Privacy Policy
Last Updated: July 9, 2026
Table of Contents
- 1. Introduction
- 2. Information We Collect
- 3. How We Use Your Information
- 4. Third-Party Services
- 5. Mobile Applications
- 6. Push Notifications
- 7. SMS Notifications
- 8. Email Communications
- 9. Data Storage and Security
- 10. Data Retention
- 11. Your Rights and Choices
- 12. Cookies and Tracking
- 13. Children's Privacy
- 14. International Users
- 15. Changes to This Policy
- 16. Contact Us
1. Introduction
Welcome to 86. We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our inventory management platform and related services.
86 is operated by 86 Software LLC, doing business as "86," based in Puerto Rico. By using our service, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
We collect information you directly provide to us, including:
- Account Information: Name, email address, phone number, organization name, and password
- Business Information: Restaurant/business details, address, cuisine type, timezone preferences
- Inventory Data: Product names, quantities, categories, vendor information, pricing, and related inventory management data
- Payment Information: Billing address and payment method details (processed securely by our payment processor)
- Communications: Messages, feedback, and support requests you send to us
- User-Generated Content: Photos of inventory items, notes, spreadsheets, and other files you upload
- Financial Data (via Plaid): When you choose to connect your bank account, we collect transaction history, account balances, and account metadata (institution name, account type, last four digits) through our integration with Plaid Inc. We do not collect your bank login credentials — Plaid handles authentication directly. See Section 4 for details.
- Invoice Data: Photos or PDFs of invoices you upload for AI-powered cost extraction and inventory price updates
2.2 Automatically Collected Information
When you use our service, we automatically collect:
- Usage Data: Features used, actions taken, time spent, and interaction patterns
- Device Information: Device type, operating system, browser type, and IP address
- Log Data: Access times, pages viewed, and technical errors
- Analytics Data: Usage patterns, page views, clicks, and performance metrics collected via PostHog in our web application (see Section 4)
- Session Replays: Recordings of how you interact with our web application, collected for product improvement and error diagnosis. We configure replays to mask typed input and on-screen text, so recordings are designed to capture layout and interactions rather than your business content (see Section 4)
- Mobile Device Information: For users of our iOS and Android apps:
- Device model and manufacturer
- Mobile operating system and version
- App version and build number
- Push notification tokens (for sending notifications)
- Device language and locale settings
3. How We Use Your Information
We use your information to:
- Provide, maintain, and improve our inventory management services
- Process your subscription payments and manage your account
- Send you operational notifications (inventory reminders, count completion alerts)
- Respond to your support requests and communicate with you
- Analyze usage patterns to improve product features and user experience
- Detect, prevent, and address technical issues, fraud, and security threats
- Comply with legal obligations and enforce our Terms of Service
- Send you important service updates and policy changes
- Measure the effectiveness of our own advertising (see Section 4.2 for details on advertising measurement)
We do not send marketing emails, newsletters, or promotional SMS messages. All emails and text messages we send are transactional and operational. We do use limited advertising measurement tools (described in Section 4.2) to understand whether our own ads on Meta and Google platforms lead to signups — we never sell your personal information, and we never share your inventory, financial, or business data with advertising platforms.
4. Third-Party Services
We use trusted third-party service providers to help us operate our business. These providers have access to your information only to perform specific tasks on our behalf and are obligated to protect your data.
4.1 Service Providers We Use
Clerk (Authentication & Billing)
- Purpose: User authentication, organization management, and subscription billing
- Data shared: Name, email, organization details, payment information
- Privacy Policy: clerk.com/legal/privacy
- Note: Clerk uses Stripe for payment processing. Your payment card information is handled directly by Stripe and never stored on our servers.
