Privacy Policy
Last updated: 14 September 2026 · Version 1.3
1. Who is responsible for your data
The controller of the personal data described here is [LEGAL ENTITY NAME], [ADDRESS], Bulgaria, company number [NUMBER] ("we", "us"). Contact us about privacy at [PRIVACY CONTACT EMAIL].
We have not appointed a Data Protection Officer. Data protection questions go to [PRIVACY CONTACT EMAIL] and are answered by us directly.
When you use Omnidara to manage listings, personal data belonging to your own customers may pass through the Service. For that data you are the controller and we are your processor - see the Data Processing Agreement.
2. What we collect, why, and on what legal basis
Account data
Email address, name (if you give one), a hashed password, verification and password-reset tokens, and your account status.
Why: to create and secure your account, sign you in, and contact you about the Service. Basis: performance of our contract with you (Art. 6(1)(b)).
Listing and sales data
Listings you create or import, their photographs, descriptions, prices, cost basis, per-marketplace settings, publication records, and the sales we detect (order identifiers, sale prices, timestamps, shipping costs you record).
Why: to run the Service - publishing, syncing, sale detection, auto-delisting and your analytics. Basis: performance of our contract.
Marketplace connection data
The marketplace accounts you connect: the marketplace, an account label, an external account identifier, connection status, and the access credentials the marketplace issues (OAuth tokens or session payloads).
Credentials are encrypted at rest with an application key held outside the database, are never shown back to you in full, and are deliberately excluded from data exports so they cannot end up in a downloads folder. Basis: performance of our contract.
Activity and operational data
An activity log of actions taken in your account (what published where, what synced, what sold, what failed), background job records including error messages, and server logs.
Why: to show you what the Service did on your behalf, to support you, and to keep the Service secure and working. Basis: performance of our contract, and our legitimate interest in operating and securing the Service (Art. 6(1)(f)).
Billing data
Your plan, subscription status and the identifiers our payment processor gives us. We never see or store your card details - payment happens on Stripe's own hosted pages. Why: to bill you and meet accounting obligations. Basis: contract, and legal obligation for records we must retain (Art. 6(1)(c)).
Inbound marketplace notifications
Where a marketplace pushes sale notifications to us, we store the raw message so a processing failure can be replayed rather than losing a sale. These messages can contain order details originating from the marketplace. They are deleted after 30 days, except messages that failed to process, which are kept until the failure is resolved.
3. What we do not do
- We never sell personal data - yours, or that of your customers when it passes through the Service - and we do not rent it out.
- If you ask us not to sell your personal data, we record that request and honour it, including against any later change to this policy. Nothing is sold today, so everyone is already opted out.
- We do not use your data to train machine-learning models.
- We do not run advertising or tracking on the Service. See the Cookie Policy - we set four cookies, all of them only to provide something you asked for.
- We do not profile you in a way that produces legal or similarly significant effects, and there is no automated decision-making under Art. 22. If that ever changed, we would tell you before it applied to you, and you would be able to opt out of it.
We respect and apply the consent decisions you make. Where something depends on a choice you have made - for example an email preference in Settings → Notifications - we act on the choice you made, and changing your mind takes effect from then on.
4. Who we share it with
Only with providers who process data on our behalf under contract, and with the marketplaces you choose to connect:
- Marketplaces you connect (eBay and others you enable): they receive the listing content you instruct us to publish. Once it reaches them it is governed by their own privacy policies, not this one.
- Stripe - payments and subscription billing.
- Google - only if you choose "Continue with Google". Choosing it shares data with Google: Google learns that you are signing in to Omnidara (and when), under Google's own privacy policy. What we receive from Google is your email address, whether Google has verified it, your name, and Google's stable account identifier - which we store to recognise the link. We request nothing else, and if you never use Google sign-in, nothing is ever shared with Google.
- Railway - application, database and listing-photograph hosting in [REGION]. Photographs sit on the same Railway volume as the application; there is no separate object-storage provider.
- Resend - sending the emails described in this policy.
