Privacy Policy

Draft — under legal review. Last updated July 12, 2026. This is a founder-written working draft, not yet reviewed by a privacy attorney. The described practices reflect what the product actually does today; the formal GDPR/CCPA legal-basis and data-processing-agreement language still needs counsel.

This policy explains what SNEIQ collects, why we collect it, and who helps us process it. The short version: we collect what we need to run a safe marketplace, and we never sell your data.

What we collect

We collect only what the marketplace actually uses. Concretely, that is:

  • Account and profile— your email, handle, display name, avatar, and bio, plus reputation data your activity produces (trust tier, completed sales, vouches, Deal Karma).
  • Seller identity and payout details— collected and held by Stripeduring seller onboarding (legal name, address, bank/payout details, tax info). SNEIQ sees Stripe’s verification status and account references, not your full banking credentials.
  • Listings and content— the items you list, photos you upload, item specifics, and, for used goods, an optional Condition Capture video that is hash-stamped for dispute evidence. For electronics we may collect a photo of the serial number.
  • Orders and shipping— your purchases and sales, amounts, the shipping address on an order, tracking, and your Sneiq Rewards ledger activity.
  • Messages— the messages you send in order and listing threads. These are retained as dispute evidence and are automatically scanned for scam and off-platform-payment patterns so we can warn the other person in real time.
  • Security and fraud signals — at checkout we store a hashed(not reversible) fingerprint of your device and network — an IP hash and a user-agent hash tied to the order — and we keep fraud and moderation flags. These let us detect self-referral rings, stolen cards, account takeover, and abuse without storing your raw IP address alongside the order.
  • Notifications— if you enable push notifications, a device push token so we can send order and alert pings.

How we use it

To operate the marketplace, process payments and payouts, run the payment protection and dispute process, prevent fraud and abuse, send transactional and (where you allow) alert notifications, provide support, and improve the product. We use the hashed device and network signals specifically for security and fraud prevention — not for advertising.

Who processes your data

We rely on a small set of trusted providers to run SNEIQ, and we share only what each needs to do its job:

  • Supabase— our database, authentication, and file storage (your account, listings, orders, photos).
  • Stripe— payments, seller identity and payout onboarding, tax calculation, and payout compliance (KYC, 1099s). Stripe holds the payment funds; SNEIQ never takes custody of your money.
  • Vercel— hosting and delivery of the web app.
  • Cloudflare— DNS, network security, and abuse protection.
  • Resend— transactional email (receipts, order updates, alerts).
  • EasyPost— shipping labels and carrier tracking, when shipping is enabled. Your shipping address is shared to buy a label and track the parcel.
  • Sentry and PostHog— error monitoring and product analytics, when enabled. These are configured to strip personal data: they receive your account’s anonymous identifier and scrubbed technical details, never your email, address, or payment details.

Cookies

SNEIQ uses a small number of first-party cookies. We don’t use third-party advertising or cross-site tracking cookies.

  • Cookies that keep you signed in and secure your session.
  • sneiq_ref(about 7 days) — remembers the share link you arrived through, so if you buy, the person who shared it earns their Rewards.
  • sneiq_via(about 30 days) — remembers a referral so the referral bonus can be credited on your first completed deal.

Your choices — export and deletion

You can exporteverything we hold about you as a single file at any time from your account’s security page (or via /api/account/export).

You can also delete your account. Because we run a marketplace with real money, deletion works by anonymizing rather than fully erasing: we scrub your profile (name, avatar, bio, precise location), remove your personal collections (drafts, wants, follows, watchlist, saved searches, notifications), remove your email and sign you out, and free your handle. We keepthe records we’re required to keep — your orders, payment/ledger history, and vouches — because those are the other party’s transaction record and are needed for tax, accounting, and fraud-prevention obligations. You can’t delete while you have an order still in progress; finish or resolve it first.

Data retention

We keep personal data while your account is active and for as long as we need it to provide the service. After deletion we retain the anonymized transactional and financial records described above for the periods required by tax, accounting, and fraud-prevention law. Message threads are retained as dispute evidence; hashed fraud signals are retained to protect the marketplace.

What we don’t do

We do not sell your personal data, and we do not share it with advertisers for their own marketing.

Your rights

Depending on where you live (including under GDPR and CCPA), you may have rights to access, correct, delete, or port your data, and to object to certain processing. The export and deletion tools above cover access, portability, and erasure directly. For anything else, or to ask a question, email privacy@sneiq.com.