Convex (Database & Backend)
- Purpose: Data storage, real-time synchronization, and backend infrastructure
- Data shared: All application data including inventory, user profiles, and business information
- Privacy Policy: convex.dev/legal/privacy
- Security: SOC 2 Type II compliant, 256-bit AES encryption at rest, TLS encryption in transit
Twilio (SMS Notifications)
- Purpose: Sending operational SMS notifications (count reminders, completion alerts)
- Data shared: Phone numbers and message content
- Privacy Policy: twilio.com/legal/privacy
- Note: See Section 7 for detailed SMS notification information
Resend (Email Notifications)
- Purpose: Sending transactional emails (data import status, account notifications)
- Data shared: Email addresses and message content
- Privacy Policy: resend.com/legal/privacy-policy
- Note: See Section 8 for detailed email communication information
Plaid (Bank Account Connection)
- Purpose: Connecting your business bank account to automatically sync transactions for expense categorization, invoice matching, and financial insights
- Data shared: Plaid securely handles your bank login credentials — we never see or store them. Plaid provides us with transaction history (amounts, dates, merchant names), account balances, and account metadata (institution name, account type, last four digits)
- Data storage: Plaid access tokens are encrypted at rest using AES-256-GCM encryption. Transaction data is stored in our database and used for expense categorization, budget tracking, and financial reporting within your account
- Data usage: Your financial data is used only within your own dashboard. It is never sold, shared with other users, or used for advertising
- Disconnection: You may disconnect your bank account at any time from Settings. When disconnected, we revoke the Plaid access token and stop syncing new transactions. Previously synced transaction data remains in your account unless you request deletion
- Privacy Policy: plaid.com/legal - End User Privacy Policy
- By using our bank connection feature, you acknowledge and agree to Plaid's End User Privacy Policy
Anthropic (AI Processing)
- Purpose: AI-powered invoice scanning, transaction categorization, review analysis, and financial insights
- Data shared: Invoice images/text, transaction descriptions, review text, and business context needed for analysis
- Data NOT shared: Bank login credentials, Plaid access tokens, or any authentication material are never sent to AI services
- Data retention: Anthropic's API data retention policy automatically deletes inputs and outputs within 30 days. Anthropic does not use API data to train models
- Privacy Policy: anthropic.com/privacy
POS Integrations (GoTab, Clover, and others)
- Purpose: Syncing daily sales data (revenue, tips, taxes, discounts) for financial reporting and bank deposit reconciliation
- Data shared: POS API credentials (encrypted at rest using AES-256-GCM). We receive sales summaries and payment data from your POS system
- Disconnection: You may disconnect your POS integration at any time from Settings
Sentry (Error Tracking)
- Purpose: Monitoring application errors and performance issues
- Data shared: Error logs, stack traces, and technical diagnostic information. So we can identify and fix problems affecting your account, error reports include your user identifiers — account ID, and on the web application also your email address and username. Web error reports may also include your IP address and request metadata, and the web application sends performance traces (page-load and request timing) to help us find slow spots
- Session replay (web application only): When an error occurs (and for a small sample of normal sessions), Sentry records a replay of the affected browser session to help us diagnose the problem. Replays are configured to mask typed input and on-screen text, so they are designed to capture page structure and interactions rather than your business content
- Mobile apps: Crash reporting only. Performance monitoring, session tracking, and session replay are disabled on iOS and Android
- Privacy Policy: sentry.io/privacy
PostHog (Product Analytics & Session Replay)
- Purpose: Understanding how the web application is used so we can improve it — page views, feature usage, clicks, and session replays
- Data shared: Usage events tied to your account ID and email address, your organization's name (so we can view usage by restaurant), device and browser information, and masked session replays. We configure replays to mask all typed input and on-screen text so they are designed to keep your inventory, financial, and customer data out of recordings
- Scope: Web application only. Our mobile apps do not run PostHog. Demo/sample-restaurant sessions are not tracked
- Data storage: PostHog's U.S. cloud (us.i.posthog.com)
- Privacy Policy: posthog.com/privacy
4.2 Advertising and Conversion Measurement (Meta & Google)
We advertise 86 on Meta platforms (Facebook, Instagram) and Google. To measure whether those ads work, we use conversion measurement tools that share limited information with Meta and Google:
- Meta Pixel and Conversions API: When you visit our website or sign up, we send Meta conversion events (such as "completed registration" or "started subscription") that may include your email address and phone number in hashed form (a one-way transformation — Meta cannot read the original values, only match them against its own hashes), your IP address, your browser's user-agent string, Meta-generated browser cookies (
_fbp,_fbc) when present, and — for subscription purchases — the purchase value and currency. Browser and server events carry shared event IDs so Meta can deduplicate them. Meta uses this to match conversions to ads it showed you. - Google tag (Google Ads / Google Analytics): Measures visits and signup/subscription conversions attributable to our Google ads. For subscription purchases we use Google's "enhanced conversions," which send your email address and name (processed by Google in hashed form) along with the purchase value and currency, so Google can match the conversion to the ad click.
