Privacy Policy

Effective Date: November 9, 2024 Last Updated: November 9, 2024

Introduction

Welcome to Cackles. This Privacy Policy explains how BestTechie Holdings, Inc. ("Cackles," "we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our iOS mobile application and website at cackles.club (collectively, the "Service").

We are committed to protecting your privacy and being transparent about our data practices. This Privacy Policy describes your privacy rights under the General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act ("CCPA"), and other applicable privacy laws.

By using Cackles, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, do not use the Service.

1. Information We Collect

We collect several types of information from and about users of our Service:

1.1 Information You Provide Directly

Account Information:

  • Email address (required for authentication)
  • Username (unique identifier)
  • Display name
  • Phone number (optional)
  • Password (stored as a cryptographic hash, never in plain text)
  • Profile picture or avatar
  • Bio or personal description
  • Interests and preferences (used for content recommendations)
  • Cackles Number (a unique member number assigned to your account)
  • Sponsor information (referral tracking data)

Payment Information:

  • Billing details and transaction history (processed via Stripe)
  • Payout information if you are a content creator
  • Note: We do NOT store credit card numbers, CVV codes, or other sensitive payment details. All payment processing is handled by our third-party payment processor, Stripe.

User-Generated Content:

  • Room titles, descriptions, and metadata
  • Bubble (community) information you create or manage
  • Messages and posts in activity feeds
  • Profile customizations and settings

Communications:

  • Messages you send to us for customer support
  • Feedback, survey responses, and other communications

1.2 Information Collected Automatically

Device and Technical Data:

  • Device tokens (for push notifications via Apple Push Notification Service)
  • IP address
  • Device type, model, and operating system version
  • Mobile app version
  • Browser type and version (for web access)
  • Unique device identifiers
  • Time zone and locale settings

Usage Data:

  • Rooms you join, create, or participate in
  • Your role in voice rooms (listener, speaker, moderator)
  • Following and follower relationships
  • Users you have blocked
  • Activity feed interactions (likes, comments, shares)
  • Bubble subscriptions and supporter status
  • Notification preferences and settings
  • Features you use and how you interact with the Service
  • Session duration and frequency of use
  • Analytics data (via PostHog)

Audio Data:

  • Live voice audio transmitted during room participation (via Agora)
  • Audio is transmitted in real-time for live conversations
  • Important: We do NOT record or store voice audio by default. Audio streams are temporary and deleted after transmission unless you or a room moderator explicitly chooses to record a session (in which case all participants will be notified).

1.3 Information from Third Parties

We may receive information about you from third-party services when you connect your Cackles account with those services, or when you interact with our Service through social media platforms or other integrations.

2. How We Collect Information

We collect information through various methods:

Directly from You:

  • When you create an account or update your profile
  • When you use features of the Service
  • When you make purchases or subscribe to Bubbles
  • When you contact customer support
  • When you participate in surveys or provide feedback

Automatically:

  • Through cookies and similar tracking technologies (see Section 11)
  • Through analytics services (PostHog)
  • Through server logs and application monitoring
  • Through mobile app analytics and crash reporting

From Third Parties:

  • From our service providers who assist us in operating the Service
  • From payment processors (transaction confirmations)
  • From analytics providers
  • From public sources (if applicable)

3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Provide and Maintain the Service

  • Create and manage your account
  • Enable voice room functionality and real-time audio transmission
  • Process payments and subscriptions
  • Provide customer support and respond to your inquiries
  • Send transactional messages (account notifications, service updates)
  • Maintain the security and integrity of the Service

3.2 Improve and Personalize the Service

  • Personalize your experience and recommend relevant content
  • Analyze usage patterns to improve features and functionality
  • Develop new features and services
  • Conduct research and analytics
  • Understand user preferences and trends

3.3 Marketing and Communications

  • Send you promotional materials and updates (with your consent)
  • Notify you about new features, events, or offers
  • Conduct surveys and gather feedback
  • You may opt out of marketing communications at any time

3.4 Safety and Security

  • Detect, prevent, and address fraud, abuse, and security incidents
  • Enforce our Terms of Service and Community Guidelines
  • Protect the rights, property, and safety of Cackles, our users, and the public
  • Comply with legal obligations and respond to lawful requests

