK, you have rights under GDPR including the right to access, rectify, restrict, or port your data. To exercise these rights, email privacy@townpay.com. We respond within 30 days.

7. Cookies

TownPay uses only session cookies for authentication. We do not use tracking cookies or third-party analytics cookies. Our authentication cookies are httpOnly, Secure, and SameSite=Lax.

8. Security

We employ industry-standard security measures including TLS 1.3 in transit, AES-256 at rest, and row-level security on all database tables. See our Security page for full details.

9. Changes to this policy

We may update this policy. Material changes will be communicated by email at least 14 days before taking effect. Continued use after that date constitutes acceptance.

10. Contact

For privacy enquiries, contact us at privacy@townpay.com or write to Bug Hutch Ltd, England and Wales.

Privacy questions? Contact us at privacy@townpay.com