Skip to main content
Lopperly

Privacy Policy

Last Updated: September 5, 2026

Lopperly LLC ("Lopperly," "we," "our," or "us") operates the Lopperly platform, a community for food producers that includes learning resources and a peer-to-peer marketplace for buying, selling, and trading produce and food. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services (collectively, the "Platform").

By accessing or using the Platform, you agree to this Privacy Policy. If you do not agree, please do not use the Platform.


1. Information We Collect

Information You Provide Directly

  • Account information: name, email address, phone number, and password
  • Profile information: display name, bio, profile photo, and social media account handles you choose to add
  • Address information: shipping, pickup, or business address for listings and orders
  • Listing content: photos, descriptions, prices, and other details you submit for listings
  • Communications: messages you send through the Platform or to our support team
  • Payment-related information: we collect only what is necessary to process transactions (see Section 6 — Payment Processing)

Information Collected Automatically

  • Usage data: the pages you view, and specific steps we measure — starting a listing, finishing it, requesting one, and signing in or registering (see Section 4)
  • Session recordings: your browsing sessions may be recorded — a replay of what happened on screen, with the text on the page and anything you type masked out and images and video blocked. Two companies do this: our analytics provider records sessions, and our error tracker records a sample of sessions plus any session in which it records an error (see Section 4)
  • Clicks: our analytics provider captures clicks across the site automatically — which element you clicked and where it sits in the page, but not the text on it (see Section 4)
  • Device and browser information: IP address, browser type and version, operating system, device identifiers
  • Location data: if you allow your browser to share your location, we use it to centre the map on you. If you use the search box once the map is showing a place you chose, that point goes to our servers and on to our search provider so nearby results rank higher — rounded to about a kilometre first, both in your browser and again on our servers, so what we send is an area and not an address (see Section 4)
  • Cookies and similar technologies: see our Cookie Policy

Information From Third Parties

  • Stripe: the status of a seller's payout account, their balances and payouts, confirmation that an order was paid, and fraud, dispute and review information about transactions (see Section 6 — Payment Processing)

2. How We Use Your Information

We use the information we collect to:

  • Create and manage your account
  • Enable you to buy, sell, and trade on the marketplace
  • Display your listings and profile to other users
  • Process transactions and communicate order status
  • Provide customer support
  • Send transactional emails (order confirmations, receipts, account alerts)
  • Send service announcements and policy updates
  • Improve and expand the Platform
  • Understand how the Platform is used, and diagnose errors when it breaks
  • Detect and prevent fraud, abuse, and violations of our Terms of Service
  • Comply with legal obligations
  • Market the Platform, including using your publicly submitted content (see Section 7 — User Content)

3. How We Share Your Information

We do not sell your personal information. We share information only in the following circumstances:

  • With other users: your public profile, listings, and any content you post publicly are visible to other users and to search engines
  • With service providers: we share data with the companies that help us run the Platform, and only what each one needs to do its job. Section 4 names them and says what each one receives.
  • With Stripe: payment processing and seller payouts are handled by Stripe. Section 6 says what we send Stripe and what we receive back; your payment data is governed by Stripe's Privacy Policy
  • With donation partners: when you choose an email-referral partner for a produce donation, we email them your name, your contact email, your exact pickup address rather than the approximate one shown publicly, since they have to turn up at it, and the details of the donation: how it should be collected, how many trees, pesticide status, terrain, and any instructions you wrote. We share your phone number only if it is verified and you opt in for that donation. Choosing an external-link partner does not send your details to that partner.
  • For legal compliance: we may disclose information if required by law, court order, or government authority, or to protect the rights, property, or safety of Lopperly, our users, or others
  • In a business transfer: if Lopperly is acquired, merged, or sold, your information may be transferred as part of that transaction; we will notify you in advance

We do not currently sell personal information to third parties. If we introduce data sharing arrangements that constitute a "sale" under applicable law, we will update this Policy, provide advance notice, and offer an opt-out mechanism before any such sharing begins.


4. The Companies We Use, and What Each One Receives

These are the companies we work with, and what each one receives. We have tried to name all of them, and we would rather be told about a gap than claim there is none.

