Privacy Policy
Effective date: 8/5/2026
This Privacy Policy explains how woo ("we", "us") collects, uses, and shares information when you use the woo marketplace.
1. Information we collect
- Account: name, email, password (hashed), profile photo.
- Listings & transactions: product photos, descriptions, prices, orders, shipping addresses, tracking, messages.
- Payments: processed by Stripe. We receive limited data such as last-4 digits, brand, and status. We do not store full card numbers.
- Tax information (sellers): legal name, address, phone, and SSN/EIN. SSN/EIN is stored encrypted at rest with AES-256-GCM and only decrypted for authorized tax reporting.
- Device & usage: IP address, device type, app version, timestamps, crash logs.
- Cookies & similar technologies: see our Cookie Policy.
2. How we use information
- Operate the marketplace, process payments, ship orders, and provide support.
- Verify identity, prevent fraud, and enforce our Terms.
- Send transactional emails (receipts, shipping, disputes) and, with consent, marketing.
- Comply with legal obligations (e.g., IRS 1099-K reporting, subpoenas).
3. How we share information
- Between buyers and sellers as needed to complete a transaction (e.g., shipping address to the seller).
- Service providers: Stripe (payments/KYC), Supabase (hosting/database), email providers, analytics, and cloud storage — under contracts limiting their use.
- Legal: to comply with law, respond to lawful requests, or protect rights, safety, and property.
- Business transfers: in a merger, acquisition, or asset sale, subject to this Policy.
- We do not sell your personal information.
4. Data retention
We keep account data for as long as your account is active and thereafter as needed to comply with law (e.g., tax records for at least 7 years). You may request deletion; some records must be retained for legal or fraud-prevention reasons.
5. Security
We use industry-standard safeguards: TLS in transit, encryption at rest for sensitive fields (SSN/EIN with AES-256-GCM), Row Level Security on our database, and least-privilege access. No system is 100% secure; report suspected issues to legal@dmaxtrust.com.
6. Your rights
Depending on where you live you may have rights to access, correct, delete, port, or restrict processing of your data, and to object to certain uses. California residents have specific rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of "sharing." EU/UK residents have rights under GDPR/UK GDPR. To exercise rights, email legal@dmaxtrust.com. We will not discriminate against you for exercising these rights.
7. Children
The Service is not intended for anyone under 18. We do not knowingly collect data from children under 13. If you believe a child has provided us data, email legal@dmaxtrust.com and we will delete it.
8. International transfers
We are based in the United States and process data there. If you access the Service from outside the U.S., your data will be transferred to and processed in the U.S. under applicable safeguards.
9. Third-party links
The Service may link to third-party sites (e.g., Stripe, carriers). Their privacy practices are their own.
10. Changes
We may update this Policy. Material changes will be posted with a new effective date and, where required, notified to you.
11. Contact
woo
Naples, Florida, USA
Email: legal@dmaxtrust.com