Privacy Policy
Last updated: March 17, 2026
1. Information We Collect
Account Data: When you register, we collect your email address, username, and optional profile information (display name, bio, avatar, Roblox username).
Payment Data: Payment processing is handled entirely by Stripe. We do not store credit card numbers. We receive transaction records including amounts, dates, and Stripe account IDs.
Usage Data: We collect analytics data including pages visited, products viewed, search queries, device type, browser, and IP address.
Content Data: Products you upload, store configurations, support tickets, and reviews.
2. How We Use Your Data
- To provide and maintain the Platform
- To process transactions and send payment confirmations
- To personalize your experience and show relevant products
- To communicate about your account, orders, and platform updates
- To detect and prevent fraud, abuse, and policy violations
- To generate anonymous, aggregate analytics to improve the Platform
- To provide customer support
3. Cookies
We use essential cookies for authentication and session management through Supabase. We may use analytics cookies to understand platform usage. You can control cookie preferences through your browser settings, though disabling essential cookies may prevent you from using the Platform.
4. Third-Party Services
We use the following third-party services that may process your data:
- Supabase — Authentication, database, and file storage. Data is stored in their cloud infrastructure.
- Stripe — Payment processing. Subject to Stripe's Privacy Policy.
- Vercel — Hosting and content delivery.
5. Data Retention
We retain your account data for as long as your account is active. If you delete your account, we will remove your personal data in a reasonable timeframe, except where required by law (e.g., transaction records for tax purposes, which may be retained for up to 7 years). Anonymous, aggregate analytics data may be retained indefinitely.
6. Your Rights
You have the right to:
- Access your personal data by contacting support
- Correct inaccurate personal data
- Delete your account and associated personal data
- Object to processing of your data for marketing purposes
- Withdraw consent at any time where processing is based on consent
- Lodge a complaint with a supervisory authority
7. GDPR Compliance
For users in the European Economic Area (EEA), we process data under the following legal bases: contract performance (providing the Platform), legitimate interests (fraud prevention, analytics), and consent (marketing communications). You may exercise your data rights by contacting us through the support center.
8. Data Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, secure authentication through Supabase, and regular security reviews. However, no method of transmission over the Internet is 100% secure.
9. Contact
For privacy-related questions or to exercise your data rights, contact us at our support center.