Where it says your browser talks to a company directly, that company also sees your IP address, because that is unavoidable when your browser makes a request.

Links are the part no list can close. Lopperly builds links out to other sites — directions, add-to-calendar, a business's own website or social account, an event's ticket page — and following one takes you to that company under its terms and its privacy policy, not ours. Nothing is sent until you follow the link, and what is sent is whatever is written into the link itself. The ones we build are described below; the directions and calendar links are in 4.4, because those two carry details of the place or the event with them.

Outbound links to businesses carry a tag saying you came from us. A link to a business's own website, its social accounts, or an event's own page has utm_source=lopperly added to it, unless the link already carries its own tags. That tells the site you arrived from Lopperly. It says nothing about who you are, and we get nothing back — it is read by the destination's own analytics, not by ours.

Contact links do not involve a company at all. "Contact seller" and the phone numbers on a page are mailto: and tel: links: following one hands the address or number to whatever mail or phone app your device uses. Nothing is sent to us or to anyone else by opening it.

4.1 Analytics — PostHog

Your browser does not talk to PostHog directly. Analytics go to an address on our own domain (lopperly.com/ingest), and our server passes them on. We do not attach your IP address when we do, so the request PostHog receives comes from our server rather than from you.

PostHog receives the pages you view and the steps we measure — starting a listing, finishing it, requesting one, signing in, registering — along with your browser and device type.

PostHog may record your browsing session, with the content masked. A recording is a replay of what happened on screen: the pages you moved through, where and how often you clicked, and when you were typing. The text on the page and everything you type are masked — replaced with blanks before the recording leaves your browser — and images and video are blocked, so a replay shows the layout of the page and how you moved through it, not the words on it or the pictures in it. Whether a session is recorded, and what share of sessions are, is a setting in PostHog's own dashboard rather than a value fixed in our code — recording is switched on, but we do not pin it to every session, so treat any given session as one that may be recorded. Recordings are kept for 30 days and then deleted. This is in addition to Sentry's recording in 4.2 — two companies record sessions, not one, and both recordings mask text and typing and block media in the same way.

PostHog also captures clicks automatically. This is a feature called autocapture, and it means PostHog is told about clicks across the whole site: which element you clicked, what kind of element it is, and where it sits in the page. The text on the thing you clicked is not sent. Nothing has to be added to our code for a click to be captured, and we do not pick which ones are.

Our own code in your browser sends a named list of events on top of that, and those we filter by name: coordinates and anything you typed — map positions, search terms, listing titles and descriptions, pickup notes, names, email addresses and phone numbers — are removed before the event is sent. Separately, we strip coordinates and search terms out of the page address attached to every event, including the automatic ones, and we mask the tracking identifiers that advertising networks add to links.

Masking is not the same as removing everything, so here is what still reaches PostHog. The structure of the page survives — which elements exist, how they are laid out, which one you interacted with, and when. So does the web address of a link you click, which for a listing or a seller contains a readable name, and the town, in the address itself — that address is the page's public web address, the same one anyone visiting the page would see. The filtering we apply to our own events is a list of property names and is unrelated to masking — neither one is a substitute for the other.

Once you are signed in, your events and recordings are tied to your account, so we can follow a flow across signing in rather than seeing two unconnected strangers.

Our servers send PostHog events of their own, for the things that happen with no browser attached — a seller approving from an email link, Stripe confirming a payment, a listing expiring overnight. These go to PostHog directly, not through our own domain. They are:

  • What happens to an order after it is requested: approved, declined, cancelled, paid, completed, marked a no-show, refunded, or disputed. Requesting an order is not one of these — that is measured in your browser, like the other steps above. Each carries the order and listing reference, the listing type and category, a price band rather than a price, the quantity, and how many hours passed since the request.
  • What happens to a listing: that it sold out, or that it expired.
  • Sign-in and registration attempts, and whether each one worked. A failure carries a reason from a fixed list — an unrecognised email, an expired code, too many attempts. Neither the email address nor the code is sent.
  • That a listing page was viewed. This one is recorded as the page is served rather than in your browser, and carries the listing's details and your browser's user-agent string. Views by obvious bots are not recorded.
  • That a campaign or guide address did not resolve. When a link to a seasonal campaign map or guide names a campaign or a region that does not exist, we record which name was asked for and why it did not resolve, so a broken link is visible rather than silently sending people back to the map. Nothing about you is attached.

