Our Commitment: We do not sell your personal information. We collect only what is necessary to operate and improve the Service. Your business data belongs to you, and you can export or delete it at any time.
Part A Introduction & Scope
1. Introduction
This Privacy Policy (“Policy”) describes how All Fair, Inc., a Delaware corporation operated by Illuminating Impact LLC (“All Fair,” “Company,” “we,” “us,” or “our”), collects, uses, discloses, stores, and protects your personal information when you access or use the All Fair platform, website (all-fair.com), mobile applications, APIs, and all related services (collectively, the “Service”).
We are committed to protecting your privacy and handling your data responsibly. We encourage you to read this Policy carefully and contact us if you have any questions.
2. Scope of This Policy
This Policy applies to all users of the Service, including vendors, market organizers, administrators, and visitors. It covers information collected through the Service, email communications, customer support interactions, and any other interactions you have with All Fair.
This Policy does not apply to third-party websites, services, or applications that may be linked from or integrated with the Service. We encourage you to review the privacy practices of any third party before providing your information.
3. Our Role as Data Controller and Processor
All Fair interacts with two distinct categories of individuals whose data may be present on the Platform:
With respect to Seller (account holder) data: All Fair is the data controller. All Fair determines the purposes and means of processing this data in connection with operating the Platform, and this Privacy Policy governs that processing.
With respect to Seller customer data: where a Seller inputs their own customers’ information into the Platform – such as a customer list or transaction history – All Fair functions as a data processor acting on the Seller’s behalf. The Seller bears primary responsibility for those customers’ privacy rights, and All Fair’s use of that data is limited to delivering services to the Seller.
Sellers are responsible for having obtained appropriate authorization from their own customers before sharing that data with All Fair.
4. Definitions
“Personal Information” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to you or your household.
“Processing” refers to any operation performed on Personal Information, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure, or destruction.
“Service Provider” means a third party that processes Personal Information on our behalf pursuant to a written agreement, to help us operate and improve the Service.
Part B Information We Collect
5. Information You Provide Directly
We collect information you voluntarily provide when you interact with the Service, including:
Account Registration: Full legal name, email address, phone number, business name, business address, and password.
Business Profile: Business entity type, industry category, years in operation, product categories, business description, logo, social media links, and other profile details you choose to share.
Identity Verification (KYC): Government-issued identification, tax identification numbers (EIN or SSN), date of birth, and other information required for identity verification and compliance purposes. This data is encrypted at rest and in transit and is used only when legally required.
Financial Information: Bank account details, billing address, and other payment information necessary to process transactions and subscription payments. Payment card information is processed and stored by our third-party payment processors – we do not store full card numbers on our servers and do not log raw financial credentials in our systems.
Product Listings & Content: Product names, descriptions, images, pricing, inventory data, and any other content you upload or create on the Platform.
Communications: Messages, emails, support requests, feedback, and other communications you send to us or to other users through the Platform.
Market Applications: Information you provide when applying to participate in markets, fairs, or festivals, including application responses, portfolio materials, and availability details.
6. Information Collected Automatically
When you access or use the Service, we automatically collect certain information, including:
Device & Browser Information: Device type, operating system and version, browser type and version, screen resolution, device identifiers, and language preferences.
Usage Data: Pages viewed, features used, links clicked, search queries, time spent on pages, navigation paths, referring and exit URLs, and dates and times of visits.
Transaction Data: Records of purchases, sales, payment amounts, payment methods, transaction timestamps, and fulfillment status.
Log Data: Server logs including your IP address, access times, error logs, and system activity information.
Performance Data: Page load times, app crashes, error reports, and other diagnostic information.
7. Location Information
We collect approximate location information derived from your IP address for security and fraud prevention purposes. We do not request precise device location permissions by default.
If you explicitly enable location-based features such as Market Discovery or nearby vendor search, we may collect more precise geolocation data from your device with your permission. You can disable location services through your device or browser settings at any time.
