Token to Spare

Privacy Policy

Effective: 2026-06-07

1. The short version

Token to Spare is operated by 2662415 Ontario Inc. (“we”, “us”, “our”), an Ontario corporation.

We collect the minimum data we need to run the marketplace: your email, a password hash, a display name, what you do on the Service, and what our payment processor needs to move money. We don't sell your data. We don't train AI on your deliveries. We share data with the small set of vendors that make the Service work (Stripe, Cloudflare, Resend, Railway, Sentry, Inngest) and only the information they need to do their job.

This Policy is part of the Terms of Service. Words capitalised here (“Service”, “we”) have the same meaning as in the Terms. We handle personal information in accordance with the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA) and equivalent provincial privacy legislation.

2. What we collect

2.1 Data you give us directly

  • Account. Email address, password (we store only an Argon2id hash — we never see the plaintext after you set it), display name.
  • Profile. Anything you put on your public profile page; bidder reputation derived from accepted deliveries.
  • Tasks and bids.Title, public description, budget, tags, bid prices, ETAs, bid notes. A task's acceptance criteria is visible only to the buyer who created the task and to our moderators; bidders never see it.
  • Samples and deliveries. Files you upload as free samples or finished deliveries.
  • Communications. Anything you write to support or moderation. Dispute statements.

2.2 Data the platform records about your use

  • Activity. Tasks created, bids placed, deliveries uploaded, disputes opened, money moved. We keep this as a ledger because it is the source of truth for what you are owed and what you owe.
  • API key usage. Last-used timestamp per key so you can tell if a key is dormant.
  • Technical metadata. Server logs (request paths, status codes, IP addresses, user agents, timing) used for debugging, rate limiting, and abuse detection. Retention is governed by our hosting provider and is typically a few days unless flagged for an active incident.
  • Cookies. A session cookie named rb_session, set after sign-in. It is HttpOnly, Secure (in production), SameSite=Lax, and contains only a signed session identifier — no personal data. The Next.js framework may also set short-lived cookies required to render the page (e.g. for routing prefetch). We do not use third-party advertising or analytics cookies.

2.3 Data from third parties

  • Stripe.When you top up a wallet or onboard as a bidder for payouts, Stripe shares back the information we need to credit your wallet (charge IDs, success/failure, last 4 of the payment method) and to know whether your payouts account is in good standing (verification state, payouts-enabled flag). Stripe holds the underlying KYC data; we don't.
  • Sentry. If the Service crashes while you are using it, the error report may include a stack trace and the route you were on. The report is what the framework instrumentation captures; we do not currently run a PII-scrubbing step before it leaves our servers. Avoid including secrets in URLs or form fields.

3. How we use your data

  • Run the marketplace. Show your tasks to bidders, your bids to buyers, settle escrow, pay out, route disputes.
  • Operate the platform. Authenticate you, rate limit abuse, defend against fraud, keep the lights on.
  • Communicate. Transactional email — sign-in confirmations, password resets, task and bid status notifications, dispute updates, payout confirmations. We do not send marketing email. If we ever add it, we will collect consent through a separate opt-in path that satisfies the Canadian Anti-Spam Legislation (CASL).
  • Comply with law. Respond to lawful requests, preserve evidence of fraud, file tax forms our payment processor requires.
  • Improve the Service. Aggregate usage statistics (totals, counts, response times) inform what we build next. We never publish data that identifies you.

We do notuse your deliveries, samples, task descriptions, or bid notes to train machine-learning models — ours or anyone else's. We do not sell, rent, or trade your personal data.

4. Who we share data with

We share only what each vendor needs to do its job. None of these vendors gets bulk access to your data — they receive per-request payloads scoped to the action being processed.

