Diaspora Link — Privacy Policy

Last Updated: June 16, 2026 • Effective: June 16, 2026

1. Introduction

This Privacy Policy ("Policy") describes how Diaspora Link LLC, a New Hampshire limited liability company ("Diaspora Link," "we," "us," or "our"), collects, uses, stores, shares, and protects your personal information when you use the Diaspora Link mobile application and related web services (collectively, the "Service"). The Service includes community posts and reels, job listings, housing listings, ride-sharing, encrypted messaging, the Marketplace, and the Merchant Portal.

By using the Service, you consent to the data practices described in this Policy and our Terms of Service.

IF YOU DO NOT AGREE WITH THIS POLICY, YOU MUST NOT USE THE SERVICE.

Contact Information

  • General Privacy: contact@diaspora-link.com
  • Data Protection / GDPR Requests: contact@diaspora-link.com
  • CCPA Requests: contact@diaspora-link.com
  • Response Time: 5 business days (inquiries), 30–45 days (formal data requests)

1.2 Children's Privacy

DIASPORA LINK IS NOT INTENDED FOR CHILDREN UNDER 13 YEARS OF AGE.

We do not knowingly collect personal information from children under 13. Users must be at least 13 years old to create an account. Users between 13 and 17 must have verifiable parental or guardian permission. Users must be at least 18 to use the Marketplace or make purchases. If we discover that we have collected personal information from a child under 13, we will immediately delete that information and terminate the associated account.

2. Information We Collect

2.1 Account Information

When you create an account:

  • Email address (required)
  • Password (cryptographically hashed — we never store plaintext passwords)
  • Full name or display name
  • Phone number (optional)
  • Home country and current city/location
  • Date of birth (for age verification)

2.2 Profile Information

  • Profile photo/avatar and cover photo
  • Biographical description ("about me")
  • Skills, experience, and education
  • Employment preferences and job-seeking status
  • Resume/CV files (PDF or DOCX, max 25MB)
  • Community memberships
  • Reputation score and ratings received from other users

2.3 User-Generated Content

  • Posts: Text, images, videos (including Reels)
  • Comments and reactions on other users' posts
  • Job Listings: Title, description, requirements, location, salary range
  • Housing Listings: Property details, photos, addresses, pricing
  • Ride-Sharing Listings: Origin, destination, departure time, available seats, vehicle information, price
  • Messages: Direct messages and group chat content (end-to-end encrypted — see Section 2.7)

2.4 Marketplace and Payment Information

When you use the Marketplace as a Buyer:

  • Order details (items purchased, quantity, price, fulfillment type)
  • Pickup or delivery address
  • Order status and history
  • Payment method type and last-four digits (retained by Stripe, not us)
  • Payment transaction identifiers (Stripe Payment Intent IDs)

When you operate as a Merchant/Seller:

  • Business name, description, address, phone number, and hours
  • Store and product information (names, descriptions, prices, images)
  • Stripe Connected Account ID and payout bank account details (managed by Stripe)
  • Sales history, order management data, and payout records
  • Analytics data from the Merchant Portal (orders, revenue, product performance)

WE DO NOT STORE YOUR FULL PAYMENT CARD NUMBER, CVV, OR BANK ACCOUNT DETAILS. PAYMENT CARD DATA IS PROCESSED AND TOKENIZED DIRECTLY BY STRIPE, INC., A PCI-DSS COMPLIANT PAYMENT PROCESSOR. WE NEVER HAVE ACCESS TO YOUR FULL CARD DETAILS.

2.5 Location Information

  • GPS coordinates (fine location access, with your permission)
  • City, state, and country names
  • Full property addresses (for housing listings you post)
  • Location is cached on your device for up to 30 minutes to improve performance
  • Pickup/delivery addresses for Marketplace orders

Location data is used to assign you to diaspora communities, display relevant local listings, filter content by area, and support Marketplace pickup/delivery features. You can revoke location access in your device settings, though some features may be limited as a result.