3.5 Legal Compliance

  • Comply with applicable laws, regulations, and legal processes
  • Respond to government requests and court orders
  • Establish, exercise, or defend legal claims
  • Maintain records as required by law

3.6 Business Operations

  • Process transactions and manage subscriptions
  • Provide analytics to content creators about their Bubbles
  • Manage referral and sponsorship programs
  • Conduct business planning and reporting

4. Sharing Your Information

We do not sell your personal information. We share your information only in the following circumstances:

4.1 With Other Users

Certain information is visible to other users by design:

  • Your username, display name, and profile picture
  • Your bio and interests
  • Rooms you participate in (when you join as a speaker or listener)
  • Your following/follower lists (unless made private)
  • Content you post in activity feeds
  • Your Cackles Number
  • Bubbles you create or moderate

4.2 With Service Providers (Data Processors)

We share information with third-party service providers who perform services on our behalf:

  • Supabase - Database hosting, authentication, and real-time data synchronization
  • Agora - Voice and audio infrastructure for real-time room communication
  • Stripe - Payment processing and subscription management
  • Vercel - Website hosting and blob storage (for profile pictures and media)
  • PostHog - Analytics, session replay, and product insights
  • Apple - Push notifications via Apple Push Notification Service

These service providers are contractually obligated to protect your information and use it only for the purposes for which we disclose it to them.

4.3 For Legal Reasons

We may disclose your information when we believe it is necessary to:

  • Comply with applicable laws, regulations, or legal processes
  • Respond to lawful requests from government authorities
  • Enforce our Terms of Service or other agreements
  • Protect our rights, property, or safety, or that of our users or the public
  • Detect, prevent, or address fraud, security, or technical issues

4.4 Business Transfers

If Cackles is involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on the Service before your information is transferred and becomes subject to a different privacy policy.

4.5 With Your Consent

We may share your information for other purposes with your explicit consent.

5. Third-Party Services and Data Processors

We use the following third-party services to operate Cackles. Each service processes personal data on our behalf under strict data processing agreements:

| Service | Purpose | Data Processed | Privacy Policy | | ------------ | ------------------------------------------------- | --------------------------------------------- | --------------------------------------------------------- | | Supabase | Database, authentication, real-time subscriptions | Account data, profile information, usage data | Supabase Privacy | | Agora | Voice/audio infrastructure | Real-time audio streams, device data | Agora Privacy | | Stripe | Payment processing | Payment information, transaction data | Stripe Privacy | | Vercel | Hosting and storage | Profile images, static assets, IP addresses | Vercel Privacy | | PostHog | Analytics and session replay | Usage data, device data, session recordings | PostHog Privacy | | Apple | Push notifications | Device tokens, notification content | Apple Privacy |

These third-party services may have access to your personal information only to perform specific tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Important: When you use Cackles, your data may be transmitted to and stored on servers located outside your country of residence. We ensure appropriate safeguards are in place (see Section 10).

6. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

6.1 Active Accounts

While your account remains active, we retain your information to provide the Service and comply with our legal obligations.

6.2 Deleted Accounts

When you delete your account:

  • Your account data is marked for deletion and will be permanently deleted within 30 days
  • During this 30-day period, you may contact us to restore your account
  • After 30 days, deletion is permanent and irreversible
  • Some information may be retained in backup systems for up to 90 days and then permanently deleted

6.3 Legal and Compliance Data

Certain data may be retained for longer periods when necessary to:

  • Comply with legal obligations (e.g., tax records, transaction history)
  • Resolve disputes or enforce our agreements
  • Prevent fraud and enhance security
  • Meet regulatory requirements

Such data is retained only for as long as legally required.

6.4 Anonymous Data

We may retain aggregated, de-identified, or anonymous data indefinitely for analytics, research, and service improvement purposes. This data cannot be used to identify you personally.

7. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information:

7.1 Rights Under GDPR (EU/EEA Users)

If you are located in the European Union or European Economic Area, you have the following rights:

  • Right to Access: Request a copy of the personal information we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete information
  • Right to Erasure ("Right to Be Forgotten"): Request deletion of your personal information
  • Right to Restriction of Processing: Request that we limit how we use your information
  • Right to Data Portability: Receive your personal information in a structured, machine-readable format
  • Right to Object: Object to our processing of your information for certain purposes
  • Right to Withdraw Consent: Withdraw your consent to data processing at any time
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

7.2 Rights Under CCPA (California Residents)

If you are a California resident, you have the following rights:

  • Right to Know: Request information about the categories and specific pieces of personal information we have collected, the sources of that information, the purposes for collection, and the categories of third parties with whom we share information
  • Right to Delete: Request deletion of your personal information (subject to certain exceptions)
  • Right to Opt-Out of Sale: While we do NOT sell personal information, you have the right to opt out if our practices change
  • Right to Non-Discrimination: You will not receive discriminatory treatment for exercising your privacy rights
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Limit Use of Sensitive Personal Information: Request limits on the use of sensitive data (if applicable)

7.3 Other US State Privacy Laws

If you reside in Virginia, Colorado, Connecticut, Utah, or other states with comprehensive privacy laws, you may have similar rights to those described above. Please contact us to exercise your rights.

7.4 How to Exercise Your Rights

To exercise any of these rights, you may:

  • Email us: privacy@cackles.club
  • Use in-app settings: Access account settings in the Cackles iOS app
  • Submit a request: Use our privacy request form at cackles.club/privacy-request

We will respond to your request within the timeframe required by applicable law (typically 30-45 days). We may need to verify your identity before processing your request.

Important: You have the right to designate an authorized agent to make requests on your behalf. The agent must provide written proof of authorization.

8. Children's Privacy

Cackles is not intended for children under the age of 18. We do not knowingly collect personal information from anyone under 18 years of age.

Age Requirement: You must be at least 18 years old to create an account and use the Service.

If we become aware that we have collected personal information from a person under 18, we will take steps to delete such information immediately. If you believe we have collected information from a child under 18, please contact us at privacy@cackles.club.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

9.1 Security Measures

Our security measures include:

  • Encryption: Data transmitted between your device and our servers is encrypted using TLS/SSL
  • Password Security: Passwords are hashed using industry-standard cryptographic algorithms (bcrypt or similar)
  • Access Controls: Strict access controls limit who can access personal information
  • Secure Infrastructure: Our data is hosted on secure, SOC 2 compliant infrastructure (Supabase, Vercel)
  • Regular Security Audits: We conduct regular security assessments and penetration testing
  • Monitoring: Continuous monitoring for security threats and vulnerabilities
  • Incident Response: We maintain an incident response plan to address potential breaches

9.2 Your Responsibility

You are responsible for:

  • Maintaining the confidentiality of your password
  • Restricting access to your device
  • Logging out of your account when using shared devices
  • Notifying us immediately of any unauthorized access

9.3 No Absolute Security

While we strive to protect your personal information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security. If you have reason to believe your account is no longer secure, please contact us immediately at security@cackles.club.

10. International Data Transfers

Cackles is based in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States and other countries where our service providers operate.

10.1 Legal Basis for Transfers

We rely on the following mechanisms for international data transfers:

  • Standard Contractual Clauses (SCCs): We use European Commission-approved Standard Contractual Clauses with our service providers
  • Adequacy Decisions: We transfer data to countries recognized by the EU as providing adequate protection
  • Your Consent: By using the Service, you consent to the transfer of your information to the United States and other jurisdictions

10.2 Data Protection Standards

We ensure that all international data transfers comply with applicable data protection laws and that appropriate safeguards are in place to protect your information.

11. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect information about your browsing activities and to provide, maintain, and improve the Service.

