This is a plain-language MVP version of our Privacy Policy, describing what NeedSaaS actually collects and how it's actually processed today. It has not been reviewed by a lawyer, and we do not claim compliance with any specific privacy framework (GDPR, CCPA, or otherwise) — see the note under Section 8.
1. Account information
When you create an account, we store the information you provide (email address, and for email/password signup, a hashed password never visible to us) or the information your identity provider shares (for Google sign-in: your name, email, and profile picture). We also store the profile details you add yourself — username, bio, avatar — and status flags like whether you're a verified or Pro Builder account.
2. Need and product information
The Needs you post, the products you list, the reviews you write, your votes, and your reward-pool contributions are stored and are, by design, visible to other users — NeedSaaS is a public marketplace, not a private tool. Don't post information in a Need or product listing that you don't want publicly visible.
3. Payment processing through Stripe
Payments — the product listing fee and the Pro Builder subscription — are processed by Stripe, not by NeedSaaS directly. We never see or store your full card number. We do store what Stripe tells us after a payment (for example, that a subscription is active, or that a specific product listing was paid for) so the marketplace can reflect your paid status.
4. Authentication through Supabase
Accounts, sign-in sessions, and the underlying database are handled through Supabase, our infrastructure provider. Supabase stores your account and profile data on our behalf; it does not use it for its own purposes.
5. Analytics and logging
We log basic usage signals to understand how the marketplace is used — for example, search queries (to see what people are looking for) and page views on products (to compute view counts shown on listings). This is operational logging to run and improve the product, not third-party ad-tracking.
6. Cookies and similar technologies
NeedSaaS uses the minimum cookies/local storage needed to keep you signed in between visits (via Supabase's authentication session). We do not currently use third-party advertising or cross-site tracking cookies.
7. Data retention and deletion
We retain your account and content for as long as your account exists. If you'd like your account or data deleted, contact us (see Section 9) and we'll process the request manually — during this early soft-launch phase we don't yet have a fully self-service deletion flow. Note that some information (for example, records of a completed payment) may need to be retained for accounting or legal reasons even after an account deletion request.
8. No claimed compliance certifications
NeedSaaS does not currently claim compliance with GDPR, CCPA, SOC 2, or any other specific privacy or security framework or certification. We handle data responsibly and only for the purposes described above, but we want to be explicit that we are not asserting formal compliance we haven't verified or certified.
Flag for legal review: whether any specific compliance framework applies once real users outside a small controlled group are onboarded, especially if any users are in the EU/UK or California.
9. Contact
[Contact email to be added — not yet published while NeedSaaS is a controlled soft launch to a small early group.]