While a Lopperly support session is viewing your account, nothing is sent to PostHog and nothing is recorded.

4.2 Errors and Session Replay — Sentry

Sentry receives errors and performance information, and it records session replay as well: a reconstruction of pages, clicks, and navigation. This is a second recording, alongside PostHog's in 4.1. Like PostHog's, it does not leave your browser for Sentry directly — it goes to an address on our own domain (lopperly.com/monitoring) and our server passes it on.

About 1 in 20 browsing sessions is recorded even when nothing goes wrong, and every session in which Sentry records an error is recorded. Not every error reaches Sentry: one browser quirk we know about and cannot fix is discarded before it is sent, and an error we never see does not trigger a recording. Text on the page and anything you type into a form are masked and images and video are blocked, exactly as they are in PostHog's recording — a replay shows the shape of the page and what was clicked, not the words on it or the pictures in it.

While a Lopperly support session is viewing your account, Sentry is not started at all: no errors, no performance information, and no recording.

4.3 Search — Algolia

Your browser does not talk to Algolia; our servers do. When you use the search box, Algolia receives what you typed. If the map is showing a place you have chosen — by moving it, following a link to a place, or allowing your browser to share your location — we also send that point so that nearby results rank higher. Until something has expressed a place, no coordinates are sent at all — a map sitting on the view it opened on is not a statement about where you are, and we do not treat it as one.

The point is rounded to about a kilometre before it reaches Algolia, and it is rounded twice. Your browser rounds it before sending it to us, which is what keeps a precise position out of our own request logs. Our servers then round again whatever arrives, and that second pass is the actual guarantee: the search endpoints are public, so anything at all can call them with a coordinate as precise as it likes, and rounding there does not depend on the request having come from our own site.

Both rounds snap the point onto a fixed grid of roughly a kilometre, rather than shifting it by a random amount. That is deliberate. A search box sends a fresh request every few hundred milliseconds as you type, and a random offset re-drawn each time would be a fresh sample of the same true point — average enough of them and the real one comes back, so the longer you type the worse it would get. A grid has no such leak: every position inside a cell reports the identical value, so repeating the query adds nothing.

Algolia also holds the listings, places, and events we publish, so that they can be searched. That is the same information already visible on the site, and it follows the same rule as the rest of the Platform: the pickup point of a private listing is shown as an approximate location, not an exact one.

4.4 Maps, Directions, and Calendars — Mapbox, Google, Apple, Microsoft

Your browser talks to Mapbox directly to load map tiles and map images, so Mapbox sees which area you are looking at. The map library also reports map loads back to Mapbox and keeps an identifier for that in your browser's storage; this is part of the library and cannot be separated from it.

Separately, when you type an address into an address box, our servers pass what you typed to a geocoding provider — Mapbox or MapAtlas — to turn it into a location. Your browser does not contact them for this; we relay it. Which of the two answers is chosen per session, and the choice is not yours to make.

Directions links go elsewhere. Tapping "directions" on a business or a listing opens Google Maps or, on an Apple device, Apple Maps, and hands that app the destination — a business's public street address, or a listing's approximate pickup point, which is the same approximate point the page itself shows. That is a link you choose to follow; nothing is sent until you do.

The directions link on an accepted order sends the exact pickup address to Google. Once a seller accepts your order, the pickup details on your orders page show the real street address rather than the approximate one — you need it in order to turn up, and that is deliberate. The "open in maps" link beside it goes to Google Maps (maps.google.com) on every device, Apple ones included: it does not offer Apple Maps and does not use whichever maps app you have chosen. The address is written into the link, so following it tells Google the exact pickup address of that order, which is frequently the seller's home. If we have no street address on file for the listing, the link carries the listing's coordinates instead — in that case the exact stored coordinates, not the approximate point shown publicly. Nothing is sent until you tap it; the address is printed on the page directly above, so you can copy it into a maps app of your own choosing instead.

