Privacy Policy
Effective 13 July 2026 · Draft pending final legal review before public launch
1. What we collect
Account: name, email, credentials (passkey public keys or a salted password hash — never your password itself). Listings: title, description, price, photos, and location. Messages: your in-app conversations. Safety records: reports you file, blocks you set, and an append-only log of security-relevant actions (sign-ins, listing creation, moderation), including IP address and browser user-agent for abuse prevention.
2. How location works — the part that matters
When you create a listing, your exact coordinates are encrypted (AES-256-GCM) at the moment of saving and are never shown to anyone but you. What the public sees is a point randomly displaced by 100–300 metres, computed once and stored — it cannot be averaged back to your true location. Photo files are automatically stripped of hidden metadata (EXIF), including any GPS coordinates your camera embedded, before they are stored.
3. What we use data for
Operating the marketplace (showing listings, chat, search), keeping it safe (rate limiting, moderation, fraud prevention), and legal compliance. We do not sell your data, we do not show third-party advertising, and we do not use your data to train AI models.
4. Who processes data on our behalf
Cloudflare (application hosting, bot protection — Turnstile); Neon (database hosting, EU region — Frankfurt); CARTO/OpenStreetMap (map tiles: your browser requests tiles for the area you view); FOSSGIS/Valhalla(travel-time zones: the Radar sends an approximate origin — snapped to a ~110 m grid — and a travel mode, never your identity). No other third parties receive personal data.
5. Cookies
One essential session cookie for sign-in (httpOnly, secure). No tracking cookies, no analytics cookies, no consent-banner theatre — there is nothing to consent to beyond what the service needs to function.
6. Retention
Account data lives while your account does. Removed or expired listings are retained briefly for safety review, then scrubbed. The security audit log is append-only and retained for legitimate security interests. Chat messages persist for both participants until account deletion (see below).
7. Your rights — self-service, no ticket needed
From Privacy & data you can export everything we hold about you as a file (including your own exact listing locations, decrypted for you alone) and delete your account — which destroys your credentials and sessions, anonymises your profile, scrubs your listings, and deletes your photo files. Messages you sent remain visible to the other participant, attributed to “Deleted user”; safety records are retained on a legitimate-interest basis. These implement GDPR articles 15, 17 and 20 and equivalent rights elsewhere.
8. Controller and contact
[To be completed before public launch: data-controller legal entity, contact email, and supervisory-authority details — pending the launch-market decision.]