Privacy Policy

Effective: [DATE] · under the GDPR (EU 2016/679). Courtesy English translation; the Hungarian version prevails.

Template — legal/DPO review recommended. Reflects the current setup: OpenAI as the AI provider, EU hosting, Stripe payments, Google sign-in.

1. Controller

[COMPANY / NAME] (seat: [ADDRESS], tax no.: [TAX NUMBER], company reg. no.: [REGISTRATION NUMBER]) regards this policy as binding. Contact: [CONTACT EMAIL]. Full details in the Legal notice.

2. Definitions

3. Principles

Personal data are processed lawfully, fairly and transparently, for specified purposes (purpose limitation), limited to what is necessary (data minimisation), accurately and up to date, kept no longer than necessary (storage limitation), and with appropriate security (integrity and confidentiality). The controller is responsible for and can demonstrate compliance (accountability).

4. What we process, why and on what basis

DataPurposeLegal basisRetention
Username, email, password (hashed), sign-in data (method, time — no IP)Account, sign-inContract (6(1)b) Until account deletion
Google/Apple identifier (if used)Social sign-in Contract (6(1)b)Until account deletion
Uploaded photos, text read from images (OCR), item data, listing texts, price researchProviding the serviceContract (6(1)b) Until item/account deletion
AI and price-research usage logsQuota enforcement, abuse prevention, statisticsLegitimate interest (6(1)f)≤ 24 months
Subscription/payment data (see section 6)Subscription, invoicing Contract (6(1)b), legal obligation (6(1)c) Invoice: 8 years (Accounting Act §169)
Waitlist: email, IP, sourceLaunch notice, abuse filtering Consent (6(1)a)Until withdrawal
Referral data, submitted feedbackReferral program, product developmentContract / legitimate interestUntil deletion
Google Analytics online identifiers and usage events (only after acceptance)Aggregate traffic and usage statistics Consent (6(1)a)Until consent is withdrawn or the retention period configured in Google Analytics expires

Statutory references: GDPR Art. 6(1) b), c) and f); E-commerce Act (CVIII of 2001), §13/A(3) (data technically indispensable to provide the service); invoices retained for 8 years under the Accounting Act (C of 2000), §169; 5-year limitation for contractual claims under the Civil Code (V of 2013), §6:22.

5. Recipients / processors

RecipientDataLocation
OpenAI (AI analysis)uploaded photos (for identification/OCR)USA
Stripe Payments Europe, Ltd.
(1 Grand Canal Street Lower, Dublin, Ireland)
name, email, payment transaction identifiers; card data handled solely by StripeEU/USA
[INVOICING PROVIDER — e.g. Billingo / Számlázz.hu] billing data, issuing electronic invoicesHungary
Google (sign-in, if used)OAuth id, emailUSA
Google Analytics (consent only) online identifiers, page-view and usage eventsEU/USA
[EMAIL/SMTP PROVIDER]email address, sent emails[EU?]
Telegram (operator alerts)on new sign-up/subscription: username and emailUSA/other
Hosting providerall stored data EU ([COUNTRY])
Marketplace providers (price research)the search queryEU

6. Subscription and billing data

For the Pro subscription we process: the subscription type (monthly/yearly), status and duration; the payment provider's identifiers (Stripe customer, checkout session, payment intent and payment method IDs) — we do not store card data; billing data (billing name, postal code, city, address, optionally a tax number for businesses); the invoicing provider's identifier; and the subscription expiry, cancellation and notification dates. Legal basis: performance of the contract (6(1)b) and accounting-law obligation (6(1)c). Billing data and transaction identifiers are retained for 8 years from the invoice date under the Accounting Act §169.

7. International transfers

Your data is stored primarily within the EU. Some recipients (OpenAI, Stripe, Google, Telegram) may process data in the USA; transfers are safeguarded by the recipient's EU-US Data Privacy Framework certification and/or the European Commission's Standard Contractual Clauses. Uploaded photos are sent to OpenAI for analysis — we also flag this on photo upload.

8. Automated processing

The AI fills fields and estimates a price as assistance — it does not make automated decisions with legal effect on you. You accept or override its suggestions.

9. Your rights

Contact us at [CONTACT EMAIL]. We inform you of measures taken without undue delay and in any case within 1 month of the request; this may be extended by 2 months where necessary (we notify you within 1 month, with reasons). Objections are examined within 15 days.

10. Security

We apply technical and organisational measures appropriate to the risk: passwords are stored hashed (bcrypt); sign-in uses an httpOnly cookie with an expiring token; uploaded photos are served via an access-controlled endpoint (not public); we log access; and we regularly review the confidentiality, integrity and availability of our systems.

11. Data breach

We notify the NAIH of a data breach without undue delay and, where feasible, within 72 hours, unless it is unlikely to pose a risk. If a breach is likely to result in a high risk to your rights, we also inform you without undue delay — unless we applied appropriate protection (e.g. encryption), the high risk is no longer likely, or informing you would require disproportionate effort (in which case we use public communication).

12. Remedies

You may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):

NAIH — 1055 Budapest, Falk Miksa utca 9-11., Hungary · Mailing: 1363 Budapest, P.O. Box 9 · Phone: +36-1-391-1400 · Email: ugyfelszolgalat@naih.hu · naih.hu. You may also go to court.

13. Legislation considered

GDPR (EU 2016/679); Privacy Act (CXII of 2011); E-commerce Act (CVIII of 2001, esp. §13/A); Accounting Act (C of 2000, §169); Civil Code (V of 2013); Unfair Commercial Practices Act (XLVII of 2008); Advertising Act (XLVIII of 2008).