Privacy Policy
Effective date: 2025-08-13
Sublyst, Inc. ("Sublyst", "we", "us") operates a two-sided marketplace for off-campus housing and related items. This Policy explains how we collect, use, share, and protect information when you use the Sublyst apps and website.
Information we collect
- Account and verification: name, academic email, university domain verification, profile details, avatar.
- Listings and marketplace content: property details, availability, prices, photos; item details and photos.
- Communications: messages/chats and related metadata; notifications you receive and interact with.
- Device and technical: device ID, OS, app version, IP address, server logs, Firebase Cloud Messaging (FCM) token.
- Location: approximate or precise location if you grant permission (used for nearby campus search and local discovery).
- Media: photos you choose to upload for listings, marketplace items, and profile.
- Cookies/local storage: local storage to maintain sessions and preferences.
How we use information
- Provide core features: authentication, listings, messaging, notifications.
- Show relevant results and nearby options using location (if permitted).
- Safety, security, and fraud prevention.
- Service communications and updates.
- Comply with legal obligations.
Legal bases (EEA/UK)
- Consent: push notifications, precise location, certain communications.
- Contract: operating the marketplace and messaging you request.
- Legitimate interests: security, service analytics via server logs.
- Legal obligation: compliance with applicable law.
Sharing and disclosure
We do not sell personal information.
- Service providers: Firebase Cloud Messaging (push notifications); Google Cloud Storage (hosting images); Google Sign‑In; hosting/infrastructure and email providers.
- Other users: your profile, listings, marketplace items, and public photos are visible as you publish them.
- Legal and safety: to comply with laws, enforce Terms, or protect rights, safety, and property.
- Business transfers: data may transfer as part of a merger, acquisition, or asset sale.
Data retention
- Account, profile, listings, items, and messages: retained while your account is active. We may retain necessary records for a reasonable period after deletion for fraud prevention, legal compliance, and auditing.
- Device tokens: retained until revoked/expired or you disable notifications/logout.
- Logs/IP: short‑term retention for security and troubleshooting.
Your choices and rights
- Disable location and notifications in device settings at any time.
- Access, correction, deletion: email sublyst.ai@gmail.com. Account deletion removes or anonymizes personal data except where retention is required by law or legitimate interests (e.g., fraud prevention).
- EEA/UK rights: portability, objection, restriction—contact us to exercise.
- No in‑app payments; no third‑party analytics/crash tools.
International transfers
Your data may be processed in the United States and other countries. Where required, we use appropriate safeguards (e.g., Standard Contractual Clauses).
Security
Encryption in transit (HTTPS), hardened infrastructure, access controls, and least‑privilege practices.
Children’s privacy
Sublyst is not intended for children under 16. We do not knowingly collect data from children under 16.
Changes
We will post updates with a new Effective date. Material changes may be highlighted in‑app and/or by email.
Contact
Sublyst, Inc.
11A Linden Street, Allston, MA 02134, USA
Email: sublyst.ai@gmail.com
Jurisdiction‑specific (CCPA/CPRA)
Rights: know, delete, correct, and non‑discrimination. We do not sell or share personal information for cross‑context behavioral advertising. Authorized agents may submit requests to sublyst.ai@gmail.com.