8. Biometric Data
All Fair does not collect biometric data. If your device uses biometric authentication (such as Face ID or Touch ID) to access our mobile application, that data remains on your device and is managed by Apple or Google – it is not transmitted to or stored by All Fair.
9. Information from Third Parties
We may receive information from third-party sources including payment processors (transaction status, fraud screening), identity verification services (KYC results and risk scores), analytics providers (aggregated usage data), and public sources (state business registrations). We combine this with information we collect directly to maintain accuracy and improve our services.
Part C How We Use Your Information
10. Service Operations
We use your information to operate, maintain, and deliver the core features of the Service, including: creating and managing your account; processing transactions and payments; verifying your identity and business information; managing product listings and inventory; facilitating market applications and event participation; generating shipping labels and tracking fulfillment; providing customer support; and sending service-related notifications.
11. Personalization & AI Features
We use your information to personalize your experience, including: recommending markets based on your location, product categories, and past activity; providing AI-powered pricing suggestions and optimization recommendations; generating business performance insights and financial forecasts; and providing AI product recognition to streamline listing creation.
AI features use your data to generate outputs specific to your business. We do not use your personal financial data to train generalized AI models shared with other users. See Section 37 for more detail on AI and automated decision-making.
12. Analytics & Research
We use aggregated and anonymized data to analyze platform usage patterns, conduct market research, develop and improve new features, and generate industry trend reports shared only in non-identifying, aggregated form.
13. Communications
We may use your contact information to send service-related communications (you cannot opt out of these), marketing or promotional messages (with your consent, opt-out available at any time), surveys to help us improve the Service, and educational content relevant to your business.
14. Legal & Compliance
We may use your information to comply with applicable laws and legal processes, enforce our Terms of Service, detect and prevent fraud and security breaches, protect the rights and safety of All Fair and its users, and respond to lawful government requests.
Part D How We Share Your Information
15. Service Providers
We share your information with trusted third-party service providers under written Data Processing Agreements (DPAs) that limit use to the purposes we specify and require appropriate security standards. Categories include: cloud hosting and infrastructure; payment processors and financial partners; identity verification and fraud prevention services; email delivery and communication platforms; analytics and performance monitoring tools; and customer support software.
Service providers are contractually prohibited from using your data for their own independent commercial purposes.
16. Market Organizers & Business Partners
When you apply to participate in a market, fair, or festival through the Platform, we share relevant application information with the event organizer. This may include your business name, product categories, contact information, and application responses. Organizers are expected to use this information solely for event-related purposes.
If you use features that integrate with third-party business tools, we share only the data necessary for those integrations to function, as authorized by you.
17. Legal Requirements
We may disclose your information if we believe in good faith that disclosure is necessary to comply with applicable laws, court orders, or governmental requests; enforce our Terms of Service; detect or prevent fraud or security issues; or protect the rights and safety of All Fair, our users, or the public. Where legally permitted, we will attempt to notify you before disclosing your information in response to legal process.
18. Business Transfers
In the event that All Fair is involved in a merger, acquisition, reorganization, bankruptcy, or sale of assets, your Personal Information may be transferred as part of that transaction. We will notify you via email or prominent notice on the Service of any change in ownership or use of your Personal Information.
19. Aggregated & De-identified Data
We may share aggregated, anonymized, or de-identified data that cannot reasonably be used to identify you with third parties for analytics, research, or business purposes, including industry trend reports and marketplace statistics.
20. No Sale of Personal Information
We do not sell your Personal Information to third parties. We do not share your Personal Information with third parties for their own direct marketing purposes without your explicit consent.
Part E Cookies & Tracking Technologies
21. Types of Cookies We Use
We use cookies and similar technologies (pixels, web beacons, local storage) to collect information and improve the Service:
Essential Cookies: Required for basic functionality such as authentication, security, and session management. These cannot be disabled without impairing the Service.
Functional Cookies: Remember your preferences and settings to provide a more personalized experience.
