Legal
Privacy Notice
Last updated: April 24, 2026
Locally1st is operated by Heartland Sky LLC ("we", "us", "our"). This Privacy Notice explains what personal information we collect, why we collect it, and how we handle it. We act as the data controller for the information we collect about you.
1. What we collect
- Account info: name, email address, password (hashed), and any display name you choose.
- Vendor profile info: operation name, owner name, story, address, neighborhood, hours, categories, and inventory items you publish.
- Communications: emails and support messages you send us.
- Usage data: pages visited, actions taken, device type, browser, IP address, and approximate location — collected to keep the Service running and prevent abuse.
- Payment info: Locally1st is currently free, so we don't collect any payment information.
2. Why we collect it
- To create and run your account (contract performance);
- To display your vendor profile to neighbors looking for local goods;
- To process subscriptions and send transactional emails (contract);
- To prevent fraud, spam, and abuse (legitimate interest);
- To improve the Service — analytics, bug fixes, feature decisions (legitimate interest);
- To comply with legal obligations (e.g. tax, fraud prevention).
3. Who we share it with
- Service providers (subprocessors): hosting, database, email delivery, error monitoring, and analytics. They process data only on our instructions.
- Payment provider: none at this time — Locally1st is free.
- Professional advisers: legal, accounting, and audit professionals where needed.
- Authorities: when required by law, court order, or to protect rights and safety.
We do not sell your personal information.
4. Public vendor information
Once your application is approved, your operation name, type, neighborhood, story, hours, categories, and inventory items are publicly visible on the map. Don't include personal details in those fields you wouldn't want strangers to see. Your email address and exact home address (if you provided one) are never displayed publicly.
5. How long we keep it
We keep account and vendor data for as long as your account is active, plus a reasonable period afterwards for legal, compliance, and backup purposes. Inactive accounts may be deleted after extended periods of inactivity. Payment records are kept as long as required by tax and accounting law.
6. Your rights
Depending on where you live, you may have rights to: access the data we hold about you, correct inaccuracies, delete it, restrict or object to its processing, withdraw consent, and lodge a complaint with your local data protection authority. To exercise any of these, email us at hello@locallyfirst.app. We aim to respond within one month.
7. International transfers
Our infrastructure providers may store and process data in the United States and other countries. Where required, we use appropriate safeguards such as Standard Contractual Clauses to protect your data when it crosses borders.
8. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit, access controls, and routine backups. No system is perfectly secure — if we ever experience a breach affecting you, we will notify you as required by law.
9. Cookies
We use a small number of cookies and similar technologies:
- Essential cookies for sign-in and security — these can't be disabled without breaking the Service.
- Analytics cookies (when enabled) help us understand how the Service is used in aggregate. We do not use these for advertising.
10. Changes to this notice
We may update this Privacy Notice from time to time. The "last updated" date at the top of the page tells you when. Material changes will be communicated via email or in-product notice.
11. Contact
For privacy questions or to exercise your rights, email hello@locallyfirst.app.