Legal

Privacy Policy

Last updated: July 2026

About this page

How to use this page

  • Use the section headings (1–7) to jump to a topic.
  • See “Your rights” to learn how to access, correct, export or delete your data.
  • Contact privacy@harpd.com if you need help with a data request.

What you'll find here

  • What data we collect, how we use and share it, retention, your rights, and security.

This policy explains what data Harpd ("we", "us") collects through harpd.com and app.harpd.com, and how we use it. Harpd is a non-custodial service: we process payment metadata for observability and reconciliation, but we never hold funds or private keys.

1. Data we collect

  • Account & billing: name, email and (via Stripe) billing details needed to provide paid plans. We do not store full card numbers.
  • Harpd Credits: wallet balances, immutable transaction history, purchases, service orders, reservations, and entitlements tied to your stable Harpd user ID.
  • Harpd Rank: submitted product URLs, names, descriptions, categories, ownership verification, immutable boost history and period snapshots. Active listings, Rank Points, positions, achievements and verified status are public.
  • Rank discovery analytics: outbound visits are counted with a short-lived hashed visitor signal so obvious repeat visits and crawlers can be reduced. Public profiles may show aggregate visit counts; clicks never affect Paid Rank Points.
  • Collector configuration: the Collector URL and API key you enter in the dashboard, stored locally in your browser and (if you connect) sent only to your own collector.
  • Payment metadata: event type, amount, endpoint, facilitator and on-chain references — never the keys that authorized a payment.
  • Usage & logs: aggregate events/month, request metadata and error logs used to operate and secure the service.
  • CrewProof operations: customer contact details, service addresses and instructions, crew names and work links, schedules, time-off entries, checklists, issue reports, browser-provided location at arrival or completion, and job photos.
  • Langue and ImgKit: Langue lesson text and voice recordings remain in your browser; entitlement checks send only a lesson hash, language, and character count. ImgKit uploads a finalized gift asset only when needed for paid private delivery and backup.

2. How we use data

To provide the dashboard, reconcile payments on-chain, detect anomalies, generate invoices, send service emails, and improve the product. We do not sell your data.

3. Data sharing

We share data only with processors necessary to run Harpd — Stripe (billing), Cloudflare (hosting/edge), and email delivery. Marketplace listings are public by design; all other data is private to your tenant.

4. Retention

Payment metadata is retained per your plan's retention window (7–365 days, or custom on Enterprise). CrewProof workspace data remains until the workspace owner deletes it; its self-service export and deletion controls are available in Settings. Billing records are kept as required for tax and accounting.

5. Your rights

Depending on your jurisdiction, you may access, correct, export or delete your data, or object to processing. Email privacy@harpd.com to exercise these rights.

6. Security

See our Security page for the controls we apply. For incidents, we notify affected tenants as required by law.

7. Contact

Questions? Email privacy@harpd.com.