Privacy
Privacy Policy
Last updated: July 20, 2026
1. Who operates SConnect and what this policy covers
SConnect is operated by Ismael Hernandez Jr., a California sole proprietor operating SConnect in Kern County, California. In this policy, “SConnect,” “we,” “us,” and “our” refer to that operator.
This policy applies to the SConnect website and progressive web application, account areas, unlisted tip pages, invite-only worker pages, invitations, checkout initiation, payouts, receipts, disputes, and support. It covers workers, tippers with accounts, people who receive invitations, guests who leave tips without an account, and authorized SConnect administrators.
Stripe-hosted checkout, identity, connected-account, and payout experiences are also governed by Stripe's own privacy terms. External websites linked by a worker are governed by their own operators' policies.
2. Account, profile, invitation, and relationship information
When someone creates an account, SConnect may collect a Firebase user identifier, name or display name, email address, account role, email-verification status, agreement records, account status, locale, time zone, and notification preferences. Firebase processes passwords and authentication credentials; SConnect does not store account passwords in its application database.
When an account holder accepts the current Terms, Privacy Policy, Fee Disclosure, or California eligibility statement, SConnect records the account identifier, each accepted document version, the source of the acceptance, the statements accepted, and the acceptance timestamp. When a guest continues from a tip page, SConnect records the versions presented, the selected tip, each disclosed fee, the exact authorized total, the checkout and payment references, and the action used to continue. These records document the agreement and transaction that actually occurred; acceptance of one version is not treated as blanket consent to materially different future fees or privacy practices.
A worker may provide a public display name, biography, page color, suggested tip amounts, venue name or location, map link, schedule, service and price-board information, likes, dislikes, and external links. Workers choose which optional private-page sections are visible and should publish only information they are comfortable sharing with the intended audience.
Automated invitation email is currently disabled. A worker can create a single-use invitation link and send it through a phone's native share sheet; SConnect stores the invitation's worker, delivery method, status, and expiration but does not receive the message composed in the selected app. Historical email-invitation records may contain a masked recipient address and a one-way identifier. When a verified tipper accepts an invitation, SConnect records the relationship and shows that worker the tipper's account display name and masked email address. Workers may revoke or block that relationship, and SConnect retains limited block information as needed to enforce the choice.
3. California worker eligibility information
Worker accounts are currently limited to adults who reside in California and use SConnect for work performed in California. SConnect records the worker's eligibility attestation, the policy and agreement versions accepted, eligibility status and reason, verification source, and relevant timestamps.
During signup or renewed consent, a worker enters a five-digit California ZIP code so SConnect can check whether it falls within the supported range. The application validates that ZIP code during the request and does not save the raw ZIP code in its database; it saves only that the ZIP check passed. SConnect also records the country and region codes Cloudflare associates with that consent request. Network location can be wrong, including when a person uses a mobile network or VPN, and it is not treated as GPS location.
Stripe collects identity and address information during connected-account onboarding. SConnect may receive the country, state, individual-account status, and verification readiness needed to determine whether the account remains eligible. SConnect stores the resulting eligibility state, such as verified for California, pending review, or ineligible, rather than a copy of the full Stripe identity file.
4. Tips, payouts, receipts, and disputes
When a guest starts a tip, SConnect may process the worker identifier, selected or custom tip amount, currency, fee allocation, optional receipt email, checkout and payment identifiers, status, timestamps, 3DS authentication result, and fraud or risk signals supplied by Stripe. Stripe collects card and billing details on its hosted pages. SConnect does not store complete card numbers, security codes, or complete bank credentials in its application database.
For connected accounts and cashouts, SConnect receives account and capability status, balances, payout identifiers and status, amount, speed, limited destination details such as type and last four digits, and provider fee information when available. A cashout request also records the worker's verified email, a masked IP address, and Cloudflare's approximate city, region, country, and time zone for the request. Those masked or approximate security details may appear in the worker's cashout receipt. SConnect does not use device GPS for this purpose.
