Legal
Longboard Privacy Policy
Last updated: August 11, 2026
1. Introduction and Scope
Longboard is a field marketing and Service Provider management platform that connects Brands with Service Providers for conducting product sampling events. Longboard is operated by Longboard LLC, a Wisconsin limited liability company with a principal place of business at 5789 State Highway 42, Sturgeon Bay, WI 54235 ("Longboard," "we," "us," or "our").
This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with:
- the Longboard web application and administrative console;
- the Longboard mobile applications and Service Provider-facing tools;
- Longboard Payments, our payment enablement functionality built on Stripe Connect;
- our marketing website at longboard.surf; and
- our sales, support, and other business communications
(collectively, the "Services").
Who this Policy covers. This Policy addresses: (a) the Brands that subscribe to Longboard and their personnel; (b) the Service Providers and field representatives who use the platform; (c) event participants and consumers whose information is captured at a Brand's sampling events (which we handle as a processor — see Section 2); and (d) visitors to our marketing website and prospective business customers. There is no separate Service Provider notice.
This Policy does not apply to: (a) the privacy practices of the Brands, agencies, and other organizations that use Longboard as their vendor, each of which maintains its own privacy policy; or (b) third-party sites and services that we link to but do not control.
1.1 United States only
Longboard is offered only in the United States. The Services are not directed to, and we do not knowingly provide the Services to, individuals or organizations located in the European Economic Area, the United Kingdom, Switzerland, or other jurisdictions outside the United States.
Our cloud infrastructure — application servers, database, file storage, and backups — is hosted in Microsoft Azure data centers in the United States (primary region U.S. Central; disaster-recovery region U.S. East). We do not replicate personal information to Azure regions outside the United States. Our subprocessors process personal information under their own terms; see the subprocessor list referenced in Section 7.
If you access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with local law.
2. Our Two Roles: Controller and Processor
Longboard handles personal information in two distinct capacities. Which one applies determines who you should contact about your data.
We act as a "controller" / "business" — meaning we determine the purposes and means of processing — with respect to:
- account, billing, and contact information for the Brands that subscribe to Longboard (each, a "Brand") and their authorized users;
- the account and authentication information for Service Providers, field representatives, and other independent workers ("Service Providers") that we collect directly to establish and administer their Longboard account, authenticate them, and secure the platform — that is, identity, contact, and credential information;
- information collected through our marketing website, events, and sales activity; and
- security, audit, and operational telemetry generated by the Services.
We act as a "processor"— meaning we process personal information on a Brand's behalf and under its instructions — with respect to:
- content, records, and personal information that a Brand or its users upload to, or generate within, the Services, including event and activation records, sampling results, Service Provider work product (check-in/out records, activation and sampling reports, survey responses, expenses, and event photos or video), consumer contacts collected at events, program and campaign data, Service Provider qualification and credential records supplied by or for a Brand, and Brand-directed communications ("Brand Data").
Where we act as a processor, the Brand is the controller. If you want to exercise privacy rights over Brand Data, direct your request to the Brand. If you contact us instead, we will refer you to the relevant Brand or forward your request, as required by applicable law and our contract with that Brand. Our processing of Brand Data is governed by our Data Processing Addendum, available at https://longboard.surf/legal/dpa.
3. Information We Collect
3.1 Information you provide directly
Brand and prospective Brand users. Name, business email, phone, job title, employer, billing contact and address, and the content of your communications with us.
Service Providers.
- Identity and contact: legal name, preferred name, email address, mobile number, mailing address, date of birth, and profile photo.
- Profile: availability, market and travel radius, and any experience, skills, or other profile details you choose to provide.
- Agreements: electronic signature records for contractor agreements, waivers, program terms, and policy acknowledgments, together with the associated signer metadata (timestamp, IP address, and document version).
- Work product: event check-in and check-out records, activation reports, sampling counts, survey responses, expense entries, receipts, and photos or video you submit from events. We process this work product as a processor on the Brand's behalf (it is Brand Data — see Section 2).
- Tax identification information, on a transient pass-through basis only. See Section 3.6.
- Bank account (ACH) information, on a transient pass-through basis only, where a Brand pays you through its own connected accounting system. See Section 3.7.
We do not verify, assess, or maintain Service Provider eligibility or credentials. Longboard does not collect or verify work authorization, alcohol server or seller permits, food handler certifications, driver's license status, or similar qualifications. Determining whether an individual is qualified and legally permitted to perform a given program is the sole responsibility of the Brand engaging them. Where a Brand chooses to record such information in the platform, it is Brand Data and the Brand is the controller.