These tags load on our marketing website and, within the web application, only while you are signed out (the sign-in and sign-up pages) or before your subscription is active (the checkout phase) — once your subscription is active they are no longer loaded (starting with your next page load), so day-to-day use of the app (inventory, banking, invoices, reports) and subscription renewals send nothing to ad platforms from your browser. They also do not load on our legal pages (this page, Terms, and account deletion) or anywhere in our mobile apps. What we never share with advertising platforms: your inventory data, financial and banking data, invoices, sales data, or any business records.
Under some U.S. state privacy laws, this kind of disclosure to advertising platforms is considered "sharing" of personal information, and you have the right to opt out. We honor the Global Privacy Control browser signal automatically for browser-based advertising tags, and you can opt your account out of all advertising events (including server-side events) by email. See "Do Not Sell or Share My Personal Information" in Section 11.
5. Mobile Applications
5.1 iOS and Android Apps
86 is available as a mobile application for iOS (iPhone and iPad) and Android devices. Our mobile apps provide the same inventory management functionality as our web application, optimized for mobile use with additional features like camera access for photo capture.
5.2 App Stores
Our mobile apps are distributed through:
- Apple App Store: For iOS devices (iPhone, iPad)
- Google Play Store: For Android devices
When you download our app from these stores, you are also subject to Apple's or Google's respective privacy policies and terms of service.
5.3 Device Permissions
Our mobile apps request the following device permissions:
Camera Permission
- Purpose: Take photos of inventory items, scan barcodes, and scan invoices (document capture) for AI-powered cost extraction
- When requested: When you attempt to take a photo or scan a document
- Required: No, you can manually enter item information instead
- iOS Message: "86 needs camera access to scan barcodes and take photos of inventory items."
Photo Library Permission
- Purpose: Attach existing photos from your device to inventory items
- When requested: When you attempt to select a photo from your library
- Required: No, you can skip adding photos
- iOS Message: "86 needs photo library access to attach images to inventory counts."
Notifications Permission
- Purpose: Receive inventory count reminders and completion alerts
- When requested: During initial app setup or when enabling notifications in settings
- Required: No, but you will not receive push notifications if denied
- Note: See Section 6 for detailed push notification information
5.4 Permission Management
You can change permission settings at any time through your device's system settings:
- iOS: Settings → 86 → Permissions
- Android: Settings → Apps → 86 → Permissions
5.5 Updates and Features
We may release updates to our mobile apps to add features, fix bugs, and improve performance. Updates are distributed through the respective app stores and may include new permission requests if new functionality requires them. We will always request permission before accessing new device features and explain why the permission is needed.
6. Push Notifications
6.1 How Push Notifications Work
Our mobile apps use push notifications to deliver timely operational alerts directly to your device. Push notifications are entirely controlled by your organization's administrators and managed by Expo's push notification service. We do not send marketing messages or unsolicited notifications.
6.2 Types of Push Notifications
You may receive the following types of operational push notifications:
- Inventory Count Reminders: Scheduled by your organization's admin to remind employees to count inventory
- Count Completion Notifications: Sent to managers when an inventory count is completed
- Missed Count Alerts: Sent to managers when a scheduled count was not completed
6.3 Push Notification Service Provider
Expo Push Notifications
- Purpose: Sending push notifications to iOS and Android devices
- Data shared: Push notification tokens (device identifiers) and message content
- Privacy Policy: expo.dev/privacy
- Platform: Built on Apple Push Notification service (APNs) for iOS and Firebase Cloud Messaging (FCM) for Android
6.4 Consent and Control
- Who Manages Notifications: Push notifications are initiated by your organization's administrator, not by 86 directly. 86 is a B2B platform where employers manage operational notifications for their teams.
- For Organization Admins: By enabling push notifications in your organization settings, you represent that you have obtained appropriate consent from the recipients (employees/team members) to receive operational work-related notifications from 86 on behalf of your organization. Admins have contractual authority as employers to manage work-related operational notifications.
