Privacy Policy
Effective: [DATE] · under the GDPR (EU 2016/679). Courtesy English translation; the Hungarian version prevails.
1. Controller
[COMPANY / NAME] (seat: [ADDRESS], tax no.: [TAX NUMBER], company reg. no.: [REGISTRATION NUMBER]) regards this policy as binding. Contact: [CONTACT EMAIL]. Full details in the Legal notice.
2. Definitions
- Personal data: any information relating to an identified or identifiable natural person ("data subject").
- Processing: any operation performed on personal data (collection, storage, use, transmission, erasure, etc.).
- Controller: who determines the purposes and means of processing.
- Processor: who processes personal data on the controller's behalf.
- Recipient: to whom personal data are disclosed.
- Consent: the data subject's freely given, specific, informed and unambiguous agreement.
- Data breach: a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
3. Principles
Personal data are processed lawfully, fairly and transparently, for specified purposes (purpose limitation), limited to what is necessary (data minimisation), accurately and up to date, kept no longer than necessary (storage limitation), and with appropriate security (integrity and confidentiality). The controller is responsible for and can demonstrate compliance (accountability).
4. What we process, why and on what basis
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Username, email, password (hashed), sign-in data (method, time — no IP) | Account, sign-in | Contract (6(1)b) | Until account deletion |
| Google/Apple identifier (if used) | Social sign-in | Contract (6(1)b) | Until account deletion |
| Uploaded photos, text read from images (OCR), item data, listing texts, price research | Providing the service | Contract (6(1)b) | Until item/account deletion |
| AI and price-research usage logs | Quota enforcement, abuse prevention, statistics | Legitimate interest (6(1)f) | ≤ 24 months |
| Subscription/payment data (see section 6) | Subscription, invoicing | Contract (6(1)b), legal obligation (6(1)c) | Invoice: 8 years (Accounting Act §169) |
| Waitlist: email, IP, source | Launch notice, abuse filtering | Consent (6(1)a) | Until withdrawal |
| Referral data, submitted feedback | Referral program, product development | Contract / legitimate interest | Until deletion |
| Google Analytics online identifiers and usage events (only after acceptance) | Aggregate traffic and usage statistics | Consent (6(1)a) | Until consent is withdrawn or the retention period configured in Google Analytics expires |
Statutory references: GDPR Art. 6(1) b), c) and f); E-commerce Act (CVIII of 2001), §13/A(3) (data technically indispensable to provide the service); invoices retained for 8 years under the Accounting Act (C of 2000), §169; 5-year limitation for contractual claims under the Civil Code (V of 2013), §6:22.
5. Recipients / processors
| Recipient | Data | Location |
|---|---|---|
| OpenAI (AI analysis) | uploaded photos (for identification/OCR) | USA |
| Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Dublin, Ireland) | name, email, payment transaction identifiers; card data handled solely by Stripe | EU/USA |
| [INVOICING PROVIDER — e.g. Billingo / Számlázz.hu] | billing data, issuing electronic invoices | Hungary |
| Google (sign-in, if used) | OAuth id, email | USA |
| Google Analytics (consent only) | online identifiers, page-view and usage events | EU/USA |
| [EMAIL/SMTP PROVIDER] | email address, sent emails | [EU?] |
| Telegram (operator alerts) | on new sign-up/subscription: username and email | USA/other |
| Hosting provider | all stored data | EU ([COUNTRY]) |
| Marketplace providers (price research) | the search query | EU |
6. Subscription and billing data
For the Pro subscription we process: the subscription type (monthly/yearly), status and duration; the payment provider's identifiers (Stripe customer, checkout session, payment intent and payment method IDs) — we do not store card data; billing data (billing name, postal code, city, address, optionally a tax number for businesses); the invoicing provider's identifier; and the subscription expiry, cancellation and notification dates. Legal basis: performance of the contract (6(1)b) and accounting-law obligation (6(1)c). Billing data and transaction identifiers are retained for 8 years from the invoice date under the Accounting Act §169.
7. International transfers
Your data is stored primarily within the EU. Some recipients (OpenAI, Stripe, Google, Telegram) may process data in the USA; transfers are safeguarded by the recipient's EU-US Data Privacy Framework certification and/or the European Commission's Standard Contractual Clauses. Uploaded photos are sent to OpenAI for analysis — we also flag this on photo upload.
8. Automated processing
The AI fills fields and estimates a price as assistance — it does not make automated decisions with legal effect on you. You accept or override its suggestions.
9. Your rights
- Access, rectification, erasure (you can permanently delete your account in Profile — all your items, photos and data are removed),
- restriction, portability, objection to processing based on legitimate interest,
- withdrawal of consent at any time (without affecting prior processing).
Contact us at [CONTACT EMAIL]. We inform you of measures taken without undue delay and in any case within 1 month of the request; this may be extended by 2 months where necessary (we notify you within 1 month, with reasons). Objections are examined within 15 days.
10. Security
We apply technical and organisational measures appropriate to the risk: passwords are stored hashed (bcrypt); sign-in uses an httpOnly cookie with an expiring token; uploaded photos are served via an access-controlled endpoint (not public); we log access; and we regularly review the confidentiality, integrity and availability of our systems.
11. Data breach
We notify the NAIH of a data breach without undue delay and, where feasible, within 72 hours, unless it is unlikely to pose a risk. If a breach is likely to result in a high risk to your rights, we also inform you without undue delay — unless we applied appropriate protection (e.g. encryption), the high risk is no longer likely, or informing you would require disproportionate effort (in which case we use public communication).
12. Remedies
You may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
NAIH — 1055 Budapest, Falk Miksa utca 9-11., Hungary · Mailing: 1363 Budapest, P.O. Box 9 · Phone: +36-1-391-1400 · Email: ugyfelszolgalat@naih.hu · naih.hu. You may also go to court.
13. Legislation considered
GDPR (EU 2016/679); Privacy Act (CXII of 2011); E-commerce Act (CVIII of 2001, esp. §13/A); Accounting Act (C of 2000, §169); Civil Code (V of 2013); Unfair Commercial Practices Act (XLVII of 2008); Advertising Act (XLVIII of 2008).