Privacy Policy
Last updated: March 8, 2026
Your Privacy Matters
CurbClue collects only the minimum data necessary to operate the Service. We never sell your personal information to third parties. Your email address and IP address are never publicly displayed. We use IP addresses solely for security purposes, abuse prevention, and legal compliance.
Information We Collect
Account Information
When you create an account, we collect:
- Username — displayed publicly with your reviews
- Email address — used for account verification and password resets (never publicly displayed)
- Password — stored as a secure bcrypt hash (we never store plaintext passwords)
Review Data
When you submit a review, we collect:
- Ratings across five categories (parking, door access, customer, address clarity, tip)
- Written comments and optional screenshots
- Delivery platform information
- Unit/apartment number (if provided)
Automatically Collected Data
- IP address — recorded with every review submission and used for rate limiting, duplicate prevention, abuse detection, and IP ban enforcement
- Browser type and device information — basic usage analytics
- Session data — for authentication and security
How We Use Your Information
- To provide, operate, and maintain the Service
- To verify your identity and prevent fraudulent activity
- To enforce one-review-per-address limits via IP tracking
- To send essential account-related emails (verification, password resets)
- To moderate content and maintain community safety
- To generate aggregate address ratings and statistics
- To detect and prevent abuse, spam, and malicious activity
- To comply with legal obligations and respond to lawful requests
IP Address Collection & Usage
We collect and store IP addresses for the following specific purposes:
- Duplicate prevention — ensuring one review per address per user
- Security — detecting automated abuse, bot activity, and suspicious behavior
- IP ban enforcement — restricting access from banned IP addresses
- Legal compliance — IP addresses may be shared with law enforcement in response to valid legal requests, court orders, or when necessary to protect the safety of individuals
IP addresses are visible only to CurbClue administrators and are never publicly displayed.
Cookies & Local Storage
- Session cookies — essential for authentication and CSRF protection
- Local storage — used to save your theme preference (light/dark mode)
We do not use third-party tracking cookies, analytics trackers, or advertising cookies.
Data Sharing & Disclosure
We do not sell, rent, or trade your personal information. We may share data only in the following circumstances:
- Legal requirements — when compelled by law, court order, subpoena, or valid legal process
- Safety & protection — to protect the rights, safety, or property of CurbClue, our users, or the public
- Service providers — with trusted providers who assist in operating the Service (e.g., email delivery via SMTP), bound by confidentiality obligations
- Law enforcement cooperation — we may proactively share information (including IP addresses and review data) when we believe content constitutes doxxing, harassment, threats, or other criminal activity
What is never publicly visible: Your email address, password, and IP address.
Data Retention
- Account data — retained as long as your account is active
- Reviews — remain on the platform unless deleted by you or an administrator
- IP addresses — retained indefinitely for security, abuse prevention, and legal compliance
- IP ban records — retained indefinitely unless manually removed by an administrator
- Deleted accounts — account data is removed upon deletion; associated reviews may be anonymized or removed
Data Security
We implement the following security measures to protect your data:
- Bcrypt password hashing with automatic salting
- CSRF token protection on all forms and API endpoints
- Prepared SQL statements to prevent injection attacks
- XSS protection through output sanitization and Content Security Policy headers
- Secure session management with periodic ID regeneration
- HTTPS encryption for all data in transit
- Rate limiting to prevent brute-force attacks
Your Rights
You have the right to:
- Access your personal data through your profile page
- Edit or delete your reviews at any time
- Update your email address and password
- Request deletion of your account and associated data by contacting us
- Object to processing of your data in certain circumstances
To exercise these rights, visit your profile settings or contact us.
Children's Privacy
CurbClue is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that a user is under 18, we will take steps to delete their account and associated data.
Third-Party Services
We use the following third-party services:
- Google Maps & Places API — for mapping, address search, and geocoding. Subject to Google's Privacy Policy.
- SMTP email provider — for sending account verification and password reset emails.
Changes to This Policy
We may update this Privacy Policy at any time. Changes will be posted on this page with an updated "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the revised policy.
Contact
For privacy-related questions, data requests, or concerns, please contact us.