Sweetspot

Privacy Policy

Effective August 30, 2026 · Applies to sweetspot.la and the Sweetspot iOS app

The short version

  • We collect what a wholesale marketplace needs to work: your account, your storefront, and the offers, orders and messages you send through it.
  • We do not sell your personal information, and we do not run advertising or cross-site tracking in the app.
  • Bank and accounting connections are optional and off unless you turn them on. We never see your bank login — Stripe does.
  • The app never asks for your location. It asks for the camera or photo library only when you add a photo.
  • Email support@sweetspot.la and we will hand over or delete your data.

1. Who we are

Sweetspot is a wholesale marketplace for small food businesses — home bakeries, cafés and local suppliers — operated from Los Angeles, California. This policy covers the website at sweetspot.la and the Sweetspot iOS app, which is a wrapper around the same website. “We” means Sweetspot; “you” means the person using it.

2. What we collect

Account

Your email address and password are handled by our authentication provider (Supabase). We store your email, your name if you give one, your city, and your timezone. We never see or store your password.

Your business and storefront

Business name, category, bio, website, Instagram handle, street address, neighbourhood and city, approximate coordinates for that address, and the cover and profile images you upload. If you match your business to a Google Places listing we store that place ID.

What you do on the marketplace

Products you list (titles, descriptions, prices, units, ingredients, allergens, photos), buy posts, offers and revisions, orders, pickup and delivery slots, invoices, ratings you give and receive, and the messages you exchange with other businesses.

Photos and files

Images you upload are stored in our Supabase storage bucket. Images attached to a public storefront are served from public URLs, so treat them as public.

Bank connections — optional

If you connect a bank account, you authenticate with your bank through Stripe Financial Connections. Your bank credentials go to Stripe and never reach us. What we store is the institution name, the account name, type and last four digits, and your transactions: amount, date, description, merchant name and category. We never receive or store full account numbers or bank logins.

Accounting connection — optional

If you connect QuickBooks, we hold an Intuit access token scoped to accounting data and read and write the invoices and transactions you ask us to sync.

Usage and device data

We use Google Analytics 4 to understand which pages get used. That means Google receives your IP address, browser and device type, referring page, and the pages you view, tied to a cookie-based identifier. We have not enabled Google advertising features or cross-site audience sharing. Our servers also keep ordinary request logs, and we record security events such as sign-ins and permission changes.

What we do not collect

No precise device location — the app has no location permission and never asks for one. No advertising identifier, no IDFA, no cross-app or cross-site tracking, no contacts, no health data, no biometrics. We do not knowingly collect anything from children.

3. How we use it

To run your account and your storefront; to show your listings to buyers in your area; to deliver offers, orders, invoices and messages between businesses; to send transactional email you have asked for or that a transaction requires; to compute your sales, expense and ingredient summaries; to keep the marketplace safe, investigate abuse and enforce our terms; and to see, in aggregate, which parts of the product get used.

We do not use your content for advertising, and we do not build profiles of you for anyone else.

4. What is public

A storefront you mark discoverable is public: business name, bio, category, neighbourhood and city, images, ratings, and the products you publish. Anyone on the internet can see it, signed in or not, and search engines can index it. You can turn discoverability off in your business settings.

Your email address, street address, bank data, accounting data and private messages are never public.

5. Automated processing

Two features send content to AI providers, and only when you use them:

  • When you paste a product description and ask us to fill in the fields, that text (up to 2,000 characters) goes to OpenAI.
  • When we read a product photo, or categorise your bank transactions, the image or the transaction description, amount, date and merchant name go to Google (Gemini). Account numbers are never included.

These are suggestions you can edit or reject. Nothing here decides anything about you with legal effect, and no human review is needed for you to override it.

6. Who we share it with

We share personal information only with the service providers that make the product run, each limited to what its job needs:

ProviderWhat it handles
SupabaseAuthentication, database, image storage
VercelWebsite hosting and request logs
StripeBank connections, if you enable them
Intuit QuickBooksAccounting sync, if you connect it
Google AnalyticsProduct usage analytics
Google Maps / PlacesAddress lookup — Google sees your IP when the map script loads
OpenAI, Google GeminiThe AI features in section 5
ResendTransactional email

We also share information when the law requires it, to protect someone’s safety or our rights, and — if Sweetspot is ever acquired or merged — with the acquirer, who would be bound by this policy until they give you notice of a new one.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

7. The iOS app

The Sweetspot app loads sweetspot.la in a web view. It collects nothing on its own and contains no advertising or analytics SDKs of its own — everything in this policy applies to it exactly as it applies to the website.

The app asks for two permissions, and only at the moment you use the feature: the camera, to photograph a product or an order, and your photo library, to attach an existing photo or save an invoice you export. Decline either and the rest of the app works normally. The app does not use the App Tracking Transparency prompt because it does not track you across other companies’ apps or websites.

8. Cookies

We set cookies to keep you signed in and to remember your selected business — the app does not work without those. Google Analytics sets its own cookie to count visitors. We use no advertising cookies. Blocking cookies in your browser will sign you out.

9. How long we keep it

Account, business and marketplace records stay while your account is open, because orders, invoices and ratings are shared records that the other business relies on too. When you ask us to delete your account we remove your personal information and take your storefront down; we keep transaction records where we are required to, and we keep aggregate, non-identifying counts. Disconnecting a bank or QuickBooks connection deletes the imported data with it.

10. Your choices and rights

You can edit or delete your business profile, products and storefront in the app at any time, turn discoverability off, disconnect bank or accounting connections, and change which emails you receive in notification settings.

Email support@sweetspot.la to get a copy of your data, correct it, or have it deleted. We will verify that the request comes from the account holder and respond within 45 days.

California residents have the right under the CCPA to know what we collect and why, to get a copy, to correct or delete it, and not to be treated differently for asking. We do not sell or share personal information, so there is nothing to opt out of — but the request address above is the one to use, and you may designate an authorised agent.

11. Security

Traffic is encrypted in transit. Passwords are handled by our authentication provider and never stored by us. Bank credentials never reach our servers at all. Access to production data is limited to people who need it, and administrative actions are logged. No system is perfectly secure; if a breach affects you we will tell you as the law requires.

12. Children

Sweetspot is for businesses and is not directed to children under 13. If we learn that we have collected information from a child under 13, we will delete it.

13. Where your data lives

Sweetspot is operated in the United States and your information is stored and processed there. If you use it from elsewhere, you are sending your information to the United States, where privacy law differs from your own.

14. Changes

When this policy changes we will update the effective date at the top, and for a change that materially affects how we use your information we will tell you in the app or by email before it takes effect.

15. Contact

Questions, requests or complaints: support@sweetspot.la.

Effective August 30, 2026. Back to Sweetspot