- Authorities, where we are legally required to disclose.
Where a provider is outside the EEA, transfers rely on an adequacy decision or on Standard Contractual Clauses with supplementary measures as needed. Ask us at [PRIVACY CONTACT EMAIL] for details of the safeguards in place.
5. How long we keep it
- Account, listings, sales and activity: for as long as your account exists.
- After you delete your account: erased immediately (see section 7), with one narrow exception. A minimised record of each purchase consent and of any exercised 14-day withdrawal right is retained: a one-way hash of your email identity, the payment-card fingerprint Stripe reported, the consent version, the amount, the currency and the timestamps — and nothing that identifies you beyond those checks. We keep it for five years from the purchase or withdrawal, whichever is later — the general limitation period for contractual claims that applies to us — because these records establish that consent was given and that a once-per-customer right was used, and they exist for the establishment and defence of legal claims (GDPR Art. 17(3)(b) and (e)). After five years they are deleted automatically.
- Verification, password-reset and email-change links: deleted within 7 days of being used, cancelled or expiring.
- Background job records: successful jobs are purged after 7 days; failed and dead jobs are kept while the account exists, because they are the record of what went wrong.
- Raw marketplace notifications: 30 days, or until a failed one is resolved. An erasure request removes the ones about you before then.
- Raw payment-processor events: the messages Stripe sends us about your subscription are stored so a billing failure can be replayed rather than lost. 30 days, or until a failed one is resolved. An erasure request removes the ones about you before then.
- Billing records: retained for the period required by Bulgarian tax law, even after account deletion. This is a legal obligation and overrides an erasure request for those records only.
- Backups: deleted data disappears from backups as they rotate, within [BACKUP RETENTION PERIOD].
6. Security
- Passwords are stored as bcrypt hashes, never in readable form.
- Marketplace credentials are encrypted at rest.
- Traffic is served over HTTPS.
- Access to production data is limited to staff who need it.
- Sessions are cookie-based, with CSRF protection on every form and a content security policy that blocks third-party scripts.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and inform you where the law requires it.
7. Your rights
Under the GDPR you have the right to access your data, correct it, erase it, restrict or object to its processing, and receive it in a portable format. Two of these are built into the product and need no request:
- Access and portability: Settings → Your data downloads the data we hold about you as a single JSON file: your account and settings, subscription and purchase consents, connected marketplaces and their connection history, listings with their per-marketplace details, photo addresses and placements, sales, imports, bulk operations, background jobs and the activity log. The file lists what it leaves out and why: stored marketplace credentials, which would let whoever holds the file act on your marketplace accounts; your password hash and the hashes of sign-in links, which are security secrets; raw payment events from Stripe, whose invoices and payment history are in the Stripe customer portal; raw marketplace notifications, which carry your buyers' personal data; internal working copies of imported marketplace data and job instructions; photos of listings imported from Discogs, whose release artwork Discogs does not license us to pass on; and the photo files themselves, which the file lists by address instead. You can download it once every 15 minutes.
- Your inventory as a spreadsheet: the same card exports your inventory as a CSV file - one row per listing, with where each one is listed - for a range of creation dates and the columns you choose.
- Erasure: Settings → Delete your account erases the account and its contents. It deletes rows; it is not a hidden flag.
For anything else - correction, restriction, objection, or withdrawing consent where we rely on it - contact [PRIVACY CONTACT EMAIL]. We answer within one month. You may also complain to your local supervisory authority; ours is the Commission for Personal Data Protection (Комисия за защита на личните данни), Sofia, Bulgaria.
8. Emails we send
Some emails are part of the Service and cannot be switched off: email verification, password reset, and confirmation that an import you started has finished. Everything else is a preference in Settings → Notifications, and switching one off actually stops it being sent: sale alerts, failed-sync alerts, broken-connection alerts and the weekly summary. We do not send marketing email without separate consent.
9. Children
The Service is not intended for anyone under 18 and we do not knowingly collect their data.
10. Changes
We will post changes here with a new "last updated" date, and notify you by email for material changes before they take effect.