Tribeacon

Privacy Policy

Effective Date: 2026-09-24

This Privacy Policy describes how CuadrillaONE, LLC, a Delaware limited liability company ("Tribeacon", "we", "us", "our"), collects, uses, shares, and protects information about you ("you", "your") when you use the Tribeacon platform, mobile applications, website, and related services (collectively, the "Service").

By using the Service, you agree to the practices described in this Policy. If you do not agree, you must not use the Service.

1. What This Policy Covers

This Policy applies to information we collect when you (a) create an account; (b) build or update a profile; (c) post jobs or apply to jobs; (d) communicate with other Users; (e) participate in engagements, including escrow funding and completion flows; or (f) contact our support team.

2. Information We Collect

We collect the following categories of data (organized to align with the Apple App Store Privacy Nutrition Label and Google Play Data Safety frameworks).

2.1 Contact Information. Email address (required), phone number (required at signup), full name.

2.2 Identifiers. Account ID, device identifiers used for session management, IP address (collected by infrastructure providers for security).

2.3 User Content. Profile photo, additional profile photos, cover photo, biographical text, headline, preferred role, skills, languages.

2.4 Personal Details (Optional). Date of birth, gender and nationality are optional. You can add, change or remove them at any time in your profile. Adding them raises your Profile strength; employers cannot search, filter or rank candidates by age, gender or nationality. City and country of residence help us show you jobs near you. When you sign up, we ask you to confirm you are 18 or older.

2.5 Document Vault (Optional, User-Controlled). Tribe Users may optionally upload identity, immigration, and qualification documents to a private cloud-drive feature within the Service ("Document Vault"). Examples include curriculum vitae, professional certifications, training certificates, additional profile photos, passport, visa, government-issued identification, and education certificates. All Document Vault uploads are optional. The Service does not require any of these documents for account creation or platform use. The Service does not verify, validate, or process Document Vault contents algorithmically. Each document has a per-document toggle that controls whether it is shared with Beacon Users you have matched with; by default, all Document Vault documents are private to you. You may delete any Document Vault document at any time.

2.6 Financial Information. Wallet balance, escrow holds, and transaction history within the Service reflect real monetary values. Card payments are handled by Stripe, Inc. (see stripe.com/privacy): your card details are entered with and held by Stripe. We receive confirmation of payment and billing metadata, never your full card number. We retain transaction records (amount, date, item) as required for accounting and legal compliance.

2.7 Communications. Messages sent through in-app chat, including text, images, and metadata such as timestamps and read receipts.

2.8 Usage Data. Pages viewed, features used, search queries, application activity, ratings and reviews you submit or receive.

2.9 Diagnostics. Error logs, performance metrics, crash reports (used to improve Service reliability).

3. How We Use Your Information

3.1 To Provide the Service. Display your profile to potential counterparties, facilitate matching, route messages, manage engagements, process escrow flows. Document Vault contents are NOT used for matching, ranking, or any platform-side decisions; they are stored solely as a user-controlled convenience.

3.2 To Personalize. Show you relevant jobs, candidates, and notifications based on your role, location, preferences, and activity.

3.3 To Communicate With You. Send service notifications, transactional emails (account verification, security alerts), and (if you opt in) product updates.

3.4 To Maintain Safety. Detect and prevent fraud, harassment, scams, off-platform circumvention, and other prohibited conduct. Review reports submitted by other Users.

3.5 To Comply With Law. Respond to legal process, enforce our Terms of Service, and meet tax, accounting, and regulatory obligations.

3.6 To Improve the Service. Analyze aggregate usage patterns to identify bugs, improve features, and inform product decisions.

4. How We Share Your Information

4.1 With Other Users. Your public profile is visible to counterparties based on privacy gating rules described in Section 5. Counterparties you have matched with see additional detail necessary to complete engagements. Document Vault documents are private by default and only shared with specific matched counterparties when you enable the per-document share toggle.

4.2 With Service Providers. We use the following third-party processors to operate the Service:

4.3 With Administrators. Members of the Tribeacon team with administrative access (currently a single administrator account) may access User data for moderation, dispute review, and support purposes.

4.4 For Legal Compliance. We may disclose information when required by law, court order, or to protect the rights, property, or safety of Tribeacon, our Users, or the public.

4.5 In a Business Transfer. If Tribeacon is acquired, merges, or sells substantially all of its assets, your information may be transferred to the acquiring entity, subject to this Privacy Policy or a successor policy.

