Your information
Privacy Policy
Effective August 25, 2026
This Privacy Policy explains how Hei Long Chan, a sole proprietor carrying on business as OpenTribes (“OpenTribes,” “we,” “us,” or “our”), handles personal information through the OpenTribes app, website, waitlist, support, and related services.
We are accountable for personal information under applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA). Hei Long Chan is the OpenTribes Privacy Officer.
1. Who we are
OpenTribes is operated by Hei Long Chan, a sole proprietor carrying on business as OpenTribes, at 23 Sheppard Avenue East, Toronto, Ontario M2N 0C8, Canada. Privacy and support email: opentribes.app@gmail.com.
OpenTribes is intended only for people in Canada who are at least 18 years old.
2. Personal information we collect
- Account and profile information, such as name, username, email address, optional phone number, profile photo, biography, preferences, and authentication-provider identifiers.
- Collector and trading content, such as binder and wishlist entries, card or item details, photos, listings, matches, offers, trade status, and history.
- Communications and social content, such as trade and group messages, community posts, comments, replies, reactions, shared images, and activity information.
- Community-group information, such as groups you create or join, membership roles, join requests, invitations, moderation actions, and group visibility settings.
- Event information, such as events you save, join, host, or submit; organizer details; check-ins; mission or contest submissions; and related photos.
- Safety and support information, such as reports, blocks, moderation actions, appeals, support requests, and evidence you provide about suspected misconduct.
- Waitlist and communications information, such as your email address, sign-up date, consent record, invitation status, and unsubscribe or withdrawal request.
- Device and technical information, such as IP address, device and app identifiers, device type, operating system, app version, push-notification token, language, timestamps, security logs, diagnostics, and app or website interactions.
- Permission-based information, such as selected photos or camera content and device location used on request to determine your city and nearby-event counts. Device coordinates are rounded to two decimal places before local caching; only the city name is added to your public profile.
3. Where information comes from
- Directly from you when you create an account, complete a profile, add content, communicate, join an event, submit a report, or contact us.
- From your device when you use a feature and grant the requested permission.
- From Apple or Google when you use their sign-in service, according to the choices you make with that provider.
- From other users, organizers, or rights holders when they communicate with you, tag or mention you, submit event information, or make a report involving you.
- Automatically from our service providers when you use the app or website.
4. Why we use personal information
- Create and secure accounts, authenticate users, provide profiles, and remember settings.
- Operate binders, wishlists, listings, matching, messages, trades, events, notifications, and optional city-based nearby discovery.
- Provide support, respond to privacy requests, communicate service and security information, and manage the waitlist.
- Detect, investigate, and prevent fraud, counterfeits, spam, harassment, security incidents, and violations of our Terms or Community Guidelines.
- Moderate content, process reports and appeals, enforce restrictions, and protect users and the public.
- Maintain, troubleshoot, analyze, and improve the reliability, usability, accessibility, and security of the service.
- Comply with law, preserve evidence, respond to lawful requests, establish or defend legal claims, and complete privacy-breach assessments.
We collect, use, and disclose personal information with consent or as otherwise permitted or required by law. We limit handling to purposes that a reasonable person would consider appropriate in the circumstances.
5. Information visible to other people
Your username, profile photo, biography, city, public binder or wishlist content, listings, event or organizer content, and other information you choose to publish may be visible to other users or the public. Messages and trade details are shared with the conversation participants. Event submissions may be visible to organizers, reviewers, or other participants as described in the feature.
After approval, public community names, descriptions, cities, categories, owner display names, posts, and comments are visible to signed-in users, including people who have not joined. Posting, commenting, reacting, member lists, and live chat require membership. Private communities are unlisted and their discussions and messages are available only to members, although a person with a valid invite code can submit a join request.
Do not publish sensitive information. People who can see information may save, copy, screenshot, or re-share it outside OpenTribes. Privacy settings reduce visibility but cannot control copies another person has already made.
6. When we disclose personal information
- To other users and organizers as needed for the features you choose to use.
- To service providers that process information for us under contractual or other appropriate protections.
- To investigate fraud, abuse, security incidents, rights complaints, or violations of our Terms, when permitted by law.
- To a court, regulator, law-enforcement body, emergency service, or other person when required or permitted by law, including to respond to a lawful request or an emergency threatening life, health, or security.
- In connection with a proposed or completed financing, reorganization, sale, merger, or transfer of the service, subject to applicable confidentiality and privacy requirements.
- With your direction or additional consent.
We do not sell or rent personal information. We do not currently use personal information for third-party targeted advertising.
7. Service providers and processing locations
We currently use service providers that may process information for the purposes described in this Policy:
- Google services, including Firebase and Google Cloud for authentication, databases, file storage, hosting, technical operations, and limited web analytics; Google Maps and Places for map or venue features; Google sign-in; and Gmail for support communications.
- Apple for Sign in with Apple, App Store distribution, device services, and push-notification delivery on Apple devices.
