Privacy Policy
The short version
- We collect what a job needs and very little else.
- We do not sell your information, and we do not share it for advertising. There is no ad business here to feed.
- A customer's exact address is hidden from a business until they accept the job.
- A crew member's live position is visible only to the customer whose job is active — never on a public map, never to other crew.
- We store a hash of an IP address rather than the address itself wherever we only need to tell repeat visitors apart.
- You can ask us for your data or ask us to delete it, and we will do it.
1. What we collect
If you are a customer
- What you type when you send a flare: your name, phone number, what you need, when you want it, and an address if the job needs one.
- Your approximate location, only if you allow your browser to share it, and only to centre the map and work out who covers you. If you say no, the map defaults to downtown Detroit and everything still works.
- What you did on the site: which businesses you looked at, which flares you sent, whether a QR code brought you here.
- Your review, if you leave one.
You do not need an account to use Flare as a customer. We do not ask you to make one.
If you are a business
- Account details: your name, your business name, email, phone, the city you work from, and the areas you cover.
- Verification documents: EIN or business registration, certificate of insurance, trade licence where one applies. These are the most sensitive things we hold and they are treated accordingly — see section 4.
- Your crew: the names you enter for seats, their hourly rate if you choose to record one, and background-check status if you have bought that service. We do not store background-check reports. We store whether the result was clear, when it was done and when it expires. Michigan seals records, and cached results go stale in a way that becomes a liability.
- Your work: jobs, prices, times, photos, mileage, and the money figures the console computes from them.
- Live position of a crew member's device, while they are on an active job and their app is open.
Automatically, from anybody
- Standard request information: browser type, pages requested, timestamps.
- A salted hash of your IP address. Not the address. It is enough to tell one person scanning a QR code ten times from ten people scanning once, and enough to rate-limit abuse. It is not enough to identify or locate you.
What we deliberately do not collect
- No payment card details, ever. A customer pays the business directly, by whatever method that business uses. Card data does not touch Flare's servers at any point. When we start charging businesses for subscriptions, that will run through Stripe's hosted checkout and the card details will go to Stripe, not to us.
- No social security numbers, no dates of birth, except where a background-check provider requires them, in which case they go to that provider and are not retained by us.
- No third-party advertising or analytics trackers. There is no Google Analytics, no Meta pixel, and no advertising cookie on this site.
2. Why we have it
| What | Why |
|---|---|
| Your flare details | So a business can turn up and do the job |
| Your address | Given to the business only once they accept |
| Location | To show who covers where you are |
| Verification documents | To check a business is real and insured before letting it near a customer |
| Job and money records | So a business can run its books, and so a dispute two years from now can be settled |
| Live crew position | So the customer whose job is active can see how far away they are |
| Hashed IP | Rate limiting and abuse prevention |
| Email address | Job notifications, invoices, and telling you when these terms change |
We do not use any of it to build an advertising profile.
3. Who else sees it
The business you contacted sees your name, phone, what you need, and — after they accept — your address.
Nobody else on Flare sees your details. Businesses cannot browse customers.
Our service providers, each doing one job and contractually barred from using the data for anything else:
- Netlify — hosting and the database.
- Resend — sending email.
- Stripe — subscription billing for businesses, once it is switched on. Stripe receives card details directly; we receive a confirmation.
- A background-check provider — only for businesses that buy that service, and only the crew member's details needed to run the check.
- A telephony provider — only for businesses that buy masked texting, and only to connect a call or a message.
Law enforcement, only where we are legally required, and we will tell you unless we are legally prohibited from telling you.
A buyer of the business, if Flare is ever sold — in which case this policy travels with the data and you would be told before anything changed.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those phrases are defined under California law. We have never done so and there is no plan to.
4. How it is protected
- Verification documents are held in private storage and are reachable only through short-lived signed links. They are not publicly addressable, and a link that leaks stops working.
- Passwords are hashed inside the database. The plaintext never lands in a log, and the hash never travels over the network.
- Session cookies are signed, HTTP-only, and checked against a live session record on every single request — so signing out, or a seat being claimed on another phone, kills a session immediately.
- One seat, one device. Signing in on a second device signs the first one out.
- The money screens are owner-only, enforced on the server, not just hidden in the interface.
- Everything is encrypted in transit and at rest, with automated backups.
No system is perfect. If we ever have a breach that affects you, we will tell you promptly and tell you what actually happened.
5. How long we keep it
| What | How long |
|---|---|
| Job records, invoices, finder fees | Seven years. These are business records; a tax authority or a dispute can reach back |
| Your account, while it is open | Until you close it |
| A closed account | Public listing removed at once; records kept as above |
| Verification documents | While the account is open, plus two years |
| Live position pings | Thirty days |
| Hashed IPs in the rate limiter | One day, then swept automatically |
| Reviews | Kept, because removing them on request would make the ratings dishonest |
| Marketing emails | Until you unsubscribe |
6. What you can ask for
Whoever you are and wherever you live, you can ask us to:
- Tell you what we hold about you, and give you a copy.
- Correct anything wrong.
- Delete what we hold, except records we must keep for tax, accounting or dispute purposes — and we will tell you exactly what we kept and why.
- Stop emailing you anything that isn't about a job you are actually part of.
Email hello@flaredetroit.com. We answer within thirty days, usually much sooner. We will not charge you and we will not make you jump through hoops.
California residents: these are the rights the CCPA gives you, offered here regardless of whether Flare currently meets the thresholds that would require it. We do not discriminate against anyone for exercising them.
7. Cookies
Flare sets one cookie, flare_session, and only after you sign in. It holds a signed token that identifies your session. It is HTTP-only, secure and same-site. Deleting it signs you out.
We use browser local storage on your own device to remember small things like whether you dismissed a tip. That never leaves your device.
There are no advertising cookies and no third-party trackers, so there is no consent banner. That is the point of not having them.
8. Children
Flare is not for anyone under 18 and we do not knowingly collect information from children. If you believe a child has given us information, email us and we will delete it.
9. Where the data lives
Flare is operated from the United States and the data is stored in the United States. We do not currently offer the service in the European Union or the United Kingdom and do not market to people there.
10. Changes
If we change this policy in a way that materially affects you, we will email you at least thirty days beforehand and ask you to accept the new version. Every version is kept, numbered and dated.
Flare Metro Detroit, Michigan hello@flaredetroit.com
If you think something here doesn't match what the product actually does, tell us. That would be a bug, and we would want to fix it.