Pre-launch privacy draft · not yet operative

Collect less. Separate what must stay private.

The final notice will name the real controller, legal bases, processors, transfers, retention, rights contact, and jurisdiction before production data collection begins.

Data categories

  • Account: email, authentication identifiers, session/security metadata.
  • Seller: public profile fields plus private identity, business, robot-control, and payout-readiness evidence.
  • Buyer: brand, contact email, optional HTTPS website, campaign note, sanitized logo derivative, and order status.
  • Payments: Stripe object identifiers and minimal reconciliation facts; no raw card data.
  • Operations: consent/terms version, moderation reasons, security logs, webhook inbox, outbox, and audit events.

Storage boundaries

Original logos, ownership evidence, and proof remain private. Public derivatives are decoded, dimension-limited, metadata-stripped, re-encoded, and moderated. External buyer URLs are never fetched by the server.

Intended processors

Supabase for database, authentication, and private storage; Stripe for payments, Connect onboarding, refunds, and payment risk; the selected commercial-compatible Next.js host; and a transactional email provider. The final list must match the deployed system.

Analytics and cookies

No advertising trackers are planned. Essential authentication and security cookies are used only when account infrastructure is enabled. Any analytics must be cookieless or separately consented and documented.

Rights and retention

Access, correction, deletion, objection, restriction, portability, withdrawal, complaint, retention periods, legal holds, and seller/controller responsibilities require final operator- and jurisdiction-specific wording.