Avoylo Privacy & Location Policy
Version: 0.1 Last Updated: September 28, 2026 Effective Date: [TBD BEFORE PUBLICATION]
This Privacy & Location Policy defines how Avoylo handles precise Host Location information, coarse geographic information, recipient information, operational photographs and evidence, and other location-sensitive data used in the Avoylo network.
This Policy is an operational privacy policy. Avoylo's broader collection, use, retention, disclosure, and legal-rights practices are described in the Avoylo Privacy Policy.
This Policy should be read together with the Avoylo Operations Policy, Host Services Policy, Seller Services Policy, Shipping & Carrier Policy, Claims & Incident Policy, Host Storage & Safety Standards, Privacy Policy, Seller Services Agreement, Host Services Agreement, and Terms of Service.
1. Core Principle
A Host's exact storage address is private operational information, not public marketplace information.
Avoylo may use or disclose the exact Host Location only when reasonably necessary for an authorized operational, safety, legal, shipping, return, transfer, incident, fraud-prevention, or compliance purpose.
Ordinary Seller browsing, Host discovery, matching previews, and marketplace-style interfaces should use coarse geographic information rather than the Host's exact address.
2. Geographic Data Classes
Avoylo separates location information into practical classes.
2.1 Coarse Area
Examples:
- state or province;
- metropolitan area;
- city-level area;
- service zone;
- broad neighborhood or district where appropriate.
Coarse Area may be shown before a Seller has any operational need for an exact Host Location.
2.2 Precise Host Location
Examples:
- street address;
- apartment or unit number;
- building access details;
- gate instructions;
- exact map coordinates;
- pickup-zone instructions that reveal the property.
Precise Host Location receives stricter access controls.
2.3 Shipment Destination
The customer's delivery address is operational recipient data and is not Host-public data.
2.4 Operational Location Evidence
Examples include:
- carrier pickup records;
- delivery events;
- transfer handoff records;
- geolocation associated with a provider event;
- incident evidence;
- authorized location-verification evidence.
Operational evidence is not automatically exposed to every participant.
3. Seller Pre-Match View
Before a Placement is committed, the Seller should ordinarily see only the minimum geographic information necessary to evaluate the network opportunity.
The ordinary pre-match Seller view may include information such as:
- California;
- Los Angeles area;
- Irvine area;
- a service radius or zone;
- expected delivery coverage; or
- other non-precise area information.
The Seller should not receive a Host's street address merely to decide whether to create or price a Placement.
4. Host Opportunity View
A Host may see Seller and Placement information reasonably necessary to decide whether to accept an Opportunity.
The Host does not receive unrelated Seller private data merely because the Host is eligible for an Opportunity.
Information should be limited to what is materially useful for:
- capacity;
- parcel quantity;
- parcel characteristics;
- service area;
- accepted commercial terms;
- inbound expectations; and
- operational eligibility.
5. Exact Address After Matching
A committed Placement does not automatically make the Host's precise address broadly visible to every Seller user.
Where an exact Host address is required for inbound transportation, Avoylo may make the address available through the authorized inbound workflow or directly to the applicable carrier/provider.
Access should be limited to:
- authorized Seller users with a legitimate operational need;
- the selected carrier/provider;
- Avoylo operations or support personnel with an authorized need; and
- other parties required for the specific operational purpose.
6. No Public Host Address Directory
Avoylo must not operate a public directory of precise Host residential addresses.
Precise Host Locations must not be indexed or published as ordinary public marketplace listings.
A Host's exact address should not appear in:
- public Host profiles;
- public search results;
- public marketing pages;
- public sitemaps;
- unauthenticated APIs; or
- public metadata.
7. Seller Use Restriction
A Seller that receives a precise Host Location may use it only for the authorized Avoylo purpose.
The Seller must not use a Host address to:
- contact the Host off-platform without authorization;
- send unrelated inventory;
- send marketing material;
- visit the Host unexpectedly;
- publish the address;
- provide it to end customers;
- use it as a general return address;
- use it for surveillance;
- use it for unrelated data enrichment; or
- facilitate off-platform fulfillment.
8. Customer Access to Host Address
End customers do not ordinarily need a Host's exact address.
A Seller must not expose the Host Location to an end customer merely because the customer order is fulfilled from that Host.
Customer-facing shipment information should use the information required by the carrier and applicable law without unnecessarily exposing private Host Location data.
9. Return Addresses
A Host Location is not a general customer-return address.
Customer returns may be directed only to an Avoylo-authorized destination.
A Seller must not print, publish, or communicate a Host address as a standing return address unless Avoylo expressly authorizes that use.
10. Shipping Labels
A shipping label may reveal origin information where required by the carrier, provider, law, or supported service.
Where a carrier permits a privacy-preserving return/origin configuration, Avoylo may use it.
