Privacy Policy
1. Information We Collect
FranksRooms collects different categories of information depending on how you interact with the platform. Below is a detailed breakdown of the data we gather and why each piece is necessary to deliver a safe, reliable subletting experience.
Account Information
When you create an account we collect your full name, email address, and phone number. Your phone number is verified through Firebase (Google Identity Platform) to confirm your identity and reduce fraudulent sign-ups. This core data is required to operate your account, send transactional notifications, and enable other members to reach you about listings.
Profile Information
You may optionally provide a bio, lifestyle preferences, city, and a profile photo. This information is displayed on your public community profile to help potential roommates assess compatibility. Your profile photo is stored in Supabase Storage and served through a content delivery network.
Listing Information
Hosts who publish listings provide photos, a street address, pricing, availability dates, and room details. Photos are stored in Supabase Storage. The exact street address is stored privately in our database and is never displayed publicly—only an approximate neighborhood location is shown on the map until a booking is confirmed.
Payment Information
All payment processing is handled by Stripe Connect. FranksRooms does not store your credit card number, bank account details, or other sensitive financial information on our servers. Stripe collects and processes this data directly under their own privacy policy and PCI-DSS compliance standards.
Chat & Messaging
Messages exchanged between members are stored in our Supabase database to enable real-time conversations and allow you to review past exchanges. Message content is passed through automated content filters designed to block spam, prohibited language, and attempts to share personal contact information outside the platform.
Usage Data
We automatically collect information about how you interact with the platform, including pages visited, actions taken (such as saving a listing or sending a message), device type, browser version, and general session duration. This data helps us improve the user experience, identify bugs, and understand which features are most valuable to the community.
Location Information
For listings, we use Mapbox to geocode addresses into approximate coordinates that are displayed on the public map. The precise location is kept private and only shared with a confirmed guest after a booking is completed. We do not track your real-time device location, and any geolocation data you provide is used solely for improving search relevance within your selected area.
2. How We Use Your Information
The information we collect serves the following purposes:
- Account Management — creating and maintaining your account, authenticating your identity, and managing your sessions across devices.
- Matching — surfacing relevant listings based on your location, budget, and lifestyle preferences, and helping hosts evaluate potential tenants through community profiles.
- Payments — facilitating secure rent payments, security deposits, and host payouts through Stripe Connect, including generating receipts and handling refunds.
- Safety & Trust — detecting and preventing fraud, enforcing community guidelines, moderating chat content, and maintaining audit logs of sensitive administrative actions.
- Communication — sending transactional emails (booking confirmations, payment receipts, account alerts) through Resend, and enabling in-app messaging between members via Supabase real-time channels.
3. Third-Party Services
FranksRooms relies on the following third-party services to operate. Each service receives only the minimum data necessary to perform its function:
- Firebase / Google Identity Platform — authentication and phone number verification. Receives your email and phone number.
- Supabase — primary database, file storage, and real-time messaging infrastructure. Stores account data, listings, photos, and chat messages.
- Stripe Connect — payment processing and host payouts. Receives financial information directly from you during checkout; we do not store this data.
- Mapbox — map rendering and address geocoding. Receives listing addresses to convert them into coordinates for map display.
- Resend — transactional email delivery. Receives your email address and the content of system-generated messages such as booking confirmations and account alerts.
- Vercel — hosting, edge network, and serverless function execution. Processes all HTTP requests to the platform and may log request metadata for performance monitoring.
4. Data Sharing
We do not sell, rent, or trade your personal information. Your data is shared only with the third-party services listed above, and strictly for the purposes described in this policy. For example, Stripe receives payment details to process transactions, and Mapbox receives addresses to render listing maps.
We may disclose your information if required by law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of FranksRooms, our users, or the public.
5. Data Retention
Your account information, profile data, and listing history are retained for as long as your account remains active. If you delete your account, we will remove your personal data from our active systems within 30 days, though anonymized usage analytics may persist indefinitely.
Chat logs are retained in accordance with our messaging policy to support dispute resolution and safety investigations. After the applicable retention period, message content is permanently deleted from our databases and backups.
6. Your Rights
You have the right to access, correct, or delete the personal information we hold about you. Specifically, you can:
- Request a copy of all personal data associated with your account.
- Update or correct inaccurate information through your profile settings or by contacting us directly.
- Request permanent deletion of your account and all associated data.
To exercise any of these rights, email us at frank@franksrooms.com. We will respond to verified requests within 30 days.
7. Security
We implement multiple layers of protection to safeguard your data:
- Row-Level Security (RLS) — Supabase enforces database-level policies so users can only access their own data. Listing addresses, payment references, and private profile fields are invisible to unauthorized queries.
- Encrypted Connections — all data transmitted between your browser and our servers is protected by TLS encryption. API calls to third-party services also use encrypted channels.
- Content Filtering — automated filters scan chat messages and listing content for prohibited material, personal information leaks, and policy violations before delivery.
While no system is perfectly secure, we continuously review and improve our security practices to protect your information against unauthorized access, alteration, or destruction.
8. Children's Privacy
FranksRooms is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors. If we learn that we have inadvertently collected data from someone under 18, we will take steps to delete that information as quickly as possible. If you believe a minor has provided us with personal data, please contact us at frank@franksrooms.com.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by posting a prominent notice on the platform and, where possible, sending an email to the address associated with your account. We encourage you to review this page periodically to stay informed about how we protect your data.
10. Contact
If you have questions, concerns, or requests related to this Privacy Policy or how your personal data is handled, please reach out to us at frank@franksrooms.com. We take every inquiry seriously and will do our best to respond promptly.
