Privacy Policy

Last Updated: June 2026  |  Version 1.0

This policy is written in accordance with the EU General Data Protection Regulation (GDPR) and the laws of Malta, an EU member state. Our supervisory authority is the Information and Data Protection Commissioner (IDPC) of Malta.

1. Who We Are (Data Controller)

Vendo is an online marketplace platform operating under Malta law. When we refer to "Vendo", "we", "us", or "our", we mean the data controller responsible for your personal data. Vendo is currently operated by an individual. For all data protection enquiries, contact us at: privacy@vendomalta.com — we will respond within 30 days.

2. What Personal Data We Collect

We collect and process the following categories of personal data:

  • Account data: Name, email address, phone number, profile photo, and biography.
  • Listing data: Titles, descriptions, prices, photos, and location (city) of items you post for sale.
  • Transaction data: Buyer/seller confirmation records and ratings.
  • Messages: Private messages exchanged between users through our platform.
  • Usage data: Log data, IP addresses, browser type, and pages visited, collected automatically when you use our service.
  • Preferences: Cookie consent choices and notification settings stored locally on your device.

3. Legal Basis for Processing (GDPR Article 6)

  • Contract (Art. 6(1)(b)): Processing necessary to provide you with the Vendo service — account creation, listing management, messaging.
  • Legitimate interest (Art. 6(1)(f)): Security logging, fraud prevention, and platform safety.
  • Consent (Art. 6(1)(a)): Non-essential cookies (analytics, marketing) — only after you explicitly accept via our cookie banner.
  • Legal obligation (Art. 6(1)(c)): Retaining records as required by applicable Malta law.

4. How Long We Keep Your Data (Retention Periods)

  • Account & profile data: Retained for as long as your account is active. Deleted within 30 days of account deletion.
  • Listings: Automatically and permanently deleted 120 days from publication date (90 days active + 30-day grace period after expiry).
  • Messages: Retained for the lifetime of your account. Permanently deleted within 30 days of account deletion.
  • Security logs: Retained for 90 days for fraud prevention purposes.
  • Cookie consent records: Stored in your browser's local storage and cleared when you clear site data.

5. Who We Share Your Data With

We do not sell your personal data. We share it only with:

  • Supabase Inc. — our database and authentication provider (data processor). Data is stored on EU-region servers. Supabase is contractually bound under a Data Processing Agreement.
  • Resend Inc. — our email delivery provider, used only to send transactional emails (account verification, notifications).
  • Cloudflare Inc. — our content delivery network (CDN) and infrastructure provider. Cloudflare processes network-level data (IP addresses, request metadata) to deliver our website securely. Cloudflare is bound by its GDPR-compliant Data Processing Addendum.
  • Law enforcement or courts — only when required by a valid legal order under Malta or EU law.

6. Cookies and Tracking

We use two categories of cookies:

  • Strictly necessary: Session cookies required for login and core functionality. These cannot be refused.
  • Optional (analytics/marketing): Only set after you click "Accept All" on our cookie banner. You can change your preference at any time by clearing your browser's local storage for this site.

7. Your Rights Under GDPR

As a data subject you have the following rights:

  • Right of access (Art. 15): Request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): Correct inaccurate or incomplete data via your profile settings.
  • Right to erasure / "right to be forgotten" (Art. 17): Delete your account and all associated data via Settings → Delete Account. Auth credentials are permanently deleted within 24 hours.
  • Right to data portability (Art. 20): Download a JSON copy of your data at any time via Settings → Personal Info → Download My Data.
  • Right to restriction (Art. 18): Request that we stop processing your data in certain circumstances.
  • Right to object (Art. 21): Object to processing based on legitimate interest.
  • Right to withdraw consent: Withdraw cookie consent at any time without affecting previous processing.

To exercise any right, email us at privacy@vendomalta.com. We will respond within 30 days.

8. Right to Lodge a Complaint

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the supervisory authority in Malta:

Information and Data Protection Commissioner (IDPC)
Level 2, Airways House, High Street, Sliema SLM 1549, Malta
Website: idpc.org.mt
Email: idpc.info@idpc.org.mt

9. International Data Transfers

Your data is stored on Supabase servers located within the European Economic Area (EEA). If any transfer outside the EEA becomes necessary, it will be governed by Standard Contractual Clauses (SCCs) approved by the European Commission.

10. Changes to This Policy

We may update this policy to reflect changes in our practices or applicable law. We will notify you of significant changes via email or an in-app notice at least 14 days before the changes take effect. The "Last Updated" date at the top of this page always reflects the current version.

11. Contact

For any data protection question or to exercise your rights:
privacy@vendomalta.com