COLLECTORIA
Legal

Privacy Policy

This policy explains what information Collectoria collects, how it is used, how long it may be kept, and the choices available to users.

Last updated: August 21, 2026/privacy

Effective date: August 21, 2026

Information we collect

Collectoria may collect account details, seller profile information, listing content, uploaded media, order and shipment details, payment and payout references, dispute evidence, support messages, device data, approximate location signals, language preferences, and analytics events needed to operate the platform.

How we use information

  • To create accounts, manage sessions, and secure access.
  • To publish shop products, auctions, seller listings, encyclopedia content, guides, collections, and outfitter services.
  • To process orders, bids, payment holds, payouts, shipment tracking, returns, disputes, and support requests.
  • To detect fraud, enforce marketplace rules, review risky listings, and protect buyers and sellers.
  • To localize the public site by language or country and improve search, recommendations, filters, and analytics.
  • To send service messages, confirmations, moderation notices, and account security alerts.

Legal bases and user consent

Where privacy law requires a legal basis, processing may be based on contract performance, legitimate interests, legal obligations, consent, or vital security needs. Non-essential marketing and analytics tools should be controlled by cookie or consent settings where required.

Sharing information

Information may be shared with payment processors, shipping providers, email providers, hosting vendors, fraud and moderation services, analytics services, professional advisers, law enforcement when legally required, and counterparties in a transaction when needed to complete an order or resolve a dispute.

Uploads and public content

Product photos, seller descriptions, collection visibility settings, comments, reviews, guides, and public profile information may be visible to other users if published. Certificates, invoices, identity documents, payment information, dispute evidence, and private messages should remain restricted to authorized users and staff workflows.

Retention

Data is kept only as long as needed for the platform purpose, legal compliance, tax/accounting records, fraud prevention, dispute history, backups, and security logs. Deleted public content may remain in backups or audit logs for a limited operational period.

User rights

Depending on local law, users may request access, correction, deletion, export, restriction, or objection to certain processing. Some records cannot be deleted immediately when they are needed for fraud prevention, accounting, legal obligations, active disputes, or marketplace safety.

Security

The platform should use secure authentication, role-based admin access, audit logs, input validation, upload controls, payment-provider tokenization, and production monitoring. No online service can guarantee absolute security, so users should also protect account passwords and report suspicious activity.

Contact

For privacy requests, use the contact page or the support email configured by the site operator. Admins should keep this page updated with the correct controller/company details before launch.