Privacy Policy
1. Information We Collect
We collect information you provide when creating an account, listing items, completing transactions, and contacting support. This includes:
- Account information: name, email, password (hashed), profile photo
- Transaction information: payment details (processed by Stripe), shipping address, purchase history
- Listing information: photos, descriptions, prices, condition
- Communications: messages between buyers and sellers, support requests
- Automatic data: IP address, device type, browser, pages visited (via cookies — see our Cookie Policy)
2. How We Use Your Information
- To operate the marketplace, process transactions, and provide customer support
- To communicate about your account, listings, orders, and policy changes
- To send marketing emails (only if you opt in — you can unsubscribe at any time)
- To detect and prevent fraud, counterfeits, and policy violations
- To comply with legal obligations (tax reporting, court orders)
3. How We Share Your Information
We share data only with:
- Other users: Sellers see buyer name and shipping address; buyers see seller name
- Subprocessors: See the table in Section 3a for the full list of service providers and what each processes
- Authorities: If required by law, subpoena, or to protect our rights
We do not sell your personal information.
3a. Subprocessors
We use the following third-party vendors to operate the Deuce marketplace. Each processes specific categories of personal data under written agreements that require them to protect your information and use it only for the purposes described.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Vercel | Application hosting, CDN, analytics, speed insights | IP address, device metadata, request logs, anonymous performance metrics | United States |
| Neon | PostgreSQL database | All account, listing, and transaction data | United States |
| Stripe | Payment processing, Connect onboarding (KYC), payouts, 1099-K tax reporting | Payment details, billing address, identity verification, transaction history | United States |
| Resend | Transactional and notification email | Email address, name, communication content | United States |
| Uploadthing | Image upload and storage (listings, profile photos) | Uploaded image files | United States |
| Sign-in (OAuth) — optional | Email, name, profile photo from Google account (only when you choose Sign in with Google) | United States | |
| Apple | Sign-in (OAuth) — optional, when enabled | Authentication identifiers, email, and name from your Apple account (only when you choose Sign in with Apple) | United States |
| Anthropic | AI listing assistant (generates a draft listing from a seller-uploaded photo) | Seller-uploaded listing photos and the generated draft text (processed in transit to produce the draft; not used to train Anthropic’s models per their API terms) | United States |
| EasyPost | Shipping-label generation and package tracking | Buyer name and shipping address, seller ship-from address, package details | United States |
| Sentry | Error monitoring and performance tracing | Error data and stack traces, plus sampled request traces (which can include URLs containing order IDs) | United States |
This list is current as of the “Last updated” date at the top of this policy. We update the list within 30 days of any change. Material changes will be announced via email to active users.
4. Your Rights
Depending on your jurisdiction (GDPR, CCPA, etc.), you may have the right to:
- Access the data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and the personal data we hold about you (see §5 for how this works in practice)
- Export your data (data portability) — available from your account settings
- Opt out of marketing communications
You can exercise these rights from your account settings or by emailing privacy@deuce.global.
5. Data Retention & Account Deletion
We retain account data for as long as your account is active.
How deletion works. When you delete your account, we permanently remove your personal identifiers — name, email, profile photo, password, and date of birth. We retain the transaction records associated with your account (orders, payments, payouts) in anonymized form. We do this for two reasons:
- Counterparty protection: If you completed a sale or purchase with another user, that user has an ongoing right to their own transaction record. Fully erasing your side of the transaction would destroy theirs.
- Tax and accounting compliance: US tax law (and our Stripe 1099-K obligations) requires us to retain marketplace transaction records for 7 years. This is the legal basis we rely on under GDPR Art. 6(1)(c) and Art. 17(3)(b) for that retention.
If you have completed no transactions, anonymization is effectively full erasure for your account. We block account deletion while you have orders in progress (paid but not yet delivered) so we never strand a counterparty mid-transaction; complete or refund those first.
6. Security
We use industry-standard security measures including encrypted data transmission (TLS), hashed passwords (bcrypt), and secure payment processing via Stripe. No system is 100% secure, however.
7. International Transfers
Your data may be stored and processed in the United States. By using Deuce, you consent to this transfer.
8. Children
Deuce is not intended for users under 18. We do not knowingly collect data from children.
9. Changes to This Policy
We will notify you of material changes via email or in-app notification.
10. Contact
Privacy questions? Email privacy@deuce.global.