★ STARTENDER
Privacy Policy
PRIVACY POLICY
STARTENDER
Operated by Nightlife Gigs LLC
Last Updated: 09.23.26
1. Introduction
Nightlife Gigs LLC operates the Startender Platform — the Startender apps for iOS and Android, our web app and website at startender.app, and related services. This Privacy Policy explains how we collect, use, store, and protect personal information. By using the Platform, you consent to the practices described in this Policy.
2. Who This Applies To
This Policy applies to all Users including nightlife workers, venue managers/owners, and venue entities. It also applies to visitors who browse our website without an account, and to people whose business contact information appears in our venue directory or outreach records (see Section 3D). The Platform is intended for individuals 18 years of age and older.
3. Information We Collect
A. Information You Provide: Full name or professional name, email address, phone number, username/handle, profile details (bio, skills, experience, roles, availability, travel preferences), any résumé or CV you upload and the work history extracted from it, venue information, photos/videos/media, messages with other Users including any images and voice notes you send, verification selfies, social media handles and follower counts, your contact-sharing choices, and your referral code and the code of whoever referred you.
B. Information Collected Automatically: Location information as described in Section 15, IP address, device information (model, OS, unique identifiers), push notification tokens, app and website usage data, log data (access times, pages viewed, referring website, browser type, crashes), profile and STARCARD view records, last-active timestamps, and delivery and engagement information for emails (see Section 4a).
C. Payment Information: When paid features are available, payments are processed through third-party providers (e.g., Stripe, Apple In-App Purchase). We do not store full payment card details.
D. Information About People Who Do Not Have an Account: We maintain a directory of nightlife venues and a record of industry contacts — venues, and nightlife professionals such as bartenders and DJs — compiled from publicly available sources: a venue's or professional's own website, public social media and mix-hosting profiles (for example Mixcloud), public business listings, publicly posted job listings, and public web archives such as Common Crawl. These records may include a business or professional name, a business or professional email address, a phone number, a public social media handle, a business address, and the public web page the information came from. Where a publicly listed contact is an individual person, that person's name and work contact details may appear in these records.
We use this information only to build the venue directory, to transmit applications and STARCARDs that Users send, and to send outreach about Startender to venues and to nightlife professionals whose work contact details are public. We do not sell it, and we do not combine it with consumer profiles for advertising. Every outreach email identifies us, gives our postal address, and carries a one-click unsubscribe. Anyone may have their information corrected or permanently removed, and be added to our do-not-contact list, by emailing hello@startender.app; we honor these requests whether or not the person has an account.
4. How We Use Information
We use information to operate and improve the Platform, enable location-based features (nearby gigs, nearby users, distance calculations), send push notifications about gigs, messages, connections, and activity, manage user access and approvals, facilitate connections, transmit applications you send, provide the optional AI features described in Section 6a, improve security and detect fraud and bot signups, enforce Terms of Service, comply with legal obligations, and analyze usage patterns.
4a. Email Delivery & Engagement
For emails we send to you, and for application emails we transmit on your behalf, we record standard delivery and engagement information: whether the message was delivered, bounced, was reported as spam, was opened, or had a link clicked. Open tracking works through a small image embedded in the message; disabling image loading in your email client prevents it. We use this to show senders whether an application was seen, to stop sending to addresses that fail, to honor unsubscribes and complaints, and to protect the reputation of our sending domain. We do not use it for advertising or sell it.
When a venue replies to an application email you sent through Startender, the reply is addressed to a Startender relay address and delivered to your email by us. We store the reply (sender, subject, and message text) so we can show you in the app that the venue answered, deliver it if the first attempt fails, and measure how often applications get a response. Replies are never used for advertising or sold. After the first reply, the venue's own address is on the message, so you and the venue can continue directly.
4b. Profile & STARCARD Views
We record when a profile or STARCARD is viewed, and we may tell the profile owner that a view happened and who viewed it, if the viewer has an account. Aggregate view counts are shown to the profile owner and are preserved when a STARCARD URL is rotated. You can turn off view notifications in Settings; that stops the alerts, not the underlying count.
5. Sharing Information
We do not sell personally identifiable information.
We may share or license aggregated, anonymized data — including platform activity trends, location-based supply and demand patterns, role and availability data, and usage behavior — with third parties for research, analytics, hospitality industry intelligence, brand partnerships, or other commercial purposes. This data does not identify you personally.