Avoylo does not promise that a precise Host Location can always be hidden from every carrier document or recipient where transportation rules require disclosure.
11. Inbound Labels
Seller-to-Host inbound shipping may require disclosure of the precise Host Location to the Seller or inbound carrier.
This disclosure is authorized only for the applicable inbound Shipment.
It does not grant the Seller a general right to reuse the address.
12. Host-to-Host Transfers
For an authorized transfer, Avoylo may disclose the necessary source and destination information to:
- the authorized Hosts;
- the carrier/provider;
- Avoylo operations; and
- other persons strictly necessary to complete the transfer.
Each Host must use the other Host's location information only for the authorized transfer.
13. Seller Removal
For an authorized Seller removal or return-to-Seller process, Avoylo may use or disclose the source Host Location to the carrier or provider as required.
The Seller receives only the information reasonably necessary to complete the approved workflow.
14. Carrier Pickup
Avoylo may provide the carrier with:
- precise pickup address;
- access instructions;
- pickup window;
- authorized contact information;
- pickup-zone information; and
- other necessary logistics data.
The carrier's handling of this information is also governed by the carrier's own privacy and service terms.
15. Building and Access Instructions
Gate codes, building instructions, lockbox details, intercom information, parking instructions, and similar access data are highly sensitive.
Avoylo should:
- collect only what is necessary;
- disclose only to authorized operational recipients;
- avoid placing such information in public or general Seller-facing interfaces;
- avoid unnecessary long-term retention where the information is no longer operationally required; and
- support update or revocation when access instructions change.
16. Host Location Verification
Avoylo may verify a Host Location through methods such as:
- address verification;
- photographs;
- video walkthrough;
- identity or document checks;
- map or address normalization;
- serviceability checks; or
- another reasonable method.
Verification evidence is private and should not become ordinary Seller-facing content.
17. No Absolute Secrecy Promise
Avoylo does not promise that a Host address will never be disclosed.
Precise location may be disclosed when reasonably necessary for:
- inbound shipment;
- pickup;
- transfer;
- return;
- removal;
- emergency response;
- incident investigation;
- legal process;
- fraud or security investigation;
- insurance or carrier claim;
- protection of rights or safety; or
- another legitimate operational or legal purpose.
The privacy rule is purpose-limited disclosure, not absolute secrecy.
18. Customer Data Minimization
A Host should receive only the customer information needed to complete the assigned outbound task.
Ordinary Host task data may include:
- recipient name where needed;
- shipping label;
- destination embedded in the label where required;
- order/task reference;
- carrier instructions; and
- other fulfillment-specific information.
The Host should not receive unrelated customer profile, payment, browsing, or account information.
19. Customer Contact
A Host must not independently contact an end customer unless Avoylo expressly instructs or enables the contact for the specific task.
The Host must not use customer data for:
- marketing;
- social media;
- personal communication;
- data enrichment;
- off-platform sales;
- identity lookup; or
- another unrelated purpose.
20. Customer Payment Data
Hosts do not need customer card numbers, bank credentials, PayPal credentials, or other payment credentials to perform ordinary Avoylo fulfillment.
Avoylo should not expose such information to Hosts.
21. Seller Data Minimization for Hosts
Hosts should receive only Seller information reasonably necessary to perform their role.
A Host does not need unrestricted access to:
- Seller bank data;
- Seller payment credentials;
- Seller internal analytics;
- Seller customer lists;
- unrelated Seller orders; or
- other unnecessary business records.
22. Host Data Minimization for Sellers
Sellers should not receive unrestricted access to:
- Host payout destination;
- Host tax documents;
- Host identity documents;
- full Host verification records;
- household information;
- unrelated Host activity;
- precise address before operational need; or
- security-system details.
23. Staging Photo Purpose
A staging photo exists to provide evidence that the Host staged the correct authorized Parcel in the required condition or pickup context.
A staging photo does not by itself prove carrier possession.
Staging evidence should be collected only to the extent necessary for:
- task verification;
- incident review;
- claims;
- fraud prevention;
- quality control; or
- another authorized operational purpose.
24. Incident Photo Purpose
Incident photo evidence is distinct from ordinary staging evidence.
Incident evidence may document:
- inbound damage;
- packaging condition;
- wrong Parcel;
- quantity issue;
- leakage;
- prohibited or suspicious item;
- pickup issue;
- missing inventory;
- storage damage;
- or another reported condition.
Avoylo should maintain a distinct private incident-evidence path rather than treating every photo as general public media.
25. Photo Access
Photo evidence should be access-controlled.
Access may be granted to:
- the submitting participant;
- another participant where the evidence is appropriately shareable and necessary;
- authorized Avoylo operations, support, claims, security, or legal personnel;
- carriers, insurers, or service providers where necessary for a claim or investigation; or
- lawful authorities where required.
