Effective Date: March 2026 | Last Updated: March 2026
1. Introduction
Favr ("we," "our," "us") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use the Favr mobile application and related services ("Service").
2. Information We Collect
Information You Provide
- Account Information: Email address, display name, password (stored by AWS Cognito).
- Profile Information: City, state, zip code, bio, skill tags, profile photo.
- Favor Data: Favor titles, descriptions, categories, locations, proof photos.
- Communications: Messages sent to other users through the platform.
- Ratings and Reviews: Scores and comments you leave for other users.
Information Collected Automatically
- Device Information: Device type, operating system, push notification token.
- Location Data: Approximate location based on city/state/zip you provide. GPS is used only when browsing the Nearby tab and is not stored.
- Usage Data: API request logs, timestamps (stored in AWS CloudWatch).
Information We Do NOT Collect
- Government-issued identification
- Financial information
- Contacts or address book data
- Browsing history outside of Favr
3. How We Use Your Information
We use your information to operate the Service, match you with nearby favors, send notifications, resolve disputes, detect fraud, and improve the Service. We do NOT sell your data, use it for targeted advertising, or share it with data brokers.
4. How We Share Your Information
| Recipient | What We Share | Why |
|---|---|---|
| Other Favr users | Display name, city/state, rating, skills | Platform functionality |
| AWS (infrastructure) | All data (encrypted) | Cloud hosting |
| Law enforcement | As required by valid legal process | Legal compliance |
We never share your email address, exact coordinates, or device tokens with other users.
5. Data Storage and Security
All data is encrypted at rest (DynamoDB, S3) and in transit (TLS/HTTPS). Authentication is handled by AWS Cognito with SRP-based password authentication. API endpoints are protected by JWT-based authentication with rate limiting.
6. Data Retention
User profiles, favors, ratings, messages, and disputes are retained indefinitely for legal compliance. Notifications are auto-deleted after 30 days. Account deletion anonymizes your profile while preserving record integrity.
7. Your Rights
All Users
- Access: View your data through the app.
- Correction: Update your profile at any time.
- Deletion: Request account deletion through the app.
- Export: Download all your data from Privacy & Data settings.
California Residents (CCPA)
Right to know, right to delete (via anonymization), right to opt out of sale (we don't sell data), right to non-discrimination.
EU Residents (GDPR)
Right of access, rectification, erasure (via anonymization), data portability, restriction of processing, and right to object.
8. Children's Privacy
Favr is not intended for users under 18 years of age. We do not knowingly collect information from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via the app or email.
10. Contact Us
For privacy-related questions: privacy@myfavrs.com