HUM PRIVACY POLICY - COMPREHENSIVE DATA PROTECTION NOTICE
IMPORTANT: This Privacy Policy explains how Hum-App Technologies Inc. ("HUM," "we," "us," "our") collects, uses, discloses, and protects your personal information when you use the HUM mobile application and related services ("Platform," "App," "Service").
Effective Date: January 11, 2026
Last Updated: January 11, 2026
Company: Hum-App Technologies Inc. (Delaware C-Corporation)
Address: 2314 28th Street, Santa Monica, CA 90405
TABLE OF CONTENTS
- Information We Collect
- How We Collect Information
- How We Use Your Information
- AI & Machine Learning Data Practices
- Information Sharing & Disclosure
- Data Security & Protection
- Data Retention & Deletion
- Your Privacy Rights & Choices
- Cookies & Tracking Technologies
- Third-Party Services & Links
- Children's Privacy
- International Data Transfers
- State-Specific Privacy Rights
- Changes to Privacy Policy
- Contact Us
1. INFORMATION WE COLLECT
1.1 Account & Profile Information
When you create an account, we collect:
- Full legal name
- Email address
- Phone number
- Date of birth
- Physical address (street, city, state, ZIP code)
- Profile photo (optional but recommended)
- Username/display name
- Bio/description (optional)
- Preferred language and communication preferences
1.2 Identity Verification Information
For security and fraud prevention, we collect:
- Government-issued photo identification (driver's license, passport, national ID)
- Facial recognition data (to match ID photo)
- Social Security Number (last 4 digits) - US users only
- Address verification documents (utility bills, bank statements)
- Selfie photos for identity confirmation
- Background check information (for certain high-value transactions)
- Date of birth verification
- Citizenship/residency status (if required)
Third-Party Verification: We use Stripe Identity and other verification services that may collect additional data per their privacy policies.
1.2A Student Verification Information
If you subscribe to Student Subscription (discounted rate), we collect:
- Student email address (typically ending in .edu)
- Current student ID card with photo and expiration date
- Enrollment verification documents
- Educational institution name and location
- Expected graduation date
- Student status (undergraduate, graduate, etc.)
- Third-party student verification service data (if applicable)
Student Verification Process:
- We may use third-party verification services (SheerID, UNiDAYS, or similar)
- Student status must be re-verified annually
- Verification documents retained for compliance and fraud prevention
- Loss of student status automatically converts subscription to Standard pricing
1.3 Payment & Financial Information
Payment data processed by Stripe (our payment processor):
- Credit/debit card information (full number, CVV, expiration)
- IMPORTANT: HUM does NOT store full card numbers
- Stripe stores payment data per their PCI-DSS compliance standards
- HUM receives only last 4 digits and card brand (e.g., "Visa ending in 1234")
- Bank account information (for payouts to Lenders)
- Billing address
- Payment transaction history and records
- Deposit authorizations and charges
- Tax identification numbers (W-9/W-8 forms for US tax reporting)
- Stripe Connect account data (for Lenders receiving payments)
HUM Retains:
- Transaction amounts, dates, and parties involved
- Service fees and platform charges
- Deposit amounts and status
- Payout records and timing
- Tax reporting information (1099-K forms)
1.4 Item Listings & Rental Information
When you list or rent items, we collect:
- Item photos (multiple images per listing)
- Item title, description, and category
- Declared item value (for insurance purposes)
- Rental pricing (daily, weekly, monthly rates)
- Item location (address, GPS coordinates)
- Availability calendar and booking dates
- Item condition assessment
- AI-generated metadata (brand, model, features, suggested pricing)
- Ownership confirmation statements
- Receipt photos (optional for high-value items)
- Pre-rental and post-rental condition photos
- Serial numbers or unique identifiers (if provided)
1.5 Communication & Message Data
We collect all communications on Platform:
- In-app messages between Users
- Customer support inquiries and responses
- Email correspondence with HUM
- SMS text messages (verification codes, notifications)
- Phone call recordings (with notice, for support quality)
- Push notification interactions
- Review and rating content
- Comments and feedback
Retention: Messages retained indefinitely for dispute resolution, legal compliance, and safety.
