Privacy policy
What we collect, why, and how we protect it.
Last updated: April 2026
1. What we collect
Account information
- Email address (required for authentication)
- Username and display name
- Profile photo (optional)
- Location (optional, shown on listings)
- Bio (optional)
Listing and transaction data
- Listing content — titles, descriptions, photos, pricing
- Order records — item, amount, buyer/seller IDs, status
- Messages sent through the platform
Usage data
- Pages visited and search queries (for improving search relevance)
- Last active timestamp (used to show online status — you can opt out by not using the platform)
- Listing view counts
2. What we don't collect
- Payment card numbers — handled entirely by Stripe
- Bank account details — handled entirely by Stripe Connect
- Government ID or tax information — handled by Stripe for sellers
3. How we use your data
- To provide and operate the marketplace
- To process payments via Stripe
- To send transactional emails (order confirmations, messages, notifications)
- To detect and prevent fraud and abuse
- To improve search and listing relevance
- To comply with legal obligations
We do not use your data for advertising, and we do not sell it to third parties.
4. Third-party services
We share data with the following third parties only as necessary to operate:
- Supabase — database, authentication, and file storage (EU/US data centres)
- Stripe — payment processing and seller payouts
- Vercel — hosting and edge delivery
Each of these services has its own privacy policy and security practices.
5. Cookies
We use cookies only for session authentication — a single secure, HTTP-only cookie to keep you logged in. We do not use advertising or tracking cookies.
6. Data retention
- Account data is retained until you request deletion.
- Completed order records are retained for 7 years for accounting and legal purposes.
- Messages are retained until you delete the conversation.
- Removed listings are soft-deleted and not visible publicly, but retained internally to preserve order history.
7. Your rights
You have the right to:
- Access the data we hold about you
- Correct inaccurate data via your profile settings
- Request deletion of your account and personal data
- Export your data
- Object to certain processing
To exercise any of these rights, email clutchyardteam@gmail.com. We'll respond within 30 days.
8. Security
All data is transmitted over HTTPS. Passwords are hashed using industry-standard algorithms. Access to production data is restricted to authorised personnel only. Despite our best efforts, no system is 100% secure — please use a strong, unique password for your account.
9. Changes to this policy
We'll notify registered users by email of material changes to this policy. The "last updated" date above reflects the most recent revision.
10. Contact
Privacy questions or requests: clutchyardteam@gmail.com