Mobile App Privacy Policy
Last Updated: February 18, 2025
1. Introduction
Welcome to the MadeInUSA.com Mobile App. This Privacy Policy explains how MadeInUSA.com LLC ("we," "us," "our") collects, uses, shares, and protects your personal information when using our mobile app, website (https://www.madeinusa.com), and related services.
By accessing or using our app, you acknowledge that you have read, understood, and agree to this Privacy Policy. If you do not agree, please discontinue use.
2. Information We Collect
We collect personal data in compliance with Google Play Store and Apple App Store privacy policies.
2.1 Voluntarily Provided Information
You provide personal data when you:
- Create an account (name, email, phone number, password)
- Make a purchase (billing details, but not full payment information)
- Subscribe to newsletters or marketing emails
- Contact customer support (messages, support history)
- Participate in surveys, promotions, or social media interactions
2.2 Automatically Collected Information
When you use our app, certain data is collected automatically:
- Device Information: Type, operating system, app version, device settings
- Usage Data: Features used, app interactions, preferences, error logs
- Location Data: If enabled, to provide region-specific product recommendations, shipping estimates, or localized offers
- IP Address & Log Data: Browsing details, device identifiers, network details
- Crash Reports & Error Tracking: Data on app performance
3. Data Security: How We Protect Your Information
We implement robust security measures to protect your personal data against unauthorized access, loss, misuse, or alteration.
3.1 Data Encryption for Sensitive Information
- End-to-End Encryption (E2EE): All sensitive user data, including passwords and personally identifiable information (PII), is encrypted using AES-256 during storage and TLS 1.3 during transmission.
- Secure Payment Transactions: We do not store full payment details on our servers. Payments are processed through PCI-DSS compliant providers (Apple Pay, Google Pay, PayPal, Stripe, Authorize.net).
3.2 Access Controls & Authentication
- Multi-Factor Authentication (MFA): If enabled, users must verify identity through an additional step (e.g., SMS, email, authenticator app).
- Role-Based Access Control (RBAC): Access to sensitive data is limited based on the principle of least privilege (PoLP).
- Automatic Logout: Inactive sessions automatically log out after a specified period.
3.3 Regular Security Updates & Monitoring
- Routine Vulnerability Scans: Weekly security assessments and quarterly penetration testing.
- Real-Time Threat Monitoring: Intrusion detection/prevention systems (IDS/IPS) monitor unauthorized access attempts.
- Security Patches: Critical updates are promptly applied to mitigate new threats.
3.4 Fraud Prevention & Anomaly Detection
- User Reporting System: Users can report suspicious activities at support@madeinusa.com.
3.5 Secure Cloud Storage & Data Redundancy
- Data Stored on Microsoft Azure: Compliant with ISO 27001 & SOC 2 Type II security standards.
- Daily Encrypted Backups: Ensures data redundancy and recovery capability.
- Disaster Recovery Plan: Quick restoration procedures minimize downtime.
3.6 Compliance with Industry Standards & Regulations
- GDPR Compliance: Ensuring lawful data processing for EU users.
- CCPA Compliance: California residents have opt-out and data deletion rights.
- PCI-DSS Compliance: Secure payment handling with Level 1 security protocols.
3.7 User Responsibility & Security Best Practices
While we take extensive security measures, users are encouraged to:
- Use Strong Passwords: Create a unique and secure password.
- Enable Multi-Factor Authentication (MFA): If available, activate MFA for added security.
- Beware of Phishing Attempts: We never request login credentials or payment details via email or phone. Report suspicious messages to support@madeinusa.com.
- Keep Software Up to Date: Ensure you are using the latest app version and mobile OS updates.
Important Note: No system is 100% secure. While we employ industry-leading security measures, protecting your login credentials and personal data is also your responsibility.
4. Marketplace Seller & Buyer Policies
4.1 Seller Communications
- All communications between buyers and third-party vendors are conducted through the MadeInUSA.com Support Team in the app.
- Sellers do not receive buyers' personal contact information directly.
- The Support Team monitors messages to prevent fraud, protect user privacy, and ensure compliance with marketplace policies.
4.2 Order Fulfillment & Returns
- Orders are fulfilled directly by third-party sellers, and shipping details are provided by each seller.
- Sellers establish their own return and refund policies, which are displayed on the product listing page.
- Refunds are processed through MadeInUSA.com in accordance with each seller's policy.
5. Data Retention & Deletion
We retain user data only as long as necessary for:
- Service Operation: To maintain and enhance our platform functionality.
- Legal Compliance: To meet regulatory, tax, and other legal obligations.
- Fraud Prevention & Security Investigations: To detect and prevent fraudulent or malicious activities.
5.1 Data Retention Periods
- Account-related data is stored for up to 5 years after account deletion, unless legal obligations require longer retention.
- Transaction-related data is retained for 7 years for financial and tax compliance.
5.2 Data Deletion Requests
Users can request to delete their personal data via in-app settings:
For iOS Users:
- Navigate to App Settings > Privacy > Delete My Data
- Requests will be processed within 30 days
- For further assistance, contact support@madeinusa.com
For Android Users:
- Navigate to App Settings > Privacy > Manage My Data
- Users can also delete app-generated data via Settings > Apps > MadeInUSA.com > Clear Data
- Requests will be processed within 30 days
5. Contact Us
For any privacy-related questions or security concerns, contact us at:
📧 Email: support@madeinusa.com
🌐 Website: https://www.madeinusa.com

