TwentyList Privacy Policy

Pre-production draft. Recommend licensed attorney review before major scaling. Not legal advice.

Last updated: June 19, 2026

Effective date: June 19, 2026


1. Introduction

TwentyList ("we," "us") explains here how we collect, use, disclose, and protect information when you use the TwentyList mobile app and related services ("Service").

Operator: TwentyList LLC

Privacy contact: support@twentylist.app

This Privacy Policy is incorporated into our Terms of Service. By using the Service, you acknowledge this Policy.

We may update this Policy. We will revise the "Last updated" date and, for material changes, provide notice in the app or by email where appropriate.


2. Information we collect

We group data into the categories below (similar to how major marketplaces disclose data for app stores and state privacy laws).

2.1 Identifiers and account data

DataExamplesSource
Account identifiersUser ID, Google subject IDGoogle sign-in
ProfileDisplay name, username, avatar URL, emailGoogle + profile edits
PhonePhone number, verification timestampYou (SMS OTP)
Terms acceptanceVersion id, acceptance timestampIn-app acceptance flow

2.2 Location and discovery

DataPurpose
Home ZIP codeFeed radius and local discovery
Derived coordinatesGeocoding ZIP via Mapbox (server-side)
Optional device locationOnly if you use a "use my location" feature — converted to approximate area, not continuous GPS tracking

We do not sell your location to data brokers.

2.3 Listing and commerce content

DataPurpose
Listing title, description, price, photos, categoryMarketplace
Listing status, expiry, boost timestampsLifecycle and monetization
Banner ad creative, link URL, campaign statsAdvertising program

2.4 Communications

DataPurpose
Direct messages between buyers and sellersContact, safety, abuse prevention
Reports, blocks, moderation notesTrust and safety
Support emailsCustomer support

2.5 Payment-related data

We use Stripe for boosts, premium subscriptions, and banner ads. We receive payment status, customer IDs, and transaction metadata — not full payment card numbers (Stripe stores those).

2.6 Verification and badges

DataPurpose
`.edu` email (college badge)Student badge verification
OTP hashesCollege email verification (not plain codes in long-term storage)

2.7 Device and usage data

DataPurpose
Device type, OS, app versionDiagnostics
IP address (server logs)Security, fraud prevention
Product analytics eventsImprove the Service (e.g., PostHog)
Push notification tokenOptional alerts (e.g., listing expiry)
Advertising ID (if AdMob enabled)Ad serving per Google/AdMob policies

2.8 Information from third parties

ProviderData received
GoogleSign-in profile (name, email, photo)
StripePayment and subscription status
MapboxGeocoding results for ZIP
Google AdMobAd interaction data (when ads enabled)
Email provider (e.g., Resend)Delivery status for college OTP emails

3. How we use information

We use information to:

  • Provide and improve the Service (feed, listings, messages, search)
  • Authenticate users and prevent fraud
  • Process boosts, premium, and banner payments
  • Enforce Community Guidelines and respond to reports
  • Send transactional SMS (phone verification) and service notifications
  • Comply with law and protect rights, safety, and property
  • Analyze aggregated usage to improve product decisions
  • We do not sell your personal information. We do not use your data to run a national classifieds index — discovery stays ZIP + radius bounded.


    4. How we share information

    RecipientWhy
    SupabaseDatabase, auth, storage, edge functions
    StripePayment processing
    MapboxZIP geocoding
    GoogleSign-in; AdMob when enabled
    Analytics provider (e.g., PostHog)Product metrics
    Email providerCollege verification emails
    Law enforcement / regulatorsValid legal process or to protect safety
    Business transfersMerger, acquisition, or asset sale (with notice where required)

    We may share public profile and listing content with other users as part of the Service (for example, seller name on a listing).


    5. Your choices and privacy rights

    Depending on where you live (including California, Colorado, Virginia, and other U.S. states with privacy laws), you may have the right to:

  • Access personal information we hold about you
  • Correct inaccurate information
  • Delete your account and associated data
  • Opt out of certain processing (where applicable)
  • Appeal a denial of a privacy request (where applicable)
  • How to exercise rights: email support@twentylist.app or use in-app Delete account in Settings. We will verify your request and respond within timelines required by law (for example, 45 days under CCPA).

    Account deletion cancels subscriptions where possible, removes your profile, and triggers deletion of listings and content per our retention schedule.

    We do not discriminate against you for exercising privacy rights.

    5.1 State-specific notices

    Some U.S. states require additional disclosures. If required by law, we will publish supplements at https://twentylist.app/privacy/states.


    6. Retention

    Data typeTypical retention
    Active listingsUntil expired, sold, or deleted
    Expired listingsRemoved from feed day 14; hard delete day 21 (images included)
    Account profileUntil you delete your account
    Direct messagesWhile accounts are active, plus up to 90 days after account deletion for safety and abuse investigations
    Moderation logs~1–2 years for safety and legal defense
    Phone verification metadataWhile account is active
    College badge dataUntil badge expires + grace period
    Stripe/billing recordsAs required for tax and fraud (often ~7 years)
    Terms acceptance recordWhile account exists + legal hold period

    We may retain information longer when required by law or to resolve disputes.


    7. Security

    We use technical and organizational measures including encryption in transit, access controls, and database row-level security. No system is 100% secure. Protect your Google account credentials.


    8. Children's privacy

    The Service is not directed to children under 18. We do not knowingly collect personal information from anyone under 18. Contact support@twentylist.app to request deletion if you believe a child provided data.


    9. International users

    TwentyList is operated from the United States. If you access the Service from elsewhere, your information may be processed in the U.S. where privacy laws may differ from your country.


    10. Cookies and similar technologies

    The mobile app does not use browser cookies. Our website (if any) and analytics providers may use cookies or similar technologies — disclosed on our website when published.


    11. Changes to this Policy

    We will post updates with a new "Last updated" date. Material changes may be notified in-app or by email. Continued use after notice means you accept the updated Policy where permitted by law.


    12. Contact

    Privacy: support@twentylist.app

    Support: support@twentylist.app