Legal
Privacy Policy
Effective date: April 7, 2026
This policy explains exactly what personal data gbp.gg collects, why we collect it, how long we keep it, and what your rights are. We've tried to make it as plain as possible rather than burying things in legalese.
1. What We Collect & Why
Everything in this table is collected for a specific purpose — nothing is hoarded.
| Data | Source | Purpose | Retention |
|---|---|---|---|
| Name, email address | You, on registration | Account identity, login, transactional emails | Until account deleted |
| Profile photo | You, optionally uploaded | Display on profile and listings | Until account deleted |
| Password (hashed) | You, on registration | Authentication | Until account deleted |
| Session token, IP address, user-agent | Automatically on login | Security, fraud prevention, session management | Session expiry |
| OAuth tokens (e.g. Komerza) | OAuth flow, merchants only | Sync listings and orders from your store | Until store disconnected |
| Store name, description, country, languages, support email, Discord | You, merchant onboarding | Public merchant profile, buyer contact | Until account deleted |
| Order details (product, amount, currency, status, delivered items) | Generated on purchase | Transaction records, delivery, dispute resolution | 7 years (legal / financial) |
| Messages between buyers and sellers | You, in platform chat | Dispute resolution, platform safety | 3 years after last activity |
| Saved listings | You, bookmarking a listing | Show your saved items | Until removed or account deleted |
| Notifications | Generated by platform activity | Keep you informed of orders, messages, and account events | 90 days |
2. What We Don't Do
✗ Sell your data
We have never sold personal data to third parties and never will.
✗ Serve targeted ads
We don't profile you for advertising purposes.
✗ Store plain-text passwords
Passwords are hashed with bcrypt before storage.
✗ Share data without a reason
Third-party access is limited to what's needed to run the platform.
3. Third-Party Processors
We share limited data with the following processors, all under data processing agreements.
| Processor | Data Shared | Purpose |
|---|---|---|
| Komerza | Store ID, OAuth tokens, order IDs | Merchant listing sync & order fulfilment |
| Payment processors (e.g. Stripe) | Payment details (not stored by us) | Process transactions securely |
| Cloud hosting (e.g. Hetzner / Docker) | All platform data (encrypted at rest) | Platform infrastructure |
4. Your Rights
Request a copy of all personal data we hold about you.
Ask us to correct inaccurate data.
Request deletion of your account and associated data. Note: order records may be retained for legal/financial compliance.
Receive your data in a structured, machine-readable format.
Ask us to pause processing of your data in certain circumstances.
Object to processing based on legitimate interests.
To exercise any of these rights, email [email protected]. We'll respond within 30 days.
5. Cookies & Session Storage
| Cookie | Type | Purpose |
|---|---|---|
| session_token | Strictly necessary | Keeps you logged in |
| currency_preference | Functional | Remembers your display currency across sessions |
| locale | Functional | Stores your language preference |
We use no third-party analytics or advertising cookies.
6. Security
All data is encrypted in transit (TLS 1.3) and at rest. Passwords are hashed using bcrypt. Session tokens are rotated on login and expire automatically. We conduct regular security reviews and access to production data is restricted to essential personnel only.
7. Contact & Updates
For any privacy-related questions, contact [email protected]. If we make material changes to this policy, we'll notify you by email or via an in-platform notice at least 14 days before they take effect.