1.6 Location Information
We collect various location data:
- Precise GPS coordinates: When you use location services for item discovery, listing, or navigation
- IP address-based location: General city/region from Internet connection
- Item pickup/return locations: Addresses where transactions occur
- Search location preferences: Areas where you browse for items
- Movement patterns: If you enable background location (for delivery features)
Location Permissions:
- "While Using App": Collected only when app is open
- "Always": Allows background collection (optional, for delivery tracking)
- You can disable location in device settings (limits functionality)
1.7 Device & Technical Information
Automatically collected when you use the App:
- Device type, model, manufacturer (e.g., "iPhone 14 Pro")
- Operating system and version (e.g., "iOS 17.2")
- Device identifiers (IDFA, Android Advertising ID, device UUID)
- IP address (IPv4 and IPv6)
- Browser type and version (for web access)
- Mobile carrier information
- Screen resolution and device capabilities
- App version and build number
- Language and timezone settings
- Wi-Fi network name (SSID) - if permitted
- Bluetooth and nearby device information (if used for features)
1.8 Usage & Analytics Data
We track how you interact with Platform:
- Features used and frequency of use
- Screens viewed and time spent
- Search queries and filters applied
- Items viewed, favorited, or contacted about
- Booking and rental history
- Cancellations and modifications
- Review and rating activity
- Click-through rates and navigation paths
- Error logs and crash reports
- Performance metrics (load times, responsiveness)
- A/B test participation and group assignments
- Referral sources (how you found HUM)
1.9 Camera, Photo Library & Media
With your permission, we access:
- Camera (to photograph items, take selfies for verification)
- Photo library (to select existing photos for listings)
- Photo metadata (EXIF data: location, timestamp, camera settings)
- Videos (if we add video listing features)
- Microphone (for future voice features or video)
Photo Data: All uploaded photos are analyzed by AI (see Section 4).
1.10 Social Media & Third-Party Account Data
If you connect social accounts (Google, Apple, Facebook):
- Profile information (name, email, photo)
- Friend lists or connections (if you grant access)
- Public profile data
- Social media authentication tokens
1.11 Information from Other Users
We may receive information about you from other Users:
- Reviews and ratings
- Messages and communications
- Dispute claims and reports
- Referrals and recommendations
- Photos/videos where you appear (in transaction documentation)
1.12 Publicly Available Information
We may collect public information:
- Business licenses or professional credentials (if you list professional items)
- Court records or legal filings (for dispute resolution or fraud investigation)
- Public social media posts (for verification or fraud detection)
- Government databases (sex offender registries, sanctions lists)
2. HOW WE COLLECT INFORMATION
2.1 Information You Provide Directly
- Account registration and profile creation
- Item listings and rental bookings
- Messages, reviews, and feedback
- Customer support interactions
- Identity verification submissions
- Payment method setup
2.2 Automatic Collection
- Cookies and tracking technologies (see Section 9)
- Mobile device sensors and APIs
- Server logs and analytics tools
- App usage monitoring
2.3 Third-Party Sources
- Payment processors (Stripe)
- Identity verification services (Stripe Identity, etc.)
- Social media platforms (if you connect accounts)
- Public databases and records
- Fraud prevention and risk assessment services
- Marketing partners and analytics providers
3. HOW WE USE YOUR INFORMATION
3.1 Core Platform Operations
We use your information to:
- Create and manage your account
- Verify your identity and prevent fraud
- Process and manage subscription payments and renewals
- Verify student status for discounted subscriptions
- Monitor subscription billing cycles and payment failures
- Enable item listings and rental transactions
- Process payments, deposits, and payouts
- Facilitate communication between Users
- Display items based on your location preferences
- Match Renters with available items
- Calculate rental pricing and fees
- Manage rental calendars and availability
- Send booking confirmations and reminders
- Handle returns and condition verification
- Process damage claims and disputes
- Enforce Terms of Service and policies
3.2 AI-Powered Features (See Section 4 for Detail)
- Analyze item photos to identify brand, model, condition
- Generate item descriptions and pricing suggestions
- Detect prohibited items and policy violations
- Assess fraud risk and pricing anomalies
- Provide search recommendations
- Calculate environmental impact metrics
- Train and improve AI models for Platform enhancements
3.3 Safety, Security & Fraud Prevention
- Verify identity and prevent account takeovers
- Detect fraudulent listings and transactions
- Identify stolen goods or counterfeit items
- Monitor for prohibited items or activities
- Investigate disputes and policy violations
- Protect against unauthorized access and security threats
- Comply with legal obligations (AML, sanctions screening)
- Respond to legal requests and law enforcement
3.4 Customer Support & Communication
- Respond to inquiries and support requests
- Troubleshoot technical issues
- Provide account assistance
- Send transactional emails and SMS (booking confirmations, payment receipts, subscription renewals)
- Send push notifications about rentals, account activity, and subscription status
- Notify users of subscription renewals, payment failures, and plan changes
- Conduct user surveys and feedback collection
3.5 Marketing & Promotional Communications (With Consent)
- Send newsletters and promotional emails
- Notify you of new features or items
- Provide personalized recommendations
- Deliver targeted advertising
- Run contests, sweepstakes, or referral programs
- Share success stories and user testimonials
You can opt-out of marketing communications (see Section 8.4).