We may also share information with other Users (profile visibility, messaging), service providers (cloud hosting, analytics, push notifications, payment processors), when required by law, to protect rights and safety, in connection with a merger or sale, or with your consent.
6. Third-Party Services
The Platform uses third-party services with their own privacy policies, including:
• Supabase — database, authentication, and file storage.
• Cloudflare — website and web app hosting, content delivery, edge functions, the proxy through which our AI requests are routed, and Workers AI (see below).
• Amazon Web Services (Amazon SES) — delivery of the emails we send, including application emails sent on your behalf.
• Expo — push notifications and native build infrastructure.
• PostHog — product analytics. We record which screens and features are used and tie those events to your account identifier so we can tell a returning user from a new one. We do not send message contents, photos, or your résumé to PostHog, and we do not record your screen.
• Sentry — crash and error reporting (diagnostic data so we can fix bugs).
• Anthropic and Cloudflare Workers AI — the AI models behind the features described in Section 6a. Content you submit to an AI feature is sent to these providers to generate that output. We also use Cloudflare Workers AI on our own venue directory — to generate a placeholder image for a venue listing that has no photo (shown as an illustration, not a photograph) and to sort venue photos. Your content is not used for either.
• Apple — Sign in with Apple, Apple Maps (the map shown on iPhone and iPad), the App Store, and In-App Purchases.
• Google — Google Sign-In, Google Play, Firebase Cloud Messaging for Android push delivery, and Google Places data used to enrich venue listings.
• OpenFreeMap — the map shown in the Android app and the web app. Loading the map sends your IP address and the map area you are viewing to OpenFreeMap's servers. Map data © OpenMapTiles, © OpenStreetMap contributors, available under the Open Database License.
• OpenStreetMap / Nominatim — converting city names into map coordinates.
• Open data — parts of the venue directory are derived from Overture Maps Foundation data (CDLA-Permissive 2.0) and Foursquare Open Source Places (Apache 2.0).
• Apify — collecting publicly posted photos from venues' own public social media profiles for venue listings.
• Adzuna, Jooble, and public employer career sites and applicant-tracking providers — publicly listed job postings shown on the gig board.
• Stripe — payments, when applicable.
Each provider operates under its own privacy policy. Maps are provided by Apple on iPhone and iPad and by OpenFreeMap on Android and the web, and are subject to their terms; your device may send location and map-usage data to them when you open a map.
6a. AI-Assisted Features
Some optional features use AI: drafting a profile bio, turning a résumé you upload into work-history entries, drafting the note attached to an application, and summarizing publicly posted third-party job listings. When you use one, the text or file you submit for it — which may include your own personal information, such as your work history — is sent to the AI providers named above, through our infrastructure providers, solely to produce that output and return it to you. We do not permit those providers to use your content to train their models, and we do not use AI to make decisions that have a legal or similarly significant effect on you. If you would rather not have your content processed this way, do not use the AI features; you can write your bio and work history yourself.
6b. Cookies, Local Storage & Similar Technologies
Our website and app store information on your device — principally a login session so you stay signed in, and small preference values such as your last-used filters. Our hosting and analytics providers also process standard server log and request data, including IP address, browser type, referring page, and timestamps, to serve the site and to detect abuse.
We do not use advertising cookies, cross-site tracking pixels, or third-party ad networks, and we do not track you across other companies' websites or apps. You can browse the public parts of our website without an account. Clearing your browser or app storage removes these values and signs you out. Aside from the email open-tracking described in Section 4a, we use no tracking technologies for marketing purposes.
7. Photo & Media Storage
Photos and media are stored on third-party cloud infrastructure. Your content may be visible to other Users as part of your profile. We use reasonable security measures but cannot guarantee absolute security.
7a. Verification Selfie & Biometric Notice
At sign-up we ask for a one-time "verification selfie" for the sole purpose of confirming that you are a real, live human (anti-bot and anti-impersonation screening). We do NOT use the selfie for facial-recognition matching, we do NOT create or store a faceprint or facial-geometry template, and we do NOT sell, lease, trade, or otherwise profit from it.
To the extent your verification selfie is ever deemed "biometric information" under laws such as the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), or the Washington My Health My Data Act, by submitting it you provide your informed, written consent to its collection and use for the verification purpose described above. We retain the verification selfie only as long as needed to complete verification, and in any event delete it no later than upon account approval, upon account deletion, or within one (1) year of your last interaction with the Platform, whichever occurs first. You may decline by not completing verification, though this may limit access to the Platform.
