LARP — Privacy Policy
Last updated: August 20, 2026 · Effective date: August 20, 2026
1. Introduction & scope
This Privacy Policy explains how Larp Marketplace LLC ("LARP," "we," "us") collects, uses, discloses, and protects personal information when you use the LARP apps, website, and services (the "Services"). It applies to Creators, Owners, and site visitors. Capitalized terms not defined here have the meaning in the Terms of Service.
2. Notice at Collection — what we collect, why, and how long (summary)
| Category (CCPA/CPRA) | Examples for LARP | Source | Purpose | Retention (target) |
|---|---|---|---|---|
| Identifiers | Name, email, phone, account ID, IP address | You; your device; your Google or Apple sign-in, if you use one (see §9) | Create/operate account; communicate; security | While account active; after deletion, retained only where tied to records we must keep for legal/tax/dispute reasons (see §12) |
| Government identifier (Sensitive PI) | Driver's license / passport / ID document & number | You, via our verification vendor | Verify identity before an Owner publishes a Listing and before a Creator books a Session; fraud/safety | Vendor-held; minimized at LARP — see §6 |
| Biometric information (Sensitive PI / special category) | Live selfie, facial geometry / face-match used for liveness & identity | You, via our verification vendor | Confirm the ID belongs to you, before you publish a Listing or book a Session; prevent fraud | Vendor-held. Our limit: no longer than 3 years from your last interaction; destroyed sooner on account deletion or request — see §6.4 for how that is carried out |
| Commercial information | Bookings, Sessions, transactions, reviews | You; the Services | Operate the marketplace; support; disputes | While account active; booking records tied to payments, disputes, or legal obligations are archived after deletion (see §12) |
| Financial information | Payment card / bank details — collected and stored by Stripe, not LARP; LARP sees limited tokens/last-4 | Stripe | Process payments and payouts | Held by Stripe under Stripe's privacy policy and Stripe's terms |
| Geolocation | Approximate location for discovery; meeting location of a Session (revealed after booking) | You; your device | Show nearby Vehicles (public map pins are deliberately approximate); share the exact meeting location after a confirmed booking | While needed for the Session; afterwards only as part of retained booking records (see §12) |
| Audio/visual (User Content) | Listing photos, photos you share, messages | You | Operate Listings/Sessions; evidence in disputes | While account active; dispute/claim evidence may be retained after deletion (see §12) |
| Internet/device & usage | Device type, app/version, pages, cookies & similar tech | Your device | Security, diagnostics, improve the Services | As long as needed for security and to operate the Services |
| Inferences (if any) | Preferences derived from use | The Services | Personalize discovery | While account active |
We do not knowingly collect: driving records, DMV data, or vehicle telematics/GPS-during-driving — because LARP has no driving. (Unlike a car-rental platform, we do not track a moving vehicle; we use only the agreed meeting location.)
3. How we use personal information
To: provide and operate the Services; verify identity and prevent fraud; process payments/payouts via Stripe; enable bookings, Sessions, messaging, and reviews; provide support; ensure trust & safety and enforce our policies; comply with law (tax, dispute, law-enforcement requests); and, with any required consent, send communications and improve the Services. We process Sensitive Personal Information only for the limited purposes above (identity verification, fraud/safety, and as required by law), and not to infer characteristics — see §5.
What we do not do. We do not use your personal information for targeted, behavioral, or personalized advertising; we do not use advertising networks or ad-tech partners; and we do not sell your personal information. See §5.1 and the Cookie Policy.
4. How we disclose personal information; categories of recipients
We are not in the business of selling your data. We disclose personal information to:
- Payment Processor — Stripe. Stripe collects and stores your payment details (card and bank information) and processes payments, payouts, Connect onboarding/KYC, and tax forms. Payments are card and digital-wallet payments through Stripe only. LARP never receives or stores your full card number — we see only limited tokens and the last four digits. Stripe's handling of that data is governed by Stripe's privacy policy.
- Identity-verification vendor — Stripe Identity (ID + selfie verification; acts as the biometric processor — see §6).
- Hosting/infrastructure — Supabase (database, authentication, storage/CDN, US-hosted).