Analytics Cookies: Help us understand how users interact with the Service. Data collected is used to improve performance and user experience.
Marketing Cookies: Used to track activity and deliver targeted advertisements. We use these only with your explicit consent.
22. Consent Management
When you first visit the Service, you will be presented with a cookie consent banner before any non-essential tracking scripts are loaded. Our consent interface meets the following standards:
Accept and Reject All options are presented with equal prominence. Declining non-essential cookies requires no more steps than accepting them.
Checkboxes for non-essential cookie categories are not pre-selected.
Selecting Reject All technically prevents non-essential tracking scripts from executing – it is not merely a recorded preference.
A Manage Preferences option allows granular category-level control.
We honor the Global Privacy Control (GPC) browser signal as an opt-out of sale and sharing for California users.
23. Third-Party Analytics
We use third-party analytics services to help us understand how the Service is used. These services may use cookies and similar technologies. We do not allow third-party analytics providers to use the information they collect for their own independent purposes.
24. Managing Cookies
You can manage cookie preferences through your browser settings or our consent banner at any time. For mobile applications, manage tracking preferences through your device settings (e.g., “Limit Ad Tracking” on iOS or “Opt out of Ads Personalization” on Android). Disabling certain cookies may affect the functionality of some features.
25. Do Not Track Signals
Because there is no industry-standard interpretation of Do Not Track (DNT) browser signals, the Service does not currently respond to DNT. We do honor the Global Privacy Control (GPC) signal as described in Section 22. We will update this Policy if a uniform DNT standard is adopted.
Part F Data Security
26. Security Measures
We implement commercially reasonable technical, administrative, and physical safeguards to protect your Personal Information, including:
Encryption: Data is encrypted in transit using TLS/SSL and at rest using industry-standard encryption. This applies to all user data, including government-issued ID numbers and financial credentials.
Access Controls: Role-based access controls, multi-factor authentication (MFA) for all team members with access to production systems, and the principle of least privilege limit who can access your data.
Infrastructure: Hosted on industry-leading cloud platforms with SOC 2 compliance, regular security audits, and physical security controls.
Monitoring: Continuous monitoring, intrusion detection systems, and automated alerting to identify and respond to potential threats.
Employee Training: Regular training on data protection, security best practices, and incident response.
While we strive to protect your information, no method of electronic transmission or storage is 100% secure. You acknowledge that you provide your information at your own risk.
27. Data Breach Notification
In the event of a data breach that compromises your Personal Information, we will notify affected users and relevant regulatory authorities in accordance with applicable law. Notifications will include a description of the breach, the types of information involved, the steps we are taking, and recommended actions you can take to protect yourself. Notifications will be provided as promptly as practicable and without unreasonable delay, consistent with applicable legal requirements.
Part G Data Retention & Deletion
28. Retention Schedule
We retain your Personal Information only as long as necessary for the purposes for which it was collected, subject to applicable legal, regulatory, and contractual requirements. The table below describes our retention periods by data category.
Where retention is required by law (such as financial records), data may be retained in anonymized or aggregated form after account deletion.
| Data Category | Default Retention | Earlier Deletion Trigger | Legal / Business Reason |
|---|---|---|---|
| Account & identity data | Active account + 30 days post-closure | User deletion request | Operational; user rights |
| Business & financial inputs | Active account + 30 days post-closure | User deletion request | Core service delivery |
| Usage & product analytics | 24 months rolling | Privacy request | Product improvement |
| Support communications | 3 years from last interaction | User deletion request | Legal; dispute resolution |
| Financial transaction records | 7 years (minimum) | Cannot delete early | IRS / tax law |
| Security & access logs | 12 months rolling | Security incident – preserve | Security; fraud prevention |
| Marketing / email preferences | Until opt-out + 30 days | Opt-out or unsubscribe | CAN-SPAM; CCPA |
| Anonymized / aggregated data | Indefinite | N/A – not identifiable | Benchmarking; AI; product |
29. Account Deletion
You may request deletion of your account and associated Personal Information by contacting us at info@all-fair.com or through your account settings. Upon receiving a valid deletion request, we will delete or anonymize your Personal Information within thirty (30) days, except where retention is required by law, necessary to complete pending transactions, or needed to fulfill compliance obligations. We will inform you of any information that cannot be deleted and the reason for its retention.