3.6 Platform Improvement & Analytics
- Analyze usage patterns and trends
- Test new features and A/B experiments
- Identify bugs and performance issues
- Improve app design and user experience
- Develop new products and services
- Create aggregated market insights and reports
3.7 Legal & Compliance
- Comply with legal obligations (tax reporting, record-keeping)
- Respond to subpoenas, court orders, legal processes
- Enforce Terms of Service and policies
- Protect rights, property, and safety of HUM and Users
- Investigate and prevent illegal activities
- Resolve disputes and legal claims
3.8 Business Operations
- Manage business relationships and partnerships
- Conduct due diligence for financing or acquisitions
- Maintain business records and accounting
- Conduct risk assessments and insurance underwriting (future)
- Generate financial reports and analytics
4. AI & MACHINE LEARNING DATA PRACTICES
CRITICAL SECTION: This section explains how we use artificial intelligence (AI) and your data for machine learning.
4.1 AI Technologies We Use
HUM uses Google Gemini AI (Google's generative AI model) for:
- Image Recognition: Identifying items, brands, models, and features in photos
- Condition Assessment: Analyzing visual wear, damage, or defects
- Pricing Intelligence: Suggesting rental prices based on market data
- Description Generation: Creating item descriptions automatically
- Fraud Detection: Identifying suspicious listings or pricing anomalies
- Safety Screening: Detecting prohibited items or policy violations
- Search Enhancement: Providing contextual search suggestions
- Environmental Impact: Calculating CO2 and resource savings
4.2 What Data is Sent to Google/Third-Party AI
When you upload a photo or use AI features:
- Image Data: The actual photo file is sent to Google's Gemini API servers
- Metadata: EXIF data (camera settings, timestamp) may be included
- Prompts: Text instructions from HUM to guide AI analysis
- Context: Item category, user-provided title/description (to improve accuracy)
Google's Role:
- Google processes images per their AI Terms and Privacy Policy
- Google may use data to improve their AI models (per Google's terms)
- HUM has limited control over Google's data practices
- See: Google AI Terms and Google Privacy Policy
4.3 AI-Generated Data & Storage
HUM stores AI analysis results including:
- Detected brand, model, and features
- Suggested item descriptions and titles
- Pricing recommendations and confidence scores
- Condition assessments
- Category classifications
- Fraud risk scores
- Prohibited item flags
Storage Duration: Indefinitely, for Platform improvement and legal compliance.
4.4 Building HUM's AI Training Datasets
IMPORTANT - READ CAREFULLY:
By using HUM, you consent to your photos and item data being used to build proprietary HUM AI training datasets and machine learning models.
Specifically, we may:
- Aggregate your photos with other user photos to create training datasets
- Label/annotate images with metadata (brand, category, condition, etc.)
- Train custom AI models specific to rental marketplace use cases
- Improve AI accuracy through supervised learning and model fine-tuning
- Develop new AI features (future visual search, damage detection, authentication)
- Create market intelligence (pricing trends, demand prediction)
Data Used for Training:
- Item photos (primary training data)
- AI-generated labels and classifications
- User edits to AI suggestions (correcting errors improves training)
- Transaction outcomes (successful rentals validate AI accuracy)
- Damage claims data (trains damage detection models)
De-Identification Efforts:
- We attempt to remove personally identifiable information (faces, license plates, addresses) from training data where feasible
- However, complete anonymization is not guaranteed, especially if identifying info is integral to image content
- User profile information is NOT directly linked to training data (images stored separately from identities where possible)
4.5 Third-Party AI Services Beyond Google
We may use additional AI/ML services:
- Fraud Detection AI: Specialized models for financial fraud, identity theft
- Image Moderation AI: To detect inappropriate or prohibited content
- Natural Language Processing: For chatbots, search, and review analysis
- Computer Vision: For damage assessment, authenticity verification
Each service has own privacy policies governing data use.
4.6 AI Limitations & User Rights
AI is NOT perfect. AI-generated information:
- May contain errors, biases, or inaccuracies
- Should be verified by Users
- Does NOT constitute professional advice or guarantees
- Cannot detect hidden defects, authenticity, or ownership
Your Rights:
- You can edit or correct AI-generated information before publishing listings
- You can delete listings (which may remove photos from active use, but training data may be retained)
- You can request account deletion (see Section 8 for data deletion rights)
- You CANNOT opt-out of AI analysis while using HUM (AI is integral to Platform operations)
4.7 Future AI Development
As AI technology evolves, we may:
- Implement new AI features (visual search, real-time authentication)
- Use additional third-party AI providers
- Expand AI training datasets and model capabilities
- Apply AI to new use cases (insurance risk assessment, dynamic pricing)
We will update this Privacy Policy to reflect significant changes in AI practices.