Add-to-calendar links go to Google or Microsoft. An event page offers to add the event to Google Calendar or to Outlook.com. Each is a link, and the event's title, description, location and start and end times are written into the link itself, so following one hands those to Google or to Microsoft respectively. The third option on that menu downloads a calendar file from us, and involves neither company.

4.5 Anti-Spam — Google reCAPTCHA

Your browser talks to Google directly, but only on the contact form. Opening the contact dialog loads reCAPTCHA, which examines your browser in order to decide whether you are a person. It is not loaded anywhere else on the site.

4.6 Instagram Posts — Meta

Some business and organization pages show that business's Instagram post. When one of those scrolls near your screen, your browser loads Instagram's embed script and the post itself from Meta, so Meta sees your IP address, the Lopperly page you are on, and any Instagram cookies your browser already holds. Nothing is loaded until the embed comes into view, so scrolling past it or never reaching it means no request is made.

This happens only on a page that carries an embed: the public page for a business or organization, and the panel that opens when you select one of those on the map. A business has an embed only if it has added an Instagram link and has not turned the embed off. Listings, seller profiles, and anything showing a private pickup point never carry one.

4.7 Email, Text Messages, and Payments

  • Resend delivers our email. It receives your email address and the contents of the message.
  • Twilio delivers our text messages. It receives your phone number and the contents of the message.
  • Stripe handles payments and seller payouts. See Section 6.

4.8 Hosting and Images

Amazon Web Services hosts the Platform and stores the photos you upload. Your browser uploads photos to AWS storage directly, and loads them back through Amazon's content delivery network. Every picture you or a seller uploads through Lopperly — listing photos, profile pictures — is held there.

Not every picture on the site is one of ours, and your browser fetches the rest from wherever they live. A donation partner's logo and banner are stored as a web address rather than as a file, and that address can point at any host on the internet. Some older business logos and event photos are the same: they were saved as addresses before we moved to uploading the files, and those entries still point where they always did. Newer ones are uploads, so this gets smaller over time rather than larger.

This one needs no click. When a page carrying such a picture loads, your browser requests it from that host as part of drawing the page. That host therefore sees your IP address and which Lopperly page you were on, and can set its own cookies while answering. Unlike the links in the rest of this section, there is nothing for you to decide to follow.

We cannot name the company, because there isn't one. It is whichever host the address happens to point at — chosen when the entry was created, and different from one entry to the next. That is the plainest illustration of why this section says we have tried to name every company we work with rather than claiming the list is closed: here the list cannot be closed even in principle.

Where it can happen: the public page for a business or organization, the page for one of its locations, an event's page, the panel that opens when you select a business on the map, and — once you are signed in — the list of donation partners and the list of businesses you follow. Everywhere else, the pictures come from our own storage.

4.9 Operational Tools That Receive Nothing About You — Slack and Grafana Cloud

Two more companies appear in how we run the Platform. Neither receives anything about you personally. They are listed anyway, because a section that quietly left out the companies we judged uninteresting would be a worse description than one that includes them.

  • Slack receives a scheduled message with platform-wide totals: how many listings are currently visible, broken down by produce category, and how many accounts have registered. Counts only — no names, no email addresses, no listing content.
  • Grafana Cloud receives operational measurements from our servers: how many geocoding requests, emails and text messages went out, how many searches each index answered or failed, whether scheduled jobs succeeded and when, and counts of fraud-related Stripe notifications by type. These are counters and timestamps about our systems, not records about people.

4.10 Your Choices

There is no consent banner on Lopperly and no setting that switches Sections 4.1 or 4.2 off. Saying otherwise would be inventing a control we have not built. Your practical options are your browser's own: clearing or blocking site data, or using a content blocker. Our Cookie Policy explains what each of those breaks.


5. Phone Numbers and SMS

You may optionally add a verified phone number to your account. We use your phone number for authentication and for transactions you have opted into. We do not use your phone number for marketing or promotional purposes.

