Privacy Policy
The short version
We collect your email address (or phone number, if you choose phone sign-in) so you can sign in. We collect listing and transaction data so the marketplace can function. Stripe handles payments. We never see or store your card number. We do not sell your data. On the website (never in the iOS app) we use one advertising-measurement tool, the Meta Pixel — what it collects and how to opt out is in Section 7.
1. Who we are
TeeBox Market ("TeeBox", "we", "us", "our") operates a peer-to-peer marketplace for golf equipment, apparel, and accessories, available as a website and as a mobile application. This Privacy Policy explains what personal information we collect about you when you use the TeeBox app or website, how we use it, and the choices you have.
If you have any questions about this policy or how your data is handled, contact us at legal@teeboxmarket.com.
2. Information we collect
Information you give us
- Account information. When you create an account we collect your email address and password (passwords are stored as a salted hash by Firebase Authentication; we cannot read them). If you choose phone-number sign-in instead, we collect your phone number for verification.
- Profile information. A display name, optional profile photo, optional short bio, and an optional location (a free-text city/state you type in, not read from your device's GPS), if you choose to add them. You can also optionally add a golf handicap, a list of clubs in your bag, and pin one of your listings to the top of your profile.
- Listings. When you list an item for sale we collect the title, brand, category, condition, asking price, description, and photos you upload.
- Transactions. When you buy or sell, we record the listing, price, buyer/seller IDs, order status, shipment tracking number and carrier (when the seller provides one), timestamps, and any messages exchanged.
- Shipping address. When you buy an item, you provide a shipping address via Stripe's secure checkout. The address is stored on the order record and shared with the seller for fulfillment. It is never shared with any other party.
- Messages. Direct messages between buyers and sellers are stored so the recipient can read them when they next open the app.
- Reviews and ratings. After a completed sale, buyers can leave a star rating and written review of the seller. Reviews are public on the seller's profile.
- Watchlist and saved searches. Items you favorite ("watch") and search terms you save are stored on your account so you can find them again. You can opt in to push notifications when a new listing matches a saved search.
- Game scores. If you play the daily Logo Bingo game, your score and display name appear on a public leaderboard.
- Support communications. Email or in-app messages you send us about a problem or question.
Information collected automatically
- Authentication tokens. A Firebase Authentication session token so you stay signed in.
- Device and connection data. Standard server-side request logs (IP address, user agent, timestamp) used to detect abuse and operate the service. These logs are kept for a limited period and are not used to build advertising profiles.
- Push notification tokens. If you grant notification permission, we collect a Firebase Cloud Messaging (FCM) device token and a truncated user-agent string. The token is stored at
users/{uid}/fcmTokens/{token}and used to send new-message alerts, price-drop alerts, order updates, and saved-search matches. Tokens that fail delivery are pruned automatically, you can revoke notifications at any time in your OS settings, and all tokens are deleted when you delete your account.
Information we do not collect
- We do not collect your precise location.
- We do not collect your contacts, calendar, photos library, microphone audio, or health data.
- The iOS app contains no third-party advertising SDKs or trackers. On the website we use one advertising-measurement tool (the Meta Pixel — see Section 7); beyond that we do not track you across other apps or websites.
- We never see or store your full credit card number. Payments are processed entirely by Stripe.
3. How we use your information
- To create and authenticate your account.
- To display your listings to other members and let buyers contact you.
- To process payments, payouts, and refunds through Stripe.
- To deliver receipts, order updates, and security notifications.
- To detect, investigate, and prevent fraud, abuse, counterfeit listings, and policy violations.
- To respond to your support requests.
- To comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information. On the website we share limited browsing and purchase events with Meta Platforms for advertising measurement and audience building (never your name or email — see Section 7), and you can opt out at any time via the Do Not Sell or Share toggle or the Global Privacy Control signal.
4. Who can see what
- Public: Your listings, seller display name, profile photo, bio, profile location (if you set one), and seller profile (ratings, reviews, completed sales count) are visible to anyone using TeeBox.
- Private to you: Your email address, phone number, password, and payout details are never shown to other members.
- Visible to the other party in a transaction: Once an order is placed, the buyer's shipping address (entered at checkout via Stripe) is shared with the seller so the item can be shipped, and basic order information (item, price, status, tracking number) is shared between the buyer and seller.
- Conversations: Messages are visible only to the two members in the conversation.
5. Service providers we share data with
We use a small number of trusted service providers ("subprocessors") to operate TeeBox. We share with them only the information they need to perform their function, and they are contractually bound to use it only on our behalf.