Cross-tenant access is prohibited unless a valid workflow expressly authorizes it.
26. No Public Photo URLs
Operational photo evidence should not rely on permanently public object URLs.
Avoylo should use private storage, authenticated retrieval, signed time-limited access, or another appropriately restricted mechanism.
27. Photo Content Minimization
Users should avoid including unnecessary sensitive information in operational photos.
Where practical, a photo should focus on:
- the Parcel;
- relevant damage;
- relevant label area;
- pickup staging; or
- the specific incident condition.
Users should avoid intentionally capturing unrelated:
- family members;
- children;
- neighbors;
- personal documents;
- private living areas;
- computer screens;
- financial information; or
- other unnecessary personal information.
28. Metadata and EXIF
Avoylo may remove or ignore unnecessary image metadata, including precise device geolocation, where the metadata is not required for the operational purpose.
Avoylo may preserve specific metadata where reasonably necessary for fraud prevention, evidence integrity, safety, claims, or legal requirements.
29. Image Integrity
Avoylo may record evidence metadata such as:
- cryptographic hash;
- MIME type;
- object size;
- upload time;
- submitting actor;
- linked Incident or task; and
- replacement/supersession relationship.
This helps preserve evidence integrity without making the object public.
30. Replacement Evidence
Where a user submits a corrected or replacement photo, Avoylo should preserve the relationship between the original and replacement rather than silently pretending the original never existed.
This is particularly important for Incident and Claims evidence.
31. Security Camera Footage
CCTV is not universally required for Hosts.
Where a Host voluntarily uses CCTV, Avoylo may request relevant footage for a serious Incident where appropriate.
Avoylo does not receive unrestricted continuous access to a Host's home cameras merely because the Host participates in the network.
32. Camera Scope
Hosts are responsible for using cameras lawfully.
Cameras used for Avoylo-related security should be positioned to protect legitimate storage or pickup areas and should avoid unnecessary intrusion into private spaces.
33. Precise Geolocation
Avoylo should not require continuous device geolocation from a Host merely to participate in ordinary storage.
Precise device location may be requested for a specific feature where necessary, such as:
- authorized location verification;
- an optional pickup feature;
- fraud prevention;
- or another clearly disclosed function.
Where used, the scope should be proportionate to the feature.
34. No Continuous Seller Tracking of Hosts
Sellers must not receive a live map showing a Host's personal movement.
Host Location is a storage location, not permission for continuous personal tracking.
35. Carrier Tracking Is Shipment Tracking
Carrier tracking refers to the Parcel or Shipment.
It should not be presented as continuous tracking of the Host as a person.
36. Staff Access
Avoylo personnel should access precise Host Location and customer information only when their role requires it.
Avoylo should use reasonable internal controls such as:
- role-based access;
- audit logging;
- least privilege;
- step-up authentication for high-risk actions;
- incident review; and
- periodic access review.
37. Support Access
Support personnel may access precise location or operational evidence where necessary to resolve:
- failed inbound;
- pickup issue;
- transfer;
- return;
- removal;
- missing inventory;
- safety Incident;
- security issue;
- claim; or
- another legitimate support request.
Support access does not make the data public.
38. Admin Audit
Material access to or modification of precise Host Location data should be auditable where technically practical.
Avoylo should avoid logging the full address into broad application logs where an identifier or redacted representation is sufficient.
39. Address Changes
A Host address change is a high-impact operational event.
Avoylo may require:
- recent authentication;
- identity re-verification;
- Host Location review;
- confirmation of existing inventory;
- temporary pause of new matching; and
- a transactionally safe update.
A changed browser field alone should not silently relocate inventory.
40. Data Accuracy
Hosts are responsible for keeping Host Location information materially accurate.
Sellers are responsible for keeping recipient and shipment information materially accurate.
Avoylo may correct or normalize obvious address formatting where doing so does not change the intended physical location.
41. Data Retention
Avoylo retains precise location and evidence information for as long as reasonably necessary for purposes such as:
- active operations;
- custody history;
- billing;
- payouts;
- fraud prevention;
- security;
- claims;
- tax or accounting;
- legal compliance;
- dispute resolution; and
- enforcement of agreements.
Avoylo may retain historical transaction-linked location records after an account closes where deletion would undermine required custody, financial, claims, or legal records.
42. Deletion Requests
A privacy deletion request does not necessarily require deletion of information Avoylo must or reasonably needs to retain for:
- open inventory custody;
- unresolved Shipment;
- billing;
- payout;
- tax;
- fraud prevention;
- claims;
- legal obligation;
- dispute; or
- security.
Where deletion is appropriate, Avoylo should remove or de-identify the information according to the broader Privacy Policy.