SMS messages we send are transactional in nature. Standard message and data rates may apply depending on your carrier.

You can remove your phone number at any time from Account Settings. Carrier-supported opt-out mechanisms are also available. SMS messages are delivered by Twilio; your phone number is shared with Twilio solely to deliver the message.


6. Payment Processing

All payments and seller payouts are handled by Stripe. It is the only payment processor we use.

Card numbers and bank account numbers never reach us. You enter card details on Stripe's own checkout page, and sellers complete identity and bank-account onboarding on Stripe's own pages. We never receive and never store a full card number or a full bank account number.

Stripe's record of a seller does reach our servers, and we keep almost none of it. When a connected account changes, we ask Stripe for that account, and Stripe's notifications to us carry the affected object with them. Those objects are Stripe's own and can include the identity and bank-account fields it holds to verify a seller, so it would be wrong to tell you none of it ever passes through us. What we do with it is read three values — whether onboarding is finished, whether the account can accept card payments, and whether payouts are enabled — and store those. Stripe's verification data is not written to our database. (A diagnostic setting can copy the raw notification into our server logs while we debug a payment problem; it is off by default.)

What we send Stripe. When you buy something, we create the checkout session and send Stripe your email address, the listing's title and price, the tax category of what is being sold, and our own order and seller reference numbers. When a seller sets up payouts, we create a connected account for them and send Stripe their email address, the name on their account split into a first and last name, their seller display name, and the web address of their public Lopperly seller page.

What we receive from Stripe. More than a confirmation:

  • The connected account's identifier and status — whether onboarding is finished, whether it can accept card payments, whether payouts are enabled.
  • A seller's balance, their pending payout and its expected arrival date, their balance transactions, and the result of payouts we initiate, including the failure code and message when one fails.
  • Payment confirmation for an order: the checkout session and payment intent identifiers, and the amount actually charged.
  • Refunds, and chargebacks and how they were resolved.
  • Fraud and risk information: early fraud warnings and the type of fraud reported, and Stripe's own reviews of a payment and the reason each was opened. We use these to pause a seller's sales or payouts while we look at the account.
  • Notices that a connected account changed, that one of its capabilities changed, or that a seller disconnected it from Lopperly.

Your payment data is governed by Stripe's Privacy Policy.


7. User Content and Marketing

Content you submit to the Platform — including listing photos, descriptions, and profile information — remains yours. By submitting content, you grant Lopperly a non-exclusive, royalty-free, worldwide license to use, reproduce, display, and distribute that content for the purpose of operating the Platform and for Lopperly's marketing and promotional activities (e.g., social media posts, advertisements, website features). We will not sell your content to third parties.


8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. If you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it by law (e.g., for tax or fraud-prevention purposes) or where it has been shared publicly (e.g., cached by search engines).


9. Security

We implement industry-standard technical and organizational measures to protect your information against unauthorized access, loss, or alteration. However, no method of transmission over the internet or electronic storage is completely secure. You use the Platform at your own risk.


10. Children's Privacy

The Platform is intended for users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected personal information from a minor, we will delete it promptly. If you believe a minor has provided us with personal information, please contact us at hello@lopperly.com.


11. Your California Privacy Rights (CCPA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: request disclosure of the categories and specific pieces of personal information we have collected about you
  • Right to Delete: request deletion of your personal information, subject to certain exceptions
  • Right to Correct: request correction of inaccurate personal information
  • Right to Non-Discrimination: we will not discriminate against you for exercising your privacy rights

To submit a request, email us at hello@lopperly.com with the subject line "California Privacy Request." We will respond within 45 days.

We do not currently sell personal information. If that changes, we will provide a "Do Not Sell My Personal Information" mechanism and notify you in advance.


12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on the Platform at least 30 days before the changes take effect. Your continued use of the Platform after the effective date constitutes acceptance of the updated Policy.


13. Contact Us

If you have questions or concerns about this Privacy Policy, please contact us:

Lopperly LLC 13209 Valle Verde Terrace Poway, CA 92064

hello@lopperly.com