BANNED FOR LIFE PRIVACY POLICY
Effective Date: July 14, 2026
Last Updated: July 23, 2026
#Contents
- Summary
- Personal Information We Collect
- How We Use Personal Information
- Automated Screening and Human Moderation
- How We Disclose Personal Information
- Current Categories of Service Providers
- Sale, Sharing, and Advertising
- Retention
- Your Choices and Controls
- Access, Correction, Deletion, and Other Privacy Rights
- California Privacy Disclosures
- Security
- Children’s Privacy
- United States Operation and International Users
- Changes to This Policy
- Contact Us
This Privacy Policy explains how Kontracts Corp., a Delaware Corporation doing business as Banned for Life (“BFL,” “we,” “us,” or “our”), collects, uses, discloses, and retains personal information when you use the Banned for Life website, iOS application, related features, communications, and services that link to this Policy (collectively, the “Service”).
This Policy does not apply to a third-party website, application, or service that has its own privacy policy, even if the Service links to or integrates with it.
#1. Summary
- Reports, ratings, comments, profile information, and uploaded media may be public.
- We collect account information, User Content, place and location information, usage data, device and log information, and moderation and support information.
- We use information to provide, secure, moderate, improve, and comply with legal obligations relating to the Service.
- We use service providers for functions such as sign-in, maps and place information, email, hosting, storage, and security.
- The Service may access precise device location in two optional, user-initiated circumstances: when you use the map’s “Locate Me” control and when you separately allow location-based ranking for a business search. Map-centering coordinates are handled on the device. Search coordinates are sent to BFL’s servers solely to rank that search’s results by proximity, are not stored, and are discarded when the request is completed.
- We do not sell personal information for money.
- We do not use personal information for cross-context behavioral advertising and do not “share” personal information for that purpose as those terms are defined under California law.
- We do not permit users under 18 and do not knowingly collect personal information from children.
- You may request access, correction, deletion, or other rights as described below.
This summary is not a substitute for the full Policy.
#2. Personal Information We Collect
The personal information we collect depends on how you use the Service and the permissions you choose to grant.
#2.1 Information you provide
#Account and profile information
We may collect:
- email address;
- display name and username;
- password credential in hashed form, if you use password-based authentication;
- profile photograph, biography, city, and other optional profile information;
- account preferences and privacy settings;
- age or confirmation that you meet the minimum age; and
- account-verification information.
We do not store a readable copy of your password. If you use a third-party sign-in method, we receive information described in Section 2.3 instead.
#User Content and social activity
We collect information you submit or generate through the Service, including:
- business and place submissions, corrections, and searches;
- reports, Lifetime Ban ratings, headlines, narratives, issue categories, visit dates, and transaction context;
- photographs, captions, alt text, receipts, screenshots, and other uploaded files;
- comments, replies, likes, follows, and blocks;
- watchlist entries, meaning places you have chosen to be notified about;
- activity records used to compute participation streaks and community-helpfulness rankings, including which of your posts received a “found this helpful” mark, comments you make, and flags you raise that are upheld;
- referral relationships, including an invite code you shared or entered at sign-up and the resulting attribution to an inviter;
- companion tags, meaning validated identifiers of other BFL users whom a report author tagged as sharing the experience;
- flags, disputes, and copyright notices; and
- communications with BFL.
Free-form fields can contain information you choose to provide. Do not submit personal information that is unnecessary to describe the experience.
#Support, dispute, and legal information
We collect information you provide when you contact support, report a safety issue, dispute content, appeal a decision, submit a legal request, or communicate with us. This may include contact information, correspondence, evidence, declarations, and information about your relationship to a user or business.
#2.2 Information collected automatically
When you use the Service, we and our service providers may automatically collect:
- Internet Protocol address;
- device type, operating system, browser, application version, language, and time zone;
- device and application identifiers;
- dates and times of access;
- pages, screens, searches, links, buttons, and features used;
- referring and exit pages;
- session, authentication, and security events;
- crash, diagnostic, latency, and performance information;
- approximate location inferred from IP address; and
- cookie, local-storage, and similar technology information.
We use this information to operate the Service, maintain sessions, remember preferences, prevent abuse, measure performance, understand feature use, and investigate security incidents.
#2.3 Information from sign-in and other providers
If you choose Sign in with Apple or Google sign-in, the provider may give us an account identifier and information you authorize it to share, such as your email address, name, or relay email address. We use that information to authenticate you and maintain your account.
We do not receive your Apple or Google password. Your use of the provider remains subject to its terms and privacy practices.
#2.4 Location and place information
The Service processes location information in three distinct ways:
- Coarse and place-related location. We may process an approximate location, such as a city, ZIP code, or location inferred from an IP address, as well as the address and coordinates of a business or place that you search for, view, add, or identify in a report. Depending on the feature, this information may be associated with a search, report, business listing, or other activity on the Service.
- Map centering. The Service may access GPS-level latitude and longitude when you actively select the “Locate Me,” “Center on My Location,” or equivalent map control and grant the location permission requested by your device or browser. BFL uses these coordinates through client-side application code solely to center the map on your current location for your convenience. These map-centering coordinates are not transmitted to BFL’s servers, associated with your BFL account, or retained by BFL after the map is centered.
- Proximity-ranked business searches. When you perform a business search, the Service may separately ask whether you want to use your current precise location to rank the results by proximity. If you agree and have granted the required device or browser permission, the Service sends your GPS-level latitude and longitude to BFL’s servers solely to rank the results for that search by distance from your current location. BFL does not store those search coordinates in a database, associate them with your BFL account, attach them to any report or Lifetime Ban post, or retain them after the search request is completed. BFL does not use search coordinates for analytics, advertising, profiling, personalization, report creation, or building a search or location history.
The Service does not access precise device location in the background, continuously, merely because you opened the Service, or without the permission required by your device or browser. The Service asks separately whether to use precise location for map centering and for proximity-ranked business searches.
Both precise-location features are optional. You may decline either request and continue using the Service. If you decline map location, the map will display available businesses or other map data using its default fit-to-bounds view. If you decline search location, business search remains fully functional, but the results will not be ranked using your current precise location. You may search using a city, state, address, or ZIP code, and you may navigate the map manually. You may revoke operating-system or browser location permission at any time through your device or browser settings.
The Service uses more than one map and place provider. The native iOS application renders the map using Apple Maps (MapKit). The web application renders the map using Google Maps. Business search, place information, and geocoding use Google Places and related Google services, and an authorized proximity-ranked business search transmits your precise coordinates to Google Places through BFL’s servers. When you use the map or a business-search feature, Apple or Google, as applicable to the feature you use, may receive location, search, map-interaction, device, and network information as necessary to provide that service. Apple processes that information under its own Privacy Policy, and Google processes that information under its own Privacy Policy. The limitations in this Section concerning BFL’s storage and retention do not govern Apple’s or Google’s independent processing.
#2.5 Uploaded media and metadata
Uploaded photographs may contain metadata, including date, device, and precise location information. We are designed to remove Exchangeable Image File Format (“EXIF”) and similar location metadata from public, processed image versions before display.
We may temporarily retain an original upload in private storage for processing, security review, dispute handling, or legal preservation. The retention period is described in Section 8. Technical processing reduces but does not eliminate privacy risk. You must review images and remove visible personal information before upload.
#2.6 Cookies and similar technologies
The web Service may use cookies, local storage, software-development kits, pixels, and similar technologies for:
- authentication and session management;
- security and fraud prevention;
- preferences and functionality;
- performance and diagnostics; and
- first-party product analytics.
We do not currently use third-party advertising cookies or tracking technologies for cross-context behavioral advertising.
Browser settings may allow you to delete or block cookies. Blocking essential technologies may prevent parts of the Service from working.
#2.7 Information from other users and public sources
Other users, businesses, and complainants may provide information about you in reports, comments, flags, disputes, or legal requests. We may also receive business and place information from public sources and licensed data providers.
#3. How We Use Personal Information
We may use personal information to:
#Provide and personalize the Service
- create and manage accounts;
- authenticate users;
- publish and display reports, ratings, comments, media, and profiles;
- provide search, map, feed, follow, watchlist, and notification features;
- use precise device location when you request map centering, solely to center the map on your device;
- receive precise device location when you separately authorize location-based business search, solely to rank the results for that request by proximity, without storing the coordinates or associating them with your account or Content;
- compute community-helpfulness rankings, participation streaks, and personal severity comparisons that are shown in-app and on your public profile;
- attribute referrals when someone signs up with your invite code; and
- respond to support requests.
#Moderate and protect users
- screen and review content;
- detect spam, manipulation, harassment, threats, doxxing, infringement, and other policy violations;
- receive and resolve flags and disputes;
- investigate account compromise, misuse, fraud, and coordinated activity;
- block users and enforce restrictions; and
- protect the safety, rights, and integrity of users, businesses, BFL, and others.
#Operate, analyze, and improve the Service
- monitor availability, reliability, and performance;
- troubleshoot errors and crashes;
- understand how features are used;
- improve search, duplicate-place detection, accessibility, and user experience;
- develop new features; and
- conduct internal research using aggregated or de-identified information where appropriate.
#Communicate with you
- send account verification and authentication messages;
- provide service, security, moderation, dispute, and legal notices;
- send notifications about comments, likes, follows, new reports on places on your watchlist, companion tags on reports you have been added to, or account activity according to your settings;
- respond to inquiries; and
- send marketing messages only where permitted and with an available opt-out.
#Comply with law and enforce agreements
- comply with lawful process and regulatory obligations;
- establish, exercise, or defend legal claims;
- preserve records subject to a dispute, investigation, or legal hold;
- enforce the Terms of Service and Posting Guidelines; and
- complete a corporate transaction, subject to appropriate safeguards.
We may use information for another purpose disclosed when it is collected or with your consent.
#4. Automated Screening and Human Moderation
We may use automated tools to identify content or activity that may violate our rules, create legal or safety risk, contain sensitive information, or require human review. Signals may include text patterns, image characteristics, account behavior, duplicate activity, user reports, and other context.
Automated tools assist moderation and prioritization. They do not establish whether an allegation is true, whether a law was violated, or whether a person is dangerous or dishonest. Material moderation actions may involve human review where appropriate. We retain information about moderation decisions and appeals as described below.
Precise coordinates received for proximity-ranked business searches are not used as moderation signals and are not processed by these automated screening tools.
#5. How We Disclose Personal Information
We may disclose personal information as follows.
#5.1 Publicly and to other users
Reports, ratings, comments, public profiles, usernames, photographs, contribution activity, and certain timestamps may be visible to anyone, including people without an account. Public content may be indexed by search engines and shared outside the Service.
We may display an edited indicator, moderation label, or aggregate information. We do not publicly display account email addresses unless you intentionally publish one.
#5.2 Service providers
We disclose information to vendors that perform services for us, such as:
- cloud, VPS, and database hosting;
- authentication and identity services;
- map, geocoding, search, and place-information services;
- email delivery;
- content processing and image transformation;
- security, fraud prevention, logging, and monitoring;
- customer support; and
- professional services.
These providers may process information only for the services they provide to us, subject to applicable contractual and legal restrictions.
When you authorize a proximity-ranked business search, precise coordinates are transmitted to and processed transiently by BFL’s servers and hosting infrastructure solely to rank the results for that request by proximity. BFL does not disclose those coordinates to businesses, other users, advertisers, data brokers, or analytics providers. BFL does not store the coordinates in its database or logs, associate them with your account, attach them to a report or Lifetime Ban post, or retain them after the request is completed.
The native iOS application renders the map using Apple Maps (MapKit). The web application renders the map using Google Maps. Business search, place information, and geocoding use Google Places and related Google services. When you use the map or a related place or search service, Apple or Google, as applicable to the feature you use, may receive search requests, map-interaction information, device and network information, and location information, including precise location when necessary for a location feature you request. When you authorize a proximity-ranked business search, BFL’s servers transmit your precise coordinates to Google Places solely to obtain results ranked by proximity for that request. Apple’s and Google’s processing is governed by their own privacy terms.
#5.3 Sign-in and user-directed services
When you use Sign in with Apple, Google sign-in, device sharing, or another integration, information is exchanged as necessary to complete your request. Information you choose to share through a third-party application is governed by that third party after it receives the information.
#5.4 Businesses and disputing parties
We may provide a business or complaining party with enough information to identify and respond to challenged content, such as the report, public username, publication date, and substance of a dispute. We may provide a contributor with a complaint or supporting information.
We do not routinely provide a contributor’s nonpublic account information to a business merely because the business requests it. We may withhold, redact, or disclose information based on safety, privacy, legal process, and fairness considerations.
#5.5 Legal, safety, and rights protection
We may disclose information if we believe in good faith that disclosure is reasonably necessary to:
- comply with law, regulation, legal process, or a valid governmental request;
- protect the rights, property, safety, or security of BFL, users, businesses, or others;
- investigate fraud, threats, abuse, infringement, or illegal activity;
- enforce our agreements and policies; or
- establish, exercise, or defend legal claims.
Where legally permitted and appropriate, we may notify the affected user before disclosing information in response to legal process.
#5.6 Corporate transactions
We may disclose information in connection with an actual or proposed merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction. A successor’s use of personal information remains subject to this Policy unless and until it provides notice of a different policy as required by law.
#5.7 Professional advisers
We may disclose information to attorneys, auditors, insurers, consultants, and other professional advisers where reasonably necessary and subject to appropriate duties or restrictions.
#5.8 With your direction or consent
We may disclose information when you direct us to do so, consent, or intentionally use a feature that requires disclosure.
#6. Current Categories of Service Providers
- Apple: Sign in with Apple, iOS distribution, device permissions, push-notification infrastructure, and Apple Maps (MapKit) rendering of the map in the native iOS application, as applicable. Apple may receive location, map-interaction, device, and network information when you use the map in the iOS application, including precise location when you activate a map location control. Privacy notice
- Google: Google sign-in; Google Maps rendering of the map in the web application; and Google Places, geocoding, or related place-information services used for business search throughout the Service. Google may receive search, location, map-interaction, device, and network information when you use those features, including precise location when necessary for a location feature you request, such as an authorized proximity-ranked business search transmitted through BFL’s servers. Privacy notice
- Resend: transactional and service email delivery. Privacy notice
- Contabo: application and server hosting. Privacy notice
Each third party has its own privacy practices for information it processes independently.
#7. Sale, Sharing, and Advertising
We do not sell personal information for money. We do not currently disclose personal information for cross-context behavioral advertising and do not currently display third-party behavioral advertisements.
If our practices change, we will update this Policy and provide any notice, consent, or opt-out mechanism required by law before using personal information in the new manner.
We may disclose personal information to service providers and other recipients described in Section 5. Such operational disclosures are not treated as a sale when applicable legal requirements are satisfied.
We do not sell precise geolocation information, share it for cross-context behavioral advertising, disclose it to data brokers or advertisers, or use it for advertising, profiling, analytics, personalization, report creation, or location-history purposes. BFL receives precise coordinates only when you authorize a proximity-ranked business search and uses them solely to rank the results for that request by proximity. BFL does not retain those coordinates after the request is completed. Map-centering coordinates are not transmitted to BFL’s servers. Google may process location information as described in Sections 2.4, 5, and 6.
#8. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Service, maintaining integrity and security, resolving disputes, enforcing agreements, and satisfying legal obligations.
Anticipated retention periods are:
- Precise device location used for map centering: BFL does not receive or retain these coordinates. They are used transiently in client-side application memory and discarded after the map is centered.
- Precise device location used for business search: These coordinates are transmitted to BFL’s servers, used transiently to rank the results for that request by proximity, and discarded when the request is completed. They are not stored in a database, cache, log, user record, Content record, analytics system, or backup.
- Account information: while the account is active and for 90 days after deletion, except for information retained for security, fraud prevention, disputes, or legal obligations.
- Public User Content: until deleted by the user or removed by BFL, subject to backups, quotations, interactions, disputes, and legal preservation.
- Original media uploads: for 90 days after successful processing, unless retained for an active report, dispute, security review, or legal hold. Processed public versions remain with the related Content.
- Authentication and security logs: generally 90 days, with longer retention for detected abuse, fraud, or incidents.
- Moderation and audit records: generally 3 years after final action to support consistency, appeals, safety, and legal defense.
- Flags, disputes, appeals, and legal requests: generally 3 years after closure, or longer during a legal hold.
- Support communications: generally 2 years after resolution.
- Backups: deleted or overwritten on a rolling schedule of approximately 90 days, unless isolated for security or legal preservation.
We may retain de-identified or aggregated information that cannot reasonably identify you.
#9. Your Choices and Controls
#9.1 Account and profile
You may review or update certain account information through account settings. Some information, such as an account identifier or audit history, may not be editable.
#9.2 Content controls
You may edit or delete eligible Content through the Service. We may preserve prior versions, moderation records, and information subject to a dispute or legal hold. Deleting a report may affect comments, but may not remove independent content submitted by others.
#9.3 Location
Precise location access is optional and requires the permission required by your device or browser. The Service separately asks whether you want to use precise location to center the map and whether you want to use it to rank a business search by proximity.
You may decline either use and continue using the Service. If you decline map location, the map will use its default fit-to-bounds view. If you decline search location, business search remains fully functional, but results will not be ranked using your current precise location. You may use the manual city, state, address, or ZIP-code search options without granting access to device location. You may revoke device or browser permission at any time through settings.
BFL does not receive map-centering coordinates. When you authorize a proximity-ranked business search, BFL receives the coordinates only to process that search and does not retain them after the request is completed.
#9.4 Notifications
You may manage email-notification preferences in account settings, including a per-account toggle to receive emails when a place on your watchlist receives a new published report. We may still send nonpromotional messages necessary for security, account administration, moderation, disputes, and legal notices.
#9.5 Email marketing
If we send marketing email, you may unsubscribe using the link in the message. Unsubscribing from marketing does not stop transactional or service communications.
#9.6 Cookies
You may control cookies through browser settings and any consent or preference tool we make available. Essential cookies cannot be disabled through our tools because they are needed for core functions.
#9.7 Blocking
You may block another user through available controls. Blocking may limit interactions but may not prevent all visibility of public content.
#10. Access, Correction, Deletion, and Other Privacy Rights
Depending on where you live and applicable law, you may have the right to:
- confirm whether we process your personal information;
- access or obtain a copy of personal information;
- correct inaccurate personal information;
- delete personal information;
- obtain information about categories, sources, purposes, and recipients;
- opt out of certain sales, sharing, targeted advertising, or profiling;
- limit certain uses of sensitive personal information;
- withdraw consent where processing relies on consent; and
- appeal a denial of a privacy request.
We do not discriminate against you for exercising an applicable privacy right.
#How to submit a request
Submit a request through https://bannedforlife.app/privacy or email bannedforlifeapp@gmail.com with the subject “Privacy Request.” Describe the right you wish to exercise and identify the account involved.
We will verify requests by matching information associated with your account or requesting additional information reasonably necessary to prevent unauthorized access or deletion. We will not request more information than reasonably needed. If we cannot verify a request, we may deny or limit it.
An authorized agent may submit a request where permitted by law. We may require evidence of the agent’s authority and may ask you to verify your identity directly.
We may deny or limit a request where an exception applies, including to protect another person’s rights, maintain security, complete a transaction, prevent fraud, preserve evidence, comply with law, or establish or defend legal claims. We will explain a denial where required.
To appeal a denied request, email bannedforlifeapp@gmail.com within 45 days and state why you believe the decision should be reconsidered.
#11. California Privacy Disclosures
#11.1 California Online Privacy Protection Act
The categories of personal information we collect, the categories of third parties with whom we disclose it, and our process for reviewing changes are described in this Policy. The effective date appears above.
#11.2 Do Not Track
Some browsers transmit “Do Not Track” signals. Because there is no universally accepted standard for responding to those signals, the Service does not currently respond to them. We do respond to legally recognized browser-based opt-out preference signals where required.
#11.3 California Consumer Privacy Act
If BFL becomes subject to the California Consumer Privacy Act, as amended, California residents may exercise the applicable rights described in Section 10. During the preceding 12 months, we collected the categories of personal information described in Section 2, used them for the purposes described in Section 3, and disclosed them to the recipient categories described in Section 5.
Precise geolocation is sensitive personal information under California law and may be treated similarly under other state privacy laws. The Service processes precise location only when you affirmatively request map centering or separately authorize proximity-ranked business search. Map-centering coordinates are handled on the device and are not transmitted to BFL’s servers. Search coordinates are transmitted to BFL’s servers solely to rank the results for that request by proximity and are discarded when the request is completed.
BFL does not store search coordinates, associate them with a BFL account, attach them to a report or Lifetime Ban post, sell or share them for cross-context behavioral advertising, disclose them to data brokers or advertisers, use them for analytics, advertising, profiling, personalization, or location history, or otherwise use or disclose them for purposes that require a right to limit under California law. You may exercise applicable rights as described in Section 10 and may decline or disable location access as described in Section 9.3. Because BFL does not retain search coordinates after completing the request, BFL ordinarily will not have stored precise-geolocation information to provide, correct, or delete in response to a later request.
We do not have actual knowledge that we sell or share the personal information of consumers under 16. The Service is limited to users age 18 or older.
#11.4 California “Shine the Light”
We do not disclose personal information to third parties for their own direct-marketing purposes as contemplated by California Civil Code section 1798.83.
#12. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including access controls, encryption in transit, credential hashing, logging, private media storage, and role-based access for moderation and administration where appropriate.
No method of transmission, storage, or security is completely secure. We cannot guarantee that personal information will never be accessed, used, altered, or disclosed without authorization. You are responsible for maintaining the security of your account and promptly reporting suspected compromise.
#13. Children’s Privacy
The Service is intended only for users who are at least 18 years old. We do not knowingly collect personal information from a child under 13 or knowingly permit a person under 18 to maintain an account.
The precise-location feature is not intended for or made available to children. Because the Service does not permit users under 18, BFL does not use precise location for separate child-directed purposes.
If you believe a child has provided personal information, contact bannedforlifeapp@gmail.com. We will investigate and take appropriate steps, which may include deleting the account and information, subject to legal preservation obligations.
Do not include information or images identifying a minor in User Content.
#14. United States Operation and International Users
The Service is operated from the United States and is initially intended for users in the United States. If you access the Service from another country, your information may be transferred to, processed in, and stored in the United States, where privacy laws may differ from those in your location.
#15. Changes to This Policy
We may update this Policy to reflect changes in the Service, law, or our practices. We will post the updated Policy and revise the “Last Updated” date. If a change materially affects how we use personal information, we will provide additional notice through the Service, by email, or by another reasonable method where required.
If required by law, we will obtain consent before applying a material change to information already collected.
#16. Contact Us
Kontracts Corp.
c/o Harvard Business Services, Inc., 16192 Coastal Highway
Lewes, Delaware 19958
Privacy email: bannedforlifeapp@gmail.com
Telephone: 561-320-3663
Privacy request form: https://bannedforlife.app/privacy