- Google Firebase. Authentication, database, file storage, push notifications, and serverless functions. Firebase Privacy
- Stripe. Payment processing, payouts to sellers, and Pro Seller subscription billing. Stripe receives the payment information you enter at checkout directly. Stripe Privacy · Stripe DPA
- Stripe Identity. For high-value seller verification, captures a selfie and a photo of your government-issued ID for identity verification. This data goes directly to Stripe and is not stored on TeeBox servers (see Section 6). Stripe DPA
- Google Cloud Vision (SafeSearch). Every uploaded listing photo is automatically scanned for adult, violent, or otherwise prohibited content. Photos are sent to Google Cloud Vision for analysis and not retained by Google beyond that request. Google Cloud DPA
- Anthropic (Claude). If you use the optional AI listing-draft feature, your listing category, any specs you have entered, and up to four of your listing photos are sent to Anthropic's Claude API to suggest a title, description, condition, specs, and a price range. Opt-in — it runs only when you tap the draft button, suggestions are always editable, and nothing publishes automatically. Anthropic Commercial Terms
- Resend. Transactional email delivery (account verification, receipts, password resets, order updates). Resend receives your email address, display name, and the body of the email being sent. Resend DPA
- Plausible Analytics. Cookieless, privacy-preserving pageview analytics. Plausible receives the page URL, referrer, and a country-level location derived from a hashed IP. No cookies are set and no cross-site identifier is used. Plausible DPA
- Meta Platforms (Meta Pixel) — website only. Advertising measurement and audience building. The pixel sends Meta information about your visit — pages viewed, listings viewed, searches, items you like, checkouts started, and purchases (order total only; never your card details, name, or email) — together with your IP address and browser information, and sets cookies in your browser. Meta may connect this with your Meta account and use it as described in Meta’s Privacy Policy. The pixel is not present in the iOS app, and it never loads if you use the Do Not Sell or Share opt-out or the Global Privacy Control signal.
- PostHog. Product analytics (web + iOS): pages viewed and actions taken in the app (searches, listings opened, checkouts started), tied to your account ID. No card details are ever sent. Used to understand and improve the product. PostHog DPA
- Apple App Store / Google Play. App distribution and crash reporting (only if you've opted into device-level diagnostics in your OS settings).
High-sensitivity data: Stripe Identity
Sellers who request identity verification (typically required for high-value listings or higher payout limits) submit a selfie and a government-issued photo ID. This biometric and identity data is captured by Stripe Identity's hosted flow and transmitted directly to Stripe. TeeBox never stores the selfie or ID image on its own servers. TeeBox only receives the verification outcome (pass / fail / pending) and a Stripe verification session ID. Retention of the selfie and ID image is governed by Stripe's policies; see the Stripe DPA and Stripe Privacy Policy for details.
Pro Seller subscription billing
Pro Seller is an optional $14.99/month subscription billed through Stripe. Subscribing creates a Stripe Customer record with your billing details and invoice history; the subscription state (active, past-due, canceled) is mirrored to your TeeBox user record so we can display the correct features. Refunds for subscriptions purchased on iOS via the App Store are handled by Apple per their policies. See support.apple.com/HT204084. Refunds for subscriptions purchased on the web are handled by TeeBox and Stripe on a case-by-case basis.
We may also disclose information when we have a good-faith belief it is required by law (subpoena, court order, lawful regulatory request) or necessary to protect the safety of our users.
6. Data retention
We keep your account information for as long as your account is active. Account deletion is processed immediately upon request. When you delete your account from inside the app (Account → Delete Account) or by emailing us, your profile, listings, messages, watchlist, saved searches, and FCM tokens are removed right away. We retain certain records (orders, tax records, payout records, and dispute records) for up to 7 years as required by law and to preserve marketplace integrity. Public listings you posted may remain visible in archived form (with the seller name removed) where another user has interacted with them, to preserve the integrity of historical orders.
7. Cookies and similar technologies
TeeBox uses a minimal set of storage technologies. On the website, one advertising-measurement tool (the Meta Pixel) sets cookies; everything else is essential or cookieless, and the pixel itself can be switched off below.
- Essential / functional. Firebase Authentication persists your sign-in using browser
localStorageon the web and in secure in-memory storage on iOS. Stripe sets its own cookies onjs.stripe.comwhen you reach a payment screen. These are third-party cookies required to process the payment securely. - Analytics. Plausible Analytics is fully cookieless and does not set any identifier in your browser.
- Advertising measurement (Meta Pixel) — website only, never in the iOS app. We use the Meta Pixel, a tool from Meta Platforms, Inc., to measure how well our advertising works and to build advertising audiences. The pixel sets cookies and sends Meta information about your visit: pages viewed, listings viewed, searches, items you like, checkouts started, and purchases (order total only — never card details, your email, or your name), together with your IP address and browser information. Meta may connect this with your Meta account and use it as described in Meta’s Privacy Policy. To opt out: use the toggle below, enable Global Privacy Control or third-party-cookie blocking in your browser, adjust your Meta Ad Preferences, or use the industry tool at optout.aboutads.info.
