Nakovia is a marketplace where property owners rent out space for advertising. This policy says what we collect, why, who else sees it, how long we keep it, and what you can do about any of it. Product controls and current integrations were checked against the repository. Pilot requests are handled manually with identity verification and lawful retention exceptions.
Pilot scope. The current export is partial and deletion is manual. This policy does not promise complete automation or an unapproved fixed retention period.
1. What we collect, and why
- Account: your name, email address, and authentication records. Login credentials are handled by the authentication provider; Nakovia application tables do not contain card or bank credentials.
- Phone number, if you give us one: to text you about time-sensitive things like a design waiting on your approval or a kit being delivered. You opt in explicitly and can turn it off or reply STOP at any time.
- Listings, if you host: the property address, its exact GPS coordinates, photos, the size and type of the display surface, your answers about visibility and audience, and your confirmation that you are allowed to advertise there. Needed to show the spot to advertisers, print the right product, and support the approved owner installation.
- Bookings: the dates, the amounts, the ad artwork you upload, and the state of the booking as it moves through design, printing, shipping, installation and verification. This is the record of a contract between two people.
- Verification media, if you host: the four photos and the short video you take of the installed ad. Needed to prove to the advertiser that what they paid for is actually up, and to detect the same photo being submitted twice.
- Payment details: entered directly with our payment processor. Nakovia never receives or stores your card number. We hold the processor’s reference for the card, the amounts, and whether each charge succeeded.
- Payout details, if you host: your bank details are entered with the payment processor during their identity check, not with us. We hold their account reference and the record of each transfer.
- Messages and offers you send through Nakovia, including the amounts offered and any note attached.
- Reviews you write and reviews written about you, including the private note a reviewer can leave that only the recipient sees.
- Technical and request data: hosting, authentication, database, and configured error-monitoring services may process IP address, browser or device details, requested pages, timestamps, and fault context to operate, secure, and troubleshoot the service.
2. Who else receives it
- Supabase — our database and file storage. Everything above is stored there. Photos, ad artwork and verification media are in restricted storage buckets.
- Our payment processor — payments, saved cards, host identity checks and payouts. Your card and bank details are theirs, not ours; their privacy policy governs them.
- Resend — sends our emails. Receives your email address and the contents of the message being sent.
- Our text-message provider receives a phone number and message content when text messaging is configured, the user is eligible for that channel, and a message is sent. Delivery is not guaranteed.
- Our AI provider receives selected inputs for listing summaries, traffic reasonableness checks, advisory artwork screening, and internal search. Current integrations are designed to limit the fields sent, but the absolute claim that sensitive data is never present has not been verified across every title, uploaded file URL, prompt, log, and provider record.
- Vercel — our hosting. Traffic to the site passes through their network, which means they process your IP address.
- Public data and mapping services receive coordinates or area queries used for geocoding, demographic context, and nearby-landmark lookup. The application does not intentionally add account contact fields to those requests, but a coordinate can still describe a property area.
- Our print and shipping suppliers — receive the ad artwork, the delivery address and the recipient name for a booking, because somebody has to post the box.
- The other party to a booking — an advertiser sees the host’s name and, once a booking is confirmed, the exact address, because they are paying for a specific place. A host sees the advertiser’s name and their artwork. Neither sees the other’s email, phone number or payment details.
- Law enforcement or a regulator, where we are legally required to hand something over.
- Nakovia does not sell your personal information, and does not share it for cross-context behavioural advertising, as those terms are defined under California law.
3. How long we keep information
- The repository does not implement an automated retention or scheduled-deletion job, and this policy does not promise an unapproved fixed retention period.
- Nakovia retains information only as needed for accounts, bookings, support, security, disputes, accounting or tax, and legal purposes.
- Deletion and correction requests are reviewed manually with identity verification and lawful retention exceptions.
- Phone and text consent records may retain the minimum suppression information needed to honor an opt-out.
- Provider technical logs follow provider and account configuration that has not been fully verified in this repository audit.
4. Your rights, and how to use them
- Download current export categories: Settings → Privacy → Your data → Download. The route produces machine-readable JSON for the account, profile, owned listings, selected booking and offer records, reviews, payouts, notifications, and cart rows it currently queries.
- The current download is not a complete export of every record held by Nakovia or its providers. It omits categories including artwork, verification-media metadata, installation jobs, design messages, privacy requests, and authentication-provider records.
- Correct something: most things you can change yourself in Settings. For anything you cannot, use Settings → Privacy → Request a correction.
- Request deletion: Settings → Privacy → Request deletion submits a request for manual review. The current route does not automatically close the account or delete records. Any retained categories and periods depend on the approved retention policy and applicable requirements.
- Stop non-essential emails: Settings → Notifications. Emails that carry a deadline or move money cannot be switched off while you have an active booking, because missing one costs you money.
- Requests are handled manually for Pilot #1. Any response timing is governed by applicable law; Nakovia does not promise a shorter unverified deadline here.
- Depending on where you live you may also have the right to complain to a data protection authority, and the right not to be treated worse for exercising any of these rights. We do not treat you differently for asking.
5. Where your data is, and how it is protected
- Nakovia uses hosted infrastructure and authentication, database, storage, and monitoring providers. Hosting regions, transfer terms, and provider security statements depend on current provider configuration.
- Application routes are designed for encrypted browser-to-server transport in deployed HTTPS environments.
- The application uses authentication, scoped queries, route authorization, and database row-level-security policies. These controls reduce access risk but do not justify a guarantee that one account can never read another account’s data.
- Current artwork and verification routes use protected storage and signed links where implemented. The repository has not proved that every legacy file and bucket follows that rule.
- You can turn on two-factor authentication in Settings → Login and security. We recommend it for any account that receives payouts.
6. Cookies
- Nakovia sets a cookie to keep you signed in. Without it you cannot have a session.
- Nakovia does not intentionally configure advertising cookies in the reviewed application code. When error monitoring is configured, a third-party monitoring client can receive scrubbed error and request context. Transaction tracing is currently disabled in code.
- You can clear cookies from your browser at any time. Doing so signs you out.
7. Children
- Nakovia is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has an account, email privacy@nakovia.com and we will remove it.
8. Changes, and how to reach us
- If we change this policy in a way that materially affects you, we will email you before it takes effect.
- For anything about your data: privacy@nakovia.com.