Legal
Privacy Policy
Effective date: September 8, 2026
Spot lets you send a friend a treat right inside your iMessage thread — “I’ll spot you a matcha.” They open it, confirm their phone number, and use the gift at a participating shop, on the web or in Apple Wallet. Spot also offers a personal assistant in iMessage, including optional Google Calendar features. This policy explains what we collect, why, who we share it with, and the choices you have.
1. Who we are
Spot is operated by Tristan Shin (“Spot,” “we,” “us,” or “our”). This policy covers the Spot iOS app, the Spot iMessage extension, the Spot personal assistant and optional connected accounts, and the web pages you use to claim a gift. You can reach us at support@usespot.me or by mail at 130 Stockton Avenue, Apt. 724, San Jose, CA 95126.
2. Information we collect
Phone number
Your phone number is your Spot account. We use it to create your account, to text you a one-time code that verifies it’s really you, to bind a gift to its sender and recipient, and to protect the service against fraud and abuse. Sign-in and account recovery work through that text code.
Your pickup details
When you order a pickup gift, you provide your pickup name, email and phone number. We save these details for future pickups and share them with the shop to fulfill your order. You may also add an optional address, which is saved privately with your pickup details. You can edit or remove it before a later order. The details accepted for an earlier order remain in that order’s private record. Your pickup details are not shown to the gift sender or on your public profile. Deleting your account removes your saved pickup details and the copies in past order attempts.
Account and device identifiers
- A server-side account ID that represents your account.
- A salted, one-way hash of your phone number that keys our own first-party usage metrics. It is not reversible back to your number and is never shared with anyone else.
- An anonymous device identifier the app generates to stage a draft gift before it’s claimed and to prevent duplicate sends. It stays anonymous unless and until a gift is bound to a verified phone number.
Gifts you send
When you send a gift we store the item you chose, an optional short note you type, an optional occasion or stamp (such as Birthday or Thanks), and the recipient you send it to, so we can deliver the gift to the right person. If you set a birthday for someone in Your People, we keep only the month and day, never the year.
Recipient details you provide
To send a gift you provide the recipient’s phone number, which becomes part of that gift. If you granted Contacts access, names from your address book are used on your device to help you pick and label people — see “Contacts” below. For people already in Your People, we store their phone number and private display name, including a name matched from Contacts, so your roster survives a reinstall. Contact photos and contacts you did not add to Your People stay on your device.
Purchases and redemption
We keep one record per gift — which item was sent, and whether it has been claimed and redeemed — so we can show you your sent and received gifts, fulfill each gift, and reconcile it with the merchant. Every charge maps to exactly one gift.
Google Calendar and assistant requests
Connecting Google Calendar is optional. If you choose to authorize access, Spot receives the Google account and calendar information needed to answer your requests, such as calendar names and identifiers, time zones, availability, and event titles, dates, times, descriptions, locations, and attendees. Spot may create, update, or delete a calendar event only when you request the change and explicitly approve its details.
We process your assistant messages and only the relevant calendar details needed to understand and complete the task you requested. We retain limited connected-account references, permission status, task and approval records, and relevant event details when needed to operate, secure, or support the service. Google account authorization is handled by Google and our connection provider, Composio; Spot does not receive your Google password or store raw Google OAuth access or refresh tokens.
Spot does not sell Google user data, use it for advertising, or use it to train or improve generalized artificial-intelligence or machine-learning models. Spot’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Café requests, introductions, and contribution recognition
When you request a café, we store the public business information you chose, such as its name, address, and map location, together with your account so we can count one request per person and tell you if that exact café joins. The founder-facing request list shows your verified account phone, the profile name and handle you chose, your answer, and any café-owner contact you voluntarily supplied. This founder-only information is used to follow up on the request and warm-intro offer; it is not shown to other users.
If a request, credited introduction, or qualifying launch-time gift leads to a contribution record, that record is private to you by default. You may publish or unpublish each earned record separately. A published record may show the café, contribution type, date, and founding rank or aggregate count; it never shows your phone number, the café owner contact, or a gift recipient. If you explicitly claim a manual introduction payout, your verified account phone is placed in the founder’s payout queue and is not made public.