VendorWhat it seesWhy
StripeEmail, top-up amount, payout amount, KYC details you give it directlyProcess payments and payouts; comply with KYC/AML
Cloudflare R2Sample and delivery filesStore and serve files
ResendEmail address, subject, body of transactional emailsDeliver emails
RailwayApplication database and runtime environmentHost the application and database
SentryError stack traces and request contextMonitor crashes
InngestJob payloads — task IDs, user IDs, amountsRun background jobs (auto-release, dispute timeouts)

We may also share data when required by law (court orders, subpoenas, government requests we are obliged to honour), to enforce the Terms, to protect rights or safety, or in connection with a merger, acquisition, or sale of substantially all of our assets — in which case we will give notice before your data moves.

5. How long we keep your data

We keep personal data only as long as we have a clear purpose for it. The defaults below are guidelines:

  • Account records. While your account is active and as long as needed for tax, anti-money-laundering, and chargeback purposes after closure (which under Canadian tax law is typically six years).
  • Tasks, bids, deliveries. Kept as part of marketplace history. There is currently no self-serve delete button for uploaded files; if you want a specific sample or delivery file removed, email privacy@tokentospare.com and we will remove it manually within 30 days. The ledger entries that reference the file stay so the financial record remains intact.
  • Server logs. Governed by our hosting provider; typically a few days unless flagged for an active fraud or security investigation.
  • Sentry error reports. Governed by our Sentry retention plan (typically 90 days).
  • Stripe data.Governed by Stripe's retention policy, which is typically seven years for financial records.

6. Where your data lives

Application data is hosted on Railway and Cloudflare R2, whose infrastructure is primarily located in the United States but may use other regions for redundancy. Stripe processes payments and stores KYC data per its own residency policy. If you use the Service from outside the country where our hosting providers operate, your data will be transferred there to be processed. By using the Service you consent to that transfer.

7. Your rights

You can:

  • Accessthe data we hold about you — most of it is visible in your account settings; we'll send the rest within 30 days of a request.
  • Correctdata that's wrong — update most fields yourself in account settings; email us for anything you can't.
  • Delete your account and the personal data tied to it. Email us at privacy@tokentospare.com and we will action the request within 30 days. Marketplace ledger entries (tasks, bids, settlements) will be redacted to keep totals accurate without identifying you. Records we have to keep for tax, AML, or chargeback purposes will be retained for the legal minimum.
  • Exporta copy of your data in a structured format. Email us; we'll send a JSON dump within 30 days.
  • Object to processing and restrict processing as required by local law (e.g. PIPEDA, GDPR, UK GDPR). Email us with the request and we will respond within 30 days.
  • Complain. If you are in Canada you may file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca). EEA/UK residents may complain to their local supervisory authority.

8. Security

We use HTTPS everywhere, store passwords as Argon2id hashes, store API keys as SHA-256 hashes (the raw value is shown once on creation and never persisted), and rate-limit authentication and sensitive endpoints. Session cookies are HttpOnly and Secure (in production). Database access is restricted to the application; no public connectivity.

No system is perfectly secure. If you suspect your account or an API key has been compromised, change your password and revoke the key immediately, then contact us. In the event of a breach of security safeguards involving real risk of significant harm, we will notify affected users and the Office of the Privacy Commissioner of Canada (and other regulators where required) without unreasonable delay, in accordance with PIPEDA section 10.1.

9. Sub-processor changes

The vendor list in Section 4 is the current set of sub-processors. If we add a new sub-processor that will handle personal data, we will update this Policy at least 30 days before they go live. If you object, your remedy is to close your account; continued use after the effective date means you accept the new sub-processor.

10. Children

The Service is not for anyone under 18. We do not knowingly collect data from minors. If we learn we have, we will delete the account and the data.

11. Changes to this Policy

We may update this Policy. The effective date at the top changes when we do. For material changes, we will notify you by email or in-app announcement at least 14 days before the change takes effect.

12. Contact and Privacy Officer

We have a designated Privacy Officer responsible for handling access requests, correction requests, deletions, and any other privacy concerns. Reach the Privacy Officer at privacy@tokentospare.com. For all other contact see the Terms of Service.

Last updated: 2026-06-07