Privacy Policy
Last updated: June 30, 2026
JS127 LLC ("FoldStack," "we," "us," or "our") operates the FoldStack platform, including the
FoldStack website (foldstack.app), the FoldStack Business mobile
application, the FoldStack Customer mobile application, and related services (collectively, the
"Service"). This Privacy Policy explains what information we collect, how we use it, and your choices.
By using the Service, you agree to the collection and use of information as described in this policy.
If you do not agree, please do not use the Service.
Where we operate: The Service is operated in the United States. Our infrastructure (databases, file storage, log aggregation) lives in AWS US-East-1 (Virginia). If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to that transfer. We disclose the rights residents of the European Union, United Kingdom, and Canada have under their respective laws in Section 5 below.
1. Information We Collect
Account Information
- Business owners (tenants): Business name, owner name, email address, phone number, and password when you register your business on FoldStack.
- Customers: Name, email address, phone number, home address, and laundry preferences when you sign up through a tenant's registration page.
- Staff members: Name, email address, phone number, and role assignment when invited by a business owner.
Payment Information
- We use Stripe to process payments. When you add a payment method, your card details are sent directly to Stripe and stored by Stripe — we never see, store, or have access to your full card number. We receive only a token, card brand, last four digits, and expiration date for display purposes.
- Business owners who accept payments connect their own Stripe account via Stripe Connect. Customer payments are routed to the owner's Stripe account. FoldStack may collect a platform fee as disclosed in the owner's service agreement.
Location Information
- Addresses: Customer addresses are collected for pickup and delivery routing.
- GPS location: The Owner mobile app may request access to your device's location for route navigation and proximity alerts. This is optional — you can deny location access and still use the app. We do not continuously track your location in the background.
Order Preferences and Add-Ons
- Laundry preferences: Detergent choice, wash and dry temperatures, and special handling instructions are stored per customer and auto-populated on new orders.
- Optional add-ons: Customers may select add-on services such as bleach treatments, stain removal, fabric softener, special handling for bedding or pillows, and other extras. These selections are stored and retained with order history.
Subscription Plans
- Owners may offer customers recurring subscription plans (weekly, biweekly, or monthly). If you subscribe to a plan, we store your subscription preference, selected tier, and cadence. Subscriptions can be cancelled at any time.
Reviews, Ratings, and Tips
- Reviews: After delivery, if the owner has enabled reviews, customers may submit a 1–5 star rating and optional written comment. Reviews are stored and visible to the owner.
- Tips: After delivery, customers may submit an optional tip via a separate Stripe charge. Tip amounts are recorded for owner reporting purposes. Tips go entirely to the Owner.
Mileage and Route Data
- When an owner logs a pickup or delivery route, we record the distance traveled per stop using the Google Maps Distance Matrix API. Mileage logs are retained for the owner's tax and accounting records and can be exported as a CSV report at any time.
Communications
- In-app messages: Messages exchanged between owners and customers within an order are stored to provide the messaging feature and for dispute resolution.
- Photos: Proof-of-pickup and proof-of-delivery photos uploaded by owners are stored for verification purposes.
- Verification codes: When you log in from a new device, we send a one-time verification code to your email address to confirm your identity. We do not send marketing or promotional messages as part of this process.
Device and Usage Information
- Device identifiers: We store a device fingerprint when you trust a device for auto-login. This is used solely for authentication — not for tracking or advertising.
- Push notification tokens: If you enable push notifications, we store your device's push token. Tokens are issued by Expo (the framework our mobile apps are built with) and routed through Expo's push service before reaching Firebase Cloud Messaging on Android or Apple Push Notification service on iOS. The token is used solely to deliver order updates.
- We do not currently collect analytics, advertising identifiers, or browsing behavior data. If we add analytics in the future, we will update this policy and notify you.
Sign-up Source Information (Business Owners Only)
- When a business owner signs up, we record how they heard about FoldStack (e.g., "Google search," "Referral from another owner," "Facebook"). If the signup link contains UTM parameters (
utm_source, utm_medium, utm_campaign), we record those as well.
- This information is used internally to understand which acquisition channels work. It is not shared with third parties and does not affect the Service you receive.
Anti-Bot Verification
- The owner signup page may load a Cloudflare Turnstile challenge to confirm you are a human rather than an automated bot. Cloudflare receives your IP address and basic browser signals (user agent, screen size) for this verification. Cloudflare does not receive any of the personal information you enter into the signup form.
2. How We Use Your Information
- Provide the Service: Connect laundry business owners with their customers, process orders, coordinate pickups and deliveries, handle payments, and send notifications.
- Authentication and security: Verify your identity via email, password, one-time verification codes sent by email, and trusted device tokens.
- Communications: Send transactional emails (password resets, staff invitations, order confirmations, verification codes) and push notifications (order updates, delivery alerts).
- Mileage and tax records: Retain route distance logs for owner tax deductions and accounting. Owners may export a CSV report of orders, mileage, and totals at any time.
- Improve the Service: Diagnose technical issues, monitor system health, and develop new features.
- Legal compliance: Respond to legal requests and enforce our terms.