Redeemed-spot memories
After you redeem a gift, Spot may invite you to add photos to a memory for that gift. Adding a photo is optional. We store the photos you choose, a smaller thumbnail, and the redeemed gift details needed to show the memory — such as the item, participating shop, redemption date, original note, declared occasion, and your private label for the sender. Every memory starts private. You may separately turn on “show these photos on my public profile” for a memory that has a photo. A published memory shows only the item, shop or branch, redemption date, and the photos you attached; it never shows the gift identifier, sender, note, occasion, payment amount, or storage address. Adding or removing a photo makes the memory private again until you review and republish it. You can turn sharing off at any time, which removes the memory from public and friend profile reads.
Usage analytics
We record first-party product events — for example when a gift is paid for, opened, claimed, delivered, or when a private-memory step is reached — along with basic details such as payment rail and counts. Private-memory events contain only the step, source, bounded error code, and photo or memory count — never photo contents, notes, names, or shop labels. These events carry the salted-hash identifier above. They are used only for our own analytics and to run the service.
On our website we also use Vercel Web Analytics to count visits and see which pages people land on. It is cookieless and does not build a profile of you across sites. Before any page view is recorded we remove the parts of a web address that could identify you or a gift: gift links, the café-connection page, and our internal pages are never recorded at all; a profile page is recorded only as “a profile page” without the handle; and everything in a link’s query string is dropped except basic campaign tags.
On the public For cafés page only, we use the Meta Pixel to measure whether a Meta ad led someone to view that page, open our scheduling link, or start a WhatsApp conversation. Meta may receive the page URL and campaign tags, IP address, browser and device information, Meta cookies or identifiers, and the bounded event name. We do not send Meta a gift link, profile handle, phone number, email address, Calendly booking details, WhatsApp message contents, payment data, or location. The Pixel is not present on gift, profile, assistant, café-management, founder-dashboard, or connection pages. On the For cafés page, the Pixel loads even when a browser sends Global Privacy Control or Do Not Track.
Meta advertising attribution
The standalone iPhone app uses Meta App Events to report automatic install and app-open events so we can measure whether a Meta ad led to an install. Meta may receive an app- or device-scoped identifier, the install/open event, limited SDK diagnostic data, and basic technical data. Spot disables advertising-identifier collection and sends no custom gift, contact, payment, or location events to Meta. Attribution uses Apple’s SKAdNetwork and is not used by Spot for user-level tracking across apps.
Location you choose to share
Location sharing is optional and off until you choose a person to share with. While sharing is active, Spot stores one overwritten last-known location, not a location history. The app uploads the device fix at full precision; each sharing grant controls whether the selected person sees a precise location or a neighborhood-level approximate location. Only people you explicitly select can view it.
You can pause sharing to hide your location from everyone, change a person’s precision, or revoke a person’s access at any time. Pausing hides the stored fix but does not delete it. Account deletion removes the stored location and all sharing grants.
Being found by your phone number
If you claim a @handle, you get a public profile page at usespot.me/@yourhandle. Separately from that page, you can choose to let someone who already has your phone number match it to that profile — so a friend who knows your number can find you without you sending them a link.
This is off unless you turn it on, in Account under Privacy. While it is off, your number does not lead anyone to your profile. Turning it on does not change what your profile page shows, and it never works in reverse: your phone number is never shown to anyone, and no page or lookup will reveal the number behind a handle. You can turn it back off at any time. People you have explicitly shared with can still see what you shared with them, because you chose them individually.
When someone checks numbers against Spot this way, we use those numbers to answer the question and do not store them; we keep only a count of how many were checked and how many matched.
What we do not collect
- Your card number. Payment runs through Apple Pay, which is tokenized by our payments processor. Spot only ever receives a payment token — never your card number, security code, or expiration date.
- Your full address book or contact photos. We do not upload or harvest your full contact list. We store only the phone numbers you choose and private display names for people in Your People, as described above; contact photos stay on your device. If you use Spot to check which of your contacts are on Spot, the numbers checked are used to answer that question and are not stored.
- Your precise location for café ranking and reminders. The nearby list sends a coordinate to rank cafés by distance. Spot does not keep that precise fix or a location history. If you consent during onboarding, Spot keeps one first-seen point rounded to neighborhood-level precision; it does not move when you later open Spot elsewhere. We use that approximate origin for aggregate adoption views and consented regional café announcements, and never put it in logs or analytics. The walk-past reminder is computed entirely on your phone and never uploads a coordinate. These café features remain separate from the optional friend-location sharing described above. You can turn the reminder off in Account and revoke location permission in iOS Settings without losing anything else.
