01Controller and contact details
The controller of personal data is Matchdays.
Privacy enquiries and requests to exercise data-protection rights may be sent to info@matchdays.store. If the Controller appoints a data protection officer, their details will be provided here.
02Data categories and sources
Depending on the functions used, we may process:
- Account data — name, username, email address, telephone number, country, settings and Account identifiers,
- verification data — date of birth, trader status, company details, tax number, registration number, and identity or payment-account verification where required for payments, security, the DSA or DAC7,
- Listing and collection data — descriptions, prices, photographs, provenance information and authenticity information,
- transaction data — cart, orders, bids, payments, payouts, commissions, delivery address, shipment tracking, returns and disputes,
- communications and evidence — messages, reports, complaints, photographs, voice or LiveCam recordings and documents supplied in a case,
- promotion data — entries, answers, predictions, scores, points, rewards and eligibility evidence if Arena or a Promotion is launched,
- technical data — IP address, session identifiers, device and browser type, security logs, and when and how functions are used,
- marketing data — consents, objections and communication records if marketing is introduced.
We receive data directly from the User, from the other party to a transaction, from the device and Platform logs and, where necessary, from payment, shipping, identification, security and AI providers.
03Purposes and legal bases
- Performance of a contract or steps taken before entering into a contract (Article 6(1)(b) GDPR) — Accounts, Listings, transactions, messages, shipping, payments, payouts, disputes and User support.
- Compliance with a legal obligation (Article 6(1)(c) GDPR) — accounting, tax, DAC7, handling public-authority requests, product safety and online-platform obligations.
- Legitimate interests (Article 6(1)(f) GDPR) — preventing fraud, protecting Accounts and infrastructure, moderation, error analysis, establishing or defending claims and basic service statistics.
- Consent (Article 6(1)(a) GDPR) — electronic marketing, optional cookies or similar technologies and other activities expressly identified as voluntary.
Where processing relies on legitimate interests, its necessity, proportionality and effect on individual rights should be assessed before it begins. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
04Whether data is required
Data marked as required must be provided to create an Account or use the relevant function. Shipping cannot be completed without a delivery address, and selling or receiving a payout may be impossible without required identity or tax details. Marketing data and optional profile fields are voluntary.
05Recipients of data
Data may be disclosed only to the extent needed for the relevant purpose:
- to the other party to a transaction, for example delivery details supplied to the Seller,
- to hosting, database, file-storage and monitoring providers, including Railway, Vercel and Supabase services used by the project,
- to payment and payment-verification providers, such as Stripe, once the relevant integration is enabled,
- to the carrier and any shipping intermediary selected for an order, once shipping is enabled,
- to email, customer-support, video and security-service providers,
- to AI model providers where a User starts an analysis that requires data to be transferred,
- to legal advisers, accountants, auditors and insurers where necessary,
- to public authorities where disclosure is required by law.
Before production launch, each recipient category must be checked against the actual provider list, each party’s role and the agreements in place. An integration that is not in use must not be presented as active.
A payment provider may act as an independent controller for identity checks, fraud prevention and regulated payment services. Its own privacy notice must be presented when the integration is enabled.
06Transfers outside the EEA
Some providers may process data outside the European Economic Area. A transfer will take place only under a mechanism permitted by the GDPR, such as an adequacy decision, the EU–US Data Privacy Framework or Standard Contractual Clauses together with a transfer-risk assessment and supplementary safeguards where needed. Information about the applicable mechanism may be requested from the Controller.
Where the UK GDPR applies, restricted transfers will use a permitted UK mechanism, such as adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum, as appropriate.
07Retention periods
- Account and profile data — for the duration of the agreement and then until relevant claims are time-barred or proceedings end,
- transactions, settlements and tax data — for the period required by applicable tax, accounting and DAC7 rules,
- Listings, messages and disputes — for as long as needed to provide the service, handle the case, prevent abuse and establish or defend claims,
- AI and LiveCam materials — for the period stated when the material is uploaded or until the related Listing or dispute ends, followed by the claims-protection period where the material is evidence,
- security logs — for the period set in the risk-based retention policy, normally no longer than 12 months unless an incident requires longer retention,
- marketing data — until consent is withdrawn, an objection is made or the data becomes outdated.
When the relevant period ends, data is deleted or permanently anonymised. Specific periods should match the implemented retention schedule and backup arrangements.
08AI, profiling and automated decisions
Matchdays may use automated tools to detect abuse, assist with descriptions and valuations, assess item features and prioritise material for moderation. AI output is guidance and may be incorrect.
As a rule, the Operator does not make decisions about a User that produce legal or similarly significant effects solely through automated processing. If such a process is introduced, the User will receive separate information about its logic, significance and consequences and the rights to human intervention and to challenge the decision.
Camera and LiveCam functions are intended to capture item evidence and facilitate a review. Matchdays does not use facial recognition or biometric identification unless a separate, lawful process is introduced with the required information, safeguards and legal basis.
09Your rights
Subject to the conditions set out in the GDPR, you may have the right to:
- access personal data and receive a copy,
- rectify inaccurate data or complete incomplete data,
- erase data or restrict its processing,
- receive and transmit data processed on the basis of consent or a contract,
- object to processing based on legitimate interests,
- withdraw consent at any time,
- complain to the President of the Polish Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl.
If the UK GDPR applies to the processing, you may also complain to the UK Information Commissioner's Office. You may complain to the competent supervisory authority in the EEA country where you live, work or consider an infringement occurred.
Requests may be sent to info@matchdays.store. Before acting on a request, we may ask for information needed to verify the requester’s identity.
10Cookies and device storage
The Platform uses cookies, localStorage and sessionStorage. A detailed and current list, purposes, durations and consent rules are set out in the Cookie Policy. Technologies necessary for login, security and functions expressly requested by the User may operate without consent. Analytics, advertising and other optional purposes require prior consent.
11Children and age limits
Matchdays Accounts and transactional features are intended for people aged 18 or over. The Platform is not knowingly directed at children and does not knowingly collect their data to provide an Account. If we learn that a child's data was submitted without a valid legal basis, we will take appropriate steps to restrict the Account and delete or otherwise lawfully handle the data.
12Security and changes
The Controller uses organisational and technical measures appropriate to the risk, including access controls, encryption in transit, backups, event logging and incident-response procedures. No system can guarantee complete security.
This Policy may be updated following changes to law, functions or providers. The revision date appears at the beginning of the document. Users will be informed appropriately of a material change affecting their rights or the purposes of processing.