5. INFORMATION SHARING & DISCLOSURE
5.1 Information Shared with Other Users
Publicly visible to all Platform Users (before login):
- Items available for rent (photos, descriptions, pricing, general location area)
- Lender first name and profile photo
- Lender ratings and review count
Visible to Users you transact with:
- Full profile (name, photo, bio)
- Contact information (within Platform messaging)
- Item details (exact pickup location, instructions)
- Rental history between you (past transactions)
- Reviews and ratings you receive
- Transaction-specific communications
NOT shared with other Users:
- Email address, phone number (unless you provide directly)
- Payment information
- Government ID or verification documents
- Precise home address (unless item pickup location)
- Social Security Number or tax ID
5.2 Service Providers & Business Partners
We share information with third parties who provide services:
5.2.1 Payment Processing
- Stripe, Inc.: Payment processing, payouts, fraud prevention
- Shares: Payment details, transaction amounts, bank account info, identity verification
- See: Stripe Privacy Policy
5.2.2 Cloud Infrastructure & Hosting
- Google Firebase: App backend, database, file storage, authentication
- Shares: Account data, item listings, messages, photos, usage analytics
- See: Firebase Privacy Policy
- Google Cloud Platform: Server infrastructure and services
- Shares: All Platform data stored on GCP servers
5.2.3 AI & Machine Learning
- Google Gemini AI: Image analysis and AI features
- Shares: Photos, prompts, item context
- See: Google AI Terms
5.2.4 Identity Verification
- Stripe Identity and other verification providers
- Shares: Government ID, selfie photos, identity documents
- May access public databases for verification
5.2.4A Student Verification Services
- Student verification providers (SheerID, UNiDAYS, or similar)
- Shares: Student email, student ID, enrollment documents, educational institution name
- Purpose: Verify current student status for subscription discounts
- Re-verification required annually
- See respective provider's privacy policy
5.2.5 Mapping & Location Services
- Google Maps Platform: Map display, geocoding, location search
- Shares: GPS coordinates, addresses, search queries
- See: Google Maps Privacy Policy
5.2.6 Communication Services
- Email Delivery: SendGrid, AWS SES (for transactional emails)
- SMS Providers: Twilio (for text message verification and notifications)
- Push Notifications: Firebase Cloud Messaging, Apple Push Notification Service
5.2.7 Analytics & Performance Monitoring
- Firebase Analytics: App usage and user behavior
- Crashlytics: Crash reporting and debugging
- Google Analytics: Web analytics (if applicable)
5.2.8 Customer Support
- Customer Support Platforms: Zendesk, Intercom (may implement)
- Shares: Support inquiries, account details, conversation history
5.2.9 Fraud Prevention & Security
- Fraud detection services: Share transaction data, device info, behavior patterns
- Background check providers: For identity and criminal record verification
Service Provider Obligations:
- Service providers are contractually required to:
- Use data only for HUM's purposes
- Maintain confidentiality and security
- Comply with applicable data protection laws
- However, HUM is not responsible for third-party data practices beyond contractual obligations
5.3 Business Transfers
In the event of merger, acquisition, or sale:
- Your information may be transferred to acquiring company
- We will provide notice before transfer and any changes to privacy practices
- Your data rights continue under successor entity
5.4 Legal Requirements & Law Enforcement
We may disclose information to:
- Law enforcement: In response to valid legal requests (subpoenas, warrants, court orders)
- Government agencies: To comply with legal obligations (tax authorities, regulatory agencies)
- Legal proceedings: In lawsuits, arbitrations, or dispute resolution
- Public safety: To prevent harm, protect rights, or address emergencies
When we disclose:
- We verify legitimacy of requests
- We may notify you (unless prohibited by law or emergency)
- We challenge overly broad or improper requests
- We disclose only information reasonably necessary
5.5 Protection of Rights & Safety
We may share information to:
- Enforce Terms of Service and policies
- Investigate violations and fraudulent activity
- Protect safety and security of Users and public
- Prevent illegal activities
- Defend against legal claims
- Protect intellectual property rights
5.6 With Your Consent
We may share information for purposes not listed above IF:
- You provide explicit consent
- You direct us to share (e.g., referrals, social sharing)
- You connect third-party services (social media accounts)
5.7 Aggregated & De-Identified Data
We may share aggregated or anonymized data publicly or with partners, such as:
- Market trends and rental statistics
- Category performance and pricing insights
- Environmental impact aggregate metrics
- Research and white papers
De-identified data is NOT considered personal information and is not subject to this Privacy Policy.
5.8 We DO NOT Sell Personal Information
HUM does NOT sell your personal information to third parties for their independent marketing purposes.