- For All Recipients: You can opt-out of push notifications at any time by:
- Disabling notifications in the 86 app settings
- Turning off notifications for 86 in your device's system settings
- Contacting your organization's administrator to adjust notification preferences
- Emailing [email protected] to request removal from notifications
- Automatic Fallback: If push notifications fail or are disabled, the system automatically falls back to SMS notifications (if configured)
- Message Frequency: Varies based on your organization's schedules (typically daily or weekly)
- No Charges: Push notifications are free and do not consume SMS credits or incur charges
6.5 Push Token Management
When you enable push notifications, the mobile app receives a unique push token from your device's operating system. This token is stored securely and used only to deliver notifications. We automatically:
- Register your push token when you enable notifications
- Update your token if it changes (e.g., after app reinstall)
- Remove invalid tokens that fail to deliver
- Delete your token when you disable notifications or uninstall the app
6.6 Privacy and Security
Push notifications are transmitted securely through Expo's infrastructure, which uses Apple's and Google's secure push notification services. Your push token and notification content are:
- Encrypted in transit using industry-standard TLS/SSL
- Used solely for delivering operational notifications
- Not sold or shared with third parties for marketing purposes
- Automatically invalidated when you uninstall the app
7. SMS Notifications
7.1 How SMS Works in 86
86 provides SMS notification features that are entirely controlled by your organization's administrators. We do not send marketing messages or unsolicited texts. SMS is used as a fallback when push notifications fail or are unavailable.
7.2 Types of SMS Messages
You may receive the following types of operational SMS messages:
- Inventory Count Reminders: Scheduled by your organization's admin to remind employees to count inventory
- Count Completion Notifications: Sent to managers when an inventory count is completed
- Missed Count Alerts: Sent to managers when a scheduled count was not completed
7.3 Consent and Control
- Who Manages SMS: SMS messages are initiated by your organization's administrator, not by 86 directly. 86 is a B2B platform where employers manage operational notifications for their teams.
- For Organization Admins: By providing phone numbers and enabling SMS notifications in your organization settings, you represent that you have obtained appropriate consent from the recipients (employees/team members) to receive operational work-related SMS messages from 86 on behalf of your organization. Admins have contractual authority as employers to manage work-related operational notifications.
- For All Recipients: Any recipient can opt-out at any time by texting "STOP" to any message. Organization admins are responsible for ensuring recipients are aware of and consent to receiving operational notifications as part of their employment or business relationship.
- Additional Opt-Out Methods: Recipients can also:
- Contact your organization's administrator to remove your phone number
- Request removal by emailing [email protected]
- Message Frequency: Varies based on your organization's schedules (typically daily or weekly)
- Charges: Message and data rates may apply based on your mobile carrier's plan
7.4 SMS Privacy and Security
We use Twilio as our SMS service provider. Your phone number and message content are transmitted securely and are used solely for delivering the requested operational notifications. We do not sell or share your phone number with third parties for marketing purposes.
7.5 Compliance
Our SMS notifications comply with the Telephone Consumer Protection Act (TCPA) and CTIA guidelines. For Canadian recipients, we follow Canada's Anti-Spam Legislation (CASL): all messages are transactional/operational in nature, sent with appropriate consent, and include the ability to opt out at any time.
8. Email Communications
8.1 Types of Emails We Send
We send only transactional and operational emails, including:
- Account Emails: Welcome messages, password resets, account verification
- Data Import Status: Updates on your uploaded inventory data import requests
- Subscription Emails: Payment confirmations, subscription changes, billing notifications
- Service Updates: Critical service announcements, security alerts, policy changes
- Support Communications: Responses to your support requests
8.2 No Marketing Emails
We do not send marketing emails, newsletters, or promotional content. All emails are necessary for the operation of your account and the service.
8.3 Email Service Provider
We use Resend to send emails. Resend is GDPR compliant and does not sell or share your email address with third parties. All emails are sent from [email protected] with a reply-to address of [email protected].
8.4 CAN-SPAM Compliance
While we don't send marketing emails, all our communications comply with the CAN-SPAM Act and include:
- Accurate sender information and subject lines
- Our physical business address
- Clear identification of the message type
9. Data Storage and Security
9.1 Where Your Data is Stored
Your data is stored on secure servers provided by Convex, which are hosted on Amazon Web Services (AWS) infrastructure in the United States. Convex maintains SOC 2 Type II compliance and follows industry-standard security practices. Our web applications are served by Vercel, whose infrastructure processes standard web-server logs (such as IP addresses) to deliver the pages.
9.2 Security Measures
We implement multiple layers of security to protect your data:
- Encryption at Rest: All data is encrypted using 256-bit AES encryption
- Encryption in Transit: All data transmission uses TLS/SSL encryption
- Access Controls: Role-based access controls ensure users only see their organization's data
- Authentication: Secure authentication provided by Clerk with industry-standard protocols
- Organization Isolation: Every query is scoped to your organization, so users can only access their own organization's data
- Monitoring: Continuous monitoring for security threats and anomalies via Sentry
- Regular Updates: We keep our systems updated with the latest security patches
9.3 Payment Security
Payment information is handled directly by Stripe (via Clerk Billing) and never stored on our servers. Stripe is PCI-DSS Level 1 compliant, the highest level of payment security certification.
9.4 Security Incidents
If a security incident affects your personal information, we will notify you and the relevant authorities as required by applicable law, and will tell you what happened, what data was involved, and what we are doing about it.
9.5 No Guarantee
While we implement strong security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security, but we continuously work to protect your information using industry best practices.
10. Data Retention
10.1 Active Accounts
We retain your data for as long as your account is active and for a reasonable period afterward to comply with legal obligations and resolve disputes. In general, we determine retention periods based on: how long the data is needed to provide the Service, legal and tax record-keeping requirements for billing and financial records, and whether the data is still needed to resolve disputes or enforce agreements. Diagnostic data is kept on shorter cycles — session replays and error reports are retained by our providers for a limited period before automatic deletion.
10.2 Cancelled Subscriptions
If you cancel your subscription but do not delete your account, we retain your inventory data and account information so you can reactivate your subscription without data loss. This data remains subject to the same security and privacy protections.
10.3 Account Deletion
You can delete your user account in the mobile app (Settings → Delete Account) or by emailing [email protected] with "Account Deletion Request" — email requests are processed within 7 business days. When your account is deleted, we permanently remove your login credentials, email address, phone number, push notification tokens, profile photo, and personal notification history — the account can no longer sign in and can no longer be contacted.
What remains: your name stays attached to your organization's business records — for example, which team member performed an inventory count or scanned an invoice. Those records belong to the organization, and keeping the name preserves the accuracy of its operating history. We never use the retained name to contact you or for advertising, and it is kept only as long as the organization retains its business records. An organization administrator can request deletion of the organization and all of its data, which removes these records entirely. We may also retain certain information if required by law or for legitimate business purposes such as:
- Preventing fraud and abuse
- Resolving disputes or legal claims
- Complying with legal or regulatory requirements
- Enforcing our Terms of Service
10.4 Backup Retention
Deleted data may persist in backup systems for up to 90 days before being permanently removed.
11. Your Rights and Choices
11.1 Access and Update Your Information
You can access and update your account information at any time through your account settings in the 86 application. This includes your name, email, phone number, organization details, and notification preferences.
11.2 Delete Your Account
You can delete your account at any time in the mobile app (Settings → Delete Account) or by emailing [email protected]. Account deletion permanently removes your personal data as described in Section 10.3.
11.3 California Residents (CCPA/CPRA Rights)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
- Right to Know: Request what personal information we collect, use, disclose, sell, or share
- Right to Delete: Request deletion of your personal information
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out of Sale or Sharing: We do not sell personal information for money. We do "share" limited personal information with advertising platforms for conversion measurement as described in Section 4.2, and you may opt out of that sharing at any time (see below)
- Right to Non-Discrimination: Not be discriminated against for exercising your rights
Do Not Sell or Share My Personal Information
You can opt out of the advertising-related "sharing" described in Section 4.2 in either of two ways:
- In your browser: Enable the Global Privacy Control (GPC) signal in your browser or install a GPC-enabled browser extension. When we detect the GPC signal, we treat it as a valid opt-out request: we do not load Meta or Google advertising tags in your browser, and when you use the web application signed in from a GPC browser we record a permanent opt-out for your organization that also blocks the server-side conversion events described in Section 4.2.
- By email: Send a request to [email protected] with "Do Not Sell or Share" in the subject line, and we will record the same organization-level opt-out — server-side conversion events stop immediately, and advertising tags stop loading for your organization's signed-in sessions.
Opting out does not affect essential cookies, product analytics used solely by us, or the operation of your account.
Sensitive personal information: Financial data synced through Plaid may qualify as "sensitive personal information" under the CPRA. We use it only to provide the Service you requested (expense tracking, reconciliation, and reporting inside your own account) — never for advertising, profiling, or any secondary purpose — so no separate "Right to Limit" action is needed.