We do not sell your personal information. We do not use your data for advertising or profiling.
3. How We Share Your Information
Between users of the Service:
- Business owners and their staff see customer information (name, address, phone, order details) as needed to fulfill orders.
- Customers see business information (business name, branding, contact details) for the tenant they are registered with.
- Tenants cannot see other tenants' data. Customer data is isolated to the tenant it belongs to.
FoldStack support staff:
- Employees and authorized personnel of JS127 LLC ("FoldStack support") may access tenant and customer data when responding to a support request, investigating a reported issue, troubleshooting a technical problem, or as required to maintain the platform. Access is logged. Support staff do not access data for marketing, advertising, or profiling purposes.
Third-party service providers (subprocessors):
- Stripe (stripe.com) — Payment processing and card storage. Subject to Stripe's Privacy Policy.
- Resend (resend.com) — Email delivery for transactional messages, password resets, and one-time verification codes. Subject to Resend's Privacy Policy.
- Firebase / Google (firebase.google.com) — Push notification delivery via Firebase Cloud Messaging (Android). Subject to Firebase's Privacy Policy.
- Expo (expo.dev) — Push notification routing for our mobile apps. Push tokens and notification payloads pass through Expo's push service before reaching Firebase Cloud Messaging or Apple Push Notification service. Subject to Expo's Privacy Policy.
- Cloudflare (cloudflare.com) — Anti-bot verification on the owner signup page via Cloudflare Turnstile. Receives your IP address and browser signals for verification; does not receive any other signup form data. Subject to Cloudflare's Privacy Policy.
- Amazon Web Services (aws.amazon.com) — Cloud hosting, file storage (S3), database hosting (RDS / Lightsail managed PostgreSQL), secrets management (Secrets Manager), and operational logging (CloudWatch). Data is stored in AWS US-East-1 (Virginia). CloudWatch logs may include user IDs, order IDs, and exception traces for debugging; logs are retained for the AWS-default retention period and are not used for analytics or profiling. Subject to AWS's Privacy Policy.
- Google Maps Platform (cloud.google.com/maps-platform) — Address autocomplete and route distance calculations. Subject to Google's Privacy Policy.
- OpenStreetMap (Nominatim) (openstreetmap.org) — City search autocomplete for tenant service-area setup. Receives the search query and the searching user's IP address. Subject to OpenStreetMap's Privacy Policy.
- Zippopotam.us (zippopotam.us) — Free zip-code-to-city lookup used during tenant service-area setup. Receives only the zip code being looked up.
Aggregated data: We may share anonymized, aggregated statistics (e.g., "average delivery time in a region") with partners. This data contains no personally identifiable information.
Legal requirements: We may disclose your information if required by law, subpoena, court order, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
No automated decision-making: FoldStack does not use automated decision-making, profiling, or algorithmic scoring that produces legal or similarly significant effects on you (GDPR Article 22). All operational decisions affecting your account or orders are made by the business owner you are registered with, not by automated systems.
4. Data Retention
- In-app messages (text and photos): Retained indefinitely while your account is active. Messages and any photos attached to them may be needed for customer history and dispute resolution. They are removed only when you request account deletion (see anonymization below).
- Order proof photos (pickup and delivery): Automatically deleted 1 year after the order is delivered. These are the photos taken by the business owner at the doorstep — they are separate from any photos sent inside the in-app message thread.
- Account data (name, email, address, phone): Retained while your account is active. When you request account deletion, a 30-day grace period begins during which the business owner is notified and may export records for their accounting.
- After the grace period: Your personal information (name, email, phone, street address, and GPS coordinates) is permanently anonymized — replaced with placeholder values that cannot be linked back to you. Your city, state, and zip code are retained for aggregate geographic analytics only.
- Order and payment records: Retained with anonymized customer references. Business owners are required by law to maintain financial records for tax and accounting purposes. These records will show "Deleted User" rather than your name.
- Reviews and tips: If you submitted a 1–5 star review or comment after a delivery, the rating and any comment you wrote are retained with the order record after anonymization. Reviews are not personally linked to you after deletion, but if you included identifying details in the free-text comment, those details remain visible to the business owner. Tip amounts (with no card details) are retained for the owner's tax and accounting records.
- Referral relationships: If you signed up through another business's referral link (business owners only), the link from your account to the referring business is retained after anonymization so the referring business owner sees the referral in their history. The referring owner sees only "Deleted User," not your original details.
- User login record: When your account is anonymized, the underlying login record is deactivated and its identifying fields are replaced with placeholder values. The record itself is retained (not hard-deleted) so historical orders and messages can still reference a consistent (anonymized) actor.
- Stripe payment data (FoldStack-side): Your Stripe customer profile and stored payment methods are deleted via the Stripe API when your account is anonymized.
- Stripe payment data (Stripe-side): Stripe independently retains historical transaction records (invoices, payment intents, refunds, disputes) per its own data retention policy, even after FoldStack-initiated deletion. These records are subject to Stripe's Privacy Policy and are outside FoldStack's control.