7b. Device Permissions
The app asks for a small number of device permissions. Each is optional, each is used only for the purpose below, and you can change any of them in your device settings at any time:
• Location — to snap you to your city at sign-up and to center the map and calculate distances while you are using those screens. See Section 15.
• Camera and photo library — to take or choose your profile photos and your verification selfie.
• Microphone — to record a voice note when you choose to send one in a chat. We do not listen to or record audio at any other time.
• Calendar — write-only, and only when you tap to add a confirmed gig. We add the event you asked for; we do not read, collect, or store your calendar, and we never see your other events.
• Face ID / device biometrics — to unlock the app quickly. This check is performed entirely by your device's operating system. Your face or fingerprint data never leaves your device, is never sent to us, and we neither receive nor store it. This is separate from the verification selfie described in Section 7a.
7c. Messages
Messages between Users, including images and voice notes, are stored on our infrastructure so they can be delivered and shown in your inbox. We record whether a message has been read, and both people in a conversation can see read receipts. We do not routinely read private messages, but we may access them to investigate a report, enforce our Terms, protect someone's safety, or comply with the law. Messages you have already sent remain in the recipient's inbox even if you delete your account.
8. User-to-User Sharing
Information you share with other Users through profiles, messages, or interactions is at your own risk. We are not responsible for how other Users use your information.
8a. Public STARCARDs
Every bartender on Startender is issued a permanent, publicly-accessible URL (a "STARCARD") that displays profile information you have provided — including name, handle, city, bio, photos, and linked social handles (Instagram, TikTok). This URL can be viewed by anyone with the link, including people who do not have a Startender account, similar to a public social media profile link. The link is shared by you (or, when you apply to a job, automatically appended to the application message you authorize) and is intended to function as a digital business card.
You can also choose to publish your own contact details on your STARCARD — your phone number and your email address. This is off by default: neither appears anywhere until you turn on contact sharing for that item in Settings, and turning it off removes it from your card and from any email sent afterwards. While it is on, your number and address are shown on the public STARCARD page and inside the application emails we send on your behalf, as tap-to-call and tap-to-email links, so a venue can reach you without an account. Because that page is public, assume anything you publish there can be copied, forwarded, or collected by automated scrapers, and turn sharing off if you would rather be reached only by replying through Startender.
You can rotate (invalidate and replace) your STARCARD URL at any time from Settings. Rotating the URL immediately breaks any previously-shared links and issues a new one. Anyone who saved the previous link will no longer be able to view your card via that URL. View counts and historical analytics are preserved across rotation.
We do not control re-sharing or screenshotting of your STARCARD by third parties. Do not include any information on your card that you would not be comfortable being widely shared.
8b. Venue Listings & Applications
Startender maintains a directory of nightlife venues compiled in part from publicly available business information (such as a venue's publicly listed business email, phone number, and social media handle). These listings are informational. A venue's inclusion in the directory does not mean the venue has an account, has claimed its listing, or endorses or is affiliated with Startender. When you apply to a gig or send your STARCARD to a venue, you authorize us to transmit your application message and STARCARD link to that venue through its public contact channels (email, SMS, or social media). Venues may request correction or removal of their listing by emailing hello@startender.app.
8c. Featured Placement on Public Pages
We may feature approved profiles, photos, STARCARDs, and venue listings on publicly accessible pages of our website and in our marketing materials. Featured pages are visible to anyone, are indexable by search engines, and may be cached by third parties we do not control. To be removed from featured placements, email hello@startender.app; we will take you out of future placements, though we cannot recall material already cached, printed, or shared elsewhere.
9. Data Retention
We retain information while accounts are active, as necessary for legitimate business purposes, as required for legal/regulatory/security purposes, and for fraud prevention.
More specifically: profile content and uploaded media are kept while your account is active and deleted as described in Section 10; verification selfies are deleted on the schedule in Section 7a; a résumé you upload is kept until you replace or delete it, or until your account is deleted; email delivery and engagement logs are kept for up to twenty-four months for deliverability and abuse prevention; unsubscribe and do-not-contact records are kept indefinitely, because we need them to keep honoring your opt-out; and directory and outreach records for people without accounts are kept while the listing is current and removed on request.
