Privacy Policy
Last updated: October 2, 2026 (rev. 6)
1. Who We Are
2. What This Policy Covers
This policy applies to the information we collect on clothgoblin.com, in the Cloth Goblin apps for iOS and Android, and in the emails we send you — together, the "Service". It explains what we collect, why, who else sees it, how long we keep it, and what you can do about it.
It does not cover:
- The websites, social accounts, and online shops of the stores we list. Following a link takes you to someone else's site, with its own policy.
- Google Maps, which draws our maps and provides place search and directions, under Google's own privacy policy.
- The Apple App Store and Google Play, which handle app downloads and in-app purchases under their own policies.
- Affiliate networks and advertisers, if you choose to click a paid link (see Section 16).
If you do not agree with this policy, please do not use the Service. Using it means you understand how we handle information as described here. Where the law requires your consent for something, we ask for it separately rather than treating your use of the Service as consent.
3. Information We Collect
We collect information in three ways: you give it to us, it is generated automatically as you use the Service, and in a few cases another company passes it to us.
A. What you give us
- Account information: Email address and optional display name when you register, plus an avatar if you add one. If you sign in with Apple or Google, we receive the identifier and email address that provider releases to us — including a private relay address if you choose one.
- Location suggestions and corrections: If you suggest a location or a fix, we store the details and associate them with your account to enforce usage limits and keep a moderation record.
- Tag suggestions: If you suggest a community tag for a location (e.g. "Nonprofit" or "Luxury Vintage"), we store the suggestion and your user ID to track review status and prevent duplicate submissions.
- Reactions, follows, and travel lists: Reactions and saved locations, the locations you follow, and the Travel Lists you build are stored and associated with your account.
- Photos and posts: If you add a photo to a location or write a post, we store the image or text with your account identifier, along with the file size and type. On a phone, the app asks your permission before using the camera or your photo library, and can reach only the files you pick.
- Organization records: If you claim or register an organization, we store the business details you give us — name, description, website, email, phone, logo — and the name and title of the person who signs the agreement.
- Verification documents: To confirm that you really run a business, or to change an organization's email address, we may ask for a document such as a business license or a utility bill. We store the file, its type and size, who uploaded it, and when. These documents can contain identity information, so we keep them in restricted storage, use them only to make that decision, and never publish them.
- Email notification signups: If you ask to hear when a location opens or goes live, we store your email address, the location, and the exact wording you agreed to, so we have a record of your consent. Every such email has an unsubscribe link.
- Feedback and support messages: If you write to us or submit feedback in the app, we keep your message and account identifier so we can reply and improve the Service.
- Payment information: Processed securely by Stripe or Apple/Google. We never see or store full card numbers. We keep only the customer and subscription identifiers we need to know what you have access to.
B. What is collected automatically
- Device location: We request your device location only to center the map on your area and to build driving directions for your Travel Lists. It is used in the moment, on your device and by the mapping provider that draws the map or calculates the route. We do not write your coordinates to our database, and we never share your location with other users or with stores. You can refuse or withdraw this permission in your device or browser settings; the map then simply opens somewhere sensible instead of near you.
- Consent records: When you agree to something that the law expects us to be able to prove — account signup, an organization agreement, an email opt-in — we record the exact wording you were shown, the date and time, your IP address, and your browser or app user agent. We keep a record of the wording rather than a simple yes/no, because that is what a regulator asks for.
- Technical logs: Our hosting and database providers necessarily receive your IP address and request details in order to deliver pages, sign you in, and protect the Service against abuse. Those operational logs sit with those providers under their own short retention periods, and we do not use them to build a profile of you.
- Website usage statistics: On clothgoblin.com (not in the mobile apps), we count page visits using Vercel Web Analytics. For each page view it records the page address (with any query string removed), the referring site, your approximate location at the country/region/city level, and your device type, operating system, and browser. It uses no cookies and no device identifiers; visits are grouped using a one-way hash of the request that is discarded after 24 hours, so we see only aggregate totals and cannot identify you or follow you across sites. Admin and account-link pages are excluded. We rely on our legitimate interest in understanding how the site is used (GDPR Art. 6(1)(f)). You can object at any time, in either of two ways: (1) turn on Global Privacy Control or Do Not Track in your browser, and we will not count your visits; or (2) use the button below, which saves a small flag in your browser so your visits are not counted.
