Legal · Privacy Policy
Privacy policy
Effective · 2026-04-29 · Version 1.0
Section 01
Data controller
The data controller for personal data processed via SudoSell is SudoSell. Privacy contact runs through the privacy & data request form.
Section 02
What data we collect
We collect only what we need to operate the marketplace:
- Account data: name, email, optional username, password hash (bcrypt, so we cannot read your password), avatar URL, OAuth provider id.
- Profile metadata: notification preferences, country (where applicable), 2FA secret (server-side, never sent back to your browser), backup codes (hashed).
- Session data: JWT session id, user-agent string, IP address (typically truncated), last-used timestamp, expiry, revocation status.
- Purchase data: order ids, items purchased, amount, currency, status, payment-processor reference id, refund/chargeback history. We do not store your full card number; payment processing is performed by a PCI-DSS compliant third-party processor.
- Cart and wishlist:product slugs you’ve saved or added.
- Reviews: products you reviewed, your rating, the review text, timestamp.
- Support tickets: messages you sent or received, related metadata.
- Search and behavior:queries you ran on the catalog and result counts (used for “what aren’t we ranking?” analytics; no per-user behavior tracking beyond this).
- Logs: request logs containing path, status, and truncated IP for security and debugging. Retained for 90 days.
We do not use third-party advertising trackers, fingerprinting, ad pixels, or session-replay tools.
Section 03
Why we use your data (lawful basis)
- Performance of contract: creating accounts, processing payments, delivering downloads, sending receipts, handling refunds.
- Legitimate interests: security (fraud detection, session management), product improvement (aggregated analytics, search analysis), preventing abuse.
- Consent: marketing newsletters, product-update emails (where you opted in). You can withdraw consent at any time in notification settings or via any unsubscribe link.
- Legal obligation: tax records, anti-money-laundering checks, sanctions screening, responding to lawful requests.
Section 04
Sharing with third parties
We only share personal data with:
- Our payment processor.A PCI-DSS compliant third-party gateway used to charge cards, process refunds, and settle payouts. It receives name, email, billing address, and transaction details. The processor’s privacy policy applies to that processing. The processor’s identity is disclosed on request via the privacy form.
- Neon. Managed PostgreSQL hosting. Stores all structured data we collect, encrypted at rest.
- Cloudflare R2. Object storage for avatar uploads and product release artifacts.
- SMTP provider. Sends transactional and (with consent) marketing emails. Receives recipient email and message body.
- Sellers. When you purchase a product, the seller sees your name and email so they can deliver support. They do not see your payment details, billing address, or other purchases.
- Law enforcement and regulators. Only when legally compelled, and we attempt to challenge overbroad requests.
We do not sell, rent, or trade personal data. We do not engage in cross-context behavioral advertising.
Section 05
International transfers
Data may be processed in jurisdictions outside your country (notably India and the United States, depending on subprocessor location). For EU/UK transfers, we rely on Standard Contractual Clauses with subprocessors. For India residents, we comply with the DPDP cross-border requirements.
Section 06
Retention
- Account data: retained while your account is active. Deleted within 30 days of account deletion, except as noted below.
- Purchase + tax records: retained for 7 years after the transaction to comply with tax and accounting law, even after account deletion.
- Sessions: deleted on logout or expiry.
- Support tickets: retained for 3 years for dispute resolution.
- Logs: 90 days.
- Backups: rotational; deleted data persists in backups for up to 35 days before being overwritten.
Section 07
Your rights
Depending on your jurisdiction, you may have the right to:
- Accessa copy of your data. Self-serve via the “Download my data” button on your profile.
- Rectify inaccurate data. Change name, email, avatar, and similar fields via settings.
- Erase your data. Delete your account from account settings. Tax-related records are retained as required by law.
- Restrict or object to processing for direct marketing. Disable in notification settings.
- Portability. The data export is JSON, suitable for re-importing or migrating.
- Withdraw consent at any time without affecting prior lawful processing.
- Lodge a complaint with your local data protection authority.
Section 08
Children
SudoSell is not directed at children under 18 (or the age of majority in your jurisdiction). We do not knowingly collect data from children. If you become aware that a child has provided data, submit the privacy request form and we will delete it promptly.
Section 09
Security
We protect your data with: HTTPS everywhere; password hashing with bcrypt at cost 12; 2FA via TOTP with hashed backup codes; signed short-lived JWT sessions with revocation tracking; encrypted-at-rest databases; limited internal access on a least-privilege basis; HMAC signature verification on payment webhooks; rate limits on sensitive endpoints; structured error logging without sensitive payloads.
No system is perfectly secure. If you believe your account is compromised, change your password, sign out of all sessions in security settings, and submit the security disclosure form. We disclose breaches that affect personal data within statutory timelines.
Section 10
Cookies
Cookies and local storage usage is described in the Cookie Policy. We use only first-party cookies necessary for authentication, security, and (with consent) preferences.
Section 13
Account inactivity
Accounts with no activity (no logged-in session, no purchase, no published listing, no withdrawal request) for twenty-four (24) months may be flagged inactive. We email the address on file at least 30 days before any inactivity action; signing in within that window restores active status. Inactive accounts retain purchase records (for tax retention) and audit data for the period required by applicable law. Personal data covered by the right-to-erasure (Section 07) is removed unless statute requires retention.
Section 11
Changes to this policy
Material changes will be announced by email at least 30 days before they take effect. The effective date at the top of this page reflects the most recent revision.
Section 12
Contact
Privacy questions or data subject rights requests go through the privacy & data request form.
Questions about this document? Send a legal contact form or open a support request.
This document may be amended from time to time. Material changes will be communicated by email to the address on file at least 30 days before they take effect.