If a payment is disputed, SConnect may process the reason, deadline, payment and transfer references, limited billing identity and address information supplied by Stripe, 3DS information, worker statements, relevant communications, evidence-file metadata, refund information, provider decisions, and an activity history. Authorized SConnect administrators may review that information to prepare, submit, or accept a response through Stripe. Stripe, card networks, issuing banks, and payout institutions may retain their own transaction and dispute records under their rules and legal obligations.
5. Device, network, cookie, and application information
SConnect and its providers may process IP address, browser or device type, referring page, request time, application events, error and security logs, and identifiers stored in cookies, IndexedDB, local storage, or similar browser storage. This information supports authentication, session continuity, fraud and abuse prevention, rate limiting, diagnostics, and operation of the installable PWA. The service worker caches the offline experience; authenticated account pages, private invitations, payment pages, and API responses are not intended for offline caching.
Cloudflare provides hosting and network services and may derive approximate location and data-center information from a connection. SConnect may transform an IP address into a limited hash for security rate limiting or mask it before saving cashout-request context. Cloudflare and other infrastructure providers may separately retain network logs under their configured terms and retention settings.
6. How and why SConnect uses information
SConnect uses personal information to create and secure accounts; verify email and worker eligibility; operate tip and private pages; generate QR and invitation links; process tips, fees, payouts, receipts, refunds, and disputes; prevent fraud and misuse; enforce page access and blocks; communicate service information; provide support; maintain accounting and audit records; comply with law and provider requirements; and diagnose and improve the reliability and usability of the service.
Depending on the context and law that applies, SConnect processes information because it is needed to provide a requested feature or payment, administer and enforce an agreement, follow the person's direction or consent, protect accounts and the Service, pursue legitimate operational and fraud-prevention interests that are not overridden by applicable rights, comply with legal or financial-provider obligations, or establish and defend legal claims. Required account, eligibility, security, payment, payout, and dispute processing cannot always be provided without the relevant information. Optional profile fields and receipt requests remain optional.
Withdrawing an optional choice affects future processing where withdrawal is available; it does not invalidate processing already performed or require deletion of records that SConnect must retain for completed transactions, security, accounting, disputes, legal claims, or provider obligations. Accepting this policy acknowledges the disclosed practices but does not replace a separate affirmative choice where applicable law requires one.
SConnect does not use a worker's eligibility information or a guest's payment information to determine eligibility for credit, employment, housing, insurance, education, or another similarly significant decision.
7. Unlisted tip pages and invite-only private pages
The public tip jar is unlisted, not confidential. Anyone with its current direct link or QR code can open and reshare it. It displays the worker's chosen public name, biography, page styling, and tip choices; it does not display the worker's sign-in email or full Stripe identity information. Changing the worker's public display name changes the address and disables the former address.
The richer private page is available only through an invitation accepted by a verified tipper account. Depending on the worker's choices, it may display venue information, a location or map link, schedule, dates and times, service price-board entries, likes, dislikes, and external links. A worker may pause the page, revoke a relationship, or block an account or invited email. An invited person should not forward an invitation link, and no access control can prevent an authorized viewer from copying information they can see.
8. When information is disclosed
SConnect uses Google Firebase for authentication and database services; Cloudflare for hosting, content delivery, network security, logs, and approximate network location; Stripe for checkout, payment processing, fraud screening, 3DS authentication, identity and connected-account onboarding, balances, payouts, refunds, and disputes; and Resend for verification, tip-receipt, cashout-receipt, and dispute email. Resend may also retain records of invitation email sent before automated invitation delivery was disabled. Each provider processes information under its own terms and may act independently where financial, fraud-prevention, security, or legal duties apply.
Information is also disclosed as necessary to the worker or tipper involved in an accepted private-page relationship, authorized SConnect administrators, card networks, issuing banks, and payout institutions. SConnect may disclose information when reasonably necessary to comply with law or valid legal process, investigate fraud or security incidents, protect people or legal rights, enforce agreements, complete a business transfer, or follow the affected person's direction.
If a worker adds a map or external link, opening it sends the visitor to that third party. Using a phone's native share sheet may send content to the messaging or sharing application selected by the worker; SConnect does not receive the contents of a message composed in that separate application.