Deletion of your account is permanent and cannot be undone.
Part H Your Rights & Choices
30. General Rights
Depending on your location and applicable law, you may have the following rights:
Right to Access: Request a copy of the Personal Information we hold about you.
Right to Correction: Request that we correct inaccurate or incomplete Personal Information.
Right to Deletion: Request that we delete your Personal Information, subject to legal exceptions.
Right to Data Portability: Request your Personal Information in a structured, machine-readable format.
Right to Restrict Processing: Request that we limit processing of your Personal Information in certain circumstances.
Right to Object: Object to processing for certain purposes, including direct marketing.
Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
31. Exercising Your Rights
To exercise any of the rights described above, contact us at info@all-fair.com with a description of your request. Include “Privacy Request” in the subject line. We will verify your identity before processing your request and respond within the timeframes required by applicable law (generally 30–45 days).
You may designate an authorized agent to submit requests on your behalf; we may require written authorization or a power of attorney. We will not discriminate against you for exercising your privacy rights.
32. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the CCPA and CPRA, including: the right to know what Personal Information we collect, use, and disclose; the right to delete your Personal Information; the right to correct inaccurate Personal Information; the right to opt out of sale or sharing (not applicable – we do not sell or share data for cross-context behavioral advertising); the right to limit use and disclosure of sensitive Personal Information; and the right to non-discrimination for exercising your rights.
To submit a California Privacy Request, email info@all-fair.com with the subject line “California Privacy Request.” We will respond within forty-five (45) days.
33. Other State Privacy Laws
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), and other states with consumer privacy legislation may have similar rights to access, correct, delete, and port their data, as well as opt-out rights for targeted advertising and profiling. Contact us at info@all-fair.com to exercise any applicable state privacy rights.
Part I Special Topics
34. Children’s Privacy
The Service is not directed to individuals under the age of eighteen (18). We do not knowingly collect Personal Information from children under 18. Account creation is restricted to users 18 and older. If you believe a child has provided us with Personal Information, contact us at info@all-fair.com and we will delete it promptly.
35. Third-Party Links & Services
The Service may contain links to or integrations with third-party websites and applications not operated by All Fair. We are not responsible for the privacy practices or security of any third-party services. We encourage you to review the privacy policies of any third party before providing your information.
36. International Data
The Service is primarily operated and hosted in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other jurisdictions where our service providers operate. Data protection laws in the United States may differ from those in your country of residence.
37. AI & Automated Decision-Making
The Service uses artificial intelligence and automated systems to provide features such as pricing optimization, market recommendations, business forecasting, product recognition, and risk screening. These features process your data to generate personalized outputs and suggestions.
Automated processing may be used in compliance-related decisions, such as identity verification screening and transaction monitoring. In cases where automated processing produces a decision that significantly affects you (such as account suspension based on fraud detection), you have the right to request human review by contacting us at info@all-fair.com.
We regularly test and audit our AI systems for accuracy, fairness, and bias. AI-generated outputs are decision-support tools and should not be relied upon as the sole basis for any significant business, financial, or legal decision.
Part J Updates & Contact
38. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will: post the updated Policy with a revised “Last updated” date; notify you by email or through a prominent notice on the Platform at least thirty (30) days before changes take effect; and where required by law, obtain your consent. Your continued use of the Service after the effective date constitutes acceptance of the revised Policy.
39. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
All Fair / Illuminating Impact LLC
Email: info@all-fair.com
Website: all-fair.com
Please include “Privacy Request” in the subject line of your email.