Event participants and consumers. Where a Brand's program includes consumer data capture, Longboard may process information collected at sampling events or activations, such as name, email address, ZIP code, age-gate confirmation, and survey or preference responses. This is Brand Data and we process it as a processor.
3.2 Information collected automatically
- Device and usage data: IP address, device identifiers, browser and OS type, app version, pages and screens viewed, features used, referring URLs, and timestamps.
- Log and security data: authentication events (including account log-in credentials and one-time verification codes), access logs, error and diagnostic data, and audit trails.
- Cookies and similar technologies: see Section 9.
3.3 Location information
Longboard uses location information to verify that field activity occurred where and when it was reported.
- Precise geolocation is collected only at two moments: when an Service Provider checks in to a shift, and when an Service Provider checks out of a shift. It is used to confirm presence at the assigned venue, and is stored together with the associated check-in/check-out record. Precise location collection requires your device permission (our apps request only foreground, "while in use," permission and capture a single reading at each check-in or check-out). We retain the precise coordinates for no longer than fourteen (14) months; after that, an automated process deletes the precise latitude, longitude, and accuracy from the record while retaining the non-precise compliance facts (the timestamp and the distance from the assigned venue).
- If you decline or revoke location permission, you can still check in and check out by recording a short reason; your check-in will simply be flagged as lacking location verification.
- We do not track Service Provider location during a shift, between shifts, or at any other time. We do not collect background location. We do not use location data for advertising, and we do not build location profiles.
Precise geolocation is treated as sensitive personal information under California and several other state laws. See Section 12.2.
3.4 Information from other sources
- Stripe. Where a Brand uses Longboard Payments (Stripe Connect), Stripe provides us with onboarding and verification status, transaction and payout metadata, and account identifiers. On the Stripe Connect path we do not receive full bank account, debit card, or card numbers. (For the separate Brand-managed accounting-system payout path, see Sections 3.7 and 6.)
- Brands. A Brand may provide us with information about individuals it wishes to invite to the platform.
- Public and commercial sources, for business contact enrichment and marketing to prospective Brands.
3.5 What we do not do
For clarity, Longboard does not:
- conduct or obtain background checks, criminal history checks, motor vehicle record checks, credit checks, or consumer reports of any kind. We are not a consumer reporting agency and we do not procure consumer reports. Any identity verification performed by Stripe as part of its own onboarding obligations is performed by Stripe as an independent controller under its own terms;
- collect, capture, store, or use biometric identifiers or biometric information. We do not perform facial recognition, face matching, face detection, faceprinting, voiceprinting, or automated tagging of individuals in photos or video. Event photos are stored and displayed as submitted;
- request or process health information, immigration documents, or government-issued identification images;
- track Service Provider location outside of shift check-in and check-out; or
- sell or share Service Provider or Brand Data for advertising.
3.6 Tax identification information — transient handling
Some Brands use an accounting or ERP integration to pay Service Providers. Where such an integration is configured, a Service Provider may enter taxpayer identification information (Form W-9 data, including a Social Security Number or EIN) into Longboard so that it can be delivered to the Brand's connected system.
We do not retain the taxpayer identification number. Specifically:
- the taxpayer identification number is held only, transiently, in a dedicated secrets vault (Azure Key Vault) — it is never written to our application database, and therefore is never present in a database backup;
- it is transmitted to the Brand's connected accounting system and removed from active systems upon confirmation of successful delivery;
- if delivery is not confirmed, an automated background process (running at least hourly) removes it no later than seven (7) days after entry; and
- Longboard does not use the taxpayer identification number for any purpose other than delivering it to the Brand's connected system.
What we retain — and what we do not. Once the taxpayer identification number is delivered or purged, we null the number-derived tax metadata: we do not retain the last four digits, the type of tax ID, your tax classification, or your business name. The only durable record we keep is a record that your W-9 certification occurred — your name, the date, and the IP address and device used — held in our audit log. This is a record that the certification took place; it is not the taxpayer identification number and is not a tax record. (This is a deliberate data-minimization choice; contrast Section 3.7, where the bank-account *last four digits* are retained to let you and the Brand recognize the account on file.)
Permanent destruction. When the taxpayer identification number is removed, we do not merely soft-delete it: we issue a hard purge from the secrets vault's recovery store and confirm by read-back that no recoverable copy remains, so the raw number is destroyed at that time.
Longboard does not issue, file, or store tax forms. Where Longboard Payments (Stripe) is used, taxpayer information is collected directly by Stripe and never passes through Longboard.