9. No sale, behavioral advertising, or third-party analytics
SConnect does not currently sell personal information or share it for cross-context behavioral advertising. SConnect does not currently display third-party ads or embed advertising pixels or third-party behavioral analytics SDKs. Operational hosting, security, authentication, email, and payment providers still process the information needed to perform their services.
Because SConnect does not currently use personal information for cross-site behavioral advertising or sell or share it for that purpose, browser Do Not Track and Global Privacy Control signals do not change the service's necessary authentication, security, payment, or network processing. Stripe-hosted pages and other providers may receive device or network identifiers and may recognize a browser or device used with their other services; their response to privacy signals is governed by their own policies.
10. Retention
SConnect keeps account, profile, preference, eligibility, relationship, and block information while it is needed to operate the account and enforce the user's choices. Agreement and eligibility attestations, transaction summaries, ledger entries, payouts, disputes, security records, and audit history may be kept longer when reasonably needed to document consent, maintain financial and tax records, prevent fraud, resolve disputes, enforce agreements, or comply with law and provider obligations.
Invitation records are set to expire after 30 days. Temporary checkout-intent records are set to expire with the associated checkout session. The cashout-request record containing the verified receipt email, masked destination, masked IP, and approximate network location is set to expire 90 days after the request began. Automatic deletion may occur after, rather than at the exact moment of, an expiration time.
Dispute evidence metadata may be scheduled for deletion when Stripe supplies an evidence-file expiration date. Stripe and other financial providers may retain identity, payment, payout, tax, fraud, and dispute information for longer periods under their own requirements. Transactional email content and delivery records may remain with Resend and in a recipient's mailbox under those parties' retention practices. SConnect may preserve information subject to a legal hold or active security, fraud, payment, or dispute investigation.
11. Choices, review, correction, and privacy requests
Workers can review and change many profile fields, visibility settings, payout choices, and preferences in their account. Tippers can review the private pages associated with their account. A person may request access to, correction of, deletion of, or a copy of personal information by emailing support@sconnect.cc. Invite recipients and guests who do not have accounts may use the same address.
A request should identify the account or interaction involved without sending a password, complete card or bank number, government identification, or other unnecessary sensitive information. SConnect may need to verify the requester's identity and authority before acting. A request may be limited or denied where retention is reasonably necessary for transaction completion, accounting, tax, fraud prevention, security, disputes, legal claims, or another exception permitted by applicable law. SConnect will explain a denial when required.
Applicable law may provide additional rights, including rights to know, correct, delete, or obtain personal information and to exercise those rights without unlawful discrimination. SConnect will evaluate and respond to verified requests according to the law that applies to the request.
12. Security
SConnect uses safeguards intended to reduce unauthorized access, including Firebase authentication, restricted database rules, server-side authorization, scoped administrator access, signed Stripe webhooks, hashed invitation tokens, masked payout and network details, limited browser caching, and HTTPS in production. Financial and identity providers receive sensitive card, bank, tax, and identity details directly where possible.
No online system is completely secure. Users should use a unique password, protect access to their email and device, sign out of shared devices, and contact SConnect promptly about suspected unauthorized activity.
13. Minors
SConnect accounts are intended for people who are at least 18 years old, and the tipping flow requires the guest to be at least 18 or otherwise legally authorized to make the payment. SConnect is not directed to children under 13 and does not knowingly collect their personal information. If you believe a child under 13 provided personal information, contact support@sconnect.cc so the information can be reviewed and handled as required by law.
14. Changes and contact
SConnect may update this policy as the Service, providers, or legal requirements change. The updated policy will be posted here with a revised effective date. For a material change to the categories collected, purposes, disclosures, retention, or available choices, SConnect will provide clear notice through the Service or by email before the change takes effect when required. SConnect will request renewed affirmative acceptance when the change requires consent or materially changes the agreement governing continued use. A prior acceptance is not blanket authorization for materially different future practices.
Privacy questions and verified privacy requests may be sent to support@sconnect.cc.
SConnect is operated by Ismael Hernandez Jr., a California sole proprietor operating SConnect in Kern County, California.