1. Who we are

The service at babybarter.app is operated by BabyBarter. BabyBarter is responsible for the account and marketplace information described in this policy. You can contact us at babybarterhq@gmail.com.

The service is intended for adult parents and caregivers. You can browse public pages without an account; signing in is required for features such as posting listings, messaging, and managing your profile.

2. Information we collect

Please do not enter children’s full names, exact birthdays, schools, exact home addresses, sensitive documents, or other unnecessary private information in profiles, listings, photos, or messages. Our forms ask for broad family preferences rather than these details.

3. Google Sign-In

If you choose Google Sign-In, Google authenticates you and Supabase Auth processes the sign-in for BabyBarter. We use only basic account identity permissions. The corresponding basic OpenID Connect scopes are openid, email, and profile; our current Supabase authorization redirect explicitly requests email and profile, without an additional openid scope. Google may display equivalent basic userinfo email/profile scope names.

These permissions allow us to receive your Google account’s unique identifier, email address and email verification status, and basic profile information that Google provides, such as name, given/family name, profile picture URL, and, when supplied, language/locale. OAuth responses also contain the proof/tokens needed to complete authentication. Not every optional profile field is returned for every account.

BabyBarter does not request access to Gmail messages, Google Drive files, Contacts, Calendar, or other sensitive Google services. We do not receive your Google password.

We use the Google identifier and verified email to authenticate you, create or log into your BabyBarter account, associate the Google identity with the appropriate account, and protect account security. Supabase can link sign-in identities with the same verified email address. Basic profile information is stored with the authentication identity and can support account identification; your public BabyBarter display name is editable in your profile.

Google’s profile picture URL may be received as authentication metadata. It is not automatically used as your public BabyBarter profile photo: our setup flow asks you to upload one real photo of yourself as an adult.

Your Google email becomes your BabyBarter account email. It may also be used for operational account/marketplace emails and, when you choose billing or seller features, provided to Stripe for those services as described below. We do not use it for advertising.

4. Google User Data and Limited Use

BabyBarter’s use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

We use Google user data to provide and secure the account features described here. We do not sell Google user data, use it for personalized advertising, or use it to train general-purpose artificial intelligence models. Sharing is limited to providing these features through necessary service providers, with your consent where applicable, or when necessary for security or legal obligations. Access by authorized people is limited to support you request, security/abuse investigation, or legal requirements; Google account information is not made public merely because you sign in with Google.

5. Why we use information

We use account information to sign you in, maintain your session, confirm email addresses, recover accounts, and handle support. We use profile, listing and preference information to show relevant items, calculate nearby matches without publishing private coordinates, support trades and purchases, and deliver saved-search alerts you enable.

Messages and offers let participants arrange transactions and meetups. Payment records support subscriptions, seller payments, fees, refunds and billing history. Reports, blocks and technical logs help us address misuse, troubleshoot problems and protect the service. We do not access unrelated Google services for any of these purposes.

6. What other users can see

Public profile fields are your display name, uploaded profile photo, bio, general city/region, public-facing interests, reputation, and public membership information. Listings and their photos are public. Choose carefully what you include: other people can copy public information.

Your account email, approximate coordinates, search radius, private location and preference fields, saved searches and private account/payment records are not public profile fields. They are restricted to the owner and required server-side processing. Conversations, messages and offers are restricted to the relevant participants and required service operation; reports and blocks are restricted rather than published as public profile data.

Do not put private details into otherwise public text or images. Sharing something in a message makes it available to that conversation’s participants.

7. Service providers and other disclosures

Authorized BabyBarter operators may process information when necessary to support accounts, moderate reports, investigate abuse, or fulfill privacy requests. If you email us, your correspondence is also processed by the email service hosting our contact inbox. We may disclose information when legally required or necessary to protect users and the service. We do not disclose private account information to other marketplace users as a general public directory.

8. Where information is stored; browser storage

Production account and marketplace records are stored in BabyBarter’s Supabase production project in the U.S. East region. Google identifiers, email addresses and returned profile metadata are stored in Supabase Auth’s user/identity records; the BabyBarter account is associated with its Supabase user ID. Uploaded photos are stored in Supabase Storage. Email, payment and technical records are also processed/stored by the applicable providers above, whose infrastructure may operate in other locations.