11.1 Types of Technologies We Use

  • Cookies: Small text files stored on your device
  • Local Storage: Data stored in your browser's local storage
  • Mobile Identifiers: Device identifiers used for analytics and advertising
  • Pixels and Beacons: Invisible images used to track email opens and page views
  • Analytics Tools: PostHog and similar services that collect usage data

11.2 Types of Cookies

  • Essential Cookies: Required for the Service to function (authentication, security)
  • Analytics Cookies: Help us understand how users interact with the Service
  • Preference Cookies: Remember your settings and preferences
  • Advertising Cookies: Currently NOT used, but may be used in the future with notice

11.3 Managing Cookies

You can control cookies through your browser settings:

  • Browser Controls: Most browsers allow you to refuse or delete cookies
  • Opt-Out Tools: You can opt out of analytics tracking through PostHog's opt-out mechanism
  • Mobile Settings: iOS users can limit ad tracking through device settings (Settings > Privacy > Tracking)

Note: Disabling essential cookies may prevent you from using certain features of the Service.

11.4 Do Not Track Signals

Some browsers support a "Do Not Track" (DNT) signal. At this time, the Service does not respond to DNT signals. We will update this Privacy Policy if our practices change.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

12.1 Notification of Changes

When we make material changes to this Privacy Policy:

  • We will update the "Last Updated" date at the top of this page
  • We will notify you via email (to the email address associated with your account)
  • We may display a prominent notice in the app or on our website
  • For significant changes, we may require you to accept the new Privacy Policy before continuing to use the Service

12.2 Your Continued Use

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the revised Privacy Policy. If you do not agree to the changes, you must stop using the Service and may delete your account.

12.3 Review Regularly

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

13. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: privacy@cackles.club Legal Entity: BestTechie Holdings, Inc. Website: https://cackles.club

For GDPR-related inquiries: Data Protection Officer: privacy@cackles.club

For CCPA-related inquiries: California Privacy Rights: privacy@cackles.club

For security concerns: security@cackles.club

Mailing Address: BestTechie Holdings, Inc. [Physical Address - To Be Added] United States

We will respond to all inquiries within a reasonable timeframe, typically within 30 days.


Additional Information for California Residents

This section provides additional information for California residents as required by the California Consumer Privacy Act (CCPA).

Categories of Personal Information Collected

In the past 12 months, we have collected the following categories of personal information:

| Category | Examples | Collected | | ------------------------------ | ---------------------------------------------------------- | --------- | | Identifiers | Name, email address, username, IP address, device ID | Yes | | Commercial Information | Purchase history, subscription status | Yes | | Internet Activity | Browsing history, app usage, interactions with the Service | Yes | | Geolocation Data | IP-based location | Yes | | Audio Information | Voice audio during room participation (not recorded) | Yes | | Inferences | Preferences, characteristics, behavior patterns | Yes | | Sensitive Personal Information | Account login credentials | Yes |

Business Purposes for Collection

We collect and use personal information for the business purposes described in Section 3 of this Privacy Policy.

Categories of Third Parties

We share personal information with the categories of third parties listed in Section 4 of this Privacy Policy.

Sale of Personal Information

We do NOT sell personal information. We have not sold personal information in the past 12 months and do not intend to do so in the future.

Retention Period

We retain personal information as described in Section 6 of this Privacy Policy.

Exercising Your CCPA Rights

California residents may exercise their rights by contacting us as described in Section 7.4 of this Privacy Policy.


Additional Information for EU/EEA Residents

This section provides additional information for residents of the European Union and European Economic Area as required by the GDPR.

Data Controller

The data controller responsible for your personal information is:

BestTechie Holdings, Inc. Email: privacy@cackles.club

Legal Bases for Processing

We process your personal information based on the following legal grounds:

  • Contract Performance: Processing necessary to provide the Service and fulfill our contractual obligations
  • Legitimate Interests: Processing necessary for our legitimate business interests (e.g., analytics, fraud prevention, security)
  • Legal Obligation: Processing required to comply with applicable laws
  • Consent: Processing based on your explicit consent (e.g., marketing communications, optional features)

You have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

Data Protection Authority

You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights. A list of EU data protection authorities is available at: https://edpb.europa.eu/about-edpb/board/members_en

International Transfers

As described in Section 10, we transfer personal information outside the EU/EEA. We ensure appropriate safeguards are in place through Standard Contractual Clauses and other approved mechanisms.


Thank you for trusting Cackles with your personal information. We are committed to protecting your privacy and providing a safe, transparent platform for voice-based social interaction.

Last reviewed and updated: November 9, 2025