LRLLight Rail LivingPlan

Legal

Privacy Policy

Gorin Collective LLC · Effective September 20, 2026

We collect what the Passport needs to work: your account, your check-ins with the location you shared at that moment, and any mission photos. We never sell it and never track you in the background.

01What this covers

This policy explains how Gorin Collective LLC handles personal information when you use Light Rail Living at lightrailliving.com, including the Passport, missions and the Rail Partners program. It applies to riders and to business customers.

02What we collect

  • Account. Email address, the identifier from a sign-in provider you choose (such as Google), and the profile you fill in: display name, username, bio, home stop and traveler type.
  • Activity. Check-ins, including the location coordinates and accuracy your device reported at the moment you tapped Check in; stamps, points, streaks, badges and mission progress; reviews, tips, collections, posts, follows and offer redemptions.
  • Photos. Images you submit for photo missions, plus the automated verdict about them.
  • Business inquiries. Business name, contact email and notes sent through the Rail Partners form, and billing details for paid plans, which Stripe processes. We do not see or store card numbers.
  • Technical. IP address, browser and device type, pages viewed and interactions (through PostHog analytics), and error reports (through Sentry). Weather and map requests do not include your identity.

We do not collect precise location in the background and we do not track you across other websites.

03How we use it

  • To run the Service: sign you in, keep your Passport, compute points and missions, show your public profile.
  • To verify visits and photos, including automated checks of location and image content. Photo checks use an artificial-intelligence model provided by Anthropic; the photo is sent for analysis and not used to train models.
  • To prevent fraud and abuse of the rewards program.
  • To understand how the product is used and improve it (aggregate analytics).
  • To send transactional messages such as sign-in links, receipts for business plans, and notices about material changes. We do not send marketing email unless you opt in.
  • To comply with law and enforce our Terms.

04Location

Your browser asks for permission before sharing location, and we request it only when you check in or submit a mission photo. The coordinates are stored with that check-in so we can audit rewards. You can decline the permission or turn it off in your device settings; check-ins will not work without it, but everything else will.

05Photos

Mission photos are stored in a private bucket, shown to you in your Passport and used to audit rewards. They are not public and are not shown to businesses. Rejected photos are not stored; only the automated verdict is. You can ask us to delete any photo at any time.

06Who we share it with

  • Service providers that process data for us under contract: Supabase (database, authentication, file storage), Vercel (hosting), Stripe (payments for business plans), PostHog (analytics), Sentry (error reports), Mapbox (maps), OpenWeather (weather), Google (business data and optional sign-in) and Anthropic (AI features).
  • Rail Partners see aggregate counts of visits and redemptions at their business. They do not receive your name, email or location unless you redeem an offer at their counter, in which case they see what is needed to honour it.
  • Other riders see what you make public: display name, username, public collections and reviews.
  • Legal. We may disclose information to comply with law, to protect riders, partners or the public, or as part of a merger or sale of the business, in which case this policy continues to apply.

We do not sell personal information and we do not share it with advertisers.

07Cookies

We use cookies to keep you signed in and, through PostHog, to measure how the product is used. We do not use third-party advertising cookies. You can clear or block cookies in your browser; you will need to sign in again.

08How long we keep it

We keep account and Passport data while your account is active, because points and stamps are the record of what you earned. When you ask us to delete your account we remove personal information within 30 days, except records we must keep for legal, billing or fraud-prevention reasons, which we keep only as long as required. Aggregate statistics that no longer identify you may be kept.

09Your choices and rights

  • Edit your profile any time from the Me page.
  • Ask for a copy of your data, or ask us to correct or delete it, by contacting us. We answer within 30 days.
  • Withhold location permission; the app still works for planning.
  • Ask us to exclude your account from analytics.

Depending on where you live you may have additional rights under laws such as the California Consumer Privacy Act or the GDPR. We honour those requests the same way; write to us and we will explain what applies.

10Children

The Service is not directed to children under 13, and we do not knowingly collect their information. If you believe a child has created an account, contact us and we will delete it.

11Security and where data lives

Data is encrypted in transit, stored with row-level access controls, and reachable only by the people and systems that need it. No system is perfectly secure, so if you learn of a problem, tell us. Our servers are in the United States; if you use the Service from elsewhere, your information is processed there.

12Changes

We may update this policy. The effective date at the top changes when we do, and for material changes we notify account holders by email or in the app. See also the Terms of Service.

13Contact

Reach Gorin Collective LLC through gorincollective.com/contact. Gorin Collective LLC, Phoenix, Arizona.

Questions

Reach Gorin Collective LLC through gorincollective.com/contact. Gorin Collective LLC, Phoenix, Arizona.

TermsRefundsContactgorincollective.com