3.7 Bank account information — transient handling (Brand-managed payouts)
Where a Brand pays a Service Provider through the Brand's own connected accounting/ERP system (see Section 6, "Brand-managed payouts"), the Service Provider may enter full bank (ACH) account and routing numbers into Longboard so that they can be delivered to the Brand's connected system for payment.
We handle this information on the same transient basis as taxpayer identification information (Section 3.6): the full account and routing numbers are held only in our secrets vault, delivered to the Brand's connected system, and removed after delivery or, if delivery is not confirmed, by an automated background process no later than seven (7) days after entry. As with the taxpayer identifier, removal is a verified hard purge from the vault (same infrastructure precondition noted in Section 3.6). Our application database retains only the last four digits of the account so you and the Brand can recognize the account on file.
4. How We Use Personal Information
| Purpose | Examples |
|---|---|
| Provide the Services | Create and authenticate accounts; staff and schedule programs; record check-ins; process activation reports; deliver notifications |
| Enable payments | Facilitate Brand-to-Service Provider payments through Stripe Connect; deliver taxpayer and bank information to a Brand's connected accounting system |
| Billing and administration | Invoice Brands; calculate subscription, usage, and platform fees; collect payment; manage subscriptions |
| Support and communications | Respond to inquiries; send service, security, and transactional messages |
| Analytics and product improvement | Understand feature usage; measure performance; debug; develop new functionality |
| Insights and reporting | Generate program performance metrics, execution and compliance reporting, and conversion analysis for Brands |
| Safety, security, and fraud prevention | Detect and investigate unauthorized access, falsified check-ins, and abuse; maintain audit logs |
| Legal and compliance | Meet recordkeeping obligations; respond to lawful requests; establish, exercise, or defend legal claims |
| Marketing | Promote Longboard to prospective Brands; measure our own advertising |
We do not use taxpayer identification information, bank account information, payment data, or precise location data for marketing, analytics, or product development.
5. Artificial Intelligence
Longboard does not currently use artificial intelligence to process personal information, and we do not use AI to make automated decisions about you. If we introduce AI features, we will update this Policy and provide advance notice as described in Section 13 before those features process your personal information, and we will describe at that time the model provider, the safeguards applied to sensitive information, and our data-training position.
6. Payments
Longboard is never the payer of Service Providers and never takes custody of Service Provider funds. Longboard is not a money transmitter and does not require a money-transmitter license.
Service Providers are paid by the Brand that engages them, in one of three ways:
1. Directly by the Brand, outside of Longboard. Longboard has no involvement in, and receives no data about, these payments beyond what the Brand chooses to record in the platform.
2. Through the Brand's connected accounting/ERP system ("brand-managed payouts"). Where enabled, a Service Provider may enter full bank (ACH) account and routing numbers into Longboard so that Longboard can deliver them to the Brand's connected accounting system, which the Brand then uses to pay the Service Provider. In this model, Longboard is a transmission channel only: it does not move or hold funds. Longboard handles the bank account and routing numbers transiently and does not permanently retain them — see Section 3.7.
3. Through Stripe Connect, where the Brand is the payer, and Stripe is the payment processor. Stripe collects and stores bank account, debit card, and identity verification information directly from the recipient. On the Stripe Connect path, Longboard does not receive or store full financial account numbers. Stripe processes this information as an independent controller under its own privacy policy at https://stripe.com/privacy.
In the Stripe Connect model, payments are processed as direct charges on the Service Provider's connected Stripe account, with Longboard collecting a platform fee (an application fee). The Service Provider's funds settle into the Service Provider's own Stripe balance and never transit a Longboard-controlled balance. Longboard receives transaction and payout metadata — amounts, status, timestamps, and account identifiers — in order to display payment status and reconcile platform fees. This is a fee arrangement between Longboard and the Brand and does not make Longboard the payer of any Service Provider.
Longboard does not issue tax forms. Form 1099-K, Form 1099-NEC, and any other information returns are issued and filed by Stripe or by the Brand, as applicable. Longboard does not maintain tax records for Service Providers. See Section 3.6 for how taxpayer identification information is handled.
We retain Brand billing records for at least seven (7) years as required by applicable tax and accounting rules.
7. How We Disclose Personal Information
We do not sell personal information for money, and we do not use advertising or cross-context behavioral advertising technologies (see the Advertising paragraph below). We disclose personal information as follows:
To Brands. An Service Provider's profile, availability, activity records, and submitted work product are visible to the Brands whose programs they apply to or work on.
Among Brands — no. Longboard is multi-Brand, but each Brand's data is isolated by database-enforced row-level security and is not disclosed to other Brands.
