Privacy Policy
Privacy Policy
Effective date: August 7, 2026
The Consignory ("we," "our," or "us") provides tools for vintage and consignment shops, consignors, and customers to manage shop access, intake, inventory, holds, purchase requests, and related communications. This Privacy Policy explains how we collect, use, share, and protect information when you use The Consignory website, mobile app, and related services.
Boutique owners determine how they use the personal information they collect from their consignors and customers for boutique operations. The Consignory processes that information to provide the services the boutique requests. Separately, The Consignory determines how information is used for its own account administration, authentication, platform security, boutique subscription billing, diagnostics, support, legal compliance, and service improvement.
Information We Collect
We may collect the following categories of information:
- Account information, such as name, email address, phone number, username, and profile details.
- Shop information, such as boutique name, address, hours, website, social handles, staff, and setup details.
- Consignor and customer information, including consignor requests, relationship status, and contact details.
- Shipping information, including an optional saved recipient name, US street address, city, state, ZIP code, delivery notes, and the address snapshot attached to a shipping request.
- Inventory information, such as item titles, brands, categories, sizes, condition, pricing, notes, tags, photos, QR codes and barcodes, SKU or variant identifiers, inventory locations and quantities, hold state, purchase state, assigned consignors, and inventory imported from a connected Shopify account.
- Transaction-related information, such as hold fees, accepted hold-fee terms, boutique policy snapshots, purchase requests, shipping and tax quotes, fulfillment and shipment status, optional carrier and tracking details, refund status, Stripe, Square, or Shopify order and payment identifiers, order amounts, tax metadata, and payment processing metadata.
- Connected provider-account information, such as the selected payment or inventory provider, Shopify store domain, merchant and location identifiers, connection and synchronization status, granted permissions, token expiration metadata, and encrypted Square payment or Shopify authorization credentials.
- Appointment and intake information, including appointment times, intake decks, review decisions, and customer-provided item details.
- Form and agreement records, such as the date and time you accept our Terms or submit a form, your IP address, and browser or device information associated with the submission.
- Location and nearby-search information, such as precise or approximate foreground device latitude and longitude when you grant location access, the map area you choose, ZIP code or town searches, Google Places search queries and place identifiers, and returned address or map results.
- Notification and device identifiers, including an app-generated installation identifier, an Expo push token, the profile associated with that token, token status, and delivery or receipt information used to route and troubleshoot push notifications.
- Private storefront communications and safety records, including hold and purchase messages, sender and recipient identifiers, related request details, sent and read times, read state, blocking state, reports, report reasons and details, reported-message snapshots, moderation notes, and resolution history.
- Technical, diagnostic, and limited usage information, such as app and build version, device platform and model context, error messages, stack traces, crash or app-hang details, limited breadcrumbs, log data, and information used to improve reliability, performance, and security.
- Public website analytics, such as the page visited, visit time, external referring site, campaign tags, general device and browser category, and coarse country or region when provided by our hosting infrastructure.
- Support information, such as ticket subjects, messages, optional screenshots, boutique context, app version, device platform, and support response history.
How We Use Information
We use information to:
- Provide, maintain, and improve The Consignory.
- Create and manage customer, consignor, owner, and staff accounts.
- Verify user identity, authenticate accounts, and help secure account access.
- Help boutiques manage inventory, intake, appointments, holds, purchase requests, shipping quotes, fulfillment, refunds, and customer communication.
- Center the shop-discovery map, identify boutiques near a selected area, and provide location search suggestions and results.
- Process payments, payment holds, refunds, Stripe Connect, Square or Shopify OAuth setup, hosted Shopify checkout reconciliation, inventory synchronization, and related records.
- Display inventory, storefront, consignor, and request information to the users who need access to it.
- Send operational messages, such as account, invite, request, appointment, inventory, hold, purchase, refund, email, and push notifications.
- Deliver private hold and purchase conversations, maintain their read state, enforce user blocks, and investigate reports.
- Detect, prevent, moderate, and troubleshoot abuse, fraud, security incidents, and service errors.
- Respond to support tickets, investigate reported issues, and maintain a history of support responses.
- Maintain records of form submissions and Terms acceptance for security, recordkeeping, and agreement enforcement.
- Comply with legal, accounting, tax, regulatory, and App Store requirements.