2.6 Device and Usage Information

  • Device type, model, and operating system version
  • Unique device identifiers (advertising ID, device ID)
  • IP address and approximate geographic location derived from IP
  • Browser type and version (for web access)
  • App version, language preference, and time zone
  • Last active timestamp and session information

2.7 Analytics Data

We use Firebase Analytics (Google) to collect:

  • Screen views and in-app navigation paths
  • Feature usage (posting, job applications, Marketplace browsing)
  • Session duration, frequency of use, and engagement metrics
  • Error logs and crash reports (via Firebase Crashlytics)
  • Merchant analytics: storefront views, product clicks, and conversion data

Analytics data is retained for 14 months. You can opt out in Settings → Privacy.

2.8 End-to-End Encrypted Messaging

Direct messages and group chat content are encrypted using end-to-end encryption ("E2EE"). Your encryption keys are generated and managed through our encryption infrastructure. We cannot access, read, or decrypt your message content.

What IS Encrypted

  • Message content (text, emojis)
  • File and media attachments (up to 10MB per file)

What Is NOT Encrypted (Accessible to Us)

  • Sender and recipient user IDs
  • Chat ID and message timestamp
  • Message type identifier and delivery status
  • Typing indicators

PUSH NOTIFICATION CONTENT: When you receive a message notification, the notification content (which may include a preview of the message) is transmitted in plaintext through Expo's push notification service and subsequently through Apple APNs or Google FCM. Expo, Apple, and Google may have access to notification content. To prevent this, disable message notifications in your device settings. Receiving a notification does not mean Diaspora Link can read your messages.

Encryption Key Recovery

If you lose your device or cannot access your account, a server-assisted key recovery mechanism is available to restore access to your encrypted messages. This recovery mechanism is designed to restore access only to the account holder upon successful identity verification. The recovery secret is derived server-side and is not stored in plaintext.

3. How We Use Your Information

3.1 To Provide and Maintain the Service

  • Create, authenticate, and manage your account
  • Enable posts, comments, reels, listings, and community features
  • Facilitate end-to-end encrypted messaging
  • Process Marketplace orders, payments, and payouts
  • Operate the Merchant Portal and associated analytics
  • Process job applications and housing inquiries
  • Display location-based content, communities, and Marketplace listings
  • Send transactional notifications (order confirmations, message alerts, account alerts)

3.2 To Improve and Personalize

  • Recommend relevant job opportunities based on your stated preferences
  • Suggest communities you may want to join
  • Display nearby housing, ride-sharing, and Marketplace listings
  • Analyze usage patterns to improve platform features and performance
  • Conduct internal research and analytics

3.3 To Ensure Safety and Security

  • Detect, prevent, and investigate fraud, spam, abuse, and policy violations
  • Enforce our Terms of Service and Community Guidelines
  • Verify merchant identities and prevent fraudulent stores
  • Detect and prevent unauthorized payment transactions
  • Respond to legal requests and comply with applicable law
  • Protect the rights, safety, and interests of users and the public

3.4 For Communications

  • Send you transactional emails (account creation, order confirmations, password resets)
  • Send service announcements and important policy updates
  • Respond to your support requests and inquiries
  • We will not send marketing emails without your explicit opt-in consent

3.5 GDPR Legal Bases for Processing

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:

  • Performance of a Contract: Processing necessary to provide the Service you registered for
  • Legitimate Interests: Fraud prevention, service improvement, security, and analytics (where not overridden by your rights)
  • Consent: Analytics, optional marketing communications, extended location tracking, and push notifications
  • Legal Obligation: Responding to valid legal process, regulatory requirements, and GDPR compliance obligations

4. Data Storage and Security

4.1 Storage Infrastructure

Your data is stored using Google Firebase, which runs on Google Cloud infrastructure:

  • User profiles and listings → Firebase Firestore → encrypted at rest (AES-256)
  • Messages → Firebase Realtime Database → end-to-end encrypted + AES-256 at rest
  • Media files (photos, videos, documents) → Firebase Storage → AES-256 at rest
  • Analytics → Google Analytics/Firebase servers → retained 14 months
  • Payment data → Stripe's PCI-DSS Level 1 certified infrastructure

4.2 Security Measures

  • In Transit: TLS 1.2+ encryption for all data in transit
  • At Rest: AES-256 encryption for all stored data
  • End-to-End: 256-bit E2EE for message content
  • Passwords: Hashed using Firebase Authentication (bcrypt-based)
  • Access Control: Firebase Security Rules restrict data access to authorized users only
  • Payments: Card data handled exclusively by Stripe (PCI-DSS compliant)

No security system is 100% secure. While we implement industry-standard security measures, we cannot guarantee absolute security of your data. You are responsible for maintaining the security of your login credentials and for any activity under your account.

4.3 Data Retention

  • Account and profile data: Retained until you delete your account
  • Posts, listings, and User Content: Retained until you delete them or your account
  • Messages: Retained until deleted by you or your account is deleted
  • Marketplace orders and transaction records: Retained for 7 years for legal and tax compliance
  • Merchant payout records: Retained for 7 years for tax compliance
  • Ride listings: Auto-archived 30 days after the listed ride date
  • Analytics data: Retained 14 months, then automatically deleted
  • Error and crash logs: Retained 90 days
  • Stripe payment records: Retained according to Stripe's data retention policies

4.4 International Data Transfers

Your data may be transferred to and processed in the United States and other countries where Firebase (Google), Stripe, Expo, and other service providers operate. These countries may have data protection laws that differ from your country of residence.

For EEA/UK users, we rely on Standard Contractual Clauses (SCCs) and Google's/Stripe's data processing agreements to ensure adequate protection of your personal data during international transfers.

5. How We Share Your Information

5.1 Information Visible to Other Users

  • Profile: Name, photo, bio, home country, current city (as set by you)
  • Posts, comments, and reactions: Visible within your community
  • Reels: Visible within your community
  • Job and housing listings: Details visible to all platform users
  • Reputation score and public ratings received
  • Marketplace: Store name, products, and publicly listed information (for Merchants)

5.2 Information Shared for Marketplace Transactions

  • Buyers: Your order details and delivery/pickup address are shared with the Seller to fulfill your order
  • Sellers/Merchants: Your store information, product catalog, and order management data are shared with buyers as needed for transactions
  • Neither party receives the other's payment card details

5.3 Third-Party Service Providers

We share data with service providers who process it on our behalf under confidentiality obligations:

  • Firebase / Google Cloud: Infrastructure, authentication, database, file storage, analytics, and crash reporting
  • Stripe, Inc.: Payment processing, merchant onboarding, and payout management — Stripe processes payment card data as an independent data controller under its own Privacy Policy
  • Virgil Security / PureKit: End-to-end encryption key management infrastructure
  • Expo: Push notification delivery (notification content sent in plaintext — see Section 2.8)
  • SendGrid (Twilio): Transactional email delivery
  • Google Maps / Mapbox: Map display, geocoding, and location services

5.4 When Required by Law

We may disclose your information when we believe in good faith that disclosure is required:

  • In response to valid legal process (subpoena, court order, search warrant)
  • To comply with law enforcement requests
  • To meet national security or government requirements
  • To cooperate with regulatory investigations
  • To protect the rights, property, or safety of Diaspora Link, users, or the public

5.5 Business Transfers

If Diaspora Link is acquired, merged, or undergoes a change of control, your personal data may be transferred to the successor entity. We will notify you of any such transfer and the applicable privacy policy via email or in-app notice.

