This Privacy Policy describes how DailyAdventureBox Inc. ("DAB," "we," "us," or "our") collects, uses, protects, and shares personal data when you access our mobile app, website (www.dailyadventurebox.com), Fund Adventure Portal, self-service lockers, or any related services (collectively, the "Services").
This policy is designed to comply with all applicable U.S. federal and state privacy laws, and is written to align with Apple App Store and Google Play Store requirements for data transparency, user consent, and third-party sharing disclosures (see Section 14).
We collect precise geolocation data only with your explicit permission to locate nearby DAB lockers and provide location-based services. You may revoke permission at any time through your device settings.
Payment processing is handled exclusively by Stripe, Inc., a PCI DSS Level 1 compliant processor. We do not store full credit card numbers, CVV codes, or bank account details. We receive payment metadata (last 4 digits, card type, expiration) and transaction records from Stripe.
Where you purchase Retail Goods, use a Storage-Only Locker, or rent Electronics (as those terms are defined in our General Terms and Conditions), we additionally collect: the item(s) purchased or rented and purchase/rental price; storage duration and locker location; and, for Electronics rentals, the make/model of the device rented and any pre-authorization hold amount tied to the device's replacement value. We do not access, copy, or retain any personal data, save files, or account credentials you may leave on a rented Electronics device — see Section 7 for how that data is handled.
We share limited data with the following service providers under strict confidentiality agreements and data processing addenda:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe, Inc. | Payment processing | Name, email, payment method, transaction amounts |
| Amazon Web Services, Inc. (AWS) | Cloud hosting, database storage, file storage, and transactional email for the rental App/account system | Account data, rental/order records, uploaded photos, email delivery metadata |
| Twilio Inc. | SMS delivery for one-time account verification codes | Phone number, verification code |
| Google LLC | Social login (Google Sign-In) | Auth tokens, name, email (as authorized by you) |
| Apple Inc. | Social login (Sign in with Apple), optional | Auth tokens, name, email (as authorized by you) |
| GitHub, Inc. | Website hosting (static) | No personal data stored |
We may also disclose personal data if required by law, court order, subpoena, or government investigation, or to protect the rights, property, or safety of DAB, our users, or the public.
DAB complies with all applicable state privacy laws nationwide, including those of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, Delaware, New Jersey, New Hampshire, Nebraska, Kentucky, Maryland, Minnesota, and any other state that has enacted, or hereafter enacts, a comprehensive consumer privacy law. As DAB expands to new states, this Section 4.c applies automatically to residents of those states without requiring a separate policy revision, though we may update this Policy from time to time to name specific new state laws for clarity. Rights generally include:
Contact support@dailyadventurebox.com to exercise any right. We respond within forty-five (45) days.
Our app may request access to camera, location, storage, notifications, and Bluetooth. These are used solely for locker access, rental tracking, and user experience. You may modify permissions in device settings at any time. Denying permissions may limit certain features but will not prevent use of core rental services.
6.1 Device Authentication (Face ID / Touch ID / Fingerprint). If you choose to use your device's built-in biometric authentication (such as Face ID, Touch ID, or Android fingerprint/face unlock) to sign in to the App, that biometric data is captured, processed, and stored entirely by your device's operating system. DAB never receives, transmits, stores, or has access to your raw biometric data (e.g., a facial scan or fingerprint image) — we receive only a confirmation from your device's OS that biometric authentication succeeded.
6.2 AR/VR Devices (e.g., Apple Vision Pro). If you rent an AR/VR Electronics device, that device may use eye-tracking, hand-tracking, or spatial-mapping data to operate. This data is processed on-device by the device manufacturer's own operating system (e.g., Apple visionOS) and is not collected, transmitted to, or stored by DAB. Unlike a device you purchase and keep for your own personal use, DAB owns each AR/VR device and repeatedly redeploys the same physical unit to different renters; the on-device-only handling described above depends on the mandatory factory-reset/wipe of the device between renters required by General Terms Section 43.3, which is the control that prevents one renter's on-device eye-tracking, hand-tracking, or spatial-mapping data from persisting to the next renter. DAB's role is otherwise limited to the rental transaction itself; your interaction data within the device's operating system during your own rental is governed by the device manufacturer's own privacy policy, which you should review before use.
6.3 DAB does not otherwise collect, use, or store biometric identifiers or biometric information as those terms are defined under applicable state biometric privacy laws (including the Illinois Biometric Information Privacy Act, 740 ILCS 14/1 et seq.).
Consistent with General Terms Section 43.3, any Electronics device you rent may be factory-reset, wiped, or restored to a default state by DAB before or after your rental, without notice, to protect the privacy of all renters. You are responsible for removing your own personal accounts, save data, and information from a rented device before returning it; DAB does not review, extract, or retain any personal data left on a returned device other than to the extent necessary to reset the device for the next renter.
We do not use advertising trackers or sell data to advertisers. Our Services do not currently respond to Do Not Track (DNT) browser signals, as no uniform standard exists.
We implement industry-standard measures including: TLS/SSL encryption in transit; AES-256 encryption at rest (AWS KMS-managed) for our database and file storage; secure API communications; PCI DSS compliance via Stripe. No system is fully immune to threats, but we continuously monitor and test our infrastructure.
In the event of a data breach affecting your personal information, DAB will: (a) notify affected users via email within seventy-two (72) hours of confirming the breach, or as otherwise required by applicable state or federal law; (b) notify applicable state authorities as required; and (c) provide information about the breach scope, data affected, and steps taken to mitigate harm.
Our Services are not directed to children under 13. We do not knowingly collect personal information from children under 13. If we learn of such collection, we will delete it promptly. Parents/guardians may contact support@dailyadventurebox.com to request removal.
Our Services are operated from and intended for use within the United States. Data will be transferred to and processed in the United States. By using our Services from outside the U.S., you consent to this transfer.
This Section 14 summarizes, in the format required by Apple's App Privacy details and Google Play's Data Safety section, the categories of data our app collects, restating what's already described above rather than describing anything new:
| Data Category | Collected? | Linked to You? | Used For |
|---|---|---|---|
| Contact Info (name, email, phone) | Yes | Yes | Account creation, service delivery |
| Location (precise, with permission) | Yes | Yes | Locker discovery, location-based service |
| Financial Info (payment metadata only, via Stripe) | Yes | Yes | Payment processing |
| Usage Data (app interactions, rental history) | Yes | Yes | Service delivery, analytics, fraud prevention |
| Identifiers (device ID, account ID) | Yes | Yes | Authentication, security |
| Photos/Video (equipment condition, security) | Yes | Yes | Damage documentation, security, incident investigation |
| Biometric Data | No (device-level only — see Section 6) | N/A | N/A — never transmitted to DAB |
| Advertising Data | No | N/A | We do not use advertising trackers or sell data (Section 3, Section 8) |
We do not use App Tracking Transparency ("ATT")-governed tracking (as defined by Apple) for cross-app or cross-site advertising purposes, and accordingly do not currently present an ATT permission prompt. If this changes, we will update this Policy and our App Store/Google Play listings before doing so, and will present any legally required consent prompt.
Verified data requests will be responded to within forty-five (45) days. If additional time is needed (up to 45 additional days), we will notify you of the extension and reason.
We may update this policy by revising the "Last Updated" date. Material changes require advance notice via app alert, email, or prominent website notice. Continued use after notice constitutes acceptance.