Sealed Ideas

Privacy Policy

Effective date: [Effective date, set after legal review]. Operator: [Legal entity name, exactly as registered with Stripe], [Registered postal address].

1. Who is responsible

The data controller is [Legal entity name, exactly as registered with Stripe], [Registered postal address]. Privacy questions and requests: privacy@sealedideas.com.

2. What we collect, where it comes from, how long we keep it

DataSourceWhyKept for
Name, email, password hash, email confirmation statusYouAccount, sign-in, contractUntil you delete the account; then anonymised, see section 8
Listings (public and sealed parts, attachments), bids, questions, answers, reviews, reportsYouRunning auctions and sales (contract)For the life of the marketplace record; anonymised after account deletion
Payment references (Stripe customer, session and payment IDs, amounts, payout status), tax and identity verification dataYou, StripePayment, payouts, fraud prevention, tax and legal obligations7 years (accounting and tax law)
Notification and email delivery recordsGeneratedDelivering and troubleshooting messages (legitimate interest)12 months
IP address, browser and device information, sign-in and rate-limit records, security logsYour browser, our hosting providerSecurity, abuse prevention (legitimate interest)90 days
Automated review records (which listing was checked, token counts, verdict)GeneratedModeration (legitimate interest)12 months
Anonymous page-view statisticsVercel AnalyticsUnderstanding usage (legitimate interest)As kept by the provider, without identifiers

3. Who processes data for us

ProviderRoleData
Vercel (USA)Hosting, serverless functions, file storage, analyticsAll application data in transit; attached files; anonymous analytics
Prisma Postgres (USA, us-east-1)Database hostingAll stored application data
Stripe (USA / EU entities)Payment processing, seller payouts, identity verification; independent controller for its own obligationsCard and bank details (never stored by us), names, emails, amounts, KYC data
Resend (USA)Transactional email deliveryEmail address, name, message content
OpenAI (USA)Automated listing checksListing title, public text and, for the pre-publish check when the seller opts in and for moderation on submission, the sealed text. Sent via the API; per the provider's API terms inputs are not used to train models and are retained for abuse monitoring for up to 30 days [to be verified against the current contract].

Other users see your name, your listings' public parts, masked bid and question activity, and reviews. Buyers who pay see the sealed part and attachments. Our staff may read content for security, moderation of reports, support and legal compliance.

4. Cookies

We set only essential cookies: your session and your theme preference. We do not use advertising or cross-site tracking cookies. Analytics is cookie-free and anonymous.

5. International transfers

Our providers are located mainly in the United States. Where you are outside the country in which data is processed, transfers rely on the providers' standard contractual clauses or equivalent safeguards. [Confirm mechanisms with counsel.]

6. Your rights

Depending on where you live you may have the right to access, correct, delete or receive a copy of your data, to restrict or object to processing, and to withdraw consent. Write to privacy@sealedideas.com; we verify requests by confirming control of the account email and answer within 30 days. You may also complain to your data protection regulator. We do not sell personal data and do not share it for cross-context behavioural advertising; if the California Consumer Privacy Act applies to you, this is also your notice of that fact and of the rights above.

7. Children

The Service is for adults (18+). We do not knowingly collect data from minors; if we learn we have, we delete it.

8. Deleting your account

When you delete your account we remove your name, email and password immediately and sign out every device. Listings, bids, questions, answers and reviews remain under “Deleted user” so other people's transactions stay intact; payment and tax records are kept for the period in section 2; backups are overwritten within 30 days.

9. Security

Passwords are hashed with bcrypt, sessions are random tokens stored hashed, all traffic is encrypted in transit, attached files are stored in a private store and served only after an access check, sign-in and reset endpoints are rate limited, and access to production data is limited to named administrators.

10. Changes and contact

We may update this policy; material changes are announced on the Service and by email. Questions: privacy@sealedideas.com, [Legal entity name, exactly as registered with Stripe], [Registered postal address].