Skip to content

Privacy Policy

Last updated: August 13, 2026

This explains what FigStead LLC collects when you use FigStead, why, and what you can do about it. We've written it to be read rather than to be technically survivable, and it describes what the software actually does.

The short version

We collect what a marketplace needs to work: your email, what you list, what you buy, and what you say to other members. We never see your card number. We don't sell your data and we don't run advertising trackers. We use Google Analytics to count visits and see which pages get used — but only if you accept it when asked, never tied to your account, and never used to target advertising. Email us at shaqqani@duck.com to get your data or have your account deleted.

1. What we collect

Account: your email address, display name, optional public @handle, and optional avatar. Your password is stored only as an Argon2 hash — we cannot read it, and neither can anyone who obtains the database. If you sign in with Google we receive your email and basic profile from Google, not your Google password.

Optional details you choose to add: a phone number, only if you turn on SMS alerts; and a ZIP code, used to work out your USDA hardiness zone so listings can show whether a plant suits your climate.

Security data:the IP address you signed up from and most recently logged in from, session records, devices you've marked as trusted, and — if you enable two-factor authentication — your TOTP secret, encrypted at rest with AES-256-GCM, plus hashed backup codes. We keep short-lived rate-limit counters keyed to your IP to blunt brute-force attacks.

Marketplace activity: your listings and their photos, bids, offers, orders, shipment tracking numbers you enter, ratings you give and receive, saved searches, watched listings, favourited sellers, reports you file, and messages you exchange with other members.

Payment records: order amounts, fees, and Stripe identifiers. We never receive your card number — card details go directly from your browser to Stripe.

Delivery address:when you buy something that ships, Stripe or PayPal collects the delivery address on their own checkout page and passes it to us, and we store it on that order. We share it with that order's seller so they can post your parcel — that is the whole point of collecting it. It is not shown to anyone else, not added to your public profile, and not reused for any other order: each purchase records the address you gave at the time. Orders collected in person never ask for one.

2. What other people can see

Public to anyone, including people who aren't logged in:

  • Your display name, @handle and avatar
  • Your listings, their photos and descriptions
  • Your seller ratings and recommendation percentage
  • Completed sale prices. Sold listings and what they sold for appear in our public price history at /sold. If you don't want a sale price public, don't sell it here.

Your email address is never shown publicly. Your phone number and ZIP code are never shown publicly. Your delivery address is shown only to the seller of the order you gave it on. Private messages are private between you and the other member — but see the next section.

3. Administrator access

Site administrators can see account details, orders and — where a report has been filed or abuse is suspected — the contents of messages. This is how moderation and fraud investigation work, and we'd rather state it plainly than let you assume otherwise. Administrators are bound by the same rules; access for curiosity rather than cause is not acceptable use.

4. Who we share it with

We do not sell personal information, and we do not share it for advertising. We use these service providers to run the site, each receiving only what their job requires:

  • Stripe — payments, payouts and seller identity verification. Sellers provide Stripe with identity and bank details directly; we never see them.
  • Vercel — hosting and content delivery. Processes request metadata including IP addresses.
  • Neon — the managed PostgreSQL database where the data above is stored.
  • Cloudinary — storage and delivery of listing photos, seller-uploaded listing videos, and avatars.
  • Resend — transactional email (password resets, sale notifications, alerts).
  • Twilio — SMS, only if you opt in and provide a number.
  • Google — sign-in with Google, if you use it; reCAPTCHA on the signup, login and password-reset forms; Google Analytics, which receives the pages you visit along with the device, browser, referrer and approximate location (derived from your IP) that come with any web request; and YouTube, where a seller has linked a YouTube video on their listing (see below — a video the seller uploaded themselves involves no Google request at all).
  • Shipping carriers (USPS, FedEx, UPS, DHL) — tracking numbers are sent to the relevant carrier to look up delivery status.

We may also disclose information where legally required, or where necessary to investigate fraud or protect someone's safety.

5. reCAPTCHA

The signup, login and password-reset forms are protected by Google reCAPTCHA v3, which scores how likely a submission is to be automated. To do that it collects device and browser information and sends it to Google, subject to Google's Privacy Policy and Terms of Service. We use it only to tell humans from bots on those three forms, never to profile you or to target anything at you.