Note for California Residents: Under CCPA, certain data sharing (e.g., with advertising partners) may be considered "sale." See Section 13.1 for California-specific rights and disclosures.
6. DATA SECURITY & PROTECTION
6.1 Security Measures We Implement
We use industry-standard security practices:
- Encryption in Transit: TLS 1.2+ encryption for all data transmission
- Encryption at Rest: Sensitive data encrypted in databases and storage
- Access Controls: Role-based access limitations, multi-factor authentication for employees
- Network Security: Firewalls, intrusion detection/prevention systems
- Secure Development: Security code reviews, vulnerability testing
- Regular Audits: Third-party security assessments and penetration testing
- Data Minimization: Collect only necessary information
- Employee Training: Security awareness and confidentiality training
- Incident Response: Procedures for detecting and responding to breaches
6.2 Third-Party Security Certifications
Our service providers maintain certifications including:
- Stripe: PCI-DSS Level 1 Service Provider (highest payment security standard)
- Google Cloud Platform: SOC 2/3, ISO 27001, GDPR compliance
- Firebase: Google's security infrastructure and compliance
6.3 User Security Responsibilities
You are responsible for:
- Keeping account credentials confidential
- Using strong, unique passwords
- Enabling two-factor authentication (if available)
- Not sharing account access
- Logging out on shared devices
- Reporting unauthorized access or suspicious activity
- Keeping device and app software updated
6.4 Security Limitations
Despite our efforts, NO security system is 100% secure. Risks include:
- Hacking, phishing, or social engineering attacks
- Unauthorized access due to stolen credentials
- Software vulnerabilities or zero-day exploits
- Insider threats or employee misconduct
- Third-party service breaches
We cannot guarantee absolute security. You use the Platform at your own risk.
6.5 Data Breach Notification
If a data breach occurs:
- We will investigate and assess the risk
- We will notify affected Users without unreasonable delay (as required by law)
- Notification will include:
- Nature of breach and data affected
- Steps we are taking to mitigate
- Recommended actions for Users
- We will report to regulatory authorities as legally required
How we notify:
- Email to registered address
- In-app notification
- Notice on Platform or website
- Media/public notice (if widespread breach)
7. DATA RETENTION & DELETION
7.1 How Long We Keep Data
Retention periods vary by data type:
7.1.1 Account Data
- While account active: Retained for Platform operations
- After account deletion: Deleted within 30-90 days (see exceptions below)
7.1.2 Transaction & Payment Data
- Transaction records: 7 years (tax and legal compliance requirements)
- Payment information: Retained by Stripe per their policy; HUM keeps transaction metadata for 7 years
- Tax forms (1099-K): 7 years per IRS requirements
7.1.3 Communications
- Messages: Retained indefinitely for dispute resolution and legal purposes
- Support tickets: 7 years
- Reviews: Retained indefinitely (associated with transactions, not individual accounts after deletion)
7.1.4 Photos & Item Listings
- Active listings: While listing is active or account exists
- AI training data: Indefinitely (de-identified where feasible)
- Deleted listings: Removed from public view; underlying data may be retained for AI training or legal purposes
7.1.5 Identity Verification Documents
- Government IDs: 7 years after account closure (fraud prevention, legal compliance)
- Verification records: 7 years
- Student verification documents: While student subscription is active + 3 years after conversion to Standard subscription or account closure (for audit and fraud prevention purposes)
- Student IDs and enrollment records: Deleted within 90 days after subscription conversion or account deletion (unless required for disputes)
7.1.6 Analytics & Usage Data
- Aggregated analytics: Retained indefinitely
- Individual usage logs: 2-3 years
7.2 Legal & Operational Retention Requirements
We may retain data longer if required for:
- Legal obligations (tax laws, record-keeping requirements)
- Pending litigation or investigations
- Fraud prevention and safety
- Resolving disputes or enforcing Terms
- Complying with lawful requests
7.3 Data Deletion Process
When you delete your account:
- Profile becomes inaccessible to other Users
- Active listings are removed
- Personal identifiers removed from reviews (reviews remain but anonymized)
- Account data deleted within 30-90 days
Exceptions (data NOT deleted):
- Transaction records (7-year retention)
- Messages and communications (dispute resolution)
- AI training datasets (de-identified photos)
- Data subject to legal holds
- Backups (deleted as backups are rotated/refreshed)
7.4 Backup Retention
We maintain backups for disaster recovery:
- Backups may retain deleted data for 90 days
- Backups not used for operational purposes
- Data in backups eventually deleted as backups are rotated
8. YOUR PRIVACY RIGHTS & CHOICES
8.1 Access Your Information
You have the right to access your personal information:
- In-App: View profile, listings, transaction history, messages through app settings
- Request Copy: Email privacy@hum-app.com to request complete data export
We will provide:
- Copy of your personal information in portable format (typically JSON or PDF)
- Information about how we use and share your data
- Response within 30 days (may extend to 60 days for complex requests)
8.2 Correct or Update Information
You can correct inaccurate information:
- In-App: Edit profile, listings, payment methods directly
- Request Correction: Email privacy@hum-app.com for information you cannot change yourself
8.3 Delete Your Information
You have the right to request deletion:
- In-App: Go to Settings > Account > Delete Account
- Email Request: Send request to privacy@hum-app.com
Deletion limitations (see Section 7.2):
- Transaction records retained for 7 years
- AI training data may be retained (de-identified)
- Legal holds and fraud prevention
- Messages retained for dispute resolution
Processing time: 30-90 days
8.4 Opt-Out of Marketing Communications
You can opt-out of marketing (but NOT transactional communications):
- Email: Click "Unsubscribe" link in emails
- SMS: Reply "STOP" to text messages
- Push Notifications: Disable in app settings or device settings
- In-App: Manage notification preferences in Settings
Transactional communications (booking confirmations, payment receipts, subscription renewals, payment failures, security alerts) CANNOT be opted-out without deleting your account.