5.6 What We Do NOT Do

WE DO NOT:

  • Sell your personal information to third parties for their independent marketing use
  • Share your encrypted message content with advertisers, law enforcement (we cannot access it), or anyone else
  • Rent or lease your email address to marketing companies
  • Share your payment card details with Sellers or other users
  • Use your personal data for targeted advertising without your explicit consent

6. Cookies and Tracking Technologies

Our web-accessible legal site and Merchant Portal may use cookies and similar technologies for:

  • Session management (authentication cookies)
  • Analytics (Firebase Analytics, which may use cookies on the web)
  • Security (fraud detection and CSRF protection)

The mobile app uses device identifiers rather than cookies. You can opt out of analytics tracking in Settings → Privacy. Essential session cookies cannot be disabled without impacting functionality.

7. Your Privacy Rights

7.1 All Users

  • Access: Request a copy of the personal data we hold about you (Settings → Privacy → Download My Data)
  • Correction: Update or correct inaccurate profile information (Settings → Edit Profile)
  • Deletion: Delete your account and associated data (Settings → Account → Delete Account)
  • Opt-Out: Disable analytics tracking (Settings → Privacy)
  • Push Notifications: Disable in your device settings at any time
  • Location: Revoke location access in your device settings

7.2 California Residents (CCPA / CPRA)

If you are a California resident, you have the following additional rights:

  • Right to Know: Request details about the categories and specific pieces of personal information we collect, use, disclose, and sell
  • Right to Delete: Request deletion of your personal information (subject to certain exceptions)
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising
  • Right to Limit Use of Sensitive Personal Information: You may limit our use of sensitive personal information
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights

We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.

To submit a CCPA request, email contact@diaspora-link.com with "CCPA Request" in the subject line.

7.3 European Economic Area / UK / Swiss Residents (GDPR / UK GDPR)

If you are located in the EEA, UK, or Switzerland, you have the following rights:

  • Right of Access (Article 15): Obtain a copy of your personal data
  • Right to Rectification (Article 16): Correct inaccurate or incomplete data
  • Right to Erasure / Right to be Forgotten (Article 17): Request deletion of your data where no lawful basis exists for retention
  • Right to Restriction of Processing (Article 18): Request that we limit processing of your data in certain circumstances
  • Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format
  • Right to Object (Article 21): Object to processing based on legitimate interests, including direct marketing
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent, without affecting prior lawful processing
  • Right to Lodge a Complaint: Lodge a complaint with your local data protection supervisory authority

To exercise GDPR rights, email contact@diaspora-link.com with "GDPR Request" in the subject line. We will respond within 30 days (extendable to 45 days for complex requests).

7.4 Other Jurisdictions

Users in other jurisdictions may have privacy rights under local law (including PIPEDA in Canada, LGPD in Brazil, POPIA in South Africa, and others). Please contact us at contact@diaspora-link.com to exercise any applicable rights.

8. Account Deletion and Data Removal

8.1 How to Delete Your Account

To permanently delete your account and data:

  1. Navigate to Settings → Account → Delete Account
  2. Review the detailed warnings about permanent data loss
  3. Enter your password to confirm your identity
  4. Confirm final deletion with explicit acknowledgment
  5. Monitor real-time deletion progress

Alternatively, email contact@diaspora-link.com with "Account Deletion Request."

8.2 What Gets Permanently Deleted

  • All profile information, photos, and biographical data
  • All posts, comments, likes, reactions, and reels
  • All job listings, applications, and uploaded resume/CV files
  • All housing and ride-sharing listings
  • All uploaded files and media
  • Your copies of direct messages (recipients retain their copies)
  • Your Firebase Authentication account (you cannot log back in)
  • Activity data, notification preferences, and settings
  • Marketplace cart and wishlist data

8.3 What Is NOT Immediately Deleted

  • Other users' copies of messages you sent to them
  • Data in encrypted backups (removed within 90 days)
  • Marketplace order and transaction records (retained 7 years for legal/tax compliance)
  • Stripe payment records (managed under Stripe's data retention policies)
  • Data subject to active legal holds or government requests
  • Anonymized and aggregated analytics data (which cannot be tied back to you)

ACCOUNT DELETION IS PERMANENT AND CANNOT BE REVERSED. ALL DELETED DATA IS UNRECOVERABLE.