To service providers and subprocessors. We use vendors who process personal information on our behalf under written contracts limiting their use of it:
| Category | Provider | Purpose |
|---|---|---|
| Cloud hosting and infrastructure | Microsoft Azure | Application hosting, database, storage, backup |
| Payments | Stripe | Payment processing, recipient onboarding, payouts |
| Transactional email | Azure Communication Services | Notifications, verification codes |
| Push notifications | Azure Notification Hubs | Mobile app notifications |
| Mobile app build & delivery | Expo / EAS | Native mobile app build and distribution, and on-device push-token issuance |
Brand-directed systems (not Longboard subprocessors). At a Brand's direction, Longboard transmits certain data to systems the Brand controls: the Brand's connected accounting/ERP system (for example, Acumatica), which is the destination for the transient taxpayer and bank information described in Sections 3.6 and 3.7; and the Brand's Shopify storefront, where a Brand chooses to publish approved event and location information. These are egress to the Brand's own systems, not vendors Longboard selects to process data on its behalf.
A current subprocessor list is maintained at https://longboard.surf/legal/subprocessors.
For legal reasons. To comply with law, subpoenas, or lawful government requests; to enforce our agreements; and to protect the rights, safety, and property of Longboard, our users, or the public.
In a business transaction. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor policy providing comparable protection.
With your direction or consent.
Advertising. We do not use advertising or cross-context behavioral advertising technologies on our marketing website or elsewhere in the Services, and we do not sell or share personal information as those terms are defined under California and other state privacy laws.
8. Data Retention
We retain personal information for as long as needed for the purposes described in this Policy, and then delete or de-identify it. Some periods below are stated as maximums (a cap after which we delete or de-identify); the rest are minimums (floors) that we keep at least that long and may keep longer where needed for the purposes in this Policy or as required by law.
| Data | Retention |
|---|---|
| Brand account and billing records | At least 7 years after the subscription term (tax/accounting) |
| Brand Data | Per the Brand's instructions and our DPA. When a Brand relationship ends, we open a 30-day wind-down window during which the Brand may retrieve its data; after that window the Brand's data is deleted across our systems — database records, stored files and their underlying storage objects, and any transient secrets — and we generate a durable proof-of-deletion record. |
| Service Provider profile data | For the life of the account; in any case, a dormant Service Provider's profile contact and identity fields are de-identified after 24 months of account inactivity (a non-identifying key is retained for financial/ledger integrity) |
| Taxpayer identification number | Removed on confirmed delivery, or within 7 days maximum — see Section 3.6 |
| Bank account (ACH) numbers | Removed on confirmed delivery, or within 7 days maximum — see Section 3.7 |
| E-signature records | Up to 7 years from execution, after which they are deleted |
| Precise location check-in/out coordinates | Maximum 14 months, after which the precise coordinates are automatically deleted (the non-precise timestamp and distance-from-venue are retained) — see Section 3.3 |
| Event photos and work product | Per Brand instruction; absent instruction, event/report photos are deleted after 24 months (the non-image report data is retained) |
| Security and audit logs | Up to 24 months, after which they are deleted |
| Marketing contact data | Until opt-out |
Backups and recovery stores. Some copies of personal information persist in encrypted, access-controlled backups and deletion-recovery stores after the data is removed from active systems — for example, database point-in-time recovery, periodic logical backups, and blob soft-delete. These copies age out on the applicable backup cycle rather than at the moment of active-system deletion. Raw financial identifiers are the exception: because we never write Social Security/taxpayer numbers or bank account and routing numbers to our database or file storage (they live only as secrets-vault entries) and we hard-purge them from the vault, they are not present in any database backup, file backup, or vault recovery store.
We may retain information longer where required by law or to establish, exercise, or defend legal claims.
9. Cookies and Tracking Technologies
We use only strictly necessary cookies and similar technologies — for authentication, session management, security, and load balancing. These are required for the Services to function and cannot be disabled.
Our marketing website does not use analytics or advertising cookies and embeds no third-party advertising or analytics tags. Because we use only strictly-necessary cookies, we do not display a cookie consent banner; you can still block or delete cookies through your browser settings.
10. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including:
- encryption of data in transit (TLS) and at rest;
- role-based, least-privilege access controls and Brand isolation enforced at the database layer by row-level security, in a fail-closed configuration — our production application refuses to start unless database-enforced Brand isolation is active;
- managed-identity authentication for our core cloud services (database, secrets vault, and blob storage), with third-party integration credentials held in a managed secrets vault;
- multi-factor authentication required for administrative and other privileged accounts — enrollment is enforced at sign-in and cannot be bypassed — with step-up re-authentication required again before sensitive or destructive operations;
- centralized log collection and append-only audit trails;
- regular encrypted backups with restore verification;
- vulnerability management and automated dependency scanning in our build pipeline; and
- contractual security obligations on the subprocessors we engage.