8.5 Limit Location Sharing
You can control location access:
- Device Settings: Disable location permissions for HUM app
- iOS: Settings > Privacy & Security > Location Services > HUM
- Android: Settings > Location > App Permissions > HUM
- Choose: "Never," "While Using App," or "Always"
Impact of disabling: Search and item discovery features limited; cannot list items without location.
8.6 Limit Ad Tracking
You can limit personalized advertising:
- iOS: Settings > Privacy & Security > Tracking > Disable "Allow Apps to Request to Track"
- Android: Settings > Google > Ads > Opt out of Ads Personalization
- In-App: Manage ad preferences in Settings (if applicable)
8.7 Object to Data Processing
You may object to certain data processing:
- Marketing and profiling
- AI training data use (note: cannot use Platform if you object to essential AI features)
- Automated decision-making with legal effects
Submit objections to: privacy@hum-app.com
8.8 Data Portability
You can request portable copy of your data:
- Email privacy@hum-app.com
- We will provide data in structured, machine-readable format (JSON, CSV)
- Includes: Profile, listings, transaction history, messages, reviews
8.9 Withdraw Consent
Where processing is based on consent (marketing, optional features):
- You can withdraw consent at any time
- Does NOT affect lawfulness of processing before withdrawal
- May limit Platform functionality if you withdraw consent for essential features
8.10 Lodge a Complaint with Regulator
If you believe we violated your privacy rights:
- You have the right to lodge a complaint with a data protection authority
- United States: Federal Trade Commission (FTC), state attorneys general
- EU/UK: Your national Data Protection Authority
- Other jurisdictions: Relevant privacy regulator
We prefer you contact us first: privacy@hum-app.com so we can address concerns directly.
9. COOKIES & TRACKING TECHNOLOGIES
9.1 What Are Cookies & Tracking Technologies
Cookies: Small text files stored on your device by websites/apps Tracking Technologies: Include cookies, pixels, beacons, local storage, SDKs
9.2 Types of Cookies & Technologies We Use
9.2.1 Essential/Functional
Purpose: Enable core Platform functionality
- Session management and authentication
- Remember preferences and settings
- Security and fraud prevention
- Load balancing and performance
Can you disable? NO (required for Platform to function)
9.2.2 Analytics & Performance
Purpose: Understand Platform usage and improve performance
- Firebase Analytics: App usage, user behavior, feature performance
- Google Analytics: Web traffic analysis (if applicable)
- Crash reporting and error logging
- A/B testing and feature experimentation
Can you disable? Partially (see Section 8.6 for opt-out options)
9.2.3 Advertising & Marketing
Purpose: Deliver personalized ads and measure campaign effectiveness
- Targeted advertising based on interests and behavior
- Conversion tracking
- Retargeting campaigns
- Social media pixels (Facebook, Instagram, if applicable)
Can you disable? YES (see Section 8.6)
9.3 Third-Party Cookies & Trackers
Third parties may set cookies/trackers:
- Google (Analytics, Ads, Firebase)
- Stripe (payment processing, fraud prevention)
- Social media platforms (if you share content)
- Advertising networks
We do not control third-party tracking. See their privacy policies.
9.4 Do Not Track (DNT) Signals
Current Status: We do not respond to "Do Not Track" browser signals, as there is no industry standard for DNT compliance.
Alternative: Use opt-out mechanisms in Section 8.6.
