THE VALLEY · PRIVACY POLICY

Privacy Policy

Effective August 24, 2026

This Privacy Policy describes how The Valley ("The Valley," "we," "us") collects, uses, and shares personal information through https://thevalley.bot and related email, checkout, owner-desk, Registry, and reporting tools (the "Service").

The Valley sells digital sponsorship rights in a virtual city. We collect buyer and visitor data to run occupancy, take payment, send mail, measure the city, and (when configured) identify who landed on a sponsor destination.

California Notice at Collection. We collect the categories below. We use them for the purposes below. We disclose them to the processors named below. We share identifiers with advertising partners — including Meta — for cross-context behavioral advertising. We do not claim that we "do not sell or share" personal information. See State privacy rights.

Cookie and pixel detail lives in Cookies and similar technologies. The thin Cookies page points here so we do not run three conflicting policies.

Who we are

The controller of personal information described here is The Valley, operating thevalley.bot. Contact: deeds@thevalley.bot. Mailing line: The Valley · digital sponsorship rights · thevalley.bot.

No incorporated entity name or street address is stored in the product configuration. Privacy requests go to the mailbox above — not a personal inbox and not a demo address.

Scope

This policy covers visitors to the city, Market, Registry, news, legal pages, sample report, checkout, commerce return, and private owner-desk tokens; buyers who pay through Stripe; and recipients of Resend transactional or marketing mail.

It does not cover destination websites you click through to (those are the sponsor's responsibility) or processors' own independent uses described in their policies.

Personal information we collect

You provide. Company name; work or personal email; destination URL; optional logo/brand color if submitted; messages you send us; unsubscribe choices.

Payment. Stripe collects card or wallet data and runs 3-D Secure / SCA. We receive payment metadata (status, last4-style descriptors Stripe exposes, customer email, amount, listing id, commercial class). We do not store full PAN or CVC on Valley servers.

City and listing use. Which listings you open; checkout attempts; reservation ids; occupancy status; deed numbers when issued; owner-desk token use.

City measurement. Impressions, property opens, outbound clicks, coarse geo (for example country), and similar first-party counts we attribute to a slot. These are observational and may undercount.

Destination identification. When a Valley click arrives at a sponsor destination with UTM intact (`utm_source=the-valley`), we and Bullseye may process identifiers, session data, company/account inference, and conversion events so an owner desk can show who landed. That is a processor relationship. Customer-facing reports describe audience, intent, and outcome — they do not need the vendor name.

Automatic. Device and browser data; IP address; approximate location; pages and query params (including `?listing=`); referrers; cookie and pixel identifiers; email open/click signals (pixels in HTML mail). An ephemeral session id in `sessionStorage` (`presence:v1`) is pinged so the city can show how many people are here now. It is not an account and it expires when the tab dies.

Brand lookup. We may send a destination host, company name, or email domain to Context.dev to retrieve public brand assets (logo/colors) for fulfillment. That is operational, not a public people-search.

We do not intend to collect. Government ID numbers, precise geolocation from a device GPS API, health data, or children's data. Do not submit those in free-text fields.

Sources

  • You (checkout forms, email replies, unsubscribe).
  • Your device (cookies, pixels, logs).
  • Stripe (payment success/failure, subscription state, 3DS outcome).
  • Bullseye (destination identification webhooks and stats).
  • Context.dev (public brand retrieve).
  • Resend (delivery, bounces, complaints, unsubscribe events).
  • Google Analytics 4 and Google Search Console (analytics and webmaster queries).
  • Meta Pixel (ads measurement and cross-context advertising identifiers).
  • Vercel (hosting and request logs).
  • Supabase (listing, occupancy, and related records we store).

How we use personal information

  • Deliver digital occupancy: reserve/fulfill listings, render sponsor surfaces, issue deeds and desk tokens.
  • Take and reconcile payment; complete 3-D Secure when Stripe or your bank requires it; fight fraud and improper chargebacks.
  • Send transactional mail (reservation, receipt, deed, occupancy). Marketing and weekly intelligence only where permitted; unsubscribe is honored for marketing.
  • Measure the city and sponsor funnels; produce owner-desk reports; keep the public sample report separate and labeled illustrative.
  • Identify destination landings and conversions via Bullseye for occupied slots.
  • Operate and secure the Site (Vercel logs, abuse, debugging).
  • Index and understand search performance via Google Search Console (site-level webmaster data, not a dossier on each visitor).
  • Measure traffic and campaigns via GA4 and Meta Pixel, including ads performance and retargeting when those tags fire.
  • Comply with law, enforce Terms, and defend claims.
  • Create aggregated or de-identified city stats. We do not attempt to re-identify de-identified stats except to test de-identification.

