Collect less. Separate what must stay private.
The final notice will name the real controller, legal bases, processors, transfers, retention, rights contact, and jurisdiction before production data collection begins.
Data categories
- Account: email, authentication identifiers, session/security metadata.
- Seller: public profile fields plus private identity, business, robot-control, and payout-readiness evidence.
- Buyer: brand, contact email, optional HTTPS website, campaign note, sanitized logo derivative, and order status.
- Payments: Stripe object identifiers and minimal reconciliation facts; no raw card data.
- Operations: consent/terms version, moderation reasons, security logs, webhook inbox, outbox, and audit events.
Storage boundaries
Original logos, ownership evidence, and proof remain private. Public derivatives are decoded, dimension-limited, metadata-stripped, re-encoded, and moderated. External buyer URLs are never fetched by the server.
Intended processors
Supabase for database, authentication, and private storage; Stripe for payments, Connect onboarding, refunds, and payment risk; the selected commercial-compatible Next.js host; and a transactional email provider. The final list must match the deployed system.
Analytics and cookies
No advertising trackers are planned. Essential authentication and security cookies are used only when account infrastructure is enabled. Any analytics must be cookieless or separately consented and documented.
Rights and retention
Access, correction, deletion, objection, restriction, portability, withdrawal, complaint, retention periods, legal holds, and seller/controller responsibilities require final operator- and jurisdiction-specific wording.