Legal and transparency
Privacy Policy
This draft describes the information practices implemented in Ultra Local LA today. It is not a certification of legal compliance and should be reviewed by counsel before final approval.
What this policy covers
This policy covers the Ultra Local LA website, public catalog, account features, saved-product library, feedback form, and first-party measurement described below. Dealer websites are separate services with their own privacy practices.
Information Ultra Local collects
Account and profile information. If you create an account, authentication is handled by Clerk. Ultra Local receives and stores Clerk's user identifier, your verified email address, and the first and last name provided through Clerk. Clerk role metadata may be read to determine authorized access. Ultra Local does not store your password or other sign-in credential in its application database.
Saved products and collections. When signed in, Ultra Local stores collection names, the products placed in each collection, and created or updated timestamps. This information is tied to your Ultra Local account.
Comments and feedback. The About form stores the topic, message, submission time, review status, and an optional reply email. A signed-in submission may also be linked to the account that sent it. Feedback is delivered to a private administrative inbox and is not published by default.
First-party analytics. Ultra Local may record page paths, referring pages, search queries, filter selections, public collection identifiers, product impressions and opens, product views, dealer-profile views, dealer-site clicks, zero-result states, discovery paths and selections, and time spent in the Discover experience. Events may include the relevant product or dealer identifier.
Anonymous public traffic. Vercel Web Analytics measures visits to public Ultra Local pages using anonymized, aggregated data without analytics cookies. Its reporting may include the public page or route, referrer, country, browser, operating system, and broad device type. Admin, profile, account, and billing-outcome pages are excluded from this measurement.
Session, device, and campaign information. Analytics uses a random anonymous session identifier stored in browser session storage. The main analytics identifier rotates after 30 minutes of inactivity. Discover uses a separate tab-scoped session and attribution identifier. Events may include a broad device category derived from viewport width, the referring URL, and UTM source, medium, campaign, term, or content values present in the page URL. These analytics events are not joined to an Ultra Local account or Clerk user identifier.
Product-page performance. Product pages report time to first byte, largest contentful paint timing, and image-load failures with the product identifier. These measurements are written to application runtime logs rather than the analytics tables.
Request protection. The application receives network request information through its host. Its rate limiter uses a forwarded IP address as an in-memory key for short request windows. When unusual request behavior is logged, the application logs a short one-way hash rather than the raw address. Raw IP addresses are not stored in the first-party analytics tables.
Browser storage
Ultra Local uses browser session storage for anonymous analytics and Discover session identifiers, Discover attribution, product-view deduplication, and temporary browse-result restoration. This storage is scoped to the browser session. Clerk uses the browser mechanisms needed to maintain an authenticated session. The first-party analytics implementation does not set an analytics cookie.
Why this information is used
- Provide and secure sign-in, account access, saved products, and collections.
- Display, operate, and improve the public catalog and discovery experience.
- Understand searches, filters, product interest, dealer visits, referrals, and navigation in aggregate.
- Measure product-page speed and identify failed images or service problems.
- Respond to comments, privacy requests, rights concerns, accessibility reports, and bug reports.
- Protect the service from excessive or harmful automated requests.
Service providers and sharing
Ultra Local uses a limited set of providers to operate the current service:
- Clerk provides authentication and account-session management.
- Vercel hosts and delivers the website, processes requests and runtime logs, and provides anonymous Web Analytics for public pages.
- Neon hosts the PostgreSQL database containing account, library, feedback, catalog, and first-party analytics records.
The implementation does not send analytics to an advertising network. Vercel processes the anonymous public-page measurement described above. When you choose a dealer link, you leave Ultra Local and interact directly with that dealer; the dealer then controls its own website and information practices.
Retention
The current application does not encode a fixed automatic deletion period for account profiles, first-party analytics, Discover events, feedback, or runtime logs. This policy therefore does not invent one.
- Saved products remain until you remove them. Deleting a collection deletes the items associated with that collection.
- Feedback can be marked read or archived, but archiving is not deletion.
- The application has no self-service account-deletion control today.
- Session-storage records last according to the browser session; the main analytics session identifier rotates after 30 minutes of inactivity.
- A random first-party visitor token remains in local storage so repeat visits can be counted without an advertising identifier. Ultra Local stores only a one-way hash of that token and does not attach it to an account.
- Provider-controlled authentication, hosting, database, and log records are also subject to each provider's settings and terms.
Access, correction, and deletion requests
Use the About feedback form, choose “Privacy request,” and provide a reply email plus enough detail to identify the relevant account or submission. Ultra Local will need to verify the requester before acting on account-linked data. Anonymous analytics generally cannot be reliably connected to a person or account.
There is no automatic request portal or promised response period in the current implementation. This interim process is manual.
California Do Not Track and third-party collection
The application does not currently inspect or change behavior in response to a browser's Do Not Track signal, so the first-party measurement described above continues when that signal is enabled. The audited implementation contains no advertising pixel or code for cross-site behavioral advertising. Vercel Web Analytics supplies aggregated public-traffic reporting without analytics cookies. Clerk and the infrastructure providers process information to provide their services, and dealer sites collect information under their own notices after you visit them.
Policy changes
When this policy changes, Ultra Local will publish the revised text here and update the effective date. This draft does not promise a separate email notice or a specific advance-notice period.