Cookies, pixels, and similar technologies

We use cookies, pixels, local storage, and similar technologies. Some are essential to checkout and security. Others are analytics or advertising.

TypeWhoWhat it doesControl
EssentialThe Valley, Stripe, Vercel, SupabaseCheckout session, reservations, owner-desk auth-by-link, load balancing, securityBrowser controls; Site may break without them
AnalyticsGoogle Analytics 4 (G-RRETJS94ER)Page views, city engagement, referral pathsGoogle Analytics opt-out
WebmasterGoogle Search ConsoleHow Google Search sees the Site; query and index data for our domain — not typically used to profile you as an end user in our product UIGoogle account / Search Console access is ours; your browser still talks to Google when you use Search
Advertising / ads measurementMeta Pixel (Meta Platforms)Measure campaigns, build/measure audiences, cross-context behavioral advertising. This is sharing under CPRA.Meta ads settings; YourAdChoices; browser GPC where we honor it as described below
PaymentStripeFraud, 3DS, Checkout cookies on stripe.comStripe and your bank; required to pay
Email pixelsResend / The ValleyWhether a letter was opened or a link clickedImage blocking; unsubscribe for marketing
Destination identifyBullseyeIdentifiers and sessions on sponsor destinations tagged with Valley UTM — not a Valley page pixel named in the owner UIDepends on the destination's own stack; UTM-stripped landings may not identify

We do not operate a FullStory-style session replay product. We do not use Flash LSOs. We do not currently respond to the legacy DNT header. We treat a recognized Global Privacy Control (GPC) signal as an opt-out of sale/sharing for that browser where required by law.

Industry opt-outs: NAI, DAA. Opting out of interest-based ads does not stop all ads or stop essential cookies. You must repeat opt-outs per browser and device.

How we share — processors and partners

We disclose personal information to vendors who process it for us, and we share identifiers with advertising platforms as described. Named processors and platforms:

NameRolePolicy
StripePayments, subscriptions, Payment Intents, 3-D Secure / SCA, fraud. We do not store PAN.stripe.com/privacy
SupabaseDatabase for listings, occupancy, buyer records, email prefs, related ledgerssupabase.com/privacy
VercelHosting, CDN, request logs, deploymentsvercel.com/legal/privacy-policy
ResendTransactional and marketing email; bounces, complaints, unsubscriberesend.com/legal/privacy-policy
Google (Analytics 4)Site analytics. Measurement ID G-RRETJS94ER is loaded in the root layout.policies.google.com/privacy
Google Search ConsoleWebmaster / search-performance data about thevalley.botpolicies.google.com/privacy
Meta Platforms (Meta Pixel)Ads measurement and cross-context advertising. CPRA sharing (and, depending on interpretation, a "sale" of identifiers even when no money changes hands).facebook.com/privacy/policy
BullseyeDestination identification — who landed and what they did after a Valley click with UTM intactbullseye.so
Context.devPublic brand retrieve (logo/colors) from destination or company signalscontext.dev

We may also disclose information to professional advisors, to authorities when we believe in good faith it is required, and to a buyer of the project as a business asset in a financing or sale. We do not sell your card number. We do not auction occupancy PII on a data marketplace.

Sponsor names, logos, and destination hosts that you ask us to put on a building are public in the city, Registry, and sometimes news. That is the product.

Sale and sharing (CPRA honesty)

We do not sell personal information for money. We do use Meta Pixel and Google advertising/analytics tags that send identifiers and event data to those companies so they can measure and, for Meta, deliver or measure cross-context ads. California CPRA treats much of that as sharing (and some of it may be a "sale" of personal information even without cash).

To opt out of sale/sharing: email deeds@thevalley.bot with the subject "Do not sell or share," use recognized GPC in a supporting browser, and use the Meta / Google / industry opt-outs above. We will not discriminate against you for exercising a privacy right.

Bullseye identification is a measurement processor for occupancies, not a cash sale of your list. Destination sites may have their own pixels; those are not ours to shut off.

Retention

We keep information as long as needed for the purpose collected, including occupancy history, deed registry (public by design), tax and payment records, chargeback defense, and legal holds.

