Privacy notice
What you share, who can see it and how to ask for help with your information.
Updated draft
These revisions are being prepared for the next release. They have not taken effect. The agreement shown during account setup identifies the version you are asked to accept.
Read the preceding versionWho is responsible
SuperIC LLC operates Sandbrockshare. This notice covers information handled through the website, accounts, exchanges, support and launch-notification emails submitted from the public waitlist. It also explains limits in the current account tools so you can make an informed choice.
Contact us if you need access, correction, deletion or an explanation of a privacy decision. You can make a request without creating another account. Do not send a password, sign-in link or identity document in a support message.
Launch emails
You can leave an email address to be notified when Sandbrockshare opens, without creating an account. That address is not treated as a verified identity or as membership.
The waitlist form stores your request for a launch notice. It does not create an account or send email by itself. We have not established a complete automatic deletion schedule for every category. Ask support if you want that address removed.
Join the waitlist · Contact support · Email a privacy request
Account and residency information
Account information includes your email, account identifiers, profile name and any optional photo, biography, phone number or profile details you provide. Authentication and account state help us secure access and apply membership restrictions.
Residency applications include the address you give, location information used to check the neighborhood boundary, an adult attestation, the method you choose and the records needed to review it. References, mail-code delivery details, corrections, reasons and decisions may also be recorded.
The current residency process uses an adult attestation. It does not require a birth date or an uploaded identity document. Application addresses and evidence are kept separately from the public profile and limited to the applicant and authorized review functions. Residency access is logged.
Offers, exchanges and payments
We handle the offers, asks, images, messages, plans, agreement state and records you create while sharing. These may identify participants, timing, amounts, handoff details, payment status and changes.
Where payment features are enabled, Stripe handles payment details and provider onboarding. The service stores payment and connected-account references, amounts and status needed to operate payments, refunds, disputes and payouts. The website does not ask you to put full card or bank details into a message.
Information you post publicly may be copied by others. Keep addresses and personal contact details out of public listing descriptions, images and asks.
Public information and private conversations
Listing information and selected profile fields can be publicly readable, including outside a signed-in session. Uploaded avatar images use public image URLs. Do not treat a profile or its photo as confidential.
Conversation access is based on participation and may include more than two people. Authorized operational access may be needed to investigate abuse or support a request. Do not use messages to store credentials or sensitive documents.
The private residency process does not establish privacy for every exchange location. Some existing listing location fields are still broadly readable. Until those controls are replaced, do not enter a home address or precise private pickup coordinates in public listing fields.
We are working toward permission-based, time-limited location sharing. That work is not a promise that existing listing coordinates already have those protections.
Support requests and abuse prevention
Support saves the topic and message you submit, an optional reply email, and any applicable account or authorized exchange reference. Request identifiers and receipt records let you check whether a submission was saved without sending it again.
Choosing no contact omits the reply email and account association from that request. The message itself and an abuse-prevention network identifier are still recorded. It is not an untraceable channel; avoid including information you do not want to share.
The network identifier is produced with a keyed transformation rather than saving a raw network address in the support request. Hosting and delivery services may separately process connection information as part of operating the website.
Cookies and storage on your device
Authentication uses session cookies. The site also uses browser storage for preferences, limited recovery identifiers and certain unfinished drafts. Support recovery stores request metadata rather than your message or reply email. Other forms, such as listing drafts, may retain typed draft fields in the current browser session.
The cookie notice records dismissal in your browser. Dismissing it is not consent to optional advertising tracking. Clearing browser storage or using another device can remove recovery information and unfinished drafts.
The website may cache public pages for loading and connection recovery. Sign out on a shared device and do not rely on browser storage as a permanent copy of a request or agreement.
Service providers and disclosure
The service uses Supabase for account, database and storage functions, Stripe for enabled payment functions, and Resend for enabled email delivery. Website hosting also processes requests needed to deliver the service. Each provider receives the information needed for its role.
When enabled, Sentry receives error and performance diagnostics, which can include page or request references and information about the browser or device. Session recording is disabled in the current source configuration. Operational settings and data minimization still require verification before release.
We may disclose relevant information when required by law or necessary to investigate abuse, protect people or resolve a transaction. This does not make private application information generally available to neighbors, an HOA or a developer.
Selling personal information, advertising targeting and public trust scores are not part of the adopted product. Optional measurement needs its own reviewed configuration and disclosure before activation.
Retention and the current account tools
Records may be needed to operate an account, fulfill an agreement, investigate a case, reconcile a payment or meet a legal obligation. We have not established a complete automatic deletion schedule for every category. An expired code or closed request does not by itself prove that its record has been erased.
The current account export is incomplete. It includes selected account and exchange records and may omit newer residency, ask, support and policy records. Request a fuller copy through support if the download does not cover what you need.
The current account deletion action closes sign-in access, hides listings and clears some profile information. It does not yet erase the authentication identity, uploaded files, conversations and all other records. Request deletion through support and identify any records or concern you want addressed; do not assume a closed login means complete erasure.
A deletion request may need to preserve information for an unresolved obligation or applicable law. Ask us to identify what remains, why it is retained and what can be removed.
Requests, corrections and review
You can ask for a copy, correction or deletion of your information, or an explanation of how it is used. We may need enough information to verify that the request concerns you, without collecting unnecessary details.
If you disagree with a privacy decision, reply with the request reference and ask for review. Explain what you believe is missing or incorrect. Rights and deadlines can depend on the laws that apply; this notice does not limit those rights.
Contact support · Email a privacy request · Texas Attorney General: consumer privacy rights
Children and sensitive information
Accounts and exchange commitments are for adults. Do not create an account for a child or post a child's identifying details. Children shown in illustrations do not represent account eligibility.
Contact support if you believe a child's information or another person's private information has been submitted improperly. Include a link or reference when possible, rather than copying the sensitive material into another message.
Changes to this notice
A material change receives a distinct revision. Account setup identifies the notice being acknowledged. This updated draft does not backdate consent, establish legal review or activate a new data use.