Skip to main content

Privacy review copy · notice analytics-notice-1.0

Privacy and analytics notice

Not legally approved. This accurately inventories the engineered controls but is not deployable legal text. Controller details, processors, transfers, retention, lawful bases, rights wording and DPIA status remain human approval gates.

Controller and contact

Backstage Market controller identity, registered address, privacy contact and complaint route must be confirmed before release.

Marketplace service

Account, company, RFQ, negotiation, Deal, message, document and audit information is processed to provide and secure requested marketplace services.

Aggregate service analytics

Short-lived identity-free service events are collected unless the visitor objects. The deployed retention period and lawful-basis wording require legal approval.

Commercial behavioural analytics

Listing engagement is associated with a visitor, user and active authorised customer account only after a purpose-specific choice. No advertising tracker, fingerprint, intent score or automated pricing is used.

Storage technologies

First-party browser storage holds authentication/session data, privacy choices, purpose-separated analytics identifiers and short-lived session identifiers.

Recipients and transfers

Supabase, the selected hosting provider and the selected transactional-email provider must be named with their processing locations and safeguards after deployment is configured.

Retention and rights

Account/export, correction, objection, restriction and analytics-erasure workflows exist. Final retention periods, identity verification, statutory exceptions and regulator details require approval.

DPIA

The authorised privacy owner must record whether a DPIA is required and approve the outcome. Codex has not made that legal decision.

Visitors can change purpose-specific choices and authenticated users can request export or erasure review in Privacy & analytics settings.