- What we do not collect. There is no advertising SDK, attribution SDK, session-recording tool, or cross-site tracker anywhere in the Service, and the mobile apps contain no analytics at all. We do not use device advertising identifiers (IDFA or Android Advertising ID), and we do not ask for App Tracking Transparency permission because we do not track you.
C. What we receive from other companies
- Payment and subscription status from Stripe, and from Apple and Google through RevenueCat, so we know what your account has access to. We receive purchase and entitlement records, not your card details.
- Sign-in details from Apple or Google if you use those buttons, limited to what you approve.
- Instagram data from Meta, only if an Organization admin connects their account — see Section 5.
- Business information about the stores themselves, from mapping and search providers. That is information about businesses, not about you.
- Advertising and affiliate links: We show a small sponsor placement on our website and in our apps, and some product links in our curated outfits earn us a commission. These collect nothing about you: the sponsor placement is served from our own database, shows the same thing to every visitor, targets nothing, and loads no advertising script, pixel, or cookie. If you click a paid link, you leave our site and the advertiser’s affiliate network may set a cookie on its own domain to credit us for a resulting purchase; we receive only anonymous totals (clicks and commissions), never your identity or what you bought. See Section 16.
4. How We Use Your Information
- To provide and improve the Cloth Goblin service.
- To understand overall website traffic (for example, how many people visit the map each month), including to report aggregate audience size to prospective advertising and sponsorship partners. We never give partners information about individual visitors.
- To process payments and verify your unlock or subscription status.
- To moderate community-submitted location suggestions and to verify that an organization is who it says it is.
- To send transactional emails (account confirmation, payment receipts). We do not send marketing email without consent.
- To send the location notifications you asked for, until you unsubscribe.
- To detect abuse and enforce usage limits.
- To keep the records the law expects of us — consent records, financial records, and our log of legal requests.
Our legal bases (GDPR, UK GDPR, and similar laws). Where those laws apply, we rely on:
- Performance of a contract — running your account, giving you the features you paid for, and taking payment.
- Consent — location notification emails, an Organization's Instagram connection, and non-essential advertiser creatives where consent is required. You can withdraw consent at any time, which does not affect what we did before you withdrew it.
- Legitimate interests — keeping the directory accurate, preventing abuse and fraud, securing the Service, and understanding aggregate website traffic. We have weighed these against your rights and you can object at any time (Section 10).
- Legal obligation — tax and accounting records, and responding to lawful requests (Section 15).
5. Data Sharing
- Supabase (Supabase Inc., USA) — database, authentication, and file storage.
- Vercel (Vercel Inc., USA) — application hosting (transiently processes requests) and cookie-free, aggregate website analytics (Vercel Web Analytics; see Section 3).
- Stripe — payment processing.
- RevenueCat — in-app subscription and purchase receipt validation on iOS and Android.
- Apple and Google — app distribution and in-app purchases, for the app stores' own purchase records.
- Resend — transactional email delivery (account confirmation, receipts, notification emails).
- Google Maps Platform — map display, place search, and directions.
- Meta (Instagram Graph API) — if an Organization admin connects their Instagram account via our "Connect Instagram" button, we receive from Meta the IG user id, IG handle, a linked Facebook Page id, a long-lived access token (stored encrypted at rest), and the Organization's recently-published public Instagram posts. We use this data only to display the Organization's latest posts on their location drawer and, at our admins' discretion, on the public Featured page and homepage carousel. We do not use it for advertising, training, enrichment, or resale.
- Law enforcement when required by applicable law — see Section 15 below for how we handle these requests.
- A future buyer, if Friar Tek, LLC is ever merged, acquired, or sold, or in a bankruptcy or similar proceeding — in which case your information would move with the business. We would tell you before your information became subject to a different privacy policy.
What we publish. Locations, tags, photos, and posts you contribute are shown publicly, together with the display name you chose — never your email address. Aggregate counts we share with an Organization (such as how many people follow a location) are counts only.
Affiliate networks are different. Awin, Rakuten Advertising and similar networks are not our service providers and receive no data from us. They see a visit only if you choose to click a paid link, at which point you are on their redirect and then the advertiser’s own site, governed by their privacy policies. We never send them your email address, account, location, or browsing history.
Each of the vendors listed above is a service provider under the CCPA/CPRA (and a processor under GDPR) bound by a written data-processing agreement to use your information only to perform services for Cloth Goblin. These disclosures are not sales or shares of personal information. See Section 14 for our full non-broker, no-sale, no-share commitments.
6. Where Your Data Is Processed
Cloth Goblin is operated from the United States, and the providers listed in Section 5 process personal data in the United States. The Service is available worldwide, so if you use it from the United Kingdom, the European Economic Area, Switzerland, or another country with data-transfer rules, your information is transferred to the United States.
For those transfers we rely on the Standard Contractual Clauses adopted by the European Commission, together with the UK International Data Transfer Addendum and the Swiss equivalent where they apply, as incorporated into each provider's data processing agreement. Several of our providers are additionally certified under the EU–US Data Privacy Framework and its UK and Swiss extensions. You can ask us for details of the safeguards that apply to a particular transfer by emailing support@clothgoblin.com.
7. Data Retention
We retain your account data for as long as your account is active.
Unconfirmed signups: If you start creating an account but never confirm your email address, we send one reminder about a week before deletion, and the unconfirmed account and its data are permanently deleted after 30 days. Free accounts with a confirmed email are kept for as long as the account is active — a free account is never deleted for not subscribing.
Account deletion on request: You may permanently delete your account at any time from your account settings or by emailing support@clothgoblin.com. When your account is deleted: your profile, reactions, travel lists, tag suggestions, and authentication credentials are permanently erased immediately. Any locations you submitted remain on the map as part of the public directory, but the link to your account is removed. Account deletion is irreversible.
What can outlive a deletion request. Content you posted publicly may already have been copied, cached, or indexed by other people and by search engines, and we cannot reach those copies. Backups are overwritten on their normal cycle rather than edited. Three records survive, and all three have the link to you removed: the financial record of a purchase, a moderation record of a submission or an enforcement decision, and — if you signed an organization agreement — that signed agreement, which we keep for seven years because it is a contract. Our log of legal requests is kept separately from your account. Everything else goes, including your consent records.
Payment records: If you have made a purchase through Cloth Goblin, your payment records (including customer records and transaction history) are retained by our payment processor, Stripe, for legal and financial record-keeping purposes. These records are considered financial records under applicable law and are not subject to deletion requests under GDPR or similar regulations. Stripe's own privacy policy governs how they handle this data.
Verification documents: A document you upload to prove your business or to change an organization's email address is kept as the audit record of that decision, in restricted storage, and is deleted when it is no longer needed for that purpose or to defend the decision.
Instagram data: If your Organization connected Instagram, you can remove the connection and all auto-fetched cached posts at any time from Org Panel → Overview → Disconnect Instagram, or by removing Cloth Goblin from Instagram's Settings → Apps and websites. When Instagram notifies us that you removed the app, we automatically delete the encrypted access token and the auto-fetched post cache. A dedicated Data Deletion page walks through every path.
Cancelled Organization subscriptions: If your Organization's subscription lapses, we keep your listing for a short grace period so you can re-subscribe and pick up where you left off — but we do not retain your connected Instagram credential or personal contact details indefinitely. We stop using your Instagram access token as soon as the subscription ends; if you do not re-subscribe within 30 days, we delete the stored Instagram access token and the auto-fetched post cache (re-subscribing afterward simply reconnects Instagram). After12 months without an active subscription, we scrub the personal contact details on the Organization record (such as the signer's name, title, and phone number); the Organization and its financial records are retained only as long as required for tax and accounting record-keeping.
8. Cookies and Do Not Track
Ours. We set only strictly-necessary cookies — to keep you logged in and the service secure. We run no analytics or tracking cookies of our own, and we do not track you across other sites or apps. Our website analytics (Section 3) are cookie-free: they store nothing on your device. Because only essential cookies are ours, no consent is required for them: on the web we show a brief informational notice, and the mobile app shows no cookie prompt.
Advertisers’. Most sponsor creatives are an image or a line of text that we host, and they set nothing. Some advertisers supply their own banner, which loads from their affiliate network and may set a cookie on that network’s domain. Those are non-essential, so they are governed by consent: in the EU, EEA, UK and Switzerland nothing third-party loads until you agree; elsewhere they load by default and you can switch them off with the Do Not Sell or Share My Personal Information link in our footer, in Settings → Privacy, or by turning on Global Privacy Control in your browser, which we honor automatically. The apps show only the creatives we host ourselves, which set nothing and reach no one outside Cloth Goblin, so there is nothing there to consent to and the apps show no consent prompt. See Section 16.
Do Not Track and Global Privacy Control. Browsers can send a Do Not Track or Global Privacy Control signal. We honor both: if your browser sends either one, we do not count your visit in our website statistics and we do not load any advertiser's own creative, and we treat Global Privacy Control as a valid opt-out of sharing for cross-context behavioral advertising. We do not track you across other websites or apps in the first place, and we permit no one else to do so through the Service.
9. Your Choices
Whatever the law where you live, these controls are available to everyone:
- Your data, exported or deleted. Download a machine-readable copy of your data, or permanently delete your account, from Settings → Privacy.
- Location. Grant or withdraw location permission in your device or browser settings. Without it the map simply does not center on you.
- Camera and photos. Granted per upload and revocable in device settings. We only ever see files you pick.
- Notification emails. Unsubscribe from the link in any such email, or from your account settings. Transactional messages — confirmations and receipts — come with your account.
- Website statistics. Use the opt-out button in Section 3, or turn on Global Privacy Control or Do Not Track.
- Advertisers' creatives. Use the Do Not Sell or Share My Personal Information link in the footer or the same control in Settings → Privacy.
- Instagram. An Organization can disconnect at any time from the Org Panel, or from Instagram's own Apps and websites settings.
- Your display name and profile. Change them at any time from your account settings. If you need something corrected that you cannot edit yourself, write to us.
10. Your Rights
Depending on where you live, you may have some or all of the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you, and confirmation of whether we process it.
- Portability: Receive your data in a structured, machine-readable format.
- Correction: Ask us to correct inaccurate or incomplete data.
- Deletion: Request deletion of your account and associated personal data (see Section 7).
- Restriction: Ask us to limit how we process your data in certain circumstances.
- Objection: Object to processing based on our legitimate interests.
- Withdraw consent: Withdraw any consent you gave, at any time.
- No retaliation: Use any of these rights without being charged a different price or given a worse service. We will not discriminate against you for exercising them.
How to make a request: Signed-in users can download a machine-readable copy of their data and permanently delete their account directly from Settings → Privacy. For access, correction, restriction, or objection requests that aren't covered by those self-service tools, email support@clothgoblin.com with the subject line "Data Request" describing what you need. We will respond within 30 days. We verify a request by confirming you control the account's email address; for an organization record, we may also confirm your role. An authorized agent may make a request for you with written proof that you appointed them.
If we say no: we will tell you why, and you can ask us to look again by replying with the subject "Privacy Appeal". A person who did not make the first decision will review it and respond within 45 days, in writing, with the reasons. If we still say no, you can complain to your data protection authority or attorney general, and we will tell you how.
EU, EEA, and UK residents (GDPR / UK GDPR): Residents of European Union and European Economic Area member states, and of the United Kingdom, have all of the rights listed above under the General Data Protection Regulation (and UK GDPR post-Brexit). If you believe we have not handled your request appropriately, you have the right to lodge a complaint with your local data protection authority (for example, the ICO in the UK, or your national DPA in the EU).
Switzerland: Swiss residents have rights under the revised Federal Act on Data Protection (nFADP), including rights to access and correction of personal data held about them.
Canada (PIPEDA / provincial): Canadian residents have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation (Quebec's Law 25, Alberta's PIPA, British Columbia's PIPA), including access, correction, and withdrawal of consent. Complaints may be lodged with the Office of the Privacy Commissioner of Canada or your provincial regulator.
Brazil (LGPD): Residents of Brazil have rights under the Lei Geral de Proteção de Dados (LGPD), including access, correction, anonymization, deletion, portability, and the right to information about sharing. Complaints may be directed to the Autoridade Nacional de Proteção de Dados (ANPD).
Australia (Privacy Act 1988 / APPs): Australian residents have rights under the Privacy Act 1988 and the Australian Privacy Principles, including access to and correction of personal information. Complaints may be directed to the Office of the Australian Information Commissioner (OAIC).
New Zealand (Privacy Act 2020): New Zealand residents have rights of access and correction under the Privacy Act 2020, overseen by the Office of the Privacy Commissioner.
Japan (APPI): Residents of Japan have rights under the Act on the Protection of Personal Information (APPI), including disclosure, correction, and cessation of use. Complaints may be directed to the Personal Information Protection Commission (PPC).
South Korea (PIPA): Korean residents have rights under the Personal Information Protection Act, including access, correction, deletion, and suspension of processing. Complaints may be directed to the Personal Information Protection Commission.
Singapore (PDPA): Singaporean residents have rights under the Personal Data Protection Act, including access and correction. Complaints may be directed to the Personal Data Protection Commission.
India (DPDP Act): Residents of India have rights under the Digital Personal Data Protection Act, 2023, including access, correction, and erasure of personal data, along with the right to nominate a representative.
11. Your US State Privacy Rights
California (CCPA / CPRA). You have the right to know what personal information we collect and how it is used, to request a copy of it, to request deletion, to correct inaccurate information, to limit the use of sensitive personal information, and to opt out of the sale or sharing of your data. We do not sell personal information. The one narrow "share" is an advertiser's own banner, which you can switch off — see Section 16. We do not knowingly sell or share the personal information of anyone under 16.
California "Shine the Light" (Civil Code § 1798.83). We do not disclose personal information to third parties for their own direct marketing purposes, so there is nothing to report — but you may confirm that in writing by emailing us with the subject "Shine the Light".
Other states. Residents of Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Utah, Iowa, Indiana, Tennessee, Delaware, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Rhode Island, Kentucky, and other states with comprehensive privacy laws have rights that, depending on the state, include:
- Confirming whether we process your personal data, and accessing it.
- Correcting inaccuracies.
- Deleting personal data we hold about you.
- Obtaining a portable copy.
- Opting out of targeted advertising, of sale, and of profiling that produces legal or similarly significant effects. We do none of these things, so there is nothing for you to opt out of beyond the advertiser creatives described in Section 16.
- Limiting or consenting to the processing of sensitive data, and of the data of minors.
The exact scope varies by state. To exercise any of them, use Settings → Privacy or email support@clothgoblin.com with the subject "Data Request". If we decline, you may appeal as described in Section 10; several of these laws give you that right expressly, and we offer it to everyone.
Nevada. Nevada residents may opt out of the sale of certain covered information. We do not sell data of the kind that statute covers, but you may send a verified request to support@clothgoblin.com with the subject "Nevada Opt-Out" and we will confirm.
12. Security
We use industry-standard security practices including encryption in transit (TLS) and at rest. Passwords are never stored in plaintext. Instagram access tokens are encrypted at rest. Access to production data is restricted to authorized personnel only, and row-level security rules in our database limit what any given request can read.
Your part. Keep your password to yourself, and take care about what you put in the public parts of the Service — anything posted publicly can be seen by anyone.
No system is perfect. Transmission over the internet and mobile networks is never completely secure, so while we work hard to protect your information we cannot guarantee it, and you send it at your own risk. If a breach ever does affect your personal data, we will notify you and the relevant regulators where the law requires it.
13. Children
The Service is not directed at children under 13, and our Terms of Service require you to be at least 13 to create an account. We do not knowingly collect personal information from children under 13. If you are under 13, please do not register, post anything, or send us any information about yourself.
If we learn that we have collected personal information from a child under 13 without verifiable parental consent — or from a child below the applicable age of digital consent in the EEA or UK, which ranges from 13 to 16 depending on the country — we will delete it. If you believe a child has given us information, email support@clothgoblin.com and we will remove it promptly.
14. No Sale, No Sharing, No Data Brokerage
Cloth Goblin does not sell your personal information, does not share it for cross-context behavioral advertising, and is not a data broker.
Self-certification under California's Delete Act. Cloth Goblin is not a "data broker" as defined by California Civil Code §1798.99.80 (the Delete Act / SB 362). We have a direct relationship with every user whose personal information we collect — you create an account, confirm your email, and interact with us directly. We do not collect or sell information about consumers with whom we lack a direct relationship, and we are therefore not required to register with the California Privacy Protection Agency's data-broker registry.
Parallel commitments under non-US regimes. The same direct-relationship and no-sale principles apply globally: we do not operate as a data broker, list broker, or information reseller under comparable frameworks including Vermont's data-broker law, Texas's data-broker registration, Oregon's data-broker law, the EU / UK GDPR, Canada's PIPEDA (and provincial equivalents), Brazil's LGPD, Australia's Privacy Act, Japan's APPI, South Korea's PIPA, Singapore's PDPA, and India's DPDP Act. Where a jurisdiction maintains a broker or intermediary registry we monitor applicability annually, and our posture remains unchanged: we collect only from users who have a direct relationship with Cloth Goblin, and we do not sell, share, rent, or license that information.
Our affirmative commitments.
- No programmatic ad exchanges, retargeting pixels, or cross-site tracking of our own (Google Ads, Meta Pixel, TikTok Pixel, LinkedIn Insight, etc.). We do not build audiences, and we never upload our user lists to any ad platform.
- No data-enrichment, audience-append, or lookalike-modelling services (Clearbit, ZoomInfo, Acxiom, etc.).
- No sale, rental, license, or transfer of user lists — including Notify-Me subscribers, pre-claim interest, travel lists, or reactions.
- Subscriber-count metrics shared with Organizations are counts only; raw identities, email addresses, and individual activity never leave Cloth Goblin.
- One exception, and how to switch it off. When an advertiser’s own banner loads (Section 16), that network may set a cookie on its own domain. California treats that as “sharing” for cross-context behavioral advertising, so a Do Not Sell or Share My Personal Information link appears in our footer, the same control sits in Settings → Privacy, and we honor Global Privacy Control automatically. Using it leaves only our own cookie-free creatives. We still never sell personal information: money is paid for the placement, never for data about you.
How to challenge this classification. If you believe we are miscategorising our practices, email support@clothgoblin.com with the subject "Data Broker Question" and we will respond within 30 days.
15. Government and Legal Requests
Cloth Goblin occasionally receives requests from government agencies, law enforcement, regulators, or in connection with civil legal process (subpoenas, search warrants, court orders, national security requests, and comparable formal instruments, together "Legal Requests"). This section describes how we handle them.
Legality review. Every Legal Request is reviewed for facial validity and jurisdictional authority before we act on it. A request that appears unlawful, improperly served, or beyond the requesting authority's jurisdiction will be challenged or rejected.
Data minimization. We disclose only the specific information the Legal Request compels and only for the users identified in the request. Where a request is overly broad, we narrow it through negotiation or formal challenge before responding. We do not volunteer additional fields, neighbouring accounts, or derived data that were not specifically requested.
Challenges. Where we believe a Legal Request is unlawful, unduly broad, or materially overreaching, we will challenge it in the appropriate forum at our own cost. Where we are permitted to do so, we will notify the affected user before disclosure so they have an opportunity to intervene. Where we are prohibited from notifying the user (for example, a non-disclosure order attached to a search warrant or national security letter), we comply with the non-disclosure term but seek to lift it as soon as permitted.
Documentation. Each Legal Request and our response are recorded in our internal legal file, including the requesting authority, the legal basis cited, the scope, the data produced, and any challenge or narrowing activity. These records are retained so we can account for our practices to regulators and to you.
Transparency. We do not currently publish a separate transparency report because we have not received Legal Requests at a volume that would make one meaningful. If that changes we will begin publishing periodic aggregate numbers. In the meantime, if you have a specific inquiry about whether Cloth Goblin received a Legal Request concerning you, email support@clothgoblin.com with the subject "Legal Request Inquiry" and we will respond to the extent permitted by law.