- Web hosting — Vercel (the larp.global website and this legal hub).
- Communications — Zoho (email) and Expo (push notifications). We do not currently use an SMS provider.
- Analytics — none. We do not currently use a third-party analytics provider; crash and error reports are collected first-party.
- The other party to a booking (limited info needed to coordinate a Session — e.g., first name, profile, verified badge, and, after confirmation, contact details and meeting location).
- Legal/safety — to comply with law, enforce our terms, or protect rights and safety.
- Corporate transaction — to a successor in a merger/acquisition, subject to this Policy.
We require service providers to use personal information only to perform services for us.
5. Your privacy rights
5.1 California (CCPA/CPRA)
You have the right to: know/access the categories and specific pieces of personal information we collect; delete it (subject to legal-retention exceptions); correct inaccuracies; opt out of "sale"/"sharing" of personal information; and limit the use and disclosure of Sensitive Personal Information to permitted purposes. We will not discriminate against you for exercising these rights.
- "Do we sell or share?" We do not sell personal information and do not "share" it for cross-context behavioral advertising. If this ever changes, we will provide a "Do Not Sell or Share My Personal Information" link and honor opt-out preference signals (e.g., GPC).
- "Limit the Use of My Sensitive Personal Information." Because we use Sensitive PI only for permitted purposes (identity verification, fraud/safety, legal compliance), a broad "limit" link may not be required — but we honor limit requests sent to admin@larp.global or made in-app.
5.2 How to exercise rights
Submit a request through in-app support or by emailing admin@larp.global. We verify your identity before responding and may use an authorized agent process. We respond within the timeframes the law requires (CCPA: generally 45 days, extendable).
5.3 UK-GDPR / GDPR (UK/EU users)
Where UK-GDPR/GDPR applies to you, you also have rights to access, rectification, erasure, restriction, portability, and objection, and to withdraw consent at any time. See §7.
5.4 Marketing communications
We send transactional messages (about your account, bookings, and Sessions) by in-app notification, push notification, and email. With your consent, we may also send promotional messages. You can opt out of promotional email via the unsubscribe link and of push notifications in your device settings. We do not currently send SMS/text messages; if we ever add SMS, we will update this Policy and obtain any required consent first. Opting out of promotional messages won't stop transactional messages needed to run your bookings.
6. Biometric Information Privacy (BIPA-grade) — important
6.1 What we collect and why. To confirm that you are who you say you are before you transact — an Owner before they can publish a Listing, a Creator before they can book a Session (because Owners and Creators meet in person) — our verification vendor, Stripe Identity, captures a government ID and a live selfie, and generates facial geometry / a biometric face-match to confirm liveness and that the selfie matches the ID. This is biometric information. It is the same check on both sides, and you complete it once. Hosts who complete verification receive a "Verified" badge.
6.2 Consent first. We obtain your written consent before any biometric capture, via the Biometric Consent Notice, and we log the consent version and timestamp. You can sign up for and browse LARP without verifying; verification (and this consent) is required before you can publish a Listing or book a Session.
6.3 Who stores it (minimization). Our verification vendor (Stripe Identity) is the biometric processor — the biometric processing is performed by Stripe, not by LARP; we design the flow so that LARP minimizes or avoids storing raw biometric identifiers itself, retaining instead a verification result/status and reference.
6.4 Retention & destruction. LARP does not store biometric identifiers or biometric information on its own systems. Biometric data collected during verification is processed and retained by Stripe under Stripe's privacy policy and its Stripe Identity terms. Our retention limit is that it is kept only as long as the verification purpose requires and in no event longer than 3 years after your last interaction with LARP.
Because Stripe holds the data, destruction happens when we instruct Stripe to redact your verification session. Today we issue that instruction in two situations: when you delete your account in the app, and when you ask us at admin@larp.global — we relay the request and confirm when it is actioned (subject to lawful retention exceptions). Since 26 August 2026 that relay is automated and durable: it retries until Stripe confirms the redaction, and the confirmation is recorded against your record rather than assumed. We do not yet run a job that issues the instruction automatically at the end of the retention period above, so if you want your biometric data destroyed before then, deleting your account or writing to us is the way to make it happen. See the Biometric Consent Notice.