4.6 What We Do NOT Do. We do not sell your personal information. We do not share your information with advertisers or data brokers. We do not use your User Content to train artificial-intelligence models without your specific consent.

5. Profile Visibility and Privacy Controls

5.1 Default Visibility. Your profile photo, headline, preferred role, city, and country are visible to authenticated counterparties browsing the platform.

5.2 Name Privacy ("First N." Rule). For Tribe Users, your full last name is hidden by default in gig-shift contexts. Counterparties see your first name plus the initial of your last name (for example, "John D.") until you have mutually matched on a full-time role. This default protects Tribe Users from unsolicited off-platform outreach.

5.3 Brand Identity. For Beacon Users, the brand name is treated as a public business identity and is displayed in full to counterparties.

5.4 User Controls. You may adjust profile visibility, who can contact you, and which surfaces show your profile from Settings → Privacy.

5.5 Block Privacy. When you block another User, neither party is notified; mutual invisibility is the only signal.

6. Data Storage and Security

6.1 Where. Account data and User Content are stored on Supabase infrastructure located in the United States. Document Vault files are stored in Supabase Storage with row-level-security policies that enforce per-user access; only you and counterparties you have explicitly shared specific documents with can read them.

6.2 How. Passwords are hashed using industry-standard one-way functions (bcrypt or equivalent) and are never stored or transmitted in plaintext. Authentication sessions use signed JSON Web Tokens (JWT). All Service traffic is encrypted in transit using TLS.

6.3 Access Control. Database access is controlled by row-level security (RLS) policies that enforce per-User read and write permissions at the data layer, not just in application code.

6.4 No Absolute Security. No security measure is perfect. We cannot guarantee absolute security of your data and disclaim any warranty of perfect security.

7. Avatar Service and Regional Fallback

For default profile photos, the Service uses the DiceBear avatar generator (api.dicebear.com). In jurisdictions where this service is unreachable (including the United Arab Emirates, where access is currently blocked), the Service falls back to self-hosted CSS-rendered initial avatars. No personal information is sent to the avatar service beyond the seed string (typically your first name or display name).

8. Data Retention

8.1 Account Active. We retain account data for as long as your account is open.

8.2 Account Deleted. Upon account deletion (Settings → Account Actions → Delete Account), authentication credentials and profile data are removed within thirty (30) days during the alpha period.

8.3 Records We Retain. Immutable transaction records (wallet ledger entries), message histories required for moderation review, and aggregated platform statistics are retained for accounting, legal, regulatory, and safety purposes, even after account deletion.

8.4 Backups. Encrypted backups may persist for up to ninety (90) days after deletion before being permanently overwritten.

9. Your Rights

Depending on your jurisdiction, you may have rights to:

To exercise any of these rights, email support@tribeacon.app. We will respond within thirty (30) days.

10. Children's Privacy

The Service is not directed to anyone under the age of eighteen (18). We do not knowingly collect information from anyone under 18. If we learn that we have collected information from someone under 18, we will delete it promptly. If you believe a child has provided information to us, please contact support@tribeacon.app.

11. Cookies, Local Storage, and Tracking

11.1 Authentication. We use signed JSON Web Tokens (JWT) stored in your browser or device for session management. These tokens are required for the Service to function and cannot be disabled.

11.2 Local Preferences. We use browser localStorage to persist profile drafts, preferred view settings, and acceptance of legal documents. This data does not leave your device.

11.3 No Advertising Trackers. We do not use third-party advertising cookies, pixels, or cross-site tracking technologies.

11.4 Cookie Banner. A formal cookie consent banner will be added before the Service launches publicly in regions requiring it (including the European Union and the United Kingdom).

12. International Data Transfers

The Service is operated from Dubai, United Arab Emirates, with data processed in the United States by our service providers. By using the Service, you consent to the transfer of your information to the United States, which may have data protection laws different from those of your jurisdiction.

13. Changes to This Policy and Contact

13.1 Updates. We may update this Privacy Policy from time to time. The "Effective Date" at the top reflects the most recent change. Material changes affecting how we use your information will be notified in-app and by email at least thirty (30) days before they take effect.

13.2 Continued Use. Continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.

13.3 Contact. Questions about this Policy or our data practices? Contact us at support@tribeacon.app.

tribeacon.app