MarketPlace

Privacy Policy

Last updated: 4 June 2026

This Privacy Policy explains how MyMarket ("we", "us") collects, uses and protects your personal data when you use our marketplace, in accordance with the EU General Data Protection Regulation (GDPR).

1. Who we are

MyMarket operates an online marketplace connecting buyers with independent vendors. We are the data controller responsible for your personal data. If you have any questions, you can contact us at privacy@mymarket.example.

2. What data we collect

  • Account data: name, email address and password (stored securely, hashed).
  • Profile and vendor data: username, business details and addresses you provide.
  • Order and transaction data: items purchased, prices, shipping and delivery status.
  • Payment data: processed directly by Stripe. We do not store your full card details.
  • Technical data: strictly necessary cookies and session information needed to keep you logged in.

3. How we use your data and legal basis

  • To provide the marketplace and your account — legal basis: performance of a contract.
  • To process orders, payments and payouts — performance of a contract.
  • To send transactional emails (order confirmations, account notices) — performance of a contract.
  • To keep the platform secure and prevent fraud — legitimate interest.
  • To comply with accounting and legal obligations — legal obligation.

4. Cookies

We only use strictly necessary cookies required to operate the site (such as login sessions, language preference and payment fraud prevention). We do not use analytics, advertising or tracking cookies, so no cookie consent banner is required. See our Cookie Policy for the full list.

5. Who we share your data with

We share data only with processors that help us run the service:

  • Supabase — authentication and database hosting.
  • Stripe — payment processing and payouts to vendors.
  • Our email provider — sending transactional emails.
  • Vendors — when you place an order, the relevant vendor receives the details needed to fulfil it.

6. International transfers

Some of our processors may store or process data outside the European Economic Area. Where this happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

7. How long we keep your data

We keep your account data for as long as your account is active. Transaction records are kept as required by accounting and tax law. When you delete your account, we delete or anonymise your personal data unless we are legally required to retain it.

8. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Request erasure of your data ("right to be forgotten").
  • Restrict or object to certain processing.
  • Data portability — receive your data in a portable format.
  • Lodge a complaint with your local data protection authority.

9. Security

We use industry-standard measures to protect your data, including encryption in transit, hashed passwords and access controls. No method of transmission is completely secure, but we work to protect your data at all times.

10. Children

Our service is not directed at children under 16, and we do not knowingly collect their personal data.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page.

12. Contact

For any privacy questions or to exercise your rights, contact us at privacy@mymarket.example.

For details about the cookies we use, see our Cookie Policy.