10. Account Deletion
You can delete your account at any time directly in the app: Settings → Delete Account. Your account is deactivated immediately and enters a 14-day grace period, during which you can restore it by logging back in. After 14 days, your profile, uploaded media, any résumé you uploaded, and your verification selfie are permanently deleted, your STARCARD URL stops working, and your authentication account is removed. You may also request deletion by emailing hello@startender.app. Some data may be retained as required by law. Messages already sent may persist in other accounts. Anonymized, aggregated data may be retained for analytics.
11. Data Security
We implement reasonable safeguards but no method of transmission or storage is 100% secure. We will notify affected users of data breaches as required by law.
12. Your Rights
Depending on your jurisdiction, you may request access to your data, correction, deletion, objection to processing, data portability, or withdrawal of consent. Contact hello@startender.app. We respond within 30 days.
13. California Privacy Rights (CCPA/CPRA)
California residents have the right to know what personal information we collect, to access and delete it, to correct it, and to opt out of its "sale" or "sharing." We do not sell personally identifiable information. We do share anonymized, aggregated data for commercial purposes as described in Section 5.
Sources and categories. We collect personal information directly from you, automatically from your device and browser, from our service providers, and from publicly available sources such as business and professional websites, public social media profiles, public business listings, publicly posted job listings, and public web archives (Section 3D). The categories we collect are identifiers, commercial and professional or employment-related information, internet and network activity, precise geolocation, audio/visual information (photos and video), and inferences drawn to match you with gigs. We disclose these to the service providers listed in Section 6 for the business purposes described in Section 4. These rights extend to California residents whose information we hold even if they have never created an account.
Sensitive Personal Information: Precise geolocation is "sensitive personal information" under the CPRA. As described in Section 15, we read precise location on your device only while you use a location feature and store only city-level location. We use it solely to provide core Platform features (nearby gigs, venues, users, and distance calculations), never to infer characteristics about you, and never for advertising — which means we do not use or disclose sensitive personal information for any purpose that would require us to offer a "Limit the Use of My Sensitive Personal Information" choice. You may still ask us to limit it by emailing hello@startender.app.
Do Not Sell or Share / Global Privacy Control: You may opt out of any "sharing" of personal information for cross-context behavioral advertising by emailing hello@startender.app, and we honor recognized opt-out preference signals such as the Global Privacy Control (GPC) where applicable. We will not discriminate against you for exercising your rights. Submit requests to hello@startender.app.
13a. Other U.S. State Privacy Rights
If you reside in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you may have the right to confirm whether we process your personal data and access it, correct inaccuracies, delete your data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and certain profiling. Precise geolocation and biometric data are treated as "sensitive data," which we process only with your consent or as needed to provide the Platform. To exercise these rights, email hello@startender.app; you may appeal a denial by replying to our response. Where required, we honor recognized universal opt-out signals.
13b. U.S.-Only Service
The Platform is intended for users located in the United States, is operated from the United States, and our service providers process data in the United States. We do not currently offer the Platform to, and it is not directed to, users in the United Kingdom, the European Economic Area, or other regions. If you access the Platform from outside the United States, you do so on your own initiative and are responsible for compliance with local laws.
14. Children's Privacy
The Platform is not intended for individuals under 18. We do not knowingly collect information from minors.
14a. Advertising & Sponsored Content
The Platform may display sponsored content, featured listings, or brand partnerships. Advertisers receive only aggregated, anonymized audience insights — never your personal information without your consent.
15. Location Data
If you grant location permission, the app reads your device's location while you are using a location feature — at sign-up to suggest your city, and on the map and nearby screens to center the view and calculate distances. That reading happens on your device and is used for that screen.
What we store on our servers is coarse: the city you select, and a general coordinate for that city so we can sort results by distance. We do not store a continuous location history, we do not track you in the background or when the app is closed, and we do not use location for advertising.
Location permission is optional. You can decline it and type your city instead, and you can turn it off at any time in your device settings; some distance and nearby features will simply stop working.
16. Push Notifications
We collect push notification tokens to alert you about new gig postings, application updates, messages, connection requests, profile approvals, and announcements. You may disable notifications through device settings.
17. Changes to This Policy
We may update this Policy at any time. Continued use constitutes acceptance. We will make reasonable efforts to notify users of material changes.
18. Contact
Nightlife Gigs LLC
Owner: Theodore James Miller
Email: hello@startender.app
Mail: 42 Maspeth Ave, Brooklyn, NY 11211
Privacy requests, removal requests, and do-not-contact requests may be sent to either address above.