Mosaic policies

Privacy Policy

This Privacy Policy explains how Mosaic collects, uses, shares, and retains information when you use mosaic5mil.com and related Mosaic services.

1. Contact

Privacy and data requests: mosaic5mil@gmail.com.

2. Information you provide

Mosaic may collect account email, display name, password-derived authentication data, verification state, profile image, security preferences, two-factor state, support communications, reports, Tile selections, Areas, offers, seller responses, purchase groups, holds, ownership records, transaction history, wallet reservations, seller proceeds, withdrawals, moderation submissions, artwork, titles, descriptions, colors, and destination URLs.

3. Payments and payouts

Payment-card details are processed by Stripe rather than stored directly in Mosaic's application database. Stripe may provide Mosaic identifiers, payment status, amounts, charges, refunds, disputes, and transaction metadata. Payout onboarding may require Stripe to collect identity, banking, tax, sanctions, or verification information.

4. Automatically collected information

Mosaic and its providers may process IP addresses, timestamps, request metadata, browser and device information, security and authentication events, rate-limit identifiers, error/performance information, and similar technical data needed to operate, secure, troubleshoot, and improve the Service.

5. Cookies and browser storage

Mosaic uses cookies or browser storage for authentication, session security, preferences, navigation state, tab state, scroll restoration, fraud prevention, and essential functionality. If Mosaic later introduces non-essential analytics or advertising technologies, this Policy and any legally required consent controls will be updated.

6. How Mosaic uses information

Mosaic uses information to create and secure accounts, authenticate users, verify email, provide two-factor authentication, process purchases, offers, wallet activity, settlement and withdrawals, prevent double sales, operate checkout holds, send transactional notices, moderate content, investigate reports and abuse, prevent fraud, reconcile financial records, provide support, enforce policies, comply with law, and maintain and improve the Service.

7. Public information

Information intentionally made public through Mosaic may include a chosen display name, profile image, approved Area content, artwork, colors, descriptions, links, Canvas coordinates, and marketplace or ownership information shown by the Service. Mosaic does not create visitable public profile pages merely because a user has a display name or profile image.

8. Service providers

Mosaic may use providers including Vercel for hosting/deployment, Neon for PostgreSQL, Cloudflare R2 for object storage, Resend for transactional email, Upstash Redis for rate limiting or ephemeral data, Sentry for error/performance monitoring, and Stripe for payments and payouts. Providers process information under their own terms and privacy practices and may change as Mosaic's infrastructure evolves.

9. Sharing

Mosaic may disclose information to service providers; payment, payout, security, and fraud providers; professional advisers; authorities or other parties when required by law or reasonably necessary to protect rights and safety; parties involved in disputes or incidents; and parties to a merger, acquisition, financing, reorganization, or sale of business assets. Mosaic does not sell personal information for money.

10. Security

Mosaic uses administrative, technical, and organizational safeguards intended to reduce unauthorized access, loss, alteration, or misuse. No online service can guarantee absolute security.

11. Data breach response

Mosaic will investigate suspected security incidents and provide legally required notices to affected individuals, regulators, consumer reporting agencies, or others when applicable.

12. Retention

Mosaic retains information for as long as reasonably necessary for the purposes described in this Policy. Short-lived security, rate-limit, session, and temporary checkout data may expire quickly. Account and content records generally remain while the account or related content is active. Transaction, ownership, accounting, payout, fraud, dispute, policy-acceptance, security, and audit records may be retained longer when reasonably necessary for reconciliation, tax/accounting obligations, fraud prevention, legal claims, enforcement, or compliance. Data may also be retained in backups for a limited period before rotation.

13. Access, correction, deletion, and privacy requests

You may update supported account information through Mosaic or contact mosaic5mil@gmail.com to request access, correction, or deletion. Mosaic may verify your identity before acting. Deleting an account does not require deletion of records Mosaic must or reasonably needs to retain for transactions, ownership, taxes, accounting, fraud, security, disputes, legal holds, or compliance.

14. State and jurisdiction-specific rights

Depending on where you live and which laws apply to Mosaic, you may have additional rights concerning access, correction, deletion, portability, or certain processing. Mosaic will honor applicable rights and required appeals or opt-outs when those laws apply. Requests may be sent to mosaic5mil@gmail.com.

15. Children

Mosaic is intended only for users age 18 or older and is not directed to children. Mosaic does not knowingly permit children under 13 to create accounts. If you believe a child has provided personal information, contact Mosaic so the matter can be reviewed.

16. Email

Mosaic may send transactional and security messages such as verification, password-reset, authentication, offer, checkout, payment, moderation, payout, policy, and support notices. Where Mosaic offers optional notification categories, users may manage those preferences in Settings. Messages required for account security, transactions, legal notices, or service operation may not be optional.

17. International processing

Mosaic and its providers may process information in the United States and other locations. Where legally required, Mosaic will use appropriate mechanisms for cross-border processing.

18. Changes

Mosaic may update this Policy as the Service, providers, or legal requirements change. The effective date will be updated, and material changes will be communicated when appropriate.

19. Contact

Website: mosaic5mil.com
Privacy and support: mosaic5mil@gmail.com

Effective August 6, 2026 · Version 2026-08-06-1