9.5 Managing Cookies
You can manage cookies via:
- Browser settings: Delete or block cookies (may limit website functionality)
- Mobile settings: Limit ad tracking, reset advertising ID
- Opt-out tools: Digital Advertising Alliance (DAA), Network Advertising Initiative (NAI)
10. THIRD-PARTY SERVICES & LINKS
10.1 Third-Party Services We Integrate
HUM integrates services from:
- Stripe (payments)
- Google (Firebase, Maps, AI)
- Apple (Sign-In, Push Notifications)
- Social media platforms (if you connect accounts)
Each service has own privacy policy governing their data practices.
HUM is NOT responsible for:
- Third-party privacy practices
- Third-party data breaches or security incidents
- Third-party terms or policy changes
- Third-party service availability or functionality
You should review third-party privacy policies.
10.2 Links to External Websites
Platform may contain links to third-party websites:
- We do NOT control external sites
- External sites have own privacy policies
- We do NOT endorse or guarantee external sites
- Clicking links is at your own risk
10.3 User-Generated Links & Content
Users may post links in messages or listings:
- HUM does NOT screen or approve links
- We are NOT responsible for linked content
- Report inappropriate links to support@hum-app.com
11. CHILDREN'S PRIVACY
11.1 Age Restriction
HUM is NOT intended for children under 13 years of age.
Users must be 18 years or older to create accounts and use the Platform (per Terms of Service).
11.2 No Knowing Collection from Children
We do NOT knowingly collect personal information from children under 13.
If we learn we have collected child data, we will:
- Delete the information promptly
- Terminate the account
- Notify parents/guardians if identifiable
11.3 COPPA Compliance
We comply with Children's Online Privacy Protection Act (COPPA).
11.4 Parental Notice
If you believe we have collected child information:
- Contact us immediately: privacy@hum-app.com
- Provide details so we can investigate and delete data
12. INTERNATIONAL DATA TRANSFERS
12.1 Data Processed in United States
Platform is operated from the United States. Information collected is:
- Processed and stored in U.S. data centers
- Subject to U.S. laws and legal process
- May be transferred to/from other countries where service providers operate
12.2 Cross-Border Transfers
Data may be transferred to countries outside your residence, including:
- United States (primary)
- Countries where Google Cloud Platform operates (global)
- Countries where service providers have infrastructure
Data protection laws in destination countries may differ from your jurisdiction.
12.3 Safeguards for International Transfers
We implement safeguards including:
- Standard Contractual Clauses (SCCs): EU-approved contracts for data transfers
- Data Processing Agreements: Contracts with service providers requiring adequate protection
- Privacy Shield (or successor frameworks): Where applicable
- Adequacy Decisions: Reliance on government-approved transfer mechanisms
12.4 Your Consent to International Transfers
By using HUM, you consent to:
- Transfer of your information to United States
- Processing in countries with different data protection laws
- Application of this Privacy Policy (not local laws) to extent permitted
12.5 EU/UK Users - GDPR Compliance
For users in European Union or United Kingdom:
- We comply with General Data Protection Regulation (GDPR) and UK GDPR
- Legal bases for processing: Consent, Contract Performance, Legitimate Interests, Legal Obligations
- EU/UK users have enhanced rights (see Section 8 and 13.2)
- Data transfers use Standard Contractual Clauses
- EU Representative: [To be designated if we have substantial EU users]
13. STATE-SPECIFIC PRIVACY RIGHTS
13.1 California Residents (CCPA/CPRA)
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant additional rights.
13.1.1 Right to Know
California residents can request:
- Categories of personal information collected
- Categories of sources
- Business purposes for collection
- Categories of third parties with whom we share
- Specific pieces of personal information we hold
13.1.2 Right to Delete
Request deletion of personal information (subject to exceptions in Section 7.2).
13.1.3 Right to Opt-Out of "Sale" or "Sharing"
Do we "sell" or "share" personal information?
- We do NOT sell personal information for monetary compensation
- However, sharing data with advertising partners may constitute "sharing" under CCPA
To opt-out: Email privacy@hum-app.com with subject "Do Not Sell/Share My Info"
13.1.4 Right to Correct Inaccurate Information
Request correction of inaccurate personal information.
13.1.5 Right to Limit Sensitive Personal Information Use
Sensitive personal information we collect:
- Government ID numbers (SSN)
- Precise geolocation
- Racial/ethnic origin (if inferred from photos - not intentionally collected)
To limit use: Email privacy@hum-app.com (note: may limit Platform functionality)
13.1.6 Right to Non-Discrimination
We will NOT discriminate against you for exercising CCPA rights by:
- Denying goods or services
- Charging different prices
- Providing different quality of service
Exception: We may offer financial incentives or different service levels if reasonably related to value of data.
13.1.7 California "Shine the Light" Law
California Civil Code Section 1798.83 allows California residents to request information about disclosure of personal information to third parties for their direct marketing purposes.