- Stripe Connect accounts (business owners): If you connected a Stripe account to accept customer payments via Stripe Connect, closing your FoldStack account removes our reference to your Stripe Connect account but does not deactivate the Stripe Connect account itself. To fully disconnect your Stripe Connect account from FoldStack, revoke FoldStack's access from within your Stripe Dashboard under Connected Apps.
- Message content and photos: In-app message text is replaced with "[message removed]" and any attached photos are permanently deleted from our storage.
- Authentication tokens: One-time verification codes, password reset tokens, email verification tokens, and trusted-device tokens are automatically purged after expiration (typically minutes to hours), with trusted devices removed after 180 days of inactivity. These are not associated with personal information.
- Audit logs: Minimal logs (e.g., "account anonymized on [date]") retained for up to 90 days for fraud prevention and legal compliance.
- Legal holds: If required by law (subpoena, tax audit, legal dispute), data may be retained longer than the periods above. It will be deleted when the legal obligation ends.
5. Your Rights and Choices
- Access your data: You may request a copy of the personal data we hold about you by emailing support@foldstack.app.
- Delete your account: You may request deletion of your account from within the app or by contacting us. A 30-day grace period begins upon your request, during which the business owner is notified and may export order records for their accounting. After 30 days, your personal information is permanently anonymized as described in the retention section above. You may cancel the deletion request during the grace period by contacting the business owner.
- Opt out of push notifications: You can disable push notifications in your device settings. Transactional emails (password resets, order updates, one-time verification codes, and receipts) cannot be opted out of while your account is active, as they are required to operate the Service.
- Opt out of marketing email: Welcome emails and other commercial messages include an "Unsubscribe" link in the footer. Clicking that link stops future marketing email immediately. To re-enable marketing email after unsubscribing, contact support@foldstack.app.
- Correct your data: You can update your profile information (name, email, phone, address) at any time from within the app.
California residents (CCPA / CPRA): You have the right to know what personal information we collect, request access to it, request deletion, request correction of inaccurate information, and opt out of the sale or sharing of personal information. FoldStack does not sell or share your personal information for cross-context behavioral advertising as those terms are defined under the CCPA / CPRA. You do not need to submit a "Do Not Sell or Share My Personal Information" request because we already do not sell or share. If you have questions or want to exercise any CCPA right, email support@foldstack.app. We will not discriminate against you for exercising your CCPA rights.
EU and UK residents (GDPR / UK GDPR): You have the right to erasure under GDPR Article 17. The 30-day grace period serves as the processing window under legitimate interest (the business owner's accounting obligations). Order and payment records are retained under the legal obligation exemption (Article 17(3)(b)). You also have the right to data portability (Article 20), the right to object to processing (Article 21), and the right to lodge a complaint with your local supervisory authority. International transfers from the EU / UK to our AWS US-East-1 infrastructure rely on Standard Contractual Clauses with our AWS subprocessor.
Canadian residents (PIPEDA / Quebec Law 25): You have the right to access the personal information we hold about you, request corrections, withdraw consent, and request that we stop processing your information (subject to legal and contractual requirements such as the business owner's accounting obligations). You have the right to data portability — you may request a copy of your personal information in a structured, commonly used electronic format. You may file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, for Quebec residents, with the Commission d'accès à l'information (cai.gouv.qc.ca). FoldStack does not engage in automated decision-making that produces legal or similarly significant effects on you. International transfers from Canada to our AWS US-East-1 infrastructure rely on Standard Contractual Clauses. To exercise any PIPEDA or Quebec Law 25 right, email support@foldstack.app.
Illinois residents: We do not collect biometric data. If we add biometric features in the future (e.g., fingerprint login), we will comply with the Illinois Biometric Information Privacy Act (BIPA) and obtain your consent.
6. Children's Privacy
The Service is not intended for children. In the United States, we do not knowingly collect personal information from anyone under the age of 13 (per the Children's Online Privacy Protection Act). For users in the European Union and the United Kingdom, the minimum age is 16 (per GDPR Article 8 / GDPR-K) — the minimum age to consent to processing of personal data without parental authorization. For users in Canada, the minimum age is 13 (per the Office of the Privacy Commissioner's guidance).
In practice, every business owner who signs up for FoldStack must add a valid credit card at registration, and every customer placing an order must have a payment method on file with a business owner. These payment requirements make use of the Service by anyone under the applicable minimum age unlikely. If we become aware that we have collected information from someone under the applicable minimum age, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at support@foldstack.app.
7. Security
We take reasonable measures to protect your data, including:
- All data transmitted over HTTPS (TLS 1.2+).
- Passwords hashed using industry-standard algorithms (never stored in plain text).
- Payment card data handled entirely by Stripe (PCI-DSS compliant) — never touches our servers.
- Database access restricted to authorized services only (not publicly accessible).
- JWT-based authentication with short-lived access tokens and refresh token rotation.
No system is 100% secure. In the event of a data breach that affects your personal information, we will notify you and any applicable regulatory authorities as required by law.
8. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through an in-app notification. Your continued use of the Service after changes take effect constitutes your acceptance of the updated policy.
9. Contact Us
If you have questions about this Privacy Policy or how your data is handled: