Privacy Policy

Last updated September 28, 2026

The short version

We collect what you give us and what you do here, we don’t sell any of it, we don’t run ads, and we don’t track you across other websites. There is no analytics service, no advertising pixel, and no third-party tracker anywhere on this site. The detail below matters though — especially the part about what is visible without signing in.

Who this is about

Bantu Connect is operated by AWO Logistics LLC, a Missouri limited liability company. This policy covers the website and everything on it. The rules for using the platform are set out separately in the Terms of Service.

What you give us

To open an account: your first and last name, a nickname if you use one, your email address, a password, your city, and the Reer you call home. You confirm that you are 18 or older. We do not ask for your date of birth.

If you choose to add it: a profile photo and cover photo, a bio, pronouns, a website, your education, your work history, the areas you work in, and your skills.

If you ask to be verified: a government ID and a selfie, plus links to your work and a description of what you’re known for. The ID and the selfie are deleted as soon as the request is decided — see how long we keep things, below.

If you list a business: its name, address, phone number, email, opening hours, social links, and photos. A business listing is a public directory entry, so treat everything in it as public.

What you create

Posts and photos, comments, reactions, saves and reshares, gatherings you host and the RSVPs you give, milestones, music you upload with its cover art, award applications, nominations and votes, sports predictions, and private messages including any photos or files in them.

What we record as you use the site

Some things are collected by the platform working rather than by you writing them:

  • Your searches. The words you type, how many results came back, what you clicked, and where in the list it sat. We use this to make search better. It is deleted after 30 days.
  • Songs you play. Which song, and when. This is what builds the weekly charts and tells an artist their song passed a play milestone. Nobody can see who played a song — not other members, not the artist. After 12 months we strip your identity from the record entirely and keep only the play itself.
  • Whether you’re online. When you were last seen, whether you’re online now, whether you’re typing, and which conversation you have open — so the person you’re messaging sees the typing indicator. This is current status, constantly overwritten, not a history.
  • Notifications about activity involving you, and a record of notification emails we tried to send you.
  • Ordinary server and device information — your IP address, browser, and the requests you make — which our hosting and database providers log to keep the service running and to stop abuse. We also count certain actions to enforce rate limits.
  • Reports and moderation records if you report something or something you posted is reported.

What we never collect

We never receive or store card numbers, bank account details, or the government ID you give Stripe to verify a seller account. That goes straight to Stripe. We don’t buy information about you from anyone, we don’t collect your precise location, and we don’t read your contacts or your device.

Who can see what

Visible to anyone on the internet, with no account: gatherings — including the host name, venue name, and the venue’s street address — along with posts, reshares, and the list of Reers and fields. Assume a gathering you create can be read by anyone. Profiles are not: a visitor without an account gets nothing from them.

Also public to anyone with the link: profile photos, business photos, gathering posters, record label logos, and uploaded music and its cover art. These are served from public storage. Private messages’ attachments, post photos, and verification documents are not — those are private and served through short-lived signed links.

Visible to signed-in members: your profile and everything on it, your milestones, your public posts and comments, your RSVPs, your music, and your sports predictions, which every member can see. Your connections list follows the setting you choose — everyone, only your connections, or only you.

Private to you: your email address, your password, your private messages, your saves, your notification settings, and your award votes. The ballot is secret: nobody but you and the awards committee that counts it can see how you voted. An award nomination is different — once approved, members can see who nominated whom.

What administrators can see. Administrators can see what any member can, plus reports and moderation history. They cannot browse your private messages. If a specific message is reported, an administrator can reveal that one message to act on the report, and every reveal is written to an audit log before the message is shown — so there is a permanent record of who looked and when. Reer leads have no moderation access at all, and awards committee members only see what their award requires.

What we do with it

Run the platform: show you your community, deliver your messages, build the charts, score the predictions, count the votes. Keep it safe: verify accounts, enforce rate limits, act on reports. Reach you: confirmation and password-reset email, and notifications you haven’t turned off. Improve it: understand what people search for so search gets better.

We do not sell your personal information, share it for advertising, or use it to build a profile of you for anyone else. We may share information when the law requires it, to protect someone’s safety, or if the business is ever transferred — in which case we’d tell you first.

Who else touches your information

  • Supabase — our database, sign-in system, and file storage. Everything described above lives there.
  • Netlify — hosts the website and serves it to your browser, so it sees your IP address and the pages you request.
  • Resend — sends our email. It receives your email address and the contents of the message being sent.
  • Stripe — will handle payments, payouts, and seller identity verification once buying and selling opens. Stripe collects and holds sellers’ identity and bank information directly under its own privacy policy. We receive a record of the transaction, never the payment details behind it.

Each of these is a US company, and each receives only what it needs to do its job.

One thing worth naming even though it isn’t a processor: the sports scores, fixtures, and team crests come from an outside sports data service. Information travels one way — we fetch from them and re-host the images ourselves, so your browser never contacts them and nothing about you is ever sent.

Cookies and what's stored on your device

Cookies: only the ones that keep you signed in. They’re set by our sign-in system and refreshed as you browse. There are no advertising cookies, no analytics cookies, and no third-party cookies of any kind.

Stored in your browser: small preferences that never leave your device — your recent searches, your emoji skin-tone choice, and a timestamp used to retry a failed request. Clearing your browser data removes them.

Offline caching: the site installs a service worker so it still works on a poor connection. It caches pages and images, and it fetches your data from the network first rather than serving it from the cache — chosen deliberately so that on a shared phone one person’s data can never be shown to the next person who signs in.

How long we keep things

  • Your profile, posts, photos, messages, music, milestones, and listings — until you delete them, or until you delete your account. We don’t expire them on a timer.
  • Searches — 30 days.
  • Who played which song — 12 months, after which your identity is stripped from the record and only the play remains.
  • Notifications — 90 days.
  • Records of notification email we sent — 30 days.
  • Verification ID and selfie — deleted as soon as the request is approved or declined. The decision itself, and what you said you’re known for, are kept.
  • Reports, moderation decisions, and the message-reveal audit log — 2 years, or until the account they concern is deleted, whichever comes first.
  • Whether you’re online — not kept as history; it is a single current value, overwritten as you use the site and removed with your account.
  • Records of money — once buying and selling opens, records of sales, refunds, and payouts are kept for 7 years, because tax and accounting law requires it. These survive account deletion. They hold what was sold, for how much, and to whom — never payment details.

Your choices

From your own settings you can:

  • Edit your profile, change your home Reer, and delete your own posts and milestones
  • Choose who can see your connections — everyone, your connections, or only you
  • Pause your profile, which takes you out of the directory, out of search, and shows you as offline
  • Block another member
  • Turn off categories of notification, in the app and by email
  • Download a copy of your data
  • Sign out of every device at once
  • Change your password, or delete your account

Deleting your account is scheduled for a fixed date 30 days after you ask, and that date doesn’t move if you come back — you’ll see a banner with the date and a button to keep your account for as long as the request stands. On that date your profile, your content, and the gatherings you created are deleted. What survives is listed above.

Your rights

Some states — California, Colorado, Connecticut, Virginia and a growing list of others — give residents the right to know what a company holds about them, get a copy, correct it, delete it, and not be treated worse for asking. Missouri has no law like that. Where a law gives you those rights, we honour them as that law requires. Where none does, the settings below are open to you anyway.

Most of what people want, you can do yourself from your settings, immediately — that is the fastest route and it needs nobody’s approval. For anything you can’t, ask us and we’ll respond within the time the applicable law allows, and within 45 days where no law sets one. We may need to confirm it’s really you first, and for a request about someone else’s account we will need proof you’re entitled to make it. We may decline a request the law lets us decline — for example where it would expose another member’s information or where we are required to keep the record — and if we do, we’ll tell you why.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We never have. There is no mechanism on this site for doing either, which is a stronger statement than a promise.

How we protect it

Access rules are enforced by the database itself, not by the interface — so a page that forgot to hide something still couldn’t show you data you’re not entitled to. Traffic is encrypted in transit. Passwords are hashed by our sign-in provider and are never visible to us. Private files — message attachments, post photos, verification documents — sit in private storage and are reachable only through short-lived signed links. Administrator access to a reported message is logged before it happens.

No system is perfectly secure, and we won’t pretend otherwise — nothing here is a guarantee that your information cannot be accessed by someone who shouldn’t. If a breach ever reaches your personal information, we’ll notify you as Missouri’s breach-notification law (Mo. Rev. Stat. § 407.1500) and any other law that applies require.

Children

Bantu Connect is for adults. You must be 18 or older to have an account, the site is not directed at children, and we don’t knowingly collect anything from anyone under 18. If we learn we have, we delete the account and its data. If you believe a child has an account here, report it to us.

Changes to this policy

If this policy changes in a way that affects you, we’ll tell you by email or a notice in the app before it takes effect, rather than quietly editing the page. The date at the top is always the current version.