6. Analytics

Analytics runs only if you agree to it, and nothing analytics-related happens before you do. The first time you visit we ask, and until you accept, Google Analytics is not loaded at all — no Google script is fetched, no request is sent, and no analytics cookie is set. Choosing “Reject” keeps it that way permanently.

If you accept, we use Google Analytics to understand how the site is used — how many people visit, which pages and listings they look at, and where they arrived from. It tells us that a page was viewed, not who viewed it: we don't send your email, name, or account ID to Google, and we don't link analytics data to your FigStead account.

It then sets its own cookies and receives the page you are on together with the device, browser, referring site and approximate location (derived from your IP address) that accompany any web request. That data is handled under Google's Privacy Policy. We do not use it for advertising, remarketing, or building a profile of you.

You can change your mind at any time. Use the Cookie settingslink at the bottom of any page — it reopens the same choice, and switching to “Reject” deletes the analytics cookies already on your device and stops any further reporting. Independently of us, Google publishes a browser opt-out add-on, and any setting or extension that blocks analytics scripts will also stop it. Nothing on this site depends on analytics working.

7. Seller videos

A seller can attach a video to a listing in two ways, and they are very different for your privacy.

A video uploaded from the seller's own device is stored by us on Cloudinary and played from there. No third-party video service is involved and nothing is sent to Google, so watching it is the same, privacy-wise, as looking at a listing photo. Your browser fetches a still frame with the rest of the page and downloads the video itself only if you press play.

A YouTube videois a link to Google's service. We show it as a still picture with a play button, and the YouTube player is not loaded until you press play. Until you do, the only thing your browser fetches from Google is that one thumbnail image.

Press play and the video is loaded from youtube-nocookie.com, Google's privacy-enhanced embed host, which does not set tracking cookies for advertising purposes. Google still receives your IP address and browser details at that point, as it would for any video you watched, under its Privacy Policy. If you would rather not, simply don't press play — the listing, its photos and its description work without it.

8. Cookies

Most cookies here exist to make the site function: a session cookie that keeps you logged in; a short-lived cookie during two-factor sign-in; a cookie remembering a device you chose to trust; a state cookie protecting the Google sign-in flow against CSRF; and your light/dark theme preference.

Those are always on, because without them the site cannot log you in or remember your theme. They are the reason the banner asks only about analytics.

The one non-essential set is Google Analytics' own cookies, which recognise repeat visits. Those are set only if you accept, as described in the section above, and removed if you later reject. There are no advertising cookies and no cross-site tracking on this site.

9. How long we keep it

Account data is kept while your account is open. Order records, including amounts and Stripe identifiers, are kept after that where we need them for financial, tax and dispute purposes.

Some records survive deletion of your account because they belong to other people too: a rating you left on a seller, a completed sale in the public price history, and the other side of a conversation remain, with your account no longer identified by name.

10. Your choices and rights

You can edit your profile, change your email, add or remove a phone number, turn two-factor on or off, and manage notification preferences from your account settings at any time. Marketing and alert emails have an unsubscribe link; transactional messages about your own orders do not, because you need them.

Access and deletion: email shaqqani@duck.comand we'll provide a copy of your data or delete your account, subject to the retention exceptions above. We'll respond within 30 days.

Depending on where you live you may have additional statutory rights — for example under the California Consumer Privacy Act, or the Illinois Personal Information Protection Act. We extend the access and deletion rights described here to everyone regardless of location, because maintaining two standards isn't worth it at our size.

11. Security

Passwords are hashed with Argon2. TOTP secrets are encrypted at rest. The site is served over HTTPS with HSTS, a content security policy and strict framing rules. Authentication endpoints are rate-limited and protected by reCAPTCHA.

No system is perfectly secure, and we won't pretend otherwise. If a breach affects your personal information we will notify you as required by law. If you find a security problem, please tell us at shaqqani@duck.com before disclosing it publicly.

12. Children

FigSteadis for adults. It is not directed at children, and we don't knowingly collect information from anyone under 18. If we learn that we have, we'll delete the account.

13. Changes and contact

If we change this policy the date at the top changes with it, and we'll flag material changes on the site. Questions, requests, or anything you think this page gets wrong:

FigStead LLC
shaqqani@duck.com