Privacy Policy
Your privacy matters to us. This policy explains what data FindIt collects, how we use it, and the choices you have.
Last updated: January 15, 2025
Information We Collect
Account Information
When you create a FindIt account, we collect your full name, email address, and a securely hashed version of your password. You may optionally provide a phone number, profile bio, and avatar image to help other users identify and contact you.
Item Listings
When you post a lost or found item, we collect the title, description, category, date, location, and any photo you choose to upload. This information is made publicly visible so that the community can help reunite items with their owners.
Claim Requests
When you submit a claim on an item, we store your claim message, proof description, and the communication between you and the item poster. This helps us maintain a complete record of the resolution process.
Usage Data
We automatically collect anonymised usage data such as pages visited, search queries, and feature interactions. This helps us understand how FindIt is used and continuously improve the platform.
How We Use Your Information
Core Platform Functionality
Your information is used to operate and maintain FindIt — including creating and managing your account, displaying item listings, processing claim requests, and sending you notifications about activity related to your posts.
Communication
We use your email address to send account-related notifications, claim status updates, and important security alerts. We do not send unsolicited marketing emails; you can opt in to community digests from your account settings.
Safety & Trust
We analyse platform activity to detect fraudulent listings, spam, or abusive behaviour. This helps us maintain a safe, trustworthy environment for everyone on FindIt.
Improvements
Aggregated, anonymised analytics help us identify pain points, prioritise features, and make FindIt faster and more reliable. Individual user data is never sold or shared with advertisers.
Data Sharing & Third Parties
We Do Not Sell Your Data
FindIt will never sell, rent, or trade your personal information to third parties for their own marketing or commercial purposes. Your data is not a product.
Service Providers
We use trusted third-party services to operate the platform — including Cloudinary for image hosting, MongoDB Atlas for database storage, and Vercel for hosting. These providers process your data solely on our behalf and are bound by strict data processing agreements.
Public Information
Item listings and your display name are visible to all users, including those who are not signed in. Please avoid including sensitive personal details (home address, financial information) in item descriptions.
Legal Requirements
We may disclose your information if required to do so by law, court order, or a valid government request, or when we believe disclosure is necessary to protect the rights, property, or safety of FindIt, our users, or the public.
Data Security
Password Protection
All passwords are hashed using bcrypt with a high cost factor before storage. We never store plaintext passwords and cannot retrieve your original password — only reset it.
Secure Transmission
All data exchanged between your browser and FindIt servers is encrypted via HTTPS/TLS. Authentication tokens are issued as signed JWTs with a 7-day expiry and are stored in secure HTTP-only cookies.
Access Controls
Only the item owner and the user who submitted a claim can view the details of a claim request. Administrative access to the database is restricted to authorised personnel only.
Incident Response
In the unlikely event of a data breach that affects your personal information, we will notify you by email within 72 hours and provide guidance on protecting your account.
Your Rights & Choices
Access & Portability
You can view and download all personal data associated with your FindIt account at any time from your profile settings. We provide data exports in JSON format.
Correction
You can update your name, email, phone number, bio, and avatar from the Profile page at any time. If you need to correct data you cannot access directly, contact us at privacy@findit.app.
Deletion
You may delete your account and all associated data from the account settings page. Deletion is permanent and irreversible — your items, claims, and profile will be removed within 30 days.
Notifications
You can manage notification preferences from your dashboard settings. You may opt out of non-essential email communications at any time by clicking the unsubscribe link in any email we send.
Data Retention
Active Accounts
We retain your personal information for as long as your account is active. Item listings remain visible until you delete them or mark them as resolved.
Deleted Accounts
When you delete your account, your personal information is removed within 30 days. Anonymised aggregate data (e.g. total items posted in a city) may be retained indefinitely for statistical purposes.
Legal Obligations
Some data may be retained for longer periods where required by applicable law, such as records related to fraud prevention or legal disputes.
Contact & Questions
Privacy Enquiries
If you have questions about this Privacy Policy, want to exercise your data rights, or have concerns about how your information is handled, please contact our privacy team at privacy@findit.app. We aim to respond within 5 business days.
Policy Changes
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you by email and display a notice on FindIt at least 14 days before the changes take effect. Continued use of FindIt after that date constitutes acceptance of the updated policy.
Questions about privacy?
Our privacy team is here to help. Reach out and we will respond within 5 business days.
privacy@findit.appAlso see our Terms of Service for the full legal terms governing FindIt.