01
Scope and roles
This Privacy Policy applies when HotSwop, Inc. processes personal information through Market Monolith websites, applications, workspaces, communications, customer programs, field operations, and the Operator Network. It does not govern information independently processed by a customer, storefront merchant, operator business, Stripe, an issuing bank, or another third party under its own policy.
In some enterprise arrangements, HotSwop processes information on a customer’s instructions. The customer may then be the business or controller responsible for the use, while HotSwop acts as a service provider or processor. Contact the customer for requests about data it controls; we will assist as required by our agreement and law.
02
Information we collect
We also collect any information you choose to provide. Please do not submit sensitive personal information that the Platform does not request.
03
Operator and field data
For applicants and operators, we may process legal and preferred names, contact details, business type, tax and payout information, qualifications, capabilities, training and readiness, work history, availability, preferred markets, licenses, insurance, identity-verification results, and information required by customers or law.
During field work, the Platform may process precise or approximate device location, route and stop progress, timestamps, task state, customer or supervisor communications, proof photographs or video, notes, form answers, QR or engagement records, file metadata, device signals, safety reports, quality review, corrections, and accepted earnings. Location access is used according to device permissions and the active feature; an opportunity will explain when location is necessary.
Field-proof privacy. Operators should capture only the evidence required for the assignment, avoid children and unnecessary bystanders, respect private property and recording-consent law, and use available redaction or escalation tools when sensitive information is incidentally captured.
04
Payments, earnings, and cards
We process purchase amounts, credits, invoices, billing contacts, transaction references, refund and dispute status, operator earnings, payout status, tax records, and fraud signals. Payment providers such as Stripe generally collect payment credentials directly; we receive identifiers and transaction status needed to administer the Platform.
A future operator-card program may require business, identity, date of birth, address, tax, verification, cardholder, merchant, authorization, receipt, refund, dispute, device, and transaction data. Stripe and the issuing bank would process that information under their own notices and required agreements. The program is not activated by accepting this public policy.
05
Sources of information
We receive information directly from you; from your organization, teammates, customers, operators, and authorized supervisors; automatically from devices and Platform use; from connected commerce, mapping, communication, payment, identity, and collaboration providers; from public websites and government or commercially available sources; and from service providers that help prevent fraud, verify identity, or support operations.
Customers must have authority to provide information about their personnel, buyers, locations, campaigns, or products. Operators must have authority to submit proof and work records. We may combine information from different sources when needed for the purposes below.
06
How we use information
- Provide accounts, authentication, workspaces, market intelligence, storefront tools, maps, planning, assignments, communications, collaboration, proof review, support, credits, payments, earnings, and related services.
- Match eligible operators with defined opportunities; assess readiness, capacity, territory, risk, timing, and quality; administer training, disputes, corrections, and records.
- Process transactions, prevent duplicate or unauthorized activity, verify identity, administer taxes and reporting, and meet payment, banking, provider, and network obligations.
- Secure, monitor, debug, maintain, and improve the Platform; understand feature performance; create deidentified or aggregated insights; and develop new capabilities.
- Communicate about accounts, opportunities, work, transactions, policy changes, support, security, and—with any consent required—marketing.
- Enforce agreements, protect rights and safety, prevent prohibited activity, comply with law, respond to lawful requests, and establish or defend legal claims.
07
How we disclose information
We disclose information as reasonably necessary to the following recipients:
- Service providers and processors for cloud hosting, security, authentication, communications, maps, analytics, support, storage, identity, payments, tax, fulfillment, and other operations.
- Customers, operators, and collaborators when necessary to plan, accept, coordinate, document, review, or pay for authorized work.
- Payment and financial partners, including Stripe and—if a card program launches—an issuing bank, card network, card manufacturer, identity provider, and compliance vendor.
- Connected third parties when you direct an integration or request a service involving them.
- Authorities and affected parties when we reasonably believe disclosure is required by law or necessary to protect rights, security, safety, or the integrity of the Platform.
- Corporate transaction participants in a financing, diligence process, merger, acquisition, reorganization, bankruptcy, or sale, subject to appropriate confidentiality and law.
