Sandbox privacy notice
Test data categories currently stored
The sandbox collects only what the demo needs to function. In production, each of these categories would need a documented lawful basis, retention window, access model, and export/deletion flow.
- Email address and authentication session used to sign in.
- Profile fields you set: display name and country.
- Cart contents and saved-deal favorites.
- Sandbox orders, order items and simulated payment attempts (no card data).
- Disputes, dispute messages and support tickets/messages you create.
- Notifications and receipt metadata for your own account.
- Audit and security metadata: IP-scoped rate signals, admin action history, and immutable audit events.
- Seller application data if you apply: legal/business name, contact email/phone, country and territories, website, authorization source/expiry metadata, and policy consents.
What we do not collect
The sandbox never collects or stores card data — checkout is simulated. It does not intentionally collect biometric data, precise location, health or children's data.
Service categories
Data is stored on a managed Postgres backend and served through a managed hosting/edge platform (Supabase-class database/auth and Lovable-class hosting). These are named here as service categories, not as parties bound by a signed data-processing agreement — an operator identity, processor agreements, subprocessor list and international-transfer story are all live-launch prerequisites.
Sharing
Order-fulfillment metadata is shared with the fictional demo seller responsible for the order, and with staff-role accounts (support, reviewer, admin) to resolve disputes. This sandbox does not sell buyer data; a production version would need a specific, verifiable public statement about data sales in each applicable jurisdiction.
Outstanding for live launch
- Operator legal identity, contact address and data-protection contact.
- Retention windows per data category and deletion mechanics.
- User-facing export / correction / deletion workflow.
- Cookie and analytics consent, if analytics are enabled.
- Subprocessor list, DPA and international-transfer safeguards.
- Incident-response contact and breach-notification runbook.
Any production privacy notice must be reviewed by qualified counsel and reflect the real operator.