- Browsing history, health data, or photos and media you do not choose to attach to a redeemed-spot memory.
- Your advertising identifier. Spot explicitly disables IDFA collection and does not track you across other apps or websites. The App Tracking Transparency prompt does not apply to Spot’s SKAdNetwork-based install attribution.
3. How we use your information
- To create and secure your account and verify it by text code.
- To send gifts, deliver them, and let recipients claim and redeem them.
- To show you your sent and received gifts, private redeemed memories, and memories you explicitly publish.
- To answer your assistant requests, show your Google Calendar schedule and availability, and make only the calendar changes you explicitly approve.
- To track café requests, tell requesters when a café joins, and show private or owner-published contribution records.
- To show your last-known location, at the precision you choose, only to friends you explicitly select.
- To prevent fraud, abuse, and misuse, and to enforce our Terms.
- To provide support when you contact us.
- To measure and improve the service with our own first-party analytics.
- To measure aggregate Meta ad installs and app opens.
- To comply with law and respond to lawful requests.
4. Payments and gift cards
You pay with Apple Pay. The payment is tokenized before it reaches us, and the app forwards only a token to our server — Spot never sees or stores your card number, security code, or expiration date. Payments are processed by Stripe.
Spot is not the issuer of the gift card. Each gift is a merchant gift card issued, fulfilled, and redeemed by the participating merchant or its gift-card provider, such as Square. The code needed to redeem a gift is delivered only through the signed Apple Wallet pass or the verified claim flow and is shown only to the verified recipient; it is not stored in the app as plain text.
5. How we share your information
We share information only as needed to run Spot:
- Service providers that operate the service on our behalf: Apple (Apple Pay, Wallet, Messages), Stripe (payment processing), Square and participating merchants (issuing and redeeming gift cards), our text message provider (sending one-time codes), Meta (limited website conversion measurement and app install/open attribution), and our cloud hosting and website-analytics provider (Vercel). For the optional personal assistant, these also include Google (Google Calendar), Composio (Google account authorization and calendar access), messaging and cloud-infrastructure providers, and artificial-intelligence processing providers handling only the request-specific information needed to provide the feature you asked for.
- Participating merchants, to the extent needed to issue and redeem the specific gift.
- Legal and safety: to comply with law, enforce our Terms, or protect the rights, safety, and property of Spot, our users, or the public.
- Business transfer: if Spot is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction.
We do not sell your personal information. The limited For cafés page events described above are shared with Meta to measure and improve Spot’s own ads; some privacy laws may call that “sharing” for cross-context behavioral advertising. We do not share gift, account, contact, payment, assistant, or location data for advertising.
Google Calendar data is shared only with service providers needed to complete your requested assistant task or when otherwise required by law; it is not shared with advertising platforms or used to train generalized artificial-intelligence models.
When you choose location sharing, the selected Spot users receive the precise or approximate last-known location you authorized for them. Spot does not disclose that location to other users.
When you choose to publish a café contribution, visitors to your public or connection profile receive only that published contribution record. You can unpublish it at any time.
6. Contacts
Contacts access is optional. If you grant it, Spot reads your address book on your device to help you find and label the person you’re sending to. Spot does not upload your full address book. When a person is already in Your People, Spot can back up that person’s phone number and matched display name to your private roster so it survives a reinstall. Contact photos and contacts you did not add stay on your device.
Whether you can be found this way by someone who has your number is a separate, opt-in setting described under “Being found by your phone number” above. It is off until you turn it on.
7. How long we keep information
We keep your account information for as long as your account is active, and gift records for as long as needed to deliver, support, and reconcile the gift and to meet legal, tax, fraud-prevention, and accounting obligations. Memory photos remain until you remove a photo or delete your account. Published memories become private immediately when you turn sharing off or change their photo stack. Café contribution records remain private unless you publish them; unpublishing removes them from profile reads immediately, and account deletion removes the identifiable request and contribution evidence. We keep only one overwritten last-known location while the location-sharing feature remains configured; pausing hides it from every viewer, and revoking a grant ends that person’s access. We retain Google Calendar connection references and relevant assistant task records only as long as needed to maintain the connection, complete or support your requests, preserve approval and security records, and satisfy legal obligations. Disconnecting Google Calendar or revoking Spot’s access through your Google Account stops future access; limited historical task and security records may remain where needed for those purposes. When you delete your account we remove your personal data and queue private memory photos for physical deletion, except where we are required or permitted by law to retain it. Deleting your account does not invalidate gifts already delivered to recipients.
