1. Data We Collect
- Data you provide: name, username, contact details (e-mail, phone), account credentials (stored securely), billing information (where required).
- Automatically collected data: IP address, device type, browser data, cookies, usage logs.
- Transaction data: order history, payments, communication with other Users.
2. Purpose of Processing
We process data for the following purposes:
- operating and providing the Service,
- account management and authentication,
- transaction processing and customer support,
- fraud prevention and security,
- compliance with legal obligations (e.g., accounting, tax),
- analytics and service improvements,
- marketing, where consent is given.
3. Legal Basis
- Contract performance – to provide the Service.
- Legitimate interest – improving security, preventing fraud, analytics.
- Legal obligation – compliance with financial and tax regulations.
- Consent – for marketing activities or optional cookies.
4. Data Sharing
We only share data with:
- payment service providers,
- IT and hosting providers,
- public authorities where required by law,
- other Users, to the extent necessary for completing transactions.
We never sell personal data to third parties.
5. Cookies
We use cookies to ensure functionality, improve the Service, and (with consent) for analytics and marketing. Users can adjust cookie settings in their browser, but some features may not work properly without them.
6. Data Retention
- Account data is stored as long as the account is active and up to 3 years after termination.
- Transaction data is retained for as long as required by law (e.g., 10 years for accounting records).
- After expiration, data is securely deleted or anonymized.
7. User Rights (GDPR)
Users have the right to:
- access their data,
- correct or update inaccurate data,
- request deletion (“right to be forgotten”),
- restrict processing,
- data portability,
- object to processing,
- lodge a complaint with the data protection authority.
8. Data Security
We use encryption (HTTPS), secure servers, and other technical and organizational measures to protect personal data. Passwords are hashed and never stored in plain text.