To exercise any of these rights, email us at [email protected] with "CCPA Request" in the subject line. You may also use an authorized agent to submit a request on your behalf; we will ask the agent for proof of authorization and may need to verify your identity directly. We verify requests by matching the information you provide against the account details we hold (such as your account email or phone number).
Other U.S. State Privacy Rights
Residents of other states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Texas, Oregon, and Montana) have similar rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising. We extend the rights and opt-out mechanisms described in this section to all U.S. users regardless of state. To exercise them, use the same contact methods above; if we decline a request, you may appeal by replying to our response, and we will review the appeal within the timeframe your state's law requires.
11.4 European Residents (GDPR Rights)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):
- Right of Access: Obtain confirmation of whether we process your data and access to it
- Right to Rectification: Correct inaccurate or incomplete personal data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Request restriction of processing under certain circumstances
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing of your personal data
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
To exercise these rights, email us at [email protected] with "GDPR Request" in the subject line.
11.5 Canadian Residents (PIPEDA Rights)
If you are located in Canada, we handle your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws (including Quebec's Law 25). You have the right to:
- Access: Request access to the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete personal information
- Withdraw Consent: Withdraw your consent to our collection, use, or disclosure of your personal information (subject to legal or contractual restrictions; withdrawing consent may limit our ability to provide the Service)
- Portability (Quebec): Quebec residents may request a copy of the computerized personal information we hold about them in a structured, commonly used technological format
- Complain: File a complaint with the Office of the Privacy Commissioner of Canada — or, for Quebec residents, the Commission d'accès à l'information du Québec — if you believe your privacy rights have been violated
Your data is stored and processed in the United States (see Section 14). Our person in charge of the protection of personal information (privacy officer) can be reached at [email protected] — include "Privacy Officer" in the subject line. We do not use your personal information to make automated decisions that have legal or similarly significant effects on you. To exercise these rights, email us at [email protected] with "Privacy Request" in the subject line.
11.6 Response Time
We will respond to your data rights requests within 30 days. If we need additional time, we will notify you of the reason and extension period.
13. Children's Privacy
86 is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected], and we will delete such information from our systems.
By using 86, you represent that you are at least 18 years of age.
14. International Users
14.1 Where 86 Is Offered
86 is offered to businesses located in the United States, U.S. territories, and Canada. We do not currently market or offer the Service in other countries.
14.2 Data Transfer
86 is operated from Puerto Rico, and our servers are located in the United States. If you access our service from outside the United States — including from Canada — your information will be transferred to, stored, and processed in the United States. By using the Service, Canadian users consent to this cross-border transfer. Our U.S. service providers are bound by contractual and security obligations described in this policy, and your information may be subject to access by U.S. authorities under U.S. law.
14.3 Canadian Users
For users in Canada, we comply with PIPEDA and applicable provincial privacy laws. Your rights are described in Section 11.5. Our SMS and email practices for Canadian recipients follow CASL (see Section 7.5).
14.4 European Users
86 is not directed at, offered in, or marketed to the European Economic Area (EEA), United Kingdom, or Switzerland. If you nevertheless access the Service from those regions:
- We honor the data-protection rights described in Section 11.4 upon request
- Data transfers from the EEA to the U.S. are based on appropriate safeguards, including our service providers' compliance with relevant frameworks (e.g., Convex and Clerk have GDPR-compliant practices)
- You have the rights described in Section 11.4
14.5 Legal Basis for Processing (GDPR)
For European users, our legal basis for processing your personal data includes:
- Contract Performance: Processing necessary to provide the service you requested
- Consent: Where you have given explicit consent (e.g., for push and SMS notifications)
- Legitimate Interests: For improving our service, preventing fraud, and ensuring security
- Legal Obligations: To comply with applicable laws and regulations
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:
- We will update the "Last Updated" date at the top of this policy
- For material changes, we will notify you via email or through a prominent notice in the application
- Changes become effective immediately upon posting unless otherwise stated
We encourage you to review this Privacy Policy periodically. Your continued use of 86 after changes are posted constitutes your acceptance of the updated policy.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
86
26 Cll Pedro Marquez
Culebra, PR 00775
United States
Email: [email protected]
For privacy-related inquiries, please include "Privacy Request" in your email subject line. We will respond to all requests within 30 days.
This Privacy Policy is effective as of July 9, 2026, and applies to all users of 86.