6.5 No sale. We do not sell, lease, trade, or otherwise profit from your biometric information, and we do not disclose it except to our verification vendor to perform the verification, as you authorize, or as required by law.
6.6 Security. Biometric data is protected using reasonable safeguards at least as protective as we use for other confidential information (see §10).
7. UK-GDPR / GDPR details (where applicable)
LARP is a US company and the Services are currently offered in the United States only. If UK-GDPR/GDPR nonetheless applies to your data, the following applies:
- Controller: Larp Marketplace LLC (contact details in §14).
- Lawful bases (Art. 6): performance of a contract (providing the Services); legitimate interests (security, fraud prevention, improving the Services); consent (where required, e.g., marketing); legal obligation (tax, disputes).
- Special category data (Art. 9): biometric data used to identify you is special category data; our lawful condition is your explicit consent (see §6 and the Biometric Consent Notice).
- Automated decision-making (Art. 22): identity verification uses automated processing (liveness/face-match) to confirm your identity. Where this would produce a legal or similarly significant effect, you may request human review of the decision by contacting us at admin@larp.global.
- International transfers: data is processed in the United States; where UK/EU law applies to a transfer, we rely on appropriate safeguards (e.g., SCCs / UK IDTA / adequacy).
- Your rights & complaints: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent; you may complain to the UK ICO or your local supervisory authority.
- Retention: as in §2 and §6; we keep data only as long as necessary.
8. Cookies & similar technologies
We use cookies and similar technologies for security and functionality. See the Cookie Policy for details and how to manage them.
9. Social sign-in & social media
9.1 Signing in with Google or Apple
You can create an account with an email address and password, or by using Google or Apple. Google and Apple are the only third-party sign-in providers LARP offers. If you use one, we receive only the profile data that provider returns to us — typically your name and email address, and, where you use Sign in with Apple with Hide My Email, a private relay email address rather than your personal one. We do not receive your password with that provider, and we do not receive your contacts, friends or follower lists, or your activity on that provider's own services. We use what we receive only for the purposes described in this Policy — creating and securing your account, and communicating with you about it.
Your relationship with Google or Apple is governed by that provider's own privacy policy, which we do not control. You can review and change what you share through your Google or Apple account settings.
9.2 LARP's social media channels
LARP maintains social media channels on Instagram and TikTok. If you follow, comment on, message, or otherwise interact with those accounts, that interaction takes place on the platform and is governed by that platform's own privacy policy, not this one. From those platforms we receive only what they make available to an account operator — for example, the comments and direct messages you send us, and aggregate, non-identifying audience statistics. We do not currently run advertising through those channels, and we do not upload your personal information to them for ad targeting.
10. Security
We use reasonable administrative, technical, and physical safeguards (e.g., encryption in transit, access controls, row-level data isolation, least-privilege keys). No system is perfectly secure; we cannot guarantee absolute security. If a breach occurs, we follow applicable breach-notification laws.
11. Children
The Services are not directed to anyone under 18, and we do not knowingly collect their personal information. If you believe a minor has provided us data, contact us and we will delete it.
12. Account & data deletion (and app-store compliance)
You can delete your account and data from within the app (Profile → Settings → Delete account). If you can't access the app, the public page larp.global/legal/account-deletion explains how to request deletion by email — no app install required. Deletion cannot complete while money is still owed to or from you: an unsettled payout, a pending refund, or an open damage claim must settle first, and deletion then goes through. On deletion, we remove or de-identify personal information and instruct our verification vendor to delete biometric data, while retaining records we are legally required to keep — for example, transaction/tax records, booking records tied to payments, disputes, or legal obligations, and records of the consents you gave — for the required period, and then deleting them.
13. Changes to this Policy
We'll post the new "Last updated" date and, for material changes, provide additional notice. Continued use after the effective date means you accept the updated Policy.
14. Contact
Privacy questions / requests: admin@larp.global · Larp Marketplace LLC, 8030 Lorraine Ave, 303, Stockton, CA 95210, United States · (+1) 209-641-3939.