43. Location Data After Host Exit
After a Host fully exits and no inventory remains, Avoylo should stop using the old Host Location for new matching or new inbound routing.
Historical custody, billing, security, and Claims records may retain the relevant location or location reference where necessary.
44. Seller Account Exit
Seller closure does not create a right to retain or reuse Host addresses for future off-platform shipping.
Any stored Host address obtained through Avoylo remains subject to the purpose restrictions in this Policy.
45. Security Incident
If Avoylo reasonably believes precise Host Location, recipient data, or sensitive operational evidence has been accessed or disclosed improperly, Avoylo may:
- restrict access;
- invalidate credentials;
- investigate logs;
- notify affected users where appropriate;
- preserve evidence;
- contact providers or authorities; and
- take other proportionate security action.
Any legally required breach notification is handled under applicable law and the Privacy Policy.
46. Doxxing and Harassment
Users must not publish, threaten to publish, or use nonpublic Host, Seller, customer, or employee location information to harass, intimidate, retaliate, stalk, or endanger another person.
Avoylo may suspend access and preserve evidence of suspected abuse.
47. Off-Platform Contact
A Seller or Host must not use private operational information to create an unauthorized off-platform relationship that bypasses Avoylo's custody, safety, billing, privacy, or fulfillment controls.
48. Emergency Disclosure
Avoylo may disclose location information where reasonably necessary to address an emergency involving risk of death, serious physical harm, fire, hazardous material, missing property, or another urgent safety issue, subject to applicable law.
49. Law Enforcement and Legal Requests
Avoylo may disclose location or operational information when required by lawful process or where otherwise permitted by applicable law.
Avoylo may review requests for legal sufficiency and may narrow or challenge requests where appropriate.
50. Insurance and Claims Disclosure
Where a claim involves a carrier, insurer, protection provider, or other claims administrator, Avoylo may share the minimum relevant location and evidence information needed to investigate or process the claim.
Providing information to a claims participant does not make the information public.
51. Service Providers
Avoylo may use service providers to process location-sensitive information for functions such as:
- cloud hosting;
- database services;
- shipping;
- identity verification;
- security;
- customer support;
- storage of private evidence;
- analytics restricted to authorized purposes; and
- legal/compliance support.
Service providers receive information subject to their role and applicable contractual/privacy restrictions.
52. No Advertising Use of Precise Host Address
Avoylo will not use a Host's precise residential address as advertising targeting data merely because the Host participates in the network.
Coarse region information may be used for service availability, operational planning, network expansion, and aggregated analytics.
53. Aggregated Location Analytics
Avoylo may use aggregated or de-identified location information to understand:
- network coverage;
- capacity;
- service areas;
- demand;
- routing efficiency;
- incident patterns; and
- operational performance.
Avoylo should avoid presenting aggregated analytics in a way that reasonably identifies a specific private Host Location.
54. Privacy by Role
Avoylo applies different visibility rules to different roles.
Seller
Sees the information required to place, manage, bill, ship, and resolve the Seller's own inventory.
Host
Sees the information required to receive, store, fulfill, and report issues concerning inventory assigned to that Host.
Admin / Authorized Staff
May access broader information where necessary for legitimate operational or legal functions.
Customer
Receives ordinary Seller/carrier fulfillment information and does not receive Host operational records merely because a Host fulfilled the order.
55. No Cross-Tenant Browsing
A Seller must not access another Seller's private records.
A Host must not access another Host's private records merely because both participate in Avoylo.
Private evidence, precise addresses, payout records, and customer data must remain tenant- and role-scoped.
56. User Security Responsibilities
Users must protect account credentials and devices that can access private location or customer data.
Users should promptly report suspected compromise.
Avoylo may revoke sessions, require reauthentication, or restrict sensitive actions where compromise is suspected.
57. Policy Enforcement
Violation of this Policy may result in:
- access restriction;
- Opportunity suspension;
- Seller or Host account suspension;
- removal from the network;
- incident investigation;
- legal action; or
- another remedy permitted by the applicable agreement.
Enforcement does not automatically determine financial liability.
58. Relationship to Privacy Policy
The Avoylo Privacy Policy governs broader privacy matters including:
- categories of personal information;
- purposes of processing;
- disclosures;
- retention;
- cookies;
- security;
- international transfers;
- user rights; and
- privacy contact procedures.
This Privacy & Location Policy provides additional operational restrictions for sensitive location and fulfillment information.
59. Policy Versioning
Avoylo may update this Policy prospectively.
A later version does not silently rewrite historical custody, access, or Incident records.
Where required by law or contract, Avoylo will provide appropriate notice of material changes.
60. Contact
Privacy Contact: [TBD] Security Contact: [TBD] Legal Contact: [TBD] Company Legal Name: [TBD] Business Address: [TBD]