8. Your choices and rights
You can delete your account and personal data at any time in the app — open your account settings and choose to delete your account. We confirm the request with a one-time code texted to you. You can also email support@usespot.me to request access to, correction of, or deletion of your information. You can also decline Camera access in iOS Settings, remove individual memory photos, and publish or unpublish each photo-bearing memory from its detail view.
You can disconnect Google Calendar, revoke Spot’s authorization in your Google Account’s third-party connections, or email support@usespot.me to request deletion of your connected-account information and assistant data. Revoking access stops Spot from making new Google Calendar requests.
Depending on where you live, including under the California Consumer Privacy Act, you may have the right to know what personal information we hold, to request its deletion or correction, and to not be discriminated against for exercising these rights, and to opt out of the limited advertising-data sharing described above. The For cafés page does not process Global Privacy Control or Do Not Track signals as automatic opt-out requests. To exercise a privacy right, contact us at the email above; we may need to verify your request using your phone number.
You can also turn being found by your phone number on or off at any time in Account under Privacy. It is off by default, and turning it off again stops new lookups immediately without affecting your profile page.
You can publish or unpublish each earned café contribution separately in your profile. These records start private, and unpublishing takes effect immediately.
Most of the text messages we send are transactional: one-time sign-in codes, account notices, a link when someone sends you a gift, your claim code, and updates about a gift you sent or received. If you were sent a gift, the person who sent it gave us your number for the purpose of delivering it to you.
We also send promotional messages, such as news that a new café has joined Spot, but only to people who have separately opted in to them. That opt-in is its own choice, it is never pre-selected, it is never required to buy or receive a gift, and you can withdraw it at any time in the Spot app under settings. Declining it does not stop the transactional messages above, which are part of using Spot.
You can stop any message by replying STOP, and reply HELP for help. Message frequency varies and message and data rates may apply.
9. Children
Spot is not directed to children under 13, and you must be at least 13 to use it. If we learn that someone under 13 has used Spot, we may suspend the account and delete their personal information as required by law.
10. Security
We use technical and organizational measures to protect your information, including verifying sensitive actions with a one-time text code and keeping gift redeem codes behind the verified claim flow. Connected Google account access is limited to authorized permissions, and calendar changes require your explicit approval. No method of transmission or storage is perfectly secure, but we work to protect your information and to limit what we collect in the first place.
11. Where Spot operates
Spot is available only in the United States, and your information is processed in the United States.
12. Changes to this policy
We may update this policy from time to time. When we make material changes we will update the effective date above and, where appropriate, notify you in the app. Your continued use of Spot after an update takes effect means you accept the updated policy.
13. Contact us
Questions or privacy requests? Email support@usespot.me or write to us at 130 Stockton Avenue, Apt. 724, San Jose, CA 95126. See also our Terms of Service.
Spot collects a phone number (account and text verification), the gift you send (item, optional note, occasion, recipient), optional private-by-default photos you attach after redemption and may publish separately per memory, and first-party usage analytics keyed by a salted hash of your phone. With onboarding consent, Spot also keeps one write-once, neighborhood-level first-seen point for aggregate adoption and geographically relevant marketing; it is not a movement history and is never logged or placed in analytics. If you opt into friend-location sharing, it also stores one overwritten last-known location and shows it only to people you select, at the precision you choose. If you connect Google Calendar, Spot uses relevant calendar and event information only to answer your requests and make changes you approve. The standalone app sends automatic install/open attribution to Meta with advertising-ID collection disabled. On the public For cafés page only, Meta receives limited page and contact-link events for Spot ad measurement, including when a browser sends Global Privacy Control or Do Not Track; gift, account, contact, payment, assistant, and location data are excluded. Spot does not store your card number or upload your full address book or contact photos.