Do Not Sell or Share My Personal Information
Setting this switch turns the Meta Pixel off in this browser: the pixel will not load or send anything on your future page views here. Your choice is stored on your own device (a tb_dnsps flag in localStorage and a first-party cookie) — clearing your browser data resets it. It applies per browser, so set it on each device you use.
8. Your rights
Regardless of where you live, you can:
- Access. Request a copy of the personal information we hold about you.
- Correct. Fix any information that is inaccurate.
- Delete. Request that we delete your personal information. You can also delete your account directly from inside the app under Account → Delete Account.
- Object / restrict. Ask us to stop or limit certain uses of your information.
- Portability. Receive a copy of your data in a structured, machine-readable format.
To exercise any of these rights, email legal@teeboxmarket.com from the email address associated with your account. We respond within 30 days.
9. California privacy rights (CCPA / CPRA)
This section is a Notice at Collection for California residents under Cal. Civ. Code §1798.140. It describes the categories of personal information we collect, where we get it, why we use it, and whether we sell or share it.
Categories of personal information we collect
- Identifiers. Name, email address, phone number (optional, only if you choose phone sign-in), Firebase UID, and IP address (server-logged). Source: you, and automatically from your device. Purpose: account creation, authentication, fraud prevention. Sold: No. Shared: your IP address and browser information accompany Meta Pixel events on the website (see Section 7); nothing else.
- Customer records. Shipping address (collected at checkout via Stripe) and billing information (collected by Stripe). Source: you, via Stripe's checkout. Purpose: to deliver purchases and process payments. Sold/shared: No.
- Commercial information. Purchase history, watchlist, saved searches, and listing activity. Source: you, through your use of TeeBox. Purpose: operate the marketplace and personalize your experience. Sold: No. Shared: purchase and checkout events (order total, listing ID — never card details) with Meta Platforms for advertising measurement, website only (see Section 7).
- Internet or other electronic network activity. App usage and aggregate pageview data (via Plausible, anonymous and cookieless), and — on the website — browsing events sent to the Meta Pixel (pages viewed, listings viewed, searches). Source: automatically from your device. Purpose: product improvement; advertising measurement (Meta, website only). Sold: No. Shared: Yes, with Meta Platforms for cross-context behavioral advertising — opt out via the Do Not Sell or Share toggle or GPC.
- Geolocation data. Country-level only, derived from your IP address. We never collect GPS or precise location. Source: automatically from your IP. Purpose: coarse analytics and fraud signals. Sold/shared: No.
- Inferences. Drawn from your listing activity (for example, an AI price suggestion based on the item you are listing). Source: derived by us from data you provide. Purpose: the AI assist features you choose to use. Sold/shared: No.
- Biometric and identity information (sellers only, optional). A selfie and a government-issued photo ID, collected only if you request seller identity verification. This data goes directly to Stripe Identity and is not stored on TeeBox servers. Source: you, via Stripe Identity. Purpose: identity verification for high-value seller activity. Sold/shared: No.
Selling and sharing of personal information
TeeBox does not sell your personal information. As of September 21, 2026, we share limited website browsing and purchase events with Meta Platforms for cross-context behavioral advertising (advertising measurement and audience building), as “share” is defined under the California Consumer Privacy Act and California Privacy Rights Act (Cal. Civ. Code §1798.135). You can opt out at any time using the Do Not Sell or Share My Personal Information toggle in Section 7 or the Global Privacy Control signal. The iOS app shares nothing for advertising.
Global Privacy Control (GPC)
TeeBox honors the Global Privacy Control browser signal as a valid opt-out of sale/sharing: when your browser sends GPC, the Meta Pixel does not load at all — no toggle needed.
Exercising your California rights
California residents may request to know, correct, delete, or receive a portable copy of their personal information, and may not be discriminated against for exercising these rights. To make a request, email legal@teeboxmarket.com from the address on your account. We will verify your identity through the email or in-app account you control before fulfilling the request.
10. Children
TeeBox is not directed to children under 13 and we do not knowingly collect personal information from children under 13. If you believe a child has signed up for TeeBox, contact us and we will delete the account.
11. Security
We use industry-standard safeguards to protect your information, including encryption in transit (HTTPS), encryption at rest (Firebase / Stripe), salted password hashing, and least-privilege access controls. No system is perfectly secure. If we ever discover a breach affecting your data, we will notify you and the appropriate authorities as required by law.
12. International transfers
TeeBox is operated from the United States. If you access TeeBox from outside the US, you consent to your information being transferred to and processed in the US, where data protection laws may differ from those in your country.
13. Changes to this policy
We may update this policy from time to time. When we make a material change, we will update the "Last updated" date at the top of this page and notify users in the app. Your continued use of TeeBox after a change means you accept the updated policy.
14. Contact
Questions, requests, or complaints? Reach us at:
- Email: legal@teeboxmarket.com
- General support: support@teeboxmarket.com