  • Checkout/payment metadata: for the life of the occupancy plus a period needed for accounting, disputes, and law (often years, not days).
  • Owner-desk tokens: until rotated or the occupancy ends and we retire the desk.
  • Marketing email prefs / suppressions: until you change them or we no longer mail.
  • GA4 / Meta / logs: per those vendors' defaults and our account settings.
  • Public Registry and deed PDFs: indefinitely as a public record of digital deeds.

When we no longer need personal information, we delete, anonymize, or isolate it. Public city history and numbered deeds may remain as ledger facts.

Your choices

  • Email. Marketing and weekly intelligence: use Unsubscribe in the letter (already wired). Transactional receipts and deed mail still send after a purchase.
  • Cookies. Browser settings; GA opt-out; Meta ads settings; GPC.
  • Checkout data. You can decline to buy. We need email and company name to fulfill.
  • Owner desk. Do not share the token. Ask us to rotate it if it leaked.
  • Access / correction / deletion. Email deeds@thevalley.bot. We will verify you (typically via the buyer email and listing reference). We may deny requests that would break a public deed record, a legal hold, or another occupant's privacy.

We do not run a consumer login profile with a self-serve privacy dashboard today. Email is the channel.

Security

We use HTTPS, hosted infrastructure, Stripe for cards, and access-controlled databases. No method of transmission or storage is perfectly secure. Owner-desk tokens are bearer links — treat them like passwords.

International transfers

We operate from the United States. Processors (Stripe, Google, Meta, Vercel, Supabase, Resend, Bullseye, Context.dev) may process data in the U.S. and other countries. If you access the Site from elsewhere, you understand your information may be processed in the U.S., where protections may differ from your home country.

Children

The Service is for people 18 and older. We do not knowingly collect personal information from children. If you believe we have, email us and we will delete it as required by law. We do not have actual knowledge that we sell or share personal information of consumers under 16.

Other sites

Sponsor destinations, Stripe Checkout pages, and processor sites are not The Valley. Their policies apply. A click out of the city is a click onto someone else's stack.

Changes to this policy

We may update this policy by posting a new effective date on this page. Material changes may also be emailed when we have your address. Continued use after the new date is acknowledgment of the update.

State privacy rights notice

If you live in a U.S. state with a comprehensive privacy law (including California CPRA, and as applicable Colorado, Connecticut, Virginia, Texas, Oregon, and others), you may have some or all of the following rights, subject to exceptions: know/access, correct, delete, portability, appeal a denial, opt out of targeted advertising, opt out of sale or sharing, and limit use of sensitive personal information. We do not use sensitive personal information to infer characteristics about you. We do not engage in solely automated decisions that produce legal or similarly significant effects about housing, credit, or employment.

How to exercise. Email deeds@thevalley.bot. Use a clear subject (Access, Delete, Correct, Appeal, or Do not sell or share). We will verify using the email on the occupancy or a declaration we reasonably require. An authorized agent must show authority (for example a power of attorney or signed permission plus verification of you).

Shine the Light (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for those third parties' own direct marketing in the Shine the Light sense as a side business. Advertising pixels are described above. Shine the Light requests: email with subject "Shine the Light Request," your name, mailing address, and certification of California residency. We accept those by email only.

Category (CPRA)ExamplesSourcesPurposesDisclosed toSold / shared?
IdentifiersEmail, IP, cookie ids, company nameYou, device, processorsFulfillment, analytics, ads measurement, securityStripe, Supabase, Vercel, Resend, Google, Meta, Bullseye, Context.devShared with Meta/Google ads/analytics; not sold for money
Commercial informationSKU, listing, amount, occupancy historyYou, Stripe, our ledgerCheckout, Registry, reports, disputesStripe, Supabase, Vercel, ResendNo cash sale; public Registry shows owner name and deed facts
Internet / electronic activityPage views, clicks, city interactionsDevice, GA4, logsAnalytics, product, ads measurementGoogle, Meta, Vercel, Bullseye (destination)Shared via pixels / analytics
Geolocation (coarse)Country / region from IP or identifyLogs, BullseyeStats, fraud, reportsVercel, Google, BullseyeMay be included in analytics/ads events
Professional informationCompany name, destination host, inferred accountYou, Context.dev, BullseyeFulfillment, who-landed reportsContext.dev, Bullseye, public city as brandingPublic as sponsor identity; identify data to Bullseye as processor
InferencesFunnel metrics, match rateDerivedOwner desk, productShown to the occupying buyer; processors that compute themNo
Sensitive personal informationNot intentionally collected (no SSN, no precise GPS)

Contact

Privacy requests and questions: deeds@thevalley.bot

The Valley · digital sponsorship rights · thevalley.bot

Site: https://thevalley.bot