We do NOT share personal information with third parties for their independent direct marketing.
13.1.8 How to Exercise California Rights
- Email: privacy@hum-app.com with "California Privacy Rights Request"
- Include: Name, email, state "I am a California resident," and specify rights you wish to exercise
- Verification: We will verify your identity (may request additional info)
- Authorized Agents: You may designate an authorized agent; must provide written authorization
Response Time: Within 45 days (may extend to 90 days if complex)
13.2 European Union & United Kingdom (GDPR)
EU/UK residents have rights under GDPR, including:
- Right to access personal data
- Right to rectification (correction)
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
- Right to lodge complaint with supervisory authority
Legal Bases for Processing:
- Consent: For marketing, optional features
- Contract Performance: For providing Platform services and processing transactions
- Legitimate Interests: For fraud prevention, analytics, Platform improvement
- Legal Obligations: For tax compliance, legal requests
Data Protection Officer (DPO): [To be designated if required based on user volume]
EU Representative: [To be designated if we have substantial EU presence]
To exercise GDPR rights: Email privacy@hum-app.com with "GDPR Request"
13.3 Other U.S. States
Other states with privacy laws (Virginia, Colorado, Connecticut, Utah, Nevada, etc.):
Residents of states with comprehensive privacy laws have rights similar to CCPA, including:
- Right to access, correct, delete personal information
- Right to opt-out of targeted advertising and sale
- Right to data portability
To exercise rights: Email privacy@hum-app.com with subject "[State] Privacy Rights Request"
We will comply with applicable state laws.
14. CHANGES TO PRIVACY POLICY
14.1 Updates & Revisions
We may update this Privacy Policy to reflect:
- Changes in Platform features or operations
- Legal, regulatory, or compliance requirements
- Industry best practices
- User feedback
14.2 Notice of Changes
We will notify you of material changes by:
- Email to registered address (at least 30 days before effective date)
- In-app notification
- Notice on Platform or website
- Updated "Last Updated" date at top of Privacy Policy
14.3 Your Acceptance
Continued use of Platform after changes constitutes acceptance.
If you disagree with changes:
- You may delete your account before effective date
- Deletion rights subject to Section 7 retention requirements
14.4 Review Privacy Policy Regularly
We encourage you to review this Privacy Policy periodically to stay informed about our data practices.
15. CONTACT US
15.1 Privacy Questions & Requests
For privacy-related inquiries, requests, or complaints:
Email: privacy@hum-app.com
Subject Line: Include specific request type (e.g., "Data Access Request," "CCPA Deletion Request," "GDPR Inquiry")
Mail:
Hum-App Technologies Inc.
Attn: Privacy Team
2314 28th Street
Santa Monica, CA 90405
15.2 General Customer Support
For non-privacy issues (account help, technical support, billing):
Email: support@hum-app.com
In-App: Use "Help" or "Support" feature in HUM app
15.3 Data Protection Officer (DPO)
If we designate a DPO (required for GDPR if substantial EU processing):
Email: dpo@hum-app.com
[To be designated if applicable]
15.4 EU Representative
For EU users (if we establish EU representative):
[To be designated if we have substantial EU user base]
15.5 Response Time
We will respond to privacy requests within:
- 30 days (standard)
- 45-60 days (for complex requests or high volume - will notify you of extension)
- As required by applicable law (may be shorter in some jurisdictions)
ACCEPTANCE & ACKNOWLEDGMENT
By creating an account, using the HUM Platform, or continuing to use HUM after updates to this Privacy Policy, you acknowledge that you have READ, UNDERSTOOD, and AGREE to this Privacy Policy.
You specifically acknowledge and consent to:
- Collection and use of your personal information as described
- Use of your photos and data for AI analysis and training
- Sharing of information with third parties as described (including Google, Stripe, other service providers)
- International transfer of your information to United States and other countries
- Storage of your information as described in retention policies
- Use of cookies and tracking technologies
- Your photos being used indefinitely for AI training datasets (de-identified where feasible)
If you do NOT agree to this Privacy Policy, you MUST NOT use the HUM Platform.
Effective Date: January 11, 2026
Version: 2.0 (Comprehensive Privacy Policy)
© 2026 Hum-App Technologies Inc. All Rights Reserved.
LEGAL DISCLAIMER: This Privacy Policy was prepared to provide comprehensive privacy disclosures and transparency. However, it does NOT constitute legal advice. Hum-App Technologies Inc. strongly recommends having this Privacy Policy reviewed by a qualified privacy attorney licensed in your jurisdiction before final implementation. Privacy laws vary by location and change over time. This document should be customized for your specific circumstances and updated regularly to reflect legal developments.