Your browser stores the Supabase authentication session so you can stay signed in and tokens can refresh. OAuth proofs/tokens are processed as part of completing sign-in and may be present in that initial session; BabyBarter does not use them to retrieve additional Google service data. The app also uses local storage for relevant device choices and a service worker/cache for website assets. Signing out clears the app’s active authentication session; shared-device users should also clear site data when needed.

Uploaded photos are resized and re-encoded by the frontend to remove camera EXIF metadata before upload. Details visible in a photo itself are still visible to its audience.

9. Sale, advertising and affiliate links

BabyBarter does not sell personal information or Google user data, and does not use Google user data for advertising. The current website does not include an advertising tracking SDK or third-party analytics tracker.

Some product suggestions are affiliate links, for which BabyBarter may earn a commission. These suggestions can relate to the item category you are viewing. We do not append your Google identity, email or private profile information to affiliate links. If you choose to visit an external retailer, that retailer’s own privacy policy and tracking practices apply.

10. How long information is retained

We keep account/Google identity information and associated marketplace activity while needed to provide your account and the service, until you request deletion or the information is otherwise removed. Closing a browser or signing out does not delete your account. We do not currently promise automatic deletion of inactive accounts after a fixed period.

When handling a deletion request, we may retain records needed for legal/accounting obligations, payments/refunds/disputes, fraud prevention, safety investigations, or to document the request. We limit retained information to those purposes. Provider logs, backups and transaction records may remain subject to provider retention and applicable obligations rather than disappearing immediately. We cannot delete copies of public information independently saved by other people.

11. Request account or data deletion

Email babybarterhq@gmail.com with the subject “BabyBarter account deletion,” preferably from your account email address. Tell us whether you want your account deleted or a particular item of data removed. We verify account ownership, review the request, and explain any records we must retain. Do not send us your password, Google password, card details or identity documents with the request.

This is a request-based process; the website does not currently provide an automatic account-deletion button. Mention any active BabyBarter+ membership or pending transaction so billing and required transaction records can be handled appropriately. You can separately cancel membership through the billing portal.

You can also remove BabyBarter’s access in your Google Account’s third-party connections settings. Revoking Google access prevents further Google authorization but does not itself delete BabyBarter data or cancel a subscription; send the deletion request above as well if that is what you want.

12. Security

We use HTTPS, Supabase-managed authentication and database access controls, ownership/participant checks, row-level security and restricted public profile fields. Private API credentials are kept in server-side configuration rather than frontend variables. Payment credentials are handled by Stripe. These controls reduce unauthorized access but no system can guarantee absolute security.

Protect your sign-in credentials, use a strong password for email/password login, sign out on shared devices, and report suspected account misuse to our contact address. A profile photo helps recognition at a meetup; it is not identity verification or a guarantee of safety.

13. Children’s privacy

BabyBarter is for adults, not for children to create accounts. We do not knowingly collect personal information directly from children under 13. Broad age ranges supplied by adult caregivers help match items; they are private preferences, not a request for a child’s identity. The public profile photo must be of the adult account holder.

If you believe a child has provided personal information or that unnecessary identifying information about a child has been posted, contact babybarterhq@gmail.com so we can investigate and remove it as appropriate.

14. Your rights and choices

You can browse without signing in, choose email/password instead of Google Sign-In, edit your profile and preferences, replace your profile photo, manage listings and saved alerts, block/report other users, decline browser location permission, sign out, and cancel BabyBarter+ through the billing portal. Essential account/security and transaction emails may still be needed to operate your account.

Depending on your location, you may have rights to access or receive a copy of your data, correct it, request deletion, or object to or restrict certain processing. Send requests to our contact email. We verify ownership and respond subject to applicable requirements and necessary retention. If relevant, you may also contact your local privacy regulator.

15. Changes to this policy

We will update this page and its “last updated” date when our data practices change. For material changes, we will provide appropriate notice through the service or account email where required. Any future request for additional Google permissions would need separate disclosure and authorization.

16. Contact BabyBarter

For questions, privacy rights, security concerns or deletion requests, contact BabyBarter at babybarterhq@gmail.com.

The public Privacy Policy URL is https://babybarter.app/privacy.