How Information Is Shared
We share information only as needed to provide and operate the service:
- With boutiques and their authorized staff so they can manage shop operations, inventory, intake, consignors, holds, purchase requests, shipping, fulfillment, and refunds. A shipping address attached to a request is shared only with the applicable boutique and its authorized staff as needed to quote and fulfill that request.
- With customers and consignors when needed to show relevant inventory, request, appointment, account, or private conversation information. Private storefront messages are available to the conversation participants and may be reviewed by authorized The Consignory administrators when a message is reported or review is otherwise needed for safety, support, legal compliance, or service enforcement.
- With commerce and payment providers, including Stripe, Square, and Shopify, to support payments, hosted checkout, connected merchant or inventory accounts, catalog and quantity synchronization, orders, refunds, and payment compliance.
- With Google Places, through our Supabase-hosted location-search service, to process a ZIP code, town, or other location query and, when available, coordinates used as a location bias for more relevant suggestions and map results.
- With service providers that help us host, store, secure, monitor, email, and operate the service, including Supabase for database, authentication, nearby-shop queries, and the Google Places proxy; DigitalOcean for hosting and infrastructure; Sentry for mobile error and crash monitoring; Stripe and Square for payments; Shopify for connected inventory and hosted checkout; Google Places for location search; email providers; and Expo for push delivery through Apple Push Notification service (APNs) or Google Firebase Cloud Messaging (FCM).
- When required by law, legal process, safety needs, fraud prevention, or to protect the rights of The Consignory, users, boutiques, or others.
Service providers are authorized to access information only as necessary to perform services on our behalf and are expected to protect it appropriately.
When a customer submits a request to become a consignor for a boutique, the customer's email address and phone number are shared with that boutique so the boutique can contact the customer about becoming a consignor.
Location and Nearby-Shop Search
If you allow foreground location access, the mobile app may obtain your device's precise or approximate latitude and longitude, depending on your device settings. We send the selected search center to Supabase to return boutiques near that area. When you use the location search field, the query, a temporary search-session identifier, and, when available, coordinates used as a location bias are processed through our Supabase-hosted service and sent to Google Places to provide suggestions and map details. Google processes that information under its Privacy Policy.
Location access is optional. You can deny or revoke it in your device settings and search by ZIP code or town instead. We use this information for app functionality, including centering the discovery map and finding nearby boutiques. We do not use it for advertising, sell it, or use it to track you across apps or websites owned by other companies. We do not save device-derived coordinates as a persistent customer profile location, although our service providers may process request and security logs as needed to operate, protect, and troubleshoot the service.
Payments
Payment card information is entered in secure Stripe or Square interfaces embedded in the app, or in a boutique's Shopify-hosted checkout when Shopify controls that boutique's inventory. Card information is processed directly by the applicable provider. The Consignory does not receive or store full payment card numbers or card security codes. We receive and may store opaque payment or order identifiers, payment and refund status, order amounts, processor and merchant identifiers, tax metadata, and related records needed to operate holds, purchases, inventory reconciliation, refunds, support, and accounting workflows.
Shipping Addresses and Fulfillment
You may save one US shipping address in your account. When you submit a manual shipping request, we copy the address into that request so the boutique can prepare a quote and fulfill an accepted order even if you later edit or remove the address saved in your profile. The applicable boutique and its authorized staff can view the request address. Other customers and boutiques cannot view it.
For a manual shipping request, the boutique enters the shipping charge and sales-tax amount. The Consignory calculates and displays the quoted total, but does not determine the carrier rate, tax obligation, delivery time, or shipment terms. If you accept and pay the quote, we retain fulfillment status and any carrier or tracking details the boutique provides as part of the transaction record.
When a boutique connects Square or Shopify, we store its authorization credentials in encrypted form. Square credentials support connected payments and refunds. Shopify credentials support contextual product-feed and quantity synchronization across active Shopify locations, Shopify-hosted checkout, and signed order, cancellation, and refund reconciliation for purchases attributed to Consignory. Consignory does not create holds or alternate payment flows for Shopify-backed inventory. Disconnecting the provider in The Consignory, or revoking access at the provider, disables the connection and removes the stored authorization credentials after remote revocation succeeds.
Website Cookies and Local Storage
Public website analytics are first-party and cookie-free. For analytics, the web server temporarily processes an IP address and browser user-agent to create a keyed pseudonymous visitor identifier. This provides an estimate and does not identify a specific person. The raw IP address and full user-agent string are not stored in the analytics table. We honor browser Do Not Track and Global Privacy Control signals for this collection.