We do not sell personal information for money. We do not knowingly use personal information for cross-context behavioral advertising without providing notices and choices required by law. Some analytics or advertising technologies may be treated as a “sale,” “sharing,” or targeted advertising in certain states; where they are used and covered, we provide the applicable opt-out mechanism and honor recognized browser signals as required.
08
Customer and operator visibility
Customers may see the identity, profile, qualifications, status, location or route state, communications, proof, quality review, and work records of operators assigned to or eligible for their authorized program, subject to role and privacy controls. Operators may see the customer, territory, tasks, timing, pay method, requirements, contacts, materials, and feedback needed to evaluate and complete an opportunity.
Supervisors, reviewers, teammates, and account administrators can see information based on their permissions. Live collaboration and private replay are intended for authorized participants, but participants may receive or create their own records where law permits. Do not share Platform information outside its intended work context.
09
Models and automated systems
We use models and automated tools to organize markets, recommend plans, match roles, identify safety or fraud concerns, prioritize review, summarize content, and assist users. These systems can affect what information or opportunities are displayed, but they do not guarantee eligibility, approval, assignment, performance, or earnings.
Where applicable law provides a right concerning a decision producing legal or similarly significant effects, you may request information, human review, or an appeal using the contact method below. We do not use operator identity, precise location, or card/KYC data for unrelated advertising.
10
Your choices and rights
You can update certain account information in the Platform, manage device permissions, choose whether to accept operator opportunities, unsubscribe from marketing email using its link, and adjust cookies through the available consent controls. Service, security, transaction, and active-work communications may continue while needed for the account or work.
To request access, correction, deletion, portability, an appeal, or another privacy right, email hello@marketmonolith.com. State your residence, request, account email, and relationship to Market Monolith. We will verify the request proportionately and may ask for more information. Authorized agents must provide authority, and we may still verify directly with you.
11
U.S. state privacy rights
Depending on where you live and whether a law applies to HotSwop’s processing, you may have rights to know or access categories and specific pieces of personal information, correct inaccuracies, delete information, obtain a portable copy, opt out of sale, sharing, targeted advertising or certain profiling, limit certain uses of sensitive information, and appeal a denied request. You also have a right not to receive unlawful discriminatory treatment for exercising a right.
We will respond within the period required by applicable law and explain any denial or extension. Some information is exempt, such as data needed for security, fraud prevention, legal compliance, transactions, active contracts, protected speech, or legal claims. We will not disclose sensitive credentials or information that would adversely affect another person.
California notice at collection. The categories described in “Information we collect,” including identifiers, commercial information, internet activity, geolocation, professional information, audio/visual content, inferences, and sensitive information, are collected for the purposes in “How we use information” and retained under “Retention and security.” We do not use or disclose sensitive personal information to infer characteristics except as permitted by law.
12
Retention and security
We retain information for as long as reasonably necessary for the purpose collected, active accounts and work, contracts, payment and tax records, proof and quality review, security, disputes, legal claims, provider obligations, and applicable law. Retention varies by data type and context. We delete, deidentify, or restrict information when it is no longer needed, subject to backups and lawful exceptions.
We use administrative, technical, and physical safeguards designed to protect information, such as access controls, authentication, encryption where appropriate, monitoring, vendor review, and incident response. No system is completely secure. If a breach requires notice, we will provide it as required by applicable law.
13
Children and international use
The Platform is for adults and business use and is not directed to children. We do not knowingly permit accounts for anyone under 18 or knowingly collect personal information from children under 13. Contact us if you believe a child provided information so we can investigate and take appropriate action.
Market Monolith is operated from the United States. If you access it elsewhere, information may be processed in the United States and other countries where providers operate. Where required, we use appropriate transfer protections. You are responsible for ensuring Platform use is lawful in your location.
14
Changes and contact
We may update this policy as the Platform, providers, and law change. We will post the new effective date and provide additional notice or seek consent where required. Material new uses of precise location, card, biometric, or similarly sensitive data will receive appropriate notice before use.
For privacy questions or requests, contact hello@marketmonolith.com with “Privacy” in the subject line. HotSwop, Inc. is responsible for this policy. If a state law provides an appeal and we deny your request, reply with “Privacy appeal” and explain why you believe the decision should be reconsidered.