Privacy Policy
Last updated: March 2026
Overview
OBXTD ("we," "us," or "our") operates obxtd.com, a service that aggregates restaurant specials, happy hours, and events on the Outer Banks of North Carolina. This policy explains what data we collect, why we collect it, and how you can control it.
We collect as little data as possible. We do not sell your data. We do not store payment information.
What We Collect
Email addresses
We collect your email address when you sign up for early access, subscribe to premium features, or use our magic link sign-in. We use email addresses to authenticate you and to communicate service-related updates. We do not send marketing emails without your explicit consent.
Usage data and analytics
We use Google Analytics to collect anonymized data about how visitors use the site. This includes pages visited, time on site, device type, approximate geographic location (city/region level), and referral source. This data is aggregated and not tied to your identity. You can opt out of Google Analytics at tools.google.com/dlpage/gaoptout.
IP addresses
Our hosting provider (Vercel) automatically logs IP addresses for security and performance purposes. We do not actively collect or store IP addresses in our own database.
Content you submit
If you submit an event, special, or image through our upload or submit forms, we collect the content you provide (text descriptions, venue names, event details). Images submitted via our photo upload feature are used solely to extract event text using AI analysis. We do not permanently store uploaded images — they are processed and discarded. Text extracted from images may be stored as event data if approved.
What we do NOT collect
We do not collect or store credit card numbers, bank account information, or any payment details. All payment processing is handled directly by Stripe. See their privacy policy at stripe.com/privacy.
How We Use Your Data
- To authenticate you via magic link email sign-in
- To manage your subscription status (active, expired, tier)
- To send transactional emails (sign-in links, payment confirmations)
- To improve the site using anonymized analytics
- To moderate submitted content for accuracy and appropriateness
Third Parties We Share Data With
We share minimal data with the following service providers, only as necessary to operate the site:
- Stripe — payment processing. Your email is shared with Stripe to create a customer record and process your subscription. Stripe's privacy policy: stripe.com/privacy
- Supabase — database and authentication. Your email and subscription status are stored in our Supabase database. Supabase privacy policy: supabase.com/privacy
- Google Analytics — anonymized site analytics. Google's privacy policy: policies.google.com/privacy
- Google Maps Platform — maps and venue data. Used to display maps and venue hours. Google's privacy policy applies to map interactions.
- Vercel — web hosting. Vercel processes requests and may log IP addresses for security. Vercel privacy policy: vercel.com/legal/privacy-policy
We do not sell, rent, or trade your personal data with any third parties for marketing purposes.
Data Retention
We retain your email address and subscription status for as long as your account is active. If you request deletion, we will remove your email and subscription record within 30 days. Anonymized analytics data may be retained longer as it cannot be tied to you individually.
Your Rights
Depending on your location, you may have the following rights:
- Access — request a copy of the data we hold about you
- Deletion — request that we delete your data (right to be forgotten)
- Correction — request that we correct inaccurate data
- Portability — request your data in a portable format
- Opt-out — unsubscribe from emails at any time
To exercise any of these rights, email us at legal@obxtd.com or use our data deletion page.
GDPR (European Union Visitors)
If you are located in the European Union, you have rights under the General Data Protection Regulation (GDPR). Our legal basis for processing your email address is contractual necessity (to provide the service you requested). For analytics, our legal basis is legitimate interest. You have the right to object to processing, request erasure, and lodge a complaint with your local supervisory authority.
CCPA (California Residents)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA). You have the right to know what personal information we collect, the right to delete your personal information, and the right to opt out of the sale of personal information. We do not sell personal information. To submit a request, email legal@obxtd.com.
CAN-SPAM
All emails we send comply with the CAN-SPAM Act. Every email includes a clear way to unsubscribe. We do not use deceptive subject lines or sender information. To unsubscribe, use the link in any email we send or visit our unsubscribe page.
Cookies
We use minimal cookies. Supabase uses a session cookie to keep you signed in. Google Analytics uses cookies to track anonymized usage. We do not use advertising or tracking cookies.
Children's Privacy
Our service is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at legal@obxtd.com.
Changes to This Policy
We may update this policy occasionally. We will notify you of significant changes by updating the date at the top of this page. Continued use of the site after changes constitutes acceptance of the updated policy.
Contact
Questions about this policy? Email us at hello@obxtd.com.