Legal

Privacy Policy

Effective July 26, 2026 · Last updated July 26, 2026

1. Who We Are

ISO Disco LLC (“ISO Disco,” “we,” “us,” or “our”) operates the In Search Of marketplace at iso-us.com (the “Service”), a reverse / demand-led marketplace where users post items they are searching for and finders or sellers respond with offers.

Questions about this Privacy Policy? Email iso.us.admin@gmail.com.

2. Information We Collect

Account & authentication. When you create an account we collect information needed to register and sign you in via Firebase Authentication, including email address, password (stored by Firebase, not in plaintext by us), and—if you use Google Sign-In—basic Google profile details such as name, email, and profile photo. We may also store email verification status and session markers so we can enforce security rules (including an absolute browser-session max age after which you must sign in again).

Private vs public identity. Your account email is stored in an owner-only private record and is not shown on your public profile by default. Public profile fields may include username/handle, avatar, bio or specialty, social handles you choose to add, city or origin you provide, trust or verification signals, and similar display information.

Onboarding & preferences. Categories, brands, budget band, notification choices, city/origin, style interests, and related taste signals you provide during onboarding or profile setup.

Marketplace activity. ISO listings (name, category, details, budget, duration, images), offers and bids, deal / “found” status, follows, saved items, upvotes or similar engagement signals, and related timestamps.

Media. Avatars, listing images, and offer/proof photos you upload, stored in cloud object storage associated with your account.

Communications. Messages and thread metadata between users (including messages about listings and offers), plus transactional emails or in-app notices we send (for example verification, security, or marketplace activity).

Marketing email (opt-in).If you choose to receive our newsletter or other marketing email, we store your email address, the fact and date of your consent, the wording you agreed to, and the IP address the consent came from, so we can evidence it later. We also record delivery and engagement events from our email provider (for example delivered, opened, bounced, unsubscribed) to keep the list healthy and honour unsubscribes. Marketing email is never sent on the basis of having created an account — it requires a separate, affirmative opt-in.

Payments (beta). The Service currently offers a simulated checkout / escrow experience for product demonstration. We do not collect or store raw payment card numbers. If and when live payments are enabled, payment details will be processed by a third-party payment provider (for example Stripe); we will update this policy accordingly.

Usage, device & security. Pages viewed, feature use, approximate location derived from IP, device/browser type, referral source, cookie or local-storage preferences (including cookie consent), and security signals such as Firebase App Check / reCAPTCHA responses used to protect the Service from abuse.

3. How We Use Your Information

  • To operate the marketplace, display listings, and connect seekers with finders or sellers
  • To authenticate users, verify email where required, manage sessions, and protect accounts
  • To power messaging, offers, notifications, and deal-related workflows
  • To personalize discovery using preferences you provide (for example categories or brands)
  • To maintain trust, reputation, and abuse-prevention signals
  • To send transactional emails (account security, verification, marketplace activity)
  • To send marketing email, such as a newsletter, only where you have separately opted in
  • To improve the product using aggregated analytics (for example Firebase Analytics where available)
  • To comply with law, enforce our Terms of Service, and respond to lawful requests

Marketing email is separate from your account. Creating an account does not subscribe you to anything. We send marketing email only to people who have affirmatively opted in, and we rely on that consent as our legal basis for it. Every marketing message includes a working unsubscribe link and our postal address, and we act on unsubscribes promptly.

Unsubscribing does not disable transactional email.If you opt out of marketing, you will still receive messages the Service needs to send you — email verification, security notices, and marketplace activity such as an offer on your ISO — because those are part of operating your account rather than promotion. You can manage marketplace notification preferences separately in Settings.

We do not sell your email address or share it with third parties for their own marketing.

4. How We Share Your Information

We do not sell your personal data. We share information only as described below:

  • Other users. Public profile fields and marketplace activity you create (listings, offers you make public in context, messages you send to another user) are visible to the people you interact with or to the community as designed by the product.
  • Infrastructure providers. We use Google Firebase (including Authentication, Cloud Firestore, Cloud Storage, Analytics, and App Check) and related Google services to host and secure the Service.
  • Payment processors. Only if and when live payments are enabled; card data would be handled by the processor, not stored as raw PANs by ISO Disco.
  • Service providers. Vendors who help us operate email, hosting, or security under contractual obligations to protect data.
  • Legal & safety. When required by law, or to protect rights, safety, and integrity of the Service and its users.
  • Business transfers. In connection with a merger, acquisition, or asset sale, subject to continued protection of personal data.

5. Cookies & Tracking

We use cookies, local storage, and similar technologies for:

  • Essential — authentication, session continuity, security (including App Check / reCAPTCHA), and remembering cookie consent
  • Analytics — understanding product usage (for example Firebase Analytics when supported by the browser and configuration)

We do not currently use third-party advertising retargeting pixels as a core part of the Service. You can manage browser cookie settings and, where shown, our on-site cookie banner.

6. Your Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or port personal data, and to withdraw consent where processing is consent-based.

Marketing email. You can withdraw consent at any time using the unsubscribe link in any marketing message, or by emailing us. Withdrawing consent does not affect the lawfulness of anything we sent before you withdrew it, and it does not stop transactional email about your account.

EU/UK (GDPR): Email iso.us.admin@gmail.com to exercise these rights. We will respond within the time required by applicable law (typically within 30 days).

California (CCPA/CPRA): You may have the right to know, delete, and correct personal information, and to opt out of “sale” or “sharing” as those terms are defined by law. We do not sell personal information.

7. Data Retention

Marketing contacts.If you unsubscribe, we keep a minimal suppression record — your email address and the fact you opted out — so that we do not email you again by mistake. Suppression records are kept for that purpose only. You can ask us to erase it entirely, with the caveat that doing so removes the record that was preventing future sends.

We retain personal data for as long as your account remains active and as needed to provide the Service. To request account closure or deletion of personal data, email iso.us.admin@gmail.com. We will process verified requests within a reasonable period, generally within 30 days, except where we must retain information for security, fraud prevention, dispute resolution, backups, or legal compliance (which may include limited retention of transaction or safety records).

8. Security

We use industry-standard measures including encryption in transit (TLS), access controls, Firebase security rules, and App Check where configured. No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at iso.us.admin@gmail.com.

9. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. The Service is intended for users who are at least 18 years old (see our ). If you believe a minor has created an account, contact us and we will take appropriate steps to delete it.

10. International Transfers

ISO Disco LLC operates the Service from the United States. Personal data is processed in the US through providers such as Google Firebase. If you access the Service from the EU, UK, or other regions, your information may be transferred to and processed in the United States. Where required, we rely on appropriate transfer mechanisms such as Standard Contractual Clauses.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If changes are material, we will provide notice (for example by email or in-product notice) before they take effect where required. The “Last updated” date at the top of this page reflects the latest revision. Continued use of the Service after the effective date of changes constitutes acceptance of the updated policy.

12. Relationship to Terms of Service

Your use of the Service is also governed by our , which include marketplace conduct rules, disclaimers, and limitation of liability. If there is a conflict between this Privacy Policy and the Terms regarding privacy practices, this Privacy Policy controls for privacy matters.

13. Contact

ISO Disco LLC
d/b/a In Search Of (ISO)
iso.us.admin@gmail.com
iso-us.com