The website may still use cookies, local storage, or similar technologies when needed to maintain authenticated sessions, remember preferences, and secure website or admin tools. These technologies are not used to build the public website traffic reports.
Authentication and Notifications
We use authentication services to verify user identity and secure accounts. To route notifications to the correct app installation, the app creates an installation identifier, stores it securely on the device, obtains an Expo push token, and links those identifiers to your profile. A notification token and the notification content needed for delivery are processed by Expo and then by APNs or FCM. Delivery and receipt data help us disable stale or unregistered installations and troubleshoot failures. We may send service-related emails, in-app notices, and push notifications for account activity, staff invites, intake, appointments, inventory updates, consignor requests, holds, purchase requests, refunds, and other operational events. These identifiers are used for app functionality and security, not advertising or tracking across other companies' apps or websites. You may be able to manage certain notification preferences through your device or app settings.
Mobile Diagnostics and Crash Reporting
We use Sentry to receive mobile crash and error reports when crash reporting is configured for a released build. Reports may include the app and build version, device and operating-system context, error messages, stack traces, crash or app-hang details, and limited diagnostic breadcrumbs. We configure this reporting not to send default personal identifiers, network-request captures, screenshots, view hierarchies, or session replays. We also filter and redact common credentials, tokens, email addresses, and local user paths before sending reports. Diagnostic reports are used to investigate failures, protect the service, and improve reliability.
Photos and Inventory Content
Inventory photos, intake deck photos, item descriptions, categories, sizes, condition, notes, and related item details may be visible to boutique owners, authorized staff, relevant consignors, customers, and storefront viewers depending on item status and account permissions.
Private Storefront Messages and Moderation
Customers and boutique users may exchange private messages about a hold or purchase request. We store the message content, conversation participants, related request, sent and read times, read state, and blocking state so the conversation and its safety controls work. When a participant reports a message, we may preserve a snapshot of the reported message together with the report reason, optional details, moderation notes, reviewer, status, and resolution history. Authorized The Consignory administrators may review those records to investigate abuse, respond to support or safety issues, enforce service rules, and comply with legal obligations. We do not use private messages or moderation records for advertising.
Support Tickets
Authenticated support tickets are visible to the submitting user and authorized The Consignory administrators. A ticket associated with a boutique is not automatically shared with other boutique owners or staff. Optional screenshots are stored privately and should not contain passwords, verification codes, full payment card numbers, or identity documents.
Data Retention
We keep information for as long as needed to provide the service, maintain business and transaction records, comply with legal obligations, resolve disputes, enforce agreements, and support boutique accounting, inventory, and refund history. Some records may be retained after account deletion when required for legal, payment, tax, fraud prevention, support continuity, or legitimate business reasons. Support records retained after account deletion may be disassociated from the deleted profile. Raw public website analytics events are deleted after 90 days; aggregate business reports may be retained for longer. Notification tokens are disabled or removed when an installation is unregistered, you sign out where supported, or the associated account is deleted, subject to limited delivery, security, or audit records. Private message and moderation records may be retained for the related transaction, support, safety, dispute, legal, and service-enforcement periods. Connected payment authorization credentials are retained only while needed to operate the active connection and are removed when that authorization is disconnected or revoked, subject to limited records needed to document the revocation and prevent unauthorized reuse.
Account Deletion
You may request account deletion through the mobile app. You can also contact us using the support information below. We may need to retain certain transaction, inventory, payment, security, or legal records as described in this policy. Deleted accounts may have identifying information removed or deactivated while transaction records are retained when legally required or needed for payment, tax, fraud prevention, dispute, accounting, or legitimate business purposes.
Your Privacy Choices and Rights
Depending on your location, you may have the right to request access to, correction of, or deletion of your personal information. You may also ask questions about how your information is used or shared. To make a privacy request, contact us using the support information below. We may need to verify your identity before completing certain requests.
Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, or disclosure. However, no electronic storage or transmission method is completely secure, so we cannot guarantee absolute security.
Children
The Consignory is not directed to children under 13. If you believe a child provided us personal information, contact us so we can review and delete it where appropriate.
Changes To This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date and may provide additional notice through the app, website, or email.
Contact Us
Questions or privacy requests can be sent to [email protected].