Platform Data received from Meta. Where a Legal Request concerns Platform Data that Meta has shared with us under the Instagram Graph API (see Section 5), we handle it under the same principles above and additionally follow any platform-specific obligations Meta requires of its developers, including preserving the underlying data's confidentiality and not using the request as an opportunity to expand our own retention.
16. Advertising and Affiliate Links
Cloth Goblin makes money three ways: subscriptions, a small sponsor placement, and commissions on some product links. This section explains the last two.
The sponsor placement. One small ad space appears on our website and in our iOS and Android apps — on the homepage, the map, the Finds from the Cosmos page, and in the Travel List panel. It is not an ad exchange: we approve every advertiser by hand, there is no bidding, no audience building, and no advertising SDK in our code. We show the same rotation to everyone, so nothing about you decides which sponsor you see. In the apps it is narrower still: only creatives we host ourselves may run there, so showing one makes no request to anyone outside Cloth Goblin. An advertiser’s own network-served banner never runs in the apps, and neither the apps nor the website use an advertising identifier — no IDFA on iOS, no Advertising ID on Android.
Two kinds of creative. Most are hosted by us — an image or a line of text plus a link — and set nothing on your device. Some advertisers only supply their own banner, served by their affiliate network (for example Awin or Rakuten). Those load inside a sandboxed frame that cannot reach our page, our storage, or our cookies, but the network can set a cookie on its own domain and will see the request your browser makes to it, including your IP address. They are therefore governed by consent: opt-in in the EU, EEA, UK and Switzerland; on by default elsewhere with a one-click opt-out in our footer and in Settings → Privacy; and never loaded at all if your browser sends Global Privacy Control or Do Not Track. We embed creatives only from affiliate networks we have joined — never arbitrary ad code.
Affiliate links. Some links in our curated outfits, and some sponsor links, are affiliate links: if you buy something after clicking one, the shop pays us a commission at no extra cost to you. Paid links are always labelled — outfit pieces say “affiliate link”, unpaid ones say “unpaid pick”, and the sponsor placement is labelled “Sponsored” (a placement offering the space itself says “Advertise here”). Paid links also carry the rel="sponsored" attribute.
What the advertiser gets. Nothing from us. When you click a paid link, you travel through the affiliate network’s redirect to the shop, and the network may set a cookie on its own domain so the sale can be credited to us. That happens on their domains, under their privacy policies, and only if you click. We receive reports of anonymous click and commission totals — never your identity, your cart, or what you bought.
No endorsement. We choose advertisers ourselves and look for evidence behind environmental claims, but a sponsor placement or affiliate link is not a certification, guarantee, or endorsement of that company or its products. See our Terms of Service for the full disclaimer.
17. AI and Automated Decisions
We do not use your personal data to train AI models. Cloth Goblin does not sell or share your data with third-party AI providers for training, and we do not use any AI-training clause to harvest your submissions.
We may use narrowly-scoped, automated features — for example, rule-based filters that flag spammy or abusive submissions, or short summaries of public location information. These run against the minimum data needed and are not used to build a profile of you.
We do not make decisions that produce legal or similarly significant effects for you (such as account bans) based solely on automated processing — a person reviews moderation decisions before any enforcement action.
Because these features make no automated decisions about you and never use your personal data for AI training, there is no separate AI setting to manage. If you have a question about this, or wish to object to a specific use of your data, email support@clothgoblin.com with the subject "Data Request" and we’ll respond within 30 days.
18. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via email or an in-app notice. The "Last updated" date above reflects the most recent revision.
Please keep a working email address on your account so we can reach you, and have a look at this page now and then. Continuing to use the Service after a change means you are on notice of it — but where a change needs your consent under the law that applies to you, we will ask for it rather than assume it.
19. Contact Us
Cloth Goblin is operated by Friar Tek, LLC, Georgia, United States.
Questions, requests, or complaints about privacy: email support@clothgoblin.com. Please put what you need in the subject line — Data Request, Privacy Appeal, Data Broker Question, or Legal Request Inquiry — and we will route it properly.
If you are not satisfied with our answer, you may complain to your data protection authority, privacy commissioner, or attorney general. We would rather hear from you first and put it right.
