Privacy
This page summarises our data practices as implemented in the product. It is a product document, not legal advice.
What we never store
- Card numbers, CVV or magnetic-stripe data. Cards are collected by our payments provider's hosted fields and reach us only as a token.
- Full identity-verification payloads. We keep the provider's identifiers and the resulting status, not the documents.
- Secrets, tokens or bank details in logs or audit records; those fields are redacted before an audit event is written.
Bidder identity
Public bid history shows a per-auction alias derived from a salt unique to that lot, so a bidder cannot be profiled across auctions. IP, device and risk signals are stored separately from the bid record with restricted access, and are never returned by ordinary bid history reads.
Addresses
Buyer addresses are snapshotted onto the order for fulfillment. Public pages show only a coarse location. When we compare a carrier destination to the buyer address we compare hashes and prefixes rather than exposing the address.
Sensitive documents
Dispute evidence and verification documents are stored privately and served only through short-lived signed URLs to people authorised to see them.
Retention
Financial and audit records are retained as long as legal, accounting and processor obligations require. Deleted accounts are anonymised where records must legally remain, and personal data is kept separate from public profile data.
Cookies and sessions
One authenticated session works across the root domain, category subdomains and seller storefront subdomains. Session cookies are scoped to current.auction only and are never shared with any future externally hosted seller domain.