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for safeguarding your account credentials.
11. Children
The Services are not directed to children. Service Providers must be at least 18 years old, and Brands are responsible for imposing any higher age requirement their programs require, including where alcohol is involved. We do not knowingly collect personal information from anyone under 18 through the Services, and if we learn we have collected information from someone under 18 in violation of this Policy, we will delete it promptly. Consumer data captured at Brand events is subject to the Brand's own age-gating requirements and applicable beverage regulations.
12. Your Privacy Rights
12.1 Rights available to everyone
Regardless of where you live, you may:
- request access to the personal information we hold about you as a controller, and obtain a copy in a portable, machine-readable format;
- request correction of inaccurate information;
- request deletion of the personal information we hold about you as a controller, subject to the narrow retention carve-out described below and to our role as a processor for Brand Data (see below);
- opt out of marketing emails via the unsubscribe link;
- close your account, or ask us to delete or de-identify it — closing disables sign-in, while a verified deletion request permanently removes or de-identifies your personal information as described below; and
- contact us with any privacy question.
How these requests are handled. For most Service Provider work product and event data, Longboard acts as a processor on a Brand's behalf; direct those requests to the relevant Brand (Section 2). For information for which we are the controller, we fulfill access and portability requests by assembling the personal information we hold about you into a portable, machine-readable file, and we act on correction and deletion requests within the period required by applicable law. When we honor a verified deletion request for information we control, we permanently delete or de-identify it and keep only (i) your signed independent-contractor agreement and its signature metadata (a contractual and legal-claims basis) and (ii) our tamper-evident security and audit log; we do not retain your taxpayer identifier metadata as a basis for a deletion carve-out. Because much Service Provider data is Brand Data for which we act only as a processor, deletion of that Brand Data must be directed to the relevant Brand.
Self-service. Signed-in users can download a copy of the data we hold about them as a controller directly from their account at any time.
Submit requests to privacy@longboard.surf. We will verify your identity before acting — for emailed requests, typically by confirming control of your account email; a self-service download is authenticated by your existing sign-in. You may use an authorized agent where permitted by law.
We will not discriminate against you for exercising these rights.
12.2 United States state privacy rights
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island, or another state with a comprehensive privacy law, you may have the rights to know/access, delete, correct, obtain a portable copy, opt out of targeted advertising or sale, opt out of profiling with legal or similarly significant effects, and appeal a denial. We honor these rights as described in Section 12.1. Portable copies are provided in a structured, machine-readable format.
California specifics.
- Categories collected in the past 12 months, with reference to Cal. Civ. Code § 1798.140: identifiers; customer records information; commercial information; internet/network activity; geolocation data; professional or employment-related information; audio/visual information (event photos); inferences; and sensitive personal information, consisting of Social Security or taxpayer identification numbers and bank account numbers (both handled transiently — see Sections 3.6 and 3.7), precise geolocation, and account log-in credentials.
- Sensitive personal information. We use sensitive personal information only for the purposes permitted under § 7027(m) of the CCPA regulations — providing the Services, security, fraud prevention, and legal compliance. We do not use or disclose it to infer characteristics about you.
- Sale/Sharing. We do not sell or share personal information for cross-context behavioral advertising and therefore do not provide a "Do Not Sell or Share My Personal Information" link. We do not knowingly sell or share the personal information of consumers under 16.
- Service Providers and applicants. California law extends full consumer rights to independent contractors and job applicants. This Policy serves as our Notice at Collection for California Service Providers and applicants.
- Shine the Light. California residents may request information about disclosures to third parties for their direct marketing purposes by writing to privacy@longboard.surf.
Appeals. If we deny your request, you may appeal by replying to our decision or writing to privacy@longboard.surf with "Privacy Appeal" in the subject line. We will respond within the period required by your state's law.
13. Changes to This Policy
We may update this Policy from time to time. We will update the "Last Updated" date and, for material changes, provide notice through the Services or by email at least 30 days before the change takes effect. Continued use after the effective date constitutes acceptance.
Material changes include the introduction of any new use of personal information for advertising, the introduction of AI features that process personal information, any new category of sensitive information collected, or any extension of retention.
14. Contact Us
Longboard LLC
5789 State Highway 42
Sturgeon Bay, WI 54235
Privacy inquiries: privacy@longboard.surf
Privacy contact: Nic Trapani, Privacy Officer — privacy@longboard.surf
Security disclosures: security@longboard.surf