- Expo and EAS for app build and delivery services and push-notification routing.
8. Processing outside Canada
OpenTribes and its providers may store or process personal information outside your province or outside Canada, including in the United States and other countries where a provider operates. Information processed in another country may be subject to that country's laws and lawful access by its courts, governments, or law-enforcement authorities.
Contact the Privacy Officer if you want more information about our service providers or cross-border processing.
9. Device permissions and your choices
- Camera and photos: used only when you choose to capture or upload profile, item, chat, event, or submission media.
- Location: used only when you request city detection or nearby-event counts. OpenTribes does not offer precise-location sharing in chat. Coordinates are reduced to two decimal places before local caching, and only your city name is written to your public profile.
- Notifications: used to send service, safety, message, trade, event, or account alerts according to your settings.
You can deny or later revoke device permissions in your operating-system settings. A feature that needs the permission may then stop working. Where consent is optional, you may withdraw it, but withdrawal does not invalidate earlier lawful handling.
10. Email and marketing communications
We may send messages needed to provide the service, such as verification, security, account, privacy, moderation, trade, event, or policy notices. Promotional email is not part of account registration or Terms acceptance.
If we introduce promotional email, it will use a separate, optional, unchecked opt-in. Where required, we will obtain consent, identify OpenTribes, provide contact information, include a working unsubscribe method, and process unsubscribe requests within the period required by Canadian anti-spam law. We may retain consent and unsubscribe records to demonstrate compliance.
11. Retention
We retain personal information only as long as reasonably necessary for the identified purposes, legal obligations, and safety needs. Our intended schedule is:
- Active account, profile, messages, and User Content: while the account or content remains active, then delete or de-identify from active systems within 30 days after a valid deletion request, subject to the exceptions below.
- Backups: removed through backup rotation within 90 days and not restored except for disaster recovery, after which deletion controls are reapplied.
- Security and technical logs: generally 90 days unless needed to investigate an incident.
- Moderation reports, actions, appeals, and related safety evidence: generally 24 months after closure.
- Trade records: generally 24 months after completion, cancellation, or closure, then delete or de-identify.
- Marketing and waitlist consent records: while we rely on the consent and for three years after the last relevant communication, withdrawal, or unsubscribe.
- Privacy-breach records: at least 24 months or longer if required by law.
We may retain particular information longer where reasonably necessary for a legal hold, court order, active dispute, fraud or safety investigation, tax or accounting rule, or another legal requirement. Information may also remain in copies made by other users or in de-identified form that no longer identifies you.
12. Account deletion
You may request deletion through the in-app account-deletion control or by emailing opentribes.app@gmail.com. We may need to verify your identity. In-app deletion closes the account and removes the account’s authored community posts and comments and its shared-message content from active systems. Other associated personal information is deleted or de-identified within the schedule above, except information we must retain for the stated legal, fraud-prevention, security, dispute, or safety reasons.
Deleting the app from a device does not delete the account. Content another user independently copied, quoted, or received may remain in that person's possession.
13. Access, correction, and privacy choices
You may ask to access personal information we hold about you, learn how it has been used or disclosed, correct inaccurate information, withdraw consent where applicable, or request deletion. Email opentribes.app@gmail.com with “Privacy Request” in the subject line.
We will verify identity, respond within 30 days unless an extension is permitted by law, and explain any lawful refusal. Access may be limited where disclosure would reveal another person's information, confidential commercial information, privileged material, or information that law permits or requires us to withhold.
You may challenge our compliance by contacting the Privacy Officer. If we do not resolve your concern, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.
14. Safeguards
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, such as authentication and authorization controls, access restrictions, service-provider protections, secure transmission where supported, logging, and procedures for responding to incidents and deletion requests.
No service can guarantee perfect security. Use a strong unique password, protect your device, avoid sending unnecessary sensitive information, and notify us promptly if you suspect unauthorized account access.
15. Privacy breaches
We assess suspected breaches of security safeguards. Where PIPEDA or other applicable law requires, we will report a breach to the appropriate regulator, notify affected individuals, notify another organization that may reduce the risk of harm, and keep the required breach records.
16. Information about other people
Do not provide another person's photo, recording, contact details, location, private messages, or other personal information unless you have authority or permission and the disclosure is lawful. If you believe someone submitted your information without permission, contact us so we can review it.
17. Age restriction
OpenTribes is not intended for anyone under 18, and we do not knowingly collect personal information from a person under 18. If we learn that an underage person created an account, we may close it and delete the associated information, subject to safety and legal retention requirements.
18. Changes to this Policy
We may update this Policy as the service or law changes. We will post the new version and effective date and provide reasonable notice of material changes. We will seek new consent before using personal information for a materially new purpose when required by law.
19. Contact the Privacy Officer
Hei Long Chan, Privacy Officer, OpenTribes
Email: opentribes.app@gmail.com
Mailing address: 23 Sheppard Avenue East, Toronto, Ontario M2N 0C8, Canada