TYSM Home

Privacy Policy

Last updated May 28, 2026

This Privacy Policy explains how TYSM, Inc. (“TYSM,” “we,” “us”) collects, uses, and shares information when you use TYSM (the “Service”). We aim to collect as little as possible to run a gratitude-payments product.

1. Information we collect

  • Identity (via Supabase). When you sign in, our authentication provider Supabase provides us your email address and basic information from your sign-in method (such as Google or Apple).
  • Profile. Your handle, display name, bio, and profile photo — the information you choose to show on your public page.
  • Payment metadata. When a thank-you is sent or received, we store details such as the amount, currency, date, a receipt identifier, and any optional note, emoji, or payer name. We do not collect or store card numbers, bank account numbers, or other payment credentials — those are handled directly by Stripe.
  • Technical data. Basic logs such as IP address and device/browser information, used to operate and secure the Service.

2. How we use information

  • operate, maintain, and improve the Service;
  • process payments and generate receipts (through Stripe);
  • detect, prevent, and address fraud, abuse, and security issues;
  • communicate with you about your account and the Service; and
  • comply with legal and tax obligations.

3. How we share information

We share information only as needed to run the Service:

  • Stripe — to process payments and payouts, subject to Stripe’s Privacy Policy.
  • Supabase — for authentication and identity, subject to its privacy policy.
  • Infrastructure providers — hosting and database providers that operate the Service on our behalf, under confidentiality obligations.
  • Legal — when required by law or to protect rights, safety, and the integrity of the Service.

We do not sell your personal information.

4. Public information

Your handle, display name, bio, photo, and thank-you receipts are public by design — that is the point of a gratitude link. Please do not put anything private in these fields.

5. Retention

We keep information for as long as needed to provide the Service and to meet legal, accounting, and tax obligations. We may retain certain records (such as transaction history) even after account closure where required.

6. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing (for example, under the GDPR or CCPA). To exercise these rights, contact us at the address below. Some data must be retained for legal or financial-record reasons.

7. Security

We use reasonable technical and organizational measures to protect your information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Children

The Service is not directed to anyone under 18, and we do not knowingly collect information from children.

9. International users

We operate in the United States, and your information may be processed there. By using the Service, you understand that your information may be transferred to and processed in the United States.

10. Changes

We may update this Privacy Policy from time to time. We will revise the date above and, where appropriate, provide additional notice.

11. Contact

Questions about your privacy? Email us at [email protected].