Skip to content
Current Auction Live

Privacy

This page summarises our data practices as implemented in the product. It is a product document, not legal advice.

What we never store

Bidder identity

Public bid history shows a per-auction alias derived from a salt unique to that lot, so a bidder cannot be profiled across auctions. IP, device and risk signals are stored separately from the bid record with restricted access, and are never returned by ordinary bid history reads.

Addresses

Buyer addresses are snapshotted onto the order for fulfillment. Public pages show only a coarse location. When we compare a carrier destination to the buyer address we compare hashes and prefixes rather than exposing the address.

Sensitive documents

Dispute evidence and verification documents are stored privately and served only through short-lived signed URLs to people authorised to see them.

Retention

Financial and audit records are retained as long as legal, accounting and processor obligations require. Deleted accounts are anonymised where records must legally remain, and personal data is kept separate from public profile data.

Cookies and sessions

One authenticated session works across the root domain, category subdomains and seller storefront subdomains. Session cookies are scoped to current.auction only and are never shared with any future externally hosted seller domain.