8.4 Deletion Timeline

  • Immediate: Profile hidden from other users; authentication disabled
  • Within 24 hours: All deletable data permanently removed from active databases
  • Within 90 days: All data removed from encrypted backup systems

9. Merchant Data Practices

9.1 Merchant Portal Analytics

Merchants have access to analytics in the Merchant Portal, including order volume, revenue, product performance, and storefront view metrics. This data relates to your store's performance and does not include buyer personal data beyond what is needed to fulfill orders.

9.2 Stripe Data

When you onboard as a Merchant, you create a Stripe Connected Account. Stripe collects and processes your personal and business information (including identity verification documents, bank account details, and tax information) as an independent data controller under Stripe's Privacy Policy. We have limited visibility into the data Stripe collects for KYC and compliance.

9.3 Order Data

As a Merchant, you will receive buyer order details (name, order contents, pickup/delivery address) necessary to fulfill orders. You are prohibited from using buyer data for any purpose other than fulfilling their order. You may not contact buyers through channels other than the Platform, add them to marketing lists, or share their data with third parties.

10. Data Breach Notification

In the event of a data breach affecting your personal information, we will:

  • Investigate the breach within 72 hours of becoming aware of it
  • Notify affected users within 72 hours of confirming a breach that likely poses high risk to your rights (as required by GDPR)
  • Notify users via email and/or prominent in-app notification
  • Notify relevant data protection authorities as required by applicable law
  • Provide a clear description of the nature of the breach, data affected, likely consequences, and steps we are taking

If you suspect your account has been compromised:

  • Change your password immediately
  • Review your account for unauthorized activity
  • Contact us immediately at contact@diaspora-link.com
  • Monitor your financial accounts if you are a Marketplace buyer or Merchant

11. Children's Privacy (COPPA)

We comply with the Children's Online Privacy Protection Act (COPPA) and similar laws. The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13 without verifiable parental consent. If you are a parent or guardian and believe your child under 13 has created an account or provided personal information without your consent, please contact us at contact@diaspora-link.com immediately. We will delete the information promptly.

For more details on how we protect children on the platform, see our Child Safety Standards.

12. Do Not Track and Automated Decision-Making

12.1 Do Not Track

Some browsers offer a "Do Not Track" (DNT) signal. We do not currently respond to DNT signals because there is no uniform standard for how to interpret them. You can opt out of analytics tracking in Settings → Privacy.

12.2 Automated Decision-Making

We use automated systems for content moderation, fraud detection, spam filtering, and content recommendations. These systems may affect the visibility of your content or access to certain features. If you are in the EEA/UK, you have the right not to be subject to decisions based solely on automated processing that produce significant effects, and to request human review. Contact us at contact@diaspora-link.com to exercise this right.

13. Changes to This Privacy Policy

We may update this Privacy Policy periodically. When we make material changes:

  • We will notify you via email and/or prominent in-app notice
  • Material changes will be effective 30 days after the notification date (CCPA requirement)
  • The "Last Updated" date at the top will be updated
  • For significant changes (such as new data sharing practices), we may require you to re-accept

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Policy. If you do not agree to the updated Policy, you must stop using the Service before the effective date.

14. Contact Us

For any privacy-related questions, requests, or concerns, please contact us:

  • General Privacy Inquiries: contact@diaspora-link.com
  • GDPR Data Subject Requests: contact@diaspora-link.com (subject: "GDPR Request")
  • CCPA Requests: contact@diaspora-link.com (subject: "CCPA Request")
  • Data Breach Reporting: contact@diaspora-link.com (subject: "Security Issue")
  • Response Time: 5 business days for general inquiries; 30–45 days for formal data requests